Legal
Privacy Policy
Last updated September 13, 2026. This document applies to the Romolo.ai website, the Romolo operations console, and the Romolo AI receptionist service.
This Privacy Policy explains how DVGM Advisory LLC d/b/a Romolo.ai (“Romolo”, “we”, “us”, “our”) collects, uses, discloses, and protects personal information when you visit romolo.ai, create a workspace in our operations console, or interact with our AI receptionist service. It also describes the choices available to you regarding that information.
Who this policy covers. Romolo is a business-to-business service. Our customers are businesses that configure an AI receptionist to answer their telephone calls (“Customers” or “you”). People who telephone a Customer’s number, or exchange text messages with it, are “Callers”. If you are a Caller, the business that you contacted is responsible for the decisions it makes about your information; Romolo processes that information on that business’s behalf. Section 12 tells Callers how to exercise rights.
1. Summary of key points
- We collect account details you give us, configuration content you upload, and call, transcript, message, and appointment data generated through your phone numbers.
- Your call audio and transcripts are processed to answer calls, produce summaries and outcomes, and power your dashboard. We do not sell personal information, and we do not use your calls, transcripts, or knowledge base content to train foundation models.
- We rely on contracted infrastructure subprocessors for telephony, realtime audio, conversation processing, data storage, authentication, hosting, and billing. Section 7 describes the processing categories.
- You control retention. Each workspace sets its own daily retention period; calls can be exported to CSV or deleted permanently from the console.
- You are responsible for providing legally required notices to your callers — including recording notices and AI disclosure where required.
2. Information we collect
2.1 Information Customers provide directly
- Account and profile data: name, work email address, password (stored only as a hash), multi-factor authentication enrollment data, role, and workspace membership.
- Business configuration: business name, industry, address, time zone, opening hours, receptionist name, greeting, voice and instruction settings, transfer targets, and tool/integration allow lists.
- Knowledge base content: documents, FAQs, policies, service descriptions, and other material you upload so the receptionist can answer questions about your business.
- Billing data: plan selection, usage metering records, spend limits, invoices, and payment details collected by our payment processor (card numbers go directly to the processor; Romolo stores only limited identifiers).
- Communications: messages you send us through support, onboarding forms, demo requests, and feedback channels.
2.2 Information generated by the service
- Call data: caller telephone number, dialed number, call date/time and duration, direction, outcome (for example booked, messaged, transferred, or voicemail), caller flags, known-customer matches, and provider call/session identifiers.
- Audio and transcripts: recordings and text transcripts of calls handled by the AI receptionist, together with any summaries extracted from them.
- SMS data: inbound and outbound message content, delivery status, segment counts, error codes, opt-out state, country, and provider-reported cost.
- Appointments: booking details captured during calls, including contact name, phone number, requested service, and scheduled time in your business time zone.
- Audit and security logs: sign-in events, privileged changes, exports, deletions, and tool-call audit records with sensitive arguments redacted.
2.3 Information Callers provide
- Their telephone number and anything they choose to say or text, which may include name, contact details, reason for calling, addresses, availability, and other personal or sensitive information they disclose voluntarily.
2.4 Automatic collection
- Usage and device data: IP address, browser type and version, pages viewed, actions taken in the console, and timestamps, collected through server logs and essential cookies needed to keep you signed in and secure.
- We do not use advertising cookies or third-party ad trackers on the product.
3. How we use information
We process personal information to:
- Provide the service: answer calls, converse with Callers, book appointments, send and receive SMS, transfer calls, and record outcomes;
- Operate your workspace: authenticate users, enforce roles and tenant isolation, apply call and cost limits, and run daily retention cleanup;
- Meter, bill, and support: calculate per-provider minutes and spend, generate invoices, respond to requests, and provide customer assistance;
- Secure and improve: detect fraud and abuse, validate webhooks, debug failures, monitor agent health, and improve reliability of the platform;
- Comply with law: satisfy legal obligations, resolve disputes, and enforce our agreements.
We do not use Customer call audio, transcripts, knowledge base content, or Caller personal information to train or fine-tune general-purpose AI models, and we do not sell or rent personal information.
4. AI processing disclosure
- Calls are answered by an automated AI receptionist. Where law requires, Customers must inform Callers that they are speaking with an automated assistant and that calls may be recorded.
- To hold a live conversation, call audio is streamed in real time through contracted conversation infrastructure under terms that prohibit submitted content from being used to train general-purpose models. Transcripts may be produced from those sessions and stored in your workspace.
- The receptionist only takes consequential actions — creating appointments, sending messages, transferring calls — through a controlled gateway with confirmation rules, allow lists, validation, and rate limits configured by you or by us on your behalf.
- AI output can be inaccurate. Outcomes such as bookings should be reviewed by your staff; the console exists so humans stay in charge.
5. Legal bases for processing (EEA/UK)
Where the GDPR or UK GDPR applies, we rely on:
- Contract — to provide the service you signed up for, manage your account, and bill you;
- Legitimate interests — to secure the platform, prevent abuse, keep records of business communications, and improve the service, balanced against your rights;
- Consent — where you give it, for example optional marketing emails or non-essential cookies, withdrawable at any time;
- Legal obligation — to retain billing records, respond to lawful requests, and meet tax and accounting duties.
As the controller of Caller data processed through your phone numbers, you are responsible for establishing a lawful basis for Callers, including any required consent for recording.
6. When we share information
We share personal information only as described below:
- With subprocessors that help us deliver the service (Section 7), under contracts restricting their use of the data;
- At your direction — with integrations you enable, recipients you configure for transfers or messages, and anyone you authorize on your workspace;
- Professional advisers — auditors, lawyers, insurers, bound by confidentiality;
- Corporate transactions — as part of a merger, financing, acquisition, or sale of assets, subject to this policy’s continuation;
- Legal and safety — to comply with law, respond to valid legal process, protect rights, property, and safety, and investigate fraud or abuse;
- Aggregated or de-identified data — statistics that no longer identify a person, used for benchmarking and service improvement.
7. Third-party processors and services
Romolo depends on specialized infrastructure providers. Each processes limited personal information under contract:
| Service category | Role | Data involved |
|---|---|---|
| Telephony and messaging infrastructure | PSTN/SIP trunking, phone number provisioning, SMS delivery, delivery receipts | Caller and recipient phone numbers, call metadata, SMS content and status, opt-out keywords |
| Realtime media infrastructure | Realtime audio transport between telephony and the AI agent; call transfers | Call audio streams and session metadata while a call is live |
| Conversation infrastructure | Realtime speech conversation engine powering the receptionist | Live call audio and session context; not used to train general-purpose models |
| Data and authentication infrastructure | Managed Postgres database, authentication, email confirmation delivery | Account data, workspace data, calls, transcripts, messages, appointments, audit logs |
| Application hosting infrastructure | Hosting of the website, operations console, and runtime API | IP addresses, request logs, and console traffic |
| Payment processors | Subscription and usage-based billing | Contact and billing details, card data handled directly by the processor |
| Email providers | Transactional email (sign-up confirmation, password reset) | Name, email address, message content |
Third-party integrations that you switch on — calendars, CRMs, custom webhooks — receive only the data necessary for the action, validated against your allow lists. Those services are governed by their own privacy policies once you connect them. Webhook secrets you supply are encrypted with AES-256-GCM before storage.
8. Cookies and similar technologies
We use essential cookies to keep you signed in, protect your session, remember preferences and connect a submitted report request to its confirmation page. If you accept analytics, we also use a random browser identifier to measure page visits, product interactions and basic error events. Optional browser analytics remains off until you accept. We do not record your screen or use advertising trackers. Your cookie choice and optional browser identifier last for up to six months. You can withdraw consent using Cookie settings; this stops future optional browser events and removes the browser identifier. Operational server logs used to secure and run the service remain separate.
9. Data retention and deletion
- Workspace-configurable retention: each workspace sets a retention window; an automated daily job permanently deletes call data older than that window.
- Manual deletion: individual calls can be deleted permanently at any time from the console, and entire datasets removed on verified written request from a workspace owner.
- Exports: CSV exports you trigger are generated on demand; we do not keep copies beyond transient processing.
- Security and audit records are kept as long as needed to protect the platform, investigate incidents, and meet legal duties, typically no more than 24 months unless a longer legal hold applies.
- Account data is retained while your workspace is active and for a short wind-down period after termination so you can export data, then deleted or anonymized.
- Backups rotate on provider-managed schedules; residual copies age out within the backup cycle.
10. International data transfers
Romolo operates in the United States, and our providers process data in the US and other countries. Where personal information is transferred out of the EEA, the UK, or Switzerland, we rely on appropriate safeguards such as the EU Standard Contractual Clauses and the UK International Data Transfer Addendum, together with supplementary measures including encryption in transit and at rest and strict access controls. You may request details of transfer safeguards by contacting us.
11. Your privacy rights
EEA, UK, and Switzerland
Subject to conditions, you may request access, rectification, erasure, restriction, portability, and objection to processing based on legitimate interests, and you may withdraw consent at any time. Lodge a complaint with your supervisory authority if you believe our processing infringes applicable law.
United States
Depending on your state, you may have rights to know what we collect, access and delete your personal information, correct inaccurate information, and receive equal service regardless of the exercise of rights. We do not sell or share personal information for cross-context behavioral advertising as those terms are defined by state law. Authorized agents may submit verified requests with written permission.
How to make a request
Workspace users should use the console tools (settings, export, deletion) or email us. We verify requests by confirming control of the associated account. We respond within the timeframes required by applicable law and will not discriminate against you for exercising your rights.
12. Notice for Callers
If you called or texted a number powered by Romolo:
- The business you contacted decides how your information is used and with whom it is shared. Romolo processes it only on that business’s instructions.
- Your number, the call audio, transcript, and any messages or bookings are visible to authorized staff of that business and stored securely by Romolo.
- To access, correct, or delete your information, or to stop being contacted, contact the business directly. Businesses can honor your request using their console controls, including permanent deletion.
- Standard carrier STOP handling applies to texts: reply STOP to opt out of further messages from that business.
- You can also reach us at the address in Section 17 and we will route your request to the relevant business.
13. Security
We design for least privilege and tenant isolation: row-level security separates every workspace, privileged actions require multi-factor authentication, webhook signatures are validated, runtime credentials are timing-safe and scoped per call, integration secrets are encrypted, and provider credentials never reach the browser or the AI model. No system is perfectly secure; if a breach affects your data, we will notify you and regulators as required by law.
14. Children’s privacy
The service is not directed to children under 13 (or the equivalent minimum age in your jurisdiction), and we do not knowingly collect their personal information. Callers who identify themselves as minors should be routed by the business to a human; if we learn we have collected a child’s data contrary to law, we will delete it.
15. Changes to this policy
We may update this policy as the service evolves. Material changes will be announced in the console or by email at least 30 days before they take effect where required. The “Last updated” date above reflects the current version, and prior versions are available on request.
16. Contact us
Questions, requests, or complaints? Contact DVGM Advisory LLC d/b/a Romolo.ai, 8 The Green, Ste R, Dover, DE 19901, United States, or email support@romolo.ai.
