Who this policy covers
This Privacy Policy explains how Sauti processes information when businesses create AI voice agents, connect communication and productivity services, receive calls, manage bookings, and review conversation analytics. A business using Sauti controls the caller and customer information processed in its workspace; Sauti processes that information to provide the platform.
Information we collect
We collect information supplied by workspace owners, users, callers, connected providers, and the devices used to access Sauti.
- Account and workspace information, including names, business details, email addresses, authentication records, plan and usage information.
- Agent configuration, knowledge content, prompts, business hours, routing rules, enabled tools, and integration preferences.
- Call and message data, including phone numbers, audio where recording is enabled, transcripts, events, duration, language, summaries, sentiment, booking details, and information a caller chooses to provide.
- Technical and security data, including IP address, browser, device, timestamps, request logs, OAuth state, and security events.
- Integration data returned by providers that a workspace explicitly connects.
Public website analytics
Sauti records public page paths, referrer hostnames, campaign tags, and product-demo events to understand whether visitors find and successfully try the service. A daily rotating identifier is created with a keyed hash of limited request data; raw IP addresses and browser user-agent strings are not stored in the analytics table.
Browser Do Not Track is respected. Detailed website analytics events are automatically deleted after 90 days, and Sauti does not use third-party advertising trackers for this measurement.
Google user data
When a workspace connects Google Calendar, Sauti may read calendar identity, calendar lists, availability or free/busy information, and event details needed to check availability, create, update, or cancel appointments at the user's direction. When Google Sheets is connected, Sauti may read configured spreadsheet metadata or rows for enabled agent tools and append configured post-call fields such as date, caller, duration, outcome, summary, and booking details.
Sauti uses Google user data only to provide and improve the user-facing integration features the workspace enables. Sauti does not sell Google user data, use it for advertising, use it to train generalized AI or machine-learning models, or allow humans to read it except when necessary for security, support requested by the user, legal compliance, or service operation. Sauti's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
- OAuth access and refresh tokens are encrypted at rest and are not exposed in ordinary API responses.
- Access is tenant-scoped and limited to the connected workspace and agents it enables.
- Disconnecting an integration stops new Google API access and removes or invalidates stored connection credentials as supported by the provider.
- Users can also revoke Sauti from their Google Account permissions page.
How information is used
- Authenticate users, operate workspaces, meter usage, and provide support.
- Transcribe and synthesize speech, generate responses, route calls, answer configured questions, and perform enabled tools.
- Create and manage bookings, send confirmations, synchronize selected integrations, and run configured post-call workflows.
- Provide transcripts, recordings where enabled, summaries, analytics, quality monitoring, fraud prevention, and reliability.
- Meet legal obligations, enforce platform terms, and protect users, callers, Sauti, and the public.
Retention, controls, and deletion
A workspace chooses an identifiable conversation-content retention period of 30, 90, 180, or 365 days and a recording retention period of 7, 30, or 90 days that cannot exceed its conversation period. The default is 90 days for conversation content and 30 days for recordings. A daily retention process redacts caller numbers, transcripts, summaries, inferred intent and sentiment, archived conversation state, and transfer details when the conversation period expires. It deletes local recordings and requests permanent deletion of Telnyx-hosted recordings when the recording period expires. Failed provider deletions remain eligible for retry.
Aggregate operational fields such as timestamps, duration, outcome, language, interruption, and latency measurements may remain after redaction. Bookings, customer records copied to connected providers, billing evidence, security audits, legal holds, and backups have separate lifecycles. Deleting Sauti data does not delete a record previously written to Google Calendar, Google Sheets, a CRM, or another provider.
To request access, correction, export, restriction, or full workspace deletion, contact the workspace that collected your caller information or email support@sauti.uk. Verified requests are handled according to applicable law. Workspace owners can change retention settings and disconnect integrations from the dashboard.
Security and international processing
Sauti uses administrative, technical, and organizational safeguards including tenant-scoped authorization, encrypted provider credentials, HTTPS, access controls, logging, backups, and secret-management practices. No system can guarantee absolute security. Information may be processed in countries where Sauti or its providers operate, with safeguards appropriate to the data and applicable law.
Children and sensitive information
Sauti is a business service and is not directed to children. Workspaces should not configure agents to collect unnecessary sensitive information. Health, financial, identity, or other sensitive data should be collected only with a lawful purpose, appropriate notice, and safeguards. Payment actions require confirmation and should use approved payment providers rather than collecting full payment credentials in conversation.
Changes and contact
We may update this policy as Sauti and applicable requirements evolve. Material changes will be identified by a new effective date and, where appropriate, an in-product or email notice. Questions and privacy requests can be sent to support@sauti.uk. Please identify the relevant workspace or call when possible, without emailing passwords, OAuth tokens, or other secrets.
Privacy, tenant isolation, explicit integrations, and safe call handling are part of Sauti's product architecture.
