Mylos

Privacy Policy

Effective date: July 9, 2026  ·  Last updated: July 13, 2026

This Privacy Policy explains how Mylos, the business name under which Kiarash Zamani, a sole proprietor in Vancouver, British Columbia, carries on business (“we”, “us”, or “our”), collects, uses, discloses, stores, and protects personal information in connection with the Mylos AI receptionist service (the “Service”). Mylos provides an AI-powered virtual receptionist that answers calls on behalf of service businesses, checks calendar availability, books appointments, and sends text-message confirmations.

We are committed to handling personal information in accordance with Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA), British Columbia’s Personal Information Protection Act (BC PIPA), and, in respect of electronic messages, Canada’s Anti-Spam Legislation (CASL). Where we access data from Google APIs, our use additionally complies with the Google API Services User Data Policy, including the Limited Use requirements (see Section 4).

Contents

  1. Who this policy covers
  2. Information we collect
  3. How we use information
  4. Google user data & Calendar access
  5. Text messaging & CASL consent
  6. Consent & legal basis
  7. How we share information
  8. Service providers & sub-processors
  9. Storage, security & location
  10. Data retention
  11. Your privacy rights
  12. Children’s privacy
  13. Changes to this policy
  14. How to contact us

1. Who this policy covers

The Service involves two distinct groups of individuals, and this policy addresses both:

For personal information about End Customers, the Business Client is the party that determines the purposes for which that information is used; Mylos processes it on the Business Client’s behalf in order to provide the Service. Mylos does not use End Customer personal information for its own independent marketing purposes.

This allocation of responsibility is set out in a binding agreement, not merely in this policy. Every Business Client accepts our Terms of Service and the Data Processing Agreement at Schedule A, under which the Business Client warrants that it has the lawful basis required to collect and use its customers’ personal information, and Mylos undertakes to process that information only on the Business Client’s instructions, to protect it, and to delete it on request.

2. Information we collect

2.1 Information from Business Clients

2.2 Information about End Customers

When Mylos answers a call on a Business Client’s behalf (whether or not the call results in a booking), it may collect and process:

Enquiries and leads. Some Business Clients use Mylos to take enquiries rather than to book appointments, and some callers are not ready to commit to a time. In those cases Mylos records the caller’s name, telephone number, and the service they asked about, with no appointment date or time, and passes those details to the Business Client so that the business can follow up. Where a Business Client has enabled lead alerts, those details are also sent to the business by text message at the time of the call.

2.3 Information collected automatically

We do not collect payment card details directly; where subscription billing is offered, it is handled by a third-party payment processor under its own terms.

2.4 Website founding-spot (waitlist) form

Ahead of launch, our website offers a form for businesses that want to reserve a founding spot. If you submit it, we collect the business name, email address, and business type you provide, together with a non-identifying tag recording which link or campaign brought you to the form. We use this information for one purpose only: to contact you about the Mylos launch, early access, and founding-business offers, as described next to the form when you sign up. You can unsubscribe at any time by replying to any such email or writing to info@getmylos.com. Submissions are received and stored by Netlify, our website hosting provider (see Section 8), and are deleted on request or once launch outreach concludes.

3. How we use information

We use personal information only for the following purposes:

We do not sell personal information. We do not use End Customer personal information, or data obtained through Google APIs, to serve advertising or to train generalized or standalone artificial-intelligence models.

4. Google user data & Calendar access

Calendar booking is an optional feature. Where a Business Client uses Mylos only to capture enquiries, no Google account is connected and none of the data described in this section is accessed.

Where a Business Client does enable calendar booking, it gives explicit authorization through Google’s OAuth consent flow, and Mylos connects to that Business Client’s Google account in order to manage appointments. This section describes exactly what Google user data we access and why.

Google data / scope Why Mylos accesses it
https://www.googleapis.com/auth/calendar.freebusy To read the busy/free periods on the Business Client’s calendar, so that Mylos offers callers only appointment times the business is actually free. This scope returns busy time ranges only, not the titles, guests, or contents of the events behind them.
https://www.googleapis.com/auth/calendar.events To create the calendar event that represents a booking made through the Service, and to read back, update, or delete that event when an appointment is confirmed, rescheduled, or cancelled.

4.1 Limited Use

Mylos’s use and transfer to any other application of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:

4.2 Revoking Google access

A Business Client may disconnect Mylos from their Google account at any time, either through the Service or directly at Google Account → Security → Third-party access. Revoking access stops further calendar reads and writes; appointments already recorded on the calendar remain under the Business Client’s control.

5. Text messaging & CASL consent

Mylos sends transactional text messages (such as appointment confirmations and reminders) to End Customers on a Business Client’s behalf. In accordance with CASL:

Message and data rates may apply to recipients depending on their mobile carrier and plan.

Under PIPEDA and BC PIPA, we collect, use, and disclose personal information with consent, except where an exception permitted or required by law applies. Business Clients provide consent when they subscribe to and configure the Service and when they authorize connected accounts. For End Customers, consent to process booking information and to receive transactional messages arises from their interaction with the Business Client through the Service. An individual may withdraw consent subject to legal or contractual restrictions and reasonable notice; withdrawing consent may limit our ability to provide the Service.

7. How we share information

We share personal information only as follows:

We do not sell personal information, and we do not disclose it for third-party advertising.

8. Service providers & sub-processors

We rely on the following categories of sub-processors to operate the Service. Each processes only the data necessary for its function:

Provider Function Data involved
Google (Google Calendar API) Availability checks and appointment calendar events Business Client calendar data; appointment details
Twilio Sending and receiving text messages End Customer phone number; message content and delivery status
Retell AI Telephony and speech-to-text for the AI receptionist Call audio, call transcript, and information spoken during the call
OpenAI (via Retell AI) Generates the AI receptionist's spoken responses during a call Call transcript / conversation content, processed to generate a response
Retell AI's speech sub-processors Voice synthesis (text-to-speech) and speech recognition (speech-to-text) during the call. Retell's platform voice uses automatic multi-provider fallback rather than a single fixed vendor; the current providers are published at Retell's own sub-processor list, trust.retellai.com/subprocessors, which we cite here rather than duplicate so this stays accurate as it changes. Call audio, processed to synthesize and transcribe speech
Supabase (PostgreSQL database hosting, ca-central-1, Montréal, Canada) Application data storage All stored Service data
Sentry Error monitoring, reliability, and debugging Technical logs and error diagnostics (personal information is not intentionally captured)
Netlify (United States) Website hosting and receipt of website form submissions Founding-spot form submissions: business name, email address, business type, and campaign source tag (Section 2.4)
GoatCounter Privacy-focused website analytics Aggregate page-view statistics; no cookies and no stored personal information (Section 2.3)

9. Storage, security & location

Location of data storage: personal information is stored on servers located in Canada (our database is hosted by Supabase in the ca-central-1 region, Montréal, Québec). Certain sub-processors listed in Section 8 (including Google, Twilio, and our voice provider) may process limited data (such as calendar events, message content, or call audio) on infrastructure outside Canada in order to deliver their services. Where personal information is processed outside Canada, it may be subject to the laws of the jurisdiction in which it is stored or processed, including lawful access requests by courts, law enforcement, and other authorities in that jurisdiction.

10. Data retention

We retain personal information only for as long as necessary to fulfil the purposes described in this policy, to provide the Service to the relevant Business Client, and to meet legal, accounting, or reporting obligations. Appointment and booking records are retained for the Business Client’s operational needs; opt-out records are retained as long as necessary to honour the opt-out. When information is no longer required, we delete or de-identify it using reasonable measures.

11. Your privacy rights

Subject to applicable law, individuals have the right to:

We will respond to an access or correction request within thirty days, as PIPEDA requires. Where we are able to delete personal information without compromising a legal, accounting, or record-keeping obligation, we will do so on request; some records (notably opt-out records) must be kept in order to honour the very request that created them.

Google user data specifically: when a Business Client disconnects their Google account or terminates the Service, we delete the stored Google authorization token and any cached Google Calendar data within thirty days. Calendar events already written to the Business Client’s own calendar remain under their control (see Section 4.2).

End Customers: because we process your information on behalf of the business you contacted, please direct access, correction, or deletion requests to that business. If you contact us directly, we will refer your request to the relevant Business Client and assist as their service provider.

Business Clients may exercise these rights, or request deletion of their account data, by contacting us as described in Section 14. We will respond within the time required by applicable law. You may also make a complaint to the Office of the Privacy Commissioner of Canada or the Office of the Information and Privacy Commissioner for British Columbia.

12. Children’s privacy

The Service is intended for use by businesses and their adult customers. It is not directed to children, and we do not knowingly collect personal information from children. If you believe a child’s information has been provided to us, please contact us so we can take appropriate action.

13. Changes to this policy

We may update this Privacy Policy from time to time. When we make material changes, we will revise the “Last updated” date above and, where appropriate, provide additional notice to Business Clients. Your continued use of the Service after an update constitutes acceptance of the revised policy.

14. How to contact us

For questions, requests, or complaints regarding this Privacy Policy or your personal information, contact our Privacy Officer: