Legal

Privacy Policy

How Conciara collects, uses, stores and shares personal information, and the rights available to individuals whose information we hold.

1. Our role

Conciara provides AI agents that answer and place calls on behalf of business customers. Those customers determine what their agent does and what information it collects.

In relation to information about their callers, the business customer is the data controller and Conciaraacts as a data processor, processing that information only on the customer’s documented instructions. In relation to the business customer’s own account and billing information, Conciara is the controller.

Individuals who have spoken with an agent and wish to exercise their rights should contact the business they called. Where that is not possible, we will forward the request to the relevant customer and assist them in responding.

2. Information we process

  • Conversation transcripts. A written record of each call or chat, so that the customer has a record of the interaction.
  • Call recordings, where enabled. Audio is not retained by default. A customer may enable recording for a given agent and may separately require the agent to announce it. Compliance with recording and notification law is the customer’s responsibility.
  • Details provided by the caller, such as name, telephone number, email address and the nature of the enquiry. The information an agent requests is configured by the customer.
  • Text messages an agent sends, where enabled. A customer may allow their agent to text a caller — a booking confirmation, or details the caller asked for. We process the message content and the destination number to deliver the message over telephone carrier networks, and we keep a record of the message for the customer. Texting is off unless the customer turns it on, and callers are only texted at a number they provided.
  • Conversation metadata, including date and time, duration, the number dialled, outcome and cost.
  • Customer account information, including the account holder’s name and contact details, billing records, and the settings and reference material they provide.

We do not sell personal information. We do not use the content of conversations to train artificial-intelligence models, whether our own or those of any third party.

3. Purposes and legal bases

We process personal information to provide and maintain the service, to secure it against misuse, to bill for it, and to comply with legal obligations. Where the General Data Protection Regulation applies, our lawful basis is the performance of a contract with the business customer and our legitimate interest in operating and securing the service. Caller information is processed on the instructions of the business customer, who is responsible for establishing its own lawful basis.

4. Accounts connected by the customer

A customer may connect a calendar so that their agent can offer genuine availability and record confirmed appointments. Where that calendar is provided by Google or Microsoft, we request the narrowest permissions capable of performing those functions:

  • Availability. The times at which the calendar is busy. This does not disclose the subject, participants, location or content of any entry, and we do not receive them.
  • Appointments. Permission to add the appointment agreed during the conversation, and to update or cancel an appointment created in this way.
  • The account address. Used only to display which account has been connected, so that the customer can confirm it is the correct one.

We request no other access. In particular, we do not request permission to read email, files or contacts.

Limited Use. Conciara’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Such information is used solely to provide the scheduling features the customer has enabled. It is not transferred to others except as necessary to provide those features, to address security concerns, or to comply with applicable law; it is not used for advertising; and it is not read by any person except with the customer’s explicit consent, where necessary for support they have requested, or where required by law.

Authorisation credentials are held in encrypted storage. A customer may disconnect an account at any time from within the service, which deletes the stored credential, and may additionally revoke access from their Google or Microsoft account.

5. Service providers

We engage a limited number of service providers to deliver the service. These fall into the following categories:

  • Telecommunications carriers, for connecting calls and delivering messages.
  • Real-time media providers, for transmitting audio during a conversation.
  • Speech recognition and speech synthesis providers.
  • Artificial-intelligence model providers, for generating the agent’s responses.
  • Cloud hosting, database and email-delivery providers.

Each is engaged under a written agreement that restricts processing to the provision of its service, requires appropriate security measures, and prohibits any independent use of the information. A current list of subprocessors is available to business customers on request, and we will give reasonable notice of any material change.

6. International transfers

Information may be processed outside the country in which it was collected, including in the United States, the European Economic Area and Canada. Where information is transferred out of a jurisdiction that restricts such transfers, we rely on recognised safeguards, including the European Commission’s Standard Contractual Clauses.

7. Retention

Transcripts, conversation records and details captured during a conversation are retained for the duration of the customer’s account, as they constitute the customer’s business record. Recordings, where enabled, are retained on the same basis. A customer may delete individual records at any time.

On termination of an account, we delete or irreversibly anonymise personal information within thirty days, except where retention is required by law, including for taxation and accounting purposes.

8. Cookies and similar technologies

Our website and dashboard use only cookies that are strictly necessary to operate the service: to keep you signed in, to maintain your session, and to protect against cross-site request forgery. We do not use advertising cookies, and we do not embed third-party analytics or tracking services.

9. Security

Information is encrypted in transit and at rest. Credentials for connected accounts are held in dedicated encrypted storage, separate from application data. Each customer’s information is isolated at the database layer, and that isolation is enforced by the database rather than by application logic. Access by our personnel is restricted to those who require it and is logged.

10. Security incidents

If a breach of security affecting personal information occurs, we will notify affected business customers without undue delay and provide the information they require to meet their own notification obligations, together with the steps we have taken in response.

11. Automated processing

The service uses artificial intelligence to conduct conversations and to summarise them. It does not make decisions producing legal or similarly significant effects concerning any individual. Where an agent records a request — an appointment, a callback, a message — the resulting action is taken by the business customer, not by the system.

12. Your rights

Subject to the law applicable to you, you may have the right to access, correct, delete, restrict or object to the processing of your personal information, to withdraw consent, to receive a portable copy, and to lodge a complaint with a supervisory authority. In Canada, that authority is the Office of the Privacy Commissioner; in the European Economic Area and the United Kingdom, it is the data protection authority of your country of residence.

Requests may be sent to hello@conciara.com. We respond within thirty days. Where the request concerns information collected because you contacted one of our business customers, we will refer it to that customer, who is the controller of that record.

13. Children

The service is intended for use by businesses and is not directed to children. We do not knowingly collect personal information from children.

14. Changes to this policy

We may update this policy from time to time. Where a change materially affects how we handle personal information, we will notify business customers by email before it takes effect. The date at the top of this page indicates when it was last revised.

15. Contact

Last updated 4 August 2026.