PRIVACY POLICY
1. INTRODUCTION AND SCOPE
1.1 About This Policy. This Privacy Policy (“Policy”) describes how AIrsa Leads, and its parent, subsidiaries, affiliates, officers, directors, employees, contractors, and agents (collectively, “AIrsa,” “Company,” “we,” “us,” or “our”) collect, use, disclose, retain, transfer, and protect information in connection with:
(a) your use of our website located at [Insert Domain] and any related subdomains, mobile-optimized pages, or successor sites (collectively, the “Site”); (b) your interactions with us through phone calls, text messages, email, chat widgets, and contact or demo-booking forms; and (c) your interactions with the AI-powered lead response, call handling, CRM automation, appointment booking, call intelligence, review generation, and reporting systems (collectively, the “Services”) that we design, build, host, and operate on behalf of our business clients (“Clients”).
1.2 Who This Policy Covers. This Policy applies to three categories of individuals, whose data may be handled differently depending on context:
(a) Site Visitors — individuals who browse the Site without submitting information;
(b) Prospective Clients — individuals or business representatives who request a demo, submit a contact form, call us, or otherwise engage with AIrsa directly as a prospective or existing customer of our Services; and
(c) End Users / Leads / Customers — individuals who call, text, message, or submit a form to a Client business that uses our Services, where AIrsa acts as a data processor or service provider on behalf of that Client, and the Client — not AIrsa — is generally the party responsible for determining the purposes and means of processing that individual’s personal information (“Controller” or “Business,” as applicable under law).
1.3 Relationship to Client Agreements. Where AIrsa processes personal information on behalf of a Client as a service provider or processor, our handling of that information is also governed by the underlying services agreement or data processing addendum between AIrsa and that Client. If you are an End User / Lead / Customer of a Client business, you should also refer to that Client’s own privacy policy, as they may have independent obligations and practices governing your information that differ from or supplement this Policy.
1.4 Acceptance. By accessing or using the Site, requesting a demo, submitting a form, calling or texting us or a Client using our Services, or otherwise providing information to us, you acknowledge that you have read, understood, and agree to be bound by this Policy. If you do not agree with any part of this Policy, you must immediately discontinue use of the Site and refrain from providing further information to us.
1.5 Changes to Scope. We may modify, expand, restrict, or discontinue any aspect of the Services described in this Policy at any time, and such changes may affect the categories, methods, or purposes of data collection described herein, subject to Section 15 (Changes to This Policy).
2. INFORMATION WE COLLECT
We collect information through multiple channels and in multiple categories, described in detail below. Not every category applies to every individual; the information actually collected depends on how you interact with the Site or Services.
2.1 Information You Provide Directly.
(a) Contact and Identification Information: full name, phone number(s), email address(es), mailing or service address, ZIP or postal code, company name, job title (if applicable).
(b) Service and Inquiry Information: the nature of the service you are inquiring about, project or job details, free-text messages submitted through forms or chat, appointment preferences, and any other information you voluntarily provide in the body of a message, call, or text.
(c) Scheduling Information: appointment dates, times, calendar selections, rescheduling requests, and related metadata generated through our booking tools.
(d) Communications Content: the content of emails, SMS/text messages, chat transcripts, and voicemail messages you send to or receive from us or a Client using our Services.
(e) Payment-Related Information (where applicable to Clients, not typically to Site visitors): if you make a payment or deposit through a Client’s booking flow that integrates with our Services, limited billing information may pass through our systems; however, we do not directly store full payment card numbers, which are handled by PCI-compliant third-party payment processors.
2.2 Information Collected Automatically.
(a) Device and Technical Information: IP address, device identifiers, browser type and version, operating system, screen resolution, language settings, and general device configuration.
(b) Usage Information: pages and sections of the Site visited, links clicked, time spent on pages, scroll behavior, entry and exit pages, referring and exit URLs, and interaction with forms, buttons, and chat widgets.
(c) Location Information: general geographic location inferred from IP address or provided ZIP code; we do not collect precise GPS location through the Site unless you separately grant such permission through a device feature.
(d) Cookie and Tracking Data: as described in Section 7 (Cookies & Tracking Technologies).
2.3 Information Collected Through Calls, Texts, and AI Systems.
(a) Call Data: call metadata (date, time, duration, phone numbers involved, call outcome/disposition), call recordings (where legally permitted and, where required, with appropriate notice or consent), and machine-generated transcripts of call audio.
(b) AI-Generated Content: summaries, categorizations, sentiment indicators, extracted data fields (such as name, service need, or urgency), and recommended next steps generated by artificial intelligence or automated systems analyzing call, text, or chat content. AI-generated summaries and transcripts may contain inaccuracies and are provided for operational convenience; they are not guaranteed to be a complete or verbatim record of any conversation.
(c) SMS/Text Data: content of text messages, delivery and read status where available, opt-in/opt-out status, and message timestamps.
(d) CRM Records: the consolidated contact and opportunity records generated within a Client’s customer relationship management system as leads move through capture, response, organization, and booking stages, including internal notes, task assignments, pipeline stage history, and follow-up logs.
2.4 Information From Third Parties. We may receive information about you from third-party sources, including: (a) advertising and marketing platforms (e.g., if you click on an ad that leads to our Site); (b) Client businesses who input or import contact information about their own leads/customers into systems we operate on their behalf; (c) publicly available sources; and (d) service providers such as telephony carriers, SMS aggregators, and scheduling or analytics platforms.
2.5 Sensitive Information. We do not intentionally collect sensitive categories of personal information (such as government identification numbers, financial account numbers, health information, or precise geolocation) through the Site, and we ask that you not submit such information through our forms, chat, calls, or texts unless specifically requested and necessary for a legitimate service purpose. If you choose to include such information in free-text fields or conversations, you do so at your own discretion, and its inclusion does not expand our obligation to treat it differently than other information described in this Policy, except as required by applicable law.
3. HOW WE USE INFORMATION
We use the information described above for the following purposes, each of which constitutes an independent, non-exclusive basis for processing to the extent required by applicable law:
3.1 Service Delivery. To operate, maintain, and provide the core functionality of the Services, including capturing leads, generating automated and AI-assisted responses, updating CRM records, scheduling and confirming appointments, generating call summaries, and triggering review requests.
3.2 Communication. To respond to inquiries, confirm demo bookings, send appointment reminders, follow up on incomplete inquiries, and otherwise communicate with you regarding your interaction with us or a Client.
3.3 Improvement and Analytics. To analyze aggregate and individual usage patterns, measure system performance (such as response time and missed-call recovery rates), identify and fix errors, and improve the accuracy, reliability, and functionality of our AI models, automations, and Site.
3.4 AI Training and Model Performance (Limited and De-identified Where Possible). Where permitted by our Client agreements and applicable law, we may use call transcripts, chat logs, and related data in de-identified, aggregated, or anonymized form to evaluate and improve the performance of the automated and AI-assisted systems underlying the Services. We do not use personal information to train third-party, general-purpose AI models operated by unaffiliated companies except to the extent such use is a necessary, incidental part of using a third-party AI or telephony infrastructure provider in the ordinary operation of the Services, and subject to that provider’s own data handling commitments to us.
3.5 Security and Fraud Prevention. To detect, investigate, and prevent fraudulent, unauthorized, or illegal activity, and to protect the rights, property, and safety of AIrsa, our Clients, End Users, and the public.
3.6 Legal Compliance and Recordkeeping. To comply with applicable laws, regulations, legal process, or governmental requests, to enforce our agreements, and to maintain business records as required for tax, accounting, insurance, and dispute-resolution purposes.
3.7 Business Operations. For internal business purposes such as auditing, quality assurance, employee and contractor training, and evaluating the effectiveness of our marketing and business development activities.
3.8 With Consent or as Otherwise Disclosed. For any other purpose disclosed to you at the time information is collected, or with your consent.
4. LEGAL BASES FOR PROCESSING (WHERE APPLICABLE)
To the extent applicable data protection law requires us to identify a legal basis for processing personal information, we rely on one or more of the following:
(a) performance of a contract to which you are a party or in order to take steps at your request prior to entering a contract (e.g., processing a demo request);
(b) our legitimate interests in operating, securing, and improving our business and the Services, provided those interests are not overridden by your data protection interests or fundamental rights;
(c) compliance with a legal obligation; and
(d) your consent, where consent is the applicable legal basis (for example, certain SMS/text communications as described in Section 5).
5. CALLS, TEXTS & AUTOMATED MESSAGING CONSENT
5.1 Nature of Communications. The Services rely heavily on automated and AI-assisted telephone calls and SMS/MMS text messages, including but not limited to: missed-call text-back messages, instant confirmation texts, appointment reminders, follow-up sequences, after-hours call handling and voice AI intake, and post-service review requests, sent by or on behalf of AIrsa or a Client business you have contacted.
5.2 Consent to Contact. By providing your telephone number to AIrsa or to a Client business using the Services — whether through a website form, a phone call, a text message, or otherwise — you expressly consent to receive calls and text messages from or on behalf of AIrsa and/or that Client business at the number provided, including calls and messages made using an automatic telephone dialing system, artificial or prerecorded voice, or AI-generated voice or text, for purposes related to your inquiry, service request, or appointment, and for related informational, transactional, and customer service purposes, including but not limited to the 5.3 Telephone Consumer Protection Act (TCPA) and similar state-level consumer protection and telemarketing statutes.
5.4 Not a Condition of Purchase. Consent to receive automated calls or text messages as described in this Section is not a condition of purchasing any goods or services from AIrsa or any Client.
5.4 Message Frequency and Charges. Message frequency will vary depending on the nature and status of your inquiry. Standard message and data rates from your wireless carrier may apply. Neither AIrsa nor its Clients are responsible for charges imposed by your telecommunications carrier.
5.5 Opt-Out Rights. You may opt out of receiving text messages at any time by replying “STOP” to any message received. You may request help by replying “HELP.” After opting out, you may still receive a final confirmatory message. Opting out of text messages does not automatically opt you out of phone calls or emails; each channel may need to be addressed separately, and you may contact us directly using the information in Section 16 to request removal from any or all communication channels.
5.6 Call Recording and Transcription. Calls made to or from AIrsa or a Client business using the Services may be recorded, transcribed, and analyzed by automated and/or AI-assisted systems for quality assurance, training, dispute resolution, and service-delivery purposes. Where applicable law requires notice or two-party/all-party consent prior to recording a call, such notice or consent will be obtained or provided as required (for example, through an audible disclosure at the start of a call). By continuing a call after receiving such notice, you consent to the recording described.
5.7 Accuracy of AI-Generated Communications. Automated and AI-assisted messages and voice responses are generated based on available information and programmed logic, and while we design these systems to be accurate and helpful, we do not guarantee that every automated communication will be free of error, delay, or misinterpretation. If a matter is urgent or requires immediate human attention, you should not rely solely on an automated system and should seek direct assistance from the relevant business.
6. HOW WE SHARE INFORMATION
We do not sell personal information for monetary consideration. We may disclose or share information in the following circumstances:
6.1 With the Relevant Client Business. Where you have contacted, called, texted, or submitted a form to a specific Client business, your information is transmitted to and becomes part of that Client’s own business records (including their CRM), since AIrsa operates these systems as a service provider on the Client’s behalf. The Client’s own use, retention, and disclosure of that information is governed by the Client’s own policies and practices, over which AIrsa does not have full control once the information has been delivered into the Client’s systems in the ordinary course of providing the Services.
6.2 With Service Providers and Subprocessors. We engage third-party vendors and subprocessors to help us operate the Services and Site, including but not limited to: CRM and workflow automation infrastructure providers; telephony, VoIP, and SMS/MMS aggregation providers; cloud hosting and data storage providers; call recording, transcription, and AI/natural-language-processing providers; scheduling and calendar integration providers; analytics and website performance providers; email delivery providers; and payment processors (where applicable). These providers are authorized to use personal information only as necessary to perform services on our behalf and are contractually or otherwise obligated to maintain appropriate confidentiality and security measures.
6.3 Legal and Safety Disclosures. We may disclose information where we believe in good faith that disclosure is necessary to: (a) comply with a subpoena, court order, or other legal process or governmental request; (b) enforce our agreements, including this Policy and our Terms & Conditions; (c) detect, prevent, or address fraud, security, or technical issues; or (d) protect against harm to the rights, property, or safety of AIrsa, our Clients, End Users, or the public, as required or permitted by law.
6.4 Business Transfers. If AIrsa is involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of all or a portion of its assets, personal information may be disclosed or transferred to a successor or affiliate as part of that transaction, subject to standard confidentiality protections and, where required by law, notice to affected individuals.
6.5 Aggregated and De-Identified Data. We may share aggregated, anonymized, or de-identified data that cannot reasonably be used to identify you, for any business purpose, including benchmarking, industry reporting, and marketing our own Services (for example, describing average response-time improvements across our client base without identifying any individual or specific Client).
6.6 With Your Consent. We may share information for any other purpose disclosed to you at the time of collection or with your consent.
7. COOKIES & TRACKING TECHNOLOGIES
7.1 Types of Technologies Used. The Site may use cookies, web beacons, pixel tags, local storage, and similar technologies (collectively, “Cookies”) to recognize your browser or device, remember preferences, understand usage patterns, and support analytics and advertising measurement.
7.2 Categories of Cookies. Cookies used on the Site may include:
(a) strictly necessary cookies required for basic Site functionality;
(b) performance and analytics cookies that help us understand how visitors use the Site;
(c) functionality cookies that remember choices you make; and (d) advertising/targeting cookies that may be used, where applicable, to measure the effectiveness of marketing campaigns.
7.3 Third-Party Analytics. We may use third-party analytics providers (such as website analytics or advertising platforms) that place their own cookies and collect information about your use of the Site over time and across other websites. These third parties’ use of information is governed by their own privacy policies.
7.4 Your Choices. Most web browsers allow you to control cookies through browser settings, including blocking or deleting cookies. Because Cookies enable certain Site features, disabling them may affect functionality. We do not currently respond to “Do Not Track” browser signals in a manner that differs from the practices described in this Policy, except where required by applicable law.
8. DATA RETENTION
8.1 General Retention Principle. We retain personal information for as long as reasonably necessary to fulfill the purposes described in this Policy, including providing the Services, maintaining accurate business records, resolving disputes, enforcing agreements, and complying with legal, tax, accounting, and regulatory obligations, after which it is deleted, anonymized, or archived in accordance with our internal data retention practices, unless a longer retention period is required or permitted by law.
8.2 Client-Controlled Records. Call recordings, transcripts, CRM contact records, and related data generated in connection with a specific Client business are generally retained in accordance with that Client’s own retention practices and instructions, since the Client typically directs the retention and deletion of records within systems we operate on their behalf, except where AIrsa has independent retention obligations under applicable law or our own internal policies.
8.3 Backup and Archival Copies. Residual copies of information may persist for a limited period in backup, archival, or disaster-recovery systems even after deletion from primary systems, consistent with standard data management practices, and will be permanently deleted or rendered inaccessible in the ordinary course of routine backup-cycle deletion.
9. YOUR RIGHTS & CHOICES
9.1 General Rights. Depending on your jurisdiction of residence, you may have some or all of the following rights with respect to your personal information: the right to request confirmation of whether we process your information; the right to access and obtain a copy of your personal information; the right to request correction of inaccurate or incomplete information; the right to request deletion of your personal information, subject to certain exceptions; the right to request restriction of or object to certain processing; the right to data portability; and the right to withdraw consent at any time where processing is based on consent, without affecting the lawfulness of processing before withdrawal.
9.2 California Residents. If you are a California resident, you may have additional rights under the California Consumer Privacy Act, as amended by the California Privacy Rights Act (“CCPA”), including the right to know what personal information has been collected, used, disclosed, or sold (we do not sell personal information as defined by the CCPA); the right to request deletion; the right to correct inaccurate information; the right to limit the use of sensitive personal information; and the right to non-discrimination for exercising your privacy rights. California residents may submit a rights request using the contact information in Section 16. We may need to verify your identity before fulfilling certain requests.
9.3 Other State and International Rights. Residents of other U.S. states or other countries with applicable comprehensive privacy laws may have similar rights as described above, subject to the specific requirements, thresholds, and exceptions of the applicable law. We will honor valid requests from individuals in a manner consistent with applicable law.
9.4 How to Exercise Rights. To exercise any of the rights described in this Section, please contact us using the information in Section 16. We may need to verify your identity and the nature of your request before taking action, and we may decline a request, in whole or in part, where permitted or required by law (for example, where the request conflicts with our legal obligations, where fulfilling the request would adversely affect the rights of others, or where the underlying records are controlled by a Client business rather than AIrsa). If your request relates to your interaction with a specific Client business rather than directly with AIrsa, we may direct you to that Client, coordinate the request with the Client, or process the request on the Client’s behalf and instruction, depending on the nature of our relationship with that Client.
9.5 No Discrimination. We will not discriminate against you for exercising any privacy rights available to you under applicable law, including by denying services, charging different prices, or providing a different level or quality of services, except as permitted by law.
10. DATA SECURITY
10.1 Safeguards. We implement reasonable administrative, technical, and organizational measures designed to protect personal information against unauthorized access, use, disclosure, alteration, or destruction, taking into account the nature of the information and the risks involved. These measures may include access controls, encryption in transit for certain data transmissions, vendor security review, and limiting internal access to personal information on a need-to-know basis.
10.2 No Absolute Guarantee. No method of electronic transmission or storage is completely secure, and we cannot and do not guarantee the absolute security of any information transmitted to or stored by us or our service providers. Any transmission of information is at your own risk. In the event of a security incident affecting your personal information, we will take reasonable steps to notify affected individuals and/or applicable regulators as required by applicable law.
10.3 Your Responsibilities. You are responsible for maintaining the confidentiality of any account credentials or access information associated with your use of the Site or Services, and for promptly notifying us of any unauthorized use or suspected security incident of which you become aware.
11. INTERNATIONAL DATA TRANSFERS
Our Services are primarily intended for businesses and individuals located in the United States. If you access the Site or Services from outside the United States, please be aware that your information may be transferred to, stored, and processed in the United States or other jurisdictions where our service providers operate, which may have data protection laws different from, and potentially less protective than, those of your home jurisdiction. By using the Site or Services, you consent to such transfer, storage, and processing, to the extent permitted by applicable law. Where required by applicable law, we will implement appropriate safeguards for such international transfers.
12. THIRD-PARTY LINKS AND INTEGRATIONS
The Site and Services may contain links to, or integrate with, third-party websites, platforms, or tools (such as scheduling systems, payment processors, or social media platforms) that are not owned or controlled by AIrsa. We are not responsible for the privacy practices, content, or security of any third-party sites or services. We encourage you to review the privacy policies of any third-party service before providing information to it. Inclusion of a link or integration does not imply endorsement by AIrsa.
13. CHILDREN’S PRIVACY
The Site and Services are intended for business use by adults and are not directed to individuals under the age of 18. We do not knowingly collect personal information from children under 18. If we become aware that we have inadvertently collected personal information from a child under 18 without appropriate consent, we will take reasonable steps to delete such information promptly. If you believe a child has provided us with personal information, please contact us using the information in Section 16.
14. AUTOMATED DECISION-MAKING AND PROFILING
Certain aspects of the Services involve automated processing, including routing leads to specific team members or calendars, prioritizing follow-up based on lead source or urgency indicators, and generating AI-assisted call summaries and recommended next steps. These processes are designed to support, not replace, human decision-making by the Client business, and generally do not produce legal or similarly significant effects concerning individuals without the opportunity for human review by the relevant Client. If you have concerns about a specific automated process affecting you, you may contact us or the relevant Client business using the information available to you.
15. CHANGES TO THIS POLICY
We may update or modify this Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons. The “Last Updated” date at the top of this Policy indicates when it was last revised. Material changes will be indicated by updating this date and, where required by applicable law, through additional notice (such as a banner on the Site or direct communication). Your continued use of the Site or Services after any change becomes effective constitutes your acceptance of the revised Policy. We encourage you to review this Policy periodically.
16.SEVERABILITY
If any provision of this Policy is found to be invalid, illegal, or unenforceable by a court or other authority of competent jurisdiction, the remaining provisions of this Policy will remain in full force and effect, and the invalid or unenforceable provision will be deemed modified to the minimum extent necessary to make it valid and enforceable while preserving its original intent as closely as possible.