AvenDesk

Privacy Policy

What we hold,
and why.

Two kinds of data pass through this service: what a business gives us about itself, and what its callers say on the phone. The second kind belongs to the business, not to us — and most of this document is about keeping that distinction honest.

Last updated 18 August 2026

The short version

  • Not for hospitals, clinics or anything involving patient records, Social Security numbers or card numbers. We are not HIPAA-compliant and hold no BAA — our Terms list what must never come through it.
  • Every company that touches your data is named, individually, on our Subprocessors page — and our Data Processing Addendum already applies to you, unsigned.
  • We do not sell your data and we do not advertise to anybody. There is no analytics and there are no tracking cookies on this website.
  • But your data passes through other companies to make the service work, and we have no contracts with them. They may use it and they may sell it — we cannot promise otherwise. §10 is the honest version.
  • We use call recordings to improve the receptionist. Set recording to off if you would rather we did not — you keep the written transcript either way.
  • Every call is transcribed; not every call is recorded. Each business chooses, and the default asks the caller for permission first.
  • Switch on form capture and your own website’s contact form copies to us too. That is your visitors’ data — telling them about it is yours to do. §6.
  • If you called a business and want your data deleted, ask that business — it is their record, not ours. §2 says how, and we will pass the request on if you cannot reach them.
  • Some of what passes through is screened automatically against our acceptable-use rules — calls, texts and the wording you give the receptionist. A flag never suspends anybody by itself; a person decides. §13.
  • Our team can read, export, erase and — under a warrant — hand over your data. Every one of those is logged with a name against it. §14 lists the lot.
  • Close your account and everything is deleted 30 days later — a deliberate window, so a misclick cannot destroy your bookings. Invoices we must keep for tax.
  • You can see, correct, export, delete and appeal. We answer within 45 days, and it never costs you anything.

This summary is for orientation only. It is not part of the agreement, and where it differs from the numbered sections below, the numbered sections are what applies.

Who we are, and the two hats we wear

AvenDesk LLC, a Colorado limited liability company (“we”, “us”), runs AvenDesk — an AI receptionist that answers a business’s telephone calls and texts, a website chat widget, and the business portal our customers sign in to. This policy explains what we do with personal information, and it forms part of our Terms of Service.

We handle two quite different kinds of data, and it matters which one you are asking about:

  • The businesses that buy from us. Their account, their billing, their business profile, their usage. We decide what happens to that data — in the language of US privacy law we are the controller of it, and this policy is our own account of what we do.
  • The people who call those businesses. Their name, their number, what they said on the phone. That data belongs to the business, not to us. We are the processor — we hold it and act on it only on that business’s instructions, and it is their privacy policy, not ours, that governs why they collected it.

If you rang a business and ended up here

You probably spoke to an AI receptionist we operate on behalf of a local business — a plumber, an electrician, a garage. We are not that business and we did not decide to collect anything about you. They did, and we hold it for them.

If you want your information corrected or deleted, ask the business you called. They can do it themselves in their portal, immediately. If you cannot reach them, email us at Flowonnco@gmail.com with the business’s name and your telephone number and we will pass the request on and follow their instruction. We will not delete one of their customer records on our own initiative, because it is not ours to delete.

What was captured about your call is set out in §4, and whether it was recorded at all depends on the setting that business chose — §5.

What we collect from a business that signs up

When you open and run an account, we collect:

  • Account and contact details — your name, business name, email address, telephone number, and the password you set (stored only as a scrypt hash, never as text anyone can read).
  • Your business profile — services, opening hours, service area, prices you enter, the jobs you will not take, your escalation number, your receptionist’s name and voice. Some of this we read from your website at setup, and you review and approve it.
  • The address of a website you already have, if you tell us one. We keep it so the portal can point at the right site and so we can check whether a tag you pasted actually landed — §6. Holding the address is not access to the site: we cannot log in to it, change it, or read anything on it that is not public.
  • Billing information — your plan, what you have bought, invoices and receipts. Card details are checked and discarded: what we keep is the card brand, the last four digits and the expiry date, which is what your portal shows you so you know which card is on file. No third party receives them — §10 — and as of today no card has been charged at all, which our Terms set out.
  • Usage — minutes, texts and chats consumed, call counts and durations, error rates and the underlying provider costs we bill against.
  • Support correspondence — what you email us and what we replied.
  • Permissions you have given us — where you have asked us to put one of our tags on your website, we keep a record of it: who agreed, when, the address it was agreed from, and the exact wording that was on the screen. Kept because it is the evidence of what you actually permitted, and deleted with the rest of your account.
  • Technical records — IP address, browser and device information, and sign-in events for the portal, kept for security.

What the receptionist collects from your callers

When someone calls, texts, or uses the chat widget, the Services process and store what they gave, which typically includes: their telephone number, their name, an email address, a service address, what they were calling about, and the appointment they booked — plus a written transcript of the conversation and, where the business’s setting permits it, an audio recording.

Live call audio is streamed to speech-recognition and language-model providers to work out what was said and what to say back, and to a speech provider to say it. That processing is transient: the audio is used to produce the response and, unless the call is being recorded, is not kept by us afterwards.

We ask for as little as the job needs. The agent is built to take a booking, not to interview anybody, and it will not ask for payment card numbers, Social Security numbers or any other government identifier, health information, or biometric data. If a caller volunteers something anyway it ends up in the transcript, which is one of the reasons transcripts sit behind a business’s own login and second factor.

More than that: this service is not sold to businesses whose ordinary work involves that kind of information. No hospitals, clinics, medical or dental practices, therapists, pharmacies or care homes — we are not a HIPAA-compliant service, we hold no Business Associate Agreement with anybody, and the Terms set out the whole of what must never be routed through it. If a caller’s name attached to an appointment would be protected health information in your hands, it is protected health information in ours, and we are not lawfully able to hold it for you.

Call recording and transcription

Every call produces a transcript. Not every call produces a recording. Each business chooses one of three settings: ask the caller for permission before anything is captured (the default), record every call with a spoken disclosure at the start, or never record.

On the consent setting, nothing is recorded unless the caller says yes, and an unclear answer, silence or an ambiguous one is treated as a refusal. That decision is made in ordinary code before the language model ever sees the turn, so it cannot be talked around.

The lawfulness of that choice is the business’s responsibility, not ours — many states require every party to a call to consent. We provide the setting and enforce it; we do not select it for anybody, and our default is not advice.

Recordings and transcripts are visible to the business in its portal, and to us only where we need them to fix a fault, investigate abuse, or answer a lawful demand.

Forms on a website of your own

If you have a website we did not build, you can switch on a small tag that sends us a copy of what people submit through the contact form already on it. It is off until you turn it on, and nothing about your site reaches us before that.

It copies; it does not intervene. Your form still submits where it always did and your own notifications still arrive. What we receive is every named field of the submission as it was filled in — usually a name, a telephone number, an email address, what the job is and when they want it — which we file as an appointment in your portal. A field we do not recognise is kept under its own label rather than dropped, and a date we cannot read is written down as words for you to read rather than guessed at.

Password fields and file uploads never leave the page. A contact form should not contain either, but if yours does, we are not the thing that copies it.

We then send a confirmation to the person who filled the form in, and a notification to you — both in your business’s name, from the same mailbox your booking emails already come from.

This is your visitors’ data and the same division in §1 applies: it is yours, we hold it on your instruction, and it is deleted, exported and corrected exactly like everything else in your portal. Telling your visitors that their submission is copied to a supplier is yours to do, in your own privacy notice, because it is your form on your site and we never see who visits it.

The key that lets your form reach us sits in your page’s source, where anyone can read it, and it is built to be safe there: it can add one entry to your list and do nothing else — it reads nothing back, names nobody, and opens no door to your customer records, your recordings, your settings or your portal. Somebody who copies it can put junk on your appointment list, which you can see and delete, and how many can arrive in ten minutes is capped. You can switch it off, or replace it with a new one, whenever you like.

This website

There is no analytics on avendesk.com. No advertising tags, no tracking pixels, no third-party cookies, no cross-site profiling. We do not know who you are while you read this page, and nothing here is shared with an advertising network.

That is now enforced rather than promised: this site sends your browser a policy that refuses to load a script from anywhere but us, and refuses to let anything on the page send data anywhere but us. If a tracker were ever added here by accident, your browser would block it before it ran.

Three things do get stored in your own browser, and none of them leaves it except as described:

  • Whether the opening animation has already played — one flag in session storage, so the title sequence does not replay every time you change page. It dies with the tab and it says nothing about you.
  • The chat widget’s transcript — kept in local storage so the conversation survives a page change. What you type is sent to our server, which forwards it to a language-model provider to compose a reply.
  • Your signup details between the two steps of checkout — held in session storage, which dies with the tab, so the till knows what the previous page collected. It is never written to a cookie or put in a URL.

When you contact us or sign up

The contact form and the signup flow post directly to our own platform. We use what you send to answer you, to set your account up, and to keep a record of the enquiry. If you ask for a demo we will follow up about it; we do not add you to a marketing list you did not ask for, and every email we do send has an unsubscribe in it.

Signing in from this site sets a session cookie on our platform’s own domain. It is strictly necessary — it is what keeps you signed in — and it is not used for anything else.

Why we use it

We use personal information only for these purposes:

  • To run the service — answer calls, book appointments, send confirmations, write to your calendar, show you your portal.
  • To bill you — take payment, meter usage, produce invoices, and stop a runaway cost.
  • To support you — answer emails, diagnose a fault, restore something.
  • To keep it safe and lawful — detect abuse and fraud, enforce our terms (including the automated screening in §13), meet legal and tax obligations, and respond to lawful requests.
  • To improve the platform — using operational and aggregated figures (counts, durations, error rates) that do not identify a business or a caller.

Who we share it with

We do not sell personal information ourselves, and we do not share it for cross-context behavioural advertising. We take no money for anybody’s data and we hand it to nobody for their own marketing.

What we cannot promise is what happens to it further down the chain. The Services run on other companies’ infrastructure — the call has to reach a carrier, the audio a speech provider, the words a language model — and we have no negotiated data-processing agreement with any of them. We use them on their own published terms, as an ordinary customer. What they do with data that passes through them is governed by those terms, not by this policy. They may use it, and they may sell it. We do not know that they do not, and we will not tell you otherwise.

We are telling you this rather than leaving it out. It is the single most important limitation on everything else on this page, and a business deciding whether to put its callers through this service should decide knowing it.

We used to disclose these by category and name them only on request. We now publish the list. Every company that handles personal information on our behalf is named individually on our Subprocessors page — what it does, what it can see, and where it is — and we update it before a new one starts. The categories are:

  • Telephony and messaging — carrying the calls and texts, and issuing telephone numbers.
  • Speech recognition and speech synthesis — turning call audio into text and text back into a voice.
  • Language models — composing what the receptionist and the chatbot say.
  • Hosting and infrastructure — running the platform and storing your data.
  • Email delivery — sending confirmations, alerts and receipts.
  • Services you connected yourself — your calendar, your mailbox, your Google Business Profile, your CRM. We only ever use the scopes you granted, and only to do what you asked.

How we use recordings to improve the receptionist

We use call recordings and transcripts to make the AI receptionist better. That means listening to calls that went wrong, correcting what it misheard, tuning how it handles a particular trade, testing changes against real conversations before they reach anybody’s phone line, and training and evaluating the models and prompts behind it. A receptionist that never learns from a mishandled call keeps mishandling it.

A business that does not want its audio used this way can set its recording mode to off, which leaves us the written transcript and no recording at all. A caller who does not want to be recorded can simply say no when asked, on the default setting — §5.

We do not sell any of it, and none of it is used to advertise to anybody.

What we cannot control is the providers this passes through — see §10. They may use content that reaches them to train their own systems, under their own terms, and we have no agreement with them that prevents it.

What the receptionist knows about a business comes from the profile that business entered and approved. It is supplied to the model at the time of the call rather than baked into it, so a correction takes effect on the next call rather than months later.

The other times we would disclose something

To our professional advisers, under a duty of confidence. To comply with the law, a court order, or a lawful request from a public authority — see §14 for exactly how that works. To establish or defend a legal claim. To protect somebody’s life or safety. And, if the business is ever sold or merged, to the buyer, under the same commitments as this policy, with notice to you first.

Automated screening for rule-breaking

Some of what passes through the service is screened automatically, against the acceptable-use rules in our Terms. This is done by pattern-matching in ordinary code — no human reads anything as a matter of routine, and no AI judges anybody.

Four things are checked: what the receptionist says on a call (its own turns, not the caller’s); the text messages a business sends, including an attempt to message somebody who has opted out; the wording a business types into its own profile for the receptionist to speak; and how many texts a business sends in a day, against its own normal.

A match records a flag, and a flag does nothing on its own. No account is suspended, throttled or closed automatically. Every flag names the rule behind it, why it fired, and — deliberately — what it does not prove, and a member of staff decides what if anything happens next. Most of these signals have an innocent explanation and the tool that shows them says so.

A flag stores a short excerpt as evidence — the matched words from a call, or up to 200 characters of a text or profile field. It never stores a full transcript. That evidence is deleted with the account, on the same 30-day timetable as everything else in §16.

We do not screen what your callers say to you, and we do not screen inbound messages. The receptionist speaks in the business’s name and the business is answerable for it; a caller is answerable for their own words to somebody else.

What our own team can do

Being straight about this is the point of the section. Our staff operate an admin console that sits above every account, and from it we can do the following. None of it is theoretical — each is a button somebody can press.

  • See your data. Bookings, messages, call records, transcripts and recordings, to fix a fault, investigate abuse, or answer a demand we are legally obliged to answer.
  • Produce everything we hold about one person, on a telephone number, as a file — a subject access request, whether it came from the business or from the caller through them.
  • Erase it. Every record we hold about a caller, across bookings, messages, calls, texts and customer records, permanently.
  • Hand data to law enforcement. Only under a warrant, subpoena or court order, and the tool that does it cannot be used without recording which one — a request made over the telephone with nothing behind it is refused.
  • Suspend or close an account, and destroy it early or bring it back during the 30 days described in §16.
  • Change a business’s settings, including its recording mode, when it asks us to.
  • Install or remove one of our tags on a website we host for that business — never on a website we do not host, which we have no access to, and never without the recorded permission described in the Terms.

And what stops us abusing that

Every export, erasure and disclosure is written to a ledger before it is carried out — what was done, to whose records, by which member of staff, and for a disclosure, which authority demanded it and under what reference. It is not optional and it cannot be skipped: the tools refuse to run without a name attached.

We tell the business before we hand their data to a public authority, unless a non-disclosure order makes telling them unlawful in itself. That exception is real and it is why this is not phrased as an absolute. Which of the two applied is one of the fields recorded in the ledger, so it can be shown afterwards that the silence was compelled rather than convenient.

We will not erase a caller’s records on our own initiative. They belong to the business, and a deletion we performed because somebody emailed us would be us destroying our customer’s records on a stranger’s say-so — §2 is how that request is meant to travel.

Access to production data is limited to the people who need it and is logged. If you want to know whether anything about your account has been exported or disclosed, ask, and we will tell you what the ledger says.

How long we keep it

While your account is open, we keep your data so you can use it — bookings, customers, transcripts and recordings stay in your portal until you delete them, and you can delete any of them yourself at any time.

When you close your account, access ends immediately and the data is destroyed 30 days later. The gap is deliberate: deletion has no undo, and a misclick, a shared login or a departing employee should not be able to obliterate every record a business has. Ask us during those 30 days and we will restore it; after them it is gone.

Two things outlive that. Invoices, receipts and tax records are kept for the period the law requires, because we do not have the option. And security and abuse logs are kept in a form that records what happened rather than what anybody said. Our rule is not to keep them beyond 12 months, and we apply it by hand rather than on a timer — so treat it as the ceiling we hold ourselves to, not as something a machine enforces.

Where your data is processed

We and our providers are in the United States, and that is where your data is stored and processed. If you or your callers are outside the US, using the Services means the data is transferred there, and US law will not always give it the protections your own country does.

We do not have Standard Contractual Clauses or an equivalent transfer mechanism in place, because we do not have negotiated agreements with our providers at all (§10).

There is now a Data Processing Addendum, it applies to every customer automatically, and nobody has to sign or request it. It is a real, binding commitment for US state privacy law — and it says plainly what it does not cover. If your business is subject to UK or EU data protection law, or your compliance file needs SCCs or a full Article 28 chain, this service still cannot satisfy it. Ask us before you sign up rather than after.

How we protect it

Passwords are stored as scrypt hashes with a per-account salt — a leak of our data would not hand anybody a usable password, and we cannot read yours. The portal supports an authenticator-app second factor, and we recommend turning it on: your portal shows real customers’ names, numbers and home addresses, and anyone with your login can see all of it.

Traffic is encrypted in transit. Access to production data inside our team is limited to the people who need it and is logged. Sign-ins are rate-limited per network and locked out per account after repeated failures, before any password check runs.

Changing your password signs out every other session immediately — every device and every browser, everywhere, except the one you are changing it from. Resetting a forgotten password signs out all of them including that one, and closing the account does the same. So if you think somebody else is inside your portal, changing your password is the thing that removes them, and it takes effect on their next click rather than when their session happens to expire.

No system is perfectly secure, and we will not claim otherwise. If a breach affects your personal information, we will tell you and the relevant regulator within the time the law requires, with what we know and what we are doing about it.

If you have found a hole in this, tell us. Where to send it, and what we ask of you before you do, is published at avendesk.com/.well-known/security.txt — the standard address for exactly this. We would far rather hear it from you than read about it later.

Your rights, and how to use them

If you are a business customer, or a Colorado resident, you have the right to know what we hold and get a copy of it, to correct it, to delete it, to take it elsewhere in a portable form, and to opt out of the sale of your data, of targeted advertising, and of profiling with legal effects. As above, we do not sell data, do not advertise to you and do not profile you — but the right is yours regardless, and exercising it costs you nothing.

On universal opt-out signals, plainly: we do not currently detect Global Privacy Control or any similar browser signal. There is nothing here for one to switch off — no sale, no targeted advertising, no profiling, and no analytics on this site at all. If that ever changes, detecting the signal will change with it, and this paragraph will say so.

We will never charge you for exercising a right, and we will never treat you worse for having used one.

How a copy actually reaches you: there is no self-serve export button in the portal yet. Email us and a member of staff produces the file — everything we hold, including on a single telephone number if that is what you are asking about. It is free, and it is the same tool described in §14.

Email Flowonnco@gmail.com from the address on your account. We answer within 45 days, and if a request is genuinely complex we may take one further 45 days and will tell you why before we do. We may need to verify who you are before we hand anything over, which for an account holder normally means signing in.

If we refuse a request, you can appeal it. Reply to our refusal saying you are appealing, and a different person reviews it and responds within 45 days. If that appeal is denied you may complain to the Colorado Attorney General, or to your own state’s regulator. Wherever you are, you may also raise it with the supervisory authority for your country.

If you are in California

The categories of personal information we have collected in the last 12 months are: identifiers (name, email, telephone number, IP address); customer records (business and billing details); commercial information (what you bought and used); internet activity limited to your own use of our portal; audio and electronic information (call recordings and transcripts); geolocation only to the extent an address was given to us; and inferences we draw for operational purposes such as usage forecasting. Where each came from, why we have it and who we disclose it to are set out in §3 to §10.

We have not sold personal information for money, and we have not shared it for cross-context behavioural advertising, in the last 12 months — including any information about anyone we knew to be under 16. We do not use or disclose sensitive personal information for any purpose that would require an opt-out under the CCPA.

One honest caveat. Disclosing data to a vendor normally falls outside the CCPA’s definition of a “sale” only where a service-provider contract restricts what the vendor may do with it. We do not have those contracts (§10). We therefore state what is true — we receive nothing for anybody’s data and pass it to nobody for marketing — rather than claiming an exemption we cannot demonstrate. If you want to opt out of that disclosure, the only effective way is not to route calls through the service, because the disclosure is how the call gets answered at all. Email Flowonnco@gmail.com and we will talk it through.

Your CCPA rights — to know, delete, correct, opt out and be free from retaliation — are exercised the same way as §19, and an authorised agent may act for you with written permission we can verify.

Children

The Services are sold to businesses and are not directed at children. We do not knowingly collect personal information from anyone under 16. If a child’s information reaches us — most likely because they rang one of our customers — tell us and we will delete it, or instruct the business to, as §2 describes.

Changes to this policy

We will update this page when what we do changes. We will email the address on your account, and a change takes effect 3 days later — the same notice period as our Terms, which set out the full rule and the four things that cannot move that fast.

Where the law demands more, the law wins. If the Colorado Privacy Act, the CCPA or any other statute that applies requires longer notice, a particular form of notice, or your explicit consent before a change — a change that would widen how we use information we already hold, or start a sale or a targeted-advertising share — we follow the statute instead of the 3 days. We will not use this section to skip a consent we are required to obtain.

A change never applies backwards. Information we already collected stays handled under the policy that was in force when we collected it, unless the newer one protects you better. The date at the top is when it last changed, and we will send you a previous version on request.

Contact us

Privacy questions, requests and appeals all go to Flowonnco@gmail.com. Put “Privacy” in the subject line and we will route it properly.

Make a request

Ask us for it, and it is yours.

A copy of everything we hold, a correction or a deletion — email us and say which. No form to fill in, no charge, and an answer within 45 days. If you came looking for a Data Processing Addendum, it already applies to you and needs no signature.

Flowonnco@gmail.com

At a glance

Controller
AvenDesk LLC, for business account data
Processor
For caller data, on the business’s instruction
Data sold
None — and none shared for advertising
Subprocessors
Named individually, on their own page
Not for
Health, financial or government-ID data
Model training
Recordings and transcripts, unless you set recording to off
Deletion
30 days after an account closes
Response time
45 days, appeal within 45 more
Last updated
18 August 2026

Read alongside our Terms of Service.