Aussie AI Receptionist

Data Security

Last updated: 26 August 2026

Your customers' calls contain sensitive information. Here's how we protect it — in plain terms.

Your data is stored in Australia. Our database is hosted in the Sydney (ap-southeast-2) region, so your information stays onshore at rest.

The essentials

Stored in Australia

Call data is held in the Sydney region — onshore at rest, not offshore.

Encrypted

Data is encrypted in transit and at rest.

Short retention

Recordings are kept only briefly and access expires within days. We don't hoard your customers' voice data.

Client isolation

Row-level security means no Client can ever see another Client's calls or data.

Least-privilege access

Access is restricted to authorised personnel who need it to run the service.

Breach response

We follow the Notifiable Data Breaches scheme, with a 30-day assessment process.

Where your data lives

Your call recordings, transcripts, and job records are stored in our database hosted in Australia (Supabase, Sydney / ap-southeast-2 region). To place and process calls, some data passes through specialist providers — voice AI, language models, telephony — several of which operate overseas, primarily in the United States. The full list of providers and their locations is set out in our Privacy Policy, as required by Australian Privacy Principle 8.

Short retention by design

We deliberately keep call recordings only for a short period, and access to a recording expires within a few days of the call. You can request deletion of any recording at any time. Short retention is one of the strongest privacy safeguards a business can adopt: it keeps your customers' data footprint small and limits exposure in the unlikely event of an incident.

Isolation between clients

Every Client's data is separated at the database level using row-level security. A login for one business can only ever access that business's own records — never another Client's calls, customers, or reporting. This is enforced by the database itself, not just the application.

Access and encryption

Data is encrypted in transit (TLS) and at rest. Access to systems and data is limited to authorised personnel on a need-to-know basis. Administrative credentials are never exposed in client-facing applications.

If something goes wrong

No system is completely secure. If a data breach occurs that is likely to result in serious harm, we will assess it promptly and, where required, notify affected individuals and the Office of the Australian Information Commissioner (OAIC) under the Notifiable Data Breaches scheme. Our short-retention approach also limits the scope of any incident — because we hold recordings only briefly.

Questions

Security or data-handling questions? Email admin@aussieaireceptionist.com.au. For how we handle personal information generally, see our Privacy Policy.