Vertical AI
    • Features
    • Use Cases
    • Pricing
    • Performance
    • Book a workshop
    • Case studies
    • Healthcare
    • Financial Services
    • Insurance
    • Logistics
    • Home Services
    • Retail
    • Hospitality
    • Debt Collection
    • View all →
    • vs Retell AI
    • vs Bland AI
    • vs Vapi
    • vs Synthflow
    • Security
    • Privacy
    • Terms
    • Sub-processors
    • DPA
    • Changelog
    • Press
    • Contact
  • Enterprise
Book a demo
Product
FeaturesUse CasesPricingPerformance
Workshops
Book a workshopCase studies
Industries
HealthcareFinancial ServicesInsuranceLogisticsHome ServicesRetailHospitalityDebt CollectionView all →
Compare
vs Retell AIvs Bland AIvs Vapivs Synthflow
Resources
SecurityPrivacyTermsSub-processorsDPAChangelogPressContact
Enterprise
Book a demo

Privacy

Privacy practices, plain language.

How we collect, use, retain, and protect personal information. Written for the Privacy Act 1988 (Cth) and GDPR.

Email privacy teamSub-processors

01 · Who we are

The entity behind the service

Last updated 25 April 2026

VerticalAI Pty Ltd is an Australian proprietary company based in Perth, Western Australia. We provide an inbound voice agent platform for Australian businesses.

For privacy questions, email privacy@verticalai.com.au. For legal matters, email legal@verticalai.com.au.

02 · What we collect

Categories of information

Account data. Email address, name, and organisation name supplied at sign-up. Roles and team memberships you assign.

Billing references. Stripe customer and payment-method tokens, billing email, and invoice IDs. We never receive or store card numbers, expiry dates, or CVV; Stripe Checkout and Customer Portal handle that data directly.

Conversation data. Text transcripts of voice and chat sessions, and any caller-supplied details collected by your flow (such as name, phone number, or appointment preferences). We do not record or store call audio.

Usage telemetry. Latency events, error traces, and feature interaction logs. Errors flow through Sentry with request bodies on billing, webhook, and auth routes stripped, and sensitive headers redacted, before send.

03 · Why we collect it

Purpose and lawful basis

We process personal information to operate, support, and improve the service you have asked us to provide.

Contract. Account creation, billing, flow operation, and the conversations your callers have with your agent.

Legitimate interests. Service security and abuse prevention, audit logging, error monitoring, and product improvement based on aggregate usage patterns.

Consent. Optional product updates and marketing email. You can withdraw consent at any time using the unsubscribe link or by emailing privacy@verticalai.com.au.

Legal obligation. Records we are required to keep under tax, financial-services, or telecommunications law.

04 · How long we keep it

Retention periods

Account, billing, and configuration data is retained while your account is active. Conversation transcripts and session events follow your organisation's retention window: 30, 90, 365, or 730 days, with 365 days the default. A daily scheduled job in Postgres purges rows past the window.

Submitting a deletion request triggers hard deletion of conversation transcripts and personal data with a 7-day operational SLA, well inside the 30-day window required by the Australian Privacy Act and GDPR Article 17.

The append-only audit log is retained for the lifetime of the account for security and accountability purposes. It records actor, action, and resource for billing, membership, and configuration changes; it does not contain conversation content.

Before any transcript line is written to the database, it passes through a redactor that masks credit card numbers (Luhn-validated), Australian Tax File Numbers, Medicare numbers, and US Social Security numbers. Operators should still avoid collecting regulated identifiers as flow variables where the conversation does not require it.

05 · Who we share it with

Sub-processors only

We share personal information only with the sub-processors required to deliver the service. Each is bound by a data processing agreement that limits processing to instructed purposes.

The full list of sub-processors, the data shared with each, and the region in which they operate is published at /sub-processors. We notify customers of material changes at least 30 days before a new sub-processor processes customer data.

We do not sell personal information.

06 · Your rights

Under the APPs and GDPR

The Australian Privacy Act 1988 (Cth) and its 13 Australian Privacy Principles (APPs) set out the rights below for Australian residents. Where GDPR applies, equivalent rights are noted in parentheses.

Request a copy of the personal information we hold about you. Email privacy@verticalai.com.au with your account email; we respond within 30 days. Self-serve export from inside the app is rolling out shortly.

Ask us to fix information that is inaccurate, out of date, incomplete, irrelevant, or misleading. Most account fields are user-editable in product. For everything else, email privacy@verticalai.com.au.

Request hard deletion of conversation transcripts and account data. Our operational SLA is 7 days, well inside the 30-day regulatory window. Records held under a legal obligation (for example, financial transaction records under tax law and append-only audit log entries retained for security purposes) are retained for the period that obligation requires.

Receive a structured export of your account and conversation data in a machine-readable format. Email privacy@verticalai.com.au and we will deliver the export within 30 days.

Raise a privacy concern with us at privacy@verticalai.com.au. If we do not resolve it to your satisfaction, you may complain to the Office of the Australian Information Commissioner at oaic.gov.au.

07 · How to exercise rights

Two paths

Email privacy@verticalai.com.au with your account email and the request. We respond within 30 days. We may request proof of identity before actioning a request that affects access to personal data. Self-serve export and erasure from inside the app are rolling out shortly.

08 · Data breach notification

Notifiable Data Breaches scheme

We comply with the Notifiable Data Breaches scheme under the Privacy Act 1988 (Cth). Where an eligible data breach is likely to result in serious harm, we notify affected individuals and the Office of the Australian Information Commissioner as soon as practicable, and within 72 hours of becoming aware where feasible.

Our incident response procedure rotates Stripe and Supabase credentials, audits the affected window via the audit log, and produces a written notice describing the breach, the kinds of information involved, and the steps individuals should take.

09 · International transfers

Where data goes

Customer data at rest stays in Sydney. Some sub-processors, including Stripe and our LLM, STT, and TTS vendors, operate from the United States and process limited data in transit.

Cross-border transfers rely on the standard contractual clauses or equivalent safeguards published by each vendor. The full list and the data shared with each is published at /sub-processors.

10 · Children

Not directed to under-16s

The service is for Australian businesses and is not directed to anyone under 16. We do not knowingly collect personal information from children. If you believe a child has provided us personal information, contact privacy@verticalai.com.au and we will delete it.

11 · Changes to this policy

Notice before material changes

We post material changes here and notify account owners by email and via an in-product banner at least 30 days before they take effect. Minor edits (clarifications, formatting) are dated at the top of this page.

12 · Contact

Reach the privacy team

Email privacy@verticalai.com.au with privacy questions, access requests, or breach reports.

If you remain unsatisfied after raising a complaint with us, you may escalate to the Office of the Australian Information Commissioner at oaic.gov.au.

Need a DPA?

Our standard DPA covers GDPR Article 28 and APP 8 obligations. Email the legal team for the latest version.

Request DPA
ProductFeaturesUse casesPricingPerformance
ExploreIndustriesCompareEnterpriseDocs
CompanyContactPressLocationsChangelog
LegalSecurityPrivacyTermsSub-processorsDPA
© 2026 VerticalAI · Built in Perth · Hosted in AustraliaVoice AI you can trust