Privacy Policy
Overview
Naitriq AI, Inc. ("Naitriq," "we," "our," or "us") operates an AI-powered virtual receptionist platform available at naitriq.com (the "Service"). This Privacy Policy explains how we collect, use, disclose, and protect information when:
- Visitors browse naitriq.com;
- Business customers ("Customers") register for and use our platform to configure and manage virtual receptionist services for their businesses; and
- Callers (individuals who call a phone number that Customers have connected to Naitriq's Service) interact with our AI system.
Please read this Policy carefully. By using naitriq.com or the Service, you agree to the practices described below.
1. Information We Collect
1.1 Website Visitors
When you visit naitriq.com, we may automatically collect:
- Technical data: IP address, browser type and version, device type, referring URL, and pages viewed
- Usage data: time spent on pages, clicks, and navigation paths
- Form submissions: if you fill out a contact or inquiry form, we collect the name, email address, and message you provide
1.2 Customers (Business Users)
When a business registers for and uses the Service, we collect:
- Account information: business name, contact name, email address, billing address, and payment information (processed by our payment processor; we store only a payment token)
- Configuration data: call scripts, routing rules, and integration credentials (stored encrypted)
- Usage data: call volumes, feature usage, login history, and support interactions
- Communications: emails and messages you send to us
1.3 Callers (Individuals Who Call a Customer's Number)
When an individual calls a phone number that a Customer has connected to our Service:
- Call data: caller's phone number (unless blocked by the caller), call date and time, and call duration
- Voice data: audio of the conversation, processed in real time by our AI system; retained as a recording only if the Customer has enabled call recording
- Caller-provided information: name, nature of inquiry, appointment preferences, and any other information the caller shares during the call
- Transcripts: a text transcript of the call, if the Customer has enabled transcription
- SMS data: if the Customer has enabled SMS features, inbound SMS messages from the caller, outbound confirmation messages (e.g., appointment confirmations), message timestamps, and delivery status
Note on caller data: When processing data on behalf of a Customer's callers, Naitriq acts as a data processor on the Customer's behalf. The Customer is the data controller responsible for the callers' data. Callers with questions about how their data is handled should contact the business they called.
1.4 Integration Data
If a Customer enables optional integrations (e.g., Google Calendar, Jobber), we receive only the data necessary to fulfil the integration — for example, calendar availability and appointment details. We do not access other data in the connected account.
2. How We Use Information
2.1 To Provide the Service
- Operating the virtual receptionist AI, routing calls, generating transcripts, and delivering caller data and summaries to Customers
- Sending appointment confirmations and follow-up SMS messages on behalf of Customers (where enabled)
- Processing payments, managing accounts, and providing customer support
- Sending service notifications, policy updates, and support communications
2.2 To Improve and Develop the Service
- Analyzing aggregated, de-identified usage patterns to improve AI accuracy and platform performance
- We do not use identifiable caller audio, transcripts, or SMS content to train AI models without the Customer's prior written consent.
2.3 Legal and Safety Purposes
- Complying with applicable laws and legal process
- Enforcing our Terms of Service and Acceptable Use Policy
- Detecting and preventing fraud, abuse, or security incidents
3. Call Recording, AI Disclosure, and SMS
3.1 Call Recording
If a Customer enables call recording, calls may be recorded, transcribed, and stored. Call recording is subject to applicable federal and state laws (including two-party consent laws in states such as California, Florida, and Illinois). Customers are responsible for providing required pre-call consent disclosures to callers.
3.2 AI Disclosure
Naitriq's virtual receptionist is powered by artificial intelligence. Where required by law (e.g., California Business & Professions Code § 17941), the system will disclose that the caller is speaking with an AI-powered automated system when directly and sincerely asked.
3.3 SMS Communications
If a Customer enables SMS, outbound messages are sent via third-party telephony providers on behalf of the Customer. Customers are responsible for obtaining any required TCPA (or equivalent) consent from recipients before enabling SMS. SMS content and delivery records are retained per the retention schedule in Section 6.
4. How We Share Information
We do not sell personal information. We share information only as follows:
| Recipient | Purpose | Safeguards |
|---|---|---|
| Customers | Deliver caller data, transcripts, recordings, and SMS records per their configuration | Governed by Master Services Agreement + Data Processing Agreement |
| Sub-processors | Cloud infrastructure, telephony, AI voice processing, calendar, and CRM integrations | Bound by sub-processor agreements |
| Professional advisors | Legal, accounting, and auditing services | Bound by confidentiality obligations |
| Law enforcement / courts | Legal obligation or protection of rights and safety | Disclosed only as legally required |
| Acquirers | Business sale, merger, or acquisition | Subject to this Policy |
Named Sub-processors
| Category | Provider(s) | Purpose |
|---|---|---|
| AI voice platform | Vapi.ai | Real-time AI call handling, transcript generation, SMS routing |
| Telephony & SMS | Twilio (via Vapi.ai) | Phone-number management, PSTN routing, SMS delivery |
| AI model APIs | OpenAI and/or equivalent LLM providers (via Vapi.ai) | Natural-language understanding powering the virtual receptionist |
| Cloud infrastructure & hosting | Microsoft Azure (Static Web Apps, Logic Apps) | Website hosting, workflow automation |
| Calendar integration | Google LLC (Google Calendar API) | Appointment booking and availability lookup (activated only when Customer enables) |
| Field-service CRM | Jobber Inc. | Job and customer management integration (activated only when Customer enables) |
A current and complete list of sub-processors is available by emailing privacy@naitriq.com. Customers will be notified of material sub-processor changes as required by the applicable Data Processing Agreement.
5. Cookies and Tracking
Our website uses cookies and similar technologies for:
- Essential / security: session management and security
- Analytics: understanding aggregate site usage (no cross-site tracking or behavioral advertising)
We do not use third-party advertising or cross-site tracking cookies. You can manage or block cookies through your browser settings; some features may not function correctly if essential cookies are disabled.
6. Data Retention
| Data Type | Retention Period |
|---|---|
| Customer account data | Duration of contract + 3 years |
| Call recordings (if enabled by Customer) | As configured by Customer |
| Call transcripts | As configured by Customer |
| SMS message content and delivery records | As configured by Customer |
| Caller phone numbers and call metadata | As configured by Customer |
| Website visitor logs | 90 days |
| Billing records | 7 years (tax/accounting requirements) |
| System/server logs | 90 days |
Customers may configure shorter retention periods or request earlier deletion within their account settings or by contacting support.
7. Data Security
We implement commercially reasonable administrative, technical, and physical safeguards, including:
- Encryption of data in transit (TLS 1.2+) and at rest (AES-256)
- Role-based access controls and multi-factor authentication for internal systems
- Scrypt password hashing for Customer account credentials
- Tenant-scoped data isolation (one Customer cannot access another Customer's data)
- Regular security assessments and incident response procedures
No system is completely secure. In the event of a data breach that affects your rights, we will notify affected parties as required by applicable law.
8. Financial Services Context
Naitriq's Service is designed to serve financial advisory firms, RIAs, wealth management professionals, and other businesses. The following applies when the Service is used in financial-services contexts:
8.1 Standard Service Scope
The standard Service is designed for appointment scheduling, call routing, and general inquiry management. It is not designed or licensed to receive, store, or transmit regulated financial data such as Social Security numbers, securities account numbers, portfolio holdings, investment account credentials, or other data subject to GLBA, SEC, or FINRA data-handling requirements.
8.2 Enterprise Financial Services Addendum
Customers who require the Service to handle regulated financial data must execute a separate Enterprise Financial Services Addendum before submitting or enabling the transmission of such data.
8.3 Customer Responsibility
Customers are solely responsible for ensuring their use of the Service complies with applicable financial-services regulations including FINRA Rules 4511 and 4370, SEC Regulation S-P, and GLBA Safeguards Rule requirements applicable to their firm.
8.4 AI Is Not Financial Advice
The virtual receptionist AI is designed to route and schedule — not to provide investment advice, securities recommendations, or fiduciary guidance.
9. Your Rights
9.1 All Users
You may request to access, correct, or delete personal information we hold about you by contacting us at privacy@naitriq.com.
Note for callers: If you called a business that uses our Service, that business is the data controller for your call data. Please contact them directly to exercise rights related to your call. We will forward requests to the appropriate Customer where legally required.
9.2 California Residents (CCPA / CPRA)
California residents have the right to:
- Know what personal information we collect, use, and disclose (we do not sell personal information)
- Delete personal information we hold, subject to legal exceptions
- Correct inaccurate personal information
- Opt out of the sale or sharing of personal information (not applicable — we do not sell or share for advertising)
- Limit use of sensitive personal information
- Non-discrimination for exercising any of the above rights
To exercise your rights, contact us at privacy@naitriq.com. We will respond within 45 days (extendable by 45 days with notice). California residents may also use an authorized agent by providing written authorization.
9.3 EEA, UK, and Swiss Residents (GDPR / UK GDPR)
If you are in the European Economic Area, United Kingdom, or Switzerland, you have rights under GDPR / UK GDPR including: access, rectification, erasure, restriction of processing, data portability, and the right to object. You may also lodge a complaint with your local data protection supervisory authority.
Legal basis for processing:
- Customer account data and website visitor data: contract performance (Art. 6(1)(b)) and legitimate interests (Art. 6(1)(f))
- Caller data processed on behalf of Customers: Naitriq acts as a processor under Art. 28; the Customer is the controller
International transfers: If we transfer personal data outside the EEA/UK, we rely on Standard Contractual Clauses (SCCs) or equivalent mechanisms approved by the relevant authority. Contact us for a copy.
10. Children's Privacy
The Service is directed to businesses and professionals. We do not knowingly collect personal information from individuals under 18. If we learn we have collected such information, we will delete it promptly.
11. Changes to This Policy
We may update this Policy from time to time. We will notify Customers by email or in-platform notification at least 30 days before material changes take effect. We will update the "Last Updated" date above. Continued use of the Service after the effective date of any change constitutes acceptance.
12. Contact Us
Naitriq AI, Inc.
Privacy inquiries: privacy@naitriq.com
For data-subject requests related to a specific Customer's use of our Service, please contact that Customer directly, as they are the data controller for caller data processed on their behalf.
This is internal legal-risk analysis, not legal advice, and is not a substitute for a licensed attorney. Before publication, this policy should be reviewed by outside counsel for GDPR/CCPA completeness and jurisdiction-specific requirements.