Data residency
Where EzyBiz Lex stores transcripts, messages and contacts, which providers process data during a call, how it is protected, and how the Privacy Act applies.
Law firms are asked where client information lives, and they need a straight answer. This page is the answer for EzyBiz Lex. The privacy policy covers the rest.
What is stored in Australia
Summaries, transcripts, messages, contact records, bookings and call details are stored in Australian data centres. The records the Service files to your own systems, a matter in Smokeball or Clio or a document in your SharePoint library, are held there under your own agreement with that provider and your own retention and access rules.
What is processed during a call
A live call passes through three providers. Twilio carries the call and delivers SMS on Australian numbers. Retell AI provides the voice technology for the answering service and processes the audio of the call in real time to hold the conversation and produce the transcript; that processing takes place on Retell's infrastructure, which includes the United States. Google Cloud runs our server-side functions that route calls, write the summary and file the record. Once the call ends, the transcript and summary are written to storage in Australia.
Where personal information is processed outside Australia we rely on APP 8 and take reasonable steps, including contractual terms, to ensure the recipient handles it in accordance with the Australian Privacy Principles.
Audio
Calls are transcribed, not kept as audio you replay. Audio is processed to produce the transcript, any audio retained for that purpose is deleted within 90 days, and the app does not offer playback. Every caller is told at the start of the call that it is being transcribed.
Retention
Transcripts, summaries and messages are kept for one year, or until the account is deleted, whichever comes first. Account data is deleted within 30 days of account deletion. Records filed to your practice management system or SharePoint library stay under your control and are not affected by deletion on our side.
Access controls
- Data is encrypted in transit (TLS 1.2 or later) and at rest (AES-256).
- Records are scoped to the firm. No subscriber can read another firm's calls, contacts or messages, and the rules that enforce that are applied by the database itself, not only by the app.
- Integration tokens for Smokeball, Clio and SharePoint are readable only by server-side functions, never by the app or by other users.
- Administrative access to production is limited to named people with multi-factor authentication, and is logged.
- The answering service discloses nothing about a matter to an unverified caller, including whether the matter exists. Verified matter conversations, if the firm turns them on, require a one-time code sent to the mobile on the firm's contact record and disclose only a narrow, fixed set of details, and every disclosure is recorded on the call.
Breaches
If a data breach is likely to result in serious harm we notify the affected firms and the Office of the Australian Information Commissioner in accordance with the Notifiable Data Breaches scheme, and we notify integration partners where their data is affected.
Certifications
Our cloud provider holds SOC 2 Type 2, ISO 27001, ISO 27017 and ISO 27018 certifications for the underlying infrastructure. Avocado does not currently hold its own certification, and we say so plainly. Firms that need a security questionnaire completed can ask and we will complete it.
Questions
Email hello@avocadodigital.com.au. If your firm needs a written statement for a client or an insurer, ask and we will provide one.