Legal
Privacy policy
Bludge makes phone calls to real people, so we take this seriously. This page says what we collect, what we do with it, who else touches it and how to get it back or have it deleted.
Who we are
Bludge is a service operated by ACN 168 669 038 Pty Ltd (formerly Slay Pty Ltd) (ABN 15 168 669 038), a company registered in Australia with its registered office at 70 Winton Road, Ashburton, Victoria 3147, Australia. In this policy, "we", "us" and "our" mean that company, and "Bludge" means the service.
We are the business you reach at privacy@bludge.ai. That address goes to a person, not a queue.
This policy covers our website at this domain, the Bludge admin that our customers log in to, and the phone calls and text messages the service places. It does not cover anyone else's website, even if we link to it.
The two roles we play
Privacy law asks who decides what happens to personal information. We answer that question twice, because we do two different things.
- Our own information: we decide
- Visitors to this website, people who ask for a demonstration call, and the staff of our customers who log in to the admin. Here we are the controller (in Australia, the "APP entity"): we decide what to collect and why, and the rest of this policy tells you.
- Our customers' leads: they decide
- The people our customers ask us to call. A customer loads or connects its own enquiries, writes the questions the assistant asks, and decides how long to keep the results. There we are the processor: we act on the customer's written instructions and nothing else. The customer is the controller, and its own privacy policy governs how that information is used.
If a business called you using Bludge and you want your details removed, you can ask us and we will act — see Your rights. In most cases we will also point you to the business that called, because it is the one that holds the relationship and decides what is kept.
What we collect from this website
The "call me now" form
If you ask the assistant to call you so you can hear it, we collect your name, your phone number and the country you pick for that number. We also record your IP address and the time, so we can stop the same number or the same connection being used to place hundreds of calls.
We use this to place one call to you, and to keep a record that the call happened and how it ended. We do not add you to a marketing list from this form, and we will not call you again unless you ask us to.
The contact form
If you ask for a walkthrough, we collect your name, work email address, business name and whatever you write in the message. We use it to reply to you and to arrange the walkthrough.
Ordinary server records
Our hosting provider keeps standard web server logs — IP address, the page requested, the time, and the browser's user-agent string. We use them to keep the site running and to investigate abuse.
Cookies
We set one cookie on this website. It is called landing_country, it stores nothing but a country code such as au or uk, and it exists so the site keeps showing you the edition you chose. It lasts a year and you can delete it at any time. It is strictly necessary for that feature and we do not ask for consent to set it.
We do not run analytics, advertising or tracking cookies on this website today. There is no Google Analytics tag, no advertising pixel and no third-party tracker. If we ever add one, we will say so here and ask for your consent first where the law requires it.
Customers who log in to the admin also get a session cookie, which is what keeps them logged in.
What we collect from customers
If your business uses Bludge, we hold:
- Account and user records — business name, country, the names and email addresses of the people you give access to, and the role each has.
- Login codes. We do not store passwords, because there are none. Signing in sends a six-digit code to your email address; the code expires after ten minutes.
- Configuration — your assistant's questions and notes, its voice, its calling hours, your phone numbers, and the settings behind them.
- Credentials for services you connect, such as an API key or an OAuth token for your CRM or calendar. These are encrypted in our database and are never shown back to you in full.
- Usage and billing records — calls placed, minutes used, appointments booked, and what we invoiced.
What we handle for our customers
This is the part where we act on a customer's instructions rather than our own. Depending on how the customer has set the service up, it can include:
- the lead's name, phone number and email address;
- the enquiry itself — what the person asked for, the form fields they filled in, and when they submitted it;
- the raw payload a CRM or web form sent us, exactly as it arrived;
- the transcript of each call, and the outcome the assistant recorded;
- appointments booked into the customer's calendar, and the notes attached to them;
- text messages sent to the lead and any reply, including an opt-out;
- timing measurements from the call, which we use to keep the conversation fast.
People who call our customers are handled the same way. A customer's Bludge number is answered by the assistant, so we also process what somebody says when they ring in: their phone number, the name they give, the transcript of the call, and anything they ask to be booked or passed on. That is done on the customer's behalf and on its instructions, exactly as it is for the people we call — the customer is the controller of it, and its own privacy notice is the one that covers its callers. A caller we cannot match to an existing enquiry becomes a new record on the customer's account.
We do not sell this information, we do not use it to train our own models, and we do not use one customer's leads for another customer's benefit. We use it to run the service the customer asked for, to keep it working, and — in a form that does not identify anyone — to measure how the system performs. What the suppliers we depend on do with it is a separate question, and Who else handles it answers it supplier by supplier.
Calls, transcripts and recordings
Every call says it is an AI in its first sentence. The wording is set by the country the account is in and cannot be removed by the business using the service — only added to. In Australia it is: "This is an AI assistant calling on behalf of the business you contacted about your enquiry."
The same is true when you ring a business rather than being rung by one. If you call a number answered by Bludge, the disclosure is still the first thing you hear — in Australia, "This is an AI assistant answering for the business you called." — and it is spoken before the greeting, before any question, and before anything you say is acted on.
Calls are transcribed. Turning speech into text is how the assistant understands the conversation at all. The transcript is stored against the call and the business that made it can read it in the admin. A call you make to a business is transcribed on the same terms as a call it makes to you, and the transcript belongs to that business.
We do not store audio recordings of calls. Recording is not switched off; it is never asked for. When we place or answer a call, the instruction that would make our telephony provider record it is not sent, and there is no account setting, assistant setting or admin control that could send it. Call audio passes through our telephony and voice providers while the call is happening, and no copy of it is kept by us afterwards. If we ever offer call recording as a feature, it will be off by default, the business will have to switch it on, and we will update this policy and the disclosure the caller hears before that happens.
What is kept is the text. For each call we store the lead's record, the transcript line by line, and the call's metadata — when it started, how long it ran, how it ended, which number it was placed from, whether a person or a machine answered, the outcome the assistant recorded, and the timing measurements we use to keep the conversation fast. The one piece of synthesized audio we do store is the assistant's own prepared speech — the disclosure sentence, the greeting and any prepared reply — cached so it plays on the first frame of the call. None of that cache is anything a caller said.
You can end the call at any time, and you can ask not to be called again — by saying so on the call, or by replying STOP to a text message. That suppresses your number across the whole of that business's account, on every list and every future enquiry.
Why we use it, and our lawful basis
Where UK or European law applies, we need a lawful basis for each purpose. These are ours.
| What we do | Why | Lawful basis (UK GDPR) |
|---|---|---|
| Call you back after you ask for a demonstration | You asked us to, on the form | Consent — Article 6(1)(a). You can withdraw it by telling us, though the one call usually happens within seconds |
| Reply to a contact form | You asked us a question | Legitimate interests — Article 6(1)(f): answering someone who wrote to us |
| Run an account, invoice it, support it | Delivering the service we agreed to | Contract — Article 6(1)(b), and legal obligation for tax and accounting records |
| Place calls and send texts on a customer's behalf | The customer instructed us to | The customer's basis, not ours. We act as processor — Article 28 |
| Keep the service secure, prevent abuse, keep logs | Fraud, abuse and rate limiting | Legitimate interests — Article 6(1)(f) |
| Measure how fast and how well calls run | Improving the service | Legitimate interests — Article 6(1)(f), on data that does not identify anyone |
Who else handles it
We use a small number of suppliers to run the service. They may handle personal information on our instructions, they are bound to keep it confidential, and they may not use it for anything else. This is the whole list, with what each one receives and where we can establish that it runs. Where a supplier does not publish where it processes data, this table says so rather than guessing.
| Supplier | What it receives | Where it processes it |
|---|---|---|
| Twilio | The caller's phone number and ours, the call's metadata, the audio of the call in both directions while it is in progress, and the text of any message we send | United States. Our telephony account is a US account, so the data for your numbers is held in its US region |
| Inworld AI | On most accounts: the caller's speech and the assistant's, the text of both sides of the conversation, and the assistant's instructions, which include the lead's first name so the assistant can greet them by it. No surname and no email address are sent. On an account using the Australian pipeline, Inworld is used for the assistant's voice alone, and receives only the words the assistant speaks — never the caller's voice and never anything the caller says | Not published. Inworld is a United States company and does not publish where its servers are |
| Google Cloud | The full transcript of the call, when the assistant's answers are extracted from it at the end | Sydney. We call Google's Australian region directly, and Google's terms for the paid service say it does not use what we send to train or improve its models |
| Deepgram | The caller's speech and its transcript, and the text the assistant is about to say together with the audio it is turned into, on the calls that use this part of the pipeline | Deepgram's Australian endpoint, which it says handles and stores the request within that region. We send every request with Deepgram's model improvement program opted out |
| OpenAI | The transcript of every finished call, read once to write the summary, the outcome and the answers to the assistant's questions. On the newest version of our pipeline, the conversation as it happens | United States |
| Fly.io | Hosts the Bludge application, its database and the part of the system that listens to the call, so everything we store passes through it | Sydney, Australia. Application logs are shipped off the machine by Fly and kept by Fly for seven days; Fly does not publish where that log index sits |
| Tigris | Object storage for the assistant's own synthesized speech — the disclosure, greetings and prepared replies. No caller audio, no recording and no transcript is written to it | Distributed by Tigris and cached close to whoever requests the file, so it is not pinned to one country |
| Amazon Web Services | Runs the per-call component of the newest version of our pipeline, and the speech-to-text it uses. Its operational logs can contain short fragments of the assistant's own speech | Oregon, United States for the per-call component and its logs; Sydney, Australia for the speech-to-text |
| Google Workspace | Delivers login codes, notifications and summary emails | United States |
What our suppliers do with it. We do not train our own models on your data. Of the suppliers above: OpenAI states that data sent to its API is not used to train or improve its models; every request we send Deepgram carries its model improvement program opted out, which Deepgram says excludes that request from the program; and Google Google states that on the paid service it does not use what we send, or what it returns, to train or improve its models, and processes it under its published data processing terms. We have written down what each of them publishes rather than what we would like it to say, and we will update this paragraph when any of it changes.
Inworld may use your speech to train its models. Inworld publishes a training exclusion for its transcription service, and for that service alone. It says nothing either way about the content of a conversation, or about the text and speech handled by the voice service, and the only setting that would exclude them is sold with its enterprise plan, which we are not on. There is no separate way to opt out. We have asked Inworld to confirm or correct this and will say here what they answer.
Separately, a customer may connect its own accounts with ActiveCampaign, HubSpot, Zoho, Calendly or SavvyCal. When it does, we send lead details, call outcomes and bookings to that service on the customer's instruction — and, where the customer has asked for a note to be written back, the full transcript of the call. Those are the customer's own suppliers under the customer's own agreements, in whatever country that customer's account lives, and what happens to the data there is governed by the customer's contract with them and their privacy policies.
We keep the list above current. Customers with a data processing agreement in place are told before we add or change a supplier, so they have a chance to object.
Where it is stored
We do not promise that your information stays in any one country. The service is built so that the part which has to be fast is close to the caller, not so that everything sits inside one border, and several of the suppliers a call depends on are overseas or do not publish where they run. This section says where each piece actually is. If we ever offer a choice of where an account's data is handled, it will be something you select, and this notice will say so.
What we hold ourselves is in Sydney. The Bludge application, its database and the part of the system that listens to the call all run on machines in Sydney, Australia. That is where lead records, transcripts, call metadata, bookings and account data live, and every call in every market is currently answered from there. We will update this notice before that changes.
What necessarily happens elsewhere. Our telephony provider holds the call records for your numbers in the United States. The caller's speech and the text of the conversation are processed while the call is happening by our voice provider, which is a United States company and does not publish where its servers are; the step that extracts the assistant's answers from the transcript is sent to a Google service in Sydney, Australia, which we call directly rather than through that provider. Some speech processing is done by a provider on its Australian endpoint, with its model improvement program opted out. The transcript of every finished call is read once by a model in the United States to write its summary and outcome. The assistant's own synthesized speech is held in object storage that distributes and caches files wherever they are requested from, so it is not pinned to one country. The per-call component of the newest version of our pipeline, and its logs, run in Oregon, United States, and the speech-to-text it uses runs in Sydney, Australia. If you connect a CRM, we write the transcript there too, wherever that CRM keeps your data.
Australia is our launch market, and this notice is written to the Privacy Act 1988 (Cth) and the Australian Privacy Principles — see Australia below, and APP 8 in particular, which covers the overseas suppliers named above. If you are somewhere else, the law of your own region applies as well: the sections below say which one and what it adds.
Where we transfer personal information out of the United Kingdom or the European Economic Area, we rely on the UK International Data Transfer Addendum to the European Commission's Standard Contractual Clauses, or on an adequacy decision where one applies. Australia has not been the subject of an adequacy decision, so transfers to us rely on those clauses. A copy is available on request.
How long we keep it
Some of these are set by the system itself and are exact. Others depend on the customer, because it is the customer's information to keep or delete. Where a row below says a record is deleted automatically, that deletion is carried out by a job that runs every night, not by somebody remembering; where a supplier or the law sets the period instead, the row says so.
| What | How long |
|---|---|
| Login codes | Ten minutes, then they stop working |
| The raw payload a CRM or form sent us | Deleted automatically after 30 days |
| Finished calls and their transcripts | Deleted automatically once the customer’s retention period passes. The default is 90 days; a customer can set it to 90 days, 6 months, 1 year, 2 years or 7 years in their settings, and it applies to calls placed and calls answered alike |
| An uploaded spreadsheet of leads | Deleted automatically within 24 hours of the import |
| Lead records and bookings | Kept while the customer’s account is open, because they are the customer’s record of who asked them for something. Deleting an account removes it and everything on it at once, including its leads and its bookings; an account that is closed but not yet removed keeps them for 30 more days, after which they are deleted automatically. A customer can delete a lead at any time. The transcript of a call attached to a lead follows the row above, not this one |
| Text messages we sent you, the form you filled in, and a conversation with the assistant in a web page | Deleted automatically on the same period as that customer’s calls — the default is 90 days. They are the same conversation by another channel, so they keep the same schedule |
| A visit to a customer’s form that you did not send | Your IP address and nothing else. Deleted automatically after 30 days |
| Do-not-call entries | Kept for as long as the account exists. Deleting them would mean calling someone who asked us not to |
| Demonstration call requests from this website | The call itself is deleted on the demonstration account’s own retention period, the same as any other call. The request record — your name, your number, the country you picked and your IP address — is deleted automatically 90 days after you asked. Ask us sooner and we will delete yours |
| Contact form messages | 12 months, then deleted. A message sent through the contact form is emailed to us and is not stored in the product at all, so this is a rule about our mailbox rather than about the database. Ask us sooner and we will delete yours |
| Invoices and accounting records | Seven years, as Australian tax law requires |
| Server and application logs | Our hosting provider keeps our application’s own log output for seven days. The logs of the per-call component in Oregon are kept for 30 days |
Deleting a call here does not reach our suppliers’ own records. The periods above are ours. Each supplier a call passed through keeps whatever its own terms allow, on its own schedule, and we cannot delete it for you. The one worth naming is Inworld: we do not have its zero-retention setting enabled, and so the speech, the text of both sides of the conversation and the assistant’s instructions we send it are stored in Inworld’s logging systems. Inworld does not publish for how long, and publishes no route by which we could ask for that copy to be deleted. If that is not acceptable for the calls you make, tell us before you start.
How we protect it
- No passwords exist to steal. Signing in uses a six-digit code sent to your email address, and the code expires after ten minutes.
- Credentials are encrypted at rest. API keys and the OAuth tokens for connected services are encrypted in the database with keys held outside it.
- Everything travels over HTTPS, and the production site refuses plain HTTP.
- Accounts are isolated. Every record belongs to one account and every query is scoped to it, so one customer cannot see another's leads.
- Access is by role. A viewer sees only what they are assigned; an account administrator sees their own business; only we can see across accounts, and only staff who need to.
- Incoming webhooks are authenticated with a per-account key, with signature checking where the sending service supports it, and are rate limited.
- The part of the system that listens to calls authenticates to the rest with a shared secret compared in constant time, and every call configuration is fetched with a token that works once.
- Sensitive actions are logged, including any change to an account's calling rules, which cannot be made without a stored reason.
- We scan our own code for security defects and our dependencies for known vulnerabilities as part of the build.
No system is perfect. If a breach happens that is likely to cause serious harm, we will notify the people affected and the relevant regulator within the time the law allows — see the regional sections below. Where we are the processor, we will notify the customer without undue delay so it can meet its own obligations.
Your rights
Wherever you are, you can ask us to:
- tell you what we hold about you, and give you a copy;
- correct it if it is wrong or out of date;
- delete it, where we do not have to keep it;
- stop calling or texting you, which we will do immediately and permanently for that business;
- explain a decision the assistant made about your enquiry.
Write to privacy@bludge.ai. We will reply within 30 days, and usually much sooner. We may need to confirm who you are first — normally by asking you to reply from the address or the phone number we hold.
Every request — for a copy, a correction or a deletion — goes to the privacy contact above and is answered within 30 days. We look you up by the phone number or the email address you give us, across every business that uses Bludge, so one request covers all of them; a deletion removes your lead record, the calls and their transcripts, the texts, the form you filled in and the bookings, and keeps only the entry that stops your number being called again.
If your request is about a call a business made using Bludge, we hold that information for that business. We will act on your request, and we will also tell the business, because it is the one that decides what it keeps. If you would rather deal with it directly, tell us and we will give you its details.
Everything above is free. If a request is clearly excessive or repetitive we may charge a reasonable fee or decline it, and we will explain why.
You are reading the Australia edition of this site. The Australia section below is the one most likely to apply to you. The others are here because a call we place for a customer in one country can reach someone in another.
Australia
We are an Australian company and we handle personal information in line with the Privacy Act 1988 (Cth) and the Australian Privacy Principles.
- APP 1 — openness. This policy is our APP privacy policy. Ask us for a copy in another format and we will send one.
- APP 6 — use and disclosure. We use personal information for the purpose it was collected for, and for directly related purposes you would reasonably expect.
- APP 8 — overseas disclosure. The suppliers listed in Who else handles it include recipients in the United States, and two whose processing location is not published. We take reasonable steps to ensure they handle the information consistently with the APPs, through the terms of our agreements with them. We do not promise that an Australian caller's information is handled only inside Australia, and Where it is stored says exactly which parts are not.
- APP 11 — security. See How we protect it.
- APP 12 and 13 — access and correction. See Your rights.
Notifiable data breaches. If a breach is likely to result in serious harm, we will notify the affected individuals and the Office of the Australian Information Commissioner as the scheme requires.
Calls. The service is built to the Australian rules on telemarketing: calls only inside the permitted hours in the called person's own state time, never on Sundays or public holidays, an AI disclosure in the first sentence, and an opt-out that takes effect straight away. There is more detail on the calling rules page.
Complaints. Write to us first at privacy@bludge.ai. We will acknowledge within 5 business days and answer within 30 days. If you are not satisfied, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au or on 1300 363 992.
United Kingdom and Europe
If you are in the United Kingdom or the European Economic Area, the UK GDPR and the Data Protection Act 2018 (or your own country's implementation of the EU GDPR) apply to how we handle your information.
Alongside the rights listed above, you have the right to restrict our processing, to object to processing based on legitimate interests, to data portability, and not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects. Our assistant qualifies an enquiry and books a meeting; it does not decide anything with a legal effect on you, and a person at the business always reviews what it did.
International transfers. See Where it is stored. In short: what we hold ourselves is stored in Australia, and parts of a call are handled by suppliers in the United States and by suppliers that do not publish where they run, under the UK International Data Transfer Addendum to the Standard Contractual Clauses. We make no promise that a UK or European caller's information stays in the United Kingdom or the European Economic Area.
For customers. If you are a business using Bludge to call people in the UK or the EEA, you are the controller and we are your processor. We offer a data processing agreement that meets Article 28, including our sub-processor list, our security measures and our breach notification commitments. Ask at privacy@bludge.ai and we will send it.
Representative. No representative in the United Kingdom or the European Union has been appointed yet; write to privacy@bludge.ai and we will answer directly.
Complaints. Tell us first. You can also complain to the Information Commissioner's Office at ico.org.uk or on 0303 123 1113, or to your own country's supervisory authority.
United States and California
Calls placed in the United States are subject to the Telephone Consumer Protection Act. In February 2024 the Federal Communications Commission confirmed that an AI-generated voice is an "artificial or prerecorded voice" for the purposes of that Act, which means calls made with it need the caller's prior express written consent unless an exemption applies. Our customers promise, in our terms, that every person they load into Bludge made an enquiry with them and consented to be contacted, and that their forms capture that consent in the words the law requires.
If you received a call you did not consent to, tell us at privacy@bludge.ai. We will suppress your number for that business immediately and look into how it got there.
Notice for California residents
Under the California Consumer Privacy Act, as amended by the CPRA:
- Categories we collect. Identifiers (name, phone number, email address, IP address); commercial information (what you enquired about, what was booked); internet activity (server logs); audio and electronic information (the content of a call, as a transcript); and, for our customers' staff, professional information.
- Where it comes from. Directly from you, from the business that you contacted, or from that business's CRM or web form.
- Why. The purposes in Why we use it.
- Who we disclose it to. The service providers listed in Who else handles it, for a business purpose only.
- We do not sell personal information, and we do not share it for cross-context behavioral advertising. We have not done so in the preceding twelve months. We do not have to offer a "Do Not Sell or Share My Personal Information" link, and we do not.
- Sensitive personal information. We do not collect it for the purpose of inferring characteristics, and we do not use or disclose it beyond what the CCPA permits without a right to limit.
- Your rights. To know, to access, to correct, to delete, and to be free from retaliation for exercising any of them. See Your rights. You can use an authorized agent; we will ask for proof of their authority.
- Where we act for a business that called you, we are that business's service provider under the CCPA. We handle your information only on its documented instructions and we do not retain, use or disclose it for any other purpose.
Residents of other US states with comparable laws have similar rights, and we will honour them in the same way.
Canada
If you are in Canada, the Personal Information Protection and Electronic Documents Act applies to how we handle your information, along with the substantially similar provincial laws in Alberta, British Columbia and Quebec.
- Consent. We collect, use and disclose personal information with your consent, and only for the purposes set out in this policy. You can withdraw your consent at any time, subject to legal or contractual restrictions and reasonable notice.
- Transfers. What we hold ourselves is stored in Australia, and parts of a call are handled by suppliers in the United States and by suppliers that do not publish where they run — see Where it is stored. That means it may be accessible to the authorities in those countries under their laws. We use contractual measures to keep it protected to a comparable standard.
- Access and correction. See Your rights.
- Complaints. Tell us first at privacy@bludge.ai. You can also complain to the Office of the Privacy Commissioner of Canada at priv.gc.ca or on 1-800-282-1376, or to your provincial commissioner.
Text messages. Follow-up texts sent by the service are commercial electronic messages under CASL. They are sent because you made an enquiry with the business, they identify that business, and every one of them can be stopped by replying STOP. We act on that immediately and permanently.
Children
Bludge is a tool for businesses. Neither this website nor the service is directed at children, and we do not knowingly collect personal information from anyone under 16.
Our customers agree not to load anyone under 16 into the service. If you believe we hold information about a child, write to privacy@bludge.ai and we will delete it.
Changes to this policy
We update this page when the service changes. The effective date at the top tells you which version you are reading, and we keep the previous versions.
If a change materially affects how we use your personal information, we will tell you before it takes effect — by email to customers, and by a notice on this page for everyone else.
Questions about this policy
A person reads this address, and we would rather answer a question than have you guess.
- Privacy: privacy@bludge.ai
- Anything else: support@bludge.ai, or the contact page
- By post: ACN 168 669 038 Pty Ltd (formerly Slay Pty Ltd), 70 Winton Road, Ashburton, Victoria 3147, Australia
See also our terms of service, our acceptable use policy and the calling rules the service enforces.