Kesio AI Automation LLC (“Kesio”, “we”, “us”, “our”) is a Georgia limited liability company with its principal place of business in the Atlanta metropolitan area, Georgia. We provide a done-for-you front office to small businesses: answering telephone calls, following up by text message, producing financial analysis from records the business already keeps, and drafting social media content for the business to approve.
This policy describes two different relationships, and the difference matters.
When we act for ourselves. Our marketing website, our own sales enquiries, and the account records of the businesses that buy our services. For this information we decide the purposes and means, and this policy governs it.
When we act on behalf of a business Client. Almost everything the Services touch — the people who telephone a Client, the texts they exchange, the Client’s financial records — belongs to the Client, not to us. We handle it under the Client’s instructions and our agreement with them. We are a service provider (a processor). If you are a caller, a customer or a client of one of our Clients, that business — not Kesio — decides how your information is used, and their privacy notice governs it.
Throughout this policy, “Client” means a business that has engaged Kesio. “End User” means a person who interacts with that business through the Services.
Business name, address and jurisdiction; the practice areas or services it offers.
Name, business email address, telephone number and role of the people at the business who use or administer the Services.
Account credentials. Passwords are stored only as salted one-way hashes; we cannot read them.
Configuration the Client supplies: greeting text, intake questions, disclosure wording, business hours, calendar connections, expense categories.
Billing contact details. Kesio does not currently process card payments — there is no payment processor integrated today, and no card number is ever collected on a call or through the product. Fees are invoiced directly (see the Terms of Service). When card payment processing is introduced, it will be handled by a PCI-compliant payment processor using its own hosted checkout fields, and Kesio will not receive or store card numbers.
Telephone number and, where given, name and email address.
Audio recording of the call and a written transcript, where the Client has enabled recording.
Answers to the intake questions the Client configured — which, depending on the Client’s business, may include the reason for the enquiry and details of a personal, medical, financial or legal matter.
Appointment date and time, and whether the appointment was kept.
Text messages sent to or from the Client’s number through the Services, and delivery status.
Where a Client uses the financial module, the Client uploads exports from books it already keeps — typically CSV or spreadsheet files from a bank, a card issuer or an accounting package. We do not connect to a Client’s bank, we hold no banking credentials, and we initiate no payments. These files ordinarily contain transaction dates, amounts, merchant names and descriptions, and may contain the names of a Client’s own customers or matters.
Request logs kept by our website host, including IP address, user agent and pages requested.
Anything voluntarily submitted through a booking link or an enquiry.
The marketing site loads no analytics, advertising or tracking script of any kind — verified directly, not assumed. If that changes, this section will be updated before the change takes effect.
To provide the Services the Client engaged us to run — answering, booking, following up, analysing and drafting.
To set up, configure and support a Client’s account, including diagnosing faults.
To secure the Services, prevent abuse and investigate suspected misuse.
To bill for the Services and keep the records a business must keep.
To comply with law and to establish, exercise or defend legal claims.
We do not sell personal information, and we do not share it for cross-context behavioural advertising. This is true of the marketing site as well as of the Services.
We do not use End User Data or a Client’s financial records to market to anyone, and we do not use one Client’s data to serve another Client.
The agent identifies itself as an AI on every call, unprompted, in its first sentence. It takes information and books appointments. It does not give legal, financial, medical or other professional advice, and it says so when asked.
Recording is a per-Client setting. Where a Client enables it, the Services play a consent preamble before the greeting on every call, for every Client — not only in states that require all-party consent, since there is no reliable way to know which state a caller is in before the call connects. The Client decides whether to record at all, and remains responsible for meeting the consent laws of every state in which its callers may be located. Recording law differs by state, and several require the consent of all parties.
The Client is the sender. Messages go out under the Client’s own registered brand and telephone number. The Client is responsible for having a lawful basis to text each recipient.
Every message stream supports opt-out. Replying STOP ends messaging to that number, and the opt-out is honoured for that number from then on.
Quiet hours are configured per Client and are respected by the Services.
For a message beyond a simple reply to something the recipient already asked for — an appointment reminder, for example — the Client’s first message to a new recipient is itself the consent request, asking the recipient to reply YES before any further reminder texts are sent. We retain a record of consent status and opt-outs so that an opt-out cannot be undone by a later upload, and so consent, once given, is not asked for again. Email reminders do not require this same reply-based consent — email is governed by CAN-SPAM, which requires an honest sender and a working opt-out rather than advance opt-in — but an email recipient’s opt-out is honoured with the same permanence as a text STOP.
Outbound text messaging is built and tested, but is not yet switched on for any Client — it is pending carrier A2P registration, which is a per-Client process. This section describes what happens to a given Client’s messages once texting is switched on for that Client.
The Services use third-party AI models to conduct calls, transcribe them, summarise them, draft text and produce financial narrative. Output can be wrong. Nothing the Services generate is professional advice, and no output is published, sent or acted on without a person at the Client approving it — with the single exception of the live conversation itself, which is why the agent is confined to taking information and booking.
Anthropic, Supabase, SendGrid and Cloudflare have each confirmed contractually that Client Data and End User Data are not used to train their models. Retell, our voice vendor, reserves the right by default to use de-identified customer data to train and improve its own models, and its published opt-out is written in terms of call recording rather than in terms that clearly cover this use — so it is not yet confirmed whether disabling recording, or any other control in the product today, actually stops it. Kesio has not yet obtained Retell’s written confirmation on this point, so this policy does not state that no vendor trains on Client Data or End User Data, because for one vendor that would not yet be true.
We use the vendors below to deliver the Services. Each is bound by its own terms and is permitted to use the data only to provide its service to us.
Retell AI — the voice agent that answers and conducts the call. Touches call audio, the live transcript, the caller’s name and number, and answers to intake questions. United States.
ElevenLabs — speech synthesis used inside the voice agent. Touches the text of what the agent says and the generated audio; no caller-supplied content is sent to it directly. United States.
Twilio — telephone numbers, call routing, SMS delivery and A2P registration. Touches phone numbers, message content and call metadata. United States.
Cal.com — calendar availability and appointment booking. Touches name, email address, appointment time and matter type. United States.
Anthropic (Claude) — call summaries, drafting and financial narrative. Touches call transcripts, ledger text and category names. United States.
Google (Gemini) — images and graphics for drafted social posts. Touches prompt text derived from the Client’s public business description. United States.
SendGrid (Twilio) — transactional email, including confirmations, resets and notifications. Touches email addresses and message bodies. United States.
Supabase (on AWS) — the production database. Touches all Client Data and End User Data held by the Services. United States — AWS us-west-2.
Render — hosting for the Kesio application. Touches all data in transit through the application. United States.
Blotato — publishing approved social posts to the Client’s own accounts. Touches approved post content and the Client’s social credentials. Not yet enabled.
Cloudflare — hosting for the public marketing website only. Touches website request logs; no Client Data or End User Data. Global edge network.
This list is current as at the date of this policy. If we add a new subprocessor, we will give Clients at least 30 days’ notice before it begins processing Client Data or End User Data, and a Client may object to the change during that window. This notice period is not yet honoured with respect to Retell specifically, since Retell does not publish its own subprocessor list for Kesio to monitor; we will update this paragraph once that changes.
We may also disclose information: to comply with law or valid legal process; to enforce our agreements; to protect the rights or safety of any person; and to a successor in connection with a merger, acquisition or sale of assets, in which case we will give the Client notice.
A Client sets a retention preference for its own account. On termination, and on a Client’s written request at any time, we delete or return Client Data and End User Data within 30 days, except where we are required to keep it by law or need it to resolve a dispute. Backups age out on their own cycle.
On our own database, a request or termination triggers a staff-run deletion process that removes every record belonging to the Client from every relevant table and logs who asked, when, and what was removed. Our voice vendor (Retell) is configured to a bounded 30-day retention window on call recordings and related data, rather than retaining indefinitely, so those recordings age out there on the same schedule.
Data is encrypted in transit. The database is hosted by Supabase on AWS in the United States and encrypted at rest by that provider.
Each Client’s records are isolated at the database level by row-level security, so one Client’s account cannot read another’s.
Access to production is limited to personnel who need it. Passwords are hashed; secrets are held outside the codebase.
Staff accounts see the records their role permits and no more; call transcripts in particular are restricted.
No system is perfectly secure. We cannot guarantee that unauthorised access will never occur. Kesio will notify an affected Client without unreasonable delay, and in any event within 5 business days of confirming a security incident affecting that Client’s Client Data or End User Data, and will reasonably cooperate with the Client’s own notification obligations to End Users and regulators. This is a starting position, not a survey of the specific notification deadlines that may apply state by state to a Client’s own End Users (provisional, pending attorney review).
If you are an End User — you telephoned or texted a business that uses Kesio — your relationship is with that business. Direct any request to access, correct or delete your information to them. If you contact us instead, we will pass your request to the Client and tell you we have done so; we will not act on it ourselves except on the Client’s instruction or where the law requires otherwise.
If you are a Client, or a person at a Client, you may access, correct, export or delete your account information by contacting us.
Depending on where you live, you may have rights to know what personal information is held, to have it corrected or deleted, to a copy of it, and not to be discriminated against for exercising those rights. At Kesio’s current size, we do not believe we meet the applicability thresholds of any state’s comprehensive consumer privacy law — most, including California’s CCPA/CPRA, apply only above a revenue or data-volume threshold Kesio is well under, and Georgia itself has no comprehensive consumer privacy statute. This is re-checked as Kesio’s client base and data volume grow, not a one-time determination (provisional, pending attorney review).
To make a request: [email protected]. We will verify the request before acting on it and respond within the period the applicable law requires, or within 45 days if none applies.
The Services are sold to businesses and are not directed to children. We do not knowingly collect personal information from a child under 13. A caller may nonetheless be a minor, or may give information about one, depending on the Client’s business. If we learn we hold such information other than on a Client’s instruction, we will delete it. None of Kesio’s current or planned verticals — personal injury, immigration, family, criminal defense, estate, bankruptcy, and eventually insurance and home-service trades — are directed to children under COPPA’s test, which turns on whether the service targets an under-13 audience rather than on whether a minor might incidentally be discussed; family-law intake may still capture information about a minor from an adult caller, which is addressed above (provisional, pending attorney review).
We will post any revised policy here with a new effective date and, where the change is material, notify Clients by email before it takes effect.
Privacy requests: [email protected]
Legal notices: [email protected]
Post: Kesio AI Automation LLC, 1227 Upper Shoal Way, Lawrenceville, Georgia 30045