Privacy Policy
Last updated: June 14, 2026 • Effective date: June 14, 2026
Version 1.0 · Last reviewed June 2026 · Reviewed at least annually.
This Privacy Policy explains how Aevon LLC (“Aevon,” “we,” “us”) collects, uses, and protects information when a business (a “Client”) uses the Aevon client portal at portal.aevon.io (the “Portal”) and our AI voice-receptionist service (the “Service”). It works alongside the agreement between Aevon and each Client.
Who this covers
- Client account users — the business owner/administrator we work with, who logs into the Portal.
- A Client’s own customers/callers — people who call a Client’s AI receptionist. Their call data is handled by Retell (our voice-AI provider, an outside service that processes data for us) on the Client’s behalf; see “Call data and PHI” below.
For a Client’s customers/callers, the Client decides how that data is used (in legal terms, the Client is the “data controller”) and Aevon simply follows the Client’s instructions and our service agreement (acting as their “processor”).
What we collect
| Category | Examples | Source |
|---|---|---|
| Account & business info | Business name, category, location, contact name, login email | You, at onboarding |
| Credentials | Password (stored only in a scrambled form that can’t be read back — never as plain text) | You |
| Configuration | Business hours, report/summary-email preferences, the Client’s access key for Retell, our voice-AI provider (encrypted while stored) | You / setup |
| Billing | Stripe customer ID, plan, and billing status (Stripe is our payment processor) | Via Stripe |
| Usage & support | Login/session activity, admin audit logs, support messages | Automatic / you |
What we do not store
We deliberately do not store call content or patient health information. The Portal does not keep call audio, transcripts, or other call content in our database. That data lives in Retell; the Portal reads it only when needed to show summary figures and activity. This deliberately lean approach keeps the data we hold to the Client account and settings listed above.
How we use information
- Provide, operate, and support the Service and Portal.
- Authenticate users and secure accounts.
- Process billing through Stripe.
- Send routine service emails (welcome messages, password resets, reports and summaries) through Google Workspace / Gmail, our email provider.
- Keep activity logs for security and accountability.
We do not sell or share personal information (including for cross-context behavioral advertising). Neither Aevon nor our subprocessors use Client or caller data to train AI models for the benefit of other customers; we use data only as needed to provide and operate the Service.
Subprocessors
We use the following outside services to run the Service. Each one handles a limited type of data under its own data-protection terms:
| Subprocessor (outside service that handles data for us) | Purpose | Data |
|---|---|---|
| Retell (our voice-AI provider) | AI voice agent (the core product) | Call audio/content & analysis — health-data contract (BAA) in place |
| Neon (our database host) | Portal database | Client account & settings |
| Stripe (our payment processor) | Billing & payments | Billing/payment data |
| Vercel (our hosting provider) | Hosting | Data while it moves between systems |
| Google Workspace (our email) | Routine service email | Recipient email + message content |
Data sharing & disclosures
We share personal information only as needed to run the Service:
- With the subprocessors listed above, each acting on our instructions under its own data-protection terms.
- At a Client’s direction — for example, configuration or data the Client asks us to handle on their behalf.
- When required by law — to comply with a valid legal request, enforce our agreements, or protect the rights, safety, and security of Aevon, our Clients, or others.
- In a business transfer — if Aevon is involved in a merger, acquisition, or sale of assets, information may transfer as part of that transaction, subject to this policy.
We do not sell or share personal information for cross-context behavioral advertising.
Call data and PHI
For healthcare Clients, calls may include patient health information (sometimes called Protected Health Information, or PHI). Our approach:
- Patient health information is handled inside Retell (our voice-AI provider); the Portal does not store call content.
- For healthcare Clients, Aevon acts as a Business Associate under HIPAA. Aevon enters into a Business Associate Agreement (BAA) with each healthcare Client, and a BAA is in place with Retell, the voice-AI provider. These agreements govern permitted uses and disclosures of PHI, required safeguards, breach-notification obligations, and Aevon’s role in supporting the Client’s compliance with individual-rights requests (access, amendment, and accounting of disclosures). This Privacy Policy supplements but does not replace the applicable BAA. Patients and callers should direct any requests concerning their PHI to the Client (the healthcare provider); Aevon will assist the Client in fulfilling such requests as required under the BAA and applicable law.
Data retention & deletion
- Client account and settings data is kept while the account is active.
- When a Client leaves, we delete the Client’s Portal account (which also removes the stored Retell key and access), then clear any incidental copies after a 30-day grace period.
- Call data held in Retell is retained according to the Client’s instructions and the applicable BAA, and otherwise for as long as Retell’s terms allow.
For the full details — what we keep, for how long, and the exact steps when a Client leaves — see our Data Retention & Deletion Policy.
Security
- Passwords are stored only in a scrambled form that can’t be reversed back into the original; Retell keys and email secrets are encrypted while stored using strong, industry-standard encryption.
- We use secure login sessions; you can “sign out everywhere” and sign out individual devices.
- Each staff member has their own account secured with a passkey or a second login step (two-factor authentication), and staff get only the access they need to do their job.
Security incident notification
If a security incident affects personal information we hold, we will notify affected Clients without undue delay and no later than the timelines required by applicable law or the applicable BAA. For incidents involving PHI, we follow the HIPAA breach-notification timelines (45 CFR §164.410) and any stricter timeline we have committed to by contract. Clients are responsible for notifying their own customers/callers where required.
International data transfers
Aevon is based in the United States and is intended for U.S. Clients; we process personal information in the United States. Some subprocessors may process limited data outside the United States; where they do, they provide appropriate safeguards (such as Standard Contractual Clauses).
Automated decision-making
Aevon does not use the personal information of account users to make automated decisions that produce legal or similarly significant effects, and does not engage in profiling for such purposes.
Your choices & rights
Depending on where you live, you may have some or all of the following rights regarding your personal information:
- Know / access the personal information we hold about you.
- Correct inaccurate personal information.
- Delete your personal information.
- Opt out of the sale or sharing of personal information — note that we do not sell or share personal information for cross-context behavioral advertising.
- Limit the use of sensitive personal information.
- Non-discrimination for exercising these rights.
Account users: submit a request by emailing support@aevon.io. We will respond within the timeframe required by applicable law (for example, within 45 days for verifiable consumer requests under the CCPA, with an extension where permitted). We may need to verify your identity before acting.
A Client’s customers/callers: because the Client decides how that data is used, please direct requests to the Client. Aevon will support the Client in responding as required under our agreement and applicable law.
California & U.S. state privacy disclosures
For residents of California and other U.S. states with comprehensive privacy laws, the personal information we collect maps to the following statutory categories:
- Identifiers — business and contact name, login email, and account identifiers.
- Commercial information — plan, billing status, and transaction records (via Stripe).
- Internet or other electronic network activity — login/session activity and admin audit logs.
We collect this information from the sources, and use it for the business purposes, described above, and disclose it only to the subprocessors and in the circumstances listed in Subprocessors and Data sharing & disclosures. We do not sell or share personal information and do not use sensitive personal information for purposes that would require a right to limit.
Cookies
The Portal uses only a small login cookie that is strictly necessary to keep you signed in. We use no outside analytics or advertising cookies and do not track you across other websites.
Children
The Service is for businesses and is not directed to children. Where a Client’s callers may include minors, the Client remains responsible for any notices or consents required under COPPA or applicable state law.
Changes
We may update this policy; material changes will be posted here with a new effective date, and we will email account administrators.
Versioning & annual review. Aevon maintains this document under version control and reviews it at least once a year, updating it as needed; any material change takes effect and is communicated in accordance with the change, amendment, and notice provisions set out in this document.
Contact
Aevon LLC · support@aevon.io