Orca

Privacy policy

Last updated October 2026. We only collect what we need to run your AI receptionist, we never sell it, and you can ask us what we hold or ask us to delete it.

Who we are

This site and the Orca product are operated by HankinCore Pty Ltd (HankinCore), ABN 26 259 814 462, based on the Gold Coast, Queensland, Australia. You can reach us on 07 5636 5055 or at contact@hankincore.com.

What we collect

  • Call recordings — voicemail audio left by your callers, stored so you can listen back.
  • Call transcripts and AI summaries — a written record of each call, generated by machine, sent to you as the message.
  • Caller phone numbers and call metadata — times, dates, durations, and whether each call was answered or missed.
  • Your account and staff details — names, numbers and emails of you and your team, used to run your service and notify you.
  • Calendar booking data — jobs your AI books into your diary, so callers get a real time slot.
  • Business details you give us — services, prices, service areas and booking preferences, used to train your AI.
  • Basic technical logs needed to keep the service running and secure.

Calls are answered by AI

Orca is an AI receptionist. Every call it answers is handled by software, not a person. Transcripts and summaries are machine-generated and can contain errors — always check anything that matters before acting on it. If you use Orca, you are responsible for telling your callers that their calls are answered by AI and may be recorded and transcribed.

Who handles your data

We use a small number of trusted providers to run the service. Some of them process data outside Australia:

  • UploadThing (Singapore) — stores voicemail audio at rest.
  • xAI (United States) — processes call audio live so your AI can speak and listen, and generates summaries. Call audio is processed in real time and is not stored by us on xAI's systems.
  • Telnyx (carrier) — connects your calls. Call records Telnyx holds fall under carrier retention obligations, not this policy.
  • Supabase (Sydney) — our database, stored in Australia.
  • Vultr (Sydney) — the servers that run the service.

Where data goes overseas, we only deal with providers that protect it to a standard comparable to the Australian Privacy Principles. We never sell your data or your callers' data, and we never share it except where the law requires.

How long we keep it

  • Voicemail audio, transcripts and call records are kept for 3 years from the date of the call, then deleted.
  • If you cancel or ask us to delete your data, recordings and transcripts are deleted straight away. Call metadata — numbers, timestamps and durations — is kept for up to 2 years from when the call was made, in case Australian telecommunications data-retention law applies to us, and is then deleted.
  • Audit logs are kept without an expiry, but they contain no call content — only event records like what happened and when.
  • Short technical logs on our servers roll over within days and are not part of the 3-year retention.

Your rights

Under the Australian Privacy Act 1988 and the Australian Privacy Principles, you can ask for access to the personal information we hold about you, ask us to correct it, or ask us to delete it. Email contact@hankincore.com and we'll sort it. If you are not happy with how we handle your request, you can complain to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.

Security

Call audio and transcripts are only accessible through your private account area, protected by signed access links. Access to our systems is limited to people who need it to run the service, and deletions are logged in an audit trail.

Questions

Ask us anything about your data — contact@hankincore.com or 07 5636 5055.