Effective 21 August 2026 Last updated 21 August 2026 Version 2026-08-21
Privacy Policy
This Privacy Policy explains how ATPAI LLC collects, uses, discloses, retains, and protects personal data when people visit our website, contact us, use our services, or interact with an AI receptionist or workflow we operate for a client.
01Scope and our roles
ATPAI LLC is a Delaware limited liability company based in the United States. We provide AI receptionist, telephony, transcription, messaging, automation, client-dashboard, reporting, support, and related services to businesses throughout the United States (the Service). This Policy applies to atpai.io, our client portal, sales and support interactions, and the Service.
Our role depends on the data and context. ATPAI acts as a controller or business when we decide how to use website visitor, prospect, client-account, billing, security, support, and business-contact data for our own purposes. ATPAI generally acts as a processor or service providerwhen we handle a client’s callers, customers, prospects, personnel, and operational records on that client’s instructions. We refer to the latter as Client-Controlled Data.
A client’s agreement, data processing addendum, or legally required notice may provide additional terms. If those terms conflict with this Policy for Client-Controlled Data, the controlling agreement governs our processing for that client.
02Personal data we collect
Depending on how a person interacts with ATPAI or a client, we may process:
- Identity and contact data: names, business names, job titles, email addresses, telephone numbers, mailing or service addresses, and preferred contact methods.
- Call and communications data:caller and called numbers, call time and duration, routing information, call recordings, transcripts, voicemail, SMS or email content, consent and opt-out records, and communications metadata.
- Service and lead data: requested services, job descriptions, service locations, urgency, availability, appointment or estimate details, lead status, notes, outcomes, and other information a caller, client, or user provides.
- AI and automation data: AI prompts, instructions, knowledge-base content, audio inputs, AI Output, generated speech or text, summaries, classifications, recommendations, workflow actions, confidence or quality signals, and human corrections.
- Account and dashboard data:usernames, authentication identifiers, organization and user roles, access permissions, settings, support requests, audit events, and portal activity.
- Device, network, and log data: IP address, browser and device type, operating system, timestamps, referring pages, pages or features used, error reports, security events, and similar technical log data.
- Commercial and billing data:package, order, invoice, subscription, payment status, transaction reference, tax, and billing-contact information. Payment processors generally receive complete payment-card details directly; ATPAI typically receives only limited transaction and account information.
- Business information: hours, service areas, services, pricing, policies, staff and escalation contacts, scripts, offers, calendars, integrations, and other information needed to configure the Service.
03Sources of personal data
We collect personal data from:
- the person who provides it by phone, message, form, email, portal, or other interaction;
- our clients and their authorized users, personnel, systems, calendars, contact lists, and integrations;
- telephony carriers, communications providers, AI providers, hosting providers, authentication providers, payment processors, and other subprocessors;
- public business sources such as a client’s website, business listing, service menu, hours, and published policies;
- device, browser, network, security, and service logs generated through use of the website, portal, or Service; and
- professional advisers, referral partners, or other persons who lawfully provide the information.
Clients are responsible for having the authority, notices, permissions, consents, and lawful basis needed to provide personal data to ATPAI and to instruct us to process it.
04Calls, recordings, transcripts, and AI
The Service uses automated and AI-assisted systems to answer or route calls, understand requests, generate speech and text, capture leads, prepare transcripts and summaries, support scheduling, and trigger approved workflows. AI systems can misunderstand a speaker, omit context, produce an inaccurate transcript or summary, or generate an incorrect response. Clients are responsible for appropriate human review and for confirming material requests, appointments, pricing, emergencies, and operational decisions.
Calls handled through the Service may be recorded, monitored, transcribed, summarized, and analyzed for client operations, quality assurance, safety, debugging, support, abuse prevention, security, billing, and dispute resolution. The Service may provide an audible recording or AI notice when configured. Laws governing recording, monitoring, transcription, consent, and AI disclosure vary by jurisdiction and circumstance. A notice alone may not satisfy every requirement. Each client is responsible for determining and approving the notices, consents, routing, and alternative contact methods required for its calls and locations.
A person who does not want to interact with an automated system or be recorded should say so, request a human or other available channel, or end the call and contact the business another way. Transfers and alternatives depend on the client’s configuration and staff availability.
05Website, account, and dashboard data
Our demo and audit forms currently prepare an email in the visitor’s own mail application rather than transmitting the form to an ATPAI web-form database. If a person sends that email, ATPAI receives the information through its email provider. We use it to respond, qualify the request, prepare a demo or audit, prevent abuse, and maintain business records.
Client accounts and dashboards process login, permission, session, device, and usage information to authenticate users, enforce tenant access, display client records, provide support, investigate errors, and secure the Service. Clients control which personnel may access their organization and must keep user access current.
06How we use personal data
ATPAI may use personal data to:
- provide, configure, operate, maintain, and support the Service;
- answer and route calls; capture requests; prepare recordings, transcripts, summaries, appointments, alerts, and reports; and run approved automations;
- authenticate users, enforce tenant separation and permissions, and secure accounts, systems, and communications;
- communicate with clients, prospects, users, callers, vendors, and advisers;
- process subscriptions, invoices, payments, taxes, refunds, disputes, and collection records;
- test, troubleshoot, monitor, measure, and improve quality, accuracy, reliability, safety, usability, and performance;
- detect, investigate, prevent, and respond to fraud, abuse, security incidents, unlawful conduct, and violations of agreements or platform rules;
- comply with law, respond to lawful requests, exercise or defend legal rights, and maintain required records; and
- create aggregated, statistical, or de-identified information that does not reasonably identify a person or client.
When ATPAI acts as a processor or service provider, we use Client-Controlled Data only to provide, secure, support, improve, document, and defend the Service; follow the client’s lawful instructions; or as otherwise permitted by the controlling agreement and applicable law.
07How we disclose personal data
ATPAI may disclose personal data to:
- Clients and authorized users for whom we operate the Service, including the business a person called or contacted.
- Subprocessors and service providersthat support telephony, communications, speech recognition, text-to-speech, AI processing, hosting, databases, authentication, security, monitoring, analytics, payments, email, support, and professional services. They may process data only for the services they provide to ATPAI or our clients, subject to contract and applicable law.
- Professional advisers, including lawyers, accountants, insurers, auditors, and consultants, where reasonably necessary and subject to appropriate duties.
- Authorities and other parties when reasonably necessary to comply with law or legal process; protect rights, safety, systems, clients, or the public; investigate misuse; or establish, exercise, or defend legal claims.
- Transaction parties in connection with a financing, merger, acquisition, restructuring, sale of assets, or similar transaction, subject to appropriate confidentiality and lawful use.
- other persons when the relevant individual or client directs or consents to the disclosure.
ATPAI may update subprocessors as the Service changes. Clients may request information about subprocessors relevant to their Service and may receive additional notice where a contract or law requires it.
08AI providers and model training
ATPAI uses third-party AI, speech, and automation providers to process audio, text, prompts, context, and AI Output needed to provide the Service. Depending on the workflow, information may be sent to more than one provider for speech recognition, language processing, text-to-speech, quality, safety, or routing.
ATPAI does not intentionally use identifiable Client-Controlled Data to train general-purpose AI models. We configure or contract with providers to limit training use where commercially available and consistent with the Service. Providers may still process and temporarily retain data to deliver, secure, monitor, or comply with law for their services. Client-specific testing, tuning, evaluation, or knowledge-base configuration may occur to provide the client’s Service under the controlling agreement.
We may use de-identified or aggregated data, quality measurements, and non-identifying learnings to improve systems, prompts, workflows, safety, analytics, and operations, provided the data does not reasonably identify a person or client.
10Calls, SMS, email, and consent
ATPAI may send operational communications to clients and authorized users about accounts, calls, leads, security, support, billing, and Service changes. A client may also configure caller or customer follow-up by call, SMS, or email when that functionality is included, enabled, and approved.
Clients are responsible for establishing and documenting the lawful basis, notices, opt-ins, and other consent required for their communications and for honoring revocation, Do Not Call, STOP, unsubscribe, and suppression requests. ATPAI may maintain consent, opt-out, and delivery records to operate and defend the Service. We may refuse, pause, or suppress communications when consent is missing, uncertain, revoked, or legally or operationally risky.
For marketing email sent by ATPAI about our own services, recipients may use the unsubscribe method in the message or contact us. Transactional, security, billing, and service messages may continue where permitted even after a person opts out of marketing.
11Retention and deletion
We retain personal data for only as long as reasonably necessary for the purposes described here, the client’s instructions, the controlling agreement, and legal, tax, accounting, security, backup, audit, fraud, billing, and dispute requirements. Retention varies by data type, client configuration, provider, and legal obligation.
- Unless a controlling agreement states otherwise, production call recordings, transcripts, summaries, message records, approval logs, and dashboard records may be retained for up to 12 months during active service.
- After service termination, reasonably available production data may be retained for up to 90 days for export and transition before deletion or de-identification.
- Backup, security, billing, tax, audit, consent, suppression, and dispute-defense records may remain for up to 180 days or longer where reasonably necessary or required by law, legal hold, vendor backup cycle, or an applicable limitations period. Communications-compliance records may be retained longer; for example, covered Telemarketing Sales Rule records may need to be retained for five years.
- Website inquiries, sales, support, and client-account records are retained for the relationship, legitimate follow-up, recordkeeping, and legal needs, then deleted or de-identified when no longer reasonably necessary.
Deletion from active systems does not always remove data immediately from encrypted backups or third-party systems with independent lawful retention obligations. We restrict such retained data from ordinary use until deletion or overwrite where commercially reasonable.
12Security
ATPAI uses commercially reasonable administrative, technical, and organizational safeguards appropriate to the nature of the Service and data. These may include access controls, least-privilege practices, tenant authorization, encryption in transit and at rest where supported, credential controls, logging, monitoring, backups, vendor review, confidentiality obligations, and incident-response procedures.
No transmission, storage, AI, telephony, or cloud system is completely secure or error-free. Clients and users must protect their devices, accounts, passwords, inboxes, phone systems, API keys, and authorized-user lists and promptly report suspected compromise to ATPAI.
13U.S. state privacy rights
Depending on a person’s state of residence, the nature of the data, our role, and whether a law applies to ATPAI or the relevant client, that person may have rights to:
- confirm whether personal data is processed and access or obtain a copy;
- correct inaccurate personal data;
- delete personal data, subject to exceptions;
- obtain portable data in a usable format;
- opt out of sale, targeted advertising, or certain profiling;
- limit or withdraw consent for certain sensitive data processing;
- use an authorized agent to submit a request where permitted;
- appeal a denial of a request where applicable; and
- receive non-discrimination for exercising applicable privacy rights.
To submit a request involving data ATPAI controls, email privacy@atpai.io with “Privacy request” in the subject. Describe the request, the relationship with ATPAI, the state of residence, and enough information for us to locate the record. Do not email government identifiers, payment-card data, passwords, or other unnecessary sensitive information.
We may verify identity, authority, and state residency before acting. For an authorized agent, we may request proof of authorization and may verify the individual directly. We generally respond within 45 days, subject to extensions or different timing permitted by applicable law. If we deny an appealable request, our response will explain how to appeal. Rights are subject to legal exceptions, and we may retain information needed for security, fraud prevention, legal obligations, suppression, contracts, or claims.
14Requests involving client-controlled data
If a request concerns a call, message, job, appointment, lead, or other Client-Controlled Data, the person should first contact the business they called or interacted with. That client determines whether and how to grant the request. ATPAI will assist the client as required by contract and applicable law and may route a request received directly to the relevant client.
To protect privacy, ATPAI may be unable to disclose which client holds a record or provide the record directly until the client and requestor are appropriately verified. A client may instruct ATPAI to preserve data subject to legal hold or another lawful exception.
15Sensitive data and children
The Service is not designed to collect Social Security numbers, government identifiers, complete payment-card data, account passwords, biometric identification templates, precise GPS location, protected health information, or other highly sensitive or regulated data unless a signed addendum expressly authorizes and governs that use. Clients must not configure the Service to request such data without ATPAI’s written approval and appropriate legal and security measures. If a caller volunteers unnecessary sensitive data, we may process it as part of the communication and work with the client to restrict, redact, or delete it where appropriate.
ATPAI’s website and Service are directed to businesses and adults and are not directed to children under 13. Clients may not knowingly use the Service to collect personal data from children under 13 without ATPAI’s written approval and legally sufficient parental authorization. If we learn that we control a child’s data contrary to this section, we will take reasonable steps to delete it. For Client-Controlled Data, we will notify or assist the relevant client as appropriate. State laws may provide additional protections for minors under 16, 17, or 18.
16Interstate and international processing
ATPAI is based in Delaware and provides services across the United States. Personal data may be processed in the state where a client or caller is located, in other U.S. states, and in other countries where an authorized subprocessor operates. Those jurisdictions may have different privacy laws.
Where required, ATPAI and its providers use contractual, technical, or organizational measures intended to protect transferred data. The Service is currently directed to U.S. businesses; a client seeking to use it outside the United States must notify ATPAI and enter any additional terms required for that use.
17Changes to this Policy
We may update this Policy to reflect changes in the Service, law, vendors, or data practices. The “Last updated” date identifies the current version. If a change materially affects how we use personal data, we will provide additional notice where required, such as by email, portal notice, or a prominent website notice. A change will not retroactively authorize a materially different use of Client-Controlled Data when a contract or law requires additional consent or instruction.
18Contact us
Questions, privacy requests, or security reports may be sent to ATPAI LLC at privacy@atpai.io. Existing clients may also use the support channel and notice information in their Service Agreement or Order Form.
ATPAI LLC300 Delaware Ave., Suite 210, Wilmington, DE 19801