# Intavia Docs Source: https://docs.intavia.ai/index Guides for setting up Intavia integrations and reviewing our legal policies ## Integrations Set up your platform integrations so your voice agent can check availability, book appointments, and follow up with callers. Connect Intavia to Cliniko and ensure online bookings and availability are configured correctly. Connect Intavia to PracticeHub and enable Online Bookings so practitioners, appointment types, and availability show up correctly. Connect Intavia to PPS with the API token permissions needed for appointment automation. Connect Intavia to GoHighLevel using an agency token and the required scopes. ## Security and legal Review Intavia's security controls, data-protection terms, and current legal documents. See how Intavia protects customer data across its infrastructure, platform, integrations, and development processes. View the MSA, DPA, Sub-processors, Privacy Policy, Cookie Policy, and the legal changelog. # Legal Document Change Log Source: https://docs.intavia.ai/legal/changelog A history of changes made to Intavia's legal documents, including what changed and when.
Version:
Effective:
Last Updated:
This page documents all changes made to Intavia's legal documents. We maintain this log to ensure transparency about updates to our terms and policies. ## How to Read This Log Each entry includes: * **Date** — When the change took effect * **Document** — Which legal document was updated * **Version** — The new version number * **Summary** — A brief description of what changed *** ## 2025 ### January 1, 2025 | Document | Version | Summary | | ------------------------- | ------- | ------------------- | | Master Services Agreement | v1.0 | Initial publication | | Data Processing Agreement | v1.0 | Initial publication | | Sub-Processors | v1.0 | Initial publication | | Privacy Policy | v1.0 | Initial publication | | Cookie Policy | v1.0 | Initial publication | **Details:** * Initial publication of all legal documents * Established baseline terms for Intavia services * GDPR-compliant data processing terms included *** ## Upcoming Changes We will announce any upcoming changes to our legal documents here before they take effect. *No upcoming changes at this time.* *** ## Notification Preferences To receive notifications when we update our legal documents: 1. **Customers** — Updates are sent to the email address associated with your Intavia account. *** # Contact us Email: **[loic@intavia.ai](mailto:loic@intavia.ai)**\ Controller: **Intavia LTD**\ Registered address: Charilaou Xyloforou 13, Agios Athanasios, 4103, Limassol, Cyprus # Cookie Policy Source: https://docs.intavia.ai/legal/cookie-policy Information about how Intavia uses cookies and similar tracking technologies on our website and services.
Version:
Effective:
Last Updated:
This Cookie Policy explains how Intavia LTD ("we", "us") uses cookies and similar technologies on our website (intavia.ai). For information about how we process personal data, please refer to our [Privacy Policy](/legal/privacy). *** # 1. What are cookies? Cookies are small text files stored on your device when you visit a website. They help websites function, enhance performance, and provide analytics. Cookies may be: * **Session cookies** — deleted when you close your browser * **Persistent cookies** — remain on your device until they expire * **First-party cookies** — placed by our website * **Third-party cookies** — placed by external services (e.g., Google Analytics) *** # 2. Why we use cookies We use cookies for the following purposes: ### **Strictly Necessary Cookies** These cookies are required for the website to function and cannot be switched off.\ Examples: * Security and fraud prevention * Routing and load balancing * Basic site operation These cookies **do not require consent**. *** ### **Analytics Cookies (Requires Consent)** Used to understand how visitors use our website, improve performance, and detect issues. We use **Google Analytics 4 (GA4)** with enhanced privacy settings: * IP anonymisation enabled * Region controls enabled * No advertising features * No cross-site identifiers Analytics cookies are only activated **after you provide consent** via our cookie banner. *** # 3. Cookies we use Below is a list of the cookies and tracking technologies used on our site. ## Strictly Necessary Cookies (no consent required) | Name | Provider | Purpose | Duration | | ---------------- | ---------- | ------------------------------------ | ----------- | | `__cf_bm` | Cloudflare | Bot protection | 30 minutes | | `session_id` | Intavia | Session routing / core functionality | Session | | `cookie_consent` | Intavia | Stores your cookie choice | 6–12 months | *** ## Analytics Cookies (consent required) | Name | Provider | Purpose | Duration | | ------------------------- | ------------------ | ------------------------------ | ----------- | | `_ga` or similar GA4 tags | Google Analytics 4 | Website analytics & engagement | 2–24 months | | `_ga_` | Google Analytics 4 | Session metrics | 2 years | *Note:* GA4 may use additional identifiers such as `client_id` or browser storage APIs (not always classical cookies). *** # 4. How to manage cookies You can manage cookie preferences via: ### **Cookie Banner** You can accept, reject, or customise cookies when you first visit our site. ### **Change Preferences at Any Time** Use the “Cookie Settings” link in our website footer. ### **Browser Settings** You may disable cookies through your browser.\ However, disabling essential cookies may affect functionality. *** # 5. Third-party services We use the following third-party services that may set or process cookies: * **Google Analytics 4** (analytics) * **Cloudflare** (security/CDN) These providers may process data outside the UK/EU.\ Transfers are safeguarded by: * Standard Contractual Clauses (SCCs) * UK IDTA * Google’s EU data protection addendum * Additional technical and organisational measures See our Privacy Policy for more details. *** # 6. Changes to this Cookie Policy We may update this Cookie Policy occasionally.\ We will post the updated version on this page, and update the "Last updated" date. *** # 7. Contact If you have questions about cookies or data protection: **Email:** [loic@intavia.ai](mailto:loic@intavia.ai)\ **Controller:** Intavia LTD\ **Registered address:** Charilaou Xyloforou 13, Agios Athanasios, 4103, Limassol, Cyprus # Data Processing Agreement Source: https://docs.intavia.ai/legal/dpa The Data Processing Agreement describes how Intavia processes personal data on behalf of customers in compliance with GDPR and other data protection laws.
Version:
Effective:
Last Updated:
This document is incorporated by reference into all Order Forms and governs your use of Intavia services.
# Data Processing Addendum (DPA) This Data Processing Addendum (“DPA”) forms part of the Agreement between Intavia LTD (“Processor”, “Provider”, “we”) and any Customer entering into an Order Form or using the Services (“Controller”, “Customer”, “you”). The current version of this DPA is always available at:\ [Data Processing Agreement](/legal/dpa) This DPA reflects the parties’ obligations under the UK GDPR, EU GDPR, and applicable data protection laws governing the processing of Personal Data in connection with the Services. *** # 1. Definitions Capitalised terms have the meanings set out in the Agreement unless defined here. **"Agreement"** means the MSA, this DPA, all Order Forms, and any applicable addenda. **"Data Protection Laws"** means all applicable data protection and privacy legislation in force from time to time in the United Kingdom and, where applicable, the European Union, including without limitation the UK GDPR, the Data Protection Act 2018, the Privacy and Electronic Communications Regulations (PECR), the EU GDPR, and any successor or implementing legislation. **"Personal Data"** means any information relating to an identified or identifiable natural person. **"Personal Data Breach"** has the meaning given in Data Protection Laws and includes any loss, accidental or unlawful destruction, damage, corruption, alteration, disclosure of, or access to Personal Data. **"Processing"**, **"Controller"**, **"Processor"**, **"Data Subject"**, and **"Supervisory Authority"** have the meanings given in Data Protection Laws. **"Customer Data"** means all data (including Personal Data) submitted or generated by Customer via the Services. **"Customer Systems"** means systems, CRMs, telephony providers, infrastructure, and tools Customer owns or controls. **"Sub-Processor"** means any third party engaged by Provider to process Customer Data. **"Services"** means the functionality described in the Order Form and Documentation. Any functionality not expressly described in the Order Form or Documentation is excluded. **"Term"** has the meaning given in clause 3.3 of this DPA. **Any functionality not expressly described in the Order Form or Documentation is excluded.** *** # 2. Roles of the Parties ## 2.1 Controller–Processor For Customer Data processed through the Services, Customer is the **Controller** and Provider is the **Processor**. ## 2.2 Independent Controller Activities For Provider's own processing (billing, account management, fraud prevention, product analytics using aggregated/anonymised data), Provider acts as an **independent Controller**. ## 2.3 Instructions Provider will only process Personal Data on documented instructions from Customer: * this DPA * the Agreement * any applicable Order Form * any written instructions consistent with the Agreement If Provider believes an instruction violates Data Protection Laws, it shall notify Customer. *** # 3. Subject Matter, Nature, Purpose, Duration ## 3.1 Subject Matter Processing of Customer Data in connection with the provision of the Services. ## 3.2 Nature & Purpose Provider processes Personal Data to: * receive, handle, route, and manage inbound calls * place outbound calls (if enabled) * generate call metadata, logs, transcripts, and analytics * surface data into dashboards * integrate with Customer Systems * provide configuration, support, and quality assurance * improve the Services using anonymised/aggregated data * comply with legal obligations ## 3.3 Duration Processing continues for the term of the Agreement, plus applicable retention periods. Detailed processing information appears in Annex 1. *** # 4. Types of Personal Data & Data Subjects ## 4.1 Categories of Personal Data Categories include (without limitation): | Category | Examples | | ------------------------------------- | -------------------------------------------------------------------------------------------------- | | **Identification & Contact** | Names, phone numbers, email addresses, business identifiers | | **Communication Content** | Call audio, transcripts, text interactions, free-text content spoken or entered | | **Metadata** | Phone numbers dialled, timestamps, duration, routing, menu selections, call outcomes, tags, labels | | **Booking / Appointment Information** | Service types, dates, times, staff members, notes entered by Customer | | **Customer Users** | User account details, login identifiers, usage logs | | **Technical Information** | IP addresses, device/browser type, operational logs | | **Free-Text Notes** | Any text entered by Customer via dashboards or configuration panels | ## 4.2 Special Categories Not intended to process special category data. If callers voluntarily share such data, Controller is responsible for: * lawful basis * notices * retention * deletion configuration ## 4.3 Data Subjects Data Subjects may include: * Customer's callers, clients, patients, and leads * Customer employees or contractors * Other individuals whose data appears in Customer Data *** # 5. Processor Obligations Provider shall: ## 5.1 Records of Processing Provider shall maintain records of processing activities to the extent required by Data Protection Laws. ## 5.2 Confidentiality Ensure all authorised persons are under confidentiality obligations. ## 5.3 Security Implement appropriate technical and organisational safeguards (see Annex 2). ## 5.4 Assistance with Data Subject Rights Assist Customer (at Customer's cost where applicable) with Data Subject rights requests. ## 5.5 Assistance with Compliance Assist Customer with: * security obligations * Personal Data Breach notifications * DPIAs and supervisory consultations ## 5.6 Breach Notification Provider shall notify Customer without undue delay (and where feasible within **72 hours**) of any Personal Data Breach affecting Customer Data, including any loss, unintended destruction, corruption, alteration, unauthorised access to, or disclosure of Personal Data. Provider will supply sufficient information to enable Customer to meet its legal obligations. ## 5.7 Deletion or Return at Termination Upon termination: * Provider retains Customer Data for **90 days** for backup/legal purposes * After 90 days, data is deleted or anonymised * Customer may request earlier deletion where feasible * Customer may export data via available tools *** # 6. AI Output Behaviour ## 6.1 Nature of AI Outputs The Services use machine-learning models that may: * generate inaccurate or fictional ("hallucinated") content * misinterpret caller intent * incorrectly infer Personal Data * generate synthetic content not based on actual Personal Data ## 6.2 AI Output Is Not a Data Breach **AI hallucination, synthetic generation, or inaccurate inference does not constitute a Personal Data Breach** unless caused by an underlying security incident. ## 6.3 Controller Responsibility Customer remains responsible for: * all inputs, prompts, flows, scripts, and business logic provided * verifying outputs where accuracy is important * ensuring no unlawful, inaccurate, or harmful instructions are given to the AI ## 6.4 Sensitive Data Customer must not require AI to generate, infer, or process special category data unless they have a lawful basis and configure retention/controls accordingly. *** # 7. Sub-Processors ## 7.1 Authorisation Customer authorises the Sub-Processors listed in Annex 3. ## 7.2 Additions & Changes Provider may add or replace Sub-Processors.\ Customer will be notified of material changes. ## 7.3 Objection Right If Customer objects on reasonable data protection grounds, parties will seek a solution.\ If none is found, Customer may terminate only the affected Services. ## 7.4 Sub-Processor Obligations Provider ensures Sub-Processors are bound by obligations no less protective than this DPA. Provider remains liable for Sub-Processor actions. *** # 8. International Transfers Provider and Sub-Processors may process Personal Data in the UK, EEA, US, or other jurisdictions. Where required, Provider relies on: * Standard Contractual Clauses * UK IDTA * or other authorised transfer mechanisms *** # 9. Security Measures Provider implements: * encryption in transit and at rest (where applicable) * access controls, authentication, least-privilege * logging, monitoring, incident response * secure development practices * vulnerability management * staff training Detailed overview: Annex 2. *** # 10. Data Storage, Recordings, and Retention ## 10.1 Call Recordings & Transcripts Where enabled: * call audio and transcripts are processed and stored by Sub-Processors such as ElevenLabs * recordings may be stored indefinitely unless Customer instructs otherwise * Provider may stream or surface recordings without retaining raw audio internally ## 10.2 Customer Responsibility Customer is responsible for: * selecting lawful retention periods * providing required caller notices * configuring deletion or disabling recording if needed ## 10.3 Deletion at Request Provider will act on Customer deletion instructions where technically feasible. *** # 11. Use of Data for Service Improvement Provider may use **anonymised or aggregated** data to: * improve models * test features * benchmark performance * conduct analytics Customer may opt out by written notice, acknowledging performance may degrade. Provider does **not** sell Personal Data or use it for third-party marketing. *** # 12. Audits & Information ## 12.1 Documentation Provider will make available information demonstrating compliance, including: * security documentation * summaries of controls * Sub-Processor information * transfer mechanism details ## 12.2 Audits Where required by law, Customer may conduct audits: * with reasonable notice * during normal business hours * without undue disruption Limited to **one audit per year**, unless required by a Supervisory Authority or following a confirmed breach. Costs: Customer bears its own costs and Provider’s reasonable costs unless Provider is in material breach. *** # 13. Data Subject Requests If a Data Subject submits a request or complaint directly to Provider, Provider will, where feasible, redirect the individual to Customer or notify Customer without undue delay. Customer is responsible for responding to Data Subject rights requests and complaints. Provider will assist Customer to the extent required by Data Protection Laws and technically feasible, and may charge for such assistance where permitted by law. *** # 14. Priority & Conflict If this DPA conflicts with other parts of the Agreement, this DPA prevails solely for Personal Data Processing. All other terms remain in full force. *** # 15. Governing Law This DPA is governed by the laws of England and Wales.\ Courts of England and Wales have exclusive jurisdiction. *** # 16. Liability Liability arising under or in connection with this DPA is governed exclusively by the liability provisions set out in the Agreement (MSA). **No additional liabilities are created by this DPA.** *** # Annex 1 — Data Processing Details This Annex provides the detail required by Article 28(3) GDPR regarding the nature, scope, purpose, and duration of processing carried out by Provider on behalf of Customer. ## 1. Subject Matter of Processing Processing of Customer Data (including Personal Data contained in inbound and outbound calls, transcripts, metadata, booking information, logs, and any data surfaced into the Platform) for the purpose of providing the Services. *** ## 2. Duration of Processing Processing occurs for: * the term of the Agreement; * any period during which Customer uses or accesses the Services; * a **90-day post-termination retention window** for backup, dispute resolution and legal compliance; * any retention configured by Customer at Sub-Processor level (e.g., ElevenLabs call recording storage); * any legally required additional retention period. Customer may request earlier deletion where technically feasible. *** ## 3. Nature and Purpose of Processing Processing activities include: ### Inbound Call Handling * receiving, answering, routing, forwarding and managing inbound calls; * executing Customer-defined flows, scripts, menus, or logic; * interacting with callers using AI voice models; * identifying, confirming or retrieving caller details. ### Outbound Calling (if enabled) * placing calls triggered by Customer actions, workflows, integrations or business logic; * appointment reminders, lead follow-up, scheduling tasks, or other permitted non-spam use cases. ### AI-Generated Outputs * generating synthetic audio responses; * creating, inferring, or transforming text or metadata; * producing summaries, tags, labels, classifications, or other derived content; * streaming this data back to the Platform. ### Data Surfacing and Storage * displaying or streaming call recordings, transcripts, metadata, tags, summaries and analytics to Customer; * caching audio/transcript segments for operational use; * generating usage logs, billing metrics, reporting data. ### Integrations with Customer Systems * syncing bookings, appointments, customer details or tags; * writing or reading data in Customer Systems as configured. ### Support & Quality Assurance * troubleshooting call quality, flows, misrouting, or integration failures; * verifying correct system operation during onboarding. ### Service Improvement (aggregated/anonymised) * improving accuracy, latency, robustness and performance of the Services; * improving routing, detection, ASR/STT/TTS models; * testing new features; * analytics and benchmarking. Customer may opt out of improvement processing (beyond operational necessity) by written notice. *** ## 4. Categories of Personal Data The following categories may be processed (non-exhaustive, depending on Customer configuration): | Category | Examples | | ---------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | | **Identification & Contact Information** | Name, phone number, email address; business or practice name; role/title where provided | | **Call Audio & Transcripts** | Voice recordings of callers; text transcripts generated by speech models; metadata associated with recordings; summaries or structured derivatives (tags, actions, labels) | | **Operational Metadata** | Call timestamps, duration, routing choices; telephone numbers involved (inbound/outbound); flow paths, menu selections; call outcomes (answered, missed, transferred, completed) | | **Appointment & Booking Data** | Appointment type, service category; date, time, location; staff/resource allocation; notes provided by caller or Customer | | **Customer User Data** | Authorised user names, emails; role and permission levels; platform activity logs | | **Technical Data** | IP address; device/browser information; performance logs and error traces (e.g., via Sentry or Datadog) | | **Free-Text Content** | Any unstructured data provided by Customer or callers, manually or verbally | *** ## 5. Categories of Data Subjects * Customer’s callers, clients, patients, prospects, or leads; * Customer’s employees, staff, contractors or authorised users; * individuals referenced in free-text notes or bookings; * any other person whose data appears in Customer Data. *** ## 6. Special Categories of Data Provider does **not** intend to process special category data. However, callers may voluntarily disclose such data during conversations (e.g., minor health information such as “I have back pain”). If Customer configures flows that lead to such disclosures, Customer is responsible for: * having a lawful basis; * appropriate notices; * configuring retention and deletion; * ensuring compliance with GDPR Article 9 requirements. Provider will process such data only as necessary to fulfil Customer instructions. *** # Annex 2 — Security Measures Provider implements technical and organisational measures appropriate to the risk, in accordance with Articles 28, 32 and 5(1)(f) GDPR. A high-level summary of measures is outlined below. ## 1. Organisational Measures ### 1.1 Information Security Policies * documented security, privacy, access control and incident response policies; * regular review and approval by leadership; * all employees and contractors receive mandatory training on confidentiality, data protection, and security obligations, and are required to comply with Provider's internal security and confidentiality policies. ### 1.2 Access Control & Authentication * role-based access control (RBAC); * least-privilege access for all internal users; * MFA enforced for staff with access to production systems; * periodic access review and revocation during offboarding. ### 1.3 Confidentiality Obligations * all employees and contractors are bound by confidentiality agreements; * access granted only to those requiring it for support or troubleshooting. ### 1.4 Secure Development Practices * code reviews, version control, CI/CD pipelines; * vulnerability scanning and dependency monitoring; * separation of development, staging, and production environments. *** ## 2. Technical Measures ### 2.1 Encryption * encryption of data in transit using TLS 1.2+; * encryption of data at rest by Sub-Processors (e.g., AWS EBS, S3, RDS, depending on subsystem); * hashed and salted credentials; * secure key management by cloud providers (KMS). ### 2.2 Infrastructure Security * hosting on Amazon Web Services (AWS), with physical/data centre protections; * network segmentation and security groups; * automated backups; * firewalls and DDoS mitigation. ### 2.3 Monitoring & Logging * application and infrastructure logging (Datadog, Sentry, CloudWatch); * anomaly detection and alerting; * audit trails for access to data and systems; * rate limiting and abuse detection for telephony endpoints. ### 2.4 Incident Response * documented incident response procedures; * processes for triage, containment, remediation, and reporting; * GDPR-compliant breach notification workflows. ### 2.5 Data Minimisation & Retention Controls * only storing operationally necessary metadata; * raw audio stored primarily by ElevenLabs as Sub-Processor; * minimal internal caching; * Customer-configurable retention where supported. *** ## 3. Telephony & AI Model Security ### 3.1 Telephony Security (Twilio) * secure SIP/TLS signalling where applicable; * fraud detection and abuse prevention controls; * carrier-level encryption where supported. ### 3.2 AI Model Security * AI models hosted by authorised Sub-Processors; * Provider does not use Customer Data for training unless anonymised/aggregated; * input/output logs controlled and access-restricted. *** ## 4. Third-Party Sub-Processor Controls Provider ensures Sub-Processors: * comply with security requirements that are no less protective than this DPA; * use secure infrastructure and encryption; * are bound by confidentiality; * are audited or certified where applicable (e.g. AWS SOC 2/ISO 27001). *** ## 5. Business Continuity & Resilience * regular backups; * multi-region redundancy for critical services; * recovery plans aligned with cloud-provider continuity guarantees; * ongoing evaluation of infrastructure reliability. *** These measures are reviewed periodically and updated to reflect evolving risks, best practices, and operational needs. *** # Annex 3 — Sub-Processors Provider uses certain Sub-Processors to support the delivery of the Services. The current list of Sub-Processors, including their roles and processing locations, is maintained at: [Sub-Processors](/legal/subprocessors) Provider may update this list in accordance with Section 7 of this DPA (Sub-Processors). Customer will be notified of any material changes in accordance with the Agreement. *** # Contact us Email: **[loic@intavia.ai](mailto:loic@intavia.ai)**\ Controller: **Intavia LTD**\ Registered address: Charilaou Xyloforou 13, Agios Athanasios, 4103, Limassol, Cyprus. # Legal Documents Source: https://docs.intavia.ai/legal/index Access all Intavia legal documents including our Master Services Agreement, Data Processing Agreement, Privacy Policy, and more.
Version:
Effective:
Last Updated:
Welcome to the Intavia legal center. Here you'll find all legal documents governing your use of our services. ## Most Recent Update **January 1, 2025** — Initial publication of all legal documents. ## Documents * **[Master Services Agreement](/legal/msa)** — Terms governing your use of Intavia services * **[Data Processing Agreement](/legal/dpa)** — How we process data on your behalf * **[Sub-Processors](/legal/subprocessors)** — Third-party services we use to deliver our platform * **[Privacy Policy](/legal/privacy)** — How we collect and use your personal information * **[Cookie Policy](/legal/cookie-policy)** — How we use cookies and similar technologies * **[Change Log](/legal/changelog)** — History of changes to our legal documents # Master Services Agreement Source: https://docs.intavia.ai/legal/msa The Master Services Agreement outlines the terms and conditions governing your use of Intavia's AI receptionist services.
Version:
Effective:
Last Updated:
This document is incorporated by reference into all Order Forms and governs your use of Intavia services.
This Master Services Agreement (“Agreement” or “MSA”) sets out the terms under which **Intavia LTD**, Charilaou Xyloforou 13, Agios Athanasios, 4103, Limassol, Cyprus (“Provider”, “we”, “us”, “our”) provides Services to any customer who signs an Order Form or uses the Services (“Customer”, “you”). This MSA, together with any Order Forms and the DPA, forms a binding Agreement. Use of the Services, and signing of the Order Form constitutes acceptance of this MSA. *** # 1. Definitions **"Affiliate"** means any entity controlling, controlled by, or under common control with a party. **"Agreement"** means this MSA, the DPA, all Order Forms, and any referenced policies. **"Customer Data"** means data provided or generated by Customer via the Services, including Personal Data of callers, leads, clients, patients, staff, or other individuals. **"Customer Systems"** means any systems, telephony providers, CRMs, calendars, booking tools, or infrastructure that Customer owns or controls. **"DPA"** means the Data Processing Addendum located at:\ [Data Processing Agreement (DPA)](/legal/dpa) **"Documentation"** means user guides, instructions, and specifications made available by Provider. **"Order Form"** means any ordering document signed or accepted by Customer. **"Personal Data"**, **"Processing"**, **"Controller"**, and **"Processor"** have the meanings given in Data Protection Laws. **"Services"** means the AI receptionist, call handling, outbound calling (if enabled), integrations, configuration, onboarding, dashboards, logging, and related services as described in the applicable Order Form and Documentation. **Any functionality not expressly described in the Order Form or Documentation is excluded.** **"Sub-Processor List"** means the list published at:\ [Sub-Processors](/legal/subprocessors) *** # 2. Structure of the Agreement If there is a conflict, the documents apply in this order: 1. The Order Form 2. Specific Addenda (e.g., Outbound Calling Addendum, SLA) 3. The Data Processing Addendum (DPA) 4. This MSA **This Agreement supersedes prior agreements relating to the Services**, but does not supersede the DPA, Order Forms, or applicable addenda which together form part of this Agreement. *** # 3. Services ## 3.1 Provision of Services Provider will provide the Services described in the applicable Order Form, using reasonable skill and care. ## 3.2 AI Output Limitations The Services use machine-learning and generative AI technologies. Accordingly: * AI outputs may be inaccurate, incomplete, or inappropriate. * Provider does not warrant the accuracy of any AI-generated content. * Customer remains responsible for reviewing, validating, and supervising outputs. * **Customer remains the data controller and is responsible for all instructions, prompts, data, and configurations used by or provided to the AI.** Customer agrees not to rely on AI Outputs as the sole source of truth for business, legal, medical, or safety-critical decisions. ## 3.3 Third-Party Dependencies The Services rely on third-party providers for telephony, AI infrastructure, hosting, and related functionality. Provider is not liable for outages or failures caused by such providers but will use reasonable efforts to minimise disruption. **Provider may replace or change third-party providers at any time, provided such changes do not materially reduce overall functionality.** ## 3.4 No Professional Advice The Services do not provide: * medical, dental, chiropractic, aesthetic, or health advice * legal advice * financial advice * regulated professional recommendations **AI may generate statements that appear to be professional advice; Customer agrees such outputs are non-advisory and must not be treated as professional guidance.** Customer must ensure scripts, flows, and instructions are clinically and legally appropriate. *** # 4. Trials, Setup, and Go-Live ## 4.1 Free Trials If a trial is offered: * duration is specified in the Order Form (typically **14 days**); * Customer may cancel anytime during the trial; * if not cancelled, the subscription begins automatically. ## 4.2 Setup Services Setup includes configuration, workflow design, integrations, tuning, and testing. Setup fees are: * due upfront * **refundable only if Provider materially fails to deliver the setup as expressly described in the Order Form** * separate from subscription fees If Customer later substantially changes their systems, additional setup fees may apply. ## 4.3 Pilot → Standard Contract Transition (High-Tier) For high-tier/custom plans: * initial pilot stage may have a **30-day** notice period * after Customer approves the pilot, the notice period becomes **90 days** or as stated in the Order Form *** # 5. Customer Responsibilities Customer must: ### (a) Compliance & Legal Duties * Comply with all applicable laws (GDPR, PECR, TCPA if applicable). * Obtain caller consent for call recordings where required. * Ensure legality of outbound calling and contact lists. * Ensure sector-specific compliance (healthcare, dental regulations, etc.). * **Ensure accuracy of all business hours, pricing, staff information, service lists, emergency procedures, and any factual content provided to the AI.** ### (b) Telephony & Technical Configuration * Configure call forwarding correctly. * Ensure their telephony provider supports forwarding. * Maintain Customer Systems in working order. ### (c) Instructions to the AI Customer is solely responsible for: * scripts, prompts, and flows they configure; * accuracy of business information; * ensuring instructions do not cause unlawful or incorrect outputs. ### (d) Integrations Customer must ensure Customer Systems (CRM, calendar, booking system) are accessible and functional. ### (e) Prohibited Use Customer shall not: * use Services for unlawful purposes; * provide harmful, misleading, or illegal instructions; * **use the Services to engage in automated calling, robocalling, or spam-like behaviour.** *** # 6. Fees and Payment ## 6.1 Subscription Fees Subscription fees are billed **monthly in advance**. ## 6.2 Usage Fees Usage fees (minutes, outbound calling, overages) are billed: * in arrears; or * on the next invoice cycle ## 6.3 Late Payments If payment fails: * retries occur over **7 days** * notice issued * services may be suspended at **14 days** * interest may be charged at **4% above Bank of England base rate** ## 6.4 Price Changes Provider may update pricing with **30 days' notice**.\ **Price changes take effect at the start of the next billing cycle following the notice period.** *** # 7. Term, Termination & Suspension ## 7.1 Term The Agreement begins when Customer signs an Order Form or uses the Services. ## 7.2 Cancellation & Notice * **Standard:** 30 days * **High-tier/custom:** 90 days after pilot phase ## 7.3 Termination for Cause Either party may terminate for material breach unresolved for **14 days**. Provider may immediately suspend or terminate if Customer: * violates telemarketing laws * misuses AI * poses a security risk * misuses outbound calling **Provider may also immediately suspend the Service if Customer's telephony setup, forwarding configuration, or integrations create service disruption, excessive load, or risk to Provider's systems.** ## 7.4 Effect of Termination Upon termination: * Services cease * Customer Data retained for **90 days** then deleted/anonymised * unpaid fees remain payable *** # 8. Data Protection See our [Data Processing Agreement (DPA)](/legal/dpa) and [Sub-Processors](/legal/subprocessors). *** # 9. Intellectual Property ## 9.1 Provider IP Provider owns all: * software, algorithms, models * system logic, call flow structures, workflow designs * tools, scripts, and dashboards * documentation ## 9.2 Custom Flows & Collaborative Work **Provider owns the logic, flow structure, and implementation of any custom flows or scripts created, even if based on Customer instructions.** Customer retains ownership of the underlying business information they provide, and receives a licence to use the implemented flows solely within the Services. ## 9.3 Customer Data Customer retains ownership of Customer Data.\ Provider may process Customer Data solely to provide the Services. *** # 10. Confidentiality Mutual confidentiality applies with standard exceptions. *** # 11. Warranties & Disclaimers Provider warrants Services will be delivered with reasonable skill and care. **Provider does not guarantee:** * uninterrupted service * accuracy of AI outputs * business/financial outcomes * long-term functionality of integrations * compatibility with all telephony or VoIP systems The Services are provided **"as is"**. *** # 12. Indemnification Customer shall indemnify, defend, and hold harmless Provider from claims arising from: * unlawful outbound calling * data misuse * incorrect business information * Customer System failures * violation of telemarketing laws * breach of this Agreement or the DPA * misuse of AI ## 12.1 AI Output Indemnity **Customer shall indemnify Provider for any claim arising from AI outputs that reflect, extend, or rely upon Customer-provided data, instructions, prompts, configurations, or business information.** *** # 13. Limitation of Liability ## 13.1 Liability Cap Provider's total liability is limited to **the fees paid by Customer in the 1 month prior to the claim**, unless a higher cap is specified in the Order Form. ## 13.2 Exclusions Provider is not liable for: * revenue loss * business loss * data loss * telephony outages * Sub-Processor failures * AI inaccuracies * emergency misrouting * indirect or consequential damages ## 13.3 Uncapped Liability Not limited for: * fraud * death/personal injury caused by negligence * misuse of data in violation of the DPA *** # 14. Changes to Services & Terms Provider may modify the Services.\ **Material reductions require 30 days' notice.**\ Non-material changes require no notice. Provider may update this MSA with **30 days' notice**. *** # Contact us Email: **[loic@intavia.ai](mailto:loic@intavia.ai)**\ Controller: **Intavia LTD**\ Registered address: Charilaou Xyloforou 13, Agios Athanasios, 4103, Limassol, Cyprus # Privacy Policy Source: https://docs.intavia.ai/legal/privacy Learn how Intavia collects, uses, and protects your personal information. Our privacy policy outlines your rights and our commitment to data protection.
Version:
Effective:
Last Updated:
We are **Intavia LTD**, a company registered in Cyprus. This Privacy Policy explains how we collect, use, share, and protect your personal data when you visit our website or use our online demo tools. If you are a customer using our AI receptionist platform to process caller data, the processing of that data is governed by our **Data Processing Addendum (DPA)**, available at: [Data Processing Agreement (DPA)](/legal/dpa) *** # 1. What this Privacy Policy covers This policy applies to: * Visitors to our website (intavia.ai) * Users who interact with our online AI Receptionist demo widget * Individuals who submit contact forms or enquiries * Individuals who communicate with us by email or phone This policy does **not** apply to caller data processed on behalf of our customers through the Intavia platform. *** # 2. Personal data we collect We collect the following categories of data depending on how you interact with us. ## 2.1 Information you provide voluntarily * First name * Last name * Email address * Business or contact details * Any information you submit through forms * Audio generated during the website AI demo * AI-generated transcripts of demo calls ## 2.2 Automatically collected data ("Usage Data") * IP address * Browser and device type * Pages visited * Time spent on pages * Technical and diagnostic information * Cookies and similar tracking technologies ## 2.3 AI Demo–Specific Data If you initiate a demo call on our website, we collect: * Audio of your call * AI-generated transcript * Session metadata including timestamps, call duration, and technical information *** # 3. How and why we use your data We process personal data for the purposes set out below, each with a lawful basis under UK/EU GDPR. | Purpose | Description | Lawful Basis | | ----------------------------------------------- | ------------------------------------------------------------------------------ | ----------------------------------------------------------------------- | | Provide our website and services | To operate, maintain, and deliver the website and online features. | Legitimate interests (running and improving our services) | | Respond to enquiries or requests | To reply to messages and handle contact requests. | Legitimate interests (communicating with users) | | Provide the website AI Receptionist demo | To enable audio interactions and return demo responses. | Legitimate interests (offering and evaluating interest in our services) | | Improve the performance and quality of the demo | To troubleshoot issues, analyse interactions, and enhance the demo experience. | Legitimate interests (service improvement) | | Maintain security and prevent fraud | To secure the website and detect abusive or harmful behaviour. | Legitimate interests (ensuring platform integrity) | | Comply with our legal obligations | To meet regulatory, tax, or record-keeping requirements. | Legal obligation | We do **not** sell personal data. *** # 4. AI Demo / Website Widget Call Processing ## 4.1 What we collect When you use our AI demo widget, we process: * Your voice/audio * AI-generated transcript * Call/session metadata * Any information you verbally provide ## 4.2 How we use demo call data We use this data to: * Provide the AI demo functionality * Diagnose performance issues * Improve demo accuracy and responsiveness * Respond if you request a follow-up * Maintain system safety and prevent abuse ## 4.3 AI Output Behaviour Our AI receptionist uses machine-learning models that may: * Misinterpret speech * Generate inaccurate or fictional responses (“hallucinations”) * Incorrectly infer personal information * Produce synthetic or approximate language outputs AI outputs must **not be treated as factual**.\ AI hallucination alone **is not** a Personal Data Breach unless caused by a security incident. ## 4.4 Lawful basis for demo processing * **Legitimate Interests (Article 6(1)(f))** — providing and improving the demo * **Consent** — only when you explicitly request follow-up communication or marketing ## 4.5 Third-party processors used for the demo Demo interactions may be processed by: * **AWS (EU – London)** — hosting and infrastructure * **Sentry (EU)** — error monitoring * **Datadog (EU)** — performance monitoring * **ElevenLabs (US)** — speech processing and audio storage All third parties act strictly under our instructions and cannot use demo data for their own purposes. ## 4.6 International transfers Where demo data is processed outside the UK/EU, we use appropriate safeguards such as: * Standard Contractual Clauses (SCCs) * UK International Data Transfer Addendum (IDTA) * Additional technical and organisational measures ## 4.7 Demo data retention We retain demo audio and transcripts for: **30-90 days**. After this period, they are permanently deleted. This retention applies only to the website demo widget. Customer platform data may follow different retention periods under the DPA. ## 4.8 Your rights regarding demo data You may request: * Access to your demo call audio or transcript * Deletion * Correction of transcript inaccuracies * Restriction or objection to processing * Data portability (where applicable) To exercise your rights, contact **[loic@intavia.ai](mailto:loic@intavia.ai)**. *** # 5. Cookies and tracking technologies We use cookies and similar technologies to: * Operate essential website functions * Maintain security * Understand website usage (if you consent to analytics cookies) Where required, we display a cookie consent banner allowing you to accept or reject non-essential cookies. For full details, see our [Cookie Policy](/legal/cookie-policy). *** # 6. How long we keep your data Retention depends on the type of data: * Website form submissions: **12–24 months** * AI demo call data: **30-90 days** * Technical logs: **30–180 days** * Email correspondence: as long as necessary to respond * Customer platform data: defined in the **DPA** We retain data longer only if required by law or necessary to establish or defend legal claims. *** # 7. Your GDPR rights Under UK and EU GDPR, you have the right to: * Access your personal data * Correct inaccurate or incomplete data * Request deletion (“right to be forgotten”) * Restrict or object to processing * Request data portability * Withdraw consent (where processing is based on consent) * File a complaint with a supervisory authority UK regulator (ICO): [https://ico.org.uk](https://ico.org.uk) We will respond to all rights requests within the timelines set by GDPR. *** # 8. Security We use appropriate technical and organisational measures to protect personal data, including: * Encryption in transit (TLS) * Role-based access controls and MFA * Secure cloud hosting (AWS) * Logging and monitoring (Sentry, Datadog) * Vulnerability scanning and dependency monitoring * Abuse and rate-limit protections For detailed security measures relevant to customer platform data, refer to our DPA. *** # 9. Changes to this policy We may update this Privacy Policy from time to time. When we make material changes, we will update the “Last updated” date and may provide additional notice where appropriate. *** # 10. Contact us If you have any questions about this Privacy Policy or how we process your data: **Email:** [loic@intavia.ai](mailto:loic@intavia.ai)\ **Controller:** Intavia LTD\ **Registered address:**\ Charilaou Xyloforou 13\ Agios Athanasios, 4103\ Limassol, Cyprus # Sub-Processors Source: https://docs.intavia.ai/legal/subprocessors A list of third-party sub-processors that Intavia uses to provide its services, including their purpose and location.
Version:
Effective:
Last Updated:
This document is incorporated by reference into all Order Forms and governs your use of Intavia services.
This page lists the third-party service providers ("Sub-Processors") that **Intavia LTD** engages to support the delivery of our AI receptionist services. A Sub-Processor is a third party that processes **Customer Data** on our behalf in connection with providing the Services. This list does **not** include vendors who only process Intavia’s own business data or website visitor data. For more information, please refer to our Data Processing Addendum (DPA):\ [Data Processing Agreement (DPA)](/legal/dpa) *** ## What is a Sub-Processor? A Sub-Processor is a third-party company contracted by Intavia LTD that processes **Customer Data** (as defined in our DPA) in order to help us provide core features of the AI receptionist platform, including: * telephony connectivity * voice processing * call audio/transcript handling * infrastructure hosting * monitoring and diagnostics We require all Sub-Processors to enter into data protection agreements with us and maintain appropriate security and confidentiality protections. Sub-Processors listed here **do not** process your data for their own purposes. *** # Current Sub-Processors Below is the current list of Sub-Processors, including their function and primary data processing region. *** ### 1. Amazon Web Services (AWS) **Role:** Cloud hosting, storage, compute, networking\ **Purpose:** Hosting of Intavia’s infrastructure and application environment\ **Region:** EU – London\ **Data processed:** Customer Data stored or processed in our platform (metadata, logs, configuration data) *** ### 2. Sentry (Functional Software, Inc.) **Role:** Application error monitoring & diagnostics\ **Purpose:** Detect, troubleshoot and fix software errors\ **Region:** EU\ **Data processed:** Application metadata, error traces, non-sensitive diagnostic data *** ### 3. Datadog **Role:** Performance monitoring & log aggregation\ **Purpose:** System observability, performance metrics, operational diagnostics\ **Region:** EU\ **Data processed:** Application logs, technical metadata *** ### 4. Twilio **Role:** Telephony connectivity (phone numbers, inbound/outbound calls, SIP, routing)\ **Purpose:** Provide phone number provisioning, call routing and real-time telephony infrastructure\ **Region:** Varies depending on Customer’s phone number and routing configuration\ **Data processed:** Telephony metadata (caller ID, timestamps, routing events) *** ### 5. ElevenLabs **Role:** Voice processing (TTS/STT); storage of call audio & transcripts\ **Purpose:** Generate AI voice responses, handle speech recognition and store call audio/transcripts\ **Region:** United States\ **Data processed:** Call audio, transcripts, timing metadata *** # How we notify customers of changes We may update this list from time to time as we add or replace Sub-Processors.\ For material changes, we will notify customers via: * Dashboard notification, **or** * Email to the account owner * Updated Sub-Processor page with version and date The current version is always available at:\ our [Sub-Processors page](/legal/subprocessors). *** # Customer right to object If you reasonably believe that a new Sub-Processor presents a material data protection risk, you may submit an objection (per the DPA) by contacting: **Email:** [loic@intavia.ai](mailto:loic@intavia.ai) We will work with you in good faith to address objections. If no resolution is possible, you may terminate the affected services in accordance with our DPA. *** # Historical versions You may request previous versions of this Sub-Processor list by contacting us.\ Version history will be maintained internally. *** # Contact us Email: **[loic@intavia.ai](mailto:loic@intavia.ai)**\ Controller: **Intavia LTD**\ Registered address: Charilaou Xyloforou 13, Agios Athanasios, 4103, Limassol, Cyprus # Security and Trust Source: https://docs.intavia.ai/security How Intavia protects customer data across its voice-agent platform, infrastructure, integrations, and development processes. # Security at Intavia This page summarises the controls Intavia uses to protect customer data. **Last updated:** 27 July 2026 ## Data hosting and encryption Intavia's primary production data is hosted in the AWS London region and is not publicly accessible. Customer data is encrypted in transit and at rest. Production credentials are protected and are not exposed to voice agents. In the standard voice-agent deployment, ElevenLabs processes call audio, transcripts, and related metadata in the United States. OpenAI may process transcript text and related call information in the United States. These transfers are governed by our [Data Processing Addendum](/legal/dpa), including the EU Standard Contractual Clauses. Other provider roles and processing locations are listed on our [Sub-Processors page](/legal/subprocessors). ## Access and integration boundaries * Customer accounts use authenticated, organisation-scoped access controls. * Administrative access is restricted to authorised personnel according to operational need. * Practice-management and scheduling integrations expose predefined operations with validated inputs; they do not provide unrestricted access to the customer's underlying system. * Where supported, customers can use dedicated integration users and provider permissions to limit access to the agreed workflows. ## Infrastructure security and availability Intavia uses web-application firewall rules, request authentication, source restrictions where appropriate, and rate limits to restrict access to expected systems and traffic. * The production database is configured for automatic failover. * Encrypted automated database backups are retained for 30 days and replicated to a second AWS region in the EU for disaster recovery. * The application layer scales automatically with demand. * Recovery procedures cover restoring core data and redeploying services. ## Monitoring and development * Infrastructure and application health are monitored, with alerts for operational failures and security-relevant events. * Operational logging favours identifiers, status information, and sanitised diagnostics. Access to operational data is restricted. * GitHub Dependabot monitors application dependencies for known vulnerabilities and raises automated security updates where fixes are available. * Software changes are version controlled, automatically checked, and deployed through controlled workflows. If a personal data breach affects a customer, Intavia will provide notification in line with the DPA and applicable law. ## Assurance and due diligence Provider assurance material is available through the [AWS Compliance Programmes](https://aws.amazon.com/compliance/programs/), [ElevenLabs Trust Center](https://compliance.elevenlabs.io/), [OpenAI Trust Portal](https://trust.openai.com/), and [Datadog Security Center](https://security.datadoghq.com/). For a security questionnaire or supporting information, email [andreas@intavia.ai](mailto:andreas@intavia.ai) with the customer name and service being reviewed. ## Report a security issue To report a suspected security vulnerability or incident, email [andreas@intavia.ai](mailto:andreas@intavia.ai) with a description of the issue and the affected service. Please do not access customer data or disrupt the service while investigating. ## Related documents * [Data Processing Addendum](/legal/dpa) * [Sub-Processors](/legal/subprocessors) * [Privacy Policy](/legal/privacy) *** **Document owner:** Intavia LTD\ **Security contact:** [andreas@intavia.ai](mailto:andreas@intavia.ai)