Legal
Privacy Policy
Last updated: August 27, 2026
This Privacy Policy, referred to in this document as the "Policy," explains how Vampo, operator of ReceptionEase and referred to in this document as "we," "us," or "our," collects, uses, stores, and protects information through the ReceptionEase website, AI-powered platform, and related support services, together referred to in this document as the "Service." The business using the Service is referred to in this document as "you," "Client," or, in the Data Processing Addendum, the "Controller."
This Privacy Policy, together with the Terms of Service and the Data Processing Addendum, are together referred to in this document as the "Legal Terms." Your acceptance of the Legal Terms supersedes any prior agreements or understandings between you and us regarding the Service.
Section 6 stands apart from the rest of this Policy. It explains how we contact businesses that are not yet customers, which happens before any use of the Service and forms no part of it.
By using the Service, you agree to the collection and use of information as described in this policy.
1. Who We Are
ReceptionEase is an AI-powered receptionist platform that answers business phone calls 24/7, books clients, manages contacts, and provides businesses with a real-time dashboard of their communications.
Company information: Vampo Rruga Ibrahim Rugova, Building No. 28, Entrance 9, Ap. 7 Tiranë, Albania 1019 Email: contact@receptionease.com
2. Information We Collect
2.1 Account & Business Information
When you register, we collect information including, but not limited to:
- Business name, phone number, address, and description
- User email address and password (retained in encrypted form only; at no point is your password kept or transmitted in a readable format)
- Team member names and email addresses
- Notification phone number: the mobile number you give us for text alerts, and a record of your consent
2.2 Call Data
Our AI telephony system processes and stores information including, but not limited to, the following for every call handled on your behalf:
- Caller phone number and identity (where provided by the caller or matched to existing contacts)
- Call date, time, and duration
- AI-generated call summary: a brief description of the call's purpose
- Intent, sentiment, and urgency classification: automatically assessed by the AI
- Call outcome: including, but not limited to, booking made, message taken, or call transferred
- Call transcript: a full text transcription of the conversation
- Call recording: an audio recording of the conversation
2.3 Contact Information
We store contact records for your callers, which may include, but are not limited to:
- Full name
- Phone number
- Email address
- Any notes added by your team
2.4 Appointment & Calendar Data
We store appointment details including, but not limited to:
- Contact name and phone number
- Appointment date, time, duration, and service type
- When Google Calendar is connected: events in the dedicated calendar the Service creates in your Google account, as described in Section 7
2.5 Usage & Technical Data
We may automatically collect information including, but not limited to:
- IP address and browser/device type when you sign up and when you accept our Legal Terms, which we record as evidence of that acceptance
- Secure session cookies that keep you signed in to your dashboard. We do not use tracking, advertising, or analytics cookies.
- Server logs for security and debugging purposes
3. How We Use Your Information
We use the information we collect for purposes including, but not limited to:
- Provide and operate the Service: answer calls, book clients, manage contacts, display your dashboard, and use the mobile number you give us to send you meeting links and reminders for meetings you have consented to
- Sync with Google Calendar: create, update, and delete events in the calendar the Service creates in your Google account when the integration is enabled, as described in Section 7
- Send service communications: account alerts, billing notices, and support responses
- Alert you to confirmed dispatches: notify you by SMS and MMS text message when a visit is confirmed for dispatch, as described in Section 5
- Follow up on calls and requests: use the mobile number you give us to send follow-up messages that are independent of any account notification, including, but not limited to, a follow-up to a call you took part in, a meeting link or a reminder for a meeting you consented to, a solicited link or demo for a product you asked for or agreed to receive on the call, or an answer to a question you asked us, as described in Section 5
- Ensure security: detect fraud, unauthorized access, and abuse
- Comply with legal obligations: retain records as required by applicable law
We do not use your call transcripts or any call data to train AI models. Your data is used solely to provide the Service to you.
3.1 Our Legal Bases for Processing
Where the law requires us to identify a legal basis for each purpose, including under the data protection law of the Republic of Albania, we rely on the following:
| What we do | Why we are permitted to do it |
|---|---|
| Answer, record, transcribe, and summarise calls; book clients; maintain your contacts and dashboard | Necessary to deliver the Service you signed up for under the Legal Terms |
| Send you the text message alerts described in Section 5 | Necessary to deliver the Service you signed up for under the Legal Terms, because the alerts are the Service you have purchased rather than marketing. Separately, we ask your permission before we text your mobile, and you can take that permission back at any time without ending the Service |
| Keep the Service secure, and detect fraud, unauthorized access, and abuse | Our legitimate interest in operating the Service safely, balanced against your rights |
| Retain billing, tax, and consent records | Compliance with a legal obligation |
Withdrawing permission. You may withdraw your permission to be texted at any time, as set out in Section 5, and withdrawing it does not affect the lawfulness of anything we did beforehand. Doing so stops the text alerts; it does not close your account or stop the notices about billing and security we are obliged to send you.
4. Call Recordings, Transcripts, and AI Processing
Calls handled by ReceptionEase are answered by our AI system. Conversations are recorded, transcribed, and stored securely.
Disclosure to callers. At the outset of every call, before the caller reaches the receptionist, the Service informs the caller that the call is recorded and transcribed. This disclosure is delivered by the Service on every call and cannot be disabled, removed, or modified.
Legal effect of the disclosure. Call recording is governed by federal and state wiretapping and eavesdropping statutes, which operate independently of consumer privacy legislation and are not satisfied by compliance with it. Federal law permits a call to be recorded with the consent of a single party, whereas approximately twelve states require the consent of every party to the call. In those states, a caller who receives the disclosure at the outset of the call and elects to remain on the line is regarded as having consented to the recording. The disclosure is provided for that purpose.
Your remaining obligations. You remain responsible for any disclosure or consent required of you by your industry or jurisdiction in addition to the disclosure described above, and for giving effect to a caller's request not to be recorded. Where you are uncertain which requirements apply to your business, you should obtain your own legal advice.
Biometric data. The Service converts speech to text for the purpose of understanding and responding to the caller. It does not measure the physical characteristics of any individual's voice. We do not create, store, or use voiceprints, speaker embeddings, or any other biometric identifier, whether for the purpose of recognising a caller or of generating a synthetic voice. Retention of the audio recording itself is governed by Section 9.
Access. Recordings and transcripts are accessible only to authenticated users of your business account.
5. Notifications and Alerts We Send You
The Service exists so that you find out about a call you could not take. This section explains the messages we send you to do that.
What we send. We send you a notification when a visit request taken by the receptionist is confirmed for dispatch. We do not send you a notification for a call that has not reached that point. We send these by SMS and MMS text message to the mobile number you give us, once you have agreed to be texted. Alongside these account notifications, we send you follow-up messages arising from a call you took part in or from something you consented to. Those can include, but are not limited to, a follow-up to the call, a meeting link, a solicited link or demo for a product you asked for or agreed to receive on the call, or an answer to something you asked.
Follow-up messages. Separately from the account notifications above, we use the mobile number you give us to follow up on a call you took part in and on what you consented to. Those messages can include, but are not limited to, a follow-up to a call you took part in, a meeting link or a reminder for a meeting you consented to, a solicited link or demo for a product you asked for or agreed to receive on the call, or an answer to a question you asked us. You may stop them by the same means as the notifications above.
These are service messages, not unsolicited marketing. They are part of the Service you are paying for. We do not send unsolicited marketing text messages.
They arrive at any hour. Because a job confirmed late in the day is of no use to you the following afternoon, alerts are sent as soon as the visit is confirmed, including outside your business hours, at weekends, and on public holidays. You can stop them at any time by replying STOP to any message.
What the message contains. An alert carries only the minimal customer information you need to run the job: the customer's first name and last initial where the receptionist learned them, the number to reach them on, the confirmed time, and the job and service address the visit is for. The full record stays in your dashboard, behind your login.
Who handles the message on its way to you. SMS and MMS messages are delivered through a third-party messaging provider acting on our instructions, and then across your own mobile network. That provider may process the message content and your phone number only to deliver the message to you. Section 8 sets out how we govern all such providers.
We do not share your mobile number. We do not sell, rent, trade, or otherwise share mobile phone numbers, or the consent you give to receive text messages, with any third party or affiliate for their own marketing purposes. This applies to every number held in the Service. No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Information sharing with subcontractors for supporting services, such as our SMS provider, is permitted. All other use case categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties.
Message frequency and cost. Message frequency varies with your job volume, because you receive one message for each visit confirmed for dispatch. Message and data rates may apply depending on your mobile phone service plan.
How to stop them. You may stop text message alerts at any time, by any reasonable means. Replying STOP to any message will do it, and so will writing to contact@receptionease.com or telling us by any other means. We do not require you to use one particular method, and we act on a request within ten business days of receiving it and normally far sooner. Reply HELP to any message for help. Stopping text alerts does not close your account or stop the email notices we must send you about billing and security.
Who the messages come from. Text messages are sent by Vampo, operator of ReceptionEase, whose full contact details appear in Section 15. We do not conceal the sender's identity, and every message gives you a free way to ask us to stop.
Numbers you add for other people. If you add a phone number belonging to a member of your staff or anyone else, you are responsible for having their agreement before you add it, and for removing it when they no longer want to be contacted.
Messages sent before you were a customer. This Section covers the messages we send you as a Client. Where we spoke to you before you had an account and you agreed on that call to receive text messages, those messages are described separately in Section 6, and the permission you gave then is separate from the permission recorded for your account.
6. Calls and Messages Before You Become a Customer
This section is not about the Service. It describes how we contact businesses that are not yet customers, and how someone who is not yet a customer asks us to contact them, and it is set out here so that the practice is written down in the Legal Terms rather than left to be inferred. Nothing in this section forms part of the Service, forms part of what a Client pays for, or changes anything in Section 5. If you are already a Client, Section 5 governs the messages we send you about your account.
Why we call. We call businesses to introduce ReceptionEase and to establish whether an AI receptionist would be of use to them. No account, subscription, or prior relationship is needed for us to call, and none is created by your taking the call.
The two ways we come to have your permission. Before you are a customer, there are exactly two: you ask us for a demo on our website and tick the boxes on that form, or you agree on a call that we may continue by text. Both are described below. We act on no other route to your number.
If you ask us for a demo on our website. Some of our web pages carry a form that asks for your name and your mobile number so that we can book a product demonstration with you. Beneath the two fields are two separate, unticked boxes: one giving us permission to call you at that number to arrange and run the demo, and one, which is optional and which you do not have to tick to book anything, giving us permission to text you about it. Neither box is ticked for you, and neither is ticked by our submitting the form on your behalf. If you tick the text box, we send you your booking confirmation, the meeting link, a reminder, and replies to anything you ask us. Message frequency varies, and is typically 2 to 5 messages for each demo you book. Message and data rates may apply depending on your mobile phone service plan. You can reply STOP at any time to stop the messages, or HELP for help. If you leave the text box unticked, we call you instead and send you nothing by text. Agreeing to be texted is never a condition of purchase and never a condition of getting the demo. We store the exact wording that was displayed to you, your number, the date and time, the IP address the form was submitted from, and your browser's user agent, and we keep that record as described below.
Continuing the conversation by text. If we speak by phone and you agree on that call to keep the conversation going by text, we may send you SMS or MMS messages about that call and about what you agreed to receive on it. Those messages can include, but are not limited to, a follow-up to the call, a meeting link, a link or demo for a product we discussed, or an answer to something you asked us.
What we tell you before we take that agreement. Before we take your agreement on a call, we tell you who we are, what we will send, roughly how often it will arrive, that message and data rates may apply, and that you can reply STOP at any time to stop the messages. Agreeing to receive text messages is never a condition of buying anything from us, and we say so on the call. Whatever else it contains, the first message you receive always identifies us and tells you how to stop the messages.
The only consent we act on is yours. We text only people who have given us that permission. However we came by your number, the only consent we act on is the consent you give us yourself: verbally on a call, or by accepting the consent terms published for the campaign you are responding to, which include your agreement to this Policy. Those terms govern where they apply. This section supplements them on points they do not cover and does not override them.
Our legal basis. We call businesses on the basis of our legitimate interest in offering the Service to businesses that may have use for it, balanced against your rights. We send the text messages described in this section on the basis of the permission you give us, and withdrawing that permission does not affect the lawfulness of anything we did beforehand.
We keep a record of your permission. We keep a dated record of when and how your permission was given, whether you gave it on a call or by ticking the box on a form. We retain that record for as long as we may text you, and for four years afterwards, which is the period in which a claim about a message we sent could still be brought. We can produce it to our messaging provider or to your mobile carrier on request. The record is kept only for that purpose and is never used to contact you.
Mobile numbers are never shared. No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Information sharing with subcontractors for supporting services, such as our SMS provider, is permitted. All other use case categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties. Mobile numbers, and the consent you give to be texted, are not sold, rented, or shared with any third party or affiliate for marketing or promotional purposes, and no part of that information is shared with anyone for those purposes. We use your number only for the purposes described in this section and in the terms you agreed to when you gave your consent, and for no other purpose. The only parties that handle your number are the messaging provider that transmits our messages for us and your own mobile carrier, and neither may use it for its own marketing.
Message frequency and cost. Message frequency varies with the conversation and with how often you reply. Typically that is 1 to 10 messages per conversation. Message and data rates may apply depending on your mobile phone service plan.
How to stop them. You can stop the messages at any time, by any reasonable means. Replying STOP to any message will do it, and so will writing to contact@receptionease.com or telling us on a call. We do not require you to use one particular method, and we act on a request within ten business days of receiving it and normally far sooner. Reply HELP to any message for help. You may ask us not to call you again by those same means, and we will honour that. After you opt out, we keep your number only so that we can keep honouring the opt-out.
If you go on to become a Client. Permission given on a call does not carry across to your account. The consent that governs the notifications described in Section 5 is asked for separately when you activate your account, and is recorded separately.
7. Google User Data
This section explains how the Service accesses, uses, stores, and shares data from your Google account. It applies in addition to the rest of this Policy.
Signing in with Google. If you create or access your account using Google, we receive the email address and the first and last name held on your Google account. We use this only to create your account, identify you when you sign in, and contact you about the Service.
Connecting Google Calendar. Connecting Google Calendar is optional and is not required to use the Service. When you connect it, you grant the following permissions:
| Permission requested | How we use it |
|---|---|
| See, create, change, and delete only the calendars this application creates | Create one dedicated calendar in your Google account, and add, update, and delete appointment events inside that calendar only |
| See your primary Google account email address | Display which Google account is connected on your dashboard |
We create a new calendar in your Google account. The first time you connect, the Service creates a separate calendar named "ReceptionEase" in your Google account, and every appointment booked through the Service is written to that calendar. We request the narrowest permission Google makes available for this purpose. The Service therefore cannot see, change, or delete your personal calendar or any other calendar in your account. It can access only the calendar it created.
What we store. We store the access and refresh tokens issued by Google, the identifier of the calendar we created, and the email address of the connected account. Appointment details are also stored in our own database so that your dashboard remains accurate if the connection is later removed.
Limits on our use of Google user data. We do not sell Google user data, use it for advertising, or use it to develop, improve, or train generalized artificial intelligence or machine learning models. No person reads your Google user data except where you have given specific consent, where it is necessary for security purposes or to resolve a support issue you have raised with us, or where the law requires it.
Disconnecting and deletion. You may disconnect Google Calendar at any time from the Calendar tab of your dashboard. When you disconnect, we delete the "ReceptionEase" calendar we created together with the appointment events inside it, and we permanently delete the stored Google tokens and the connected account's email address. You may also withdraw our access directly through your Google account permissions page.
Compliance. ReceptionEase's use and transfer of information received from Google APIs to any other application will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
8. Data Sharing and Third Parties
We do not sell your data, and we do not share it for advertising.
We share data only with third-party service providers, referred to as sub-processors, who help us operate the Service, and only to the extent necessary for them to perform that role on our behalf. The categories of sub-processor we use are:
| Category | What they do for us |
|---|---|
| Cloud hosting and infrastructure | Run the servers and database that hold your account data |
| Telephony and voice processing | Carry the phone calls the receptionist answers, and convert speech to text |
| Messaging delivery | Deliver the text message alerts described in Section 5 |
| Payment and subscription processing | Take your subscription payment and hold your billing record |
Our agreement with each sub-processor is formed by accepting that provider's own terms of service and, where offered, its standard data processing terms, which bind us and it from the moment we begin using that provider. Those terms limit the provider to the function described above. None of them is permitted to use your data for its own purposes, to use it for marketing, or to disclose it further, and all are required to handle it securely and in compliance with applicable privacy law. We remain responsible to you for how each of them handles your data.
We do not name the individual providers in this Policy. You may request their current identities by writing to contact@receptionease.com, following the process in Section 9 of the Data Processing Addendum.
We may also disclose data where we are required to do so by law, by a court, or by a competent authority, and we will tell you when that happens unless we are legally prohibited from doing so.
9. Data Retention
Audio call recordings are retained for up to 6 months from the date of the call, after which they are automatically and permanently deleted. This 6-month limit applies only to the audio recording, on a fixed schedule, regardless of your subscription status.
All other account data (including, but not limited to, contacts, call transcripts, call summaries, appointments, and business information) is retained for as long as your account exists. Cancelling your subscription alone does not delete this data.
When you delete your account, all data associated with your account, including, but not limited to, contacts, call transcripts, call summaries, appointments, and business information, is permanently deleted within 30 days of account deletion. (Audio recordings continue to follow the separate 6-month schedule above regardless of when you delete your account.)
Records we are obliged to keep. Deletion does not extend to the records the law requires us to retain: your billing and tax records, and the record of your consent to be texted described in Section 2.1. We keep the consent record for four years after your account closes, which is the period in which a claim about a message we sent could still be brought, and billing and tax records for as long as tax law requires. These records are kept only for those purposes, are never used to contact you, and are deleted once the period ends.
You may request deletion of specific data at any time (see Section 11).
Server logs are retained for up to 30 days for security and debugging purposes.
10. Data Security
We maintain security measures designed to protect your data, addressing areas including, but not limited to:
- Credential and password protection, so plaintext passwords are never stored or transmitted
- Secure session and account authentication
- Encrypted connections between your device and our servers
- Restricted, access-controlled storage for your data
- Access to production systems limited to authorized personnel only
No method of transmission over the internet or electronic storage is 100% secure. While we use commercially reasonable measures to protect your data, we cannot guarantee absolute security.
If there is a breach. If personal data we hold is lost, disclosed, or accessed without authorization, we will notify you without undue delay and in any event within 72 hours of becoming aware of it, and we will tell you what happened, what data was involved, what the likely consequences are, and what we are doing about it. Where the law requires the people affected or a supervisory authority to be told, we will make or support that notification within the deadline that applies. United States state breach notification laws generally require this within 30 to 45 days of discovery, and Albanian law requires it without undue delay.
11. Your Rights
You have rights including, but not limited to, the right to:
- Access: request a copy of the personal data we hold about you, and be told why we hold it, who we share it with, and how long we keep it
- Correction: request correction of inaccurate or incomplete data
- Deletion: request deletion of your personal data
- Restriction: ask us to pause our use of your data while a dispute about its accuracy or our use of it is resolved
- Objection: object to processing we carry out on the basis of our legitimate interests
- Portability: receive the data you gave us in a structured, commonly used, machine-readable format, and ask us to transmit it to another provider where that is technically feasible
- Withdraw consent: withdraw any consent you have given us, at any time, without affecting anything lawfully done before you withdrew it
- Opt-out: decline certain uses of your data, such as by replying STOP to any text alert, or by disconnecting Google Calendar at any time from your dashboard
- Human review: ask a person to review any decision about you that was made solely by automated means and that has a legal or similarly significant effect on you
- Non-discrimination: you will not be penalized, charged more, or given a lesser Service for exercising any of the rights above
To exercise any of these rights, contact us at contact@receptionease.com. We will respond within 30 days. We do not charge for this, and we will not ask you for more information than we need to confirm who you are.
If you are not satisfied. You may complain to us first at contact@receptionease.com, and we will investigate. You also have the right to complain directly to a supervisory authority. In Albania, that authority is the Information and Data Protection Commissioner (Komisioneri për të Drejtën e Informimit dhe Mbrojtjen e të Dhënave Personale), Rruga "Abdi Toptani", Nd. 5, Tiranë, Albania, www.idp.al. Complaining to us first is not a condition of complaining to them.
Callers and contacts. If you are a caller or a contact rather than a ReceptionEase customer, the business that answered your call decides what happens to your data and is the right party to ask. Write to us at contact@receptionease.com and we will pass your request to that business without delay and help them to answer it.
12. Children's Privacy
The Service is intended for use by businesses and is not directed to individuals under the age of 18. We do not knowingly collect personal information from children. If you believe a child has provided us personal information, please contact us and we will delete it.
13. International Data Transfers
We are established in the Republic of Albania. Our servers, and the sub-processors described in Section 8, are located in the United States, which is where your data and your callers' data are stored and processed. Operating the Service therefore involves transferring data between Albania and the United States.
We do not rely on your acceptance of this Policy alone to make that transfer lawful. Each transfer is covered by a safeguard permitted under Albanian data protection law, being either:
- the terms of service and, where offered, the standard data processing terms of each sub-processor that receives the data, which we accept by using that provider and which set out the data protection and security obligations it owes; or
- another transfer mechanism approved by the Information and Data Protection Commissioner of the Republic of Albania.
We apply technical measures to protect data in transit and in storage, including encryption and access controls. You may ask which safeguard applies to your data by writing to contact@receptionease.com.
14. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date at the top of this page and notify you when those changes take effect.
Your continued use of the Service after changes become effective constitutes acceptance of the updated policy.
15. Contact Us
For privacy-related questions, requests, or complaints:
Vampo Email: contact@receptionease.com Address: Rruga Ibrahim Rugova, Building No. 28, Entrance 9, Ap. 7, Tiranë, Albania 1019