After Hours Virtual Receptionist
Call Amelia 24/7: (832) 979-5957

Security & Compliance

Your calls are your customers. Here is exactly how we protect them, including the honest parts most vendors bury.

Encryption

Calls, recordings, transcripts, and customer data are encrypted in transit (TLS) and at rest. Payment details are handled entirely by Stripe; we never see or store card numbers.

Access controls

Each business sees only its own calls, bookings, and settings, enforced at the database level with row-level security. Dashboard logins use emailed one-time links, so there are no passwords to steal. Administrative access is limited to the operating team.

What the AI collects

Only what each business configures: typically name, phone, email, address, and the reason for the call. The AI is instructed never to collect payment card numbers, Social Security numbers, or passwords, and to decline them if offered.

Recordings and transcripts

Every call is recorded and transcribed so the business can review and correct its receptionist. Recordings are available in the business's dashboard and retained while the account is active or as law requires. Businesses are responsible for following their state's call-recording notice requirements; we help configure a disclosure line where needed.

Data deletion

Businesses can request deletion of their account data, and callers can request deletion of their personal information, by emailing info@afterhoursvirtualreceptionist.com. We verify and honor requests consistent with applicable law.

Subprocessors

We build on established providers: voice AI and telephony infrastructure, SMS delivery, cloud hosting and database, Stripe for payments, and transactional email. Each processes data only to deliver the service.

Texting compliance

Texts are sent to people who contacted the business, identify the sender, and honor STOP and HELP automatically. Sending runs through carrier-registered business messaging (A2P 10DLC). Details are in our SMS terms.

HIPAA, stated honestly

We do not currently claim HIPAA compliance and do not yet offer business associate agreements. Practices that handle protected health information by phone should review HHS guidance on business associates before routing patient calls through any vendor, including us. When we offer a BAA, this page will say so plainly.

Incidents

If a security incident affects your data, we will notify you promptly with what happened, what was affected, and what we are doing about it, consistent with applicable breach-notification laws.

Questions about any of this? Email info@afterhoursvirtualreceptionist.com and a person will answer. Also see our privacy policy.