Privacy Policy
Effective 16 June 2026
Elioxa ("we", "us") provides Elioxa Voice OS, a B2B platform for AI-powered business phone workflows. This Privacy Policy explains how we collect, use, and protect information when business customers ("Customers") use our services and when their callers interact with the voice system.
1. Roles and scope
Customers are the data controllers for caller and workflow information processed on their behalf. Elioxa acts as a data processor for Customer account data and call processing, except where we act as controller for our own website, billing, and product analytics.
This policy applies to the marketing site (elioxa.com), admin portal (app.elioxa.com), API, and voice services. It does not cover third-party backend systems or payment systems configured by the Customer.
2. Information we collect
We process the following categories of information:
- →Account data: organisation name, admin users, email, role, billing contact, and configuration settings.
- →Call data: caller phone number, call metadata, audio recordings (when enabled), transcripts, consent flags, and call duration.
- →Workflow data: structured outcome data submitted to the Customer's configured backend adapter.
- →Usage data: billable minutes, workflow counts, and estimated AI cost metrics for invoicing.
- →Support and lead data: contact form submissions, demo requests, and correspondence with our team.
3. How we use information
We use information to:
- →Provide, operate, and improve the Voice OS — routing, catalog search, workflow execution, and integration sync.
- →Prefetch customer context (e.g. prior interactions by caller number) when configured by the Customer.
- →Send workflow confirmations or alerts via WhatsApp or SMS when the Customer enables notifications.
- →Bill Customers, prevent fraud, and enforce our Terms of Service.
- →Monitor reliability, debug failures, and run quality reviews with appropriate access controls.
4. Recording and consent
Where call recording or live speech-to-text is enabled, the voice system discloses that the caller is speaking with an AI assistant and that the call may be recorded. Affirmative consent is collected before workflow processing continues.
Customers are responsible for displaying any location-level notices required under applicable law and for configuring fallback numbers for human transfer.
5. Subprocessors
We use trusted infrastructure and AI/telephony providers to deliver the service. Depending on configuration and region, subprocessors may include:
- →Twilio (voice telephony and SMS)
- →Deepgram (speech-to-text), OpenAI (language model), Cartesia (text-to-speech)
- →Fly.io (API and voice worker hosting), Vercel (web and portal hosting)
- →PostgreSQL hosting, Redis, object storage (S3/R2-compatible) for recordings
- →WhatsApp Business API (workflow notifications)
- →Resend (marketing lead email delivery)
6. Data residency and retention
Production deployments are hosted in regions appropriate to Customer geography and latency requirements. Region selection is configured during onboarding or enterprise setup.
Call recordings and transcripts: default retention 90 days unless the Customer requests a different period in writing. Account and billing records are retained as required for tax and contract purposes.
7. Security
We use TLS in transit, role-based access control, organisation-scoped data isolation, and secrets management for production environments. Access to call recordings and transcripts is limited to authorised Customer users and Elioxa operations staff with a legitimate need.
8. Your rights and Customer responsibilities
Customers may access, export, or delete organisation data through the admin portal or by contacting us. Callers should direct privacy requests regarding their personal data to the business they called (the data controller).
We will assist Customers in responding to lawful requests where required by our Data Processing Agreement.
9. International transfers
Some subprocessors may process data outside the Customer's primary region. Where required, we implement appropriate safeguards (contractual clauses, regional deployment choices) consistent with Customer agreements.
10. Changes
We may update this policy from time to time. Material changes will be posted on this page with an updated effective date. Continued use of the service after changes constitutes acceptance where permitted by law.
Questions or DPA requests: hello@elioxa.com