Everaide Privacy Notice
Version and effective date: stated in the page header and in the release record for this document
1. Who we are
Mawlawi Tech Solutions LLC, a Texas LLC, operates Everaide. Privacy contact: support@geteveraide.com; our postal correspondence address is provided on request to that address.
This notice covers website visitors, account users, people who contact us, and people whose calls or information an organization processes using Everaide. Organizations normally decide why their caller/contact information is processed; we provide the service under their instructions. We decide purposes for our own account administration, security, billing and marketing. The organization's own privacy notice also applies to its activities. You do not need an Everaide account to contact us about privacy or unwanted calls.
2. Information and sources
| Information | Source | Principal purpose |
|---|---|---|
| Staff email, organization identity, membership and login/security records | You, your organization and use of the app | Account access, security, administration and notices |
| Plan, invoices, usage and payment references | You, service usage and our payment provider | Billing, refunds, accounting and disputes |
| Uploaded documents and extracted searchable passages | Your organization and its authorized users | Answering questions grounded in that organization's information |
| Caller numbers, voice, transcripts, summaries, message details and call metadata | Call participants, telephony providers and customer instructions | Handling calls, taking messages and maintaining records |
| Campaign contacts, consent evidence and opt-out records | Your organization, its authorized sources and recipients | Approved calls and respecting communication preferences |
| Owner alert enrollment, phone verification, delivery and consent/withdrawal evidence | The enrolling owner, service requests and messaging provider | Optional transactional SMS, delivery, suppression and compliance evidence |
| Appointment and callback information | Callers and authorized users | Requested booking and follow-up workflows |
| Support/help messages and technical diagnostics | You, your device and service operation | Assistance, reliability, fraud prevention and security |
Your organization should explain the original source of a campaign list and the purposes for which it obtained the information. Ask that organization or our privacy contact if you do not know why you were called. We may receive information about you from someone acting for you; that does not eliminate required notices or permissions.
Payment-card entry for subscriptions occurs through Stripe. We receive payment references and billing information, not your complete card number or security code through that checkout. Do not give card details, passwords, government identifiers, health or other sensitive information to the phone assistant. Do not give card details, passwords, government identifiers, health or other sensitive information to this help chat. Unexpected information may still enter a call and require handling; redaction is not a guarantee that every sensitive detail is removed.
3. Purposes and legal bases
We use account and service-administration information to deliver contracted services, maintain secure access, resolve problems, collect valid fees and meet legal obligations. Where EU/UK data-protection law applies, our bases are performance of a contract where you are personally a party, legitimate interests in operating and securing organizational services for staff contacts, legal obligations, and consent where required for optional communications or technologies. We assess legitimate interests against individuals' rights and honor applicable objections.
For customer-controlled call, document and contact data, we act on documented instructions. The organization identifies its applicable lawful basis and any additional permission for sensitive data, recording or automated communications. A subscription agreement or a GDPR basis does not by itself provide telemarketing consent.
We do not sell personal information or use customer call/document content for targeted advertising. We do not use that content to train or fine-tune our own general-purpose AI models. Retrieving passages from your documents to answer a question is part of providing the service, not training a shared foundation model. Third-party processing is described below.
4. AI, recording and human access
Everaide uses automated systems to generate speech, transcribe conversations, retrieve relevant information and produce answers and summaries. Those outputs can be wrong. They are not intended to determine admission, employment, credit, health or other legally significant outcomes. Contact the organization for a human review of important information.
Our telephony provider processes call audio and may retain recordings under the agreed configuration. Everaide stores call text and related records; the current service does not independently archive call audio or retain recording links in its live application records. Removal of a link from Everaide does not erase the provider’s audio. Provider copies and restricted historical backups follow their own retention and deletion processes. Authorized organization users can view records within their permitted access. Authorized operators and suppliers may access data when necessary to provide, secure or support the service under appropriate restrictions; we do not promise that nobody at Everaide can access it.
Callers should be told they are interacting with AI and given recording/privacy information at the appropriate time. Where consent is required, it must be obtained through a supported process. If you do not wish to continue, you can end the call and contact the organization another way.
Our telephony and speech provider handles call transport, speech recognition and speech synthesis, and we separately use a hosted AI inference provider for answers. Their applicable contracts and configurations determine their permitted processing and retention. Everaide does not promise that every supplier makes no use of de-identified or aggregated information. De-identification must meet applicable law; merely removing a name or storing a phone digest does not necessarily make information anonymous.
Optional owner SMS
If an owner chooses SMS alerts, we use the owner's supplied number to verify control of it and send the account and business-line notifications described at enrollment. We record the consent wording/version, collection method, timestamp and request evidence. SMS is optional; it is not marketing to callers and does not authorize AI marketing calls. See the Owner SMS Terms for stopping messages and obtaining help.
We do not sell or share mobile phone numbers, SMS opt-in information or SMS consent with third parties or affiliates for their marketing or promotional purposes. We disclose the minimum necessary information to service providers, including our messaging provider, to deliver messages, operate and secure this program, and handle opt-outs under appropriate restrictions. Necessary legal disclosures described below may also apply. SMS consent is not transferred to another organization for that organization's own messaging.
5. Recipients and international processing
The Subprocessor List identifies service providers, functions, information and processing locations. These include telephony/speech services, the separate chat model, hosting, mail, backup storage and billing providers. Some providers act independently for their own legally required purposes; Stripe's roles, for example, vary by activity.
Our primary service infrastructure is in the United States. UK/EEA information may be processed outside those territories. We do not offer a general EU-only or UK-only residency promise. Where required, transfers use the applicable completed safeguards described in our DPA and transfer schedule; contact us for a copy, with confidential details reasonably redacted. Everaide is currently offered to US-based organizations only and has not completed a restricted-transfer safeguard for any customer; if a restricted transfer arises, the applicable instrument is completed before that processing begins.
We may disclose information where legally required, to address a lawful safety/security need, or in a business transfer subject to appropriate confidentiality and data-protection requirements. We assess requests rather than treating all informal requests as legal compulsion. Where permitted, we notify affected customers of legally compelled disclosure and provide only the information responsive to a valid requirement.
6. Retention
We retain information for the purposes above, according to category, customer instructions, legal duties and justified claims/holds. Deletion of content and retention of limited billing/compliance records are different operations.
| Category | Retention and outcome |
|---|---|
| Call transcripts/summaries and associated raw events | The organization's retention window, then an automatic scheduled purge of the content (360 days by default; an organization can set a shorter window). Call outcome, duration and quality markers are kept without the content. |
| Booking/callback content | Defined purpose and relevant event-based window; future appointments are treated separately from historic calls |
| Uploaded documents and extracted passages | Until the organization deletes them, which its owner can do at any time, or until we remove them under the closure procedure in the DPA; deletion of a source document does not automatically erase historic call content containing excerpts |
| Billing/accounting evidence | Seven years from the end of the relevant financial year under our accounting policy, with longer retention where legally required or subject to an outstanding hold |
| Owner SMS consent evidence (text alerts are not yet enabled) | Once text alerts are enabled: while an episode of consent is active, then five calendar years after the later of the end of that episode or its last message; scoped legal holds may extend this. A later account closure does not restart an already inactive episode. |
| Other calling consent, suppression and audit evidence | Necessary restricted records: do-not-call and suppression records are kept for as long as the number must stay suppressed; contact-list provenance, consent attestations and audit records are kept as compliance evidence for the life of the organization's account and reviewed annually. Suppression is handled separately from content deletion. |
| Support, security and operational logs | 14 days for the technical service logs (application and container output, kept on our own server for security and reliability); other support records on a limited purpose-specific schedule |
| Backups | Restricted, encrypted recovery copies. Local copies are removed once their off-site copy is confirmed; off-site copies are currently kept without automatic expiry, and we will state the expiry period in this notice when an automatic schedule is in force. Restoration must reapply relevant deletions before ordinary use. |
| Vendor copies | Provider-specific schedules and deletion process, not automatically identical to our main database |
Redaction reduces personal information but is not a guarantee that logs can never contain it. Application logs are redacted at the logger, periodically scanned for caller identifiers and kept for 14 days. Live call content follows the retention window in the table above, which is enforced automatically (the current default is 360 days). Support correspondence has a separate purpose-based schedule in our support mailbox. Backup copies expire as stated in the Data Processing Addendum, and supplier copies follow each supplier's own retention.
A residual record with a call ID, account link or telephone number may still be personal data. We do not label such records anonymous. If a request cannot be fully fulfilled because of a lawful exception, we explain the relevant reason and restrict retained data. Technical inconvenience alone is not a legal exception.
7. Rights and choices
Depending on applicable law and our role, you may request access, correction, deletion, a copy/portability, restriction, objection, withdrawal of consent, or appeal of a request decision. Withdrawal does not invalidate earlier lawful processing. We will not retaliate for exercising applicable rights. You may also complain to the regulator responsible for your jurisdiction, including your EU supervisory authority, the UK ICO or the relevant US authority.
Contact support@geteveraide.com; correspondence details are available on request. Tell us enough to find the record, such as the organization and approximate call time; do not send passwords or sensitive identity documents unless a secure, necessary verification process is agreed. We verify identity and authority proportionately and protect other people's information. We respond within the applicable legal deadline and explain permitted extensions or denials and appeal routes.
For customer-controlled information, contacting the organization is usually quickest. We will assist it and route requests appropriately; we will not ignore a request merely because you are not our customer. If you want campaign calls to stop, say so during the call or contact the organization/our abuse route. We prioritize suppression separately from identity-heavy access requests.
We have not appointed a representative in the EU or the UK or a data protection officer, because Everaide is offered to US-based organizations only and our processing takes place in the United States; if that changes, we will update this notice with the appointment and its contact details.
8. Children, schools and security
Accounts are for authorized adults acting for organizations or their sole-trader business, across industries and company sizes. The general service is not directed at children. Confidential legal matters and patient information require an approved supported arrangement; ordinary registration does not authorize these workflows. School processing of student information requires the applicable School Addendum and supported controls; school enrollment does not itself authorize every use of a child's information. Tell us if child or other restricted data was provided without the required arrangement.
We maintain safeguards appropriate to the service, including access restrictions, tenant-scoped processing, transport security, monitoring and controlled operational access. Specific verified measures are in the DPA security schedule. No service is completely secure. We do not claim certifications held only by our suppliers or make a blanket encryption claim. If a reportable incident occurs, we follow applicable notification obligations and our customer agreements.
9. Cookies, marketing and updates
See the Cookie Notice for necessary session technologies and any choices. Optional marketing email is sent only to a person who has chosen to receive it, and that choice is recorded with the exact wording shown; it is separate from service notices about your own account, number and calls. You can change it at any time on Settings → Legal in the app or through the unsubscribe link in each optional email; earlier organization-wide unsubscribes are honored until you record your own choice.
We date material changes and notify affected users as appropriate. A revised notice does not retroactively provide consent or authorize incompatible use. Prior versions are kept unchanged at geteveraide.com/legal/archive/, one copy per published version, and each page shows its version and effective date.