Document sections
Last updated: July 29, 2026 · Version 1.4 (supersedes Version 1.3, dated July 27, 2026). Version 1.4 records the verified provider setting: transcript and personal-information deletion is enabled for calls begun after the setting was changed on July 29, 2026 and was not applied retroactively. Earlier transcripts and audio may therefore remain at the provider until separately deleted.
Workforce AI Corp operating as Vetted Intake (“Vetted Intake,” “we,” “us,” or “our”) provides the Service. This Privacy Policy explains how Vetted Intake handles personal information when a law firm (“Firm”) uses our AI voice intake Service to answer and qualify calls from prospective clients (“Callers”).
Roles. For the personal information of Callers, the Firm is the controller (the party that determines the purposes and means of processing) and Vetted Intake is the processor and agent acting on the Firm’s documented instructions. This Policy describes Vetted Intake’s own practices; each Firm also maintains its own privacy notice governing its relationship with Callers and prospective clients. Where a Firm’s instructions and this Policy conflict as to Caller data, the Firm’s lawful, documented instructions govern (see the DPA, Part 2).
1.1 Information we collect
From Callers, on behalf of the Firm, during an intake call:
- Identity & contact: name, phone number, and (if provided) email and mailing address.
- Other parties involved: the names of any other parties the Caller volunteers during intake (for example, another driver, a business, or an insurer).
- Intake / case facts: the Caller’s description of what happened — e.g., incident type, date, location, injuries, treatment, insurance, and prior representation — as volunteered by the Caller.
- Call metadata: date, time, duration, inbound number, call-progress signals, and routing/booking outcome.
- Scheduling data: consultation date/time and related booking details passed to the Firm’s scheduling provider.
- Audio & transcript: the call audio and its machine transcript, subject to the short-retention schedule in §1.4.
From the Firm (account/administrative data): authorized-user names, business email, phone, billing contact, firm configuration (greeting, intake script, routing rules, minute band).
When you contact us through the website: name, work email, phone number, firm name, the message or referral details you choose to provide, the site route where the request was made (without its query string), and the time you submitted the request. Do not submit confidential case details through these sales and demo forms.
Automatically (website): standard server logs and strictly-necessary cookies. We record a small set of first-party conversion events (such as a calendar, call, audio, pricing, or form interaction) with the site route and limited referral/source labels. These events do not contain names, contact details, message contents, full referring URLs, persistent visitor identifiers, or raw IP addresses. For form abuse prevention, we keep a short-lived keyed hash derived from the request IP address and form type; the raw IP address is not stored in the lead database. We minimize non-essential tracking and honor opt-out/consent signals where applicable.
We do not ask Callers for, and instruct Callers not to volunteer, payment-card numbers, Social Security numbers, or account passwords. If such data is spoken anyway, a pattern filter removes Social-Security-shaped and payment-card-shaped digit strings from the intake record we create before that record is stored. That filter runs on our own record only. It does not redact the voice provider’s copy of the transcript, and we do not currently have automatic redaction of that copy — see §1.4.
1.2 Why we process it (purposes)
- Answer the Firm’s phone 24/7 and greet the Caller as the Firm’s receptionist.
- Qualify the personal-injury inquiry and capture structured intake.
- Book a consultation and, where included in the signed implementation, warm-transfer or route the Caller to the Firm using validated routing rules.
- Deliver intake summaries and records through the destination and field mapping configured and validated with the Firm during implementation.
- Respond to website demo, callback, chat, and partner-referral requests and measure whether the site routes visitors to those requested actions.
- Maintain, secure, debug, and improve the Service (using de-identified/aggregated operational data only — never Firm or Caller content to train models; see §1.5).
- Comply with law and enforce our agreements.
1.3 Legal bases (where GDPR/UK GDPR or similar applies)
For Caller data, the Firm determines and stands behind the legal basis as controller — typically legitimate interests (responding to an inbound inquiry the Caller initiated and requesting professional services), steps at the Caller’s request prior to entering a contract, and, where required by an all-party-consent jurisdiction, consent to recording (Part 5). Vetted Intake processes only as processor under the DPA. For Firm account data, our basis is performance of the subscription contract and our legitimate interest in operating and securing the Service.
1.3A SMS / text messaging
Program name: Vetted Intake. You can check the texting box on our contact form at vettedintake.com/talk and give us your mobile number to receive customer care and occasional marketing texts. That box is unchecked by default and is never required to send the form. If you text our business number first, that authorizes customer care replies to your conversation only; it does not authorize marketing messages.
Vetted Intake sends customer care messages — replies to your question, demo and appointment confirmations, and scheduling or onboarding follow-ups — to people who use either opt-in path. We send occasional marketing messages, such as product updates, offers, and invitations to book a call, only when the website checkbox consent is recorded. Msg frequency varies. Msg & data rates may apply. Reply STOP at any time to opt out, or HELP for help. Carriers are not liable for delayed or undelivered messages. We do not sell or share your mobile number or messaging consent with any third party or affiliate for their own marketing. Consent to receive texts is not a condition of any purchase.
When you opt in through the website form, we store the exact disclosure wording you accepted together with the date and time of the opt-in, so the consent record is auditable. That record follows the website-submission schedule in §1.4.
1.4 Retention schedule
We practice data minimization — we keep the least we can while still serving the Firm. The schedule is firm-selectable during implementation; the defaults below apply unless the Firm chooses a shorter period in writing:
| Data category | Default retention | Notes |
|---|---|---|
| Structured intake fields | ~30 days in the firm-specific store configured and validated for the implementation, then delivered to the Firm and purged from active systems | The Firm may select a shorter period and retains its own copy in its systems |
| Raw call audio | Not retained by default; only where a Firm enables QA, ≤7 days, then purged | The Firm may select a shorter period; no audio is needed for AMD/call-progress signals |
| Call transcripts | Up to 3 days for calls begun after the provider setting was changed on July 29, 2026 — provider-side transcript and personal-information deletion is enabled for those new calls. We keep no transcript of our own in any system | The Firm may select a shorter period. Earlier transcripts were not deleted retroactively and may still be held at the provider. Transcript redaction is not enabled — read “How the voice provider is actually configured” below before relying on this row |
| Call metadata / logs | Limited operational period for billing, security, and abuse-prevention, then aggregated or deleted | |
| Firm account/billing data | Duration of the subscription + the period required by law/tax rules | |
| Website sales, demo, callback, chat, and referral submissions | Up to 180 days, then automatically deleted | If an inquiry becomes a customer, the separate account and contract records follow the account/billing schedule; the original website submission still expires |
| First-party website conversion events | Up to 90 days, then automatically deleted | Allowlisted event name, route, and limited referral/source labels only; no submitted form fields, persistent visitor identifier, or raw IP address |
| Form rate-limit keys | Up to 24 hours, then automatically deleted | Keyed hashes used only for abuse prevention; raw request IP addresses are not stored in this table |
How the voice provider is actually configured. We would rather publish the live setting than a promise. As of July 29, 2026, the conversational-voice provider that carries the call is set as follows:
- Voice recording: off. The provider is configured not to record call audio. Calls placed to our public demo line before July 22, 2026 were recorded under the previous setting, and that audio is still held at the provider; the change was applied to new calls only, not retroactively.
- Retention window: 3 days.
- Delete audio when the window closes: on.
- Delete transcript and personal information when the window closes: on, enabled for calls begun after the setting changed on July 29, 2026. The setting was not applied retroactively, so earlier transcripts may remain retrievable at the provider until we delete them individually.
- Zero-retention mode: off. It is an enterprise-tier provider feature and our workspace is not on that tier.
- Automatic redaction of the stored conversation history: not enabled. The provider’s conversation-history redaction feature is enterprise-only, and on our current plan the provider declines to enable it. There is no automatic redaction of the provider-side transcript today.
What we do instead, today. Our intake assistant is instructed never to ask for payment-card numbers, Social Security numbers, or passwords and to steer a Caller away from volunteering them. The record we create in our own systems holds a short structured summary and the fields the Caller gave — never the transcript, the turn-by-turn text, a provider-generated summary, or any audio — and the pattern filter described in §1.1 runs on that summary before it is written. That filter is narrow, it is not a substitute for provider-side redaction, and we do not describe it as one.
We do not present provider-side redaction or zero-retention processing as active controls today. Where a Firm requires either one, meeting that requirement depends on a provider tier or an architecture that supports it, and we will state in writing whether it is in place for that Firm’s implementation before any live traffic.
Legal hold. Where a Firm requires legal hold, the per-matter control and authorization process are configured and validated during the signed implementation. Once an authorized hold is active, the schedule above is suspended for that matter until the Firm releases the hold.
Discoverability caveat (honesty). Privilege and work-product protect communications, not underlying facts. The crash, the date, and the injury remain discoverable regardless of our controls. We therefore minimize what is created and stored on a belt-and-suspenders basis; we do not and cannot guarantee that any record could never be discovered.
1.5 No model training on your data
We do not use Caller content, call audio, transcripts, or Firm content to train, fine-tune, or improve any machine-learning model, and we contractually prohibit our sub-processors from doing so. Voice and language-model processing is performed by enterprise, no-training providers under contractual data-protection terms, including zero-data-retention (“ZDR”) API terms where available. Any product-improvement analytics use only de-identified or aggregated operational signals that do not contain Caller communications. If a Firm requires a Business Associate Agreement (BAA), a BAA and the required configuration can be arranged in writing during implementation.
1.6 Security measures
Before live traffic, technical and organizational controls are scoped, configured, and validated for each signed Firm implementation. Depending on that Firm’s documented requirements, these controls include:
- Encryption in transit and at rest.
- Firm-specific data isolation across the approved call, delivery, storage, and memory paths.
- Sensitive-identifier filtering on the records we create — the pattern filter described in §1.1 and §1.4. Automatic redaction of the voice provider’s stored transcript is not enabled today (§1.4); we will state in writing whether it is available for a given implementation rather than assume it.
- CRM delivery, warm-transfer routing, and fallback behavior configured and validated with the Firm before go-live.
- Role-based access, least-privilege administration, audit logging, and MFA for privileged access.
- Sub-processors bound by written no-training / data-protection terms.
- AI-generated summaries are labeled “AI-generated / unverified — attorney to confirm” so they are never mistaken for attorney work product.
No system is perfectly secure; we cannot guarantee absolute security.
1.7 Sub-processor roles
We use a limited set of sub-processors, engaged under written no-training / data-protection terms, to deliver the Service:
- Enterprise voice provider (speech synthesis and telephony transport).
- Enterprise language-model provider (natural-language understanding and intake logic).
- Scheduling provider (consultation booking).
- Cloud infrastructure, storage, and communications providers (hosting, delivery, notifications).
We do not sell personal information, and we do not share Caller content with third parties for their own purposes. The named list — the Vetted Intake Sub-Processor List (Part 6), which gives each vendor’s legal name, its role, the categories of data it processes, and its location where we can establish it, and which separates vendors that touch Caller or Firm data from vendors used only for our own outbound sales — is maintained per the DPA (Part 2, §2.4) and is available to Firms and their counsel on request at privacy@vettedintake.com. We keep vendor names out of this public Policy and out of caller-facing notices (Part 5), not out of the list itself.
1.8 Breach notification
If we become aware of a personal-data breach affecting Caller or Firm data, we will notify the affected Firm without undue delay and within 72 hours of confirmation, with the information the Firm needs to meet its own notification duties. As processor, we do not notify Callers or regulators directly unless the Firm instructs us or the law requires it of us.
1.9 Data-subject / consumer rights
Because the Firm is the controller of Caller data, Callers who wish to exercise access, correction, deletion, portability, restriction, objection, or opt-out rights (including under GDPR/UK GDPR, CCPA/CPRA, and similar laws) should contact the relevant Firm. Vetted Intake will assist the Firm in fulfilling verified requests as required by the DPA. Firm authorized users may exercise rights regarding their own account data by contacting us at the address below.
1.10 International transfers
Where personal data is transferred across borders, transfers are made under an approved mechanism (e.g., Standard Contractual Clauses / UK Addendum) as set out in the DPA, with supplementary measures as appropriate.
1.11 Children
The Service is for law-firm business use and is not directed to children. We do not knowingly collect data from children through the website. Intake calls may concern minors as claimants; such information is handled as Firm-controlled Caller data under this Policy and the DPA.
1.12 Changes; contact
We may update this Policy; material changes will be posted with a new “Last updated” date and, for Firms, communicated per the subscription agreement. Privacy contact: Mario Costanz, Workforce AI Corp, 1607 Capitol Avenue, Suite 322, Cheyenne, Wyoming 82001; privacy@vettedintake.com. Direct inquiries may also be sent to mario@vettedintake.com.