Privacy Policy
Last Updated: April 22, 2026
1. Introduction
This Privacy Policy describes how 15336732 CANADA INC. (the "Company," "we," "us," or "our"), collects, uses, discloses, and protects information in connection with the Agentic Front Desk service (the "Service").
We are committed to protecting the privacy and security of all individuals whose data is processed through the Service. This Policy applies to: (a) business subscribers ("Subscribers") who use the Service, (b) the end-user clients ("Callers") who interact with the AI receptionist, and (c) visitors to our website.
2. Data Storage & Ownership
Agentic Front Desk stores the minimum client data needed to operate your AI receptionist — customer names, phone numbers, appointment history, and your staff/service directory — in our own secured database, hosted on Amazon Web Services in Canada (ca-central-1). We do not store Protected Health Information (PHI) as part of the standard appointment-booking Service. Your Google Calendar remains the record of scheduled appointments, owned and controlled entirely by you.
The optional In-Room Clinical Transcription Add-On is different: it does process and store a limited set of PHI (a patient-identifier index record; the clinical note and transcript themselves are written only to your own Google Workspace), and it may only be enabled after a Business Associate Agreement is executed. See In-Room Clinical Transcription and the Data Processing Agreement, Schedule B, for full details.
We act as a Data Processor on your behalf. Access to your data is restricted by tenant-level database controls (each business's data is isolated from every other business's), encrypted at rest and in transit, and used solely to operate the Service for your account.
3. Information We Collect
3.1 Subscriber Information (Business Accounts)
When you subscribe to the Service, we collect:
- Account Information: Business name, contact name, email address, phone number, and mailing address.
- Billing Information: Payment card details (processed and stored exclusively by Stripe, Inc.; we do not store card numbers).
- Configuration Data: Business records ID, calendar IDs, service names, professional names, and business settings.
3.2 Caller Information (End Users / Patients / Clients)
When a Caller interacts with the AI receptionist, the following data is processed:
- Caller ID: The phone number from which the call originates, used to cross-reference the Subscriber's business records and stored as part of that Subscriber's client records, as described in Section 2.
- Voice Audio: Real-time audio streams processed during active calls to generate text transcripts and AI responses. Audio is not recorded or stored.
- In-Room Session Audio (Clinical & Elite add-on, or Transcription-Only Service): When in-room voice transcription is enabled and a session is initiated by Subscriber staff, audio is captured with explicit patient consent and transcribed in real time. Audio is never recorded or stored — it is processed in memory and discarded the moment it is transcribed. The generated clinical note and the full verbatim transcript are written to the Subscriber's own Google Workspace (Drive), not to our systems. We do retain session metadata — patient name and phone number, provider name, appointment date, duration, session status, and a link to the Subscriber's own document — in our tenant-isolated database, so the Subscriber can see and manage their Clinical Notes records; this metadata is subject to the retention schedule in Section 7.
- Room Assistant Application (shared in-room devices): A Subscriber may deploy the Moonlight AI Room Assistant Android application on a shared in-room device — for example a Temi robot moving between exam rooms — in place of a fixed tablet. The device authenticates using an organization-issued credential managed by the Subscriber's administrator, and each provider identifies themselves with a short numeric PIN before starting a session. The application requests microphone access only, stores no patient data on the device, and holds the provider's session token in memory only (never written to device storage). It processes the same data categories described in the In-Room Session Audio item above and no others.
- Conversational Data: The AI's interpretation of the caller's intent (e.g., "book haircut on Monday at 2 PM"); the resulting booking outcome is stored as part of the Subscriber's client records.
- Calendar Data: Appointment details read from and written to the Subscriber's Google Calendar.
3.3 Website Visitor Information
When you visit our website, we may collect standard web analytics data including IP address, browser type, referring page, and pages visited. This data is collected via cookies and similar technologies as described in Section 12.
4. How We Use Information
We use the information we collect for the following purposes:
- To provide, operate, and maintain the Service.
- To process appointments, cancellations, and schedule modifications on behalf of Subscribers.
- To send SMS appointment confirmations and reminders (where enabled by the Subscriber).
- To generate anonymized usage analytics and billing reports.
- To monitor service health, diagnose technical issues, and improve reliability.
- To comply with legal obligations, including tax reporting and regulatory requirements.
- To detect, prevent, and address fraud, abuse, and security incidents.
We do NOT use Personal Data for:
- Direct marketing or advertising (we will never contact your clients for our own purposes).
- Selling, renting, or sharing data with third-party marketers.
- Training, fine-tuning, or improving AI models (see Section 5).
- Profiling individuals for purposes unrelated to appointment scheduling.
5. SMS and Mobile Privacy Compliance
No mobile information will be shared with third parties or affiliates for marketing/promotional purposes. All other categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties.
Consent for SMS messaging is collected independently and is used solely for the purposes of appointment confirmations and reminders requested by the Caller or Subscriber. Message frequency varies based on appointment activity and user requests. As always, message and data rates may apply for any messages sent to you from us and to us from you. If you have any questions about your text plan or data plan, please contact your wireless provider.
6. AI Model Training — Absolute Prohibition
No customer data from any source — including voice audio, text transcripts, caller phone numbers, appointment details, client names, health information, or any other Personal Data — is or will ever be used to train, fine-tune, evaluate, benchmark, or improve any Large Language Model (LLM), artificial intelligence model, or machine learning system.
This is an unconditional, irrevocable commitment. Client data is utilized strictly as ephemeral context window inputs to facilitate the immediate transaction and is discarded from the AI model's context upon session termination.
7. Data Retention
| Data Category | Retention Period | Storage Location |
|---|---|---|
| Client PII (names, phones, appointment history, staff/service directory) | Duration of your active account; deleted within 30 days of the post-termination export window (or immediately on request) | AWS-managed relational database (ca-central-1) |
| Conversation session state | Auto-deleted within 2 hours | AWS-managed NoSQL store (encrypted, TTL) |
| Call audit records | 90 days | AWS CloudWatch / AWS-managed NoSQL store |
| Operational/error logs | 30 days | AWS CloudWatch |
| Billing & invoice records | 7 years (tax compliance) | Stripe |
| Voice audio recordings (phone and in-room) | Not recorded or stored | N/A |
| In-room clinical note metadata (patient name/phone, provider, appointment time, duration, status, document link) | Retained for a Subscriber-configured period set to match the Subscriber's own records-retention obligation (commonly several years; 365-day default if unset), then auto-deleted; also deleted within 30 days of account termination, or immediately when the Subscriber deletes the session in their Tenant Portal (which also deletes the linked Google Doc) | AWS-managed relational database (ca-central-1) |
| In-room clinical note body & verbatim transcript | Not stored by us — written to the Subscriber's Google Workspace, under their control | Subscriber's Google Drive |
8. Third-Party Sub-Processors
We utilize the following industry-leading sub-processors to power our infrastructure:
| Sub-Processor | Purpose | Data Region |
|---|---|---|
| Amazon Web Services (AWS) | Core compute (Lambda, Fargate, ECS), session storage, client PII database, email (SES), in-room speech-to-text (Amazon Transcribe), in-room clinical-note generation (Amazon Bedrock) | ca-central-1 (Canada) |
| Twilio Inc. | Voice gateway, PSTN call routing, real-time audio Media Streams, SMS delivery | United States |
| Google Cloud Platform (Gemini Live) | Real-time AI language model inference for voice conversations | United States |
| Google Workspace (Calendar) | Appointment calendar management (Subscriber-owned) | North America |
| Stripe, Inc. | Payment & subscription billing | United States |
Each sub-processor is contractually bound to data protection obligations consistent with this Privacy Policy and applicable law.
9. Cross-Border Data Transfers
The majority of data processing occurs within Canada (AWS ca-central-1). However, certain sub-processors (Twilio, Google Gemini Live, Stripe) may process data in the United States. All cross-border transfers are protected by:
- Contractual safeguards equivalent to PIPEDA requirements.
- Standard Contractual Clauses (SCCs) where applicable under GDPR.
- Sub-processor compliance with SOC 2 Type II and/or ISO 27001 certifications.
10. Data Security
We implement the following security measures to protect data processed through the Service:
- Encryption in Transit: All data transmitted between components uses HTTPS/TLS 1.3. Live call audio is streamed over WSS (WebSocket Secure / TLS 1.3) between Twilio and our processing pipeline.
- Encryption at Rest: Ephemeral session data is encrypted using AES-256 (AWS-managed keys).
- Access Controls: Production access is restricted via MFA, role-based access control (RBAC), and least-privilege principles.
- Tenant Isolation: Each Subscriber's data is isolated at the database level via row-level security controls (no Subscriber's query can return another Subscriber's rows) as well as separate Google credentials for Calendar access. Cross-tenant data access is impossible by design.
- Vulnerability Management: Regular patching, automated security scanning, and periodic access reviews.
11. Your Rights (PIPEDA / GDPR)
Depending on your jurisdiction, you may have the following rights regarding your Personal Data:
- Access: Request a copy of Personal Data we hold about you.
- Rectification: Request correction of inaccurate or incomplete data.
- Erasure: Request deletion of your Personal Data (subject to legal retention requirements) — see our Delete Your Data page for exact steps and retention timelines.
- Portability: Request your data in a structured, machine-readable format.
- Objection: Object to processing of your data for specific purposes.
- Withdrawal of Consent: Withdraw previously given consent at any time.
Most persistent Personal Data (client names, phone numbers, appointment history, staff/service directory) is held in our own database on the Subscriber's behalf. Data subject requests for that data are fulfilled via the Subscriber's Tenant Portal (self-serve export/deletion where available) or by contacting us at the address below; appointment/calendar data remains directly accessible to the Subscriber through their own Google Workspace.
We will respond to valid requests within thirty (30) days.
12. Data Breach Notification
In the event of a confirmed data breach affecting Personal Data, we will:
- Notify affected Subscribers without undue delay and within 72 hours of confirmation.
- Provide details of the breach scope, affected data categories, and remediation steps.
- Cooperate with Subscribers in meeting their own regulatory notification obligations.
- Report to the Office of the Privacy Commissioner of Canada (OPC) as required by PIPEDA.
We maintain a persistent database of client data, as described in Section 2. Exposure in a Processor-side breach is mitigated, not eliminated, by the tenant-isolation and encryption controls described there — we will disclose the actual scope of any confirmed breach, not a presumed-limited one, under the notification process above.
13. Cookies & Website Analytics
Our website uses cookies and similar tracking technologies for:
- Essential Cookies: Required for basic website functionality (session management, security).
- Analytics Cookies: To understand website traffic patterns and improve user experience. We do not use these cookies to track individual users across other websites.
You can manage cookie preferences through your browser settings. Disabling essential cookies may affect website functionality.
14. Children's Privacy
The Service is not directed to individuals under the age of 18. We do not knowingly collect Personal Data from children. If we become aware that we have collected data from a child, we will promptly delete it.
15. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email to active Subscribers with at least fourteen (14) days' notice. The "Last Updated" date at the top of this page indicates when the policy was last revised. Continued use of the Service after the effective date constitutes acceptance.
16. Contact Us
If you have questions about this Privacy Policy, wish to exercise your data protection rights, or need to report a privacy concern, please contact us:
15336732 CANADA INC.
Privacy Officer
Email: support@moonlightai.ca
For complaints that cannot be resolved directly, you may contact the Office of the Privacy Commissioner of Canada at www.priv.gc.ca.