gavelLegal

Privacy policy

How EzyBiz Lex collects, uses, stores and shares personal information, where it is stored, how long it is kept, and how to access, correct or delete it.

This policy explains how Avocado Pty Ltd (ACN 652 199 687, "Avocado", "we") handles personal information in connection with EzyBiz and EzyBiz Lex (the "Service"): the mobile app, the business phone line, the answering service, and the integrations with practice management systems. We are bound by the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).

Because the Service answers calls on behalf of a law firm, two kinds of people are covered: subscribers, the firms and staff who use the app, and callers, the people who ring or text a subscriber's number. Both are covered by this policy.

1. What we collect

From subscribers

  • Account information: name, email address and the identifier from the Google or Microsoft account used to sign in; the personal mobile number used to receive transferred calls, verified by SMS code.
  • Firm configuration: the firm's name, practice areas, hours, locations, booking rules and the instructions given to the answering service.
  • Subscription information: the plan and its status, from the App Store or Google Play via RevenueCat. We do not receive card numbers.
  • Integration credentials: when a firm connects Smokeball, Clio or SharePoint, the access tokens needed to read contacts and matters and to write records. Tokens are stored encrypted and are readable only by our server-side functions.
  • Device and usage information: device type, operating system, app version, push notification tokens, crash and error reports, and usage analytics.

From callers and message senders

  • Call details: the calling number, the number called, the time and duration, and the outcome (answered, transferred, booked, message taken).
  • Transcripts and summaries: what was said on the call, transcribed, and a written summary. Every caller is told at the start of the call that it is being transcribed.
  • Call audio: audio is processed to produce the transcript. Where audio is retained for that purpose it is deleted within 90 days of the call. The app does not offer audio playback.
  • Messages: SMS sent to and from the business number.
  • Contact details: the caller's name, number, and other details they give, such as the matter they are calling about or the time they would like a call back; and contact records synced from the firm's practice management system.

2. Why we collect it

We use personal information to provide the Service: to answer and route calls, take messages, make bookings, send and receive SMS, produce summaries and transcripts, file records to the firm's practice management system or SharePoint library, show caller identity and matter information to the firm, notify the firm of activity, bill subscriptions, provide support, and keep the Service secure and working. We also use aggregated, de-identified data to understand how the Service is used and to improve it.

We do not sell personal information and we do not use call content to advertise to anyone.

3. The answering service and legal matters

The answering service does not give legal advice and does not confirm whether any person is a client of the firm. Nothing about a matter is disclosed to a caller unless the firm has turned on verified matter conversations and the caller has proven possession of the mobile number on the firm's contact record by entering a one-time code. Any such disclosure is recorded on the call and noted in the filed record.

4. Who we share it with

We share personal information with service providers who help us run the Service, under contracts that restrict their use of it to providing the service to us:

  • Google Firebase: authentication, database, server-side functions, push notifications and crash reporting.
  • Twilio: phone numbers, call connection, SMS delivery and one-time verification codes.
  • Retell AI: the voice technology that powers the answering service. It receives the firm's configuration and the audio of calls the service handles in order to hold the conversation and produce the transcript.
  • RevenueCat: subscription status, linked to the App Store or Google Play.
  • Sentry: error reports, which may include technical identifiers.
  • The firm's practice management system or Microsoft 365 tenant: Smokeball, Clio or SharePoint, when the firm has connected it. Records written there are governed by the firm's own agreement with that provider.

We may also disclose personal information where the law requires it, or to protect the rights and safety of users and the public.

5. Where it is stored

Summaries, transcripts, messages and contact records are stored in Australian data centres. Some of our providers, in particular the voice technology and telephony providers, process data during a call in other countries, including the United States. Where that happens we take reasonable steps under APP 8 to ensure the recipient handles the information in accordance with the APPs. Our data residency page sets this out in more detail.

6. How long we keep it

  • Account data: for as long as the account is active, then deleted within 30 days of account deletion.
  • Call audio: deleted within 90 days of the call.
  • Transcripts, summaries and messages: kept for one year from the date of the call or message, or until the account is deleted, whichever comes first. Records the firm has filed to its own practice management system or SharePoint library remain there under the firm's control.
  • Aggregated analytics: de-identified and kept indefinitely.

7. Security

Data is encrypted in transit and at rest. Access to production systems is limited to the people who need it and protected by multi-factor authentication. Integration tokens are stored so that only server-side functions can read them. We review our dependencies for known vulnerabilities and apply patches promptly. No system is perfectly secure, and if a breach is likely to cause serious harm we will notify affected people and the Office of the Australian Information Commissioner as the Notifiable Data Breaches scheme requires.

8. Your rights

You can ask us for access to the personal information we hold about you, ask us to correct it, ask us to delete it, ask for an export of your data, or withdraw consent to processing that depends on consent (which may mean you can no longer use the Service). Subscribers can delete their account from the app. Callers who want to know what a firm holds about them should contact the firm, which controls the records filed to its own systems; we will help the firm respond.

To make a request, email hello@avocadodigital.com.au. We respond within 30 days. If you are not satisfied with our response you can complain to the Office of the Australian Information Commissioner at oaic.gov.au.

9. Children

The Service is for businesses and is not directed at people under 18.

10. Changes

We will post changes to this policy on this page and update the date at the top. Material changes will be notified in the app.

11. Contact

Avocado Pty Ltd, Melbourne, Australia. Email hello@avocadodigital.com.au.