Privacy Policy
Overview
DaiZ Automation ("DaiZ", "we", "us", "our") builds AI Receptionist, a software service that helps service businesses ("Customers") handle inbound phone calls and SMS messages, manage appointments, and route leads using AI. The AI Receptionist mobile app (iOS, Android) and web dashboard at app.daiz-auto.com are tools used by authorized staff of those Customer businesses.
This policy explains what information AI Receptionist collects, how we use it, who we share it with, and the choices you have.
Roles. For information about people who call or message a Customer business, that Customer is the "controller" or "Business" of that information under applicable law, and DaiZ acts as their "processor" or "Service Provider". Caller-rights requests are routed first to the relevant Customer; see Section 9.
1. Information We Collect
- Account information. Username, name, role, push-token for notifications, and authentication credentials of staff users provisioned by a Customer.
- Customer business information. Business name, phone numbers, hours, services, pricing, staff schedules, and similar configuration data needed to operate the AI receptionist.
- Caller and message data. Phone numbers, call audio, call transcripts, SMS message content, voicemails, and metadata such as timestamps and durations of calls and messages routed through the service.
- Booking and appointment data. Appointments created, cancelled, or modified through the service; client notes; gift cards; memberships; and related records originating from or returned to the Customer's connected booking system.
- Device information. For the mobile app: device push tokens (Apple Push Notification service for iOS, Firebase Cloud Messaging for Android), operating-system version, and crash logs.
- Usage information. Logs of which features were used, timestamps, and IP addresses, used to operate and secure the service.
- Demo requests from our website. If you request a demo at daiz-auto.com, we collect the name, business name, email address, and phone number you submit. See "Marketing Website & Demo Requests" below.
2. How We Use Information
- To provide AI-driven phone and SMS handling on behalf of the Customer.
- To create, modify, and look up appointments, customer records, gift cards, memberships, and related items in the Customer's connected booking system.
- To deliver call notifications, dashboards, analytics, and reports to authorized staff.
- To debug, monitor performance, and improve the service.
- To detect, prevent, and respond to fraud, abuse, or security incidents.
- To comply with legal obligations.
AI training. We do not sell personal information. We do not use call audio, transcripts, or message content to train general-purpose AI models that are not part of providing the service to the Customer. Our language model and speech processing providers operate under contractual terms that prohibit using API inputs and outputs to train their public models, and we additionally enable the model-improvement opt-out controls those providers make available at the API level.
Marketing Website & Demo Requests
When you submit the demo request form on daiz-auto.com, we use the information you provide to email you a private demo link and to contact you — by email, phone, or text — about your demo and our service. Demo sessions themselves (the conversation you have with the demo AI) are recorded and transcribed the same way production calls are, and are used to operate and improve the service. We do not sell this information, and we do not use it for third-party advertising. To have your demo-request information deleted, email [email protected].
3. Call Recording and Transcription
When callers contact a Customer's phone line that is connected to the service, AI Receptionist records the call audio and generates a text transcript. Callers receive a verbal disclosure at the start of the call notifying them that the call is being recorded and processed by an automated system.
In jurisdictions that require all-party consent for recording (including but not limited to California, Connecticut, Florida, Illinois, Maryland, Massachusetts, Pennsylvania, and Washington), the disclosure is played before the conversation begins and a caller who does not wish to be recorded may end the call at that point or reach the Customer through another contact method the Customer makes available. Where applicable law requires affirmative consent that cannot be satisfied by notice alone, the Customer is responsible for confirming that its use of the service meets that requirement in the jurisdictions where it operates. Callers who do not consent may end the call at any time. The Customer is responsible for ensuring that the configured greeting includes a recording disclosure appropriate for the jurisdictions in which it operates.
Recordings and transcripts are used to deliver the booking and message service requested by the Customer, to operate and improve the service (including troubleshooting, quality monitoring, and AI performance evaluation), and as required by law. Retention periods are described in Section 7.
4. Sub-processors and Third-Party Services
AI Receptionist relies on the following categories of sub-processors. Each receives only the data needed to perform its function, and each is bound by the terms described below.
- Telephony and messaging provider — voice call transport, SMS delivery, and call recording storage.
- Real-time voice infrastructure — carries live call audio between the caller and the AI.
- Speech processing providers — speech-to-text transcription and text-to-speech voice generation. Our integrations enable the available model-improvement opt-out controls, so call audio is not used to improve these providers' models.
- AI model gateway and language model provider — routing and inference for the AI's responses. Contractual terms prohibit using API inputs and outputs to train public models.
- Booking system — the scheduling platform the Customer already uses (for example Boulevard), where the Customer connects it.
- Cloud database and hosting — Postgres database hosting and authentication.
- Push notification services — mobile push delivery through Apple and Google platform services.
- Transactional email delivery — demo invitations, password resets, and account notices.
- Network, TLS, and DNS provider — TLS termination, network protection, content delivery, and email routing.
Named list. A current list naming each sub-processor, its location, and its function is available to Customers and prospective Customers on request at [email protected], and is provided as part of our data processing terms. We keep the public list at the category level so that routine changes of vendor do not require a policy revision, while Customers with a data processing agreement receive advance notice of the specific providers we use.
Equivalent protection. We require all sub-processors and third-party services that receive personal information through the service to provide protection of that information that is at least equivalent to the protection described in this Privacy Policy, through written contracts, data processing agreements, or applicable industry certifications such as SOC 2 or ISO 27001.
Updates to sub-processors. We will provide reasonable advance notice of new sub-processors to Customers with a signed data processing agreement by email to the account administrator, and will update the categories above if the nature of the processing changes. Customers may have additional rights to object to specific sub-processors as set out in their agreement.
5. How We Share Information
We share information only as needed to operate the service:
- With the sub-processors listed above to perform their function.
- With the Customer whose business the data belongs to. The Customer's authorized staff can see calls placed to their own business through the dashboard.
- When required by law, valid legal process, or to protect the rights, property, or safety of DaiZ, our Customers, or others.
- In connection with a corporate transaction such as a merger or acquisition, in which case we will provide notice and the recipient will be bound by terms at least as protective as this policy.
We do not share Customer caller data with other Customers.
6. Healthcare and HIPAA
The service is offered to a wide range of small businesses, some of which operate in healthcare-adjacent fields (for example, medical spas offering cosmetic procedures). The Health Insurance Portability and Accountability Act ("HIPAA") may apply to a Customer if it qualifies as a Covered Entity under 45 CFR § 160.103.
Today, AI Receptionist is not configured for use by HIPAA Covered Entities or Business Associates that handle Protected Health Information ("PHI"). Customers must not transmit PHI through the service, must not instruct callers to share PHI through the service, and must not use the service to schedule procedures that require collection of PHI.
If a Customer requires PHI handling, contact [email protected] about a Business Associate Agreement and an enterprise configuration. Without a BAA in place, callers should not be asked for, and Customers must not enter, any information that is or could constitute PHI under HIPAA.
State consumer health privacy laws. Several U.S. states regulate consumer health data outside of HIPAA — including the Washington My Health My Data Act, the Nevada Consumer Health Data Privacy Act, and the health-data provisions of Connecticut’s privacy law. These can apply to businesses in health, wellness, and aesthetic fields even when HIPAA does not. Where such a law applies, the Customer is the party that determines what is collected from its clients and is responsible for providing the required notice and obtaining the opt-in consent those laws require before health-related or appointment-intake information is collected through the service.
7. Data Retention
- Call audio and transcripts: retained for up to twelve (12) months from the call date, after which they are deleted from active systems.
- Message content: retained while the Customer's account is active, then deleted within 90 days of account closure.
- Account credentials and configuration: retained while the Customer's account is active and for a reasonable period thereafter for legal, accounting, and audit purposes.
- Backups may persist for up to 90 days after deletion from active systems.
- Demo sessions and website demo requests: demo call recordings, transcripts, and the contact details submitted through the demo-request form are retained for up to ninety (90) days from collection, then permanently deleted, unless the person becomes a Customer.
- Aggregated and de-identified data may be retained indefinitely for analytics and service improvement.
Customers may request earlier deletion of specific records by contacting us at the email below.
8. Account Deletion
Staff users. Staff accounts on AI Receptionist are provisioned and managed by the Customer business that employs the user. To delete your staff account, contact your business administrator or email [email protected] from the address on file. We will verify your identity, action the request within 30 days, and email confirmation when complete. Deletion removes your authentication credentials, profile, push tokens, and personally-attributable audit-trail entries. Where a deletion request covers data held by a sub-processor on our behalf (for example call recordings held by our telephony provider, or records in our hosted database), we propagate the deletion to those systems within thirty (30) days of actioning the request; backups may persist for the period described in Section 7.
Customer accounts. A Customer's primary administrator may request deletion of the entire Customer account and its associated business data (including caller data processed on its behalf) by emailing [email protected]. Deletion is completed within 30 days, subject to the backup retention window in Section 7 and to legal-hold or fraud-prevention obligations.
Web-based deletion request. Users without app access may submit a deletion request by emailing [email protected] with the subject "Account Deletion Request" and the username or email on the account.
Account deletion does not by itself delete records that are independently retained as part of a Customer's required business records (for example, a booking confirmation forwarded to the Customer's own booking system).
9. Your Rights
End callers. If you called or messaged a business that uses AI Receptionist and want to access, correct, or delete information about that interaction, please contact the business directly. They are the controller of that data; we act as their processor and will assist them in responding.
Staff users. Authorized staff of a Customer business may exercise rights of access, correction, or deletion through the Customer's administrator or by contacting us at the email below.
California residents (CCPA/CPRA)
We do not "sell" personal information and do not "share" it for cross-context behavioral advertising as those terms are defined under the California Consumer Privacy Act as amended by the CPRA. We do not use call recordings, transcripts, or other voice data to generate voiceprints, perform speaker identification, or train biometric identification systems, and we do not treat audio collected through the service as Sensitive Personal Information for the purpose of biometric identification.
Service Provider status. With respect to caller data processed on behalf of a Customer, DaiZ acts as a “Service Provider” as that term is defined in Cal. Civ. Code § 1798.140(ag). DaiZ certifies that it shall not: (1) sell or share that personal information; (2) retain, use, or disclose it for any purpose other than the business purposes specified in its agreement with the Customer, including retaining, using, or disclosing it for a commercial purpose other than those business purposes; (3) retain, use, or disclose it outside the direct business relationship between DaiZ and the Customer; or (4) combine it with personal information received from or on behalf of another person, except as expressly permitted under the CPRA regulations. For information collected from callers on a Customer's behalf, please contact the Customer directly; they are the "Business" for that data under the CCPA, and we act as their "Service Provider".
Voice biometrics (BIPA, CUBI, BPA)
We do not collect, capture, purchase, receive through trade, or otherwise obtain "biometric identifiers" or "biometric information" as defined under the Illinois Biometric Information Privacy Act (740 ILCS 14), the Texas Capture or Use of Biometric Identifier Act, or the Washington Biometric Privacy Act. We do not generate voiceprint templates, perform speaker identification or speaker verification, or use voice characteristics to identify any caller. Audio is transcribed to text using a speech-to-text service and discarded after the retention period in Section 7.
European users (GDPR / UK GDPR)
The service is operated from the United States and primarily marketed to U.S. businesses. We do not target users in the European Economic Area, the United Kingdom, or Switzerland. If you access the service from those regions, the following applies:
- Lawful bases for processing under Article 6 GDPR are: performance of a contract with the Customer (Art. 6(1)(b)); legitimate interests in operating, securing, and improving the service (Art. 6(1)(f)); and consent (Art. 6(1)(a)) where required.
- For caller data processed on behalf of a Customer, we act as a processor and the Customer is the controller. Direct access, rectification, erasure, restriction, portability, and objection requests to the Customer in the first instance.
- Personal data is transferred to and stored in the United States. Where required, we rely on the Standard Contractual Clauses approved by the European Commission, supplemented by additional safeguards.
- We have not appointed an EU representative under Article 27 because our processing of EU resident data is occasional and does not include large-scale processing of special categories. We will reassess this as the service expands.
10. Cookies and Similar Technologies
The web dashboard uses cookies and similar storage technologies that are strictly necessary to operate the service: to keep you signed in (authentication and session cookies), to remember preferences such as timezone and theme, and to protect against fraud and abuse (CSRF tokens, rate-limit identifiers). We do not use advertising, analytics, or cross-site tracking cookies in the authenticated dashboard.
The mobile app uses local device storage and the secure keychain/keystore to retain authentication tokens and preferences. It does not use browser cookies.
11. Marketing Communications
We may send service-related communications such as security alerts, billing notices, and important policy changes that you cannot opt out of while your account is active. Promotional communications, if any, will include an unsubscribe mechanism. SMS messages from the service support STOP, START, and HELP keywords as required by U.S. carrier guidelines and the Telephone Consumer Protection Act (47 USC § 227).
12. Security
We use industry-standard safeguards including encryption in transit (TLS 1.2+), encrypted storage at the database layer, role-based access control, and operational monitoring. No method of transmission or storage is 100% secure; if you believe an incident has occurred, please contact us immediately.
13. Children's Privacy
AI Receptionist is not directed to children under 13 (or the equivalent minimum age in the relevant jurisdiction). We do not knowingly collect personal information from children. If we learn we have collected information from a child under 13, we will delete it. To report this, contact [email protected].
14. International Transfers
We are based in the United States. By using the service, you understand that information may be processed in the United States and other countries where our sub-processors operate.
15. Changes to This Policy
We may update this policy from time to time. Material changes will be communicated through the service or by email to account administrators. The "Last updated" date at the top of this page indicates when the policy was last revised.
16. Contact Us
For privacy questions or to exercise your rights, contact:
DaiZ Automation
Email: [email protected]