Last Updated: 16 June 2026
CallSara, Inc. (“CallSara,” “we,” “us,” or “our”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and protect your personal data when you interact with our website (www.callsara.ai) and our services.
CallSara, Inc. is an AI-powered healthcare technology company. Our brand name “CallSara” is a registered trademark of CallSara, Inc. and has no connection to any pharmaceutical product, dietary supplement, herbal remedy, or any product regulated by the U.S. Food and Drug Administration (FDA) or Drug Enforcement Administration (DEA). CallSara does not manufacture, sell, dispense, distribute, or promote any drug, supplement, or regulated health product of any kind.
This Privacy Policy applies only to information collected through our website (www.callsara.ai).
It does not apply to patient data or information processed through CallSara’s services on behalf of healthcare providers. Such data is governed by separate Business Associate Agreements (BAAs) and applicable healthcare regulations, including HIPAA. If you are a patient of a healthcare organisation that uses CallSara, please contact that organisation directly regarding your health information.
CallSara is a software and communications platform for healthcare organisations. We are not a pharmacy, telehealth provider, or drug manufacturer.
We do not sell, dispense, fulfil, or promote prescription drugs, over-the-counter medications, dietary supplements, herbal products, vitamins, controlled substances, or any product on the LegitScript Unapproved Pharmaceuticals and Supplements list.
We do not provide medical advice, diagnosis, or treatment.
Protected Health Information (PHI) processed on behalf of healthcare provider Customers is governed exclusively by the relevant BAA, not this Privacy Policy.
When you interact with our website or services (e.g., demo requests, contact forms), we may collect:
You may choose to browse parts of our website without providing personal data. We do not collect sensitive health or medical information through our website forms.
When you visit our website, we may automatically collect:
We use cookies and similar technologies to:
We use the following third-party tracking technologies on our website:
We operate Google Consent Mode v2. This means that in regions where prior opt-in consent is required for non-essential cookies (including the EU and UK), no analytics or advertising cookies are placed until you provide consent via our cookie banner. If you click “Deny,” only strictly necessary cookies are set and no data is sent to advertising platforms.
You can manage or withdraw your cookie preferences at any time via the Cookie Settings link in our site footer. Some website features may not function correctly if you disable all cookies.
We may receive information about you from:
When CallSara’s voice AI platform handles calls on behalf of a healthcare provider Customer, we process call audio, transcripts, caller phone numbers, and call metadata (timestamps, duration, routing events) as a data processor acting on the Customer’s instructions. Where this data relates to an identified or identifiable patient, it constitutes PHI and is governed by the relevant BAA, not this Privacy Policy.
CallSara does not use Customer call audio, transcripts, or PHI to train general-purpose AI models without the explicit, separate written consent of the Customer.
Customers are solely responsible for obtaining all legally required consents from callers before using CallSara’s platform to record calls, place automated outbound calls, or conduct any telemarketing or patient recall activity. Applicable laws include the U.S. Telephone Consumer Protection Act (TCPA), state call-recording laws (including all-party consent requirements), and equivalent laws in other jurisdictions.
We use personal data for the following purposes:
Contract, to perform services you have signed up for.
Legitimate interests, to respond to enquiries, improve our product, and run our business.
Consent, for marketing emails and non-essential cookies. You can withdraw consent at any time without affecting prior processing.
Legal obligation, where law requires us to process data.
We do not sell personal data
We may share your data with:
All third-party service providers are required to maintain appropriate confidentiality and security measures. A list of key sub-processors is maintained at callsara.ai/legal/sub-processors and is updated when we add or change providers.
CallSara markets its Services through third-party advertising platforms including Google Ads, which have their own content and trademark policies. CallSara may remove or modify any Customer-supplied content (including testimonials, case studies, and co-marketing materials) published on our website if, in CallSara’s reasonable judgment, that content creates a risk of disapproval or restriction under any applicable advertising platform policy. This may include removing references to Customer brand names that coincidentally match terms flagged by automated advertising policy systems. Such removal is not a breach by CallSara and will be carried out in good faith.
Our website and supporting systems are primarily hosted in the United States. In some cases, personal data may be processed in other jurisdictions where our service providers operate.
For transfers from the European Economic Area (EEA) or the United Kingdom to the United States or other third countries, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission or the UK Information Commissioner’s Office to provide appropriate safeguards.
For data of residents of India, we process data in accordance with the Digital Personal Data Protection Act, 2023 (DPDP Act) and will update our practices as implementing regulations are issued.
We implement appropriate technical and organisational measures to protect personal data from unauthorised access, disclosure, alteration, or misuse. These include encryption of data in transit (TLS 1.2+) and at rest, role-based access controls, multi-factor authentication for internal systems, regular security assessments and penetration testing, and incident response procedures.
CallSara maintains SOC 2 Type II certification. Contact founders@callsara.ai to request a copy of our report under NDA.
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify affected individuals and relevant authorities within the timeframes required by applicable law (72 hours for GDPR; without unreasonable delay under U.S. state breach notification laws).
We retain personal data only as long as necessary to:
We may use third-party advertising services to deliver relevant ads and measure campaign performance. Technologies we use include Google Analytics 4, Google Ads conversion tracking, and Google Tag Manager. We may also use LinkedIn Insight Tag and similar tools.
Because our advertising platforms (including Google Ads) have automated content-scanning systems that review the pages our ads point to, we ensure that our website content, including all product descriptions, customer testimonials, and case studies, accurately represents CallSara’s software and communications services and contains no references to pharmaceutical products, dietary supplements, or other regulated health products.
You can opt out of targeted advertising via:
You can manage your cookie preferences at any time via the Cookie Settings link in our site footer.
Depending on your location, you may have the right to:
To exercise any of these rights, contact us at:
founders@callsara.aiWe may need to verify your identity before fulfilling your request. We will respond within the timeframe required by applicable law (generally 30-45 days, with possible extension for complex requests).
Residents of certain U.S. states have additional rights under their state’s privacy laws. These currently include California, Colorado, Connecticut, Delaware, Iowa, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Tennessee, Texas, Utah, and Virginia, among others. Healthcare data is classified as sensitive personal information in most of these states.
These additional rights may include:
Requests can be submitted by email to founders@callsara.ai. California residents may also contact the California Privacy Protection Agency or the California Attorney General’s office for assistance.
Our website and Services are intended for business users, specifically personnel of healthcare organisations, and are not directed at individuals under the age of 13. We do not knowingly collect personal data from children under 13. If you believe a child under 13 has provided personal data through our website, please contact founders@callsara.ai and we will take steps to delete that data promptly.
Our website may contain links to third-party websites, integrations, or resources. This Privacy Policy applies only to www.callsara.ai and our Services. We are not responsible for the privacy practices or content of any third-party sites and encourage you to review their privacy policies before sharing personal data.
We may update this Privacy Policy periodically to reflect changes in our practices, legal requirements, or the Services. Changes will be posted on this page with an updated date.
For material changes, particularly those that affect how we use data you have already provided, we will notify you by email (if we have your address) or by a prominent notice on our website at least 14 days before the change takes effect. Your continued use of our website after the effective date constitutes acceptance of the updated Policy.
If you have any questions, concerns, or requests relating to this Privacy Policy or our data practices, please reach out to us:
© 2026 CallSara, Inc. All rights reserved.
callsara.ai/privacy-policy
115 Broadway Street
New York, NY 10006
CallSara is a healthcare communication and workflow automation platform for healthcare organizations. CallSara does not provide medical advice, diagnosis, treatment, telehealth services, pharmacy services, prescription drug sales, prescription fulfillment, or medication dispensing. Any medication-related workflow is limited to request capture, routing, and handoff to the healthcare provider’s authorized staff.