Privacy Policy for ReplyAI

Effective Date: 15 July 2026

Last Updated: 14 August 2026

ReplyAI is a conversational voice artificial intelligence and booking automation platform operated by SEEN Pty Ltd (“we”, “us”, or “our”). We are dedicated to maintaining the confidentiality, security, and integrity of the personal and business data entrusted to us by our customers and users.

This Privacy Policy explains how we collect, use, store, disclose, and protect your information when you access our website at www.replyai247.com, use our voice-receptionist platform, or connect your Google Calendar.

1. Compliance with Privacy Frameworks

We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). Where applicable, we take reasonable steps to comply with international data protection laws by applying administrative, technical, and physical safeguards to protect your data.

2. Data Controller & Data Processor Roles

ReplyAI as a Data Processor: When providing our conversational AI voice services to your business, we act as a Data Processor. Your business is the Data Controller for all personal data relating to your end-users, callers, and customers. In simple terms, your business decides what personal information is collected from your customers, and ReplyAI processes that information only on your instructions.

ReplyAI as a Data Controller: We act as a Data Controller only for the account, billing, and system usage information we collect directly from you to manage your subscription, maintain our platform, and secure your account.

3. Information We Collect and Process

We collect and process personal and business information only when it is necessary to provide, manage, and optimize our services.

A. Customer-Provided Business Data

To configure and personalise your custom AI voice assistant, we store the business details you explicitly provide:

  • Business names, contact phone numbers, and operating hours.
  • Frequently Asked Questions (FAQs), services offered, and pricing structures.
  • Prompt configurations, instructional guidelines, and uploaded business knowledge base documents.

B. User Account & Identity Details

When registering or logging into your portal via Google OAuth, we collect basic profile details to authenticate your session:

  • Your name, email address, and profile photo.

C. Voice Calls & Audio Processing

When individuals interact with our telephony lines, we process communication data as a data processor on your behalf:

  • Call Recordings: Securely processed audio recordings of phone conversations.
  • Transcriptions: Plain-text transcriptions of the verbal communication, parsed by our voice engine.
  • Call Metadata: Technical logs including call durations, telephone numbers, and connection timestamps.

A. Customer-Provided Business Data

To configure and personalise your custom AI voice assistant, we store the business details you explicitly provide:

  • Business names, contact phone numbers, and operating hours.
  • Frequently Asked Questions (FAQs), services offered, and pricing structures.
  • Prompt configurations, instructional guidelines, and uploaded business knowledge base documents.

B. User Account & Identity Details

When registering or logging into your portal via Google OAuth, we collect basic profile details to authenticate your session:

  • Your name, email address, and profile photo.

C. Voice Calls & Audio Processing

When individuals interact with our telephony lines, we process communication data as a data processor on your behalf:

  • Call Recordings: Securely processed audio recordings of phone conversations.
  • Transcriptions: Plain-text transcriptions of the verbal communication, parsed by our voice engine.
  • Call Metadata: Technical logs including call durations, telephone numbers, and connection timestamps.

4. Google API Services & OAuth Scopes

ReplyAI integrates with Google Workspace APIs solely to automate scheduling and booking workflows on your behalf. We do not request, access, or process your emails, contacts, or documents.

To sync your availability, our application requests access only to the minimum required standard identity and Google Calendar scopes required for booking functionality:

  • openid / email / profile: Used to safely authenticate your account and manage secure platform login.
  • https://www\.googleapis.com/auth/calendar.events: Used to check calendar availability, create new bookings, and update or cancel existing appointments as directed by your callers.

5. Google's "Limited Use" Disclosure

ReplyAI’s use and transfer of information received from Google APIs to any other application will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically:

No AI Model Training: We do not use, transfer, or analyze Google user data to train, retrain, or improve general-purpose artificial intelligence, large language models (LLMs), or machine learning architectures.

No Advertising: Google user data is never used, sold, or transferred for advertising, profiling, or targeting purposes.

Limited Transfers: We only transfer derived Google Calendar information (such as available appointment times) to our voice AI subprocessor, Vapi, to directly provide the booking feature you use. We never transfer your raw Google Calendar data, OAuth tokens, or credentials to Vapi, Twilio, Stripe, or any other third party.

Strictly Limited Personnel Access: Access to Google Calendar data by our personnel is strictly limited to situations where it is necessary for technical support, security investigations, legal compliance, or where you have expressly requested assistance.

6. Data Security Protocols

We implement industry-standard physical, administrative, and technical safeguards designed to prevent unauthorized access, alteration, or disclosure of your data:

  • Encryption in Transit: All communication between our website, dashboard, and external APIs is encrypted using secure HTTPS/TLS 1.3 protocols.
  • Encryption at Rest: Sensitive credentials, including Google OAuth refresh tokens and customer API keys, are stored in isolated databases and encrypted using industry-standard AES-256 protocols.
  • OAuth 2.0 Framework: We rely entirely on secure Google OAuth protocols to connect with your Google Calendar. We never ask for, nor do we store, your Google account passwords.
  • Monitoring & Vulnerability Management: We employ regular security monitoring, logging, and vulnerability management practices to identify and mitigate technical risks.
  • Access Controls: System access is restricted on a strict “least-privilege” basis to authorized technical personnel who require access solely for system maintenance.

7. Data Retention Schedule

To maximize data minimization, we adhere to a strict, structured retention schedule for all information stored within the ReplyAI platform:

Data Category Retention Period Post-Retention Action
Call Recordings
90 Days
Permanently deleted.
Call Transcripts
Duration of active subscription + 30 days
Permanently deleted.
Google OAuth Tokens
Retained for the duration of the active subscription
Deleted upon account disconnection or verified deletion request.
Account Configuration
Duration of active subscription
Deleted 30 days post-termination.
Billing & Transaction Records
7 Years
Kept as required by corporate tax laws.

8. Artificial Intelligence Processing & Automated Decisions

ReplyAI utilizes secure generative artificial intelligence to respond to caller inquiries and schedule calendar events.

  • Subprocessors: Voice calls and transcripts may be processed by secure, enterprise-grade third-party AI model providers used to deliver the voice conversational logic.
  • No Professional Advice: AI-generated responses are generated automatically and should not be relied upon as legal, financial, medical, or emergency advice.
  • Emergency Services Disclaimer: ReplyAI is strictly not designed, built, or intended to contact emergency services or respond to life-threatening emergency situations.
  • Automated Decisions: Our platform utilizes automated processes to answer calls, handle basic customer support inquiries, and create bookings on your calendar. Final business decisions, pricing policies, acceptance of specific jobs, and manual customer follow-ups remain the sole responsibility of the customer.
  • Review: Customers remain solely responsible for configuring their assistants, uploading accurate knowledge bases, and routinely reviewing system performance.

9. Third-Party Subprocessors

To deliver telephony and voice processing, we securely integrate with and transmit select data to the following standard industry subprocessors:

  • Twilio: For carrier-grade telephony and business phone number routing.
  • Vapi: For real-time voice orchestration and voice-to-text pipeline management.
  • Stripe: For secure PCI-compliant subscription billing and payment processing.
  • Google: For identity authentication and secure Google Calendar synchronization.
  • Cloud Infrastructure Providers: For secure, isolated application hosting and database storage.

Google User Data Handling: Data retrieved via the Google Calendar API (such as calendar events and availability) is accessed exclusively by our own backend servers, and is used only to provide the booking feature within our application. Only the resulting availability windows or booking confirmations derived from this data — never your raw Google Calendar data, OAuth tokens, or credentials — are passed to Vapi so it can inform callers of open appointment times and confirm bookings during a call. Google user data is never shared with Twilio or Stripe, and is never used for advertising, profiling, or to train AI/ML models.

10. Cookies and Tracking Technologies

We use cookies, web beacons, and similar secure identifiers to support the functionality of our website and user dashboard:

  • Authentication: To keep you securely logged into your ReplyAI dashboard session.
  • Preferences: To remember your dashboard preferences, dark/light mode choices, and system state.
  • Analytics: To analyze aggregate website traffic patterns, monitor load times, and improve performance.
  • Security: To prevent fraudulent account actions, block bots, and protect customer data.

You can adjust your browser settings to decline cookies, though doing so may prevent certain parts of our dashboard or scheduling tools from functioning correctly.

11. Your Data Subject Rights

Depending on your jurisdiction, you have the following legal rights regarding your personal data:

  • Right of Access & Portability: Request a copy of all personal data we hold about you.
  • Right to Rectification: Request correction of inaccurate, outdated, or incomplete personal details.
  • Right to Erasure (Deletion): Request the permanent deletion of your account and associated communication transcripts.
  • Right to Withdraw Consent: Disconnect integrations or withdraw consent for call recording at any time, which will immediately cease further data collection.

To exercise any of these rights, please contact our support team at the email address listed below.

12. Privacy Complaints

If you believe we have breached your privacy rights, please contact us first at info@replyai247.com. We take your concerns seriously; we will thoroughly investigate your complaint and respond to you within a reasonable period (typically 30 days). If you remain dissatisfied with our response, you have the right to escalate your complaint to the Office of the Australian Information Commissioner (OAIC).

13. Children's Privacy

ReplyAI is a commercial B2B platform intended strictly for use by businesses and individuals aged 18 years or older. We do not knowingly collect, process, or store personal information from children under the age of 13 (or under 16 in certain jurisdictions). If we discover that we have inadvertently collected such data, we will take immediate steps to delete it from our servers.

14. International Data Transfers

Our database infrastructure and secure third-party subprocessors operate globally, primarily in Australia and other secure jurisdictions where our approved cloud service providers host operations. By using our services, you acknowledge that your data may be processed and stored in these locations. We ensure all cross-border data transfers comply with applicable privacy laws and utilize standard contractual safeguards.

15. Changes to this Policy

We may update this Privacy Policy from time to time to reflect changes in our platform architecture, integrations, or legal obligations. Any changes will be published on this page with an updated “Last Updated” date at the top. Where required by law, we will notify customers of material updates.

16. Contact Information

For questions regarding this Privacy Policy, your data rights, or our compliance with Google API policies, please reach out to:

  • Legal Entity: SEEN Pty Ltd
  • ABN: 72 621 324 721
  • Registered Office: Queensland, Australia
  • Support Email: info@replyai247.com
  • Website: www.replyai247.com
Scroll to Top