Skip to main content
LyraTalk

Legal

Privacy Policy

Last updated 1 September 2026.

LyraTalk is operated by Agentonic AI LLC (“LyraTalk”, “we”, “us”, “our”), a limited liability company based in Orange County, California. This policy explains what personal information we collect, why, who we share it with, how long we keep it, and what you can ask us to do with it.

It covers three situations: browsing our website, using LyraTalk as a customer, and calling a business whose phone is answered by a LyraTalk agent.

1. Customers and callers are treated differently

Customers are businesses that subscribe to LyraTalk. For their account information we are the controller, and this policy governs directly.

Callersare people who contact a customer’s phone number, chat widget or SMS number and reach an agent. For that conversation the business you contacted is the controller and LyraTalk is its processor: we handle the data on their instructions and do not use it for our own purposes. If you are a caller and want your information corrected or deleted, contact the business you called. You may also contact us at info@lyratalk.ai and we will route your request to them and assist in fulfilling it.

2. Information we collect

When you use our website

  • Pages viewed, referring page, approximate location derived from IP address, browser and device type, collected through Google Analytics.
  • Technical diagnostics when something fails, including the URL, the error and limited request context, collected through Sentry.
  • Anything you choose to send us by email.

When you create and run an account

  • Name, business name, email address and password credentials, handled by our authentication provider, Clerk. We never see or store your password.
  • Billing name, address, subscription plan and payment history. Card numbers are entered directly with Stripe and are never transmitted through or stored on our systems.
  • Configuration you supply so the agent can do its job: business hours, services, prices, policies, staff names, phone numbers and any documents you upload to its knowledge base.
  • Credentials or tokens authorising us to connect to your booking or CRM system, stored encrypted.

When an agent handles a conversation

  • Call audio. Telephone calls are recorded and the audio file is stored in Amazon S3.
  • Transcripts and summaries. Every session produces a text transcript, a summary and structured data extracted from the conversation. This includes web chat and SMS sessions, which have no audio recording.
  • Contact details.The caller’s telephone number, and whatever they provide during the conversation: name, email address, appointment preferences, and any other detail needed to complete their request.
  • Records in connected systems.Where a customer has connected a booking or practice management system, the agent reads and writes records in that system on the customer’s behalf.

We do not ask callers for payment card numbers, Social Security numbers or government identifiers, and agents are instructed not to collect them.

3. Call recording and consent

Telephone calls handled by a LyraTalk agent are recorded and transcribed. Recording is enabled by default so that customers have an accurate record of what was said and agreed.

California, where we are based, is a two-party consent state, and several other states have comparable laws. Customers configure the spoken disclosure their agent gives at the start of a call, and each customer is responsible for ensuring callers to its numbers are notified that the call is recorded, and for obtaining consent where the law of the relevant jurisdiction requires it. We provide the disclosure mechanism; the customer decides its wording and is accountable for using it.

If you are a caller and do not wish to be recorded, say so and ask to be transferred to a member of staff, or contact the business directly by another channel.

4. How we use information

  • To provide the service and let the agent complete requests.
  • To show customers their own call history, transcripts, summaries and analytics.
  • To take payment, and to prevent fraud and abuse.
  • To operate, monitor, debug and secure the service, including investigating a call that went wrong.
  • To send service messages such as billing notices, security alerts and material changes to this policy.
  • To comply with law and enforce our terms.

We do not sell personal information, and we do not share it for cross-context behavioural advertising. We do not use customer call content to train general-purpose AI models, and our model providers are engaged under terms that prohibit them from doing so with data we send.

5. Legal bases

Where the GDPR or UK GDPR applies, we rely on: performance of a contract, for account and service data; legitimate interests, for security, debugging, fraud prevention and service improvement; consent, where required for a particular processing activity such as non-essential analytics; and legal obligation, for tax and accounting records.

6. Who we share information with

We share personal information only with service providers who process it on our behalf under written terms:

  • Amazon Web Services for hosting, databases and recording storage
  • Stripe for payment processing and card handling
  • Clerk for account authentication
  • Telnyx and LiveKit for telephony, SMS and real-time audio transport
  • OpenAI for the language and speech models the agent runs on
  • Amazon SES for transactional email
  • Sentry for error reporting and diagnostics
  • Google Analytics for website analytics, on our marketing pages only, never inside the customer dashboard

We also disclose information where we are legally required to, where necessary to protect our rights or someone’s safety, and to an acquirer in a merger or sale of assets, in which case this policy continues to apply until the acquirer gives notice of its own.

7. International transfers

We process and store information in the United States. If you access the service from outside the United States, your information is transferred there. Where required, we rely on the European Commission’s Standard Contractual Clauses and equivalent UK transfer mechanisms with our providers.

8. How long we keep it

  • Call recordings, transcripts and summaries.Kept for as long as the customer’s account is active, then deleted within 30 days of account closure. Customers may delete an individual recording or transcript at any time from the dashboard, and may ask us to apply a shorter retention period to their account.
  • Account and configuration data. Kept for the life of the account, then deleted within 30 days of closure.
  • Billing and tax records. Kept for seven years, as required by US tax and accounting rules, after which they are deleted.
  • Website analytics. Retained for 14 months.
  • Error and diagnostic logs. Retained for 90 days.

We may retain information for longer where we are required to by law or where it is needed to resolve a dispute or enforce our agreements. Backups are overwritten on a rolling 35-day cycle.

9. Your choices and rights

Subject to verification of your identity, you may ask us to give you a copy of the personal information we hold about you, correct it, delete it, export it in a portable format, restrict or object to particular processing, or withdraw a consent you previously gave.

Email info@lyratalk.ai. We respond within 30 days, and will tell you if we need longer and why. We will not discriminate against you for exercising these rights.

California residents. Under the CCPA as amended by the CPRA you have the rights above, plus the right to know the categories of personal information collected, the purposes for collecting them and the categories of third parties they are disclosed to, all of which are set out in sections 2, 4 and 6. We do not sell personal information and we do not share it for cross-context behavioural advertising, so there is nothing to opt out of. You may use an authorised agent to make a request.

EEA and UK residents. You may also lodge a complaint with your local supervisory authority.

10. Health information

Some LyraTalk customers are healthcare providers. Where a customer is a covered entity under HIPAA and we handle protected health information on their behalf, we act as a business associate and enter into a Business Associate Agreement before any such information is processed. Contact us to put one in place. If you are a patient with a question about your health information, contact the practice you called; they are the covered entity.

11. Security

Personal information is encrypted in transit using TLS and encrypted at rest. Access is role-based and limited to personnel who need it, each customer’s data is isolated to their own account, and integration credentials are stored encrypted. We monitor for unusual activity and review access periodically. No system is perfectly secure, and we do not claim otherwise; if a breach affects your personal information we will notify you and any regulator as the law requires.

12. Children

LyraTalk is a business service and is not directed to children under 13, and we do not knowingly collect their personal information. A child’s details may incidentally appear in a call where a parent books an appointment on their behalf; that information is handled as part of the customer’s record and under their control. If you believe we hold a child’s information that should not be there, contact us and we will delete it.

13. Changes to this policy

We will post any revised version on this page and update the date at the top. If a change materially affects how we handle personal information, we will notify customers by email at least 14 days before it takes effect.

14. Contact us

Agentonic AI LLC, Orange County, California, United States.
info@lyratalk.ai

See also our Terms of Service.