🎙️ Digital Front Desk

Legal & trust

Last updated: 2026-08-07 · Version 0.1 · Status: Draft for legal review — not yet in force

These documents were written from the source code rather than from a template, so where the honest answer is unflattering it is the one printed. If you find a sentence here that does not match what the software does, that is a defect and we want to hear about it: [PRIVACY CONTACT EMAIL].

Published

DocumentWhat it answersWritten for
Privacy policy What we collect, why, who else sees it, where it is processed, and what deleting something does and does not do. The business buying the service, and its staff.

Written but not yet published

These five are drafted against the same source code and are with counsel. They are named here rather than left off, because "we have not published our sub-processor list yet" is itself an answer somebody doing due diligence is entitled to. Ask us for a draft: [PRIVACY CONTACT EMAIL].

DocumentWhat it will answerWritten for
Call recording & AI disclosure What happens to a phone call: that the voice is a machine, that the call is transcribed, that it may be recorded, and who ends up holding it. People who call a business that uses us.
Sub-processor list Every third party in the chain, what each one receives, and where it runs. Anyone doing due diligence.
Data retention & deletion How long each table is kept, which ones are never deleted, and exactly what our delete buttons do. Anyone who needs a retention schedule.
Security overview What is isolated, what is not, and which certifications we do not hold. Anyone doing due diligence.
Terms of service The agreement between us and the business that buys the service. Customers.

Four things worth knowing before you read any of them

These are the answers a template would have got wrong

  • Everything is processed in the United States. Hosting, database, backups, the chat assistant's virtual machine, and every AI model. There is no Canadian region anywhere in this system.
  • Deleting a conversation with the chat assistant does not erase it. It removes the conversation from your list. The assistant's own copy, and anything it has committed to its long-term memory, stay.
  • The chat assistant's memory is shared by everyone at your business, not private per person.
  • We do not yet announce recording to callers automatically. The product records by default and says nothing. Until that is fixed in the software, informing callers is the business's job.

Who to contact

Privacy questions, access requests and complaints: [PRIVACY OFFICER NAME AND TITLE], [PRIVACY CONTACT EMAIL], [REGISTERED ADDRESS].

Review note — remove before publishing. The project's public contact address today is <code>info@moneliautomation.com</code> (app/core/config.py, CONTACT_FORM_TO). Decide deliberately whether privacy and access requests go there or to a dedicated role address before filling in the placeholder, and note that PIPEDA Principle 4.8 and Quebec's Law 25 both require a named accountable person, not just an inbox.
This is not legal advice. This document was drafted from what the software actually does, by the people who built it, and it has not been reviewed by a lawyer. It must be reviewed by Canadian privacy counsel — and, where a customer is a health information custodian or a law firm, by counsel familiar with PHIPA, the Alberta Health Information Act, Quebec's Law 25 and professional obligations of confidentiality — before it is published or relied on by anyone. Highlighted [LIKE THIS] are facts we have deliberately not invented; they must be filled in before publication.