This Policy explains how GetAlo processes account, workspace, billing, and call-operation data. A customer organization is generally the controller of caller data placed into its workspace; GetAlo processes that data to provide the configured service.
1. Data we process
- Account data such as name, work email, password hash, verification status, workspace membership, role, and session activity.
- Workspace configuration such as flows, revision history, managed phone-number routing, retention, and spend limits.
- Call-operation data such as masked phone identifiers, timestamps, duration, outcomes, provider event IDs, redacted transcripts, and tool execution status.
- Billing data such as plan, usage ledger, invoice metadata, and a payment-method summary. Full card details are handled by Stripe and are not stored by GetAlo.
2. Why we use data
We use data to authenticate users, isolate tenants, run published voice flows, prevent duplicate provider actions, meter usage, provide support, detect abuse, protect the service, and comply with legal obligations. We do not sell personal data.
3. Voice and transcript handling
Live audio is relayed through GetAlo's managed voice service. Final transcript source text is encrypted at rest. Product endpoints expose only redacted final segments. Workspace owners select the transcript retention period; expired segments are removed by the retention worker. Recording remains off unless a future recording feature is explicitly enabled and configured.
4. Service providers
To provide the managed service, data may be processed by OpenAI for conversation and transcription, ElevenLabs for speech synthesis, Twilio for telephony and messaging, Stripe for billing, and infrastructure providers used to host the application and databases. Customers may also configure their own HTTPS action endpoints.
5. Security and retention
GetAlo uses tenant-aware authorization, PostgreSQL row-level security, encrypted infrastructure credentials, encrypted transcript source text, signed webhooks, short-lived runtime tokens, role checks, rate limits, and durable event sequencing. No security program eliminates all risk, so suspected incidents should be reported promptly.
6. Your choices and rights
Workspace members can update profile information through an owner or administrator. Workspace owners control members, transcript retention, and subscription state. Requests to access, correct, export, restrict, or delete personal data can be sent to the address below; identity and authority may need to be verified.
7. International processing
GetAlo subprocessors may process data in countries different from the caller or workspace member. GetAlo applies its configured data-region and contractual safeguards; customers remain responsible for configuring flows consistently with applicable law.
8. Contact
Privacy questions and rights requests should be sent through the verified privacy contact published by the operator of this deployment. For this installation, email [email protected].