OnFrontBaseBook a call

Privacy Policy

Last updated: 1 September 2026

1. Who we are

OnFrontBase is operated by Dhruv Rana, an individual sole trader based in Delhi, India ("OnFrontBase", "we", "us", "our").

Contact: dhruv@onfrontbase.com Postal address: House No. 96, Siraspur, Delhi 110042, India

We provide AI employees for businesses. Our current service is an AI Receptionist that answers a business's telephone calls, answers questions, books appointments, and passes callers to a human when needed.

Each business chooses the name and voice its AI Receptionist uses when speaking to callers. In this policy we refer to it by function rather than by any particular name.

This policy explains what personal information we handle, why, where it goes, how long we keep it, and what rights you have. It applies worldwide.

2. Our role: controller and processor

Our role differs depending on whose information is involved.

We are a processor of information about callers. When someone telephones a business that uses an AI Receptionist, the business decides why that call happens and what is done with the information. The business is the controller. We handle the call on their instructions.

We are a controller of information about our clients themselves — the business owner's account details, billing records, and how they use the portal.

If you called a business and want your information deleted, your request is properly directed to that business. We will help — see section 15.

3. Who this policy covers

  • Clients — businesses that subscribe to OnFrontBase
  • Callers — anyone who telephones a business using one of our AI employees
  • Prospective clients — anyone who calls one of our demonstration lines or contacts us
  • Visitors — anyone who uses our website or portal

4. What we collect

From callers

CategoryDetail
Call audioA recording of the telephone call, where recording is enabled by the business
Call transcriptA written record of what was said by both parties
Contact detailsYour name, and the phone number you call from or provide
Appointment detailsThe service discussed, dates, times, and whether you are a returning customer
Call metadataTime, duration, whether answered, response latency
Derived informationThe apparent reason for your call, whether the conversation was positive or negative, whether you asked for a human, and questions we could not answer

We do not ask for and do not want payment card details, government identifiers, or clinical information. Our AI Receptionist is not configured to request them. If you volunteer such information during a call it may be captured in the recording and transcript, and will be deleted on the schedule in section 11.

From clients

Account details (name, business name, email, phone, business address), business information you enter for your AI Receptionist to use (services, prices, opening hours, staff names, policies), Google Calendar access where you connect it, and billing and usage records.

From website visitors

Standard server logs, including IP address and browser type, retained briefly for security and diagnostics. We do not run analytics or advertising trackers.

5. Why we process, and our legal basis

For people in the UK, EU, and other jurisdictions requiring a stated legal basis:

PurposeLegal basis
Answering and handling calls on a client's behalfProcessed on the client's instructions; the client determines the basis, generally their legitimate interests in operating their business, or consent where required
Recording callsConsent of the caller, obtained by disclosure at the start of the call and the opportunity to end it; and the client's own legal basis as controller
Booking and managing appointmentsPerformance of a contract between the caller and the business, or the business's legitimate interests
Operating a client's account and billing themPerformance of our contract with the client
Security, fraud prevention, and diagnosing faultsOur legitimate interests in a secure, working service
Complying with tax, accounting and legal obligationsLegal obligation

We do not use call content for advertising. We do not sell or share personal information, as those terms are defined under United States state privacy laws.

We do not use client data, caller data, call audio or transcripts to train AI models, and our contracts with providers prohibit them from doing so.

6. Automated processing

Our AI Receptionist is an AI system and handles calls without a human involved. It books, reschedules and cancels appointments automatically.

This does not produce legal effects or similarly significant effects on callers within the meaning of Article 22 of the UK and EU GDPR. Where a caller wants a human instead, the AI Receptionist will transfer them if the business has configured a transfer number, or take a message so the business can call back.

7. Google user data

Where a client connects their Google Calendar, we request the minimum access needed.

What we access: events in the calendar the client selects.

Why: so the AI Receptionist can check when the business is genuinely free before offering a caller a time, and can create, reschedule and cancel appointments booked by phone.

What we store: an encrypted access credential, the identifier of the connected calendar, and identifiers of events we create. Credentials are encrypted at rest with AES-256-GCM and are not accessible to our workflow automation, which requests short-lived tokens through an internal broker instead.

What we do not do: we do not read calendar events for any purpose beyond availability and appointment management; we do not transfer Google user data to third parties except as needed to provide this feature; we do not use it for advertising; we do not use it to train AI models; and no human at OnFrontBase reads calendar contents except where required to diagnose a fault the client has reported, or for security or legal reasons.

OnFrontBase's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

A client can disconnect their calendar at any time from the portal. Doing so revokes our access at Google and deletes the stored credential.

8. Sub-processors

ProviderFunctionProcessing location
ElevenLabsVoice synthesis, speech recognition, conversation handling; call audio and transcriptsUnited States
AnthropicAI model generating the receptionist's replies, accessed through ElevenLabsUnited States
Amazon Web ServicesMay host the AI model used by our AI Receptionist, where our voice provider serves it through AWSUnited States
TwilioTelephone numbers, call routing, call metadataUnited States
SupabaseDatabase and recording storageUnited States (us-east-1)
VercelApplication hostingUnited States
HostingerServer hosting our workflow automationIndia
GoogleCalendar access, where a client connects itUnited States
ZohoBusiness emailIndia

Each provider processes personal information only as needed for its function and is bound by contract.

We will update this list before engaging a new provider that handles personal information. Clients may object to a new sub-processor as set out in their services agreement.

9. Where your information goes

This service moves personal information across borders. Please read this section.

Our databases and recording storage are in the United States. Our application hosting is in the United States. Voice processing and AI generation occur in the United States.

Our workflow automation runs on a server in India. Call transcripts, caller contact details, and appointment information pass through this server while a call is processed.

We operate from India and access data from India in the course of running and supporting the service.

For information originating in the UK or European Economic Area: the United States and India are not, in general, subject to a UK or European Commission adequacy decision covering these transfers. Where we transfer personal information from the UK or EEA, we rely on the Standard Contractual Clauses approved by the European Commission, and the UK International Data Transfer Addendum, together with an assessment of the safeguards in place. A copy of the relevant clauses is available on request.

For information originating elsewhere: we rely on the transfer mechanisms available under the applicable law, including consent, contractual necessity, or approved contractual clauses.

If cross-border transfer is not acceptable for your business, tell us before subscribing — some of it is structural to how the service works and cannot be changed.

10. Health information

Some of our clients are medical spas, aesthetic clinics and similar businesses. A call to such a business may reveal that a person is seeking a treatment, which in many jurisdictions is sensitive or special category information.

We treat all call content as potentially sensitive. Our AI Receptionist is not configured to ask about medical history, conditions, or clinical details, and clients are instructed not to configure it to do so.

Clients subject to HIPAA: if you are a covered entity or business associate under the United States Health Insurance Portability and Accountability Act, you must tell us before onboarding. Handling protected health information requires a Business Associate Agreement between us and equivalent agreements with our sub-processors. Do not use the service for protected health information unless we have signed a Business Associate Agreement with you.

Clients subject to state health privacy laws: several United States states — including Washington and Nevada — regulate consumer health data regardless of whether HIPAA applies, and some provide individuals a private right of action. If your business operates in such a state, tell us so we can agree the appropriate terms.

Special category data under UK and EU GDPR: where call content amounts to data concerning health, the client as controller is responsible for identifying a valid Article 9 condition. We process it only on the client's instructions.

11. How long we keep information

DataRetention
Call audio recordings90 days from the call, then permanently deleted
Full call transcripts and extracted call content90 days from the call, then permanently deleted
Call summaries, outcomes and appointment recordsFor the life of the client account
Caller name and phone numberFor the life of the client account
Demonstration call transcripts30 days, then deleted
Client account recordsFor the life of the account, then deleted within 90 days of closure except as below
Billing and tax recordsAs required by Indian tax and accounting law, currently up to 8 years
Security and server logs30 days

Deletion of audio and transcripts is automated and runs daily. Deleted recordings are removed from storage, not hidden or flagged.

Call summaries and appointment records are kept beyond 90 days because they are the business record our clients rely on. Summaries describe what a call was about; they are not a verbatim record, and the AI Receptionist is instructed not to include contact details in them.

When a client account closes, we delete or return their data as set out in their services agreement.

12. Call recording and consent

Recording is enabled by default and can be disabled by a client for their account.

Every call begins with a spoken disclosure that the caller is speaking to an AI assistant and that the call may be recorded. This disclosure is built into the service and cannot be removed or altered by a client. A caller who does not consent can end the call at that point.

Recording laws vary widely. Some jurisdictions require the consent of all parties; some require only one. Our clients are responsible for ensuring that recording calls to their business is lawful where they operate and where their callers are located, and for disabling recording where it is not.

13. Artificial intelligence disclosure

Our AI employees are artificial intelligence systems, not people. Callers are told so at the start of every call, before any substantive conversation, whatever name the business has chosen for its AI Receptionist.

This disclosure is provided to satisfy transparency obligations including Article 50 of the EU Artificial Intelligence Act and comparable requirements in other jurisdictions. It cannot be disabled by a client.

An AI Receptionist can make mistakes. It may mishear, misunderstand, or fail to complete a booking. Do not rely on a conversation with it as confirmation of anything important without checking with the business directly.

14. Demonstration calls

We operate demonstration lines that prospective clients can call to hear how our AI Receptionist works.

Demonstration calls are not recorded. A transcript is kept for 30 days so we can follow up with the enquiry, then deleted. The AI disclosure applies as it does to live calls.

15. Your rights

Your rights depend on where you live. We honour valid requests in accordance with applicable law and do not discriminate against anyone for exercising them.

Rights that may be available to you: to know what information we hold and obtain a copy; to have inaccurate information corrected; to have information deleted; to restrict or object to processing; to receive your information in a portable format; to withdraw consent; and, under United States state laws, to opt out of sale, sharing, targeted advertising and certain profiling — none of which we do.

If you are a caller: your relationship is with the business you telephoned, which is the controller. Send your request to that business, or to us at dhruv@onfrontbase.com and we will pass it on and assist them in responding. We will tell you which business holds your information where we lawfully can.

If you are a client: access, correct, export or delete your data through the portal, or contact us.

How to reach us: dhruv@onfrontbase.com. We will respond within one month, or sooner where the law requires. We may ask you to verify your identity. There is no charge unless a request is manifestly unfounded or excessive.

You may use an authorised agent where the law permits.

16. Complaints

If you are unhappy with how we have handled your information, contact us first at dhruv@onfrontbase.com and we will try to resolve it.

You also have the right to complain to a data protection authority:

  • UK: the Information Commissioner's Office
  • EEA: the supervisory authority in your country of residence, place of work, or where the issue arose
  • India: the Data Protection Board of India
  • Elsewhere: your local privacy or data protection regulator

You do not have to contact us first.

17. Security

  • Third-party access credentials are encrypted at rest using AES-256-GCM
  • Database access is restricted per client at the database level, so one client cannot read another's data
  • Recording storage is private; recordings are served only through short-lived signed links to authorised users
  • Requests between our systems are authenticated and signed
  • We use multi-factor authentication on the accounts that administer this service

We are a small operation. Our founder has administrative access to systems containing client and caller information, exercised only to operate, support and secure the service.

No system is perfectly secure. If a breach affects personal information we process, we will notify affected clients without undue delay so they can meet their own notification obligations, and we will notify regulators and individuals directly where the law requires us to.

18. Cookies

Our portal uses cookies only to keep you signed in and to keep the service secure. These are strictly necessary and do not require consent. We do not use analytics, advertising, or tracking cookies.

19. Children

Our service is not directed at children. We do not knowingly collect information from anyone under 16, or under the age of digital consent in your country where that is higher. If you believe a child's information has reached us, contact us and we will delete it.

20. Changes

We will update this policy when the service changes. The date at the top shows when it was last revised. Material changes affecting clients will be notified by email at least 30 days in advance where practicable.

21. Contact

dhruv@onfrontbase.com House No. 96, Siraspur Delhi 110042 India