Avello Systems — Privacy Policy
Last updated: July 22, 2026
Avello Systems ("Avello," "we," "us," or "our") provides AI-powered voice agents, automated receptionist services, and related call-handling and workflow-automation software, offered through avellosystems.com and our platform.
We are a small company. This policy is written to be clear about what we do with personal information — and, importantly, about the difference between the information we handle for our own business and the information we handle on behalf of the businesses that use our service.
It applies when you visit our website, contact us, request a demo, subscribe to or use our services, interact with an AI voice agent powered by Avello, or call a business that uses our technology.
Avello is incorporated in Singapore. Our team accesses and administers data from Canada, and our servers and most of our technology providers are in the United States. Depending on the situation, the laws that may apply include Singapore's Personal Data Protection Act (PDPA), Canada's PIPEDA and provincial equivalents, the California Consumer Privacy Act (as amended), and other US state privacy laws.
1. Our Role: When We Decide, and When Our Customers Decide
We handle personal information in two different capacities.
When we act as the controller (our own data). For our website, sales, demos, billing, support, recruiting, and security, we decide why and how information is used. This policy governs that information.
When we act as a processor (our customers' data). When a business uses Avello to answer calls, talk to callers, book appointments, qualify leads, transfer calls, or automate workflows, we generally handle that call information on the customer's behalf and under their instructions. In those cases the customer decides what the agent asks, what it collects, where calls go, and how long their records are kept. If you interact with an Avello-powered agent, the privacy practices of the business you called may also apply. If you send us a privacy request about information we hold only for a customer, we may forward it to that customer or help them respond.
2. Information We Collect
Information you give us directly. When you request a demo, subscribe, set up an account, complete onboarding, contact us, or apply for a job, we may collect your name, business name and address, email, phone number, role, region, billing details, and anything else you choose to share.
Information processed during AI voice calls. Our standard voice service records and transcribes calls. When someone interacts with an Avello-powered agent, we may process the caller's and called numbers, name, voice and audio, the recording and transcript, call time and duration, what was said, service address, appointment preferences, the service requested, a description of the problem, urgency, booking and routing details, and an AI-generated summary and structured data drawn from the conversation. For home-services customers this can include details about plumbing, heating, cooling, electrical, or property-maintenance needs. Exactly what's collected depends on how the customer configured their agent.
Customer knowledge-base information. Customers give us business information — hours, services, pricing, service areas, FAQs, policies, documents — that their agent uses to answer callers. Customers are responsible for having the right to share what they upload.
Information collected automatically. When you use our website we collect technical data such as IP address, browser and device type, approximate location from IP, pages visited, referring site, and cookie and session identifiers.
Information from public and third-party sources. For business development we may collect professional contact information from public business websites, Google Business Profiles, professional networks, directories, and referral partners.
3. How We Use Information
We use personal information to:
-
Provide the voice service — answer calls, talk to callers, qualify leads, answer questions from the customer's knowledge base, flag emergencies, route and transfer calls, book appointments, and create recordings, transcripts, and summaries;
-
Run automations and integrations — move information between authorized systems, trigger workflows, update CRMs and calendars, send SMS and email notifications, and record usage for billing;
-
Operate our business — manage accounts, run demos and onboarding, process payments, provide support, maintain security, prevent fraud and abuse, keep records, and meet legal obligations;
-
Improve our service, as described in Section 4; and
-
Communicate with businesses about sales and marketing where the law allows. You can unsubscribe from marketing emails at any time; we'll still send necessary account, billing, and service messages.
4. AI Learning and De-Identification
We may use call content to test and improve our service — for example, to improve comprehension, handle accents and interruptions, reduce errors, and improve emergency classification and booking accuracy.
Before call content is used for this kind of longer-term learning, we apply reasonable measures to remove or mask direct identifiers such as names, phone numbers, email addresses, full service addresses, and account identifiers, and we store that learning copy separately from the operational records our customers use to identify and contact callers. We don't use the learning copy to identify, contact, profile, market to, or make decisions about any individual caller.
Because callers sometimes say identifying details out loud, we can't promise any recording or transcript is perfectly anonymous, so we treat de-identification as an ongoing safeguard rather than a one-time guarantee. We don't sell call content, and we don't use caller names, numbers, emails, or addresses for advertising. We may keep de-identified and aggregated information longer than identifiable information where it's reasonably needed for testing, analytics, and product improvement.
5. AI, Automation, and Our Providers
We don't run our own foundation model. We build on third-party technology, and the specific providers involved in any given call depend on how it's configured. Our stack includes:
-
A voice AI orchestration platform (currently Vapi) that ties together telephony, speech recognition, AI models, voice generation, recording, transcription, transfers, and call analysis;
-
Underlying AI, speech-to-text, and text-to-speech providers (which may include vendors such as OpenAI, Deepgram, and Cartesia) that process the audio, transcripts, and prompts needed to understand callers and generate responses;
-
A workflow-automation tool (currently n8n) that moves information between systems and triggers actions like notifications, bookings, and CRM updates;
-
Payment processing (currently Stripe), website and application hosting (currently Lovable.dev), and business email (currently Zoho); and
-
Telecommunications providers for phone numbers, calling, routing, transfers, recording, and SMS.
We choose providers based on performance, reliability, security, functionality, geography, and cost, and we may change them as the service evolves. Where a provider's settings allow, we configure it to limit use of our customers' data for that provider's own general-purpose model training. We don't use caller voices to create authentication voiceprints unless that's expressly disclosed for a specific service.
6. Call Recording and AI Disclosure
Calls on our standard service are recorded and transcribed. Depending on where a caller is located, the law may require that callers be told they're speaking with an AI, that the call is recorded and transcribed, and that information is processed using AI.
Publishing this policy does not, by itself, satisfy those requirements. Recording-consent and AI-disclosure obligations are usually met with a spoken notice at the start of the call. Avello and each customer are responsible for their own obligations around call recording, AI disclosure, consent, automated calling, and messaging. Customers must configure and use Avello lawfully and provide any notices or consents their jurisdiction requires. We can offer standard disclosure language and features to help, but that doesn't replace the customer's responsibility to meet its own legal requirements.
7. How We Share Information
We share personal information only as needed to run our business and provide the service:
-
Service providers in the categories above (AI and voice technology, automation, telecommunications, hosting and cloud, payments, email and communications);
-
Customer-authorized integrations such as calendars, CRMs, and scheduling tools connected at a customer's direction;
-
Professional advisers such as lawyers, accountants, and auditors;
-
Parties to a merger, acquisition, financing, or similar transaction; and
-
Government authorities or others where reasonably necessary to comply with law, respond to valid legal process, protect our rights, or prevent fraud, abuse, or security threats.
We don't sell personal information for money.
8. International Data Transfers
Because of where we operate and where our providers sit, personal information may be stored or processed in Singapore (our place of incorporation), the United States (our servers and most providers), Canada (where our team accesses and administers data), and India (our email provider, Zoho), as well as other locations where authorized providers operate. Privacy laws in these countries differ from one another. Where the law requires it, we use appropriate contractual and technical safeguards for cross-border processing. Unless we agree otherwise in writing, we don't guarantee data residency in any particular country.
9. Data Retention
We keep personal information as long as reasonably necessary for the purposes it was collected — to provide the service, maintain accounts and call records, calculate billing, troubleshoot, prevent fraud, resolve disputes, and meet legal, tax, and contractual obligations. Retention varies by data type, customer configuration, and provider settings. Caller-identifying records and de-identified learning data may have different retention periods, and de-identified or aggregated data may be kept longer for testing, analytics, and improvement. When a customer's account ends, their identifiable information is deleted, returned, or retained as required by our agreement, their instructions, backup schedules, and the law.
10. How We Protect Information
We use reasonable administrative, technical, and organizational safeguards — including separating caller-identifying information from AI-learning content, masking direct identifiers, encryption in transit (and at rest where supported), access controls, authentication, monitoring, backups, and incident-response procedures. We also rely on the security of specialized cloud and technology providers. No system can be guaranteed completely secure, so we can't promise absolute security.
If we become aware of a confirmed security incident involving personal information, we'll investigate, work to contain it and limit harm, and notify affected customers, individuals, regulators, or others where the law or our contracts require. Where we're acting on a customer's behalf, we'll cooperate with them on their breach obligations.
11. Your Privacy Rights
Your rights depend on where you live and the situation. Depending on the applicable law, you may be able to request access to your information, correct it, delete it, receive a copy, withdraw consent, object to or restrict certain processing, opt out of marketing, opt out of the "sale" or "sharing" of personal information, limit certain uses of sensitive information, and file a complaint with a regulator. These rights aren't absolute and are subject to legal exceptions and identity verification.
United States. California residents have rights under the CCPA/CPRA, including to know, access, delete, and correct information, opt out of sale or sharing, and limit the use of sensitive personal information, plus protection from discrimination for exercising them. Residents of other states with comprehensive privacy laws — including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and a growing number of others — generally have similar rights to access, correct, delete, and obtain a copy of their information, and to opt out of targeted advertising and sale. To exercise any of these, contact us at the address below. We don't sell personal information for money.
Canada. Where PIPEDA or provincial law applies, you may request access to and correction of your information and may complain to the relevant privacy regulator.
Singapore. Where the PDPA applies, you may request access to and correction of personal data in our control, subject to applicable exceptions.
Where we hold information only on behalf of a business customer, we may direct or forward your request to that customer and assist them in responding.
12. Sensitive Information
Callers should avoid sharing unnecessary sensitive information during AI calls. Unless specifically agreed and configured for a use case, our standard service isn't meant to collect government ID numbers, passwords, full payment-card or bank credentials, highly sensitive medical information, information subject to HIPAA, or biometric authentication data. Customers should configure their agents to collect only what the business genuinely needs.
13. Children
Our service is built for businesses and isn't directed at children, and we don't knowingly collect children's information to create accounts. Someone calling a business that uses Avello could be a minor; customers are responsible for complying with laws about minors' information. If we learn information was collected unlawfully, we'll take reasonable steps to delete it.
14. Cookies
We use cookies and similar technologies for essential website functionality, security, session management, remembering preferences, analytics, and — where permitted — marketing. You can control cookies through your browser or any cookie tool we provide; disabling some may affect functionality.
15. Changes to This Policy
We may update this policy as our products, providers, and legal requirements change. We won't necessarily update it just because we swap one provider for another that does substantially the same thing. The date at the top shows when it last changed, and where the law requires, we'll give additional notice of material changes.
16. Contact Us
Avello Systems
60 Paya Lebar Road, #06-28, Paya Lebar Square, Singapore 409051
Email: support@avellosystems.com
Website: avellosystems.com
If we process your information only on behalf of a business customer, you can also contact that business directly.
