Legal

Privacy Policy

Effective date: 22 May 2026Last updated: 22 May 2026

This policy explains how Aerlou collects, uses, stores, and protects personal data when you, your team, or your callers interact with the Aerlou platform, including the website at aerlou.com and the AI voice, SMS, and CRM integration services. By using Aerlou you agree to the practices described below.

1

Who we are

Aerlou operates an AI front desk platform for phone-heavy businesses, including healthcare practices, automotive dealerships, and real estate offices. The service is offered through aerlou.com and connected products. Privacy inquiries can be sent to privacy@aerlou.com.

2

Scope and acceptance

This policy applies to anyone who creates an account, configures an AI agent, places or receives a call routed through Aerlou, or otherwise interacts with the platform. Where Aerlou processes data on behalf of a business customer, that customer is the data controller and Aerlou acts as processor. Customers are responsible for the lawful collection and use of caller, patient, and contact data they push through the platform.

3

What data we collect

3.1 Account and team data

Name, work email, role, business name, billing information processed by our payment provider, login credentials, and account preferences.

3.2 Caller, patient, and contact data

Phone numbers, names, voice interactions, SMS messages, appointment details, intent and routing notes, and any context the caller provides during the conversation. Customers are responsible for obtaining consent from data subjects where required by law.

3.3 Voice recordings and transcripts

Where call recording is enabled, Aerlou stores the audio file and a written transcript so that bookings, routing, and follow-up can be reconstructed. Customers control recording configuration and are responsible for two-party consent notices where applicable in their jurisdiction.

3.4 Integration data

When a customer connects a CRM, EMR, calendar, or messaging tool, Aerlou exchanges only the data needed to complete the requested workflow, such as patient or contact records, calendar availability, and appointment outcomes.

3.5 Usage and technical data

Device and browser information, IP addresses, session logs, call metadata such as duration and outcome, and product analytics generated through normal use of the platform.

4

How we use your data

PurposeLegal basis
Operating the AI voice and SMS servicePerformance of contract
Routing calls, booking appointments, and following upPerformance of contract
Syncing transcripts and outcomes to your CRM or EMRPerformance of contract
Platform notifications and service updatesContract and legitimate interest
Improving voice models and detecting abuseLegitimate interest
Billing, fraud prevention, and account securityLegal obligation and contract
Responding to support requestsPerformance of contract
Regulatory complianceLegal obligation
Product announcements and marketingConsent or legitimate interest

Aerlou does not use your personal data, your team's data, or your callers' data to train third-party foundation models.

5

AI processing and model use

Conversations, transcripts, and contextual notes are processed by large-language-model providers under agreements that prohibit training on customer data. Aerlou routes tasks to the most appropriate model and caches non-sensitive system prompts to keep latency low. Personal data is excluded from prompt caches. Customers remain responsible for reviewing AI-generated outputs that drive downstream action.

6

Voice, SMS, and recording practices

Aerlou places and receives calls through regulated telephony providers and sends SMS through compliant messaging carriers. Customers configure recording, consent notices, and disclosures. Where local law requires one-party or two-party consent, the customer is responsible for ensuring that the AI greeting, IVR menu, or SMS sequence captures it. Aerlou provides configurable templates to support this.

7

Healthcare customers and sensitive data

For healthcare practices that handle protected health information, Aerlou operates with HIPAA-aligned safeguards including encryption in transit and at rest, role-based access controls, audit logs, and minimum-necessary data handling. Business Associate Agreements are available on request for qualifying healthcare plans. Customers are responsible for confirming that their use of the platform fits the scope of any signed BAA.

8

Team accounts and multi-user data

Account administrators can access aggregated call metrics, transcripts generated by their organization, and configuration settings. Personal login credentials and private communications between an individual team member and Aerlou support are not exposed to administrators. Organizations on team or business plans assume controller responsibilities for member consent and data handling.

9

Data sharing and third parties

9.1 Service providers

Aerlou shares data with cloud hosting providers, voice and SMS carriers, LLM providers, payment processors, customer support tools, and analytics platforms. Each provider is bound by a written processing agreement.

9.2 Integration partners

When a customer authorizes a CRM, EMR, calendar, or messaging integration, Aerlou transmits only the data required to complete the requested action. Customers should review the privacy practices of each integration partner.

9.3 Legal obligations

Aerlou may disclose data where required by valid legal process or to protect the rights, property, or safety of Aerlou, its customers, or the public.

9.4 Business transfers

If Aerlou is involved in a merger, acquisition, or asset sale, customer and personal data may be transferred to the successor entity subject to this policy.

10

International data transfers

Aerlou's infrastructure is hosted across multiple regions. Where personal data crosses borders, transfers are protected by standard contractual clauses, equivalent safeguards, or customer-selected regional processing where available.

11

Data retention

Data typeRetention
Account and profile dataDuration of the account plus 90 days after closure
Call transcripts and SMS history12 months by default, configurable per plan
Voice recordings30 days by default, configurable per plan
Patient or contact records pushed via APIUntil the customer or data subject requests deletion
Billing and tax records7 years
Support communications3 years
Usage and security logs12 months

After the retention period, data is securely deleted or anonymized. Customers can request earlier deletion at any time.

12

Your rights

Subject to local law, you may request access to the personal data Aerlou holds about you, correction of inaccurate data, deletion, restriction of processing, portability, or to object to a specific use. Requests can be sent to privacy@aerlou.com and are answered within 30 days after identity verification.

13

Security

Aerlou applies industry-standard technical and organizational measures, including TLS 1.2 or higher for data in transit, AES-256 encryption at rest, role-based access controls, multi-factor authentication for staff, regular security assessments, and a defined breach notification protocol.

14

Cookies and site analytics

Aerlou.com uses strictly necessary cookies to keep the site functional, performance cookies to understand how visitors use the site, and functional cookies to remember preferences. Aerlou does not run advertising or cross-site tracking on its marketing site.

15

Children

Aerlou is intended for business users aged 18 and over and does not knowingly collect personal data from minors. Healthcare customers processing pediatric data through the platform remain responsible for applicable parental consent requirements.

16

Changes to this policy

Material updates are communicated to registered users at least 14 days before they take effect. Minor edits, such as clarifications and typo fixes, may be made at any time. The effective date at the top of this page always reflects the current version.

17

Contact

Privacy questions, deletion requests, and data subject inquiries can be sent to privacy@aerlou.com. General contact runs through contact@aerlou.com. Where applicable, you may also escalate concerns to the supervisory authority in your jurisdiction.