gavelLegal & Corporate Compliance

Privacy & Data Protection Policy

Enterprise-grade data protection, confidentiality, and regulatory governance under GDPR, HIPAA, KVKK, and CCPA/CPRA for AI-powered telephony and reception workflows.

eventEffective Date: August 18, 2026
verifiedVersion: 4.2 (Enterprise Legal Master)

1. Controller & Processor Legal Scope

This Privacy Policy governs the collection, processing, and safeguarding of personal data by AI-Reception.ist ("Provider", "we", "us") across all intelligent conversational concierge services, telephony gateways, and enterprise orchestration APIs.

When Serving Tenants: Data Processor / Business Associate

For inbound calls, patient triage, customer service dialogues, and appointment records handled on behalf of our enterprise subscribers, AI-Reception.ist acts strictly as a Data Processor under GDPR / Business Associate under HIPAA.

For Account Holders: Data Controller

For registered workspace administrators, billing contacts, website visitors, and sales inquiries, AI-Reception.ist acts as the direct Data Controller.

2. Categories of Personal & Operational Data

To deliver real-time, ultra-low latency voice and text orchestration, we process the following distinct data streams:

  • Telephony & Caller Metadata (ANI/CLI): Inbound caller ID, dialed phone number, timestamp, call duration, SIP header signaling, and network latency telemetry.
  • Audio Streams & Real-Time Transcripts: Encrypted real-time audio RTP streams, generated speech-to-text (STT) conversational transcripts, extracted entity metadata, and automated call summaries.
  • Enterprise Workflow Records: Calendar bookings, CRM synchronization logs, EHR intake notes, reservation identifiers, and customer status tags.
  • Administrative & Billing Data: Corporate name, administrative email, tax identifier, billing address, and tokenized payment identifiers handled via PCI-DSS Level 1 payment processors.

We process personal data only when an authorized legal basis under applicable privacy legislation exists:

  • Contractual Necessity (GDPR Art. 6(1)(b), KVKK Art. 5/2-c): Delivering core automated receptionist services, call routing, calendar bookings, and API integrations.
  • Legitimate Business Interests (GDPR Art. 6(1)(f)): Network security, anti-abuse/anti-spam filtering, latency optimization, and infrastructure monitoring.
  • Explicit Consent (GDPR Art. 6(1)(a) & Art. 9(2)(a)): Explicit opt-in consent where required by law for audio recording disclosure or processing of sensitive health categories.
  • Legal & Regulatory Compliance: Compliance with mandatory telecommunications retention rules, tax obligations, and lawful court subpoenas.

4. Voice Processing & Non-Biometric Scope

AI-Reception.ist voice orchestration converts acoustic sound waves into real-time text phonemes strictly for speech recognition and intent classification.

fingerprintNo Biometric Voiceprints or Voice Identifiers Created

We do not extract, store, or analyze biometric identifiers, voiceprints, or physiological vocal tract profiles to uniquely identify natural persons. Audio is processed solely as ephemeral acoustic signal data for immediate transcription.

5. Zero Foundation Model Training Guarantee

Your proprietary enterprise data, caller audio recordings, customer transcripts, and company knowledge bases are NEVER used by AI-Reception.ist or our upstream model providers to train or fine-tune public foundation LLMs.

  • Zero Data Retention (ZDR) enforced on inference endpoints.
  • Cryptographically isolated multi-tenant data boundaries.
  • Full customer ownership of all generated summaries and analytics outputs.

6. Healthcare Data & Protected Health Information (HIPAA & KVKK)

For healthcare providers, dental clinics, medical tourism coordinators, and aesthetic practices, we enforce stringent clinical safeguards compliant with HIPAA and KVKK Health Data Regulations:

  • Business Associate Agreement (BAA): We execute formal HIPAA Business Associate Agreements (BAAs) and GDPR Data Processing Addenda with all covered healthcare entities.
  • Automated PHI Redaction: Sensitive medical notes and diagnostic details are automatically masked in standard dashboard views via configurable redaction rules.
  • Encrypted EHR/EMR Connectors: Electronic Health Record (EHR) connectors operate over mutual TLS (mTLS) with dedicated IP allowlisting.

7. Cross-Border Data Transfers & Regional Residency

We provide regional data residency guarantees to ensure enterprise compliance with local sovereignty statutes:

apartment
AB / EU Residency
Frankfurt (Almanya) — Tam GDPR Uyumlu
domain
TR / Türkiye Bölgesi
İstanbul & Ankara — KVKK Uyumlu
cloud
US / Amerika Bölgesi
N. Virginia — HIPAA / SOC2

Cross-border transfers outside the European Economic Area rely on the European Commission's Standard Contractual Clauses (SCCs Modules 2 & 3) and the EU-U.S. Data Privacy Framework.

8. Authorized Sub-Processors & Infrastructure

We partner exclusively with accredited, enterprise-grade cloud and telecommunication sub-processors bound by stringent Data Processing Addenda:

Sub-ProcessorService FunctionLocationCertifications
Twilio / Retell / LiveKitTelephony, WebRTC & SIP TrunkingUS / EUSOC2, HIPAA, ISO 27001
Hetzner Online / AWS / GCPCloud Compute & Encrypted StorageGermany / Ireland / TRISO 27001, SOC2 Type II
Stripe PaymentsPayment & Billing OrchestrationGlobal / USPCI-DSS Level 1

9. Data Retention & Cryptographic Purge

Customer records are retained only for the duration required to achieve business purposes or fulfill regulatory retention periods. Tenants can configure customized auto-purge intervals (0-day immediate shredding, 30-day, 90-day, or custom):

  • Ephemeral Shredding: Audio buffer is cryptographically wiped from memory immediately upon transcript generation.
  • Cryptographic Erasure: Expired datasets undergo NIST SP 800-88 compliant cryptographic erasure.

10. Technical & Organizational Security Measures (TOMs)

We enforce state-of-the-art security controls across physical, operational, and network layers:

  • 🔒 Encryption in Transit: TLS 1.3, Perfect Forward Secrecy (PFS), SRTP / DTLS ses şifrelemesi.
  • 🛡️ Encryption at Rest: AES-GCM-256 bit şifreleme ve KMS anahtar yönetimi.
  • 🔑 Identity & Access: FIDO2/WebAuthn Donanımsal 2FA, Okta/Azure SAML SSO, Role-Based Access Control (RBAC).
  • Network Defense: Cloudflare Enterprise DDoS koruması, Web Application Firewall (WAF), Zero-Trust mimarisi.

11. Data Subject Rights & Data Protection Officer (DPO)

Under GDPR (Articles 15–22), KVKK (Article 11), and CCPA/CPRA, data subjects hold the following sovereign rights:

  • Right to access and inspect processed personal records.
  • Right to rectify inaccurate or incomplete records.
  • Right to erasure, account destruction, and data portability (Right to be Forgotten).
  • Right to object to automated decision-making and profiling without human recourse.
securityData Protection Officer (DPO) Contact Channel

All statutory data subject inquiries are reviewed and resolved within 30 calendar days at no charge.

Corporate Address: SmartEE Digital Technologies Inc., Legal & Privacy Compliance Division