1. Who we are

KalimLabs LLC (“KalimLabs”, “we”, “us”) is a Wyoming limited liability company. Our registered address is 1309 Coffeen Avenue STE 1200, Sheridan, Wyoming 82801, USA.

We build and run automated business systems for other companies — phone answering, messaging, customer relationship management (CRM) automation, lead follow-up, document review, and custom builds. Most of our clients are small and mid-sized businesses in the United States and Nigeria.

KalimLabs is run by a single operator based in Lagos, Nigeria. That matters for your data, and we explain it plainly in section 10.

You can reach us about anything on this page at support@kalimlabs.com.

2. Who this policy covers

Two different groups of people appear in our systems, and they are not the same.

  • Clients. Business owners and their staff who hire us. They sign an agreement with us and choose what we build.
  • Callers and contacts. Members of the public who ring a client’s business line and reach our answering system, or who message that business. They never signed anything with us. They are dealing with the business they called — we are the system behind the phone.

Sections 3 and 4 say what we hold for each group. Section 8 explains our role, which is different for each.

3. What we collect from clients

When a business hires us, we collect:

  • Contact and business details. Name, business name, role, email address, mobile phone number, business address, and the business phone line we are configuring.
  • What your system needs to know. Your services, prices, hours, service area, the questions you want callers asked, and where enquiries should go. You give us this, and you can change it at any time.
  • Billing information. Invoices, amounts, and payment records. Card details are handled by our payment processor. We do not see or store full card numbers.
  • Support messages. Emails and messages you send us, and our replies.

4. What we collect from callers and contacts

When someone calls a business we answer for, or messages a line we manage, our system records what is needed to handle the enquiry. That typically includes:

  • Their name.
  • Their phone number.
  • The address where they need the work done, when the job requires one.
  • What they are calling about, in their own words.
  • A recording of the call.
  • A written transcript of the call.
  • The date, time, and length of the call, and whether it was passed on.

We pass this to the business they called, so that business can serve them. We do not build profiles of callers, and we do not use their details to market anything to them.

Callers should not give sensitive information — such as card numbers, health details, or identity documents — to an automated phone line. Our systems do not ask for it. If a caller gives it anyway, it may end up in the recording or transcript, and we delete it on request (see section 13).

5. Call recording, and how we tell people

Calls are recorded and written up automatically. That is how the business gets an accurate message instead of a half-remembered note.

At the start of every call, before any conversation begins, our system plays a short notice. It says the caller is speaking to an automated assistant and that the call is recorded. The caller can hang up at that point, or ask to be put through to a person where the business has set that up.

We do this on every call, in every location. Some states require every person on a call to consent to recording, and some require telling people they are speaking to an automated system. Playing the notice up front, every time, is designed to meet those rules rather than guess at which apply. Our clients control their own phone line and the laws that apply to it — see our Terms of Service.

6. Text messages (SMS)

Mobile phone numbers collected for SMS purposes will not be shared with or sold to third parties or affiliates for marketing purposes. No mobile information will be shared with third parties for marketing or promotional purposes.

We text one group of people: the business owners who hire us, at the mobile number they give us when they sign up and agree to our SMS Terms. We do not send marketing texts, and we do not text callers unless the client has set up a follow-up message and has the caller’s consent to send it.

How many messages to expect. If you use our phone answering service, we send you one text per call we answer for you, so you know straight away who rang and what they wanted. That is typically 3–10 messages a day. Busy days are more, quiet days fewer.

Message and data rates may apply.

Reply STOP to any message to stop receiving them. You will get one confirmation, then nothing further. Reply HELP for help, or write to us at support@kalimlabs.com. Stopping the texts does not cancel your service — your call records stay in your dashboard and email.

Carriers are not liable for delayed or undelivered messages.

7. Why we use this information

We use the data above to:

  • Answer calls and messages for our clients and pass on what was said.
  • Build, configure, and fix the systems a client has hired us to run.
  • Send clients the notifications they signed up for.
  • Invoice clients and keep our accounts.
  • Keep our systems secure, and investigate misuse or abuse.
  • Meet our legal obligations.

We do not sell personal information. We do not share it for advertising. We do not use client or caller data to train our own models, and our language-model providers are under agreements that do not permit training on our data.

8. Our role: we work on the client’s instruction

For caller and contact data, the client business decides what is collected, what it is used for, and how long it is kept. In data-protection language, the client is the controller and we are the processor or service provider. We handle that data on their written instruction and for no purpose of our own.

So if you called a business and want your details removed, the fastest route is to ask that business. You can also write to us at support@kalimlabs.com and we will pass the request on, and act on it where we are able.

For client data — the account, billing, and support information in section 3 — we are the controller and this policy is our own commitment to you.

9. Who else touches the data

Running a phone and messaging system takes specialist providers. Each one only receives what it needs to do its job, and each is bound by a contract that limits what it may do with it. The providers we use today:

  • Vapi — the voice platform that runs the automated conversation.
  • Twilio — phone numbers, call delivery, and text messages.
  • Deepgram — turns speech into text.
  • Cartesia — turns text into the voice the caller hears.
  • OpenAI and Anthropic — the language models that decide what the assistant says and write the call summary.
  • Railway — hosting and databases.
  • Cloudflare R2 — storage for call recordings.
  • Resend — email delivery.
  • WhatsApp Business Platform (Meta) — WhatsApp messaging, where a client uses it.

We also share data where the law requires it — a valid court order, for example — and with professional advisers bound by confidentiality. If our business is ever sold or merged, data may transfer with it, and we would tell clients first.

This list changes as tools change. The current list always lives on this page, and we update the effective date at the top when it does.

10. Where your data is processed

Our systems and the providers above run in the United States. That is where call recordings, transcripts, and account data are stored.

KalimLabs is operated from Lagos, Nigeria. Day-to-day work — building systems, fixing faults, answering support requests — means the operator accesses that data from Nigeria. Some providers may also process data in other countries where they run infrastructure.

So personal information crosses borders: into the United States, and accessed from Nigeria. Nigeria has not been ruled “adequate” by the European Commission or the UK. Where European or UK data protection law applies to a client’s data, we rely on Standard Contractual Clauses and the UK Addendum, and we sign a data processing agreement on request. Ask us at support@kalimlabs.com.

11. How long we keep it

  • Call recordings and transcripts: 90 days, then deleted automatically. A client can contract for a shorter or longer period in writing, and some clients need longer for their own record-keeping rules.
  • Caller contact details passed to a client stay in that client’s own systems — their CRM, inbox, or dashboard — and are then governed by that business’s own retention rules, not ours.
  • Client account data is kept for the life of the contract, plus any period the law requires us to keep records, such as tax and accounting rules.
  • Invoices and payment records are kept as long as tax law requires.

See section 15 for what happens when a contract ends.

12. How we protect it

In honest terms, here is what we do:

  • Data is encrypted while travelling over the internet and while stored.
  • Access is limited to the operator, and to the providers listed in section 9 that need it to run the service.
  • Accounts we use are protected with strong, unique credentials and two-factor login.
  • Call recordings are deleted on the schedule in section 11 rather than kept forever.

We hold no security certifications. We are not SOC 2 or ISO 27001 audited, and we will not claim otherwise. No system is perfectly secure. If a breach affects your data, we will tell affected clients without undue delay and report it to regulators where the law requires.

13. Your rights over your data

Depending on where you live, you may have the right to ask us for a copy of your data, to correct it, to delete it, to limit or object to how it is used, to take it elsewhere, and not to be treated worse for asking.

  • California (CCPA/CPRA). You may ask what we collected, why, and who we shared it with, and ask us to delete or correct it. We do not sell personal information and do not share it for cross-context behavioural advertising, so there is nothing to opt out of on that front. You may use an authorised agent. We will not discriminate against you for asking.
  • Europe and the UK (GDPR / UK GDPR). Where this applies, you have the rights above and the right to complain to your data protection authority.
  • Nigeria (NDPA 2023). You have the rights above and may complain to the Nigeria Data Protection Commission.

How to ask. Email support@kalimlabs.com with what you want and enough detail to find your records — for a call, the phone number you rang from and roughly when. We may need to check who you are before we act, and we will only ask for what is needed to do that.

How long we take. We reply within 30 days. If a law that applies to you gives a different deadline — California allows 45 days, with an extension where a request is complex — we follow that one and tell you if we need the extra time.

If your request is about a call you made to a business, see section 8: that business decides, and we act on their instruction.

14. Children

Our services are sold to businesses and are not directed at children. We do not knowingly collect information from anyone under 18. If we learn that we hold a child’s information without a lawful basis, we delete it. If you believe a child’s data has reached us, write to support@kalimlabs.com.

15. Changes to this policy

When this policy changes, we update the effective date at the top of the page and post the new version here. If a change materially affects how we handle personal information, we email active clients before it takes effect.

The effective date of this version is September 17, 2026.

16. Contact us

Questions, requests, or complaints about this policy: support@kalimlabs.com.

KalimLabs LLC, 1309 Coffeen Avenue STE 1200, Sheridan, Wyoming 82801, USA.

Privacy Policy | KalimLabs