Privacy Policy
1. Introduction
Eliza ("we", "us", "our") is an AI-powered telephone receptionist and appointment-scheduling service designed for appointment-based businesses of any kind.
Eliza is operated by [[COMPANY LEGAL NAME]], [[REGISTERED ADDRESS]], Romania (company registration number [[REGISTRATION NUMBER]], VAT [[VAT NUMBER]]). We are the data controller for the account data of Business Users. For the personal data of Callers we act as a processor on behalf of each Business User: the business decides why an appointment is taken and what is done with it, and we handle that data on their instructions. Questions and requests about your data go to info@baum.ro.
This Privacy Policy explains what personal data we collect, why we collect it, how we use and protect it, and what rights you have over it. It applies to all users of the Eliza platform, including business owners who register an account ("Business Users") and their customers who interact with Eliza over the phone ("Callers").
By using Eliza, you agree to the practices described in this policy.
2. Information We Collect
Business Account Data
When you register and configure your Eliza account, we collect:
- Your email address and hashed password
- Business name, phone number, email address, and timezone
- Staff member names, phone numbers, and email addresses
- Working hours and schedule configurations
- Service names, durations, and pricing
Caller Data
When a customer calls your business number and interacts with Eliza, we may collect and store:
- The caller's phone number (provided automatically by the telephone network via Twilio)
- The caller's name, as stated during the conversation
- Appointment details: requested service, preferred staff member, and chosen date and time
- A short numeric PIN generated for appointment verification or cancellation
Call Logs and Metadata
We retain metadata about each call handled by Eliza, including:
- Origin and destination phone numbers
- Call start time, duration, and final status
- Whether an appointment was booked, rescheduled, or cancelled
- A one-sentence AI-written summary of how the call went, shown in your dashboard. It is generated without the caller's name, phone number, e-mail address or PIN
Voice and Conversation Data
Visits to This Website
When you open one of this website's public pages — the home page, the FAQ, this policy or the terms — our server records your IP address, the country that address is registered to, the page, the time, and the identification string your browser sends with every request (its user agent). The country is looked up on our own server, from a database kept there; your address is not sent to anyone else for this. We use these records to see how many people visit the website and from where, and to tell people apart from automated traffic. No cookie is set for this, and nothing follows you to any other website.
3. How We Use Your Information
We use the data we collect to:
- Operate the Eliza service — answering calls, booking and managing appointments
- Display appointment and call-log history in your business dashboard
- Authenticate and manage your account securely
- Determine staff availability and match callers to the right team member
- Improve reliability and diagnose technical issues within the platform
We do not sell personal data to third parties. We do not use Caller data for advertising or any purpose beyond operating the appointment scheduling service for the business you called.
4. Legal Basis for Processing
We process personal data only where the law gives us a basis for doing so. Which basis applies depends on what the data is for:
- Running the service — answering calls, checking availability, and creating, moving or cancelling appointments. Performance of a contract with the Business User (Article 6(1)(b) GDPR) and, as regards the caller, the legitimate interest that both they and the business have in the appointment actually being arranged (Article 6(1)(f)).
- Your account and subscription — registering you, signing you in, taking payment. Performance of a contract (Article 6(1)(b)) and, for invoicing and accounting records, a legal obligation (Article 6(1)(c)).
- Keeping the platform working and safe — rate limits, the PIN attempt budget, blocking abusive callers, diagnosing faults. Our legitimate interest in a service that is neither abused nor broken (Article 6(1)(f)).
- Publishing your business details, if you switch it on. Your consent (Article 6(1)(a)), which you can withdraw at any time using the same switch.
- Knowing who visits this website — counting visits to our public pages and where they come from. Our legitimate interest in understanding how our website is used and keeping it safe (Article 6(1)(f)). You can object to it at any time (see Section 10).
We do not rely on consent for caller data, and Eliza does not ask callers for it. At the start of every call Eliza says what it is and that the caller's name, number and appointment details are stored in order to make the booking. That is the information Articles 13 and 14 require us to give, not a consent request, and the call does not stop to wait for an answer — the caller has rung up precisely so that those details will be used. If a caller does object, we do not process them anyway: Eliza hands the call to a human instead.
5. Third-Party Services
Eliza relies on the following third-party infrastructure providers. Each has its own privacy policy that governs how they handle data passed through their systems.
Twilio
All telephone calls are routed through Twilio's voice platform. Twilio receives call metadata (phone numbers, timestamps, duration) and may retain records in accordance with their own retention policies. Please review Twilio's Privacy Policy.
Google Gemini API
Real-time voice understanding and AI responses are powered by Google's Gemini API, which is the default for every account. Audio streams are sent to Google's servers for processing. We do not receive or store the raw audio after the call ends. Please review Google's Privacy Policy.
OpenAI
After a call ends, its text transcript is sent to OpenAI once to produce the short call summary shown in your dashboard. The transcript is not stored by us, and the summary is written without the caller's name, phone number, e-mail address or PIN. Please review OpenAI's Privacy Policy.
Hosting and Database
Appointment and account data is stored in a PostgreSQL database hosted on infrastructure we control. Data is not shared with hosting providers beyond what is technically necessary to operate the service.
Stripe
Subscriptions and pay-per-call top-ups are processed by Stripe. Card details are entered on Stripe's own checkout page — we never see or store a full card number. We hold your Stripe customer and subscription identifiers, your plan, and the amounts due or paid. Please review Stripe's Privacy Policy.
E-mail and SMS
Verification codes, alerts and other transactional e-mail are sent from our own mail server. SMS confirmations to your customers, and the notifications your staff receive, are sent through Twilio and are covered by the same terms as calls.
6. International Data Transfers
Our own servers and database are in Europe. Several of the providers in Section 5 are headquartered in the United States, however, and personal data may be processed outside the European Economic Area by Twilio, Google, OpenAI and Stripe.
Where data leaves the EEA, the transfer is made under the European Commission's Standard Contractual Clauses, or under the EU–US Data Privacy Framework where the provider is certified under it. You can ask us which applies to a particular provider and for a copy of the safeguards in place.
7. Data Retention
Business account data is retained for as long as your account is active. Deleting your account starts a 30-day countdown and shows you the exact date: nothing is erased in the meantime, the service keeps working, and you can cancel the request at any point before that date. On that date your account and everything belonging to it are permanently erased, unless we are required to retain something by law.
Call-related data is purged automatically on a fixed schedule, whether or not you ask. 30 days after an appointment has taken place, everything personal about it is erased — the caller's name, phone number and PIN, and the customer record behind them — while the booking itself stays in your history. Phone-book entries are deleted 180 days after that number last called. The caller's name on a browser call is cleared after 90 days. Voicemail transcripts and call summaries are deleted once they are 180 days old. A number blocked automatically after abusive calls is released after 365 days; a number you block by hand is kept, together with the reason you gave, until you unblock it — that is a standing decision of yours rather than a log that has gone stale. You may request earlier deletion at any time.
Caller data (name, phone number, appointment details) is stored only for as long as needed to fulfil the appointment and is tied to the above retention window.
Records of visits to this website (Section 2) are deleted automatically 90 days after the visit.
8. Data Security
Passwords are never stored in plain text — we use bcrypt hashing. All data in transit is protected using TLS encryption. Your data is stored in a managed database that is backed up automatically and regularly, so it stays safe even in the event of a hardware failure. Access to customer and appointment data is scoped to the authenticated business account that owns it; one business cannot access another's data, and we do not access, sell, or share your business's data in the ordinary course of business.
While we take reasonable precautions, no system is completely immune to security risks. We encourage Business Users to use strong, unique passwords and to contact us immediately if they suspect unauthorised access.
9. Cookies
Eliza sets two cookies. We use no analytics, advertising or tracking cookies at all, and neither of these follows you to any other website.
- session — a signed cookie that keeps you signed in to the dashboard. Strictly necessary: without it there is no way to stay signed in. It is cleared when you sign out, and stops working by itself if your password changes.
- lang — remembers which of the three languages you chose, for a year, so pages come back in it. Set only when you pick a language yourself.
Because both are either strictly necessary or set by an action you took yourself, no cookie banner is required. You can block or delete them in your browser, but the dashboard cannot sign you in without the session cookie.
10. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access the personal data we hold about you
- Correct inaccurate or incomplete data
- Delete your data ("right to be forgotten")
- Restrict how we process your data in certain circumstances
- Port your data to another service in a machine-readable format
- Object to processing we carry out on the basis of our legitimate interests
- Complain to a data protection supervisory authority
To exercise any of these rights, please contact us at the address in Section 14. We will respond within 30 days.
Callers who wish to have their appointment data or phone number removed from a business's records may contact that business directly, or reach us and we will facilitate the request.
If you believe we have mishandled your personal data you can lodge a complaint with your national supervisory authority. In Romania that is the National Supervisory Authority for Personal Data Processing (ANSPDCP), dataprotection.ro. We would much rather you came to us first at info@baum.ro so that we can put it right.
11. Children's Privacy
Eliza is not directed at children under the age of 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.
12. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date at the top of this page. For significant changes, we will notify registered Business Users via email. Continued use of Eliza after changes are posted constitutes acceptance of the updated policy.
13. Publishing Your Business Details
Your call link page is reachable by anyone who has the link. Separately, you may choose to publish that page: this adds your business details to it and allows search engines to list it, so that customers can find you without having been sent the link.
Publishing is off unless you turn it on, in Settings → Call Handling. We never enable it for you. When it is on, the page shows your business name and your services, with their duration and price. Three further details are each their own separate choice, and each is off until you enable it: your business description, your address, and your staff members' names together with their working hours. Your telephone number is never published.
If you publish your staff members' names and hours, you are publishing information about other people. You are responsible for making sure you are entitled to do so — normally by informing them and, where required, obtaining their agreement. Publish only what those people would be content to see on a public web page.
You can stop publishing at any time using the same switch. We stop serving the details immediately and remove the page from our sitemap on the next request. We cannot control how quickly a search engine drops what it has already stored: published details may remain visible in search results and caches for some time afterwards, and copies made by others while the page was public are outside our control.
14. Contact
If you have questions about this policy, wish to exercise your data rights, or need to report a concern, please contact us at:
Email: info@baum.ro