Privacy policy
Last updated: · Aligned with the Australian Privacy Act 1988 and the Australian Privacy Principles (APPs). Plain-English summary; the signed Data Processing Agreement (DPA) controls the legal relationship with each client.
Plain-English summary
Yappa is an AI voice agent. We handle two kinds of personal information:
- Lead data — phone numbers, names, and campaign metadata that client businessesupload so Yappa can call those leads on the client's behalf. The client is the data controller; Yappa is a data processor.
- Site-visitor data — names, emails, phone numbers entered into the demo-call form on yappa.com.au, and the IP / user-agent of every request. Yappa is the controller for this data.
We don't sell either. We store it in Australia (Sydney region) wherever possible, encrypted at rest, and only use it for the purpose it was collected for.
1. What we collect, and why
From client businesses (your data, your customers' data):
- Business identity — legal name, ABN/ACN, trading name, website, address, primary contact name/email/phone.
- Operational config — tier, billing details, dedicated phone number, transfer destination, calling-hours preferences, DNC handling preference.
- Lead lists — phone numbers (E.164), names, emails, AU-state, lead source, custom CRM fields. Provided by the client either via CSV upload, the /v1/leads webhook with a workspace API token, or an OAuth integration (HubSpot / Salesforce / GoHighLevel).
- Call artefacts — recordings, transcripts, outcome labels, cost components. Generated by Yappa from the call itself.
From site visitors (you):
- Demo-call form submissions — name, email, mobile, chosen umbrella / industry / service.
- Server logs — IP address, user-agent, requested path, timestamp. Retained for 30 days for spam triage and operational debugging.
- Authentication cookies (operator sign-in only) — a single session token, HttpOnly, Secure, sliding 2-hour expiry. No analytics cookies as of this writing.
2. How we use it
- Lead data: only to place outbound calls on the client's behalf, qualify the lead per the agreed script, transfer the warm ones, and report outcomes back to the client.
- Call artefacts: only to surface to the client in their dashboard and to improve the script via weekly tuning, both within the client's own workspace. Transcripts of one client are never used to train models or scripts for another client.
- Site-visitor data: only to follow up about the demo the visitor requested and to maintain the quality + security of the site.
- We do not sell, rent, or trade personal information.
3. Who we share with
Yappa relies on a small, vetted set of third-party sub-processors. Each is bound by contract to keep the data confidential and to use it solely to provide their service to us.
4. International transfers
Some of our sub-processors process call data in the United States. By using Yappa, you and your client acknowledge that lead phone numbers and call transcripts cross the US border for the duration of the call and for the configured retention period.
We hold sub-processors to standards equivalent to the Australian Privacy Principles via their published privacy terms and our service contracts with them.
5. SMS communications
Yappa sends SMS messages on behalf of client businesses in four scenarios: follow-ups when a call goes unanswered, booking confirmations after an AI-qualified call, STOP-acknowledgements when a recipient opts out, and (when the client has approved them) bulk re-engagement campaigns to existing lead lists.
Consent. Every SMS recipient has given express consent to be contacted by the client business — via the client's own web form (with a logged opt-in timestamp), a voice confirmation on a prior call, or an existing customer relationship in which SMS contact was agreed. Yappa does not send unsolicited SMS, and we do not on-sell or rent phone numbers.
Opting out. Reply STOP at any time to any SMS Yappa sends. Opt-outs are immediate, irrevocable, and propagate to Yappa's federal Do Not Call mirror so the same number won't be called or texted again by any Yappa client. Reply HELP for contact information. Standard message and data rates from your carrier may apply to inbound replies.
Sender ID. Outbound SMS is sent either from a registered Australian Alpha sender (the client business's name, max 11 chars — e.g. YAPPA, STRONK, HEALTHHV) or from Yappa's long-code +61 485 021 100 while a client's Alpha sender is pending carrier registration. Each client's current sender is shown on their dashboard.
Compliance. All Yappa SMS conforms to the Spam Act 2003 (Cth), the Do Not Call Register Act 2006 (Cth), and the ACMA Industry Code C661:2021. Branded (Alpha) sender IDs are registered with our messaging carrier and ratified by the Australian mobile carriers before any branded send goes out.
6. Google Calendar integration (Google user data)
Yappa offers an optional integration that lets a client connect their Google Calendar so that appointments and lead call-backs booked during a Yappa call are written straight into their calendar.
- What we access. When a client chooses to connect Google Calendar, we request a single Google permission — Google Calendar events (
https://www.googleapis.com/auth/calendar.events). We use it to create and update appointment and call-back events on the calendar the client authorises, and to read event times to offer available slots. We do not request or access Gmail, contacts, Drive, or any other Google data. - How we use it.This access is used solely to add and manage the client’s own appointment and call-back events. We do not use Google user data for advertising, and we do not use it to develop, improve, or train generalised AI or machine-learning models, nor do we allow any third party to do so.
- How we store it.We store the OAuth tokens Google issues in encrypted form, only so the connection can keep syncing events. Events are written to the client’s own Google Calendar; we do not retain a separate copy of the client’s wider calendar.
- Sharing. We do not sell Google user data. We share it only with the infrastructure sub-processors needed to run the integration, or where required by law.
- Revoking access.A client can disconnect Google Calendar at any time from Yappa’s Integrations page, or revoke Yappa’s access at myaccount.google.com/permissions. On disconnection we delete the stored tokens.
Yappa’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
7. Storage + security
- Production database hosted in Sydney, Australia.
- Phone numbers, full names, and emails on lead records are encrypted at rest, application-side, with a master key Yappa holds outside the database. A separate HMAC enables lookups without ever decrypting (used by the DNC gate). The database never sees plaintext PII for these fields.
- Operator authentication via HttpOnly Secure cookies with 2-hour inactivity expiry; the backend additionally enforces row-level security per workspace.
- Call recordings are stored with a signed-URL model — the dashboard fetches them through short-lived URLs that expire.
- Every read against a workspace's data is logged in the internal-audit table for the configured retention window.
8. Retention
- Lead records: retained for the life of the workspace plus 30 days after offboarding.
- Call recordings + transcripts: default 90 days, configurable per workspace up to 7 years (max under Telecommunications (Interception and Access) Act 1979 record-keeping conventions).
- SMS message content + delivery status: default 90 days, configurable per workspace up to 7 years. Opt-out (STOP) records are retained indefinitely — required to prove honour of an opt-out.
- Compliance audit logs: 7 years (regulator audit window).
- Demo-form submissions: 12 months unless converted to a client account.
- Server access logs: 30 days.
9. Your rights under the Privacy Act
You can request, at any time, that we:
- Confirm what personal information about you we hold;
- Provide a copy of it;
- Correct it if inaccurate or incomplete;
- Delete it (subject to legal retention obligations);
- Stop processing it for purposes beyond the original collection purpose.
Email hello@yappa.com.au with the subject line "Privacy request". We respond within 30 days.
If you're a lead who was called by Yappa on a client's behalf — the data controller for your record is the client business, not Yappa. We'll forward your request to them and assist with fulfilment.
To complain about how we've handled your personal information, contact us first. If unresolved, escalate to the Office of the Australian Information Commissioner.
10. Cookies + tracking
Yappa runs lean. The only first-party cookies the site currently sets are:
yappa_passcode— landing-site preview gate (30-day expiry).yappa_admin_session— operator dashboard session (sliding 2-hour expiry).yappa_business_session— per-tenant client dashboard session, HMAC-signed and pinned to a single workspace (sliding 2-hour expiry).ws-slug— the active workspace short-name for cross-page routing. Cleared at sign-out.
No third-party analytics or advertising cookies are set on public surfaces as of the date of this policy. If we add them, this policy will be updated and a banner will appear.
11. Children
Yappa is a B2B service. We don't knowingly collect information from anyone under 16. If you believe we have, contact us and we'll delete it.
12. Changes
Material changes — anything that meaningfully shifts how we collect, use, or share data — are notified to clients by email at least 30 days before they take effect.
13. Contact
Lead Bridge Group Pty Ltd (trading as Yappa) · Melbourne, Australia · hello@yappa.com.au · +61 412 393 557
