Introduction, Scope, and Processing Roles
Black Diamond Labs Inc. ("Black Diamond Labs," "we," "our," or "us") develops, operates, and supports applied AI products and services. This Privacy Policy explains how we process personal information through our website, z-gateway, Managed AI Call Operations, dashboards, APIs, integrations, communications systems, documentation, support, and future Black Diamond Labs products and services (collectively, the "Services").
Managed AI Call Operations may, as configured by a business customer, answer or route calls, process customer inquiries, coordinate appointments, send approved communications, interact with customer-authorized systems, and create operational records. A person who communicates with one of our business customers through the Services is a "Caller" or "End Customer."
Depending on the context and applicable law, we may act as a controller or business for our own website, account, billing, marketing, security, and support data. When we process Caller, End Customer, or workflow data for a business customer, we generally act as that customer’s processor, service provider, or data handler. The Customer generally decides why the system is used and which approved workflows it performs. Customer-specific terms or a Data Processing Addendum may further govern that processing; legal classifications may differ by jurisdiction and use case.
This Policy applies to website visitors, business prospects, Customers, Authorized Users, Callers, and End Customers whose information reaches the Services. It does not govern a third party’s independent practices, including a Customer’s own handling of information or a linked service that Black Diamond Labs does not operate.
If we process information for a Customer, requests about that information should ordinarily be directed to the Customer. We assist Customers with verified requests as required by applicable law and contract. If we receive a request directly, we may refer it to the appropriate Customer unless law prohibits us from doing so.
Business Customer and Account Data
We collect information provided by prospective and current Customers, authorized users, partners, and support contacts.
Account and business-contact information may be required to create an account, authorize an organization, prepare a pilot or order, administer access, deliver support, and maintain a record of the commercial relationship. If an organization administers an account, its administrators may manage Authorized Users and view account activity associated with that organization.
- Names, business names, job titles, email addresses, telephone numbers, and account identifiers.
- Organization, workspace, project, authorized-user, authentication, and access information.
- Billing, subscription, invoice, usage, and transaction records associated with Black Diamond Labs fees.
- Pilot inquiries, onboarding responses, acceptance records, configuration preferences, and service inventory.
- Support requests, feedback, correspondence, and other communications with us.
- Marketing preferences, meeting details, survey responses, and records of consent or objection where applicable.
- Credentials and security information such as password hashes, authentication tokens, session identifiers, identity-provider metadata, permission assignments, and account-recovery events.
Business Configuration and Knowledge
Customers may supply information needed to configure an applied AI system for their operations. The Customer controls what approved business information and procedures are made available to the Service.
Configuration information may be entered directly, provided during onboarding, imported from a Customer-authorized source, or generated from Customer-approved materials. It may be updated as a Customer changes its hours, services, personnel, service area, scheduling rules, or operating procedures.
- Business hours, locations, service areas, services offered, and availability.
- Scheduling rules, service categories, FAQs, pricing or estimate policies, and qualification criteria.
- Escalation contacts, transfer destinations, callback instructions, and after-hours procedures.
- Approved scripts, disclosures, business knowledge, operational procedures, and prohibited claims.
- Integration settings, resource selections, workflow permissions, and system-of-record rules.
- Prompt, agent, policy, and approval configurations; role and permission assignments; and version or change history needed to operate or troubleshoot the Service.
Sensitive and regulated information
The Services are not intended to receive complete payment-card numbers by voice, account passwords, authentication secrets, government identification numbers, medical diagnoses, or other highly sensitive information unless an applicable order expressly authorizes a supported use and appropriate safeguards are in place. Customers must not instruct Callers to provide unsupported sensitive information and should configure collection fields, scripts, and integrations to minimize unnecessary data.
A home-service Caller may describe an equipment problem, accessibility need, or urgent circumstance so a Customer can route the request. That intake does not make the Service a medical, emergency, or technical-diagnosis service. Customers remain responsible for identifying sector-specific requirements before using the Services with regulated data.
Caller and Communication Data
Depending on Customer configuration, contractual requirements, and applicable law, Managed AI Call Operations may process the following information. Recording and transcription are not necessarily enabled for every call.
A Customer may configure a disclosure, recording, transcription, transfer, callback, or opt-out flow. The information collected during a particular interaction depends on what the Caller chooses to provide and what the Customer has authorized the system to request.
- Caller phone number or caller ID, name, contact details, and information the Caller chooses to provide.
- Call timestamps, duration, direction, status, routing, transfer, callback, and technical metadata.
- Audio recordings and call transcripts when enabled and legally permitted.
- Conversation summaries, Caller intent, service-request details, addresses or service locations, urgency, and appointment preferences.
- Call outcomes, quality, safety, reliability, and performance signals.
- SMS or email content associated with an approved workflow, together with consent, opt-out, delivery, and communication-status records.
- Speech-to-text input, text-to-speech output, model prompts and responses, tool-call records, confidence or classification signals, and human-review or correction records used to provide and monitor the configured interaction.
Appointment, Workflow, and Product Data
Workflow records help the Customer understand what the system attempted, whether an action completed, what information was used, and whether a person intervened. The available records and level of detail depend on the Service, configuration, provider capabilities, and applicable order.
- Availability information, calendar and resource identifiers, appointment dates and times, event details, and time zones.
- Booking, cancellation, rescheduling, transfer, and callback status.
- Service-request identifiers, CRM or field-service references, callback tasks, approved workflow inputs, and outcomes.
- For z-gateway and other agent systems: workspace and project metadata, policy decisions, approvals, tool-action records, audit events, and execution results.
- API requests, webhook events, usage records, configuration changes, diagnostics, and operational telemetry.
- Calendar availability windows, technician or resource assignments, time-zone information, location or service-area matching, and records of attempted or completed synchronization.
- Follow-up tasks, escalation history, human-review status, exception handling, retry history, and changes applied to a Customer-authorized system.
Customer-Authorized Integrations
The Services may connect, when authorized and supported, to calendars, CRM or field-service platforms, telephony providers, payment platforms, email and messaging services, business databases, APIs, and other Customer systems. We may process authorization tokens, provider account identifiers, granted scopes, calendar or resource identifiers, webhook events, integration-health information, and the data required to perform the authorized workflow.
Access is limited to Customer-authorized purposes and scopes, subject to provider capabilities, contractual terms, and Customer configuration. Customers may revoke provider access, though revocation may prevent an integration from operating. Third-party services process information under their own terms and privacy practices.
Where a Customer authorizes access to Google user data, our use and transfer of that data is also subject to the applicable Google terms, including the Google API Services User Data Policy. The exact scopes and resources depend on the Customer-authorized workflow.
For an authorized integration, we may receive provider account identifiers, resource names, calendar or CRM objects, field mappings, synchronization status, token-expiration information, error details, and webhook payloads. We use this information to perform the requested workflow, maintain the connection, diagnose failures, and record the result.
Customers can disconnect an integration through the supported Customer or provider controls. Disconnecting stops new authorized access after revocation takes effect but does not automatically remove records already created in the Customer’s system, records we must retain, or data remaining in backups until their normal rotation.
Website, Device, and Third-Party Source Data
We use cookies and similar technologies as needed to operate, secure, and understand the Services. We do not use the website for cross-context behavioral advertising or sell personal information for money. Browser controls may affect optional technologies and some Service functionality.
We may receive information directly from an individual, from the Customer that configures or uses the Services, from an Authorized User, from a Caller’s device or communications carrier, from a Customer-authorized integration, or from a service provider acting for us. We may also create derived information such as a call summary, workflow status, fraud signal, service-health metric, or aggregate usage statistic.
- IP address, browser, device, operating system, network, request, and approximate location information.
- Session identifiers, essential cookies, preferences, authentication events, and fraud-prevention signals.
- Service usage, page and feature activity, error reports, audit logs, security events, and performance diagnostics.
- Information received from identity providers, Customer-authorized integrations, payment processors, communications providers, and referral sources.
- Hosting, database, monitoring, error, performance, and security telemetry necessary to deliver and protect the Services.
Cookies and similar technologies
Essential cookies and local-storage technologies may support authentication, session continuity, security, fraud prevention, preferences, and core functionality. Analytics or performance technologies, if enabled, help us understand page and feature performance. Browser settings may block or remove these technologies, but doing so can impair account or Service functionality.
The Services do not currently respond to browser Do Not Track signals because there is no uniform standard. Where applicable law requires recognition of a supported opt-out preference signal, such as Global Privacy Control, we process that signal for the browser or device from which it is received.
Diagnostics and error monitoring
Diagnostic data may include error messages, stack traces, request metadata, application state, device or browser details, performance measurements, infrastructure telemetry, and account, workspace, call, or workflow identifiers needed to investigate an issue. We seek to minimize unrelated content and restrict access to diagnostic systems. Customers should not place passwords, private credentials, payment-card data, or unrelated sensitive content in support tickets, prompts, or diagnostic fields.
Payment and Billing Information
Black Diamond Labs may use a payment processor such as Stripe to bill Customers for setup, subscription, usage, or related fees. The processor generally receives and processes complete payment credentials; we may receive customer, invoice, subscription, payment-status, Checkout Session, transaction-reference, and dispute metadata.
Separately, a Customer may use a Customer-owned payment link or connected payment account to collect a payment from its Caller or End Customer. The Customer and payment processor are responsible for the underlying transaction. Managed AI Call Operations is not intended to collect complete payment-card numbers by voice.
A payment link workflow may record that a link was generated or sent, a checkout or transaction reference, payment status, amount or currency, and related workflow outcome. Complete card or bank credentials are generally submitted directly to the payment processor and are governed by that processor’s privacy policy and terms.
How We Use Information
Black Diamond Labs does not use identifiable Customer call recordings, transcripts, or other Customer Data to train general-purpose AI models without the Customer’s express written authorization. We may use aggregated or de-identified operational information that cannot reasonably be associated with a Customer or identifiable person to operate, secure, evaluate, and improve the Services, as permitted by law and contract.
Third-party model, voice, and transcription providers may process content to deliver configured features. Their retention and data-use treatment depends on our provider configuration, contract, and their applicable terms. Customer-specific restrictions or disclosures may also appear in an order or DPA.
- Provide, configure, operate, maintain, and support the Services.
- Answer, route, document, and analyze communications and execute Customer-approved workflows.
- Coordinate scheduling, integration operations, transfers, callbacks, and approved follow-up.
- Authenticate users, enforce authorization, prevent fraud and abuse, and protect Customers, End Customers, and systems.
- Bill Customers, administer accounts, communicate about the Services, and respond to support requests.
- Monitor reliability, investigate errors, troubleshoot integrations, evaluate quality, and improve products using controls appropriate to our role and applicable agreements.
- Comply with law, enforce agreements, resolve disputes, and protect legal rights.
- Create aggregate or de-identified reporting, measure adoption and performance, and plan capacity without identifying a Caller or Customer where identification is not needed.
AI Processing and Human Review
The Services may use AI to interpret language, generate responses, extract structured information, summarize conversations, classify requests, recommend actions, or initiate Customer-authorized workflow steps. AI output can be incomplete, inaccurate, or contextually inappropriate.
Customers should configure human transfer, escalation, correction, and review appropriate to the workflow, particularly for consequential matters. Black Diamond Labs also designs and operates controls within the scope of the applicable Service and agreement; Customer responsibility does not eliminate our own privacy and security obligations.
Depending on the Service, a person may review a flagged interaction, failed workflow, support issue, quality sample, or suspected abuse event. Access is limited according to role and operational need. AI processing is not used by Black Diamond Labs to make employment, credit, insurance, housing, medical, legal, or similarly consequential decisions about Callers on our own behalf.
Retention and Deletion
Retention depends on Customer configuration, contract terms, product requirements, legal obligations, security and dispute needs, and backup cycles. Account and billing records may be retained for administration and legal compliance. Audit and workflow records may be retained for security, reliability, and accountability. Call recordings and transcripts, when enabled, may have Customer-specific retention settings. Support records may be retained while relevant to the relationship or issue.
When information is no longer required, we take steps to delete, de-identify, or isolate it as appropriate. Deletion from active systems may not immediately remove data from backups or records that must be retained for legal, security, or dispute purposes. Contractual export or deletion procedures may apply at termination.
- Account, organization, and access records: generally retained while the account is active and for a reasonable period afterward for administration, reactivation, security, and dispute handling.
- Billing, invoice, tax, and transaction records: retained as required for accounting, tax, fraud prevention, audit, and legal obligations.
- Call recordings and transcripts: retained only when enabled, according to Customer configuration, contract terms, product requirements, legal obligations, and supported deletion controls.
- Summaries, appointments, workflow results, and audit records: retained according to Customer settings and the operational, accountability, security, and contractual needs of the Service.
- Support communications and diagnostics: retained while needed to address the issue, maintain service history, protect security, and meet legal or contractual obligations.
- Backups: rotated on operational schedules; deletion from active systems may take effect before the same information ages out of protected backups.
Offboarding, export, and disconnection
At termination, Customers are responsible for removing forwarding, revoking provider access, disconnecting integrations, and completing Customer-controlled export or porting steps. We provide export or deletion assistance when required by the applicable order, DPA, or law. Disconnecting an integration does not delete information retained independently by the third-party provider or the Customer.
Security
We use reasonable administrative, technical, and organizational measures designed to protect information, which may include access controls, scoped credentials, encryption where appropriate, logging, monitoring, incident response, and vendor management. No transmission, storage, or processing method is completely secure, and we cannot guarantee absolute security.
Measures are selected according to the nature of the Service and may include role-based access, authentication controls, least-privilege permissions, credential-management practices, network and application monitoring, audit records, vulnerability management, backup and recovery procedures, and review of providers. Specific contractual security commitments, if any, are stated in an order, DPA, or security addendum.
If you believe information or a Service account may be compromised, contact security@black-diamond.tech. Do not include passwords, secret keys, or complete payment-card information in the report.
Customer Responsibilities
We remain responsible for our own processing and for the controls and obligations assigned to us under applicable law and Customer agreements.
- Provide legally required AI, monitoring, recording, transcription, and communication notices.
- Determine whether recording or transcription is lawful and obtain required consent.
- Approve and maintain accurate business rules, disclosures, connected-system access, and escalation paths.
- Use outbound calls, SMS, email, and opt-out features lawfully and honor communication preferences.
- Address industry-specific requirements and ensure submitted data and connected-system access are authorized.
- Keep Authorized User access current, protect credentials, revoke access promptly, and notify us of suspected misuse or compromise.
- Provide accurate contact, hours, service, price, availability, transfer, emergency, and fulfillment information and maintain a correction process.
Legal Bases for Processing
Where a legal basis is required, we process personal information as necessary to perform a contract, pursue legitimate interests such as operating and securing the Services, comply with legal obligations, protect vital interests where applicable, or based on consent. When we process information for a Customer, the Customer determines the relevant purpose and legal basis subject to applicable law.
Our legitimate interests may include maintaining service reliability, preventing fraud and abuse, improving usability, supporting Customers, protecting legal rights, and understanding business performance, provided those interests are not overridden by applicable individual rights. Consent may be withdrawn where it is the applicable basis, without affecting processing that was lawful before withdrawal.
Privacy Rights and Choices
Depending on location and applicable law, individuals may have rights to access, correct, delete, restrict, object to, or obtain a portable copy of personal information, withdraw consent, opt out of certain processing, or appeal a denied request. We do not discriminate for exercising applicable rights.
For data we process on behalf of a Customer, a Caller or End Customer should generally contact that Customer first. We will assist Customers as required by applicable agreements and law. We may verify identity or authority and may retain information where an exception applies.
Available requests
- Confirm whether personal information is processed and request access to it.
- Correct inaccurate information or complete information that is materially incomplete.
- Request deletion, restriction, or objection where the right applies.
- Request a portable copy of certain information where technically feasible and legally required.
- Withdraw consent or opt out of marketing communications.
- Opt out of sale, targeted advertising, or certain profiling where applicable; we do not currently sell personal information or use it for cross-context behavioral advertising.
- Appeal a denied request where applicable law provides that right.
Verification and authorized agents
We may request information reasonably necessary to verify identity, account association, authority, or jurisdiction. An authorized agent may submit a request where permitted, but we may require proof of authorization and direct confirmation from the individual. We do not discriminate against an individual for exercising an applicable privacy right.
Regional rights
Residents of California and other U.S. states with comprehensive privacy laws may have rights to know, access, correct, delete, port, or opt out of specified processing. Individuals in the European Economic Area, United Kingdom, or Switzerland may also have rights to restrict or object, withdraw consent, and complain to a supervisory authority. These rights are subject to legal definitions, exemptions, and our role in the processing.
Depending on the interaction, the categories collected may include identifiers; customer-record information; commercial and transaction information; internet or electronic-network activity; approximate location derived from an IP address; professional information; audio or communications information; inferences such as intent or workflow classification; and sensitive information only where supplied through an authorized and supported workflow. Sources and business purposes are described in Sections 2 through 11.
If applicable law provides an appeal right and we deny a verified request, the response will explain how to appeal. A person may also contact the competent privacy or data-protection authority. We do not use personal information for profiling in furtherance of decisions that produce legal or similarly significant effects on our own behalf.
International Transfers
Black Diamond Labs is based in the United States. Information may be processed in the United States or other countries where we or our providers operate. Where required, we use a recognized transfer mechanism or other appropriate safeguard. Privacy rights and safeguards may differ by jurisdiction.
Where applicable, transfer safeguards may include contractual protections such as the European Commission’s Standard Contractual Clauses, a United Kingdom addendum, or another lawful mechanism. Customers may contact us for information about a mechanism that applies to their processing.
Children
The Services are directed to businesses and professional users, not children under 16. We do not knowingly collect personal information directly from children under 16 through our website or account services. A business customer should not configure the Services to collect children’s information unless the use is lawful, contractually approved, and appropriately protected.
If you believe a child has provided information to us outside an authorized and lawful Customer workflow, contact us so we can investigate and take appropriate action.
Changes and Contact
We may update this Policy as our Services, practices, or legal obligations change. We will update the date above and provide additional notice when required by law or an applicable agreement.
Questions, complaints, and privacy requests may be sent to the address below. Include “Privacy Request” in the subject line for a rights request and identify the relevant Customer or Service when possible. We may ask for additional information to route and verify the request.
Black Diamond Labs Inc.
Privacy inquiries: privacy@black-diamond.tech
Website: https://black-diamond.tech