Vistura Voice← Back to home

Privacy Policy

Vistura Voice · ABN 80 306 936 503

Last updated 9 October 2026

Draft for review. This policy has not been reviewed by an Australian privacy lawyer. Provider processing locations, recording settings and retention arrangements should be confirmed before final approval.

1. Who we are and what this policy covers

Vistura Voice (ABN 80 306 936 503) is based in Brisbane, Queensland and provides AI voice reception and automation services to Australian businesses. This policy covers our website, demonstrations, consultations, client accounts, onboarding, billing and the information we process when providing our services.

When we handle calls for a client business, we process caller information to provide that business’s agreed service. The business also has its own privacy obligations and privacy policy. Contact the business you called for questions about its use of your information, or contact us for questions about our handling of it.

We aim to handle personal information consistently with the Australian Privacy Principles. This policy does not represent a certification or a determination that every provision of the Privacy Act 1988 (Cth) applies to our business. Applicable legal obligations depend on the circumstances.

2. Information we collect

We may collect your name, email address, telephone number, business name, industry, service area, operating hours, website and correspondence. Account and setup information can include your call-routing numbers, greeting preferences, services, approved pricing guidance, calendar or CRM details, and notification preferences. Your setup questionnaire saves answers as you enter them so you can return later.

Accelerator applications collect your name, company, work email, mobile number, industry, estimated inbound call volume and the phone bottleneck you describe. We use these details to assess your requirements and follow up about the sprint. Application records are accessible only to authorised administration, not to other visitors.

For consultations and client services, we may collect appointment details, caller contact information, call times and duration, transfer outcomes, messages, transcripts, summaries and recordings where enabled. Information you choose to tell an AI agent may be included in those records. Call information may contain health or other sensitive information, depending on the business and what the caller shares.

For billing and referrals we keep payment status, subscription and transaction references, contact details and referral attribution. Stripe collects payment card details directly through its payment form; we do not receive or store your full card number or security code.

Website and service providers may collect technical information such as IP address, browser and device information, request logs and error information to operate and protect the service.

3. How we collect information

We collect information when you contact us, create an account, complete or update your setup questionnaire, book a consultation, make a payment or talk to a voice agent. We also receive information from the business whose calls we handle and from connected payment, voice, telephony, calendar, CRM and notification services when needed to deliver the agreed workflow.

You can browse public pages without creating an account and may contact us without identifying yourself where practical. We need sufficient details to provide an account, arrange a booking, process a payment or follow up an enquiry; without them we may be unable to provide that service.

4. Why we use information

We use information to respond to enquiries, configure and maintain agents, answer and route calls, arrange appointments, send confirmations and service alerts, manage accounts and subscriptions, administer referrals, resolve problems, protect against misuse and meet legal obligations. We may review relevant call records to investigate errors and improve an agreed call flow.

We do not sell personal information. We do not use this policy as blanket consent to collect unnecessary sensitive information or to use caller information for unrelated marketing. If we send promotional messages, you can ask us to stop using the contact details below or the unsubscribe option in the message. Essential account and service notices may still be sent.

5. AI conversations and sensitive information

Our voice agents use AI and are not people. Your microphone audio is sent to the voice provider when you start a browser conversation and grant microphone permission. Depending on the agent configuration, audio, transcripts and summaries may be retained by the provider. Ending a conversation stops the live session; it does not automatically delete existing records.

Avoid sharing passwords, API keys, payment card details, identity documents or information unrelated to the enquiry in demonstrations or setup answers. Sensitive information should only be collected when necessary for the agreed service and with consent or another lawful basis where required. Client businesses must arrange appropriate caller notices and any required recording consent before enabling their call service.

An AI agent is not a substitute for clinical, legal or emergency advice. For immediate danger in Australia, call 000. Contact us if you have shared sensitive information by mistake or want to discuss a non-AI way to contact the business.

6. Who may receive information

Information may be available to authorised Vistura Voice personnel, the client business whose calls we handle, and providers needed to deliver the service. These include Stripe for payments, ElevenLabs for voice processing, and providers of hosting, account authentication, data storage, email delivery and telephony. Calendar, CRM and SMS services receive relevant information only where those workflows are connected. Not every integration is active for every client.

We may also disclose information to professional advisers or authorities where required or permitted by law, or where reasonably necessary to respond to fraud, a security incident or a serious threat. We seek to limit disclosures to the information needed for the purpose.

Facebook and WhatsApp links take you to services governed by their own privacy policies. They do not give those services access to your client portal merely because you follow a link.

7. Overseas processing

Some providers operate internationally, so information may be stored, processed or accessed outside Australia, including in the United States. Actual locations depend on provider arrangements and the integrations used. We have not verified a complete country list for every provider and subprocessor; Australian-only storage is not promised.

Contact us before supplying information if location restrictions apply to your business. We can discuss the providers and locations relevant to your proposed setup. Where Australian privacy law applies, we must take the steps required for overseas disclosures; using our service does not waive your privacy rights.

8. Security and access

The live website uses HTTPS to encrypt information in transit. Client accounts require sign-in, and access rules restrict customer records to the relevant account and authorised administration. Stripe’s payment form handles card details separately from our voice agents and questionnaire.

These protections reduce risk but do not make any system completely secure. Keep your account password private and tell us promptly about suspected unauthorised access. Where a breach triggers a legal notification obligation, we will follow the applicable requirements, including the Notifiable Data Breaches scheme where it applies.

9. Storage, retention and deletion

Information is held in our hosted systems and relevant provider systems. There is no single confirmed retention period across all account, call, payment and provider records, and an automatic deletion schedule has not been established for all records. Cancelling a subscription or ending a call does not automatically erase those records.

Contact us to request deletion or ask about a particular record’s retention. We will assess the request, including provider-held copies, legal recordkeeping requirements and any continuing need to resolve a dispute. Where required by applicable law, we take reasonable steps to destroy or de-identify information no longer needed. Backups and legally required records may not be immediately removable; we will explain relevant limitations.

10. Cookies and browser storage

The site uses browser storage to maintain sign-in sessions, remember referral attribution and return you to the appropriate page after sign-in. Embedded payment and voice services may also use cookies or similar technology under their own policies. You can control cookies and site storage through your browser, but clearing or blocking them may affect sign-in, payments or referrals.

11. Access, corrections and complaints

You can review and update setup answers in your client portal. For access to other personal information, corrections, deletion requests or a privacy complaint, contact Kris Jenkins at kris@visturavoice.com.au or call 0447 446 289. Please describe your request without sending passwords or full card details. We may need to confirm your identity before releasing or changing information.

We will assess your request and respond within a reasonable period. If we cannot provide access or make a requested change, we will explain why and the available next steps, subject to legal restrictions. For records handled on behalf of a client business, we may need to coordinate with or direct the request to that business.

If you are dissatisfied with our response, you may contact the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au or on 1300 363 992. The OAIC can explain whether it can consider your complaint.

12. Updates to this policy

We may update this policy when our services, provider arrangements or legal requirements change. The current version and its update date will appear on this page. Material changes will be communicated where appropriate or legally required.