Privacy Policy
Effective Date: April 30, 2026
Blackstar Systems ("Blackstar," "we," "us," or "our") provides an AI-assisted operations platform that processes inbound communications on behalf of businesses to execute configured workflows and integrations. This Privacy Policy describes how we collect, use, disclose, and protect information in connection with our websites, applications, and services (collectively, the "Services").
1. Scope and Data Processing Roles
Blackstar Systems operates primarily as a data processor on behalf of our business clients. Our clients (the "data controllers") determine what data is collected from their customers and how it is used. This Privacy Policy applies to:
- Business Users: Employees and operators of client businesses who use our platform
- End Callers: Individuals who interact with our clients' AI-powered phone systems
When processing end caller data, we act on behalf of and according to the instructions of our business clients.
2. Information We Collect
2.1 Business User Information
When you create an account or use our dashboard, we collect:
- Email address and authentication credentials
- Login metadata (timestamps, IP addresses, session information)
- Account configuration data and workflow settings
- Communications with our support team
2.2 Call and Communication Data
When processing inbound communications on behalf of clients, we may collect:
- Phone numbers and caller identification
- Call metadata (timestamps, duration, participants)
- Call recordings (when enabled by the client)
- Call transcripts generated through AI transcription
- Structured data extracted from conversations (intent, dates, contact information, scheduling details)
- Associated operational metadata
2.3 Integration and Operational Data
- Data exchanged with third-party services (CRMs, scheduling platforms, calendars)
- API credentials and authentication tokens (stored securely)
- Workflow execution logs and action results
- System performance data and error states
- Configuration templates and mapping rules
2.4 Automatically Collected Information
- IP addresses and device information
- Browser type and operating system
- Usage patterns and interaction logs
- Authentication events and security metadata
3. How We Use Information
We use collected information to:
- Provide, operate, and maintain the Services
- Authenticate users and secure accounts
- Process calls, transcribe communications, and extract structured data
- Execute configured workflows and business actions
- Integrate with third-party systems according to client instructions
- Log and audit operational activities
- Monitor system performance, reliability, and security
- Detect and prevent fraud, abuse, and security incidents
- Communicate service-related information
- Improve and develop our Services
- Comply with legal obligations and enforce our agreements
4. Role of AI in Our Services
We use artificial intelligence to:
- Transcribe voice communications
- Extract structured information from unstructured inputs
- Classify intent and route workflows
AI outputs are used to facilitate deterministic, configured business actions. AI does not make autonomous decisions, provide advice, or replace human judgment. All executed actions are logged and auditable.
Important Limitations: AI transcription and data extraction are not perfectly accurate. Clients remain responsible for verifying critical information and ensuring compliance with applicable laws.
5. How We Share Information
We may share information in the following circumstances:
5.1 Service Providers and Subprocessors
We engage third-party service providers to support infrastructure, including hosting, email delivery, analytics, and transcription services. These providers are contractually obligated to protect data and use it only as directed.
5.2 Client-Directed Integrations
We share data with third-party platforms (CRMs, scheduling tools, communication systems) when clients configure integrations. These integrations operate according to client instructions.
5.3 Legal Requirements
We may disclose information to comply with legal obligations, respond to lawful requests from authorities, enforce our agreements, protect our rights and property, or ensure the safety of users and the public.
5.4 Business Transactions
In connection with a merger, acquisition, reorganization, or sale of assets, user information may be transferred. We will provide notice before information becomes subject to different privacy practices.
5.5 Aggregate and De-identified Data
We may share aggregate, de-identified, or anonymized data that cannot reasonably be used to identify individuals.
5.6 Google API Services
Orbit OS integrates with Google Calendar to create appointment events on your behalf following AI-processed phone calls. When you authorize this integration:
We use the calendar.events scope to programmatically create calendar events based on scheduling information extracted from customer calls We request only the minimum permissions necessary to perform this specific function We do not access, read, modify, or delete existing calendar events beyond those created by our service Calendar access tokens are encrypted in transit and at rest and are never shared with third parties except as required to perform the calendar integration
Limited Use Disclosure: Orbit OS's use and transfer to any other app of information received from Google APIs will adhere to Google API Services User Data Policy, including the Limited Use requirements.
We do not sell personal data.
6. Data Retention
We retain information only as long as necessary to provide the Services, fulfill business and legal obligations, and resolve disputes. Retention periods vary based on:
- Data type and purpose
- Client configuration and instructions
- Legal and regulatory requirements
- Operational necessity
Clients may configure retention settings for call recordings, transcripts, and operational logs within their accounts.
7. Security
We implement reasonable technical and organizational security measures designed to protect information against unauthorized access, alteration, disclosure, or destruction. These measures include encryption, access controls, secure authentication, and regular security assessments.
However, no system is completely secure. We cannot guarantee absolute security of data transmitted to or stored within our Services.
8. Your Rights and Choices
Depending on your location and applicable law, you may have rights regarding your personal information:
- Access: Request confirmation of whether we process your data and obtain a copy
- Correction: Request correction of inaccurate or incomplete information
- Deletion: Request deletion of your information, subject to legal obligations
- Restriction: Request limitation of certain processing activities
- Objection: Object to processing based on legitimate interests
- Portability: Request transfer of your data to another service
- Withdrawal of Consent: Where processing is based on consent, withdraw consent at any time
For Business Users: Contact us at ops@blackstar.systems to exercise your rights.
For End Callers: Contact the business you interacted with. As a data processor, we process end caller data on behalf of our clients and according to their instructions.
9. Call Recording and Consent
Our Services enable clients to record phone calls. Clients are solely responsible for:
- Obtaining any required consent from callers
- Providing appropriate notice of recording
- Complying with applicable call recording laws and regulations
- Configuring systems to meet legal requirements in their jurisdictions
Call recording laws vary significantly by location. Clients must ensure compliance with all applicable federal, state, and international laws.
10. International Data Transfers
Our Services are operated from the United States. If you access the Services from outside the United States, your information may be transferred to, stored in, and processed in the United States or other jurisdictions that may have different data protection laws than your country of residence.
11. Children's Privacy
Our Services are not directed to individuals under the age of 13, and we do not knowingly collect personal information from children. If we learn that we have collected information from a child under 13, we will take steps to delete it promptly.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will post the updated policy on this page with a revised effective date. Your continued use of the Services after changes become effective constitutes acceptance of the updated policy.
For material changes, we will provide additional notice, such as via email or a prominent notification within the Services.
13. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:
Blackstar Systems
Email: ops@blackstar.systems
For data protection inquiries or to exercise your rights, please include "Privacy Request" in the subject line and provide sufficient detail to allow us to verify your identity and process your request.