Privacy Policy
Municate answers calls and messages on behalf of businesses. That work involves personal information, and we treat it with the same care we promise our clients. This policy explains what we collect, why, where it is processed, and the choices you have.
Who we are
Municate is an AI front desk for South African businesses, operated from Cape Town, South Africa. When this policy says we, us, or Municate, it means the operators of municate.co.za and the Municate service.
For anything in this policy, you can reach us at hello@municate.co.za.
What we collect
We collect information in three situations: when you use this website, when you sign up as a client, and when Municate answers conversations on behalf of a client business.
- Website: the details you submit in forms, such as your name, business name, and mobile number when you request a demo call.
- Clients: account and billing details, your business playbook, the settings you configure, and the material you add to your knowledge base so the receptionist can answer from it.
- Conversations: when Municate answers for a business, it processes what callers and customers say. Depending on the channel that means the phone number or handle in use, a recording of the call, a written transcript, a short summary written after the call, and any details shared in the conversation, such as a name, a date, or an address for a booking.
- Channels: Municate answers phone calls, WhatsApp, Facebook Messenger and Instagram messages. The same policy covers all of them.
Why we collect it
We use personal information to run the service and for nothing else: answering and routing conversations, capturing bookings, orders, tickets and messages for the business you contacted, phoning you back when you request a demo, billing our clients, and keeping the service secure.
We do not sell personal information, we do not use conversation content to advertise to callers, and we do not use it to train generative AI or machine learning models.
You are speaking to an AI
Municate is software, not a person. It answers from a playbook the business approved, and it can pass you to a human on that business's team when you ask for one or when the conversation calls for it.
After a call, the service writes a short summary of what was discussed so the business has a record it can read quickly. That summary is produced automatically. No decision with a legal effect on you is made by the service on its own.
Where your information is processed
The service runs on servers we operate in Johannesburg, South Africa. Conversation records, recordings, transcripts, summaries, knowledge base content, and the vault holding access to connected accounts all live there.
Two things necessarily leave South Africa, and we would rather say so than let you find out from a security questionnaire:
- Speech and language processing. Turning speech into text, working out what to say, turning the reply back into speech, and indexing knowledge base content are done by specialist providers outside South Africa. Fragments of audio and text are sent to them for that purpose and are not used to train their models.
- Transactional email. Our email provider operates outside South Africa, so a recipient address, a business name, and an invoice total cross the border when we send an account email. Caller identity and conversation content are never put in these emails.
Recording, and how long we keep things
Calls may be recorded. The business you are calling decides whether recording is on and is responsible for telling you at the start of the call.
Each business sets its own retention periods within limits we enforce. Unless the business changes them, the defaults are:
- Recordings: 30 days, and never longer than a year.
- Transcripts: 90 days, and never longer than two years.
- Records of actions taken during a call, such as a booking made on your behalf: 90 days, and never longer than two years.
- Call summaries: one year, and never longer than three years.
Where conversations go
When Municate answers for a business, the conversation belongs to that business relationship. Recordings, transcripts, summaries, and captured details are made available to the business you contacted, so they can serve you. We act on their instructions for that data.
Connecting your own accounts
A business using Municate can connect the tools it already runs on so the receptionist answers with real information instead of guessing. Today that covers calendars, online stores, help desks, and customer record systems.
Connecting is always a deliberate act: someone signs in to that account themselves and approves what Municate may see. Access is held by a credential vault we run in South Africa. Municate never sees or stores the password to a connected account, and a connection can be withdrawn at any time from the Integrations page or from the account provider directly. Withdrawing it stops all further access immediately.
A connected account is read and, where the business has asked for it, written to. If you book an appointment, raise a support ticket, or ask about an order, Municate may create or update the matching record in that business's own system so their team sees it.
Google user data
When a business connects a Google Calendar, Municate requests three permissions and no others: to see when that calendar is busy, to create and manage the appointments Municate itself books on it, and to read the email address of the account so we can show which calendar is connected.
We use this only to answer a caller who wants an appointment and to place the booking they agree to. Busy times are read to work out which slots to offer. An appointment is written when a caller confirms one. The connected email address is displayed in the portal so the business can see whose calendar it is.
We store the times a calendar is busy for as long as needed to offer slots during a call, and we keep a record of the appointments Municate booked so the business has its own copy. We do not read the contents, titles, attendees, or descriptions of events we did not create, and we do not use Google user data to build advertising profiles, to train generative AI or machine-learning models, or for any purpose beyond providing the features described here.
Google user data is never sold. It is never shared with third parties except where it is required to deliver the feature the business asked for, or where the law requires it. Municate's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
A business can disconnect its calendar at any time, which revokes our access and stops any further reading or writing. Anyone may also remove access directly at myaccount.google.com under third-party connections.
Checking who is calling
When a caller wants to change something that already exists, such as moving an appointment, Municate has to be reasonably sure it is talking to the right person. It may ask for a reference code it gave out earlier, or for a detail already on the record, such as a date of birth.
We never store a South African ID number, in any form. The most that is ever kept is an irreversible one-way value derived from the last four digits, held separately for each business, which can be used to check an answer and cannot be turned back into an ID number. Caller display is treated as a hint and never as proof, because a number can be faked.
Being verified lasts for ten minutes, applies only to the record it was granted for, and ends with the call.
The chat window on a business website
When a business places the Municate chat window on its own site, the window is loaded from us and works only on the web addresses that business has listed. What you type there reaches Municate the same way a call does, and is covered by this policy. The pages you browse on that site are not visible to us.
Text messages
If you reply STOP to a text message from a business using Municate, we record that and no further messages are sent to that number by that business.
Who else is involved
We keep the list of outside providers short and use them only to run the service. They fall into five groups: the speech and language providers described above, our payment gateway, our transactional email provider, the credential vault that holds access to connected accounts, and the telecommunications carrier that carries calls.
Card details are handled by our payment gateway and never reach Municate. Where a client agrees to automatic renewal, the gateway holds the payment mandate and gives us only a reference we can charge against.
When our team needs to look
To support a client, a Municate administrator can enter that client's workspace and see what their team sees. Every such session is recorded against the real person who opened it, along with the changes made during it, and it names a workspace rather than impersonating a named employee. We use this to fix problems, not to browse.
How we protect it
Conversations are encrypted in transit. Each business's data is separated inside the database so one client cannot read another's, and that separation is enforced by the database itself rather than by application code alone. Access to connected accounts sits in a vault rather than in our tables, and changes that matter are written to an audit record.
No system is perfectly secure, but we design for the assumption that this data matters.
Your rights
You may ask what personal information we hold about you, ask us to correct it, or ask us to delete it. If Municate took a message from you on behalf of a business, we may refer parts of your request to that business, since they hold the customer relationship.
Two things about deletion, stated plainly. If you have asked not to be contacted, we keep a scrambled record of that request so the instruction survives the deletion of everything else, otherwise deleting your details would be an invitation to call you again. And where a call summary has fed a business's historical totals, the personal details in it are removed rather than the whole record, so those totals are not silently rewritten.
To exercise any of these rights, email hello@municate.co.za. We respond to every request.
Changes to this policy
If we change this policy in a way that matters, we will update this page and the date at the top. Continued use of the site or service after a change means the updated policy applies.