Booking Assistant

Legal

Privacy Policy

Last updated: 10 August 2026

This policy explains what personal data Booking Assistant processes, why, how it is stored, who it is shared with, and how you can access or remove it. It covers our voice-AI platform at voice.lenacall.ch and, in particular, the calendar booking integration that connects a business’s Google or Microsoft calendar to its AI voice agent, the mailbox integration that lets a business’s AI assistant read and answer the email sent to its own Gmail or Outlook mailbox, and the regulatory identity documents some countries require before a phone number can be activated (Section 7).

1. Who we are

Booking Assistant (“Booking Assistant”, “we”, “us”) is a white-label voice-AI reception platform hosted at voice.lenacall.ch, operated by LenaCall. For the calendar data described below, LenaCall acts as a data processor on behalf of the connected business (the “customer”), which is the controller of its own calendar. You can reach us at your LenaCall contact.

2A. The calendar integration — what we access and why

When a business connects its calendar, its AI voice agent can check real availability and manage appointment events during phone calls, so callers can be booked, rescheduled, or cancelled without a human picking up. To do this we request only the narrowest calendar scopes each provider offers, plus a basic sign-in scope so your dashboard can show which account is connected.

The calendar integration and the mailbox integration described in Section 2B are entirely separate. They use different applications, are connected separately, and are revoked separately: connecting a calendar gives us no access to your email or mailbox contents, and connecting a mailbox gives us no access to your calendar. Neither gives us access to your contacts, your files, or any other data.

Google Calendar

Microsoft Outlook / Microsoft 365

2B. The mailbox integration — what we access and why

A business can connect its own mailbox so that its AI assistant answers the email its clients send it — the same job the assistant does on the phone, in writing. This is a separate, optional integration, connected from Integrations → Messaging channels, and it uses a different application from the calendar integration above. A business that never connects a mailbox is never asked for any mail permission.

What happens, precisely. When a new message arrives in the connected mailbox’s inbox, the provider notifies us that something changed. We then fetch that message only — its headers and its body — remove the quoted history and signature beneath it, and pass the remaining text to the AI assistant, which composes a reply and sends it from the same mailbox, in the same conversation thread.

Gmail

Microsoft Outlook mail

What we store from your mail

Google API Services — Limited Use. Booking Assistant’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. This applies to all Google user data we receive — Google Calendar data and Gmail message content alike. We do not use it for advertising, we do not sell it, we do not transfer it to others except as needed to provide or improve this feature, to comply with law, or as part of a merger or acquisition, and we do not allow humans to read it except as needed for support with your explicit consent, to comply with law, or for security. Google user data is never used to develop, improve, or train generalized or foundational AI/ML models.

3. How calendar tokens are stored and protected

4. Sharing, AI processing, and subprocessors

We do not sell your data and we do not use it for advertising. For the calendar integration, calendar data flows only between you, the connected business, the calendar provider you chose, and the AI model that runs the voice agent:

AI and your data. The AI that conducts the call runs on Google Cloud Vertex AI, and Google is the only AI provider that ever receives Google Workspace data — calendar or Gmail message content — or Microsoft calendar or mailbox data. We do not send any of it to any other AI or machine-learning service. We use one further AI subprocessor for a single, narrower purpose — ElevenLabs transcribes the audio of a call after that call has ended, and receives nothing else; it is described in its own section below. Under the Vertex AI terms, Google does not use your prompts, calendar data, mail content, or the model’s outputs to train or improve its foundation models. Our use of data received from Google APIs, including any use by AI features, adheres to the Google API Services User Data Policy and its Limited Use requirements, and is never used to develop, improve, or train generalized or foundational AI/ML models.

Beyond the providers listed above we use no additional third-party subprocessors for calendar data. We may disclose data if legally required, or to protect the security and integrity of the service.

Telnyx — telephony and regulatory number registration

Telnyx is the telephony carrier behind the platform’s phone numbers. It is a subprocessor for two separate purposes:

We do not give Telnyx access to your calendar or to the tokens that connect it, and the documents described in Section 7 are not sent to any AI model.

ElevenLabs — transcription of call recordings

Where a business has call recording switched on, the recording is transcribed after the call ends so that the business has an accurate written record of what was said. That transcription is performed by ElevenLabs, using their speech-to-text service.

If you would prefer that call audio is not sent for transcription, call recording can be switched off for your business, and no recording is made or transcribed. Ask the provider who set your service up, or contact us at your LenaCall contact.

5. Retention

A calendar or mailbox connection and its encrypted refresh token are kept only while the connection is active. When you disconnect, or when a connection is revoked or its business account is closed, the stored refresh token is deleted or permanently invalidated. Booking events that were already written to your calendar remain on your calendar and are managed by you there.

Mail conversations. The message text and the assistant’s reply are kept as a conversation thread in the business’s dashboard, under that business’s own retention settings, for the same period as its other conversation records. Disconnecting the mailbox stops any further mail being read or sent; the mail itself stays in your mailbox throughout and is never removed or altered by us.

Regulatory identity documents. There is no retention period for the documents on our side because we do not keep them (Section 7). What we keep is the reference to each filing, for as long as the phone number it supports is in service — it is the only record of which regulatory filing backs which number. The documents themselves are retained by Telnyx as part of the regulatory record for that number: that retention is the carrier’s, tied to the record and to the rules of the country’s regulator, and is not a period we set or can state on the carrier’s behalf. Deletion at the carrier can be requested — see Section 7.

6. How to revoke access

You can disconnect at any time. Disconnecting inside Booking Assistant immediately stops our use of your calendar or mailbox and permanently invalidates the token we hold. This does not by itself revoke the access you granted on Google’s or Microsoft’s side, so for full revocation you should also remove Booking Assistant’s access in that provider’s own account settings.

⚠️ The calendar and the mailbox are separate grants on separate applications, so revoking one leaves the other in place. If you want both withdrawn, disconnect both — and at the provider, remove both entries.

7. Other data we process

To run the platform we also process account and sign-in data (such as your email address and authentication codes), and operational records of calls handled by the voice agents (for example call metadata, transcripts, and appointment details captured during a call) on behalf of the business you interact with. This data is used to provide and secure the service, not for advertising, and is isolated per tenant.

Regulatory identity documents for phone numbers

Telecoms regulators in many countries will not let a phone number be activated until the carrier holds evidence of who is going to use it. Where the country of the number requires it, the business buying the number — or the person authorised to act for it — is asked for some combination of:

The list is set by each country’s regulator, and only what that list names is asked for. An identity document can carry more information than the check itself needs — a facial image, for example, which may be treated as a special category of personal data under Article 9 GDPR. It is transmitted for the sole purpose of the carrier’s and the regulator’s identity check. We do not read, extract, index or analyse its contents beyond confirming that the file really is the kind of document it claims to be, and it is never sent to any AI model.

We transmit these documents; we do not store them. An uploaded file passes through our server only to be forwarded to Telnyx in the same request. We do not keep it: it is not written to our database, our object storage or our backups, no copy remains once the transfer completes, and our platform offers no way for anyone — including our own staff and support — to view or download it afterwards. What we keep is a reference to it: the carrier’s document identifier, a SHA-256 checksum of the file, its type and size, the verification status the carrier reports, and the file’s name so we can show you which document you sent. Telnyx is the system of record for the documents and for the identity details filed alongside them; our database holds identifiers, not documents.

A filing is made on the Telnyx account of the provider that set your service up, so that provider can see it in their own carrier account. Telnyx is headquartered in the United States, so personal data in a regulatory filing may be processed outside the EEA. Email your LenaCall contact if you would like details of the safeguards that apply to that transfer.

Deleting a filing. To have a filing removed, contact us at your LenaCall contact or ask the provider who set your service up. We instruct the carrier to delete the regulatory record and then the documents filed under it, and we delete our own references to them. Deletion may not be possible while the filing is still supporting a phone number in service, or where the carrier is required to keep the regulatory record; in those cases we will tell you which applies rather than report a deletion that did not happen.

8. Data location and security

Data is stored on infrastructure operated for the platform, protected with encryption in transit, encryption of sensitive secrets at rest, and role-based, per-tenant access controls. We restrict access to the minimum staff needed to operate and support the service.

Regulatory identity documents are protected by not being kept. They are uploaded over an encrypted connection and forwarded to the carrier within the same request, so the only lasting record on our side is the reference described in Section 7. In addition, an upload is capped at 10 MB and limited to a short list of document formats (PDF, PNG, JPEG, DOCX, XLSX), each checked against the file’s actual contents rather than the type it claims to be; and the credentials used to reach the carrier are decrypted at a single server-side point that first verifies the requesting account is entitled to them.

9. Your rights

Subject to applicable law (including the EU/Lithuanian GDPR), you may request access to, correction of, or deletion of your personal data, and you may object to or restrict certain processing. For calendar data, the fastest route is to disconnect (Section 6). For documents filed with the telephony carrier, use the deletion route in Section 7. For anything else, contact your LenaCall contact. You also have the right to lodge a complaint with your local data protection authority.

10. Changes to this policy

We may update this policy as the product evolves. Material changes will be reflected here with a new “last updated” date.

11. Contact

Questions about this policy or your data? Email your LenaCall contact.