Your privacy is our priority
We are committed to protecting your personal information and being transparent about how we collect, use, and safeguard your data.
Last updated: October 11, 2026
Executive Summary
Artificium AI operates Deskly and this website. This document provides a comprehensive overview of our data handling, privacy protections, and security measures. Our system is designed with privacy-by-design principles, ensuring that data protection considerations are embedded into every aspect of our service architecture.
We are a New Zealand company and handle personal information under the Privacy Act 2020. Because calls can include health information, we also follow the Health Information Privacy Code 2020. We maintain strict compliance with international privacy regulations including GDPR, CCPA, and PIPEDA, while providing transparent communication about how your data is collected, processed, stored, and protected.
We are committed to maintaining the highest standards of data protection and privacy compliance while delivering exceptional service quality. This document serves as your comprehensive guide to understanding our privacy practices and your rights.
Data Collection & Processing
We collect information you provide directly to us, such as when you fill in a form on this website, book a demo, use our services, or contact us for support. Our data collection practices are designed to be transparent, necessary, and respectful of your privacy.
Information We Collect
- Contact information (name, email, phone number)
- Used to reply to you and communicate with you
- Business information (company name, industry)
- Used to customize our services for your business
- Service usage data and interaction patterns
- Used to improve our services and provide better support
How We Use Your Information
- Service Delivery
- Provide and maintain our services, process transactions, and deliver customer support.
- Service Improvement
- Analyze usage patterns to improve our systems, develop new features, and enhance user experience.
- Communication
- Send important updates, respond to inquiries, and provide customer support.
- Security & Compliance
- Ensure the security of our platform, prevent fraud, and comply with legal obligations.
Phone Calls
When you phone a clinic that uses Deskly, our AI receptionist answers on the clinic’s behalf. We handle the call to provide the service to the clinic, and the clinic remains responsible for its patient information.
- What the call collects
- Your phone number, what you say on the call, and the details needed to book, change or cancel an appointment or take a message. This can include health information.
- Where it goes
- Bookings, changes and messages are saved in the clinic’s own booking system, such as Cliniko. Text confirmations are sent to your phone.
- Recordings and transcripts
- We do not keep our own copy of calls. Vapi may keep call recordings and transcripts; we can turn this off or shorten how long they are kept for each clinic. Make.com may keep short-term logs of the automations it runs. Everything else is saved in the clinic’s booking system.
Third-Party Services
We use the following services to run this website and our AI phone calls. They may store and process your information outside New Zealand.
- Google Analytics
- Measures how visitors use this website. It sets cookies and receives the pages you view, the buttons you click, whether you play the video or send a form, your device and browser, and your approximate location.
- EmailJS
- Delivers the contact and demo forms to our inbox. It receives everything you enter in the form.
- Vapi
- Runs our AI phone calls, using services such as Twilio (phone lines), Deepgram (speech to text), ElevenLabs (voice), and Google Gemini and OpenAI (language models). It receives your phone number and what you say on the call, and may keep recordings and transcripts.
- Make.com
- Receives the details from our phone calls through Vapi, looks up and updates appointments in the clinic’s booking system, and sends follow-up emails. It receives details such as your name, contact details, appointment and the reason you called.
Data Storage & Retention
We implement industry-leading security measures to protect your personal information from unauthorized access, alteration, disclosure, or destruction.
- Retention Policies
- We keep no copy of calls. Website enquiries stay in our email inbox until they are no longer needed, and you can ask us to delete them at any time.
- Monitoring
- Continuous monitoring and threat detection systems protect against security breaches.
- Compliance
- We maintain compliance with GDPR, CCPA, and other relevant privacy regulations.
Security Measures
We implement comprehensive security measures to protect your data throughout its lifecycle, from collection to deletion.
- Encryption in Transit
- Data sent to and from our services is encrypted with TLS.
- 24/7 Security Monitoring
- Continuous security monitoring systems analyze system behavior and network traffic for potential threats.
Privacy Compliance
We maintain comprehensive compliance with international privacy regulations and industry standards.
- GDPR Compliance
- Full compliance with EU General Data Protection Regulation requirements.
- CCPA Compliance
- Complete adherence to California Consumer Privacy Act standards.
- PIPEDA Compliance
- Compliance with Canadian Personal Information Protection and Electronic Documents Act.
- SOC 2 Type II
- Maintain SOC 2 Type II compliance for security, availability, and privacy controls.
Your Data Rights
You have certain rights regarding your personal information. We are committed to honoring these rights and will respond to your requests in a timely manner.
For information from a phone call, contact the clinic you called: your bookings and messages are in its booking system. We will help the clinic with your request.
- Access
- Request access to the personal information we hold about you.
- Correction
- Request correction of inaccurate or incomplete personal information.
- Deletion
- Request deletion of your personal information in certain circumstances.
- Portability
- Request a copy of your data in a portable format.
Data Breach Response
We maintain comprehensive incident response procedures to ensure rapid and effective response to any potential security incidents.
- Detection & Assessment
- 24/7 monitoring systems detect potential incidents with immediate assessment procedures.
- Containment
- Immediate containment strategies prevent further unauthorized access and limit data exposure.
- Notification
- Timely communication with affected parties within 72 hours of incident confirmation.
- Remediation
- Comprehensive remediation procedures address vulnerabilities and implement corrective measures.
Access Controls
We implement comprehensive access controls to ensure that only authorized personnel can access your data.
- Multi-Factor Authentication
- All administrative accounts require MFA using enterprise-grade authentication systems.
- Role-Based Access Control
- Users have access only to resources necessary for their specific job responsibilities.
- Audit Logging
- All administrative actions are comprehensively logged with detailed audit trails.
Data Minimization
We collect only the data necessary for providing our services and improving user experience.
- Necessity Assessment
- Every data collection activity undergoes rigorous necessity assessment.
- Proportionality Analysis
- Data collection is proportionate to stated business purposes.
- Relevance Validation
- All collected data must be directly relevant to specific business functions.
- Accuracy Assurance
- Comprehensive procedures ensure data accuracy and quality.
Continuous Improvement
We continuously enhance our privacy and security measures to address emerging threats and regulatory requirements.
- Regular Updates
- Comprehensive patch management ensures timely security updates and patches.
- Threat Monitoring
- Advanced threat monitoring systems identify emerging security risks.
- Regulatory Compliance
- Dedicated teams monitor regulatory developments across all jurisdictions.
- External Audits
- Regular third-party audits provide independent validation of our programs.
Contact Us
If you have any questions about this Privacy Policy or our data practices, please contact us.
Privacy Team
Email: team@deskly.co.nz
We will respond to your request within a week of receipt. If you are not satisfied with our response, you can complain to the Office of the Privacy Commissioner at privacy.org.nz.
Ready to get started?
If you have any questions about our services or how AI can benefit your business, feel free to reach out. We’re here to help you every step of the way.