AIvolve Privacy Policy

    AIvolve Limited (NZBN 9429053285812)

    Last updated: December 27, 2025

    1. Scope and Data Protection Roles

    AIvolve Limited ("AIvolve", "we", "us") is committed to protecting privacy and handling personal information transparently and lawfully. This Privacy Policy explains how personal information is collected, used, stored, disclosed, and protected when the AIvolve platform and related services ("Service") are used. This Policy applies to:

    • Business customers using the Service ("Customers"), and
    • Callers whose personal information is processed through the Service.

    2. Personal Information We Process

    Depending on how the Service is configured by the Customer, AIvolve may process the following categories of personal information.

    2.1 Caller and Contact Information

    • Telephone numbers
    • Names or addresses (if disclosed verbally by the caller)
    • Voicemail messages

    2.2 Call Content and Voice Data

    • Audio recordings of calls
    • Transcripts generated from call audio
    • AI-generated summaries or notes
    • Call sentiment indicators (e.g. neutral, frustrated, urgent), where enabled
    • Acoustic characteristics of speech used for transcription, diarisation (speaker separation), or call handling purposes

    AIvolve does not perform voice identification or biometric identity verification. However, voice audio may be processed in ways that regulators may consider biometric-adjacent in nature.

    2.3 Customer Account Information

    • Business name
    • Contact name and email address
    • Billing and subscription information

    2.4 Technical and Usage Data

    • Call timestamps and duration
    • System logs and diagnostics
    • IP address
    • Device and browser information
    • Device identifiers or fingerprints, where used for security or fraud prevention

    AIvolve does not intentionally collect sensitive personal information unless voluntarily disclosed by a caller during a call.

    3. How We Use Personal Information

    Personal information is processed only for the following purposes:

    • Providing and operating the Service
    • Answering, routing, recording, transcribing, and summarising calls
    • Detecting call intent, urgency, or sentiment (where enabled)
    • Scheduling appointments and sending notifications
    • Producing analytics and reports for Customers
    • Maintaining system security, performance, and reliability
    • Complying with legal and regulatory obligations

    AIvolve does not sell personal information.

    3.1 How We Use Google User Data

    When you authorize AIvolve to access your Google Calendar, we use this data exclusively to:

    • Check booking availability: Read your calendar to verify time slots are free before confirming appointments with customers
    • Create booking events: Add confirmed appointments to your selected Google Calendar
    • Update bookings: Modify calendar events when appointment details change
    • Delete cancelled bookings: Remove cancelled appointments from your calendar
    • Display your schedule: Show your calendar within the AIvolve dashboard for your convenience

    Limited Use Disclosure: AIvolve's use and transfer of information received from Google APIs adheres to Google API Services User Data Policy, including the Limited Use requirements. We only use Google Calendar data to provide and improve the calendar synchronization features of AIvolve, and for no other purpose.

    4. AI Processing and Model Improvement

    4.1 Customer Content Isolation

    Call recordings, transcripts, summaries, and related content ("Customer Content") are logically isolated per Customer.

    4.2 AI Training and Improvement

    • Customer Content is not used to train global AI models in an identifiable form
    • AIvolve may use:
    • Aggregated and anonymised Service Data, and
    • Anonymised transcripts and text-based data (with personal identifiers removed),

    to improve system performance, accuracy, and reliability

    AIvolve does not use raw audio recordings to train models in a way that retains identifiable voice characteristics.

    5. Call Recording and Consent

    Customers are responsible for:

    • Determining whether call recording or transcription is lawful in their jurisdiction
    • Configuring the Service to announce recording where required
    • Obtaining all legally required consents from callers

    AIvolve acts solely on Customer instructions and does not independently verify consent.

    6. Data Storage and Location

    Customer Data is stored using secure cloud infrastructure located in Australia and/or New Zealand, where available. To provide AI processing, transcription, or analytics functionality, certain data may be processed by trusted third-party service providers located in other jurisdictions (including the United States). Where this occurs, AIvolve ensures appropriate contractual and technical safeguards are in place consistent with applicable data protection laws.

    7. Data Retention

    Customer Content is retained while the Customer account remains active

    • Upon termination, Customer Content is retained for up to 30 days to allow retrieval
    • After this period, Customer Content is permanently deleted, unless retention is required by law
    • Aggregated and anonymised Service Data may be retained for analytics and system improvement purposes.

    8. Data Security

    AIvolve implements reasonable and appropriate technical and organisational security measures, including:

    • Encryption in transit (TLS) and at rest (AES-256)
    • Role-based access controls
    • Monitoring and logging

    No system is completely secure, but AIvolve takes reasonable steps to protect information from misuse, loss, or unauthorised access.

    9. Data Breach Notification

    In the event of a suspected or confirmed personal data breach, AIvolve will:

    • Notify the affected Customer without undue delay after becoming aware of the breach
    • Provide information reasonably necessary for the Customer to assess and comply with breach notification obligations

    Customers are responsible for notifying regulators and affected individuals, unless otherwise required by law.

    10. Disclosure and Subprocessors

    AIvolve may disclose personal information to trusted subprocessors, including:

    • Cloud infrastructure providers (for data storage and hosting)
    • Telephony and communications providers (for call routing and SMS delivery)
    • AI, transcription, and analytics service providers (for core service functionality)
    • Security and monitoring providers (for system security and fraud prevention)
    • Payment processing providers (for billing and subscription management)

    All subprocessors are contractually required to protect personal information and use it only to provide services to AIvolve. 👉 A current list of AIvolve subprocessors is available upon request. AIvolve may also disclose information where required by law.

    10.1 Google Calendar Data

    When you connect your Google Calendar to AIvolve, we access your calendar data solely to:

    • Check availability before confirming bookings (to prevent double bookings)
    • Create, update, and delete calendar events for confirmed bookings
    • Display your calendar information within the AIvolve dashboard

    Important: AIvolve does NOT:

    • Sell Google Calendar data to third parties
    • Transfer Google Calendar data to data brokers or information resellers
    • Use Google Calendar data for advertising purposes (targeted, personalized, retargeted, or interest-based)
    • Use Google Calendar data for credit-worthiness determination or lending purposes
    • Share Google Calendar data with any third party except as necessary to provide core service functionality

    Google Calendar data is processed solely to provide and improve AIvolve's calendar synchronization features. Your calendar data remains private and is never used for any purpose beyond the core functionality of the Service.

    11. International Transfers

    Where personal information is transferred outside New Zealand or Australia, AIvolve ensures appropriate safeguards are in place, including contractual protections consistent with GDPR, the NZ Privacy Act, and Australian Privacy Act requirements.

    12. Data Processing Agreement (DPA)

    For Customers subject to GDPR or similar regimes, AIvolve provides a Data Processing Agreement (DPA) upon request, governing processing activities, breach notification, and cross-border transfers.

    13. Individual Rights

    Depending on jurisdiction, individuals may have rights to:

    • Access personal information
    • Request correction
    • Request deletion
    • Object to or restrict processing

    Requests should be directed to the Customer (as Data Controller). AIvolve will assist Customers in fulfilling lawful requests.

    14. Cookies and Tracking

    AIvolve uses cookies and similar technologies on its website and dashboard for authentication, security, and analytics purposes. These do not track callers.

    15. Complaints

    If you believe personal information has been mishandled, please contact us. Unresolved complaints may be escalated to:

    • Office of the Privacy Commissioner (New Zealand)
    • Office of the Australian Information Commissioner (Australia)

    16. Changes to This Policy

    AIvolve may update this Privacy Policy from time to time. Material changes will be notified via the Service or website.

    17. Contact Us

    AIvolve Limited

    NZBN: 9429053285812

    • Email: admin@aivolve.co.nz

    Last updated: December 27, 2025