Privacy Policy
Ringdown, by BCK Systems · Effective August 20, 2026
The short version
We answer, record and transcribe calls made to your business line, and we use what a caller tells us to book the appointment and hand you the details.
We do not sell personal information, and we have opted out of model training on every platform we run on.
As between you and us, your recordings and transcripts are yours. You can export them or ask us to delete them at any time.
Callers are told the line is recorded, in the greeting, on every call.
A cloned voice is used only on your own line, and only with written permission from the person speaking.
We are not a HIPAA business associate unless we have signed a business associate agreement with you.
The website itself keeps things light: our own analytics are anonymous and cookie-free, we do not sell or share visitor information, and the one advertising tag on the site measures our own Google ads.
01
Who this policy is about
Ringdown is operated by BCK Systems. This policy covers two different relationships. The first is with our clients: the businesses that hire us to answer their phone. The second is with their callers: the people who dial that business and end up speaking to a receptionist we built. For information a caller gives during a call, the business is the one deciding what gets collected and why, and we act on that business’s instructions. For account, billing and support information, we are acting for ourselves.
02
What we collect from our clients
The information you give us so we can build and run your line, and the records that come out of running it.
Business details: name, legal name, address, phone numbers, service area, hours, tax identifiers where texting registration requires them.
Contact details for you and anyone who should receive urgent calls: names, mobile numbers, email addresses.
What the receptionist needs to know: services, prices, policies, scripts, uploaded documents, links to your pages.
Voice recordings you send us for cloning, if you choose that option.
Credentials and connection tokens for systems you ask us to write into, such as a calendar or a booking system.
Billing information. Card details are handled by our payment processor and never stored on our systems.
03
What we collect from your callers
Only what a caller says on a call to your line, plus what the phone network provides.
Audio recording of the call and a written transcript of it.
The caller’s phone number, and the time and length of the call.
Whatever the caller provides in conversation: name, callback number, address, email, the reason for the call, urgency, and any other fields you asked us to capture.
Notes and outcomes: what was booked, what was quoted, what was promised, who the call was transferred to.
Text messages we send the caller on your behalf, such as an appointment confirmation, and their replies.
04
Where information comes from
Directly from you when you fill in the intake or email us. From your callers during a call. From your public website and business listings, when you ask us to pull details from them to save you typing. From systems you connect, such as a calendar returning its availability. And automatically from the phone network and our own logs, which record that a call happened, how long it lasted and whether anything failed.
05
Why we use it
For a short and specific list of purposes.
Answering, screening, routing and booking calls the way you configured.
Building and tuning your receptionist, including testing it against difficult calls before it goes live and correcting it afterwards.
Sending confirmations, reminders and follow-ups you have asked for, within the consent rules described in our SMS policy.
Giving you the record of each call, and the summaries and reports built from it.
Billing you, supporting you, keeping the service secure, investigating abuse, and meeting our legal obligations.
06
Recording, and telling callers about it
Every call your Ringdown line answers is recorded and transcribed. The greeting tells the caller so, in the same sentence as your business name, because twelve states require every party to a call to consent to recording and a growing number of states require disclosure when software is on the line. Doing it everywhere turns a fifty state question into one line of script. If a caller objects, they can ask for a person and we will stop. If a caller asks us to delete their recording, we will, and we will tell you we did.
07
Who we share it with
We do not sell personal information, and we do not share it for anyone else’s advertising. We use a small set of vendors to actually run the service, each with access only to what their part requires.
ElevenLabs, for the voice platform that speaks and listens on the call.
Large language model providers, which generate the receptionist’s side of the conversation.
Twilio, for the phone number, the call itself and text messaging.
The calendar, booking or CRM system you asked us to write into.
Cloud hosting and error monitoring for the software around all of it.
Stripe, for payments.
Professional advisers, and law enforcement or a court where we are legally required to respond.
A buyer, if the business is ever sold, under the same commitments made here.
08
AI models, and training
Your calls are used to run your line and to improve your line, and they are not used to train foundation models. It is worth being precise about how that is achieved rather than just promising it. The platforms we run on grant themselves, in their own terms, a broad and long-lived licence to use content passing through them in order to operate and improve their services, and each offers a way to opt out of using customer content for model training. We have exercised that opt-out on our accounts. Two honest caveats: an opt-out applies from the date it is made and does not reach backwards, and a platform still has to process your call in order to answer it, which is not the same thing as training on it. Where a vendor offers a zero-retention mode we can switch it on for your line on request, at some cost in features. Separately, we may use anonymous aggregated numbers about the service, such as average call length or how often calls transfer, to improve Ringdown generally. Those do not identify you, your callers or your business.
09
How long we keep it
Recordings and transcripts are kept for twelve months by default, then deleted. The voice platform’s own default is longer than that, so we turn it down to twelve months on every line we build. You can ask for a shorter window, a longer one, or for recording to be switched off entirely and transcripts kept alone. Account and billing records are kept for seven years because tax law requires it. Voice cloning samples are deleted once the voice is built unless you ask us to keep them for retuning. When you leave, you have thirty days to export everything, and we delete your call data within sixty days of the account closing, other than what we must keep by law or in encrypted backups that age out on their own schedule.
10
Cloned voices
If you ask us to answer in your voice, we use the recordings you send only to build and run the voice on your own line. We require your written confirmation that the voice is yours or that you have the speaker’s written permission. We do not use it on any other client’s line, we do not license it to anyone, and we delete the voice and its source audio on request or when your account closes. If the person whose voice it is withdraws permission, tell us and we will switch the line to a library voice the same day.
11
Text messages
When your plan includes confirmations, we text the caller on your behalf from a number registered to your business. Callers can reply STOP to any message and we stop, permanently, and record it. We do not send marketing texts on your behalf without written consent collected by you, and we will not set up a campaign that we think crosses that line. Message and data rates apply for the recipient. A caller opts in by giving the receptionist their mobile number on the call and agreeing to the text, which is the only way a number enters the program; we do not import, buy or rent numbers. No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Text messaging originator opt-in data and consent are not shared with any third parties. The carriers and messaging platform named in section 07 transmit the message for us and receive only what delivering it requires, which is not sharing for marketing. The full policy is on the SMS Consent page, linked at the bottom of this one.
12
Security
Call audio and transcripts are encrypted in transit and at rest. Access is limited to the people who need it to run the service, on accounts with multi-factor authentication, and we log who looked at what. Connection tokens for your systems are stored encrypted and scoped as narrowly as the system allows. No system is perfect and we will not claim otherwise. If a breach affects your information, we will tell you without undue delay and give you what you need for your own notifications.
13
Your rights
Depending on where you live, you may have the right to know what we hold, get a copy, correct it, delete it, limit how it is used, and not be discriminated against for asking. California residents have these rights under the CCPA as amended by the CPRA, including the right to know what categories we collect and disclose, and the right to opt out of sale or sharing, which is straightforward here because we do neither. Residents of other states with similar laws have comparable rights. Where the GDPR or UK GDPR applies, our clients are the controller for call content and we are their processor, so a caller request should reach the business, though we will act on it either way. To exercise any of this, use the contact details below. We may need to verify who you are, and we will not charge you for a reasonable request.
14
If you are a caller, not a client
You can ask us to delete the recording and transcript of your call, to correct what was written down, to stop texting you, and never to be called back. Say it on the call and the receptionist records it, or contact us afterwards. We will pass the request to the business you called and honor it on our side regardless of what they do.
15
Health, legal and financial information
Callers volunteer sensitive things on the phone, and a receptionist cannot always stop them. We are not a HIPAA business associate and Ringdown must not be used to create, receive or store protected health information unless we have signed a business associate agreement with you first. Ask us and we will discuss it. For law firms, understand that call content passes through the vendors listed above, which may affect how you treat privilege; talk to us before putting Ringdown on an intake line where that matters. We do not knowingly ask for social security numbers, card numbers or medical detail, and we can configure the receptionist to refuse them.
16
Children
Ringdown is sold to businesses, not to consumers, and it is not intended for anyone under sixteen. Some of our clients are childcare centers, so a call may include a child’s first name and age. That information is handled as the center’s data, kept to what the center asked us to capture, and deleted on the same schedule as everything else.
17
If you visit our website
Most of this policy is about phone calls, because that is the product. The website collects far less, and it is worth stating exactly what.
Our own analytics are first-party and anonymous. We count which pages and sections get read and for how long, in rounded ranges, and we record use of tools like the pricing calculator, including the figures entered. A random identifier groups one visit's activity together and is discarded when you close the tab. These events carry no cookies, no IP address and no browser details, and we cannot connect one visit to the next.
If you arrive from a link in an email we sent to your business, the link may carry a tag that tells us the visit came from you. It identifies no one we were not already writing to, and we use it only to know which of our messages was worth your click.
We advertise on Google, and a Google tag on the site sets cookies to measure whether those ads lead to calls. That measurement serves our own campaigns. Blocking it with a content or cookie blocker does not affect the site.
Our hosting platform counts page views without cookies, the intake form may run an anti-bot check from Cloudflare, and standard server logs exist, as they do everywhere, aging out on their own schedule.
If you talk to the voice concierge on the site, that conversation works like a call to one of our lines: it is recorded and transcribed, the rest of this policy applies to it, and a callback number you leave is used to call you back.
We do not sell website visitor information, and we do not share it for anyone else's advertising. Opt-out preference signals such as Global Privacy Control ask us to stop selling or sharing; since we do neither, the signal changes nothing, and neither does Do Not Track. The answer is already no.
18
Changes to this policy
If we change something material, we will email the address on your account at least thirty days before it takes effect, and update the date at the top. Continuing to use the service after that date means the new version applies. Older versions are available on request.
Questions, or a request about your data
Email privacy@ringdown.io. The number published on our website is a demonstration line answered by a sample receptionist, so email is the way to reach a person here. We answer data requests within thirty days, and sooner where the law requires it. If you are a caller rather than a Ringdown client, tell us the business you called and roughly when, and we will pass your request to them and act on it ourselves.