1. Purpose of This Policy
This Data Processing Policy explains exactly how PipeGuide processes call recordings, transcriptions, AI-generated analysis and billing-related data. Given the sensitive nature of sales conversations, we are committed to transparency about how this data is captured, processed, stored, shared, and ultimately deleted. This policy supplements our Privacy Policy and forms part of our Terms of Service.
2. Data Capture Methods
Browser Microphone (In-Person / Solo Calls)
- Audio is captured via the browser's WebRTC / MediaRecorder API after you grant microphone permission.
- The audio stream is sent over a secure WebSocket to Deepgram, our speech-to-text sub-processor, which returns text transcripts in real time.
- Raw audio is not stored on our servers. Only the resulting text transcript is persisted.
- Transcription occurs only while the call session is actively running. Closing the tab or ending the call stops capture immediately.
Meeting Bot (Online Meetings)
- When you supply a meeting link (Zoom, Microsoft Teams, or Google Meet), our sub-processor Recall.ai dispatches a bot to join the meeting as a visible participant.
- The bot is named so all meeting participants can see that the meeting is being recorded. Most major platforms also display a "recording in progress" banner.
- The bot streams meeting audio to Recall.ai which generates a real-time transcription that is then streamed to your PipeGuide dashboard via Server-Sent Events.
- The bot can be removed from the meeting at any time by any participant, ending capture immediately.
3. AI Processing
Once a transcript is captured, it is analysed by AI systems as follows:
- Real-time analysis: during an active call, the most recent transcript window is sent to OpenAI's GPT models every 15 seconds for live qualification scoring (using your selected framework — BANT, MEDDIC, SPICED, etc.) and to generate suggested probing questions.
- Post-call summaries: after a call ends, the full transcript is processed to generate an executive summary, a prospect profile, a qualification assessment, recommended next steps, requirements identified, and a risk-and-opportunity assessment.
- Company research: when you provide a company website URL, we may scrape publicly available information to provide context for the analysis. We do not access password-protected or paywalled content.
- What we send to AI providers: only the text transcript. We do not send audio, video, IP addresses, or any personally identifiable information beyond what is naturally spoken in the conversation.
- Provider data usage: we use OpenAI's API which does not use customer inputs to train OpenAI's models. Recall.ai and Deepgram also operate under no-training contractual terms.
4. What Data Is Stored
| Data Type | Stored? | Retention |
|---|
| Raw audio (browser mic) | No | Streamed to Deepgram only; not retained |
| Raw audio (meeting bot) | Held by Recall.ai per their policy; not stored on PipeGuide servers | Recall.ai default ~30 days |
| Text transcripts | Yes | Until account deletion (then 60-day window) |
| AI qualification scores | Yes | Until account deletion |
| Post-call summaries | Yes | Until account deletion |
| Solution notes / requirements | Yes | Until account deletion |
| PDF exports | Generated on-demand | Not permanently stored |
| CRM credentials (e.g. HubSpot API key) | Yes, encrypted at rest | Until you remove the integration |
| Billing metadata (Paystack) | Yes | 7 years for tax compliance |
| Authentication logs | Yes | 90 days |
| Audit logs (lifecycle, dunning) | Yes | 3 years |
5. User Responsibilities
As a user of PipeGuide, you are responsible for:
- Obtaining consent: informing every call participant that the conversation is being recorded and analysed by AI, and obtaining explicit consent where required by law.
- Recording laws: complying with all applicable recording-consent laws (e.g. POPIA in South Africa, GDPR in the EU/UK, CCPA in California, state-level wiretapping laws in the US).
- Data accuracy: ensuring that prospect and company information entered into the Service is accurate and appropriately handled.
- Access control: admin users must manage team-member access appropriately and revoke access when team members leave the organisation. Bulk-invite and per-rep removal tools are available in the Team Management page.
- Prohibited content: not using PipeGuide to capture conversations covered by attorney-client privilege, medical privilege, or other regulated confidential settings.
6. Data Access and Sharing Within PipeGuide
- Sales representatives can access only their own call data.
- Managers can access call data and analytics for users in their assigned department.
- Administrators can access call data for all users in their organisation.
- Platform operators (PipeGuide staff) can only access a customer's data via an audit-logged impersonation flow, used for support purposes and visible to the customer admin in audit logs.
- Call data is never shared with other organisations or third parties, except for the sub-processors listed in our Privacy Policy and as necessary for AI processing as described in clause 3.
- We do not sell your data. We do not use your call content for advertising or any other commercial purpose unrelated to delivering the Service to you.
- We may disclose data if required by law, court order, or governmental authority. Where legally permissible, we will notify you before doing so.
7. Account Lifecycle and Data Deletion
- Per-call deletion: users can request deletion of specific call sessions at any time from within the app.
- Account suspension (e.g. for non-payment): data is preserved unchanged. No deletion occurs.
- Account termination (by you, by us, or automatically after 30 days of non-payment): Customer Data is moved to read-only status and retained for 60 days.
- During the 60-day retention window: you may request a full data export or full account reactivation by contacting support@pipeguide.tech. Exports are provided in CSV (structured data) and PDF (transcripts and summaries) formats.
- After 60 days: all Customer Data is permanently deleted from production. Backups are purged within a further 30 days. Only the minimum metadata required to evidence compliance (audit log entry containing the org ID and deletion timestamp) is retained.
- Tax records exception: billing metadata required to be retained under tax law (e.g. invoices, payment confirmations) is retained for 7 years from issue date, with the rest of the customer's data deleted on the standard schedule.
- Ad-hoc deletion requests can also be sent to support@pipeguide.tech.
8. Security Measures
- All data transmission uses TLS / HTTPS encryption.
- Databases are hosted on MongoDB Atlas with encryption-at-rest enabled.
- Passwords are hashed using bcrypt with appropriate cost factors.
- JWT access tokens are short-lived and can be invalidated on suspension or password change.
- Brute-force protection is implemented on the login endpoint; sustained failed attempts result in temporary IP lockout.
- Rate limiting is applied to sensitive endpoints to prevent abuse.
- Third-party API credentials (e.g. CRM keys, OAuth tokens) are stored encrypted.
- Webhook payloads (e.g. Paystack, Recall.ai) are signature-verified before processing.
- Regular dependency scanning and security patching is applied to all components.
9. Data Breach Notification
In the event of a data breach affecting your Customer Data, we will notify the primary administrator by email within 72 hours of becoming aware of the breach, and we will also notify the relevant supervisory authority (e.g. the Information Regulator under POPIA) where required by law. The notification will include the nature of the breach, the categories of data affected, the likely consequences, and the measures taken to mitigate the impact.
10. Contact
For questions about how your data is processed, to submit a data deletion or access request, or to report a security concern, please contact our Information Officer at support@pipeguide.tech.