Privacy Policy
How we collect, store, use, and protect information — and where the boundaries are.
Last modified: July 29, 2026
- 1. Introduction and Acceptance
- 2. Scope
- 3. Information We Collect
- 4. Communications Data and the TALOS Platform
- 5. Recording, Transcription, and Consent
- 6. Where Data Is Processed and Stored
- 7. Text Messaging (SMS)
- 8. Email Communications
- 9. How We Use Your Information
- 10. Marketing, Advertising, and De-Identified Data
- 11. Intellectual Property and Content License
- 12. Sharing Information
- 13. Securing Your Information
- 14. Disclaimers and Limitation of Liability
- 15. Data Retention
- 16. Children Under 13
- 17. Residents of the European Union
- 18. California Residents
- 19. Changes to This Policy
- 20. Contact Us
01Introduction and Acceptance
Hephaestus, LLC dba Talos Cognitive Systems (“Talos Cognitive Systems,” “we,” “us,” or “our”) is a limited liability company organized under the laws of the State of South Carolina, located at PO Box 3378, Bluffton, South Carolina 29910, with the contact email address web [at] taloscognitive [dot] com. We are the data controller for purposes of applicable state, federal, and international data protection regulations, including the EU General Data Protection Regulation (“GDPR”).
We build technology that processes human communication. That makes privacy a design constraint rather than a disclosure exercise, and this Policy is written to describe what we actually do with information — including where processing physically happens and where it does not.
This Policy is a standalone document. It applies on its own terms and does not require a signed agreement to take effect.
Acceptance by use. By visiting our website, submitting information to us, requesting or accepting an estimate or proposal, participating in a demonstration or pilot, engaging our services, or continuing to communicate with us by email, text message, or telephone, you acknowledge that you have read this Policy and agree to the practices described in it. If you do not agree, do not use our website, provide information to us, or continue communications with us.
Where you have also entered into a written agreement with us, that agreement may add to the terms described here. If a signed agreement and this Policy conflict on a particular point, the signed agreement controls for that party as to that point. This Policy continues to apply in full to everyone else and to all matters the agreement does not address.
02Scope
This Policy applies to all interactions with Talos Cognitive Systems, including:
- Our website at taloscognitive.com and any related sub-site, page, form, service, or feature, together with all content and software associated with it (the “Site”);
- Email communications with us;
- Text (SMS/MMS) messages exchanged with us;
- Telephone calls and voicemail;
- Inquiries, consultations, demonstrations, estimates, proposals, and other pre-engagement interactions;
- The TALOS platform and any related software, hardware, hosting, or professional services we provide (collectively with the foregoing, the “Services”).
The terms “you” and “your” refer to you as a visitor, prospective client, client, pilot participant, or other person who interacts with us.
03Information We Collect and How We Collect It
Information you give us
This includes your name, organization, email address, telephone number, physical or mailing address, professional role, and any other information you choose to provide through a form, an email, a text message, a phone call, or in the course of receiving Services.
Information collected automatically
We automatically receive and record technical information from your web browser when you interact with the Site, including your internet connection, your device and operating system, your browser, and your Internet Protocol (“IP”) address or other device identifiers. The Site also collects usage information such as the number and frequency of visitors, which we generally use in aggregate form.
In the course of email, text, and telephone communications, we also receive associated technical and routing information — message timestamps, delivery status, telephone numbers, call duration, and similar metadata generated by the carriers and service providers that transmit those communications.
Cookies and similar technologies
Cookies are small data files sent to your browser when you access a website and stored on your device. We use session cookies to track preferences and monitor usage and traffic on the Site; these are erased when you close your browser. We use persistent cookies to store preferences and make your experience consistent; these remain until they expire or you delete them.
Most browsers automatically accept cookies. You can change your browser settings to refuse cookies, prompt you before accepting them, or delete cookies you already have. If you disable or refuse cookies, certain features of the Site may become inaccessible or fail to function properly.
Our cookies do not, by themselves, contain personal information. This Policy covers our own use of cookies only; we do not control when or how third parties place cookies on your device.
We may use web analytics tools, and clear GIFs (also known as web beacons or pixel tags) on the Site or in communications with you, to determine whether you have visited a part of the Site or received or opened a message. The Site does not respond to browser “Do Not Track” (DNT) signals.
04Communications Data and the TALOS Platform
The TALOS platform provides real-time and post-call communication support. Delivering that capability necessarily involves processing communications content. This section describes what that means.
What the platform processes
- Audio from telephone calls and voicemail on lines connected to the platform;
- Transcripts produced from that audio, including speaker attribution;
- Communications metadata — numbers, timestamps, duration, direction, and delivery status;
- Derived analysis — including conversational patterns, tone and emotion signals, and behavioral models built from prior communications.
Third parties to a communication
A telephone call has at least two participants. When a client operates the platform on their own lines, the client is the party who determines what is processed and who is responsible for providing any notice or obtaining any consent required from the other participants in their jurisdiction. In that arrangement we act as a service provider to the client and process communications data on the client's instructions.
When you communicate with us directly, we are the controller of that communication and this Policy governs it.
Exclusion
The platform supports marking a contact as excluded from behavioral processing. Where a contact is excluded, no behavioral model is built for that contact and no personalized analysis is generated about them. If you communicate with us and wish to be excluded, contact us at web [at] taloscognitive [dot] com.
05Recording, Transcription, and Consent
Calls with us may be recorded, transcribed, and analyzed by the platform. We provide notice and obtain consent where required by applicable law.
Consent requirements for recording vary by jurisdiction. South Carolina permits recording with the consent of one party to the communication; a number of other states require the consent of all parties. Where any participant in a call is located in a jurisdiction requiring all-party consent, we treat that standard as governing.
If you do not wish a call with us to be recorded or transcribed, tell us at the start of the call and we will disable it for that call, or continue in writing instead. Declining does not affect your ability to work with us.
Clients operating the platform on their own lines are responsible for their own compliance with recording and wiretap laws in the jurisdictions where they and the people they speak with are located. We provide the capability; we do not provide legal advice on its use, and use of the platform is not a substitute for obtaining it.
06Where Data Is Processed and Stored
Our architecture draws a deliberate line between two categories of data, and we describe it here because it is a substantive commitment rather than a marketing claim.
Infrastructure data
Raw communications — audio, transcripts, and metadata — necessarily transit third-party infrastructure in the same way email transits a mail provider and a telephone call transits a carrier. That transit is a property of operating on public communications networks. Where we use a cloud intake buffer, it holds raw communications data for a limited retention window of no more than thirty (30) days before deletion.
Behavioral data
Derived behavioral intelligence — models, baselines, conversational analysis, and the personalized output the platform generates — is processed and stored on systems we control directly. We do not persist behavioral models or baselines on third-party cloud infrastructure.
General
Information we collect is stored and processed in the United States, by personnel operating within the United States who work for us or for one of our service providers. We take all steps reasonably necessary to ensure your personal information is treated securely and in accordance with this Policy.
We do not use your communications content to train models offered to other customers or to any third party.
07Text Messaging (SMS)
We may send text messages in connection with our Services, including appointment and scheduling messages, account and status notifications, responses to your inquiries, and — where you have consented — informational or promotional messages.
Consent
You may opt in to receive text messages from us by providing your mobile number through a form on the Site, in an agreement or proposal, verbally, in writing, or by texting us first. Consent to receive marketing text messages is not a condition of purchasing any goods or services from us.
Message frequency and cost
Message frequency varies. Message and data rates may apply. Carriers are not liable for delayed or undelivered messages.
Opting out and getting help
You may cancel text messages at any time by replying STOP to any message from us. After you send STOP, we will send one confirmation message and will not send further text messages unless you opt in again. For assistance, reply HELP or contact us at web [at] taloscognitive [dot] com.
No sale or sharing of mobile opt-in data. No mobile information, opt-in data, or consent will be shared with or sold to third parties or affiliates for marketing or promotional purposes. All other categories of information described in this Policy exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties.
This does not restrict disclosure of mobile information to service providers and subcontractors — such as telecommunications carriers and messaging platforms — who assist us in delivering messages you have requested. Those parties are prohibited from using the information for their own marketing purposes.
08Email Communications
We use your contact information to communicate with you about our Services and, where applicable, to send marketing emails. You may withdraw your consent to marketing emails at any time by using the unsubscribe link in those messages or by contacting us at web [at] taloscognitive [dot] com.
If you opt out of marketing emails, we will still send non-marketing emails. Non-marketing emails include messages about your account, engagement, deadlines, billing, security, and our business dealings with you. We also reserve the right to contact you when we believe it is necessary.
09How We Use Your Information
Because it is in our legitimate interests to process your information in order to provide effective services, we use information we collect about you or that you provide to us, including personal information, to:
- Provide, operate, maintain, and support the TALOS platform and related Services;
- Prepare and deliver demonstrations, estimates, proposals, and engagement documents;
- Communicate with you about the Services, content, features, or products you use or request;
- Customize and improve your experience with the Site and the Services;
- Analyze and improve our Services, including diagnostics, quality assurance, and system reliability;
- Secure accounts, detect abuse, and prevent fraud;
- Carry out our obligations and enforce our rights under any contract between you and us, including billing and collection;
- Comply with legal and regulatory obligations;
- Protect our own or third-party rights or interests; and
- Any other purpose we describe to you at the time you provide the information.
With your consent, we will also process your personal information to notify you of new services, features, enhancements, promotions, or special offers.
10Marketing, Advertising, and De-Identified Data
We may use aggregated, anonymized, or de-identified information — including usage patterns, service statistics, and communications metadata stripped of identifying details — internally, for analytics, benchmarking, service development and improvement, and quality assurance. We may also publish aggregate statistics derived from that information in our own marketing and advertising materials.
Information is treated as de-identified when it cannot reasonably be used, alone or in combination with other information we hold, to identify you or any other individual. De-identified information is not personal information under this Policy. We do not attempt to re-identify de-identified information.
We do not provide de-identified or aggregated information derived from your data to third parties for their own purposes, and we do not license or sell datasets derived from customer communications. The limits in Section 12 apply to de-identified information as well.
We may also use non-identifying descriptions of our work — the type of organization served, the scope of an engagement, or general results achieved — in marketing materials, on the Site, and in proposals.
We do not sell your personal information. We do not use the substance of your communications for advertising purposes in any form that identifies you or your organization without your prior consent. The commitment in Section 7 regarding mobile opt-in data applies without exception, including to the uses described in this section.
11Intellectual Property and Content License
Our content
All content on the Site — text, graphics, logos, images, page layout, product descriptions, documentation, and software — is the property of Hephaestus, LLC dba Talos Cognitive Systems or its licensors and is protected by United States and international copyright, trademark, and other intellectual property laws. The names “TALOS” and “Talos Cognitive Systems,” and our logos and marks, are our trademarks and may not be used without our prior written permission.
The platform and its underlying methods are the subject of pending patent applications. Nothing on the Site grants any license under any patent, copyright, trademark, or trade secret.
You may view and print Site content for your own personal or internal business use. You may not otherwise reproduce, distribute, modify, publicly display, create derivative works from, or commercially exploit any Site content without our prior written permission.
Content you provide to us
You retain ownership of the content, documents, and materials you provide to us. By providing content to us — including testimonials, reviews, photographs, comments, and feedback — you grant us a non-exclusive, royalty-free, worldwide, perpetual license to use, reproduce, display, and distribute that content in connection with operating and promoting our business, including on the Site, in proposals, and in marketing and advertising materials.
This license does not extend to your communications content, transcripts, business records, or other confidential material, which we use solely to provide the Services and as otherwise described in this Policy.
Where you have signed an agreement with us that addresses the use of your name, logo, likeness, or content, that agreement governs for you as to those matters.
12Sharing Information
We do not sell, rent, trade, or otherwise disclose personal information to any third party for that third party’s own purposes. We do not share information with advertising networks, data brokers, analytics resellers, or list vendors. We do not disclose information outside the scope of delivering the Services you have requested, except in the narrow circumstances described below.
Service providers
We use a limited set of service providers to operate the Services — for example, hosting and infrastructure providers, payment processors, email and messaging platforms, and telecommunications carriers. Providing the Services requires that information pass through them.
These providers act on our instructions and are bound to use the information solely to perform the function we have engaged them for. They are prohibited from using it for their own purposes, from disclosing it to anyone else, and from using it for marketing. Disclosure to a service provider is limited to the information reasonably necessary for that provider to perform its function.
Service providers are located in and store information in the United States.
Where a client operates the platform
Where a client operates the TALOS platform on their own lines, communications data associated with that deployment is handled on the client’s instructions, as described in Section 4. We do not use that data for any purpose of our own beyond operating and supporting the Services.
Legal compulsion
We will disclose information without your consent where we are legally required or compelled to do so, or where disclosure is otherwise necessary:
- In response to a subpoena, court order, warrant, or other lawful process, or where a regulatory authority has the power to require the records or information;
- Where disclosure is otherwise required or authorized by applicable law;
- Where disclosure is reasonably necessary to enable a law enforcement body to perform its functions;
- Where we believe in good faith that there is a serious and imminent threat to the life, health, or safety of you or another person; or
- Where reasonably necessary to establish, exercise, or defend our legal rights, including to investigate or act on a violation of our terms.
Where we are permitted to notify you of a legal demand for your information, and not prohibited from doing so, we will make reasonable efforts to do so.
Business transfer
We may transfer personal information to a buyer or other successor in the event of a merger, acquisition, divestiture, restructuring, reorganization, dissolution, or other sale or transfer of some or all of our assets, whether as a going concern or as part of a bankruptcy, liquidation, or similar proceeding, in which personal information we hold is among the assets transferred. Any such successor will remain bound by the commitments in this Policy with respect to information transferred, unless and until you are notified of and accept a different policy.
13Securing Your Information
Transmission of information over the internet, by email, or by text message is not completely secure. Although we do our best to protect your personal information, we cannot guarantee the security of information transmitted through the Site, over email, or by text message; any transmission is at your own risk. Once we have received your personal information, we apply appropriate technical and organizational measures to safeguard it against loss, theft, and unauthorized use, access, or modification.
The Site may contain links to and from websites operated by third parties. Those websites have their own privacy policies, and we do not accept responsibility or liability for them. Please review those policies before submitting information to them.
14Disclaimers, Security Limitations, and Limitation of Liability
No guarantee of security
No method of transmitting or storing information is completely secure, and no system can be made impenetrable. While we apply appropriate technical and organizational safeguards as described in Section 13, we do not warrant, guarantee, or represent that the Site, the Services, or any information you provide to us will be free from unauthorized access, interception, hacking, malware, phishing, ransomware, service interruption, data loss, or other compromise.
You acknowledge and accept that you provide information to us at your own risk, and that events of this kind may occur despite reasonable security practices.
No warranty
The Site and the Services are provided on an “as is” and “as available” basis. To the fullest extent permitted by law, we disclaim all warranties of any kind, whether express or implied, including implied warranties of merchantability, fitness for a particular purpose, title, non-infringement, accuracy, and uninterrupted or error-free operation. We do not warrant that the Site or the Services will be available at any particular time, that defects will be corrected, or that any analysis, transcription, or output generated by the platform will be accurate, complete, or suitable for any particular decision or purpose.
Third-party providers
We rely on third-party service providers — including hosting and storage providers, payment processors, email and messaging platforms, and telecommunications carriers — to deliver the Services. We are not responsible or liable for the acts, omissions, security failures, outages, or data breaches of those providers, or of any website or service we link to.
Release and limitation of liability
To the fullest extent permitted by applicable law, and except where caused by our gross negligence or willful misconduct, you release and hold harmless Hephaestus, LLC dba Talos Cognitive Systems and its members, officers, employees, contractors, and agents from any and all claims, damages, losses, liabilities, costs, and expenses arising out of or relating to:
- Unauthorized access to, acquisition of, disclosure of, alteration of, or destruction of your information by any third party;
- Any interruption, delay, error, or failure of the Site, the Services, or any communication by email, text message, or telephone;
- Any act or omission of a third-party service provider; or
- Any use of information you transmitted to us over an unsecured channel.
To the fullest extent permitted by applicable law, we will not be liable for any indirect, incidental, special, consequential, exemplary, or punitive damages, or for lost profits, lost revenue, lost data, or business interruption, arising out of or relating to this Policy, the Site, or the Services, whether based in contract, tort, strict liability, or any other theory, and whether or not we were advised of the possibility of such damages.
To the fullest extent permitted by applicable law, our total aggregate liability for all claims arising out of or relating to a data breach, security incident, or unauthorized access to, acquisition of, disclosure of, alteration of, or destruction of your information will not exceed the lesser of (a) the total amount of fees you paid to us for the Services during the twelve (12) months immediately preceding the event giving rise to the claim, or (b) the total amount of fees you have paid to us for the Services. If you have paid us no fees, our total aggregate liability for such claims will not exceed one hundred dollars ($100.00).
This limitation applies to all such claims in the aggregate, regardless of the number of incidents or claimants, and regardless of whether the claim is based in contract, tort, statute, strict liability, or any other theory. It does not apply to liability arising from our gross negligence or willful misconduct, or to any liability that cannot be limited as a matter of law.
Your responsibilities
You are responsible for maintaining the confidentiality and security of any credentials used to access accounts, portals, or software in connection with the Services, and for the security of the devices and email accounts you use to communicate with us. You agree to notify us promptly at web [at] taloscognitive [dot] com if you believe any credential, device, or account has been compromised, or if you receive a communication that appears to come from us but that you believe to be fraudulent.
Email and text message are not secure channels. You should not transmit sensitive information to us by email or text unless we have provided a secure method for doing so.
Limitations on these disclaimers
Some jurisdictions do not allow the exclusion of certain warranties or the limitation or exclusion of liability for certain damages. To the extent any provision of this section is held unenforceable, it will be limited or eliminated to the minimum extent necessary, and the remainder of this section will remain in effect.
Nothing in this section limits, waives, or excuses any obligation we have under applicable law, including our obligations under South Carolina and other applicable data breach notification statutes to notify affected individuals and authorities of a security breach involving personal information. Nothing in this section limits liability that cannot be limited as a matter of law.
15Data Retention
We retain personal information relating to your transactions with us, the Services we provide, and your use of the Site for the period during which you or we could bring a claim arising from those dealings, and for any longer period required by applicable law.
Raw communications data held in a cloud intake buffer is retained for no more than thirty (30) days, as described in Section 6. Retention of communications data on client-controlled systems is determined by the client.
After you have terminated your use of the Services and the Site and any applicable retention period has expired, we may continue to hold your information in aggregated and anonymized form.
16Children Under 13
We do not knowingly collect or solicit personal information from anyone under the age of 13, or knowingly allow such persons to register for the Services. If you are under 13, please do not attempt to use or register for the Services or send any personal information about yourself to us, including your name, physical address, telephone number, or email address. If we learn that we have collected personal information from a child under 13, we will delete that information where reasonably possible. If you believe we hold information from or about a child under 13, please send a detailed message to web [at] taloscognitive [dot] com.
17Residents of the European Union
We adhere to the framework and guidance provided by the General Data Protection Regulation (GDPR) and provide the data rights afforded under the GDPR to EU residents. To exercise any of these rights, contact us at web [at] taloscognitive [dot] com.
You have the following rights in relation to your personal information. Some apply only in certain circumstances.
- Access: to inquire about and access personal information we hold about you, and details of how we use it and who we share it with;
- Portability: to receive, or ask us to provide to a third party, your personal information in a structured, commonly used, machine-readable format, where we process information you provided based on contract or consent;
- Correction: to correct inaccurate personal information and have incomplete data completed. Where you request correction, please explain in detail why you believe the information is inaccurate or incomplete so we can assess whether correction is required;
- Erasure: to have your personal information erased in certain circumstances;
- Restriction of processing to storage only: to require us to stop processing your personal information other than for storage purposes in certain circumstances; and
- Objection: to restrict or object to our processing of your personal information in certain circumstances.
Withdrawal of consent. Where you have provided consent for us to process your personal information, you may withdraw it at any time by contacting us at web [at] taloscognitive [dot] com.
Objection to marketing. You have the right at any time to object to our processing of your data for the purpose of sending you news, offers, and promotional content, and we will stop processing your data for that purpose.
Complaints. If you wish to make a complaint about how we process your personal information, please contact us first at web [at] taloscognitive [dot] com and we will endeavor to address your request as soon as possible. This is without prejudice to your right to lodge a claim with the data protection supervisory authority in the EU country in which you live or work, or where you believe we have infringed data protection laws.
18California Residents
California residents may request certain information regarding our disclosure of personal information to third parties for those third parties’ direct marketing purposes, or may opt out of such disclosure. Our policy is not to disclose personal information collected online to any third party for direct marketing without your approval, and we do not sell personal information. To make a request or to opt out at any time, contact us at web [at] taloscognitive [dot] com and indicate what communications or services you no longer wish to receive.
19Changes to This Policy
This Policy is effective as of the date stated at the top of this page. It may be necessary from time to time for us to modify this Policy to reflect changes in how we collect and use information, or changes in privacy-related laws, regulations, and industry standards. We reserve the right to change this Policy at any time by posting the revised policy here and updating the “last modified” date. We encourage you to review this Policy on an ongoing basis. If revisions to this Policy are unacceptable to you, you must cease using the Site and the Services.
20Contact Us
If you have questions, requests, or suggestions regarding this Privacy Policy, contact us at:
Hephaestus, LLC dba Talos Cognitive Systems
PO Box 3378
Bluffton, South Carolina 29910
web [at] taloscognitive [dot] com
843 · 936 · 8800