Herald
by Virtual Guardians
Last updated: July 12, 2026
This Privacy Policy describes how Virtual Guardians, LLC ("Virtual Guardians," "we," "us") collects, uses, and protects information in connection with Herald — our screen-pop and CRM-integration service for Cisco Webex Calling (including the Herald web application at herald.virtual-guardians.com, the Herald embedded sidebar app inside the Webex App, and the Herald administrative consoles) (together, the "Service").
Herald is a business-to-business service. We provide it to companies (our "Customers"), whose call-center agents and administrators ("Users") use it in the course of their work. Herald connects a Customer's Webex Calling to the Customer's own CRM system (the "connected CRM" — currently HubSpot, with other CRMs planned).
We handle information in two distinct capacities:
Customers are responsible for determining what information is stored within their CRM and other connected systems, which integrations are enabled, what permissions are granted to Herald, and for ensuring they have all required legal authority, notices, and consents necessary to use the Service (including any consents required for call monitoring, recording, or transcription).
Herald displays and transfers information provided by the systems the Customer connects. Virtual Guardians does not verify the completeness, accuracy, or timeliness of information returned by those systems. In particular:
When an inbound call rings a User's Webex Calling line, Cisco Webex sends Herald a call notification containing the caller's phone number, the network-provided caller name, the called agent's Webex identifier, a call identifier, and timestamps. Herald uses this to look the caller up in the Customer's connected CRM and show the answering agent who is calling. If a caller has withheld their number (private/anonymous calling), Herald performs no CRM lookup for that call.
With the Customer's authorization, Herald searches the Customer's connected CRM (currently HubSpot) for contacts matching the caller's phone number and displays matching contact details to the answering agent (such as name, title, company, lifecycle stage, record owner, and related records the CRM returns). For Customers on the Pro tier, Herald can also write to the connected CRM: it logs completed calls as CRM call activities (direction, ring/talk duration, outcome) and, where the Customer has enabled Webex call recording with AI summaries, appends the Webex-generated call transcript or AI notes to that CRM call record. Herald retrieves transcript content from Webex transiently for this purpose and does not keep its own copy; Herald never accesses or stores call audio.
Herald stores the OAuth tokens that Users and administrators grant it (Webex and the connected CRM). Tokens are encrypted at rest with AES-256-GCM; encryption keys are held in Google Secret Manager. Herald never stores customer passwords — sign-in always happens on the connected platform's own pages. Herald requests only the narrow permission scopes it needs (for example, reading the signed-in User's own incoming-call events and profile), and tokens are revoked and deleted when a User is offboarded, an integration is disconnected, or authorization is revoked.
Herald is not designed to independently collect Protected Health Information ("PHI"). Any PHI processed through Herald results solely from the Customer's configuration of connected systems (for example, PHI the Customer keeps in its own CRM fields or that appears in its own call transcripts). Virtual Guardians is not a Covered Entity under HIPAA. Where required for a healthcare Customer, Virtual Guardians will execute a separate Business Associate Agreement (BAA) — contact info@virtual-guardians.com.
Herald uses only essential first-party cookies: session and authentication cookies that keep Users, administrators, and vendor staff signed in, and short-lived cookies that protect sign-in flows (OAuth state). These are HttpOnly where the browser permits and are not used to track you across other sites. Herald sets no advertising cookies and no third-party tracking cookies, and uses no third-party analytics services. The installable pop app uses standard browser storage to cache its own interface files.
We keep Customer Data no longer than necessary to provide the Service:
| Data | Retention |
|---|---|
| Screen-pop delivery events (event bus) | Expire 10 minutes after the call; automated deletion completes within ~24 hours of expiry |
| Per-call records (call status, CRM record linkage) | No longer than necessary to provide the Service — typically ~24 hours after the call; automated deletion completes within ~24 hours of expiry |
| Operational and diagnostic logs | ~30 days (Google Cloud Logging default) |
| OAuth tokens | Deleted when a User is offboarded, an integration is disconnected, or authorization is revoked |
| Account, license, and audit records | Life of the Customer's subscription, then deleted per the DPA; billing records kept as required by law |
Data Herald writes into the Customer's connected CRM (call logs, transcripts/AI notes) lives in the Customer's own CRM account and is governed by the Customer's agreement with that provider and its retention practices, not by this table.
Our vendors may access information only to provide their contracted services and are contractually obligated to protect it. We will notify Customers before adding or replacing subprocessors, as described in the DPA.
All traffic is encrypted in transit (HTTPS/TLS). Webhooks from Webex are authenticated with HMAC signatures. Tokens are encrypted at rest (AES-256-GCM) with keys in Google Secret Manager, and Virtual Guardians does not store customer passwords. Administrative access is granted only to authorized personnel with a legitimate business need, requires multi-factor authentication, and every administrative action is audit-logged. Herald requests least-privilege OAuth scopes from Webex and the connected CRM. Our security controls are periodically reviewed and updated. No method of transmission or storage is 100% secure, but we work to protect your information using industry-standard measures, and we will notify affected Customers without undue delay if we become aware of a personal-data breach.
Depending on where you live, you may have rights to access, correct, delete, or receive a copy of your personal information.
We do not sell or "share" (as defined by the California Consumer Privacy Act) personal information, and we act as a "service provider" with respect to Customer data under that law. We do not discriminate against anyone for exercising privacy rights.
Herald currently operates only within United States infrastructure: it is operated from the United States and hosted in the us-east1 (South Carolina) Google Cloud region. If you use the Service from outside the United States, your information will be transferred to and processed in the United States.
Herald is a workplace tool and is not directed to children under 16. We do not knowingly collect personal information from children.
We may update this Privacy Policy from time to time. We will post the updated version at this URL and update the "Last updated" date; for material changes we will also notify Customer administrators.
Virtual Guardians, LLC
1608 Queen Street #21, Wilmington, NC 28401, USA
info@virtual-guardians.com ·
(910) 530-1600