1. Who We Are and What This Policy Covers
Ulyvero, Inc., a Delaware corporation, provides an AI-powered front office for businesses. This policy covers ulyvero.com, our account experience, and AI communications we operate for business customers. We are a controller for business-account information and a processor for the personal data our customers instruct us to handle about their callers and contacts.
2. Information We Collect
- Account data, including business and user names, email, phone, authentication data, settings, plan, and authorized users.
- Business knowledge you provide, including FAQs, documents, service details, hours, routing rules, and contact directories.
- Conversation records, including messages, transcripts, optional recordings, phone numbers, contact details, call metadata, and actions taken during a conversation.
- Appointments, contacts, billing and subscription records. Stripe processes full payment-card details; Ulyvero does not store them.
- Security, device, log, and interaction data; strictly necessary cookies; and cookieless or privacy-preserving analytics.
- Information supplied for a personalized demo.
3. How We Use Information
- Provide calls, texts, chats, appointments, notifications, dashboard functions, support, and billing.
- Detect fraud, abuse, safety issues, malfunction, and quality drift, and apply bounded protective actions.
- Validate improvements in a sandbox that does not contact a real person.
- Communicate about the Service and send optional marketing to business contacts with unsubscribe honored.
- Comply with law and enforce agreements.
4. AI Processing
Conversation content may be processed by AI language and voice providers acting under contract. Providers may use the data only to deliver the contracted service, not to train their public foundation models. Transient retention for response caching, security, and abuse prevention may apply.
5. Service Providers, Data Shared, and Business Transfers
Depending on the features used, we share account identifiers, business configuration, conversation content and metadata, appointment data, subscription records, and security or device data with service providers only as needed to perform their contracted functions. Categories of recipients include hosting, authentication, communications, AI inference, voice synthesis, payment, email, monitoring, business enrichment, and connected-calendar providers. The current provider list is available on the Subprocessors page. We may transfer information in a reorganization, financing, merger, acquisition, or asset sale subject to this policy and required notice.
6. Data Retention
- Account data, business knowledge, contacts, and appointments are retained while the account is active.
- Transcripts and message content are retained while the account is active unless a shorter setting applies. Default transcript and summary retention is 12 months.
- Optional call audio may be retained by the voice provider under a shorter provider window. Ulyvero does not keep a separate copy unless expressly shown in the dashboard.
- Safety and conversation-activity records are deleted after 90 days unless needed for a security or legal matter.
- Following account deletion, covered data is deleted within 30 days, subject to legal, tax, consent, de-identified, backup, and provider-retention exceptions.
7. Data We Process for Our Customers
Our business customers decide why and how their callers’ data is processed. We process it on documented instructions to handle inbound and authorized outbound communications, pass information within the customer account, create contact and appointment records, record calls when enabled with required disclosure, and perform the quality and safety operations described above. Individuals should ordinarily direct privacy requests to the business they contacted; we will assist that business.
8. Security
We use administrative, technical, and organizational safeguards including encryption in transit and at rest, role-based access, tenant isolation, restricted service credentials, audit logs, data minimization, and incident response. No system is perfectly secure. We provide legally required breach notices.
9. AI Accuracy
AI-generated content can be inaccurate. Business customers are responsible for reviewing output that affects their operations and for maintaining a route to a person where appropriate.
10. Cookies and Browser Signals
We use strictly necessary cookies for authentication, session security, preferences, and payment flow. We do not use cross-site advertising trackers, and other parties do not collect personal information through Ulyvero over time across unaffiliated websites for targeted advertising. Because we do not engage in that tracking, legacy browser Do Not Track signals do not change how the Service operates. If these practices change, we will update this policy and implement legally required consent and opt-out controls before the change is deployed.
11. Delaware and US State Privacy Rights
Where the Delaware Personal Data Privacy Act or another applicable US state privacy law applies, eligible residents may request confirmation and access, correction, deletion, a portable copy of personal data, and a list of the categories of third parties to which personal data was disclosed. Eligible residents may also opt out of targeted advertising, sale, and qualifying profiling. Ulyvero does not sell personal data or use it for cross-context behavioral advertising.
We respond without undue delay and, for Delaware requests, within 45 days. We may extend once by up to 45 additional days when reasonably necessary and will explain the extension during the initial response period. If we deny a request, we will explain why and how to appeal. We decide Delaware appeals in writing within 60 days and, if an appeal is denied, provide a method to contact the Delaware Department of Justice. We do not discriminate against anyone for exercising a privacy right.
12. Sensitive Data and Consent
When Ulyvero acts as a controller and applicable law requires consent to process sensitive data, we obtain a clear affirmative consent and provide a revocation method that is at least as easy to use. Where the Delaware Personal Data Privacy Act applies, we stop the consent-based processing as soon as practicable and no later than 15 days after a valid revocation request. When Ulyvero acts as a processor, the business customer is responsible for establishing the lawful basis and providing any notice or consent required for the data it instructs us to process.
13. De-identified and Aggregated Data
We may use de-identified and aggregated usage patterns to improve reliability, safety, and quality. We maintain the data in de-identified form and do not attempt to re-identify it except to test our de-identification controls as permitted by law.
14. International Processing
The Service is operated from the United States and offered primarily to US businesses. If data is transferred from a jurisdiction that requires a transfer mechanism, the DPA and applicable contractual safeguards govern.
15. Data Processing Addendum
The Data Processing Addendum applies to all business customers and is incorporated into the Terms. An executed counterpart is available when required for procurement.
16. Children
The Service is not directed to children under 13. Business customers must not configure Ulyvero for child-directed use or submit children’s sensitive data without a lawful basis and all required parental consent.
17. Changes
We will post updates here and provide at least 14 days notice before a material change becomes effective, unless a faster change is required by law or needed to address an urgent security issue.
18. Contact, Requests, and Appeals
Submit privacy requests, authorized-agent requests, appeals, and questions by emailing admin@ulyvero.com. No new account is required. We use commercially reasonable methods to authenticate requests before disclosing, correcting, or deleting personal data. Support requests may also be sent to admin@ulyvero.com. Include the state where you reside and enough information for us to authenticate and process the request. An authorized agent must provide legally sufficient authority. We use the same email channel for appeals and may request additional information when commercially reasonable authentication is not possible.