This Privacy Policy explains how Mylos, the business name under which Kiarash Zamani, a sole proprietor in Vancouver, British Columbia, carries on business (“we”, “us”, or “our”), collects, uses, discloses, stores, and protects personal information in connection with the Mylos AI receptionist service (the “Service”). Mylos provides an AI-powered virtual receptionist that answers calls on behalf of service businesses, checks calendar availability, books appointments, and sends text-message confirmations.
We are committed to handling personal information in accordance with Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA), British Columbia’s Personal Information Protection Act (BC PIPA), and, in respect of electronic messages, Canada’s Anti-Spam Legislation (CASL). Where we access data from Google APIs, our use additionally complies with the Google API Services User Data Policy, including the Limited Use requirements (see Section 4).
The Service involves two distinct groups of individuals, and this policy addresses both:
For personal information about End Customers, the Business Client is the party that determines the purposes for which that information is used; Mylos processes it on the Business Client’s behalf in order to provide the Service. Mylos does not use End Customer personal information for its own independent marketing purposes.
This allocation of responsibility is set out in a binding agreement, not merely in this policy. Every Business Client accepts our Terms of Service and the Data Processing Agreement at Schedule A, under which the Business Client warrants that it has the lawful basis required to collect and use its customers’ personal information, and Mylos undertakes to process that information only on the Business Client’s instructions, to protect it, and to delete it on request.
When Mylos answers a call on a Business Client’s behalf (whether or not the call results in a booking), it may collect and process:
Enquiries and leads. Some Business Clients use Mylos to take enquiries rather than to book appointments, and some callers are not ready to commit to a time. In those cases Mylos records the caller’s name, telephone number, and the service they asked about, with no appointment date or time, and passes those details to the Business Client so that the business can follow up. Where a Business Client has enabled lead alerts, those details are also sent to the business by text message at the time of the call.
We do not collect payment card details directly; where subscription billing is offered, it is handled by a third-party payment processor under its own terms.
Ahead of launch, our website offers a form for businesses that want to reserve a founding spot. If you submit it, we collect the business name, email address, and business type you provide, together with a non-identifying tag recording which link or campaign brought you to the form. We use this information for one purpose only: to contact you about the Mylos launch, early access, and founding-business offers, as described next to the form when you sign up. You can unsubscribe at any time by replying to any such email or writing to info@getmylos.com. Submissions are received and stored by Netlify, our website hosting provider (see Section 8), and are deleted on request or once launch outreach concludes.
We use personal information only for the following purposes:
We do not sell personal information. We do not use End Customer personal information, or data obtained through Google APIs, to serve advertising or to train generalized or standalone artificial-intelligence models.
Calendar booking is an optional feature. Where a Business Client uses Mylos only to capture enquiries, no Google account is connected and none of the data described in this section is accessed.
Where a Business Client does enable calendar booking, it gives explicit authorization through Google’s OAuth consent flow, and Mylos connects to that Business Client’s Google account in order to manage appointments. This section describes exactly what Google user data we access and why.
| Google data / scope | Why Mylos accesses it |
|---|---|
https://www.googleapis.com/auth/calendar.freebusy |
To read the busy/free periods on the Business Client’s calendar, so that Mylos offers callers only appointment times the business is actually free. This scope returns busy time ranges only, not the titles, guests, or contents of the events behind them. |
https://www.googleapis.com/auth/calendar.events |
To create the calendar event that represents a booking made through the Service, and to read back, update, or delete that event when an appointment is confirmed, rescheduled, or cancelled. |
Mylos’s use and transfer to any other application of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
A Business Client may disconnect Mylos from their Google account at any time, either through the Service or directly at Google Account → Security → Third-party access. Revoking access stops further calendar reads and writes; appointments already recorded on the calendar remain under the Business Client’s control.
Mylos sends transactional text messages (such as appointment confirmations and reminders) to End Customers on a Business Client’s behalf. In accordance with CASL:
Message and data rates may apply to recipients depending on their mobile carrier and plan.
Under PIPEDA and BC PIPA, we collect, use, and disclose personal information with consent, except where an exception permitted or required by law applies. Business Clients provide consent when they subscribe to and configure the Service and when they authorize connected accounts. For End Customers, consent to process booking information and to receive transactional messages arises from their interaction with the Business Client through the Service. An individual may withdraw consent subject to legal or contractual restrictions and reasonable notice; withdrawing consent may limit our ability to provide the Service.
We share personal information only as follows:
We do not sell personal information, and we do not disclose it for third-party advertising.
We rely on the following categories of sub-processors to operate the Service. Each processes only the data necessary for its function:
| Provider | Function | Data involved |
|---|---|---|
| Google (Google Calendar API) | Availability checks and appointment calendar events | Business Client calendar data; appointment details |
| Twilio | Sending and receiving text messages | End Customer phone number; message content and delivery status |
| Retell AI | Telephony and speech-to-text for the AI receptionist | Call audio, call transcript, and information spoken during the call |
| OpenAI (via Retell AI) | Generates the AI receptionist's spoken responses during a call | Call transcript / conversation content, processed to generate a response |
| Retell AI's speech sub-processors | Voice synthesis (text-to-speech) and speech recognition (speech-to-text) during the call. Retell's platform voice uses automatic multi-provider fallback rather than a single fixed vendor; the current providers are published at Retell's own sub-processor list, trust.retellai.com/subprocessors, which we cite here rather than duplicate so this stays accurate as it changes. | Call audio, processed to synthesize and transcribe speech |
Supabase (PostgreSQL database hosting, ca-central-1, Montréal, Canada) |
Application data storage | All stored Service data |
| Sentry | Error monitoring, reliability, and debugging | Technical logs and error diagnostics (personal information is not intentionally captured) |
| Netlify (United States) | Website hosting and receipt of website form submissions | Founding-spot form submissions: business name, email address, business type, and campaign source tag (Section 2.4) |
| GoatCounter | Privacy-focused website analytics | Aggregate page-view statistics; no cookies and no stored personal information (Section 2.3) |
Location of data storage: personal information is stored on servers located in
Canada (our database is hosted by Supabase in the ca-central-1 region, Montréal,
Québec). Certain sub-processors listed
in Section 8 (including Google, Twilio, and our voice provider) may process limited data (such
as calendar events, message content, or call audio) on infrastructure outside Canada in order to
deliver their services. Where personal information is processed outside Canada, it may be subject
to the laws of the jurisdiction in which it is stored or processed, including lawful access
requests by courts, law enforcement, and other authorities in that jurisdiction.
We retain personal information only for as long as necessary to fulfil the purposes described in this policy, to provide the Service to the relevant Business Client, and to meet legal, accounting, or reporting obligations. Appointment and booking records are retained for the Business Client’s operational needs; opt-out records are retained as long as necessary to honour the opt-out. When information is no longer required, we delete or de-identify it using reasonable measures.
Subject to applicable law, individuals have the right to:
We will respond to an access or correction request within thirty days, as PIPEDA requires. Where we are able to delete personal information without compromising a legal, accounting, or record-keeping obligation, we will do so on request; some records (notably opt-out records) must be kept in order to honour the very request that created them.
Google user data specifically: when a Business Client disconnects their Google account or terminates the Service, we delete the stored Google authorization token and any cached Google Calendar data within thirty days. Calendar events already written to the Business Client’s own calendar remain under their control (see Section 4.2).
End Customers: because we process your information on behalf of the business you contacted, please direct access, correction, or deletion requests to that business. If you contact us directly, we will refer your request to the relevant Business Client and assist as their service provider.
Business Clients may exercise these rights, or request deletion of their account data, by contacting us as described in Section 14. We will respond within the time required by applicable law. You may also make a complaint to the Office of the Privacy Commissioner of Canada or the Office of the Information and Privacy Commissioner for British Columbia.
The Service is intended for use by businesses and their adult customers. It is not directed to children, and we do not knowingly collect personal information from children. If you believe a child’s information has been provided to us, please contact us so we can take appropriate action.
We may update this Privacy Policy from time to time. When we make material changes, we will revise the “Last updated” date above and, where appropriate, provide additional notice to Business Clients. Your continued use of the Service after an update constitutes acceptance of the revised policy.
For questions, requests, or complaints regarding this Privacy Policy or your personal information, contact our Privacy Officer: