Privacy Policy
Elgentic LLC, doing business as Elgentic AI (“Elgentic,” “we,” “us”), provides Elgentic Reception, an AI phone receptionist for service businesses. This Policy explains how we handle personal information when someone visits elgentic.ai, contacts us, uses our public demo, receives our operational communications, or uses our customer portal.
1. Our role when we serve a business
When Elgentic Reception answers calls or processes scheduling information for a business customer, that business generally decides why the caller’s information is processed. Elgentic processes the information on that customer’s behalf under our customer agreement and data-processing terms. Callers should also review the privacy information provided by the business they called.
Elgentic separately determines how it processes information about website visitors, business contacts, portal users, billing contacts, public-demo callers, and security activity.
2. Information we handle
- Business customers and prospects: name, role, business name, email, phone number, service address, communication preferences, account and portal details, onboarding and business configuration, support communications, contract acceptance, and billing records.
- Callers: caller ID or phone number when available, call audio, transcript, caller-provided name and callback number, questions, messages, appointment requests and scheduling details, timestamps, duration, routing, outcome, and recording or AI-disclosure evidence.
- Public-demo callers: the same general call information. Aster Row Salon is a fictional practice salon. Please use fictional details and do not provide sensitive or confidential information.
- Website and device data: standard request and device information received by hosting and analytics providers, such as IP address, browser information, requested page, referring page, timestamp, and performance information. Elgentic also counts selected actions as daily totals that are not designed to include a visitor ID, session ID, IP address, user agent, phone number, or free-text value.
- Connected services: authorizations, service or calendar configuration, staff and service information, availability, appointment data, and other information needed for the capability a customer enables.
- Telephony and assigned endpoints: calling and called numbers, audio in transit, routing and communications-usage data, timestamps, duration, status, and information needed for security, abuse prevention, legal compliance, and number administration.
- SMS and email: designated recipient contact details, consent and opt-out information, message content, and delivery status.
When a prospect submits the public onboarding SMS opt-in form, we store the business name, contact name, and mobile number in an encrypted payload with the consent version, collection path and timestamp, retention deadline, and privacy-minimized notification-delivery information. Submitting the form does not create an account, membership, entitlement, or live service.
Business customers may provide business information through approved portal entries, forms, files, communications, websites, connected accounts, scheduling services, and other enabled systems. Customers are responsible for the accuracy of that information and for authorizing the sources, connected accounts, uses, and recipients they configure.
We collect information directly from customers, prospects, portal users, demo callers, and callers to customer businesses; automatically from browsers, devices, telephone and messaging networks, and service activity; from customer-authorized connected services; and from providers that help us operate, secure, support, and bill for the service.
When the service reports an appointment as Booked, the enabled scheduling service returned authoritative confirmation, including its appointment identifier and scheduled time. Message captured means the request was durably recorded. Human follow-up means a person owns the next step; it does not by itself mean that person acted or that the request was resolved.
For operational notifications, provider acceptance and final delivery are separate states. Neither proves that the recipient read or acted on a message or that the underlying request was resolved. The current program serves authorized business recipients; it does not send proactive caller follow-up or caller booking-confirmation texts.
3. How we use information
- Provide, configure, secure, support, and administer Elgentic Reception.
- Receive business information through customer-approved sources, answer calls using that information, take messages, and create supported appointments through enabled compatible integrations.
- Generate and deliver supported responses, summaries, messages, appointment results, and other configured outputs to authorized recipients and enabled integrations.
- Notify authorized business recipients about handled calls and service operations.
- Operate accounts, the portal, contracts, billing, support, and audit records.
- Troubleshoot failures and perform quality assurance for the relevant customer.
- Operate, protect, debug, and understand the website and public demo.
- Prevent fraud, abuse, security incidents, unlawful use, and violations of our terms.
- Comply with law and establish, exercise, or defend legal claims.
4. Calls, AI identity, recording, and the public demo
Elgentic Reception identifies itself as an AI or automated receptionist. Calls may be recorded and transcribed depending on the applicable configuration and law.
The public Aster Row demo announces that it is an AI receptionist, states that the call may be recorded and transcribed for quality and customer service, and asks for verbal permission before handling the request. If the caller declines or does not clearly agree after a clarification, the automated demo ends without continuing. The website notice supports this call-level process but is not the only consent mechanism because a person can dial the number directly.
5. AI model training and provider data use
Elgentic does not currently use customer content or caller data to train, fine-tune, or improve generalized or cross-customer AI models, create cross-customer training datasets, or advertise. We use call information for service delivery, security, troubleshooting, and quality assurance for the relevant customer.
Voice AI, telephony, hosting, messaging, payment, identity, analytics, backup, and customer-enabled scheduling providers process information to deliver, secure, support, analyze, and administer the applicable service. Elgentic has executed a data processing addendum with its current voice provider that limits processing of customer personal data to Elgentic’s instructions, applicable law, and the defined service purposes; takes precedence over conflicting standard terms; and requires substantially equivalent data-protection obligations for subprocessors. The provider has also confirmed in writing that it does not use customer content or caller data to train its own or third-party AI models and that its model providers operate under zero-retention and no-training terms. Provider terms and practices can change; Elgentic manages this through vendor selection, contractual purpose limits, account configuration, and accurate disclosure.
This public Policy identifies provider categories and material processing purposes rather than publishing Elgentic’s named vendor or technology map. Business customers may obtain the current named Subprocessor List through their customer documentation, an authenticated customer channel, or on request, including applicable change notices.
If Elgentic later introduces a customer-authorized training program, it will apply prospectively only after we define its scope and controls, complete legal and product review, obtain the required customer authorization and caller notice or consent, and update this Policy. A policy update, continued use, silence, or de-identification alone will not give Elgentic a retroactive right to use previously collected call content for generalized model training.
6. How we disclose information
We disclose information to the relevant business customer and its authorized users; to providers that host the service, process calls, deliver messages, support billing, store encrypted backups, provide analytics, or otherwise operate the service; to a scheduling or calendar provider the customer enables; to professional advisers, auditors, and insurers under appropriate protections; when required by law or needed to protect safety and rights; in a business transaction; or as directed by the relevant person or customer.
Elgentic does not receive money in exchange for personal information and does not intentionally disclose personal information for cross-context behavioral advertising. We do not provide SMS opt-in consent or mobile numbers to third parties for their own marketing. Certain state laws define “sell,” “share,” and related terms broadly, and the classification of a disclosure can depend on the recipient’s contract, purpose, and technical settings.
7. Retention
- Provider sessions, call recordings, transcripts, caller identifiers, free-text messages or summaries, notification bodies, and booking identity fields are ordinarily deleted or scrubbed after up to 90 days, unless a different period is required by an agreement or law.
- Encrypted public onboarding opt-in submissions, including their contact payload, consent information, and operator-notification delivery state, are deleted after 90 days.
- Purpose-limited structured quality and customer-analytics events may be retained for up to 365 days and are designed not to include recordings, transcripts, caller identifiers, or free-text call content.
- Limited non-content checksums or governance records may remain where needed to prove policy, deletion, security, billing, or legal compliance.
- Account, billing, tax, consent, dispute, audit, security, and legal records are retained for as long as reasonably needed for those purposes and applicable requirements.
- Encrypted backups age out through the normal recovery cycle. If a backup is restored, applicable deletion rules are reapplied.
8. Your choices and privacy requests
Depending on where you live and the law that applies, you may be able to request access, correction, deletion, or a copy of personal information, withdraw consent, limit certain uses, or appeal a denied request. Email privacy@elgentic.ai with the subject “Privacy Request.” Tell us your relationship to Elgentic and the business involved, but do not email sensitive information. We may request information reasonably needed to verify identity, authority, and the correct customer relationship.
If your request concerns a call to an Elgentic customer, that business may be responsible for responding. We may forward the request to the business or assist it. To stop operational SMS, reply STOP; reply HELP for assistance.
9. Security
We use administrative, technical, and organizational safeguards designed to protect personal information. No system is perfectly secure. If you believe information or an account is at risk, contact support@elgentic.ai promptly.
10. Children, processing locations, and external links
Elgentic Reception is offered to businesses and is not directed to children. The website, portal, and public demo are intended for adults. Elgentic is based in Texas, and information may be processed in the United States and other locations used by our providers. External services and links are governed by their own terms and privacy practices.
11. Changes
We may update this Policy as our service, providers, or legal obligations change. We will post a new effective date and provide additional notice of a material change when appropriate. Changes apply prospectively unless law requires otherwise.
12. Contact
Elgentic LLC, doing business as Elgentic AI
Frisco, Texas
privacy@elgentic.ai