Legal
Privacy Policy
This policy explains how Aerlou collects, uses, stores, and protects personal data when you, your team, or your callers interact with the Aerlou platform, including the website at aerlou.com and the AI voice, SMS, and CRM integration services. By using Aerlou you agree to the practices described below.
Who we are
Aerlou operates an AI front desk platform for phone-heavy businesses, including healthcare practices, automotive dealerships, and real estate offices. The service is offered through aerlou.com and connected products. Privacy inquiries can be sent to privacy@aerlou.com.
Scope and acceptance
This policy applies to anyone who creates an account, configures an AI agent, places or receives a call routed through Aerlou, or otherwise interacts with the platform. Where Aerlou processes data on behalf of a business customer, that customer is the data controller and Aerlou acts as processor. Customers are responsible for the lawful collection and use of caller, patient, and contact data they push through the platform.
What data we collect
3.1 Account and team data
Name, work email, role, business name, billing information processed by our payment provider, login credentials, and account preferences.
3.2 Caller, patient, and contact data
Phone numbers, names, voice interactions, SMS messages, appointment details, intent and routing notes, and any context the caller provides during the conversation. Customers are responsible for obtaining consent from data subjects where required by law.
3.3 Voice recordings and transcripts
Where call recording is enabled, Aerlou stores the audio file and a written transcript so that bookings, routing, and follow-up can be reconstructed. Customers control recording configuration and are responsible for two-party consent notices where applicable in their jurisdiction.
3.4 Integration data
When a customer connects a CRM, EMR, calendar, or messaging tool, Aerlou exchanges only the data needed to complete the requested workflow, such as patient or contact records, calendar availability, and appointment outcomes.
3.5 Usage and technical data
Device and browser information, IP addresses, session logs, call metadata such as duration and outcome, and product analytics generated through normal use of the platform.
How we use your data
| Purpose | Legal basis |
|---|---|
| Operating the AI voice and SMS service | Performance of contract |
| Routing calls, booking appointments, and following up | Performance of contract |
| Syncing transcripts and outcomes to your CRM or EMR | Performance of contract |
| Platform notifications and service updates | Contract and legitimate interest |
| Improving voice models and detecting abuse | Legitimate interest |
| Billing, fraud prevention, and account security | Legal obligation and contract |
| Responding to support requests | Performance of contract |
| Regulatory compliance | Legal obligation |
| Product announcements and marketing | Consent or legitimate interest |
Aerlou does not use your personal data, your team's data, or your callers' data to train third-party foundation models.
AI processing and model use
Conversations, transcripts, and contextual notes are processed by large-language-model providers under agreements that prohibit training on customer data. Aerlou routes tasks to the most appropriate model and caches non-sensitive system prompts to keep latency low. Personal data is excluded from prompt caches. Customers remain responsible for reviewing AI-generated outputs that drive downstream action.
Voice, SMS, and recording practices
Aerlou places and receives calls through regulated telephony providers and sends SMS through compliant messaging carriers. Customers configure recording, consent notices, and disclosures. Where local law requires one-party or two-party consent, the customer is responsible for ensuring that the AI greeting, IVR menu, or SMS sequence captures it. Aerlou provides configurable templates to support this.
Healthcare customers and sensitive data
For healthcare practices that handle protected health information, Aerlou operates with HIPAA-aligned safeguards including encryption in transit and at rest, role-based access controls, audit logs, and minimum-necessary data handling. Business Associate Agreements are available on request for qualifying healthcare plans. Customers are responsible for confirming that their use of the platform fits the scope of any signed BAA.
Team accounts and multi-user data
Account administrators can access aggregated call metrics, transcripts generated by their organization, and configuration settings. Personal login credentials and private communications between an individual team member and Aerlou support are not exposed to administrators. Organizations on team or business plans assume controller responsibilities for member consent and data handling.
Data sharing and third parties
9.1 Service providers
Aerlou shares data with cloud hosting providers, voice and SMS carriers, LLM providers, payment processors, customer support tools, and analytics platforms. Each provider is bound by a written processing agreement.
9.2 Integration partners
When a customer authorizes a CRM, EMR, calendar, or messaging integration, Aerlou transmits only the data required to complete the requested action. Customers should review the privacy practices of each integration partner.
9.3 Legal obligations
Aerlou may disclose data where required by valid legal process or to protect the rights, property, or safety of Aerlou, its customers, or the public.
9.4 Business transfers
If Aerlou is involved in a merger, acquisition, or asset sale, customer and personal data may be transferred to the successor entity subject to this policy.
International data transfers
Aerlou's infrastructure is hosted across multiple regions. Where personal data crosses borders, transfers are protected by standard contractual clauses, equivalent safeguards, or customer-selected regional processing where available.
Data retention
| Data type | Retention |
|---|---|
| Account and profile data | Duration of the account plus 90 days after closure |
| Call transcripts and SMS history | 12 months by default, configurable per plan |
| Voice recordings | 30 days by default, configurable per plan |
| Patient or contact records pushed via API | Until the customer or data subject requests deletion |
| Billing and tax records | 7 years |
| Support communications | 3 years |
| Usage and security logs | 12 months |
After the retention period, data is securely deleted or anonymized. Customers can request earlier deletion at any time.
Your rights
Subject to local law, you may request access to the personal data Aerlou holds about you, correction of inaccurate data, deletion, restriction of processing, portability, or to object to a specific use. Requests can be sent to privacy@aerlou.com and are answered within 30 days after identity verification.
Security
Aerlou applies industry-standard technical and organizational measures, including TLS 1.2 or higher for data in transit, AES-256 encryption at rest, role-based access controls, multi-factor authentication for staff, regular security assessments, and a defined breach notification protocol.
Cookies and site analytics
Aerlou.com uses strictly necessary cookies to keep the site functional, performance cookies to understand how visitors use the site, and functional cookies to remember preferences. Aerlou does not run advertising or cross-site tracking on its marketing site.
Children
Aerlou is intended for business users aged 18 and over and does not knowingly collect personal data from minors. Healthcare customers processing pediatric data through the platform remain responsible for applicable parental consent requirements.
Changes to this policy
Material updates are communicated to registered users at least 14 days before they take effect. Minor edits, such as clarifications and typo fixes, may be made at any time. The effective date at the top of this page always reflects the current version.
Contact
Privacy questions, deletion requests, and data subject inquiries can be sent to privacy@aerlou.com. General contact runs through contact@aerlou.com. Where applicable, you may also escalate concerns to the supervisory authority in your jurisdiction.