This Privacy Policy explains how AskSiya Inc. ("AskSiya", "we", "us") collects, uses, discloses, and protects personal information when you use asksiya.com, the AskSiya dashboard, and the Siya voice service (together, the "Service"). We are a Canadian company and we take the privacy of both our customers and their callers seriously.
1. Who this policy covers
- Customers: the businesses (restaurants, hotels, motels, property managers) that create AskSiya accounts.
- Callers: people who phone a customer's business line answered by Siya, or who use the browser demo.
- Visitors: people browsing this website.
2. Information we collect
From customers
- Account details: name, email address, business name, business address, phone numbers.
- Business configuration: menus, prices, room types and rates, business hours, greetings, escalation contacts.
- Billing details: plan, invoices, and payment status. Card details are collected and stored by our payment processor (Stripe); we never see full card numbers.
- Team members: the name and email address of staff the account owner invites.
- Sign-in: if you choose "Continue with Google", we receive your name and email address from Google; we never see your Google password.
- Support correspondence: messages you send us through the in-app helpdesk or by email.
From callers
- Call audio and transcripts. When Siya answers a call, the conversation is processed in real time by our voice AI infrastructure to conduct the call, and a text transcript is retained. Transcripts, caller phone number, call time and duration, and the structured result of the call (an order, table reservation, room booking, appointment, maintenance ticket, or message, including any name, callback number, and address details the caller provides) are stored so the business can serve the caller. So that Siya can recognize returning callers, recent call history for a phone number is used to give the business context (for example, a repeat caller's last order).
- Browser demo audio is processed the same way to power the live demo; demo calls are capped and are not linked to an account.
From visitors
- Standard server logs (IP address, user agent, pages viewed) and, if we enable analytics, aggregate usage statistics. We do not run advertising trackers.
- Sign-in pages on the dashboard are protected by Google reCAPTCHA, which collects device and interaction signals to distinguish people from bots; Google's Privacy Policy and Terms of Service apply to it.
3. Call recording, transcription, and consent
Siya identifies herself as an automated assistant at the start of calls when the customer enables AI disclosure, and our terms require customers to enable it where the law demands it. Depending on the jurisdiction, notifying callers that a call is answered by an automated system and/or transcribed may be legally required (for example, all-party consent rules in some provinces and states). Customers are responsible for complying with the call-consent laws that apply to their business, and we provide the disclosure tools to make that straightforward. Transcript retention exists so the business has a record of its own customer interactions - the same way a written order slip would.
4. How we use information
- To operate the Service: answering calls, creating orders and bookings, sending notifications the customer configures.
- To maintain safety and quality: investigating failed calls, preventing abuse, improving Siya's accuracy on the customer's own configuration.
- To bill and support accounts.
- We do not sell personal information, and we do not use caller audio or transcripts to train foundation models.
5. Legal bases and Canadian/EU compliance
We handle personal information in accordance with Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and, where it applies to callers or customers in the European Economic Area, the General Data Protection Regulation (GDPR). Under the GDPR our legal bases are: performance of a contract (operating the Service for customers), legitimate interests (service quality, security, fraud prevention), and consent where required (for example, marketing emails). For caller data processed on behalf of our customers, AskSiya generally acts as a service provider/processor and the customer is the controller.
6. Sharing and subprocessors
We share personal information only with the subprocessors needed to run the Service:
- A telephony carrier (call routing and phone numbers).
- Realtime voice AI infrastructure (the speech processing that powers Siya during a call).
- A payment processor (card details never reach our servers).
- A transactional email delivery provider (notifications and account emails).
- A bot-protection and optional sign-in provider on our dashboard sign-in pages.
- Cloud hosting, encrypted offsite backup storage, content delivery, and business email providers.
A current list of subprocessors is available on request at contact@asksiya.com.
Each subprocessor is bound by contractual confidentiality and data-protection obligations. We may also disclose information when required by law.
7. Retention
- Call transcripts and structured results are retained for the life of the customer account so the business keeps its records.
- After an account closes, data is exportable for 30 days, then deleted or anonymized within a reasonable period.
- Expired-trial configurations are kept for 30 days and then anonymized.
8. Security
All data is encrypted in transit (TLS). Production access is limited to personnel who need it to operate the Service, credentials and secrets are stored in managed configuration (never in code), and offsite database backups are stored with a provider that encrypts stored data. No system is perfectly secure; we will notify affected parties of a breach as required by law.
9. Your rights
Subject to applicable law, you may request access to, correction of, or deletion of your personal information. EEA residents additionally have rights to restriction, portability, and objection, and the right to lodge a complaint with a supervisory authority. Canadians may contact the Office of the Privacy Commissioner of Canada. Callers should direct requests about a specific business's records to that business first (they control the data); we support our customers in fulfilling them.
10. International transfers
Our production infrastructure and most subprocessors process data in the United States; AskSiya Inc. is a Canadian company, and website content is delivered from global CDN edge locations. Where personal data leaves its region of origin we rely on appropriate safeguards such as standard contractual clauses.
11. Children
The Service is for businesses and is not directed at children under 13, and we do not knowingly collect their information.
12. Changes
We will post any changes to this policy on this page and update the date above. Material changes will be announced to customers by email.
13. Contact
Privacy questions or requests: contact@asksiya.com
AskSiya Inc., Toronto, Ontario, Canada.