This Privacy Policy explains how AskSiya Inc. ("AskSiya", "we", "us") collects, uses, discloses, and protects personal information when you use asksiya.com, the AskSiya dashboard, and the Siya voice service (together, the "Service"). We are a Canadian company and we take the privacy of both our customers and their callers seriously.
Siya identifies herself as an automated assistant at the start of calls when the customer enables AI disclosure, and our terms require customers to enable it where the law demands it. Depending on the jurisdiction, notifying callers that a call is answered by an automated system and/or transcribed may be legally required (for example, all-party consent rules in some provinces and states). Customers are responsible for complying with the call-consent laws that apply to their business, and we provide the disclosure tools to make that straightforward. Transcript retention exists so the business has a record of its own customer interactions - the same way a written order slip would.
We handle personal information in accordance with Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and, where it applies to callers or customers in the European Economic Area, the General Data Protection Regulation (GDPR). Under the GDPR our legal bases are: performance of a contract (operating the Service for customers), legitimate interests (service quality, security, fraud prevention), and consent where required (for example, marketing emails). For caller data processed on behalf of our customers, AskSiya generally acts as a service provider/processor and the customer is the controller.
We share personal information only with the subprocessors needed to run the Service:
Each subprocessor is bound by contractual confidentiality and data-protection obligations. We will publish a current subprocessor list before general availability. We may also disclose information when required by law.
Data is encrypted in transit (TLS) and at rest. Access to production data is limited to personnel who need it to operate the Service, and secrets are stored in managed configuration, never in code. No system is perfectly secure; we will notify affected parties of a breach as required by law.
Subject to applicable law, you may request access to, correction of, or deletion of your personal information. EEA residents additionally have rights to restriction, portability, and objection, and the right to lodge a complaint with a supervisory authority. Canadians may contact the Office of the Privacy Commissioner of Canada. Callers should direct requests about a specific business's records to that business first (they control the data); we support our customers in fulfilling them.
Our infrastructure and subprocessors may process data in Canada, the United States, and the European Union. Where data leaves its region of origin we rely on appropriate safeguards such as standard contractual clauses.
The Service is for businesses and is not directed at children under 13, and we do not knowingly collect their information.
We will post any changes to this policy on this page and update the date above. Material changes will be announced to customers by email.
Privacy questions or requests: privacy@asksiya.com
AskSiya Inc., Toronto, Ontario, Canada.