This agreement sets out how Intelox Pty Ltd (ACN 700 471 665) ("Intelox") handles personal information when providing Services to the Client. It forms part of the Customer Terms of Service and applies when the call agent calls, messages or acts for the Client.
1. Who is responsible for call data
| Situation | Who controls the data | Intelox's role |
|---|---|---|
| The agent calls or messages for the Client (the Client's customers, suppliers or contacts) | The Client decides why the data is collected and what it is used for | Intelox processes it only on the Client's instructions |
| The agent calls or messages on Intelox's own behalf (for example, marketing Intelox) | Intelox | Intelox is fully responsible |
| Client account, billing and support data | Intelox | Intelox is fully responsible |
When the agent acts for the Client, the Client is responsible for having a lawful basis to contact each person, including consent where required, and for its own privacy notices. Intelox is responsible for handling the data securely and as this agreement says.
2. Intelox's commitments
- 2.1Use the Client's data only to provide the Services and as the Client instructs in writing (including through account settings).
- 2.2Not sell the Client's data or use it for Intelox's own purposes.
- 2.3Make sure staff and contractors with access are bound by confidentiality.
- 2.4Protect the data with encryption, access controls and secure Sydney hosting for recordings, transcripts and records held by Intelox.
- 2.5Delete recordings and transcripts automatically after 31 days, unless the Client instructs a different period in writing.
- 2.6Help the Client respond to access, correction and deletion requests, by providing data export and deletion within 15 days of a request.
- 2.7Notify the Client without undue delay, and within 72 hours, after becoming aware of a data breach affecting the Client's data, with the details available at that time.
- 2.8Help the Client assess and notify eligible data breaches under the Notifiable Data Breaches scheme where it applies.
3. Sub-processors
The Client agrees that Intelox may use these sub-processors:
| Sub-processor | Purpose | Data location |
|---|---|---|
| Twilio | Phone calls, SMS, call recordings | Australia (Twilio AU1 region). Twilio does not yet guarantee that all data stays in the selected region |
| Google (Gemini) | AI processing of calls and messages, call summaries and analysis | Australia (Google Cloud Vertex AI, Sydney region) |
| ElevenLabs | Speech to text and text to speech on calls | United States; may also process in the Netherlands or Singapore |
| OpenAI | Optional alternative AI models and voices, only if the Client selects them | United States |
| Supabase | Database | Sydney, Australia |
| n8n | Optional n8n integration, only for clients who turn it on | Germany (n8n Cloud, Frankfurt) |
| Vercel | Website and client console | Server functions in Sydney, Australia; website files served from a worldwide network |
| Stripe | Payments and billing | United States, and other countries where Stripe and its providers operate |
| Meta (WhatsApp) | WhatsApp messaging | Australia (local storage); processing in other countries for up to 60 minutes |
Intelox will give the Client at least 30 days' notice before adding or replacing a sub-processor. The Client may object on reasonable privacy grounds. If the objection cannot be resolved, the Client may end the affected Services without a cancellation fee.
Apps the Client connects to its automations (for example its email, calendar, CRM or accounting software) are the Client's own providers, not Intelox sub-processors. The Client is responsible for its agreements with those providers.
If the Client turns off the n8n integration, Intelox stops sending new data to n8n. Data already sent is deleted in line with the retention settings of Intelox's n8n account.
4. Overseas transfers
Where a sub-processor handles data outside Australia, Intelox will take reasonable steps to make sure it protects the data consistently with the Australian Privacy Principles.
5. Audits
On reasonable written request, no more than once a year, Intelox will provide information showing it complies with this agreement, such as a summary of its security controls.
6. End of the agreement
Within 30 days after the agreement ends, Intelox will, at the Client's choice, export the Client's data to the Client and then delete it, unless the law requires Intelox to keep it.
7. Governing law
This agreement is governed by the laws of Victoria, Australia.