Vertical AI
  • Product
    • Features
    • Use Cases
    • Pricing
    • Performance
  • Integrations
    • Salesforce
    • HubSpot
    • Slack
    • Google Calendar
    • Zendesk
    • Stripe
  • Industries
    • Healthcare
    • Financial Services
    • Insurance
    • Logistics
    • Home Services
    • Retail
    • Hospitality
    • Debt Collection
  • Compare
    • vs Retell AI
    • vs Bland AI
    • vs Vapi
    • vs Synthflow
  • Resources
    • Case studies
    • Security
    • Privacy
    • Terms
    • Sub-processors
    • DPA
    • Changelog
    • Press
    • Contact
  • Partners
    • Who we work with
    • Adapt
    • Partner program
  • Enterprise
Log inBook a demo
Product
All productFeaturesUse CasesPricingPerformance
Integrations
All integrationsSalesforceHubSpotSlackGoogle CalendarZendeskStripe
Industries
All industriesHealthcareFinancial ServicesInsuranceLogisticsHome ServicesRetailHospitalityDebt Collection
Compare
All comparevs Retell AIvs Bland AIvs Vapivs Synthflow
Resources
All resourcesCase studiesSecurityPrivacyTermsSub-processorsDPAChangelogPressContact
Partners
All partnersWho we work withAdaptPartner program
Enterprise
Log in
Book a demo

Privacy

Privacy policy.

How we handle personal information across our website, platform, voice agents, text agents, and outbound campaigns.

Email privacy teamSub-processors

01 · About this policy

Who we are and what this covers

Last updated 17 July 2026

VERTICAL AI PTY LTD (ABN 73 695 607 946) operates VerticalAI. Our address is Perth WA 6000, Australia. Contact us at privacy@verticalai.com.au.

This policy covers our public website, sales activities, accounts, application, voice and text agents, inbound and outbound calls, campaigns, support, and related services. It explains how we handle personal information under the Privacy Act 1988 (Cth), the Australian Privacy Principles (APPs), and other laws that apply to us.

A customer contract, data processing agreement (DPA), or service schedule may impose tighter terms. Those terms apply to the extent of any inconsistency with this policy.

02 · Privacy roles

Customers, users, callers, and contacts

We control personal information used for our website, accounts, billing, security, sales, marketing, and direct customer relationships.

A business customer usually decides why and how its agent handles caller, recipient, employee, and end-user information. For that customer content, we act as the customer's service provider or processor and follow its documented instructions, contract, and applicable law. Requests about a customer's call or message may need to go to that customer first.

03 · Information we handle

Data depends on how you use VerticalAI

Account and business data. Names, work contact details, organisation, role, workspace membership, authentication records, preferences, agreements, support messages, and audit events.

Sales and enquiry data. Contact details, meeting details, referral source, correspondence, call notes, product interests, and information supplied through forms, email, events, social platforms, Cal.com, or sales partners.

Billing data. Billing contacts, plan and usage, invoices, transaction references, and payment tokens. Stripe handles payment-card details under its own privacy and security terms.

Voice, text, and campaign data. Phone numbers, caller ID, recipient lists, consent and suppression records, call metadata, audio or recordings when enabled, transcripts, messages, prompts, agent instructions, tool inputs and outputs, outcomes, and details a person shares during a conversation.

Connected service data. Connector settings, access tokens, identifiers, and data exchanged with systems a customer connects, such as calendars, CRMs, webhooks, and automation tools.

Device, website, and cookie data. IP address, browser and device details, pages and features used, timestamps, referrer, approximate location derived from IP, cookie identifiers, diagnostics, and security events.

04 · Collection

Where information comes from

We collect information from you, our customers and their users, callers and message recipients, connected services, payment and communications providers, public business sources, referrals, social and advertising platforms, and devices that access our services.

If you do not provide required account, billing, security, or service data, we may be unable to open an account, provide a feature, respond to an enquiry, process payment, or meet legal and security requirements. Optional fields can be left blank unless we say otherwise.

05 · Purposes

How and why we use information

We use personal information to provide and administer the service, route and process conversations, run customer-configured tools and connectors, manage accounts and payments, support users, secure the platform, prevent abuse, investigate incidents, keep records, and comply with law.

We also use information to measure service performance, debug failures, develop and improve features, forecast capacity, conduct research using aggregated or de-identified information, communicate about the service, and manage sales and customer relationships.

Where a law requires a legal basis, we rely as appropriate on performance of a contract, legitimate interests, consent, compliance with legal obligations, and protection of vital or legal interests. Australian privacy law may instead permit use where it relates to the primary collection purpose or where another exception applies.

06 · AI and connectors

Customer instructions shape each agent

We send relevant conversation context and instructions to model, speech, telephony, and connector providers so an agent can respond and complete customer-configured tasks. Outputs can be inaccurate. Customers must review agent design, permissions, disclosures, and outcomes for their use case.

We do not use customer content to train shared models unless the customer gives express opt-in consent. Customer content includes prompts, transcripts, recordings, messages, connector data, and tool results. We require providers to handle data under their service terms and the settings available for our account.

We do not send prompts, transcripts, call audio, secrets, or sensitive call content to PostHog. Customers control which external systems they connect and should grant only the permissions their agent needs.

07 · Marketing and analytics

Communications, cookies, and measurement

Direct marketing. We may send product, event, or service marketing to business contacts and sales leads where permitted by law. You can unsubscribe through the message or by contacting us. We may still send account, billing, security, and service notices.

We use essential cookies for sign-in, preferences, security, and service operation. We may use PostHog for product and website analytics and Meta technologies for advertising, campaign measurement, and lead management. PostHog may receive account-user and direct sales lead contact details, stable identifiers, workspace details, device data, pages and features used, and campaign information. It does not receive customer prompts, transcripts, call audio, secrets, or sensitive call content. Meta may receive device, cookie, campaign, and form data, subject to consent controls where required.

Browser controls can limit cookies, but some account features may not work. Advertising choices do not stop non-advertising service messages.

08 · Disclosures

Who may receive information

We disclose information to hosting, database, AI, speech, telephony, communications, authentication, analytics, support, payment, scheduling, connector, and automation providers. Relevant providers include PostHog, Meta, Cal.com, Zapier, and Stripe. See our sub-processor list.

We may also disclose information to a customer that controls it, its authorised users and connected services, our professional advisers, auditors and insurers, regulators, courts, law enforcement, and parties involved in a financing, reorganisation, merger, sale, or transfer of assets. We may disclose information where law permits or requires it, or to protect people, rights, systems, and property.

We do not sell customer conversation content. Some privacy laws define advertising disclosures more broadly than an ordinary sale. Where those laws apply, we provide the choices they require.

09 · Overseas processing

Providers operate in several countries

Core application data may be hosted in Australia, but we do not claim that all processing occurs here. Providers and support teams may process information in Australia, the United States, and countries in the European Union, including Germany and Ireland. Global networks may route data through other locations.

We assess providers and use available contractual, organisational, regional, and technical safeguards. These may include contractual transfer terms, access controls, encryption, and regional hosting. APP 8 and other cross-border rules apply where required. A customer contract or DPA may set narrower location terms.

10 · Security

Controls proportionate to the risk

We use administrative, technical, and physical safeguards designed for the nature of the information and service. Controls include access restrictions, authentication, encryption in transit and at rest where supported, logging, backups, monitoring, supplier review, and incident response.

No internet service can guarantee complete security. Customers must protect credentials, configure roles and connectors, limit data collection, and tell us about suspected misuse.

11 · Retention

We keep information for a justified period

Retention depends on the data type, account settings, customer instructions, contract, security and dispute needs, backup cycles, and legal obligations. Customer-configured retention can apply to recordings, transcripts, and session data. We may keep billing, tax, consent, suppression, audit, and legal records after an account ends.

When information is no longer required, we delete it, de-identify it, or restrict it from ordinary use where reasonably practicable. Deletion from active systems and backups may occur on different schedules. We do not promise an absolute deletion period unless a customer contract or applicable law sets one.

12 · Access and choices

Requests depend on your location and role

You may ask to access or correct personal information under APP 12 and APP 13. We may verify your identity, consult the customer that controls the data, charge a permitted access cost, or refuse a request where law allows. If we refuse, we will explain the reason and available complaint steps where required.

You may also ask us to delete information or close an account. We will consider the request but may retain information where a customer instruction, contract, security need, legal claim, or law requires it. Australian law does not provide a general right to erasure.

Where the GDPR applies, you may have rights to erasure, restriction, objection, portability, and withdrawal of consent, plus the right to complain to a supervisory authority. These rights have legal limits. Send requests to privacy@verticalai.com.au.

13 · Special categories

Extra care for sensitive information

Conversations may contain sensitive information, including health, disability, racial or ethnic origin, religious beliefs, sexual orientation, union membership, criminal history, or biometric information. Customers should collect sensitive information only where lawful and necessary. We handle it on customer instructions or where consent or another legal exception permits.

Do not configure agents to collect government identifiers, payment card security codes, or identity documents unless the use is lawful, necessary, and protected by suitable controls. We use or disclose government-related identifiers only as permitted by law.

14 · Collection limits

Anonymity and unsolicited information

You may browse public pages without identifying yourself. You may use a pseudonym where practicable, but we need accurate details for accounts, contracts, billing, support, security, and regulated transactions.

If we receive unsolicited personal information, we assess whether we could have collected it lawfully. If not, we destroy or de-identify it where lawful and reasonably practicable.

15 · Children

The service is built for organisations

Our accounts and sales services are not directed to children under 16. A customer's agent may interact with a child where the customer has a lawful use case. The customer must set suitable notices, consent, collection limits, and human escalation. Contact us if you believe we hold a child's information unlawfully.

16 · Automated decisions

Agents can take configured actions

Agents use models and customer instructions to respond, classify conversations, route contacts, and take configured actions. These processes may affect service access or the outcome of an interaction. Customers decide the purpose, rules, tools, and human review for their agents.

Customers should not use the service as the sole basis for decisions that create significant legal or similar effects unless they have assessed the law, accuracy, fairness, explanation, review, and challenge rights that apply.

17 · Breaches and complaints

How we respond

We investigate suspected data breaches and follow the Notifiable Data Breaches scheme. Where the law requires, we notify affected people and the Office of the Australian Information Commissioner (OAIC) and give recommended response steps.

Send a privacy complaint to privacy@verticalai.com.au. Include enough detail for us to investigate. We will acknowledge and handle the complaint within a reasonable period. If you remain dissatisfied, you may contact the OAIC at oaic.gov.au.

18 · Changes and contact

Policy updates and privacy contact

We may update this policy as our services, providers, and legal obligations change. We publish the current version here and update the date above. We may give additional notice where a change is material or a contract requires it.

Contact VERTICAL AI PTY LTD at privacy@verticalai.com.au or write to Perth WA 6000, Australia.

Customer privacy terms

Customer contracts and DPAs can set tighter processing, security, residency, and retention terms.

View DPA
ProductFeaturesIntegrationsUse casesPricingPerformance
ExploreIndustriesCompareEnterprisePartnersPartner program
CitiesAll locationsSydneyMelbourneBrisbanePerthAdelaideCanberra
CompanyAboutContactPressBook a workshopChangelog
LegalSecurityPrivacyTermsSub-processorsDPA
© 2026 VERTICAL AI PTY LTD · ABN 73 695 607 946 · Perth WA 6000, AustraliaVoice AI you can trust