WIT SOLUTIONS PTY LTD (ACN 634 805 324), trading as ReelAI ("we", "us", or "our"), operates a business-to-business (B2B) software-as-a-service (SaaS) platform that enables businesses ("Clients") to manage AI-powered voice receptionist services.
This Privacy Policy explains how we collect, use, disclose, and protect information about our business clients who use our platform. This policy does not cover the personal information of your end-users (customers who call your business) — you are responsible for your own privacy practices regarding that data.
We are committed to protecting your privacy and complying with the Australian Privacy Act 1988 and the Australian Privacy Principles (APPs).
2. Data Controller vs Data Processor
2.1 ReelAI as Data Processor
For call recordings, transcripts, and end-user data processed through our platform:
You (the Client) are the Data Controller
ReelAI is the Data Processor
You determine the purposes and means of processing
We process data only on your instructions
You are responsible for obtaining consent from your end-users
2.2 ReelAI as Data Controller
For your business account information (company name, email, billing details):
ReelAI is the Data Controller
We determine how this information is collected and used
We do NOT store payment card details. All payment processing is handled securely by Stripe, a PCI DSS Level 1 certified payment processor. Payment card information is entered directly on Stripe's secure payment forms and never touches our servers.
Information we store for billing purposes:
Stripe Customer ID and Subscription ID (for account management)
Billing history and invoices
Tax information (GST registration number if provided)
3.4 End-User Data (Processed on Your Behalf)
We process the following data on your instructions as a Data Processor:
Call recordings and transcripts
Phone numbers of callers
Names and information provided during calls
Call metadata (duration, date/time, outcome)
Campaign data uploaded by you (CSV imports)
4. How We Use Your Information
4.1 Service Delivery
Provide and maintain the ReelAI platform
Process voice calls and transcriptions
Store and manage call recordings
Send you notifications about calls and system events
Provide customer support
4.2 Platform Improvement
Analyze platform usage to improve features
Monitor system performance and reliability
Develop new features and services
Conduct research and development
4.3 Business Operations
Process billing and payments
Send account-related communications
Comply with legal obligations
Enforce our Terms of Service
Protect against fraud and abuse
5. Data Storage and Security
5.1 Storage Location
We use the following infrastructure providers:
Amazon Web Services (AWS) - Sydney, Australia: All permanent data storage including encrypted databases, secure file storage, and email services. AWS Sydney infrastructure is IRAP-assessed at the PROTECTED level.
Azure OpenAI - Australia East: AI analysis and processing for call transcripts and data mapping
Anthropic (via AWS Bedrock) - Sydney, Australia: AI analysis for call insights. Data is processed within AWS in Australia and is not shared with or retained by Anthropic.
Retell AI - United States: Real-time call processing during active calls. Retell retains metadata only (transcripts, recordings, and PII removed) and deletes any retained data within 24 hours; the permanent record is stored in Australia - see Section 6.1 below
5.2 Security Measures
We implement enterprise-grade security measures to protect your data:
Military-Grade Encryption at Rest: All data stored in our secure databases and file storage uses AES-256 encryption, the same standard used by governments and financial institutions worldwide
Encryption in Transit: All data transmission uses TLS 1.3 protocol with perfect forward secrecy
Australian Data Centres: Permanent storage is hosted on AWS Sydney infrastructure, which is IRAP-assessed at the PROTECTED level
Multi-Tenant Isolation: Database-level client separation ensures your data cannot be accessed by other clients
Zero Payment Card Storage: All payment processing handled by PCI DSS Level 1 certified Stripe
Role-Based Access Controls (RBAC): Granular permission system with admin and client roles
Secure Password Storage: Industry-standard bcrypt hashing with salt
Webhook Security: Rate limiting and endpoint protections on inbound webhook traffic
Security Maintenance: Ongoing application of security patches and platform updates
Why Security Matters to Your Business
We've invested in enterprise-grade security infrastructure because your reputation depends on it. When your customers' call data is protected by the same AES-256 encryption used by banks and governments, you can confidently assure them their information is safe.
100% Australian data sovereignty means all permanent storage remains in Sydney data centers, giving you clear answers for privacy-conscious customers and compliance audits.
Hosting on AWS Sydney infrastructure that is IRAP-assessed at the PROTECTED level isn't just a checkbox—it's a competitive advantage that sets you apart from competitors using generic cloud platforms.
5.3 Data Retention
Call recordings and transcripts: Retained for 7 years by default (configurable per client)
Account information: Retained while your account is active plus 2 years after closure
Billing records: Retained for 7 years (Australian tax compliance)
Usage logs: Retained for 90 days
5.4 Data Breach Notification
We take data security incidents seriously and have comprehensive protocols in place:
Incident Response: We maintain documented incident response procedures designed for rapid assessment and containment
Assessment: Any suspected breach is immediately investigated to determine scope, impact, and appropriate response measures
Notification: In the event of a data breach that may impact your business or customers, we will:
Notify your organization (as Data Controller) immediately
Provide detailed information about the nature and scope of the breach
Work with you to determine appropriate notification requirements for affected individuals
Breach Details: Our notifications will include: nature of the breach, types of information involved, steps taken to mitigate harm, and recommended actions
Prevention: Post-incident reviews are conducted to strengthen security measures and prevent recurrence
Where a data breach is likely to result in serious harm, we will comply with our obligations under the Notifiable Data Breaches (NDB) scheme, including notifying affected individuals and the Office of the Australian Information Commissioner (OAIC) where required. Our multi-layered security approach is designed to prevent unauthorized access and detect anomalies before they become incidents.
6. Third-Party Sub-Processors (APP 8 Disclosure)
Important Cross-Border Disclosure (APP 8): During active calls, call audio is processed in real time by Retell AI in the United States. Retell is configured to store metadata only — call transcripts, recordings, and other personal information are removed and permanently deleted within 24 hours. The permanent transcript and recording are stored on our Australian infrastructure.
6.1 Essential Service Providers
Retell AI (United States)
Purpose: Real-time voice call processing and transcription
Data: Call audio processed in real time during active calls
Retention: Metadata only retained by Retell; transcripts, recordings, and PII removed and permanently deleted within 24 hours
Location: United States
Necessity: Required for core AI voice functionality
Amazon Web Services (Australia)
Purpose: Secure data storage and infrastructure services
Data: All platform data including recordings
Retention: As per your data retention settings (7 years default)
Location: Australia
Security: Encrypted at rest (AES-256) and in transit (TLS)
Data: Call transcripts, customer names, campaign data
Retention: Not used to train AI models. Content may be retained transiently (up to 30 days) for abuse monitoring in accordance with Microsoft's terms, unless a zero-retention exception applies
Location: Australia (East region)
Anthropic (via AWS Bedrock, Sydney, Australia)
Purpose: AI-powered call insights and analysis
Data: Call transcripts and related call data
Retention: Processed within AWS in Australia; not shared with or retained by Anthropic, and not used to train models
Location: Australia (AWS Sydney region)
Email Service Provider (Australia)
Purpose: Email notifications and communications
Data: Email addresses, call summaries
Retention: Email delivery logs retained for 14 days
Location: Australia
6.2 Your Consent to Cross-Border Disclosure
By using our services, you acknowledge and consent to:
Real-time processing of call audio in the United States by Retell AI (metadata-only retention, deleted within 24 hours)
The overseas disclosure described in this section (APP 8)
The privacy and data protection practices of our sub-processors
7. When We Share Your Information
We do not sell your personal information. We only share information in these circumstances:
7.1 With Your Consent
When you explicitly authorize us to share information
With third-party integrations you choose to enable
7.2 Service Providers
Sub-processors listed in Section 6
Payment processors for billing
Customer support tools
7.3 Legal Requirements
To comply with court orders, subpoenas, or legal process
To respond to government or regulatory requests
To protect our rights, property, or safety
To enforce our Terms of Service
7.4 Business Transfers
If ReelAI is acquired or merged with another company, your information may be transferred to the new owners (you will be notified beforehand).
8. Your Privacy Rights (Australian Privacy Principles)
Under the Australian Privacy Act 1988, you have the following rights:
8.1 Access (APP 12)
Request a copy of your personal information we hold
View your account information in the portal at any time
8.2 Correction (APP 13)
Update your account details through the portal
Request correction of inaccurate or outdated information
8.3 Deletion
Request deletion of your account and data
Some data may be retained for legal compliance (e.g., billing records)
We will work with you to resolve the matter to your satisfaction
9. Cookies and Tracking Technologies
We use cookies and similar technologies for:
9.1 Essential Cookies
Session management (login authentication)
Security features (CSRF protection)
These cookies are necessary for the platform to function
9.2 Preference Cookies
Remember your theme selection (dark/light mode)
Store your notification preferences
9.3 Analytics Cookies
Understand how you use the platform
Improve features and performance
Where possible this data is aggregated; it may include identifiers such as IP address and device information as described in Section 3.2
10. Children's Privacy
ReelAI Portal is a B2B service intended for business use only. We do not knowingly collect information from individuals under 18 years of age. If you become aware that a child has provided us with personal information, please contact us immediately.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect:
Changes to our services
Legal or regulatory changes
Changes to our data practices
We will notify you of significant changes by:
Email to your registered address
In-app notification
Updating the "Last Updated" date at the top of this page
12. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or your personal information: