Auxiliaries AI Inc. ("Auxiliaries AI Inc.", "we", "us", or "our") respects your privacy and is committed to protecting personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard information when you visit our website, use the Voice AI by Auxiliaries platform, or interact with our voice AI infrastructure (collectively, the "Services").
This policy is designed to comply with Canada's Personal Information Protection and Electronic Documents Act ("PIPEDA"), applicable provincial legislation (including the British Columbia Personal Information Protection Act and Quebec Law 25), and applicable international standards.
1. Scope & privacy roles
To understand our privacy practices, it is important to distinguish between our two legal roles:
- As a data controller — we are accountable for personal information collected from our business Customers, website visitors, and account administrators (for example, account registration details, billing data, and platform telemetry).
- As a data processor — when our Customers deploy voice agents to make or receive calls, process transcripts, or connect CRMs, the Customer is the data controller. We handle call audio, transcripts, and End-User data on behalf of, and under the instructions of, that Customer.
Separately from the processing we perform on a Customer's instructions, we act as a controller when we use Customer Data to secure, operate, improve, and develop the Services, and when we produce aggregated and de-identified data, as described in section 4. Our Customers agree to this use under our Terms of Service and are responsible for obtaining the consents it requires.
2. Accountability & designated Privacy Officer
Auxiliaries AI Inc. has designated a Privacy Officer accountable for our privacy management program and our PIPEDA and provincial compliance. If you have questions about our practices or wish to exercise your rights, contact:
Privacy Officer, Auxiliaries AI Inc.
Email: privacy@auxiliariesai.com
General legal inquiries: legal@auxiliariesai.com
British Columbia, Canada
3. Information we collect
We collect information only as necessary to provide, secure, and operate the Services.
A. Information provided directly by Customers
- Account & contact data — name, business email address, phone number, company name, business address, and authentication identifiers.
- Billing & transaction data — payment metadata, transaction history, and billing contacts. Card processing is handled by our payment processor; full card details are never stored on our servers.
- Integration credentials — API keys, access tokens, and webhook URLs you authorize when connecting third-party platforms such as CRMs and calendars. Credentials are encrypted at rest.
B. Call, voice & End-User data (processed on behalf of Customers)
- Audio & media — audio recordings and real-time audio streams generated during voice calls routed through your agents.
- Transcripts & AI output — machine-generated transcripts, call summaries, call metadata (duration, phone numbers, timestamps), and records of actions triggered during calls.
C. Technical, log & telemetry information
- IP addresses, browser type, operating system, device identifiers, system activity, rate-limit metrics, network latency, and session telemetry collected automatically when you interact with the platform.
4. How we use information
- Service provision — to route voice calls, execute AI workflows, run speech-to-text and text-to-speech processing, and maintain integrations.
- Account management & billing — to authenticate users, issue invoices, meter usage credits, and manage billing.
- Security & system integrity — to detect, prevent, and respond to security incidents, fraud, abuse, and rate-limit evasion.
- Service operation — to analyze telemetry, diagnose latency, repair defects, and maintain tenant isolation.
- Service improvement & development — to evaluate and improve the accuracy, reliability, and quality of our voice agents, prompts, and platform features, and to develop new features and products.
- Legal compliance — to meet legal obligations, respond to lawful demands, and enforce our Terms of Service.
How we use call content. We use Customer Data, which can include call audio and transcripts, to operate the Services and to improve and develop them — for example to evaluate agent accuracy, tune prompts, diagnose failures, and measure quality. We also create aggregated and de-identified data, which no longer identifies any individual, and use it for analytics, benchmarking, and product development.
What we do not do. We do not sell Customer Data, voice audio, or transcripts. We do not disclose call audio or transcripts to third-party AI providers for the training of their public or foundational models — where AI processing is performed by a model provider on our behalf, it is carried out under commercial terms that prohibit the use of that content for model training. We do not use one Customer's data to build a service offering specific to a competitor of that Customer.
Where we act as a processor, our Customer is responsible for obtaining the consents required for this processing from the individuals concerned. See section 7.
5. Sub-processors & data sharing
We share personal information strictly on a need-to-know basis with vetted service providers, under agreements requiring confidentiality and security standards equivalent to our own. Our sub-processors fall into the following categories:
- Cloud infrastructure & database hosting — application hosting, managed database, and storage of call recordings.
- Telecommunications carriers — origination and termination of voice calls and text messages over the public telephone network.
- AI speech & language model providers — speech recognition, speech synthesis, and language model processing of call audio.
- Payment processing — billing, invoicing, and card handling.
- Transactional email delivery — service notices, reports, and account communications.
A current list identifying each sub-processor by name is available to Customers on request from privacy@auxiliariesai.com.
Separately, where you connect a third-party integration to your workspace, data is transmitted to that provider at your direction and is then governed by that provider's own privacy terms. You control which integrations are connected.
We may also disclose personal information where required by law, regulation, search warrant, subpoena, or court order, or where necessary to protect the rights, safety, or security of Auxiliaries AI Inc., our users, or the public.
6. International & cross-border data transfers
Auxiliaries AI Inc. is based in Canada. Our service providers and cloud infrastructure operate in multiple jurisdictions, including the United States.
You acknowledge that personal information, voice recordings, and transcripts may be stored, processed, or accessed outside your home province and outside Canada, including in the United States. While data resides in a foreign jurisdiction, it may be subject to lawful access requests from that jurisdiction's law enforcement, courts, or national security authorities.
7. Call recording notice & Customer responsibility
Under PIPEDA and provincial privacy laws, individuals must be informed of, and consent to, the collection and recording of their personal information.
Where Auxiliaries AI Inc. acts as a processor, our Customer is solely responsible for providing pre-call disclosures and obtaining all legally required consents from call participants before audio is captured or transcripts are processed. The platform provides recording and consent-mode controls; the Customer decides how they are configured and used.
8. Data safeguards & security
We employ organizational, technical, and administrative measures designed to protect personal information against loss, theft, and unauthorized access, disclosure, or modification. These include:
- Encryption of integration credentials and call transcripts at rest using AES-256, and encryption in transit using TLS;
- Storage of call recordings in private, access-controlled storage, retrievable only through short-lived expiring links, with encryption at rest applied at the infrastructure layer;
- Multi-tenant database isolation controls;
- Access restrictions limiting data access to authorized personnel with a verified operational need;
- Automated monitoring for unauthorized access attempts and abuse.
While we take rigorous steps to secure data, no method of transmission or storage can be guaranteed completely secure.
9. Security incident notification
We maintain procedures to investigate and respond to security incidents. Where a breach of security safeguards creates a real risk of significant harm, we will notify the affected Customer without undue delay and will report to the Office of the Privacy Commissioner of Canada and to affected individuals as required by PIPEDA and applicable provincial law. Where we act as a processor, we will notify the Customer so that the Customer can meet its own notification obligations.
10. Data retention & deletion
We retain personal information for as long as necessary to provide the Services, meet our legal and audit obligations, and enforce our agreements.
- Account & workspace data — retained while your workspace remains active.
- Call audio, transcripts & call records — retained for the life of your workspace so that they remain available to you in the platform. We do not automatically delete call data on a fixed schedule.
- Deletion on request — Customers may request deletion of specific recordings and transcripts, or of an entire workspace, by contacting privacy@auxiliariesai.com. On workspace closure or a written deletion request, Customer Data is deleted or anonymized, subject to our routine backup rotation and to any data we must retain by law.
- Aggregated & de-identified data — data that has been aggregated or de-identified so that it no longer identifies you, your End Users, or any individual is not personal information, and we retain and continue to use it after deletion or workspace closure.
11. Cookies & similar technologies
We use only strictly necessary first-party cookies — those required to keep you signed in, maintain your session, and protect against cross-site request forgery. We do not use advertising cookies, third-party analytics, tracking pixels, or cross-site trackers, and we do not sell or share personal information for behavioural advertising.
12. Google user data (Google API Services)
Customers can optionally connect a Google account so that their voice agents can use Google Calendar and Gmail. This section describes how we handle information received through Google APIs ("Google user data").
- What we access. With your consent via Google's authorization screen: your Google account email address (used to label the connection in your dashboard); your calendar list and calendar event data (used to check availability and to create, update, or cancel the appointments your agents book); and, where you connect Gmail, the ability to send email messages your agents compose on your behalf and to retrieve recent messages when you or your agent explicitly request them.
- How we use it. Google user data is used solely to provide these user-facing features — appointment scheduling and email follow-up performed by your voice agents at your direction. We do not use Google user data for advertising purposes, do not sell it, and do not use it to develop, improve, or train generalized artificial-intelligence or machine-learning models.
- Storage. We store the authorization tokens needed to keep the connection active on access-controlled infrastructure, with encryption at rest applied at the infrastructure layer. Calendar and email content is processed in real time to fulfil a request; details your agent relays during a call (for example, a booked appointment time) may appear in that call's transcript.
- Sharing. We do not transfer Google user data to third parties except as necessary to provide these features, to comply with applicable law, or as part of a merger or acquisition where you are given prior notice. Our personnel do not read this data except with your permission, where necessary for security or abuse investigations, or where required by law.
- Revocation & deletion. You can disconnect Google at any time from your dashboard — we delete the stored tokens on disconnect — or revoke our access from your Google account security settings.
Voice AI by Auxiliaries's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
13. Your rights & data subject requests
Depending on your jurisdiction (for example PIPEDA, BC PIPA, Quebec Law 25, or the GDPR), you may have the right to:
- Access & correction — request access to, and correction of, personal information we hold about you.
- Erasure & withdrawal of consent — request deletion of personal information or withdraw consent to processing, subject to legal and contractual exceptions.
- Portability — receive personal data you provided to us in a structured, commonly used electronic format.
- Automated decision-making — request information about automated processing and AI-assisted decisions affecting you.
How to exercise these rights. If you are an account holder, contact our Privacy Officer at privacy@auxiliariesai.com. If you are an End User who interacted with a voice agent operated by one of our business Customers, please submit your request directly to that Customer, who controls the data; as a processor, we will assist them in fulfilling valid requests as directed.
14. Children's privacy
The Services are designed for business operations and are not directed to individuals under sixteen (16) years of age. We do not knowingly collect personal information from children.
15. Updates to this policy
We may update this Privacy Policy to reflect technological, operational, or legal changes. Material changes will be reflected by updating the "Last updated" date above and, where appropriate, by notice through the platform or to your registered email address.
16. Contacting us & regulatory recourse
Questions, concerns, or complaints about this policy or our privacy compliance can be sent to our Privacy Officer at privacy@auxiliariesai.com. General support is available at support@auxiliariesai.com.
If you are not satisfied with our response, you may lodge a complaint with the Office of the Privacy Commissioner of Canada at www.priv.gc.ca, or with your provincial privacy commissioner (such as the Office of the Information and Privacy Commissioner for British Columbia, or the Commission d'accès à l'information du Québec).