1. Where your data is stored
The information that matters most — the recordings, transcripts, messages and configuration that describe your business — is held on infrastructure located in Australia.
Australia — Sydney region. Call recordings, transcripts, SMS content, contacts, knowledge base, and account data are stored on cloud infrastructure operating in Australian availability zones.
- Phone numbers: Australian local, mobile and 1300 numbers, provisioned from Australian carriers.
- Call recordings: Stored at rest in Australian object storage, encrypted with AES‑256.
- Call transcripts & summaries: Written to an Australian‑hosted database.
- SMS content: Sent, received, and retained through Australian‑hosted messaging infrastructure.
- Account & billing metadata: Stored in an Australian‑hosted database; billing identifiers are held by the app store used to purchase your subscription.
2. Sub‑processors and their locations
EzyBiz relies on a small number of specialist providers to deliver telephony, authentication and AI voice services. The table below shows what each does and where the processing occurs.
| Sub‑processor | Purpose | Processing region |
|---|---|---|
| Twilio | Number provisioning, call carriage, SMS delivery | AU |
| Firebase (Google Cloud) | Authentication, application database, push notifications | AU Sydney (australia-southeast1) |
| RetellAI | Real‑time voice processing for the virtual receptionist | US with strict TLS in transit |
| RevenueCat | Subscription entitlement management | US |
| Firebase Crashlytics | Anonymised crash reporting | US |
Every sub‑processor is bound by a data‑processing agreement that requires equivalent protections to those set out in the Australian Privacy Principles.
3. Cross‑border transfers
Where a sub‑processor operates outside Australia, we only transfer the minimum data necessary for that service to function. Voice audio sent to RetellAI is streamed live for real‑time reply generation and is not retained by RetellAI for model training. Diagnostic data is anonymised before it leaves your device.
All traffic between your device, EzyBiz systems and every sub‑processor is protected by TLS 1.2 or above. Voice payloads use SRTP where the carrier supports it. Nothing about your callers is sent in the clear.
4. Retention windows
Data is only kept for as long as it remains useful to you, then removed on the schedule below. You can request earlier deletion at any time.
- Call recordings: 90 days from the call.
- Call transcripts & summaries: 12 months from the call.
- SMS messages: 12 months from send or receipt.
- Contacts & knowledge base: Retained while your account is active.
- Account data after deletion: Removed within 30 days of account closure.
5. Access controls
Access to production systems is limited to a small named group of engineers, authenticated via hardware‑backed multi‑factor sign‑in and logged. Customer data is not accessed by our staff except to investigate a specific issue you have raised or to comply with a lawful request.
6. Government and law‑enforcement requests
We follow the Telecommunications Act 1997 (Cth) and the Telecommunications (Interception and Access) Act 1979 (Cth) when responding to any lawful request from Australian authorities. We do not provide bulk access to customer data. Where legally permitted, we notify affected customers of a request that concerns their account.
7. Portability and export
You can export your knowledge base, call history and transcripts through the app at any time. If you close your account, you can request a copy of your data within the 30‑day retention window before it is permanently removed.
8. Questions or complaints
If you have questions about how EzyBiz handles your data, contact us at hello@avocadodigital.com.au. If you are not satisfied with our response, you can raise a complaint with the Office of the Australian Information Commissioner at oaic.gov.au.
EzyBiz
Back to home