Legal

Privacy Policy

Effective

This policy explains how personal information is handled when you use Malka communications and accessibility services.

Who and what this policy covers

This Privacy Policy explains how Malka Communications Group, Inc. (“Malka,” “we,” “us,” or “our”) handles personal information when people use MalkaVRS, MalkaVRI, Malka Terp, MapleVRI where Malka operates the service, Malka Relay, IP captioned telephone service, Malka Jobs, and related websites, mobile applications, communications, and support services (collectively, the “Services”).

Some Services are provided for a business, government agency, health care or education organization, or certified telecommunications partner. In those cases, that organization may decide why and how information is handled. Its privacy notice, contract, or instructions may also apply. Contact your account sponsor if you are unsure which organization manages your account.

Information we collect

  • Account and profile information: name, email address, phone number or service handle where enabled, role, organization, languages, service modes, account status, authentication and security events, and preferences.
  • Contacts and scheduling information: contacts you save or import, contact groups, blocked contacts, availability, scheduled sessions, invite details, calendar connection status, and team or billing profile selections. If you import contacts from Google, we read the names, email addresses, phone numbers, and organizations in your Google contacts to find people you know on the Services.
  • Connected calendar information (optional): if you connect Google Calendar or Microsoft Outlook, the access we are granted and the account address it belongs to, and the calendar events described in Connected calendars, notifications, and text messages.
  • Notification and text-message information: push-notification tokens for devices where you allow notifications, your notification choices, and, if you opt in to text alerts, the verified mobile number, when you agreed, delivery status, and replies such as STOP or HELP.
  • Call, queue, and service records: request and queue timestamps, interpreter or captioner assignment, room and session identifiers, call type, the phone numbers called and calling, call duration, connection and hangup events, call-detail records, and operational lifecycle logs. These records describe the service event; they are not recordings of the conversation.
  • In-call chat: text messages sent in a call’s chat, with who sent them and when. See Chat, captions, and call observation.
  • Captions: live caption text while captioning is active, the caption text of Malka Relay phone calls, lines of public caption events, caption-session metadata, consent records, and delivery status. See Chat, captions, and call observation.
  • VideoMail and voicemail: a message you intentionally record, message metadata, thumbnails, delivery and read status, and the information needed to store and play the message.
  • IP captioned telephone service (IP CTS) registration: full name, date of birth, address, phone number, the last four digits of your Social Security number, your self-certification that you have a hearing loss that requires captions, your electronic signature, and your consent to registration in the FCC’s TRS User Registration Database. The hearing-loss certification is health information.
  • Interpreter and provider information: see Interpreters and other service providers.
  • Billing and business information: customer organization, billing contact, rate, invoice, payment and reconciliation status, and provider payment or payable records. Payment processors handle payment-card details; Malka does not store full payment-card numbers in the application database.
  • Optional attendance location: when an interpreter chooses to attach it, precise current location is stored with a job check-in or check-out, assignment identifier, and timestamp. Declining location does not prevent attendance submission.
  • Other location information: addresses for jobs and appointments, an interpreter’s travel starting point, and, when you tap “use my location” in an address field, your device’s current location, which is sent to our address-lookup provider to find the nearest address.
  • Device and diagnostic information: device and app version, browser type, IP address, request or session identifiers, connectivity and media state, security events, crash or diagnostic information when enabled, and locally cached app data.
  • Support and audit information: support requests, administrative actions, exports, account changes, moderation activity, and security or incident evidence needed to investigate a reported problem.
Calls are not recorded by default. VideoMail is a separate, user-initiated recording feature. We will not enable call recording without an approved notice and consent flow, secure storage, a defined retention period, and required legal and partner approval.

How we use information

We use personal information to:

  • provide, schedule, route, and operate the Services;
  • authenticate users, administer accounts, and prevent fraud or misuse;
  • connect clients with interpreters, captioners, invited guests, and approved service providers;
  • deliver VideoMail, service invitations, account notices, and requested communications;
  • remind you when a meeting on a connected calendar is starting, so you can ask for an interpreter (a reminder never reserves an interpreter);
  • produce captions, and, where enabled, label the tone of voices and caption text on Relay calls and flag possible emergencies or spam;
  • look up addresses and plan interpreter travel;
  • measure service quality, including live quality observation of interpreted calls, troubleshoot failures, support users, and maintain security and reliability;
  • calculate usage, create invoices and provider payables, reconcile payments, and maintain required business and audit records;
  • verify an interpreter’s optional location-assisted attendance record;
  • register IP CTS users as FCC rules require;
  • comply with applicable law, contracts, legal process, accessibility service requirements, and certified-partner obligations; and
  • improve the Services using operational and diagnostic information limited to what is reasonably needed for that purpose.

We do not sell personal information. We do not use call audio, video, captions, transcripts, chat, or VideoMail content for advertising, and we do not use them to train AI models. Some providers that process this content for us may use it to improve their own services under their terms, as described in Automated analysis and AI. A materially different use by Malka would require a separate approved policy and, where required, explicit consent.

Chat, captions, and call observation

  • In-call chat: chat messages are stored encrypted while the call is in progress. When the call ends, the chat is deleted, unless you turned on “Keep chat logs” in Settings. Then it stays, encrypted, in your call history until you delete it. If another person in the call kept the chat, their copy stays until they delete it. If you ask us to email a chat log, or turn on automatic chat-log email, we send the messages to the address you choose through our email provider; a copy in a mailbox is outside our control.
  • Relay captions: the caption text of a Malka Relay phone call is stored encrypted during the call and deleted when the call ends, unless you turned on “Keep future transcripts”. Then it is kept until you ask Support to delete it. The option is unavailable for customers in regulated industries such as health care, education, legal, and government.
  • Public caption events: the lines of a public caption event can be read by anyone who has the event’s code, without signing in. The latest lines are kept while the event is open and deleted about a day after it ends. The event’s name and organizer are kept as a service record.
  • Other live captions: captions shown during a video call are delivered live and are not stored on our servers. Regulated customer categories disable local transcript history and export.
  • Call observation: for quality and training, an authorized manager may watch and listen to an interpreted call live. The interpreter and the Malka users in the call are told when a manager is observing; a person on a telephone line is not. Observation is not recorded; we keep a record of who observed which call, when, and why.

Interpreters and other service providers

  • Onboarding: legal name, date of birth, address, phone number, Social Security number or ITIN, tax classification, bank name, account holder, routing and account numbers, identity and certification documents, and signed agreements. Tax identification and bank account numbers are stored encrypted; tax and deposit forms we generate show only their last four digits. Agreement signatures record the typed or drawn signature, the time, a one-way hash of the IP address, and the browser used.
  • Payouts: to pay interpreters, we share their name and email address with our payment processor, which collects any further details it needs.
  • Jobs: job offers, responses, and text-message replies; check-in and check-out times; the name of the on-site person who confirms attendance; ratings and comments about completed jobs; and the optional attendance location described above.

Connected calendars, notifications, and text messages

Connecting a calendar is optional. You connect Google Calendar or Microsoft Outlook through that provider’s own sign-in, which shows the access you are granting. You can use a connected calendar in two ways:

  • Meeting reminders: while reminders are on, we read the events on your calendar for the coming day, including their title, time, location, description, and video-meeting details. We do this only to find a Zoom, Google Meet, Microsoft Teams, or Webex link. For each meeting with such a link, we keep its title, start and end time, platform, and link, and the link is encrypted. We do not keep event descriptions, attendee lists, or events without a meeting link.
  • Session sync: for VRI sessions you schedule with us, we create, update, or remove the matching event on your calendar, including any invitations you set up for the session.

We use calendar information only for these features. We do not sell it, use it for advertising, or use it to train AI models. We share it only with service providers who help us run these features, or when required for security or by law. Our staff do not read it unless you ask us to, or for security or legal reasons. Malka’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Notifications: a meeting reminder can reach your phone as a push notification through Apple or Google. It says only which platform the meeting is on and when it starts, not the meeting’s title or link. Incoming-call notifications show the caller’s name.

Text messages: call alerts and meeting-reminder texts are optional. You turn each on in Settings, and each needs a verified mobile number. Meeting-reminder texts are at most one per calendar meeting and do not include the meeting’s title or link. Interpreters who use Malka Jobs may also receive job offers and updates by text. Message and data rates may apply. Reply HELP for help. Reply STOP to any text to stop all texts from us. We do not share mobile numbers or text-message consent with third parties or affiliates for their marketing or promotional purposes.

Automated analysis and AI

  • Speech recognition: our speech-recognition provider (Deepgram) turns call audio into captions. Under its own terms, it may use audio it processes to improve its models.
  • Tone and safety labels: where enabled, Relay caption text is sent to an analysis provider (TypeSafe) to label tone and flag possible emergencies or spam. Our own software may also score the tone of voices on Relay calls. These labels are kept with the call’s service records.
  • Jobs: where enabled, job requests and interpreters’ text replies are sent to an analysis provider (TypeSafe) to understand and route them.
  • Business tools: an AI provider (xAI) drafts internal account summaries from our staff’s notes about business customers. Summaries are not made for customers in regulated industries.
  • Accessibility tools on customer websites: when a visitor uses them, an AI provider (xAI) translates text, reads it aloud, and describes images on that website.

These analyses help deliver the Services. They do not by themselves make decisions with legal or similarly significant effects about you.

When we share information

We may share information only as needed with:

  • the organization that sponsors or administers your account;
  • interpreters, captioners, invited participants, certified partners, and other providers involved in delivering the requested service;
  • service providers acting for us, including:
    • infrastructure and storage providers that host the Services;
    • Twilio, for text messages, telephone calls, and Relay call audio;
    • Resend, for email, including chat logs you ask us to send;
    • Apple, Google, and your browser’s push service, for notifications;
    • Deepgram, for speech recognition;
    • TypeSafe and xAI, for the analysis described above;
    • Stripe, for payments and interpreter payouts;
    • Google, for connected calendars and contact import;
    • Microsoft, for connected calendars;
    • Zoom, when you connect a Zoom account;
    • Geoapify, for address lookup;
  • the FCC’s TRS User Registration Database administrator, for IP CTS registration;
  • professional advisers, auditors, insurers, and authorities when reasonably necessary to meet legal, safety, security, or compliance obligations; and
  • a successor in a merger, financing, reorganization, or sale, subject to appropriate confidentiality and notice requirements.

We require service providers to handle information for authorized purposes and under applicable contractual safeguards. Provider availability varies by tenant, service mode, and feature configuration.

Retention

We keep information only for as long as reasonably needed for service delivery, account administration, billing, security, dispute resolution, legal obligations, and certified-partner or customer requirements.

  • live call media is not recorded or retained;
  • in-call chat is deleted when the call ends unless you keep chat logs, and a kept chat log stays until you delete it;
  • Relay caption text is deleted when the call ends unless you choose to keep transcripts, and kept transcripts stay until you ask us to delete them;
  • public caption event lines are deleted about a day after the event ends;
  • caption-session metadata is deleted after 90 days;
  • VideoMail messages expire after one service-wide period, 30 days by default, counted from when they are recorded; greetings, and messages that were never completed, stay until deleted;
  • short-lived invite and handoff credentials expire automatically;
  • meeting reminders are deleted one day after the meeting ends, or at once when you turn reminders off or disconnect the calendar, and disconnecting also deletes our access to that calendar;
  • call, Relay, observation, IP CTS, onboarding, and job records are kept as service and business records; they are not deleted automatically;
  • call-detail, billing, payment, and audit records may be kept longer where accounting, contract, legal, or certified-partner requirements apply;
  • optional attendance location is retained with the related job attendance and audit record under the same customer, billing, and legal requirements; and
  • diagnostic data stored on a device remains until it expires, is cleared by the app, or the user removes it.

We may preserve information for an active dispute, security investigation, or legal hold. Where an organization sponsors your account, its retention instructions may control.

Your choices and requests

Depending on where you live and the organization that sponsors your account, you may be able to request access, correction, deletion, restriction, objection, or a portable copy of personal information, or withdraw consent where consent is the basis for processing.

You can manage many contact, VideoMail, caption, chat-log, notification, scheduling, and device preferences in the Services. You can delete a kept chat log from your call history. You can turn calendar reminders off or disconnect a calendar in Settings at any time, and you can also remove our access in your Google or Microsoft account settings. You can stop texts in Settings or by replying STOP to any text. Interpreters can decline location for each job check-in or check-out and still submit attendance. You may also contact Support or your account sponsor. We may need to verify your identity and may retain information where law, billing, security, certified-partner, or contract requirements do not permit deletion.

Security

We use administrative, technical, and organizational safeguards intended to protect personal information, including access controls, tenant boundaries, encrypted transport, encryption of chat, Relay caption text, tax identification and bank numbers, and calendar and Zoom credentials, scoped and expiring credentials, audit logging, and security monitoring. No system is completely secure. If you believe your account or information is at risk, contact Support promptly and do not include passwords, access tokens, or sensitive conversation content in an ordinary support message.

International processing

Malka and its service providers may process information in the United States, Canada, or another country where an approved provider operates. Privacy and data-protection rules may differ across countries. We use contractual and other safeguards where applicable.

Children

The Services are not directed to children for independent consumer use. A school, health care provider, parent, guardian, or other authorized organization may arrange an accessibility or interpreting service involving a minor. That organization is responsible for the permissions and notices required for the service it requests. Contact Support if you believe a child provided account information without appropriate authorization.

Changes to this policy

We may update this policy as the Services, providers, or legal requirements change. We will post the revised date and provide additional notice when a change materially affects how personal information is handled.

Contact us

Use the Help or Support option in the Services, or contact the organization that sponsors your account. Do not include passwords, access tokens, payment-card details, or sensitive conversation content in an ordinary support message.