Legal
Privacy policy
Bludge makes phone calls to real people, so we take this seriously. This page says what we collect, what we do with it, who else touches it and how to get it back or have it deleted.
Who we are
Bludge is a service operated by [Company legal name] (ABN [ABN]), a company registered in Australia with its registered office at [registered address]. In this policy, "we", "us" and "our" mean that company, and "Bludge" means the service.
We are the business you reach at [privacy contact email]. That address goes to a person, not a queue.
This policy covers our website at this domain, the Bludge admin that our customers log in to, and the phone calls and text messages the service places. It does not cover anyone else's website, even if we link to it.
The two roles we play
Privacy law asks who decides what happens to personal information. We answer that question twice, because we do two different things.
- Our own information: we decide
- Visitors to this website, people who ask for a demonstration call, and the staff of our customers who log in to the admin. Here we are the controller (in Australia, the "APP entity"): we decide what to collect and why, and the rest of this policy tells you.
- Our customers' leads: they decide
- The people our customers ask us to call. A customer loads or connects its own enquiries, writes the questions the assistant asks, and decides how long to keep the results. There we are the processor: we act on the customer's written instructions and nothing else. The customer is the controller, and its own privacy policy governs how that information is used.
If a business called you using Bludge and you want your details removed, you can ask us and we will act — see Your rights. In most cases we will also point you to the business that called, because it is the one that holds the relationship and decides what is kept.
What we collect from this website
The "call me now" form
If you ask the assistant to call you so you can hear it, we collect your name, your phone number and the country you pick for that number. We also record your IP address and the time, so we can stop the same number or the same connection being used to place hundreds of calls.
We use this to place one call to you, and to keep a record that the call happened and how it ended. We do not add you to a marketing list from this form, and we will not call you again unless you ask us to.
The contact form
If you ask for a walkthrough, we collect your name, work email address, business name and whatever you write in the message. We use it to reply to you and to arrange the walkthrough.
Ordinary server records
Our hosting provider keeps standard web server logs — IP address, the page requested, the time, and the browser's user-agent string. We use them to keep the site running and to investigate abuse.
Cookies
We set one cookie on this website. It is called landing_country, it stores nothing but a country code such as au or uk, and it exists so the site keeps showing you the edition you chose. It lasts a year and you can delete it at any time. It is strictly necessary for that feature and we do not ask for consent to set it.
We do not run analytics, advertising or tracking cookies on this website today. There is no Google Analytics tag, no advertising pixel and no third-party tracker. If we ever add one, we will say so here and ask for your consent first where the law requires it.
Customers who log in to the admin also get a session cookie, which is what keeps them logged in.
What we collect from customers
If your business uses Bludge, we hold:
- Account and user records — business name, country, the names and email addresses of the people you give access to, and the role each has.
- Login codes. We do not store passwords, because there are none. Signing in sends a six-digit code to your email address; the code expires after ten minutes.
- Configuration — your assistant's questions and notes, its voice, its calling hours, your phone numbers, and the settings behind them.
- Credentials for services you connect, such as an API key or an OAuth token for your CRM or calendar. These are encrypted in our database and are never shown back to you in full.
- Usage and billing records — calls placed, minutes used, appointments booked, and what we invoiced.
What we handle for our customers
This is the part where we act on a customer's instructions rather than our own. Depending on how the customer has set the service up, it can include:
- the lead's name, phone number and email address;
- the enquiry itself — what the person asked for, the form fields they filled in, and when they submitted it;
- the raw payload a CRM or web form sent us, exactly as it arrived;
- the transcript of each call, and the outcome the assistant recorded;
- appointments booked into the customer's calendar, and the notes attached to them;
- text messages sent to the lead and any reply, including an opt-out;
- timing measurements from the call, which we use to keep the conversation fast.
People who call our customers are handled the same way. A customer's Bludge number is answered by the assistant, so we also process what somebody says when they ring in: their phone number, the name they give, the transcript of the call, and anything they ask to be booked or passed on. That is done on the customer's behalf and on its instructions, exactly as it is for the people we call — the customer is the controller of it, and its own privacy notice is the one that covers its callers. A caller we cannot match to an existing enquiry becomes a new record on the customer's account.
We do not sell this information, we do not use it to train our own models, and we do not use one customer's leads for another customer's benefit. We use it to run the service the customer asked for, to keep it working, and — in a form that does not identify anyone — to measure how the system performs.
Calls, transcripts and recordings
Every call says it is an AI in its first sentence. The wording is set by the country the account is in and cannot be removed by the business using the service — only added to. In United Kingdom it is: "This is an AI assistant calling on behalf of the business you contacted about your enquiry."
The same is true when you ring a business rather than being rung by one. If you call a number answered by Bludge, the disclosure is still the first thing you hear — in United Kingdom, "This is an AI assistant answering for the business you called." — and it is spoken before the greeting, before any question, and before anything you say is acted on.
Calls are transcribed. Turning speech into text is how the assistant understands the conversation at all. The transcript is stored against the call and the business that made it can read it in the admin. A call you make to a business is transcribed on the same terms as a call it makes to you, and the transcript belongs to that business.
We do not store audio recordings of calls. Call audio passes through our telephony and voice providers while the call is happening, and is not kept by us afterwards. If we ever offer call recording as a feature, it will be off by default, the business will have to switch it on, and we will update this policy and the disclosure the caller hears before that happens.
You can end the call at any time, and you can ask not to be called again — by saying so on the call, or by replying STOP to a text message. That suppresses your number across the whole of that business's account, on every list and every future enquiry.
Why we use it, and our lawful basis
Where UK or European law applies, we need a lawful basis for each purpose. These are ours.
| What we do | Why | Lawful basis (UK GDPR) |
|---|---|---|
| Call you back after you ask for a demonstration | You asked us to, on the form | Consent — Article 6(1)(a). You can withdraw it by telling us, though the one call usually happens within seconds |
| Reply to a contact form | You asked us a question | Legitimate interests — Article 6(1)(f): answering someone who wrote to us |
| Run an account, invoice it, support it | Delivering the service we agreed to | Contract — Article 6(1)(b), and legal obligation for tax and accounting records |
| Place calls and send texts on a customer's behalf | The customer instructed us to | The customer's basis, not ours. We act as processor — Article 28 |
| Keep the service secure, prevent abuse, keep logs | Fraud, abuse and rate limiting | Legitimate interests — Article 6(1)(f) |
| Measure how fast and how well calls run | Improving the service | Legitimate interests — Article 6(1)(f), on data that does not identify anyone |
Who else handles it
We use a small number of suppliers to run the service. They may handle personal information on our instructions, they are bound to keep it confidential, and they may not use it for anything else.
| Supplier | What it does | Where |
|---|---|---|
| Twilio | Places the phone calls, carries the audio, provides the phone numbers and sends the text messages | United States, with call media handled in the region closest to the caller |
| Inworld AI | Understands the caller's speech, decides what to say, and speaks the reply in the chosen voice | United States |
| Fly.io | Hosts the application, its database and the telephony bridge that listens to the call | Sydney, Australia is our primary region; a second bridge runs in San Jose, United States for US calls |
| Amazon Web Services | Runs the per-call component and the speech-to-text used by the newest version of our call pipeline | Oregon, United States and Sydney, Australia |
| Google (Gmail SMTP) | Delivers login codes, notifications and summary emails | United States |
Separately, a customer may connect its own accounts with ActiveCampaign, HubSpot, Zoho, Calendly or SavvyCal. When it does, we send lead details, call outcomes and bookings to that service on the customer's instruction. Those are the customer's own suppliers under the customer's own agreements, and what happens to the data there is governed by the customer's contract with them and their privacy policies.
We keep the list above current. Customers with a data processing agreement in place are told before we add or change a supplier, so they have a chance to object.
Where it is stored
The Bludge application and its database run in Sydney, Australia. That is where lead records, transcripts, bookings and account data live.
Two things necessarily happen elsewhere. Voice processing runs in the United States, because that is where our voice provider operates, so call audio and the text of the conversation cross the Pacific while the call is in progress. For customers in the United States, the part of our system that listens to the call runs in San Jose rather than Sydney, so that calls to American numbers are fast.
Where we transfer personal information out of the United Kingdom or the European Economic Area, we rely on the UK International Data Transfer Addendum to the European Commission's Standard Contractual Clauses, or on an adequacy decision where one applies. Australia has not been the subject of an adequacy decision, so transfers to us rely on those clauses. A copy is available on request.
How long we keep it
Some of these are set by the system itself and are exact. Others depend on the customer, because it is the customer's information to keep or delete.
| What | How long |
|---|---|
| Login codes | Ten minutes, then they stop working |
| The raw payload a CRM or form sent us | Deleted automatically after 30 days |
| Finished calls and their transcripts | Deleted automatically once the customer’s retention period passes. The default is 90 days; a customer can set it to 90 days, 6 months, 1 year, 2 years or 7 years in their settings, and it applies to calls placed and calls answered alike |
| An uploaded spreadsheet of leads | Deleted automatically within 24 hours of the import |
| Lead records and bookings | Kept while the customer’s account is open, and deleted [retention period after an account closes — still to be set] after it closes. A customer can delete a lead at any time. The transcript of a call attached to a lead follows the row above, not this one |
| Do-not-call entries | Kept for as long as the account exists. Deleting them would mean calling someone who asked us not to |
| Demonstration call requests from this website | The call itself is deleted on the demonstration account’s own retention period, the same as any other call. How long the request record itself is kept is [still to be set] |
| Contact form messages | [retention period] |
| Invoices and accounting records | Seven years, as Australian tax law requires |
| Server and application logs | [retention period] |
How we protect it
- No passwords exist to steal. Signing in uses a six-digit code sent to your email address, and the code expires after ten minutes.
- Credentials are encrypted at rest. API keys and the OAuth tokens for connected services are encrypted in the database with keys held outside it.
- Everything travels over HTTPS, and the production site refuses plain HTTP.
- Accounts are isolated. Every record belongs to one account and every query is scoped to it, so one customer cannot see another's leads.
- Access is by role. A viewer sees only what they are assigned; an account administrator sees their own business; only we can see across accounts, and only staff who need to.
- Incoming webhooks are authenticated with a per-account key, with signature checking where the sending service supports it, and are rate limited.
- The part of the system that listens to calls authenticates to the rest with a shared secret compared in constant time, and every call configuration is fetched with a token that works once.
- Sensitive actions are logged, including any change to an account's calling rules, which cannot be made without a stored reason.
- We scan our own code for security defects and our dependencies for known vulnerabilities as part of the build.
No system is perfect. If a breach happens that is likely to cause serious harm, we will notify the people affected and the relevant regulator within the time the law allows — see the regional sections below. Where we are the processor, we will notify the customer without undue delay so it can meet its own obligations.
Your rights
Wherever you are, you can ask us to:
- tell you what we hold about you, and give you a copy;
- correct it if it is wrong or out of date;
- delete it, where we do not have to keep it;
- stop calling or texting you, which we will do immediately and permanently for that business;
- explain a decision the assistant made about your enquiry.
Write to [privacy contact email]. We will reply within 30 days, and usually much sooner. We may need to confirm who you are first — normally by asking you to reply from the address or the phone number we hold.
If your request is about a call a business made using Bludge, we hold that information for that business. We will act on your request, and we will also tell the business, because it is the one that decides what it keeps. If you would rather deal with it directly, tell us and we will give you its details.
Everything above is free. If a request is clearly excessive or repetitive we may charge a reasonable fee or decline it, and we will explain why.
You are reading the United Kingdom edition of this site. The United Kingdom section below is the one most likely to apply to you. The others are here because a call we place for a customer in one country can reach someone in another.
Australia
We are an Australian company and we handle personal information in line with the Privacy Act 1988 (Cth) and the Australian Privacy Principles.
- APP 1 — openness. This policy is our APP privacy policy. Ask us for a copy in another format and we will send one.
- APP 6 — use and disclosure. We use personal information for the purpose it was collected for, and for directly related purposes you would reasonably expect.
- APP 8 — overseas disclosure. The suppliers listed above include recipients in the United States. We take reasonable steps to ensure they handle the information consistently with the APPs, through the terms of our agreements with them.
- APP 11 — security. See How we protect it.
- APP 12 and 13 — access and correction. See Your rights.
Notifiable data breaches. If a breach is likely to result in serious harm, we will notify the affected individuals and the Office of the Australian Information Commissioner as the scheme requires.
Calls. The service is built to the Australian rules on telemarketing: calls only inside the permitted hours in the called person's own state time, never on Sundays or public holidays, an AI disclosure in the first sentence, and an opt-out that takes effect straight away. There is more detail on the calling rules page.
Complaints. Write to us first at [privacy contact email]. We will acknowledge within 5 business days and answer within 30 days. If you are not satisfied, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au or on 1300 363 992.
United Kingdom and Europe
If you are in the United Kingdom or the European Economic Area, the UK GDPR and the Data Protection Act 2018 (or your own country's implementation of the EU GDPR) apply to how we handle your information.
Alongside the rights listed above, you have the right to restrict our processing, to object to processing based on legitimate interests, to data portability, and not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects. Our assistant qualifies an enquiry and books a meeting; it does not decide anything with a legal effect on you, and a person at the business always reviews what it did.
International transfers. See Where it is stored. In short: your information is stored in Australia and processed in the United States during a call, under the UK International Data Transfer Addendum to the Standard Contractual Clauses.
For customers. If you are a business using Bludge to call people in the UK or the EEA, you are the controller and we are your processor. We offer a data processing agreement that meets Article 28, including our sub-processor list, our security measures and our breach notification commitments. Ask at [privacy contact email] and we will send it.
Representative. [UK/EU Article 27 representative, if one is appointed].
Complaints. Tell us first. You can also complain to the Information Commissioner's Office at ico.org.uk or on 0303 123 1113, or to your own country's supervisory authority.
United States and California
Calls placed in the United States are subject to the Telephone Consumer Protection Act. In February 2024 the Federal Communications Commission confirmed that an AI-generated voice is an "artificial or prerecorded voice" for the purposes of that Act, which means calls made with it need the caller's prior express written consent unless an exemption applies. Our customers promise, in our terms, that every person they load into Bludge made an enquiry with them and consented to be contacted, and that their forms capture that consent in the words the law requires.
If you received a call you did not consent to, tell us at [privacy contact email]. We will suppress your number for that business immediately and look into how it got there.
Notice for California residents
Under the California Consumer Privacy Act, as amended by the CPRA:
- Categories we collect. Identifiers (name, phone number, email address, IP address); commercial information (what you enquired about, what was booked); internet activity (server logs); audio and electronic information (the content of a call, as a transcript); and, for our customers' staff, professional information.
- Where it comes from. Directly from you, from the business that you contacted, or from that business's CRM or web form.
- Why. The purposes in Why we use it.
- Who we disclose it to. The service providers listed in Who else handles it, for a business purpose only.
- We do not sell personal information, and we do not share it for cross-context behavioural advertising. We have not done so in the preceding twelve months. We do not have to offer a "Do Not Sell or Share My Personal Information" link, and we do not.
- Sensitive personal information. We do not collect it for the purpose of inferring characteristics, and we do not use or disclose it beyond what the CCPA permits without a right to limit.
- Your rights. To know, to access, to correct, to delete, and to be free from retaliation for exercising any of them. See Your rights. You can use an authorised agent; we will ask for proof of their authority.
- Where we act for a business that called you, we are that business's service provider under the CCPA. We handle your information only on its documented instructions and we do not retain, use or disclose it for any other purpose.
Residents of other US states with comparable laws have similar rights, and we will honour them in the same way.
Canada
If you are in Canada, the Personal Information Protection and Electronic Documents Act applies to how we handle your information, along with the substantially similar provincial laws in Alberta, British Columbia and Quebec.
- Consent. We collect, use and disclose personal information with your consent, and only for the purposes set out in this policy. You can withdraw your consent at any time, subject to legal or contractual restrictions and reasonable notice.
- Transfers. Your information is stored in Australia and processed in the United States, which means it may be accessible to the authorities in those countries under their laws. We use contractual measures to keep it protected to a comparable standard.
- Access and correction. See Your rights.
- Complaints. Tell us first at [privacy contact email]. You can also complain to the Office of the Privacy Commissioner of Canada at priv.gc.ca or on 1-800-282-1376, or to your provincial commissioner.
Text messages. Follow-up texts sent by the service are commercial electronic messages under CASL. They are sent because you made an enquiry with the business, they identify that business, and every one of them can be stopped by replying STOP. We act on that immediately and permanently.
Children
Bludge is a tool for businesses. Neither this website nor the service is directed at children, and we do not knowingly collect personal information from anyone under 16.
Our customers agree not to load anyone under 16 into the service. If you believe we hold information about a child, write to [privacy contact email] and we will delete it.
Changes to this policy
We update this page when the service changes. The effective date at the top tells you which version you are reading, and we keep the previous versions.
If a change materially affects how we use your personal information, we will tell you before it takes effect — by email to customers, and by a notice on this page for everyone else.
Questions about this policy
A person reads this address, and we would rather answer a question than have you guess.
- Privacy: [privacy contact email]
- Anything else: [support email], or the contact page
- By post: [Company legal name], [registered address]
See also our terms of service, our acceptable use policy and the calling rules the service enforces.