DRAFT — pending legal review. These documents are not final and are not yet in effect. Questions: privacy@torklio.com
Privacy Policy
==============

SOURCE: Torklio Interim Legal Package v1.0 (owner-prepared interim draft, 2026-09-03). DRAFT - attorney review required; bracketed [FIELDS] must be completed and every statement verified against production before any effective date is set. Loaded into the legal center 2026-09-03.

Privacy Policy

How Torklio collects, uses, discloses, and retains information

PUBLICATION CONTROL  Effective date: [PUBLICATION DATE]. Replace all red bracketed fields and verify the text against production before publication. Internal status: attorney review required.



1. Scope

This Privacy Policy explains how Torklio LLC ("Torklio," "we," "us," or "our") handles personal information through torklio.com, Torklio accounts and dashboards, AI-assisted calls, web chat and booking experiences, customer communications, integrations, and support (collectively, the "Service").

This Policy applies both to business customers and their authorized users and to people who interact with a business using Torklio. When a business uses Torklio to communicate with its customers, that business generally decides why and how the information is used, and Torklio processes it on the business's behalf. Questions about a business's practices should also be directed to that business.

2. Information we collect

2.1 Account and business information

We may collect names, business names, job titles, email addresses, phone numbers, login and authentication information, account roles, industry and eligibility information, service settings, support communications, billing metadata, and transaction records. Payment-card details are processed by our payment provider; Torklio is not intended to receive or store full card numbers or security codes.

2.2 Call, chat, and customer-interaction information

Depending on the business's configuration and the interaction, we may process caller ID, names, contact details, call audio, recordings, transcriptions, chat and SMS content, uploaded files or images, customer requests, service interests, appointment details, consent and opt-out records, AI-generated summaries, lead or customer status, routing events, transfers, outcomes, and staff notes.

Calls should begin with notice that the caller is interacting with an AI assistant. When recording or transcription is enabled, the business and Torklio are responsible for deploying the configured notice and consent flow. A caller may request a person or decline recording as described in the interaction.

2.3 Calendar and integration information

When a user connects Google Calendar, Microsoft Calendar, or another integration, we may receive account identifiers, authorization tokens, calendar names, event details, availability information, attendee information, and data needed to create, update, find, or cancel appointments. We request access intended to support the features the user enables.

Torklio's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We do not sell Google user data, use it for advertising, or use it to determine creditworthiness.

2.4 Device, website, and operational information

We may collect IP address, browser and device information, timestamps, page and feature activity, authentication events, cookie or session identifiers, error reports, system logs, security events, usage measurements, call metadata, provider delivery status, and diagnostic information.

2.5 Sources

We collect information from business customers and their users, people who call or message a customer, connected calendars and services, communications and payment providers, websites and devices, and information generated through use of the Service.

3. How we use information

We use information to:

provide AI-assisted answering, chat, scheduling, CRM, routing, transfer, messaging, and support features;

authenticate users, administer accounts, process subscriptions, and provide customer support;

connect calendars and other user-authorized services;

generate transcripts, summaries, classifications, and suggested actions for the applicable business;

record and enforce consent, communication preferences, suppression, and eligibility restrictions;

secure, monitor, debug, test, maintain, and improve reliability of the Service;

detect misuse, fraud, security incidents, and violations of our policies;

comply with legal obligations and enforce agreements; and

create aggregated or deidentified information that does not reasonably identify a person.

AI model use

Torklio does not itself use Customer Content to train a general-purpose AI model unless the Customer expressly authorizes that use after a specific disclosure. We send information to AI and speech providers only as needed to deliver configured features, security, or support. [PENDING - verify each AI provider's API data-use terms and configuration before publication]

4. How we disclose information

We may disclose information:

to the business on whose behalf Torklio handled the call, message, appointment, or customer record;

to authorized users and integrations selected by that business;

to providers that perform telecommunications, AI, speech, email, calendar, payment, cloud-hosting, backup, security, analytics, or support functions;

when required by law, legal process, or a valid governmental request;

to protect rights, safety, property, users, the Service, or the public;

in connection with a merger, financing, acquisition, reorganization, bankruptcy, or sale of assets, subject to appropriate protections; and

with direction or consent from the applicable customer or individual.

We do not sell personal information. We do not share personal information for cross-context behavioral advertising. We do not sell or share mobile opt-in information with third parties or affiliates for their own marketing or promotional purposes. Providers may receive information only to perform services for Torklio or the applicable business, subject to applicable restrictions.

5. Sensitive information and prohibited submissions

Torklio is not intended for protected health information or healthcare use. Do not provide medical information, Social Security numbers, complete payment-card numbers, card security codes, passwords, bank-account credentials, authentication secrets, or other information prohibited by the Acceptable Use Policy. If sensitive information is provided contrary to instructions, we may restrict processing, redact it where feasible, notify the business, or delete it consistent with legal and operational requirements.

6. Recording and transcription

Call recording and transcription laws vary. Businesses using Torklio are responsible for determining which notices and consents apply to their calls. Torklio provides standardized disclosure and consent controls and may require their use. Where a caller refuses recording, the configured system should not store a recording or transcript and may offer a human or alternative contact path. Businesses must not disable or evade legally required disclosures.

7. Retention

We retain information for the period reasonably necessary to provide the Service, maintain business and security records, comply with law, resolve disputes, enforce agreements, and follow the applicable customer's configuration and instructions. Retention depends on the information type, customer settings, account status, legal obligations, backup cycles, security needs, and whether the information remains necessary for the purpose collected.

Current enforced schedule: call recordings 90 days per tenant; OTP codes minutes; auth tokens up to 7 days; export files 1 hour; consent and acceptance logs retained as compliance evidence; local backups 30 days with offsite copies on rotation. [PENDING - enforce transcript age-out and audit-log rotation; see the Data Retention Schedule] When information is no longer required, we delete or deidentify it according to the applicable process, subject to legal holds and limited backup retention.

8. Security

We use administrative, technical, and organizational safeguards designed to protect information, including authentication and access controls, tenant separation, encrypted network transport where supported, logging, monitoring, backups, testing, and incident-response procedures. No system is completely secure, and we cannot guarantee that unauthorized access, loss, or misuse will never occur. Do not rely on this Policy as a representation that Torklio holds a particular certification or encrypts every category of stored data.

9. Choices and rights

Depending on location and relationship, a person may have rights to request access, correction, deletion, portability, restriction, or information about processing, and to appeal certain decisions. To submit a request, contact privacy@torklio.com. We may need to verify identity and authority. When Torklio processes information for a business customer, we may direct the request to that business and assist it as required by contract or law.

Users may disconnect calendar integrations through account settings or the provider's account controls. Disconnecting stops new access but does not automatically delete previously created appointments or records that must be retained for another lawful reason. Marketing email recipients may use the unsubscribe method in the message. SMS recipients may reply STOP to supported programs.

10. Cookies and similar technologies

Torklio may use essential cookies or similar storage to maintain sessions, authenticate users, preserve security, remember settings, and operate the Service. As of 2026-09-03 Torklio deploys only essential session, authentication, and security cookies; no analytics or advertising trackers are in use on torklio.com or the product. Torklio should not deploy cross-site advertising tracking unless this Policy and any required consent interface are updated first.

11. Children

The Service is intended for businesses and adults and is not directed to children under 13. Customers may not configure Torklio as a child-directed service or use it to collect personal information from children in violation of applicable law. If we learn that prohibited children's information was collected, we may delete it and suspend the relevant use.

12. Geographic scope

The Service is currently intended for use by eligible businesses in the United States. Customer must obtain written approval before deploying the Service for another country or region. Information may be processed where Torklio and its providers operate, subject to applicable contractual and legal safeguards.

13. Changes to this Policy

We may update this Policy. The revised version will state a new effective date. We will provide additional notice or request consent when a change materially affects how we use information and applicable law requires it.

14. Contact

Privacy requests: privacy@torklio.com. Legal notices: Torklio LLC, 701 South Street, Suite 100, Mountain Home, AR 72653, legal@torklio.com. Support: support@torklio.com.

← Legal Center