At AuditLift, we understand that businesses trust us with information that may be important to their operations and customer relationships.
We are committed to handling information responsibly and using reasonable safeguards to protect information provided to us through our website, communications, onboarding process and AI Call Agent implementation services.
This User Data Protection Policy explains the general measures and practices we use to protect information.
This policy should be read together with our Privacy Policy, Cookie Policy, Terms of Service, AI Call Agent Terms & Conditions, and applicable Service Agreement.
1. Our Approach to Data Protection
AuditLift follows a principle of collecting, using and retaining only information reasonably necessary for the purpose for which it was provided.
We aim to:
- collect appropriate information;
- use information only for legitimate business purposes;
- limit access to authorized individuals;
- use reasonable security measures;
- work with reputable third-party technology providers;
- avoid unnecessary collection of sensitive information;
- maintain appropriate contractual protections; and
- respond appropriately to suspected security incidents.
2. Information We May Collect
Depending on how you interact with AuditLift, we may receive information such as:
- Contact Information
- Full name
- Business name
- Email address
- Telephone number
- Business website
- Business address
Business Information
When you request our AI Call Agent services, we may receive:
- Business hours
- Services offered
- Service areas
- Frequently asked questions
- Business policies
- Appointment information
- Call-handling instructions
- Lead qualification requirements
- Call-transfer instructions
- CRM or calendar information
- Other information necessary to configure your AI receptionist
Communications
We may also retain information contained in communications between you and AuditLift, including emails, support requests and implementation discussions.
3. Information Collected Through Our Website
The AuditLift website is primarily an informational HTML/CSS-based website.
Our website may contain simple contact or inquiry forms that allow visitors to voluntarily provide information such as:
- name;
- email;
- phone number;
- website;
- business information; and
- message or service requirements.
We use this information primarily to respond to inquiries and communicate with prospective or existing clients.
We do not use our website contact forms as a payment-card collection mechanism.
4. Payment Information
AuditLift does not operate a payment gateway or online card-payment form directly on the Website.
For services requiring payment, AuditLift may issue invoices through PayPal.
Payment information submitted through PayPal is processed by PayPal according to its applicable privacy policies, security practices and terms.
AuditLift does not intentionally request complete payment-card information, CVV codes, banking passwords or payment credentials through our website contact forms.
5. AI Call Agent Data
When AuditLift configures an AI Call Agent for a client, the system may process information provided by callers.
Depending on the client's configuration, this may include:
- caller name;
- telephone number;
- email address;
- service requirements;
- appointment information;
- location;
- customer questions;
- call transcripts;
- call recordings, where enabled;
- call summaries;
- lead information; and
- other information voluntarily provided during a call.
The exact information processed depends on the client's AI Call Agent configuration and the third-party technology used.
6. Client Responsibility for Caller Data
For AI Call Agent implementations, the client generally determines what information its AI receptionist collects from its customers and callers.
Clients are responsible for:
- determining what information is necessary;
- providing appropriate instructions to AuditLift;
- reviewing AI workflows before launch;
- providing legally required notices;
- obtaining legally required consent;
- establishing appropriate data-retention practices;
- responding to applicable customer privacy requests; and
- complying with laws applicable to their business.
AuditLift provides implementation and configuration services and does not provide legal advice regarding a client's specific privacy obligations.
7. Data Minimization
AuditLift encourages clients to configure AI Call Agents to collect only information reasonably necessary for the intended business purpose.
For example, an HVAC business may reasonably need:
Name + phone number + service required + location + preferred appointment time.
It generally should not ask a caller for unrelated sensitive information.
We recommend that clients avoid instructing AI Call Agents to collect unnecessary:
- Social Security numbers;
- passwords;
- authentication credentials;
- payment-card numbers;
- banking credentials;
- government identification numbers; or
- other highly sensitive information.
8. Sensitive Information
AuditLift's standard AI Call Agent implementation is not designed for unnecessary collection of highly sensitive personal information.
If a client requires an AI Call Agent to process sensitive, regulated or confidential information, the client must notify AuditLift before implementation.
Additional technical, contractual, privacy or regulatory requirements may apply.
9. Healthcare Information
Unless expressly agreed in writing, AuditLift's standard AI Call Agent service is not intended to process protected health information (�PHI�) subject to HIPAA.
Clients operating in healthcare or other regulated industries must notify AuditLift before providing or processing regulated information.
Where legally required, additional arrangements may be necessary, such as a Business Associate Agreement and appropriate third-party platform configuration.
AuditLift will not knowingly configure a standard implementation to process PHI without first determining whether additional contractual and technical requirements are necessary.
10. Third-Party Technology Providers
AuditLift may rely on third-party technology providers to deliver AI Call Agent functionality.
Depending on the project, these may include providers of:
- AI voice technology;
- telecommunications;
- telephone numbers;
- cloud infrastructure;
- speech recognition;
- text-to-speech;
- CRM systems;
- calendar systems;
- SMS services;
- automation services; and
- other integrations.
These providers may process information on behalf of the client or AuditLift depending on the service configuration.
Each provider may have its own privacy policy, security practices and terms of service.
11. Client-Owned AI Platform Accounts
Where possible, AuditLift recommends that clients maintain ownership of their underlying AI platform account.
Under this model:
- Client owns the platform account.
- Client pays the technology provider directly.
- AuditLift provides implementation and configuration services.
This approach provides clients with greater visibility and control over their underlying AI platform subscription and account.
12. Access Controls
AuditLift limits access to client information to individuals who reasonably require access to perform authorized business or implementation activities.
Where practical, access should be limited according to the principle of least privilege.
Client credentials should not be shared through unsecured channels.
AuditLift may use authorized account access provided by clients to configure and support their AI Call Agent systems.
13. Account Credentials
Clients are responsible for maintaining the security of their own third-party accounts.
Clients should:
- use strong passwords;
- enable multi-factor authentication where available;
- avoid sharing credentials;
- provide authorized access instead of sharing personal passwords where the platform supports it;
- remove AuditLift access when services are terminated where appropriate; and
- notify AuditLift of suspected unauthorized access.
AuditLift will not intentionally request a client's banking password, payment password or other unnecessary personal credentials.
14. Data Transmission
Information submitted through the Website or communicated to AuditLift may be transmitted through internet-based services.
Although AuditLift uses reasonable measures to protect information, no internet, email, cloud or telecommunications system can be guaranteed to be completely secure.
Clients and website visitors should avoid sending highly sensitive information through ordinary contact forms or unsecured email unless specifically requested through an appropriate secure process.
15. Data Storage
Information may be stored using systems and services used by AuditLift for legitimate business and service-delivery purposes.
Depending on the nature of the information, these systems may include:
- business email;
- cloud storage;
- project-management systems;
- CRM systems;
- AI platforms;
- telecommunications platforms; and
- other authorized business tools.
Retention periods may vary depending on the type of information and the reason it is being retained.
16. Data Retention
AuditLift does not retain personal or business information indefinitely unless there is a legitimate business, contractual or legal reason to do so.
We may retain information for purposes such as:
- providing contracted services;
- maintaining business records;
- resolving disputes;
- complying with legal obligations;
- accounting and tax requirements;
- preventing fraud or abuse; and
- maintaining appropriate service history.
When information is no longer reasonably required, we may delete, anonymize or securely dispose of it, subject to applicable legal or contractual requirements.
17. Call Recordings and Transcripts
If an AI Call Agent is configured to record calls or generate transcripts, those materials may contain personal or business information.
Call recordings and transcripts may be processed and stored by the applicable third-party AI or telecommunications provider.
Clients are responsible for determining:
- whether calls should be recorded;
- whether callers must be notified;
- whether consent is required;
- how recordings should be retained;
- when recordings should be deleted; and
- what privacy requirements apply.
AuditLift can assist with configuration where technically supported but does not provide legal advice concerning call recording laws.
18. Security Measures
AuditLift uses reasonable administrative, technical and organizational measures appropriate to the nature of the information handled.
Depending on the circumstances, these may include:
- access controls;
- account authentication;
- authorized user access;
- password protection;
- multi-factor authentication where available;
- secure third-party platforms;
- limited access to client information;
- data minimization;
- service-provider review; and
- appropriate deletion practices.
Security measures may vary depending on the technology platform and services involved.
19. No Absolute Security Guarantee
While we take reasonable steps to protect information, no method of electronic transmission, storage or processing is completely secure.
Accordingly, AuditLift cannot guarantee that information will never be:
- accessed without authorization;
- lost;
- disclosed;
- altered;
- intercepted; or
- compromised.
If a security incident occurs, AuditLift will take reasonable steps to investigate and respond based on the nature and circumstances of the incident and applicable legal requirements.
20. Security Incidents
If AuditLift becomes aware of a suspected security incident involving information under its control, we may take appropriate steps including:
- investigating the incident;
- limiting further unauthorized access;
- securing affected systems;
- determining the information involved;
- taking reasonable corrective measures; and
- providing notifications where required by applicable law or contractual obligations.
Where information is controlled by a third-party provider, that provider may have its own incident-response and notification obligations.
21. Third-Party Security
AuditLift may depend on third-party providers for certain technology services.
AuditLift evaluates third-party services based on factors appropriate to the service and intended use, but AuditLift cannot guarantee the security practices or availability of independent third parties.
Clients should review applicable third-party terms and privacy/security documentation when appropriate.
22. Data Sharing
AuditLift does not sell personal information simply because you submit an inquiry through our Website.
We may disclose information to authorized service providers when reasonably necessary to:
- operate our business;
- communicate with clients;
- deliver contracted services;
- configure AI Call Agents;
- provide technical support;
- process invoices;
- maintain systems;
- prevent fraud or security incidents; or
- comply with legal obligations.
We may also disclose information when required by law or when reasonably necessary to protect the rights, property or safety of AuditLift, our clients or others.
For additional information, please review our Privacy Policy.
23. International Data Processing
Because AuditLift may operate from outside the United States and may use international technology providers, information may be processed or stored in countries other than the country where the information was originally collected.
The privacy and data-protection laws of those countries may differ from those of your jurisdiction.
Where applicable, AuditLift will take reasonable steps to address relevant legal requirements concerning international data transfers.
24. U.S. State Privacy Rights
Depending on your state of residence and applicable law, you may have privacy rights concerning personal information.
These may include rights to:
- access information;
- request correction;
- request deletion;
- request portability;
- opt out of certain targeted advertising or sharing activities;
- limit certain uses of sensitive information; and
- exercise other rights provided by applicable law.
The availability of these rights depends on whether the applicable law applies to AuditLift and the particular processing activity.
Please see our Privacy Policy for additional information about privacy rights and how to submit a request.
25. Children's Information
AuditLift's services are intended for businesses and adults.
We do not knowingly design our Website or standard AI Call Agent services to collect personal information from children.
Clients are responsible for implementing appropriate safeguards where their business may receive calls or information from minors.
26. Client Data vs. AuditLift Data
For clarity, information may be handled in different capacities.
AuditLift Business Information
Information you provide directly to AuditLift for purposes such as:
- requesting a service;
- communicating with us;
- purchasing services;
- managing your business relationship; or
- receiving support.
Client Customer Information
Information collected through an AI Call Agent operating for a Client's business may belong to or be controlled by that Client, depending on the circumstances and applicable law.
The Client is responsible for determining its legal obligations regarding such customer information.
AuditLift acts according to the agreed service scope and instructions when providing implementation and support.
27. Data Protection Requests
If you have a privacy or data-protection request concerning information directly held by AuditLift, you may contact us.
Please include enough information for us to understand and verify your request.
We may need to verify your identity before processing certain requests.
Email: [YOUR PRIVACY EMAIL]
Subject: Data Protection Request
We will handle applicable requests in accordance with relevant law.
28. Changes to This Policy
We may update this User Data Protection Policy from time to time.
Updates may be necessary because of:
- changes to our services;
- changes to technology;
- changes to third-party providers;
- changes to our data practices;
- changes to applicable laws; or
- improvements to our security practices.
The updated policy will be published on this page with a revised �Last Updated� date.
29. Contact AuditLift
For questions concerning this User Data Protection Policy or our data-protection practices:
AuditLift
Website: https://auditlift.online/
Email: auditbiz.online@gmail.com
Business Address: Jaipur, Rajasthan, India.