Legal
Privacy Policy
Last updated: 4 August 2026
1. Overview
Estric ("we", "us") provides an AI front desk platform. This policy explains how we handle personal information under the Australian Privacy Act 1988 (including the Australian Privacy Principles) and, where they apply to you, the privacy laws of the country where you or the business you contacted are located, including the EU/UK GDPR, the New Zealand Privacy Act 2020, Canada’s PIPEDA, US state privacy laws (such as the California Consumer Privacy Act), the Singapore Personal Data Protection Act 2012, the Hong Kong Personal Data (Privacy) Ordinance, and the Malaysia Personal Data Protection Act 2010.
Two roles matter. For information about our business customers (account holders), we act as the data controller. For the conversations, recordings, and contact details of our customers’ end customers ("callers"), we process that information on behalf of the business you contacted; that business decides why and how it is used.
2. What we collect
Account data: name, email, phone number, business details, sign-in credentials (passwordless links and passkeys; we never store passwords), and billing details (handled by Stripe; we do not store card numbers).
Conversation data: the content of calls, messages, and web chats handled by the Service, including audio processed for transcription, transcripts, bookings, leads, and any details a caller provides (such as name and contact number).
Integration data: product and order information from a connected shop, and contact records sent to a connected CRM, as configured by the business.
Technical data: logs, device and usage information, and cookies necessary for sign-in and session state. Our chat widget stores an anonymous session identifier in the visitor’s browser; it does not track visitors across sites.
Cookies: essential cookies keep you signed in and are always on. Any optional analytics cookies load only after you choose "Accept all" in our cookie notice; choosing "Essential only" keeps them off. You can change your choice by clearing site data in your browser.
3. How we use it
To deliver the Service: answering conversations with AI, transcribing calls, booking appointments, capturing leads, sending confirmations and payment links, syncing to connected systems, and showing all of this to the business in its dashboard.
To operate and improve the platform: security, abuse prevention, support, billing, and product analytics on an aggregated or de-identified basis.
Where the GDPR applies, our lawful bases are performance of a contract (delivering the Service), legitimate interests (security, abuse prevention, product improvement), and consent where we ask for it.
We do not sell personal information. We do not use your conversations to train our own or third-party foundation models, and our AI providers are engaged on API terms that do not permit them to train on your data. Separately, we analyse a business’s own conversations to suggest improvements to that same business’s assistant (for example, knowledge base suggestions); these suggestions never leave the business’s account and are applied only with the business owner’s approval.
We send account holders service emails needed to run the account (receipts, security notices, usage and trial reminders); these cannot be opted out of while the account exists. Marketing emails, where sent, always include an unsubscribe link.
4. AI processing and call recording
We use artificial intelligence to process your data. To generate responses, conversation content and the business information needed to answer it are sent to third-party AI providers acting as our subprocessors: large language models operated by Google (Gemini), OpenAI, or Anthropic (the model in use can vary by plan, feature, and load), and speech-to-text / text-to-speech services operated by ElevenLabs. Telephony and SMS are carried by Twilio. Each provider is engaged under API terms that prohibit using your data to train their models.
Call audio is streamed to our speech provider in real time for transcription and reply generation. We do not keep the audio: once a call is transcribed, only the transcript is stored so the business has a record.
Recording and monitoring disclosures are the responsibility of the business you contacted, and requirements vary by jurisdiction. If you do not want a call processed this way, hang up and contact the business directly.
5. Sharing
We share personal information only with: the business whose number or website you contacted (conversations belong to them); subprocessors that deliver the Service (Google Cloud / Firebase for hosting and data storage; Google Gemini, OpenAI, and Anthropic for language models; ElevenLabs for speech; Twilio for telephony and SMS; Stripe for payments; Meta/WhatsApp where used; Resend or an SMTP provider for email); systems the business connects (its shop or CRM); and authorities where the law requires it.
Some subprocessors process data outside your country (including in the United States and Australia). We take reasonable steps to ensure comparable protection, including contractual safeguards, and where the EU/UK GDPR applies we rely on Standard Contractual Clauses as described in the Data Processing Addendum.
6. Retention and security
Conversation data is retained while the business account is active so the business keeps its records, and is deleted or de-identified within 90 days of account closure (export is available for 30 days after termination). Expired trial accounts are kept so you can subscribe later; you may request deletion at any time at [email protected].
We protect data with encryption in transit and at rest, server-side credential storage that is never exposed to browsers, access controls, and tenant isolation. We assess data breaches under the Australian Notifiable Data Breaches scheme and notify affected parties and the OAIC where required. No system is perfectly secure; notify us of concerns at [email protected].
7. Your rights
Account holders can access and update account data in the dashboard, or request a copy or deletion by emailing [email protected]. We respond to access, correction, and deletion requests within 30 days.
Callers: because conversations are held for the business you contacted, direct access, correction, or deletion requests to that business. If you contact us, we will refer the request to them and assist.
You may complain to us first, and to your privacy regulator if unresolved: the Office of the Australian Information Commissioner (oaic.gov.au) in Australia, the Office of the Privacy Commissioner (privacy.org.nz) in New Zealand, the Information Commissioner’s Office (ico.org.uk) in the UK, the Data Protection Commission (dataprotection.ie) in Ireland or your GDPR supervisory authority elsewhere in the EU, the Office of the Privacy Commissioner of Canada (priv.gc.ca), your state attorney general in the US, the Personal Data Protection Commission (pdpc.gov.sg) in Singapore, the Privacy Commissioner for Personal Data (pcpd.org.hk) in Hong Kong, or the Personal Data Protection Department (pdp.gov.my) in Malaysia.
8. Region-specific notices
European Union and United Kingdom: where the GDPR or UK GDPR applies, you have the rights of access, rectification, erasure, restriction, portability, and objection described in those laws, exercisable as set out in section 7. Our Data Processing Addendum governs processing we perform for business customers and incorporates Standard Contractual Clauses for international transfers.
United States: we do not sell personal information and do not share it for cross-context behavioural advertising as those terms are defined in the California Consumer Privacy Act. California residents and residents of other states with comparable laws may exercise access, correction, and deletion rights via [email protected]; we do not discriminate for exercising them.
Canada: we handle personal information consistently with PIPEDA’s fair information principles. Our contact for privacy matters, including access and challenge-of-compliance requests, is [email protected].
New Zealand, Singapore, Hong Kong, and Malaysia: we handle personal information consistently with the Privacy Act 2020 (NZ), the PDPA 2012 (Singapore), the PDPO (Hong Kong), and the PDPA 2010 (Malaysia) respectively, including their rules on access, correction, and cross-border transfer.
9. Children
The Service is not directed at children under 16, and businesses must not configure it to target or solicit information from children. If you believe a child’s personal information has been provided to us, contact [email protected] and we will delete it.
10. Changes and contact
We will post updates to this policy here and notify account holders of material changes. Contact: [email protected].