Privacy Policy
Effective: January 1, 2026 · Last updated: July 7, 2026
AWTC Technology LLC ("INGAVRA," "we," "us," or "our") provides AI-powered phone receptionist services. This Privacy Policy explains how we collect, use, store, and protect your information.
1. Information We Collect
From You (Account & Signup)
- Name, email, phone number, business name, and industry
- Business hours, services offered, pricing, insurance lists, and FAQs you provide during setup
- Payment information (processed by Stripe — we never store card numbers)
From Phone Calls (Through Our Service)
- Caller phone numbers (for booking, transfers, and message callbacks)
- Caller names and information provided during calls (e.g., insurance, date of birth, reason for visit)
- Call recordings and AI-generated transcripts
- Appointment bookings, cancellations, and messages handled by INGAVRA Voice
From the Website Demo
- If you try the live demo on our website: the name, business, email, and phone you choose to enter or say on the call
- The demo call's recording, transcript, and an AI summary, used only to follow up with you about INGAVRA Voice
Automatically Collected
- Website usage data (pages visited, referral source) via standard server logs
- IP address and approximate geographic location
2. How We Use Your Information
- Provide the service: Answer calls, book appointments, handle FAQs, transfer urgent calls, and send daily summary reports
- Improve the service: Review transcripts to improve response accuracy and reduce caller frustration
- Communicate with you: Setup coordination, support responses, billing notices, and optional product updates
- Legal compliance: Respond to lawful requests or enforce our Terms of Service
3. HIPAA & Protected Health Information (PHI)
For healthcare clients: INGAVRA Voice can operate as a HIPAA-covered Business Associate. We will sign a Business Associate Agreement (BAA) with any covered entity. When a BAA is in place, all PHI in call recordings, transcripts, and booking data receives the protections described below and in the BAA.
- Encryption at rest (AES-256) and in transit (TLS 1.2+)
- Access restricted to authorized INGAVRA Voice personnel with role-based controls
- Audit logging of all data access
- 30-day automatic purging of call recordings (configurable per client)
- Annual staff HIPAA training
- Breach notification within 72 hours as required by HHS
4. Data Sharing
We do not sell your data or share it for advertising. We share information only with:
- Sub-processors: Vapi (voice AI infrastructure), Twilio/Vonage (telephony), Stripe (payments), and your calendar provider (Google Calendar, Dentrix, Open Dental, etc.).
- Legal requirements: Court orders, subpoenas, or government requests where legally required.
- Your consent: Only when you explicitly direct us to share data.
5. Data Retention
- Call recordings: 30 days, then automatically deleted (configurable)
- Transcripts: 1 year, then archived or deleted
- Appointment data: Retained as long as your account is active
- Account data: Retained while active; deletion within 30 days of cancellation request
6. Your Rights
Depending on your location (CCPA/CPRA in California, GDPR in EU/UK), you may:
- Request a copy of your personal data
- Request correction or deletion of your data
- Opt out of any non-essential data collection
- Request a list of sub-processors
To exercise any of these rights, email [email protected].
7. California Privacy Rights (CCPA/CPRA)
If you are a California resident, you have the right to:
- Know what personal information is collected and how it's used
- Request deletion of your personal information
- Opt out of the "sale" of personal information (we do not sell data)
- Not be discriminated against for exercising your rights
8. Children's Privacy
INGAVRA Voice is a business-to-business service and is not directed at children under 13. We do not knowingly collect data from children.
9. Security
- All data encrypted at rest (AES-256) and in transit (TLS 1.2+)
- Access controls and audit logging on all systems
- Regular security reviews and dependency updates
- No plain-text storage of passwords or API keys
10. International Data
Data is stored on servers in the United States. If you are outside the US, your data is transferred to and processed in the US under appropriate safeguards.
11. Outbound Calling & TCPA
For clients using the Complete (outbound) plan, we comply with the Telephone Consumer Protection Act (TCPA) and related regulations. We only call numbers where prior express consent or an established business relationship exists, and we honor all opt-out and Do Not Call requests.
12. Cookies
Our website uses minimal session cookies for form functionality. We do not use third-party advertising or tracking cookies. No cookie consent banner is required under current usage, but we will add one if analytics or marketing tools are introduced.
13. Changes to This Policy
We'll notify you of material changes via email or a notice on our website at least 30 days before they take effect.
14. Contact
AWTC Technology LLC
United States