Privacy Policy
Cortex Voice Inc.
Effective date: July 4, 2026 · Last updated: July 4, 2026
1. Who we are and how to read this policy
Cortex provides an AI voice agent that answers inbound telephone calls on behalf of restaurants and other food-service businesses. When a person calls a restaurant that uses Cortex, our AI agent answers the phone, takes their food order, answers questions about the menu, and passes the order to the restaurant. To do this, our system records the call and stores information such as the caller's name, phone number, and order details.
We handle personal information in two different roles, and your rights depend on which role applies:
- As a “business” (CCPA) / “controller” (GDPR): for the personal information of our own direct customers — the restaurant owners, managers, and staff who sign up for, log into, and administer the Cortex service — and for visitors to our website. In this role we decide why and how that information is used, and this policy governs directly.
- As a “service provider” (CCPA) / “processor” (GDPR): for the personal information of end callers (the restaurant's customers who phone in to place an order). We process that information only on behalf of, and under the instructions of, the restaurant that received the call, under a written contract that restricts our use of it. In this role, the restaurant is the business/controller, its own privacy policy governs the caller relationship, and you should direct rights requests about your call to the restaurant you called. We will support the restaurant in honoring your request. Section 8 explains this in detail.
We are not currently subject to the CCPA under its revenue and volume thresholds, but we have chosen to describe our practices to CCPA/CPRA and GDPR standards so that our customers and their callers are treated as if we were.
This is a privacy policy, not legal advice. See the note at the end of this document.
2. Scope
This policy covers personal information we collect through:
- Our website, marketing pages, and demo-request / “call me” forms at cor-tex.solutions;
- Our customer dashboard and account system (used by restaurant staff);
- Inbound phone calls answered by the Cortex AI agent, including call audio recordings and transcripts; and
- Direct communications with us (email, support requests, sales conversations).
It does not cover: the privacy practices of the restaurants that use Cortex (each restaurant is responsible for its own policy and disclosures to its callers), or third-party websites or services we link to.
3. Categories of personal information we collect
The table below lists every category of personal information (as those categories are defined in Cal. Civ. Code § 1798.140(v)) that we have collected within the preceding 12 months, the sources, the business purpose, and whether we “sell” or “share” it. We do not sell personal information and we do not share it for cross-context behavioral advertising (see Section 6).
| CCPA category (§ 1798.140(v)(1)) | Examples of what we collect | Source | Primary purpose | Sold? | Shared for cross-context ads? |
|---|---|---|---|---|---|
| (A) Identifiers | Caller name, caller phone number, restaurant contact name, business email, account username, IP address | End caller (spoken on the call); restaurant staff (account signup); website visitors | Take and route food orders; operate accounts; security; support | No | No |
| (B) Customer records (Cal. Civ. Code § 1798.80(e)) | Name tied to phone number and order history; business billing contact | End caller; restaurant | Fulfill orders; billing to the restaurant | No | No |
| (C) Protected-classification characteristics | We do not intentionally collect these. Age, gender, national origin, etc. may be inferable from a voice recording but are not used or retained as distinct fields | (incidental, via audio) | N/A — not used | No | No |
| (D) Commercial information | Food and drink items ordered, order totals, order history, menu items discussed, records of services purchased by the restaurant | End caller; restaurant | Fulfill orders; provide the service to the restaurant | No | No |
| (E) Biometric information | We do not create voiceprints or use call audio for biometric identification | N/A | N/A | No | No |
| (F) Internet / network activity | Dashboard usage logs, pages viewed, device/browser info, cookies (see Section 7) | Website / dashboard | Operate and secure the service; product improvement | No | No |
| (G) Geolocation data | Approximate location inferred from IP address (city-level); we do not collect precise GPS location | Website / dashboard | Security, fraud prevention, analytics | No | No |
| (H) Audio, electronic, visual information | Audio recordings of inbound calls and their transcripts; call metadata (time, duration, phone numbers) | The phone call itself | Take the order, quality assurance, transcription for order accuracy, debugging and improving the AI agent | No | No |
| (I) Professional / employment information | Job title / role of restaurant staff who use the dashboard | Restaurant staff | Account administration and role-based access | No | No |
| (J) Education information | We do not collect this | N/A | N/A | No | No |
| (K) Inferences | Order preferences derived from prior orders (e.g. usual order) | Derived from A/D/H | Improve order accuracy and speed for that restaurant | No | No |
| Sensitive PI (§ 1798.140(ae)) | See Section 4 | No | No |
Retention: We retain personal information for as long as needed to provide the service and for our legitimate business purposes. Rather than deleting order and call data, we de-identify it after it is no longer needed in identifiable form (see Section 9), so that historical records can be kept for analytics and service improvement without identifying any individual.
4. Sensitive personal information
Under the CPRA, “sensitive personal information” (§ 1798.140(ae)) includes precise geolocation, government IDs, financial account details, race/ethnicity, health, sex life/orientation, and the contents of certain communications.
- We do not intentionally collect sensitive PI as part of normal order-taking. We do not collect Social Security numbers, driver's-license numbers, precise geolocation, or account passwords from callers.
- Call content: the contents of a phone call can, in principle, include sensitive information if a caller volunteers it (for example, mentioning a health-related dietary restriction). We do not solicit this, do not use it to infer characteristics about the caller, and use call content only to take and fulfill the order and to operate/improve the service.
- Payment card data: the Cortex AI agent does not take, request, or read back credit-card numbers over the phone. When payment is required, the caller is sent a secure payment link and pays on a payment processor's or point-of-sale provider's own hosted page. Card details are handled entirely by that PCI-DSS-compliant processor and are never spoken to, transcribed by, recorded by, or stored by Cortex.
Because we do not use or disclose sensitive PI for purposes beyond those permitted by § 1798.121(a) (i.e. only as necessary to perform the service), we are not required to offer a “Limit the Use of My Sensitive Personal Information” link — but you may still contact us to ask how any incidentally-collected sensitive information is handled.
5. Why we use personal information (purposes)
We use personal information for the following business purposes. Where we act as a service provider to a restaurant, we do so only on that restaurant's documented instructions.
- Answering calls and taking orders — recognizing the caller, understanding the order, quoting menu prices, and delivering the order to the restaurant.
- Call recording and transcription — recording each call and generating a transcript so the order is accurate and can be reviewed (see Section 6, Call Recording).
- Providing and operating the service — running the AI agent, the dashboard, and order history for each restaurant.
- Quality assurance and improving the AI agent — reviewing calls and transcripts to debug errors, measure accuracy, and improve the speech and language models used to serve our customers. We do not use call recordings to build general-purpose commercial AI products for third parties.
- Security, fraud prevention, and abuse detection — protecting the service, detecting telecom fraud and unlawful use.
- Account administration and billing — managing restaurant accounts and billing the restaurant.
- Support and communications — responding to requests and sending service-related messages.
- Legal compliance — complying with law, responding to lawful requests, and enforcing our terms.
We will not use personal information for a materially different, incompatible purpose without providing notice.
6. Call recording — dedicated disclosure
This section describes the single most important data practice at Cortex. Please read it.
What we record
When a person calls a restaurant served by Cortex, the call is recorded. Call audio is an enumerated category of “personal information” under the CCPA/CPRA (Cal. Civ. Code § 1798.140(v)(1)(H) — “audio, electronic, visual… information”), which is why we describe this practice in writing here rather than relying only on the spoken announcement. We capture:
- The audio of the call — both the caller's side and the AI agent's side.
- A transcript of the call, generated by automated speech-to-text.
- Call metadata — the phone numbers involved, the date and time, and the call duration.
- The order and any personal details spoken on the call — typically the caller's name, phone number, and the items ordered.
How the recording is disclosed and consent
At the start of every call, the caller hears a verbal announcement that the call is being recorded and that they are speaking with an AI assistant. Continuing with the call after this announcement indicates consent to the recording. This all-party-disclosure practice is designed to satisfy the “all-party consent” recording laws of states including California, Delaware (civil), Florida, Illinois, Maryland, Massachusetts, Montana, New Hampshire, Pennsylvania, Washington, and Connecticut (civil), as well as the federal one-party standard (18 U.S.C. § 2511). A verbal announcement on the call does not replace this written policy; this section is the written disclosure of the practice.
If a caller does not consent to being recorded, they may hang up and place their order by another method offered by the restaurant (for example, by calling back and speaking to a staff member directly, or ordering in person).
Why we record
We record calls to (a) take the order accurately, (b) create an order record the restaurant can rely on and reference for disputes, (c) provide quality assurance, and (d) debug and improve the accuracy of the AI agent for that restaurant. Recording is integral to the service — it is how the order gets taken and verified.
AI, transcription, and automated processing
The call audio is processed by automated speech-to-text (transcription) and by a large language model that conducts the conversation and assembles the order. This is automated processing. It is order-taking assistance, not a decision that produces legal or similarly significant effects about the caller; a human at the restaurant remains responsible for fulfilling (or declining) any order. See Section 12 on automated decision-making. We do not use call audio to create voiceprints or for biometric identification.
Who has access to recordings
Access to call recordings and transcripts is limited to:
- The restaurant that received the call (through its dashboard / order records);
- Authorized Cortex personnel who need access to operate, support, debug, or improve the service, under confidentiality obligations; and
- Subprocessors strictly necessary to deliver the service (for example, our telephony and speech-processing providers — see Section 8), under contract.
We do not sell recordings or transcripts, and we do not share them for advertising.
How long we keep recordings
Call recordings and transcripts are retained in identifiable form for as long as reasonably needed to take and verify orders, resolve disputes, provide the service to the restaurant, and improve the AI agent. We do not routinely delete this data; instead, once it is no longer needed in identifiable form, we de-identify it (stripping the caller's name, phone number, and other direct identifiers) so that it can be retained for analytics and model-improvement purposes without identifying any individual. See Section 9.
7. Cookies and website analytics
On our website and dashboard we use cookies and similar technologies for essential functionality (keeping you logged in) and security. We do not use advertising or cross-site tracking cookies, and we do not sell or share personal information for advertising. We currently honor browser-level opt-out preference signals such as Global Privacy Control (GPC) where applicable. If we introduce advertising or third-party tracking technologies in the future, we will update this policy and honor applicable opt-out requirements.
8. Disclosure of personal information — subprocessors and our service-provider role
We do not sell or “share” personal information
We do not sell personal information for money or other valuable consideration, and we do not “share” it for cross-context behavioral advertising, as those terms are defined in § 1798.140(ad), (ah). We have not done so in the preceding 12 months.
Categories of third parties who may receive personal information
We disclose personal information only to service providers/processors who help us deliver the service, under written contracts that prohibit them from using it for their own purposes:
| Recipient type | Purpose | Example categories disclosed |
|---|---|---|
| Telephony / call-carrier provider | Connecting and recording calls | Identifiers, audio, call metadata |
| Speech-to-text and AI/LLM providers | Transcription and conducting the conversation | Audio, transcript content |
| Cloud hosting / infrastructure | Running and storing the service | All categories, as processed |
| Analytics / error-monitoring | Operating and improving the product | Network activity, limited identifiers |
| Payment processor (restaurant billing) | Billing our restaurant customers | Business contact, commercial info |
| Professional advisors, legal, auditors | Compliance and diligence | As strictly necessary |
Our current subprocessors include: Telnyx (telephony and call recording), OpenAI and Microsoft Azure OpenAI (speech-to-text and language-model processing), Vercel (website and dashboard hosting), Neon (database hosting), Auth0/Okta (authentication), and Resend (transactional email). We maintain a current list and will provide it on request; enterprise customers receive the list as part of their agreement.
We may also disclose personal information: (a) to comply with law or a lawful request; (b) to protect the rights, safety, or property of Cortex, our customers, or others; and (c) in connection with a merger, acquisition, or sale of assets, subject to this policy.
Our role as a service provider to restaurants
For end-caller personal information collected on calls, Cortex acts as a service provider (CCPA) / processor (GDPR) to the restaurant. This means:
- We process caller information only to provide the service to the restaurant and for the limited, enumerated purposes above, and not for our own independent commercial purposes.
- We do not sell or share caller information, and we do not combine it across restaurants to build independent profiles.
- We support each restaurant in responding to caller rights requests (access, deletion, correction) and in meeting its own obligations, including via a Data Processing Addendum (DPA) that forms part of our customer agreement (see the Terms of Service).
- If you are a caller and want to exercise rights about a call you made, contact the restaurant you called first; you may also contact us at the address in Section 15 and we will route or support the request.
9. How long we keep information (retention)
Our approach is to retain data but de-identify it rather than routinely deleting it. We keep personal information in identifiable form only for as long as reasonably necessary for the purposes described above; once it is no longer needed in identifiable form, we strip direct identifiers (such as the caller's name and phone number) so the remaining data is de-identified and can be retained for analytics, reporting, and improving the AI agent. De-identified data is maintained without re-identifying it and is not treated as personal information.
| Data | Retention approach | Notes |
|---|---|---|
| Raw call audio recordings | Retained while needed to take/verify orders and improve the service; de-identified when no longer needed in identifiable form | Contains voice; treated as the most sensitive category |
| Call transcripts | Same as above; direct identifiers removed on de-identification | |
| Order records (name, phone, items) | Retained for order history and service; de-identified once no longer needed to identify the caller | Restaurants rely on order history |
| Restaurant account data | Retained for the life of the account; de-identified or removed after the account is closed, subject to legal/backup retention | |
| Website / demo-request leads | Retained while a business relationship is reasonably possible, then de-identified or removed | |
| Security / access logs | Retained as needed for security and then rotated | |
| Billing records | Retained as required by tax and accounting law (typically up to 7 years) | Legal obligation |
You may still request deletion of your personal information (Section 11); where we can, we will delete rather than de-identify on request, subject to legal exceptions.
Where we act as a service provider, retention of caller data is also governed by the restaurant's instructions in the DPA, and we will delete or return it on the restaurant's instruction or on termination, subject to legal retention requirements.
10. How we protect information
We use administrative, technical, and organizational safeguards appropriate to the sensitivity of the data. These include: encryption of data in transit (TLS) and at rest (AES-256) provided by our infrastructure providers; access controls that limit who can reach call recordings and account data; per-account scoping so each restaurant can access only its own data; authenticated access to the dashboard; and rate limiting and monitoring on our systems. We do not currently hold a SOC 2 or ISO 27001 certification; we describe only the controls that are actually in place. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
11. Your California privacy rights (CCPA / CPRA)
If you are a California resident, you have the following rights. We do not discriminate or retaliate against you for exercising them (§ 1798.125): we will not deny service, charge different prices, or provide a different quality of service because you exercised a right.
- Right to know / access (§ 1798.110) — request the categories and specific pieces of personal information we have collected about you, the sources, the purposes, and the categories of third parties to whom we disclosed it, over the preceding 12 months.
- Right to delete (§ 1798.105) — request deletion of personal information we collected from you, subject to legal exceptions.
- Right to correct (§ 1798.106) — request correction of inaccurate personal information.
- Right to opt out of sale/sharing (§ 1798.120) — we do not sell or share personal information, so there is nothing to opt out of; however, we honor opt-out preference signals such as Global Privacy Control (GPC) as a browser-level opt-out where applicable.
- Right to limit use of sensitive personal information (§ 1798.121) — we do not use sensitive PI beyond permitted purposes, so no separate limit link is required (see Section 4).
- Right to non-discrimination / no retaliation (§ 1798.125).
How to exercise your rights
- Email: office@cor-tex.solutions (our primary channel for privacy requests).
- Online: you may also submit a request through the contact form linked from our website footer at cor-tex.solutions.
Verification. To protect your information, we will verify your identity before fulfilling a request to know, delete, or correct — typically by confirming information we already hold (such as matching the phone number used on a call, or verifying control of the account email). For call-related data we may ask you to confirm the phone number and approximate date/time of the call. We will not use information collected for verification for any other purpose.
Authorized agents. You may use an authorized agent to submit a request. We may require the agent to provide proof of authorization and may separately verify your identity.
Response time. We will confirm receipt within 10 business days and respond within 45 days. If we need more time, we may extend once by an additional 45 days and will tell you why.
Minors. We do not knowingly sell or share the personal information of consumers under 16 (and do not sell/share at all). Our service is directed at businesses, not children.
12. Your rights under the GDPR / UK GDPR (EEA, UK, and Switzerland)
This section applies if and to the extent we collect personal data of individuals in the EEA, UK, or Switzerland (for example, an EU-based website visitor or an EU restaurant customer). Where we act as a processor for a restaurant, the restaurant is the controller and its notice governs; this section describes our own controller-role processing (our customers and site visitors).
Controller: Cortex Voice Inc., a Delaware corporation (mailing address available on request via office@cor-tex.solutions). EU/UK representative (Art. 27): not currently appointed; we will designate one if and when our processing of EU/UK personal data becomes regular and within the scope of Art. 3(2). Data protection contact: office@cor-tex.solutions.
Legal bases (Art. 6)
| Processing | Legal basis |
|---|---|
| Providing the service to a restaurant customer; account administration; billing | Contract (Art. 6(1)(b)) |
| Recording and processing calls to take orders (our processor role) | Controller (restaurant) provides the basis; we act on documented instructions (Art. 28) |
| Security, fraud prevention, product improvement, B2B marketing to prospects | Legitimate interests (Art. 6(1)(f)) — our interest in operating, securing, and improving the service and growing our business, balanced against your rights |
| Non-essential cookies/analytics (where used) | Consent (Art. 6(1)(a)) where required |
| Compliance with legal obligations | Legal obligation (Art. 6(1)(c)) |
Where we rely on legitimate interests, you may object (see below); we have balanced our interests against your rights and freedoms.
Your data-subject rights (Arts. 15–22)
Access; rectification; erasure (“right to be forgotten”); restriction of processing; data portability; objection (including to processing based on legitimate interests and to direct marketing); the right to withdraw consent at any time (without affecting prior processing); and the right to not be subject to solely automated decisions with legal or similarly significant effects (Art. 22). To exercise any of these, contact us (Section 15). You also have the right to lodge a complaint with your local supervisory authority (or the UK ICO).
International transfers
If we transfer personal data out of the EEA/UK, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses (and the UK Addendum), or an adequacy decision. Our primary hosting and processing takes place in the United States, and our subprocessors that handle personal data provide Standard Contractual Clauses or equivalent safeguards under their data processing agreements.
Retention
We retain personal data only as long as necessary for the purposes described, per the criteria and periods in Section 9.
Automated decision-making
The AI agent's order-taking is automated processing but does not produce legal or similarly significant effects on the caller within the meaning of Art. 22; order fulfillment decisions rest with the restaurant. We do not carry out profiling that produces such effects.
Whether provision is required
Providing your name and phone number is necessary to place an order through the AI agent; without it the order cannot be taken. Providing account information is necessary to enter into and perform our customer contract.
13. Children's privacy
Cortex is a business service and is not directed to children under 16. We do not knowingly collect personal information from children. If you believe a child's information has been collected, contact us and we will delete it.
14. Changes to this policy
We may update this policy. When we do, we will change the “Last updated” date at the top and, for material changes, provide additional notice. We review this policy at least every 12 months, as the CCPA requires for the enumerated categories.
15. Contact us
Questions, requests, or complaints about privacy:
- Email: office@cor-tex.solutions
- Mail: Cortex Voice Inc. (mailing address available on request)
For requests about a call you placed to a restaurant, please contact that restaurant first; we will support them in responding.
Not legal advice — independent review advisable. This Privacy Policy was prepared as a thorough, good-faith draft grounded in the CCPA/CPRA (Cal. Civ. Code § 1798.100 et seq. and its implementing regulations at 11 CCR §§ 7001–7304), the GDPR/UK GDPR, and applicable call-recording statutes. It is not legal advice and does not create an attorney-client relationship. Privacy law is fact-specific and changes frequently. Before relying on this policy at scale, have it reviewed by a qualified privacy attorney licensed in the relevant jurisdictions, and verify that the described practices (recording, de-identification and retention, security controls, and subprocessors) continue to match what the company actually does as the product evolves.