Privacy Policy

9.0 PRIVACY POLICY & PRIVACY DATA PROCESSING


The Provider is committed to protecting privacy in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). This section details how personal data managed during both background and self-serve operations is compiled, used, and secured.

9.1 Information Formally Processed: To successfully fulfill the capabilities of the AI Voice Receptionist, the system systematically handles identity parameters, voice architectural assets, and diagnostic logs across data sub-sections 9.2, 9.3, and 9.4.

9.2 Identity & Interaction Data: Full names, verified phone numbers, residential/business addresses, digital booking notes, and email parameters provided by inbound callers.

9.3 Voice and Telephony Audio Data: Raw digital audio file streams of processed voice calls, alongside corresponding machine-generated text transcripts synthesized via underlying Large Language Models (LLMs).

9.4 Operational Logs: System ledger entries, metadata tracking connection intervals, API call triggers, and payload diagnostics.

9.5 Data Utilization: Captured information is accessed strictly to deliver operational value to The Client. This includes executing automated phone bookings, populating custom GoHighLevel CRM workflows, routing system operations, and auditing technical performance parameters. The Provider does not trade, distribute, sell, or rent collected personal data, voice blueprints, or transcripts to external data aggregators or third-party marketing networks.

9.6 Cross-Border & Overseas Data Transmission: By entering this agreement, The Client expressly acknowledges that the underlying backend technological architecture requires third-party API configurations (GoHighLevel, Vapi, and Twilio). Personal data, call logs, audio records, and transactional metadata will be securely transmitted, processed, and maintained on overseas servers primarily located within the United States. In alignment with APP 8, the Provider enforces rigid encryption protocols to maintain data safety during cross-border operations.

9.7 Surveillance & Legal Audio Recording Mandate: Where a Client explicitly selects the 'Summaries and Transcripts' option during onboarding, The Client possesses exclusive operational accountability for adhering to state-based surveillance, wiretapping, and Listening Devices Acts within Australia. The AI Voice infrastructure can deploy mandatory vocal recording notifications (e.g., "This call is recorded for quality purposes"). If The Client explicitly elects to deactivate or bypass these warning notifications during a customized deployment, The Client legally warrants they possess independent regulatory clearance to execute unannounced audio recordings within their operational jurisdiction.

9.8 Technical Security & Storage Architecture: All platform communication pipelines employ Secure Sockets Layer (SSL/TLS) data encryption protocols in transit and at rest. Text transcripts and underlying digital recordings are securely hosted for the standard lifetime of the subscription to preserve conversational context. Upon active account termination, all identifying information, audio recordings, sub-account pipelines, and associated call transcripts are completely and permanently purged from active cloud servers within sixty (60) business days.

 

9.9 Zero-Retention Data Configuration Option: Where a Client explicitly selects the 'No Summaries and Transcripts' option during onboarding, the Provider will configure backend API endpoints (Vapi and GoHighLevel) to immediately purge live call audio streams and text translations upon the physical termination of each phone call. In this configuration, no historical voice records, conversational transcripts, or call audio summaries are retained on active cloud architecture. The system will strictly retain the basic contact parameters (Name, Phone, and Appointment Time) required to execute the calendar booking.

9.10 Access Rights, Data Amending, and Complaints Handling: Individuals retaining records inside the system possess statutory rights to request access to or amendments of their personal data or transcripts. Access inquiries or formal privacy complaints must be formally submitted in writing via email to [email protected] If an escalated privacy complaint cannot be satisfactorily resolved via internal corporate review, users maintain an absolute legal right to lodge a formal regulatory dispute directly with the Office of the Australian Information Commission (OAIC) at www.oaic.gov.au.