No sale of personal data
We do not sell personal information or share it for cross-context behavioral advertising.
This policy explains how NevoDesk handles the account, customer, communication, scheduling, job, payment, and support data needed to operate an AI front desk. It also explains the choices available to businesses, workspace users, callers, and other individuals.
We do not sell personal information or share it for cross-context behavioral advertising.
Customer conversations and service records are not used to target advertising.
Service Data is not used to train shared foundation models unless the customer expressly opts in.
Workspace roles, location scope, retention settings, and audit history limit operational access.
This Privacy Policy applies to NevoDesk websites, applications, communications, support, and AI front-desk services (the “Services”). “Personal information” means information that identifies, relates to, describes, or can reasonably be linked with an individual or household.
NevoDesk acts as a controller or business for information about website visitors, account holders, prospects, and people who contact NevoDesk directly. We use that information for account administration, security, support, billing, and operation of our own business.
A business using NevoDesk generally controls the customer and conversation data processed in its workspace. For that data, NevoDesk acts as a processor or service provider and follows the business’s documented instructions. The business is responsible for its privacy notice, lawful basis, recording and messaging disclosures, and responses to its customers’ requests. NevoDesk assists as required by contract and applicable law.
Direct a privacy request to that business first. If you are unsure which business controls the data, email privacy@nevodesk.com with the phone number, email address, approximate interaction date, and business name. Do not send passwords or full payment-card details.
We collect information directly from businesses and users, from people who communicate with a NevoDesk-powered business, automatically from devices and service activity, and from integrations a business chooses to connect.
| Category | Examples | Primary source |
|---|---|---|
| Account and identity | Name, email, phone, login identifier, role, workspace, and authentication events. | You, your employer, or an invited workspace administrator. |
| Business configuration | Locations, hours, services, staff, calendars, pricing, policies, FAQs, scripts, routing rules, and authority limits. | Business users and connected systems. |
| Communications | Phone numbers, caller identity, recordings when enabled, transcripts, voicemail, messages, attachments, summaries, sentiment or intent signals, and routing results. | Callers, message participants, the business, and communications providers. |
| Operational records | Appointments, jobs, leads, orders, reservations, cases, service addresses, access notes, preferences, confirmations, and status history. | Customers, workspace users, AI-assisted intake, and integrations. |
| Commercial and payment | Plan, invoices, transaction amount, currency, payment status, refunds, disputes, connected-account identifiers, and fee records. | The business, NevoDesk, and payment providers. |
| Integration and device | Calendar availability, connection status, integration identifiers, IP address, browser/device data, cookies, logs, and diagnostics. | Your device and services you authorize. |
| AI-derived information | Conversation summaries, classifications, suggested actions, risk flags, and business-discovery recommendations. | Generated from information supplied to the Services. |
We may process sensitive information when a customer intentionally uses the Services for a workflow that requires it—for example health-related scheduling, precise service locations, payment status, or the contents of private communications. Customers should configure collection to the minimum necessary for the approved workflow.
We use personal information to:
Where applicable law requires a legal basis, we process information to perform a contract, follow customer instructions, comply with legal obligations, protect legitimate interests that do not override individual rights, or based on consent.
NevoDesk uses machine-learning and language-model systems to understand requests, transcribe and summarize communications, retrieve approved business information, recommend actions, and prepare structured records. Relevant Service Data may be sent to vetted model and infrastructure providers solely to provide these functions.
NevoDesk is an operational assistant, not a licensed clinician, lawyer, accountant, financial adviser, emergency dispatcher, or final decision-maker. High-impact questions must be routed to a qualified person designated by the business.
A NevoDesk-powered interaction may involve an AI voice, automated transcription, recording, messaging, or routing. Whether recording is enabled depends on the business’s configuration and applicable law.
When payment features are enabled, payment-card and bank-account details are collected directly by the payment provider, such as Stripe. NevoDesk receives identifiers, amounts, status, refunds, disputes, and related records needed to connect the payment to the business workflow. We do not intend to store complete card numbers or card security codes.
The connected business is the merchant of record for payments made by its customers and controls fulfillment, taxes, refund decisions, and dispute evidence. Payment-provider privacy terms also apply.
We disclose information only as reasonably necessary to:
NevoDesk does not sell personal information, share it for cross-context behavioral advertising, or use customer conversations to build advertising profiles. If that practice changes, we will update this policy and provide legally required choice before the change applies.
NevoDesk uses administrative, technical, and organizational safeguards designed for the sensitivity of the data and the nature of the Services. These include workspace separation, role and location access controls, authentication protections, encryption in transit and at rest where supported, audit events, secrets management, restricted administrative access, monitoring, backups, and incident-response procedures.
No system is completely secure. Customers must use strong authentication, limit user access, review permissions and connected systems, maintain accurate administrators, and notify security@nevodesk.com promptly of a suspected compromise. If a security incident affects personal information, NevoDesk will investigate, contain, remediate, and provide notices as required by contract and law.
We retain information only for as long as reasonably necessary for the purposes described in this policy, the customer’s configured or contracted retention period, legal and financial recordkeeping, security, dispute resolution, and enforcement. Different records have different retention needs.
Depending on where you live and our role, you may have rights to know or access personal information, correct it, delete it, receive a portable copy, restrict or object to processing, withdraw consent, limit use of sensitive information, or appeal a denied request. You will not be discriminated against for exercising a privacy right.
Email privacy@nevodesk.com. Describe your relationship to NevoDesk, the relevant business or workspace, and the right you want to exercise. We may verify identity and authority, and an authorized agent may be asked for proof of authorization. If NevoDesk processes the data only for a business customer, we may refer the request to that business or assist it in responding.
Because NevoDesk does not sell personal information or share it for cross-context behavioral advertising, there is no sale or advertising sharing to opt out of. We will honor applicable browser-based privacy signals if our practices later fall within a law that requires them.
NevoDesk and its providers may process information in the United States and other countries that may have different data-protection laws. Where required, we use contractual, organizational, and technical safeguards intended to support lawful transfers. Enterprise customers may request applicable data-processing and transfer terms.
The standard Services are not represented as HIPAA-compliant and this Privacy Policy is not a Business Associate Agreement. A covered entity or business associate must not submit protected health information unless NevoDesk has signed an applicable BAA and the workspace has been approved and configured for that use.
The same principle applies to other specially regulated information, including government identifiers, full payment credentials, biometric identifiers used for identification, children’s data, education records, and information subject to financial, legal, or professional secrecy duties. Contact legal@nevodesk.com before enabling such a workflow.
NevoDesk is a business service and is not directed to children under 13. We do not knowingly create accounts for children. A business serving minors is responsible for obtaining required parental or guardian authorization and must use only an approved configuration. Contact us if you believe a child’s information was collected improperly.
We may update this policy as the Services, providers, or law change. We will post the updated version, revise the effective date, and provide additional notice for material changes when required.
Privacy requests: privacy@nevodesk.com
Security reports: security@nevodesk.com
Legal and contractual questions: legal@nevodesk.com
General support: support@nevodesk.com
Contact us for a data processing agreement, regulated-workflow review, security information, or enterprise terms.
Contact NevoDesk