Menu

Legal

Privacy Notice

Effective date: The date this Notice is first published by AlwaysGreet LLC after its formation.

Version 2026-08-01

This Privacy Notice explains how AlwaysGreet LLC (“AlwaysGreet,” “we,” “us,” or “our”) collects, uses, discloses, and retains personal information through alwaysgreet.com and the Services. It covers business customers and their personnel (“Users”) and people who call a business using AlwaysGreet (“Callers”).

For Caller information processed to provide a Customer’s receptionist service, the Customer generally determines why and how the information is used and is the controller/business; AlwaysGreet is its processor/service provider. Callers should also review the called business’s privacy notice. AlwaysGreet acts as an independent controller for account administration, billing, security, fraud prevention, product operations, and legal compliance.

1. Information we collect

1.1 Account and business information

We collect names, business contact details, login identifiers, organization information, role, authentication events, preferences, support communications, plan information, and billing records. When payments are enabled, the payment processor will receive payment-card details directly; AlwaysGreet will not store full card numbers.

1.2 Call and service information

Depending on Customer settings, we process caller and called numbers, call time and duration, audio, transcripts, messages, appointment requests, names, callback details, caller statements, call outcomes, routing events, AI prompts and outputs, and configuration variables.

Standard mode may store recordings and transcripts. Privacy mode disables persistent audio storage and uses transient speech processing to operate the AI, retaining only configured structured results and limited operational logs. Real-time speech processing is necessary for an AI voice receptionist to participate in a call.

1.3 Customer content and integrations

We process business hours, services, FAQs, scripts, knowledge content, calendar availability, routing instructions, and data returned by connected services. Customers control the information they connect and must avoid prohibited sensitive data.

1.4 Technical information

We collect IP address, device and browser information, pages and features used, timestamps, cookie or local-storage identifiers, diagnostics, security events, approximate location inferred from IP, and interaction logs.

1.5 Sources

We receive information from Users and Callers, Customer-configured systems, telecommunications and AI providers, authentication providers, calendars, payment processors, analytics and security services, public business sources selected by Customer, and information generated through use of the Services.

2. How we use information

We use personal information to:

  • provide inbound call handling, message intake, appointment scheduling, dashboards, support, and requested integrations;
  • authenticate users and protect accounts;
  • process payments and administer subscriptions;
  • route calls, troubleshoot failures, monitor availability, and prevent abuse;
  • honor recording, deletion, access, and opt-out choices;
  • communicate about service, security, billing, and support;
  • comply with law and enforce agreements; and
  • create aggregated or de-identified analytics for security, reliability, capacity planning, benchmarking, and product improvement.

We do not sell personal information for money. We do not use identifiable Customer recordings or transcripts to train a general-purpose AI model or for third-party advertising without separate, explicit permission. We do not use Callers’ personal information for cross-context behavioral advertising.

3. Legal grounds

Where a legal basis is required, processing is based on performance of a contract, legitimate interests in operating and securing the Services, compliance with legal obligations, and consent where required. The Customer is responsible for the legal basis and notices applicable to Caller data it instructs us to process.

4. How we disclose information

We disclose information only as reasonably necessary:

  • To the Customer: call results, appointments, messages, recordings, transcripts, and account activity are made available to authorized Customer users.
  • To subprocessors: vendors provide hosting, databases, telecommunications, AI and speech processing, authentication, calendars, billing, support, email, monitoring, and security.
  • For legal and safety reasons: when reasonably necessary to comply with law, protect rights or safety, investigate fraud, or enforce agreements.
  • For corporate transactions: subject to appropriate confidentiality in a financing, merger, acquisition, reorganization, or sale of assets.
  • At direction or with consent: when a User or Customer directs an integration or disclosure.

Our current Subprocessor Notice identifies material providers and processing locations. We require subprocessors to protect personal information under contractual obligations appropriate to their role.

5. Call recording, transcription, and AI disclosure

The default greeting identifies the receptionist as AI and states that a call may be recorded and transcribed. Customers control call configuration and are responsible for confirming that notices and consent are lawful in applicable jurisdictions.

If a Caller declines persistent recording, the Customer may configure the Service to stop recording and continue using transient processing without storage, transfer the call, or end the AI interaction. Callers may contact the called business to exercise choices concerning data controlled by that business.

6. Retention

Stored audio recordings and transcripts are retained for 30 days by default unless the Customer selects a shorter available period or deletes them sooner. Structured appointments and messages are retained according to Customer account settings and legitimate operational needs. Account, transaction, security, consent, and legal records may be retained longer when needed for contract administration, fraud prevention, dispute resolution, tax, audit, or law.

Deletion from active systems may not immediately delete encrypted backups, which are isolated and expire under backup schedules. We may preserve specific data when legally required or reasonably necessary for a pending dispute or security investigation.

7. Sensitive data and healthcare prohibition

At launch, the Services are not offered for PHI or HIPAA-regulated workflows. Customers and Callers should not provide medical information, payment-card numbers, bank credentials, Social Security numbers, government identification numbers, passwords, authentication codes, or other highly sensitive data. If such data is submitted unexpectedly, we may restrict access, delete it, or take protective action.

8. Security

We use administrative, technical, and physical safeguards designed to protect personal information, including access controls, encryption in transit, appropriate encryption at rest, credential management, logging, backups, vulnerability management, vendor review, and incident-response procedures. No system is completely secure, and we cannot guarantee absolute security.

Users are responsible for securing accounts, devices, credentials, connected services, exports, and personnel access.

9. Individual privacy rights

Depending on location and applicable law, individuals may have rights to know, access, correct, delete, restrict, object to, or obtain a copy of personal information, and to appeal a denied request. Some information may be exempt, and identity verification may be required.

For Caller data controlled by a Customer, submit the request to the called business. We assist Customers with verified requests as required by the DPA. Users may submit requests to support@alwaysgreet.com. Authorized agents must provide proof of authority. We will not discriminate for exercising applicable rights.

AlwaysGreet does not currently sell personal information or use it for targeted advertising as those terms are defined by applicable comprehensive U.S. state privacy laws. If that changes, we will update this Notice and provide required choices before beginning the practice.

10. Cookies and analytics

We use necessary technologies for login, security, session continuity, preferences, and core functionality. We may use limited analytics to understand aggregate site and product use. Where required, nonessential analytics will be controlled by a consent mechanism. Browser “Do Not Track” signals are not standardized. Where legally required and technically supported, we will honor recognized universal opt-out preference signals for applicable activities.

11. Children

The Services are for businesses and are not directed to children under 13. Customers must not intentionally configure the Services to solicit personal information from children. If we learn that information was collected from a child contrary to this Notice, we will take appropriate deletion steps.

12. United States processing and international transfers

AlwaysGreet is based in the United States, and information may be processed in the United States and other locations used by approved subprocessors. Before offering the Services to individuals outside the United States, AlwaysGreet will implement any required transfer mechanism and regional disclosures.

13. Changes

We may update this Notice to reflect legal, technical, or business changes. We will post the updated Notice and revise the effective date. Material changes will be communicated through the Services or by email where appropriate.

14. Contact

Privacy questions and requests: support@alwaysgreet.com

AlwaysGreet LLC’s business mailing address will be listed in its Washington public registration after formation.