Privacy Policy · Last updated 2 September 2026

Privacy Policy

This policy explains what Vanthos collects when you use vanthos.com and our products and systems, what we do with it, and the choices you have.

1. Who we are

The data controller is Vanthos (ABN 51 694 368 931), an Australian private company serving customers globally. For anything in this policy, contact [email protected].

2. What we collect

  • Account information. Your name, email address and profile picture from the account you sign in with, and the business details you enter when setting up a workspace.
  • Content you bring into the products. Mail, calendar events, files, call recordings, transcripts, bookings and instructions that you connect, upload or create so that our products can work on them.
  • Usage and device information. Log data such as IP address, browser, pages viewed and actions taken, used for security, reliability and support.
  • Communications. Messages you send to us, including support requests.

3. Connected accounts and services

Our products work inside the systems you already use. When you connect an account, such as email, calendar, file storage, a phone line or a booking channel, you choose what we may reach, and we access only what is needed to carry out the tasks and workflows you have set up.

We act on your instructions and nothing else. We do not go through connected accounts for our own purposes, we do not use what is in them to build profiles or to market to you, and we do not pass their contents to anyone beyond the service providers described below. You can disconnect an account at any time, which ends our access to it immediately.

We do not use your content, or anything we access in a connected account, to train or improve general or foundation AI models. We do not sell it and we do not use it for advertising. Our people do not read it except with your agreement, for security, or where the law requires it.

4. Call recordings

Our products record calls when you turn recording on. Recordings are transcribed, summarised and may be used in the workflows you have set up. Recordings, transcripts and summaries are stored for your workspace and are not shared outside it except with the service providers that host and process them.

You are responsible for telling the other parties on a call that it is being recorded and for having a lawful basis to record, which differs by jurisdiction. In Australia there is no single recording statute and the rules vary by state; in the European Union the GDPR and the ePrivacy rules apply. Our products provide recording notices to help, and our Terms set out your obligations.

5. How we use information

  • To provide, operate and support the products you use.
  • To carry out the instructions and workflows you set up.
  • To keep the products secure and to prevent abuse.
  • To communicate with you about your account and about service changes.
  • To meet our legal obligations.

We do not sell personal information and we do not use it for third-party advertising.

6. Who we share information with

  • Service providers who host our infrastructure, deliver email, provide telephony, and run the AI models that produce summaries and drafts. Each is bound by contract to process data only on our instructions.
  • The services you connect, in order to carry out the actions you request in them.
  • Authorities, where we are required by law or where necessary to protect our rights or the safety of others.
  • A successor, if we are involved in a merger, acquisition or sale of assets, subject to this policy.

7. Where data is stored and how long we keep it

We store customer data on servers in Australia and the European Union.

How long we keep data depends on what it is and why we hold it. We keep each type for as long as it is needed to provide the Services to you and to meet our legal obligations, and no longer.

When you disconnect an account we stop accessing it immediately, and you can also withdraw access from within that provider's own security settings. When you delete your workspace we delete the data associated with it, except where we must keep it to comply with law. You can ask us to delete your data at any time by writing to [email protected].

8. Security

We protect data with encryption in transit and at rest, access controls that limit who at Vanthos can reach production systems, and logging of administrative access. No system is perfectly secure; if we become aware of a breach affecting your data we will notify you as required by law.

9. Your rights

You can ask us to access, correct or delete the personal information we hold about you, and you can object to or restrict certain processing. If you are in the European Union or United Kingdom you also have the right to data portability and to lodge a complaint with your local supervisory authority.

Customers who need a data processing agreement for GDPR purposes can request one at [email protected].

10. Complaints

If you have a concern about how we handle your information, contact us first at [email protected] and we will respond within 30 days. If you are not satisfied, you can complain to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au, or to your local data protection authority if you are in the EU or UK.

11. Changes to this policy

We will post any changes on this page and update the date at the top. If a change materially affects how we use your data, we will tell you before it takes effect.

This policy is linked from our homepage.