Privacy Policy

Privacy Policy

Privacy Policy

This Privacy Policy was last updated on 2 May 2026.

Purpose and Scope

Summit AI Limited (“Summit”, “we”, “us”, or “our”) provides AI-powered phone answering, appointment scheduling, and administrative workflow automation services designed specifically for healthcare clinics and allied health practices. We are committed to maintaining strict privacy, security, and confidentiality standards for all personal information processed across our platform.


This Privacy Policy does not limit your existing rights under relevant privacy and data protection laws.

Purpose of This Policy & Who It Applies To

Summit is committed to protecting the privacy of everyone who interacts with our services. This Privacy Policy explains how Summit collects, holds, uses, discloses, transfers, and safeguards personal information across our operations, website (www.usesummitai.com), applications, and automated phone answering platform (collectively, the “Services”). By using our services, you acknowledge that you have read, understood, and agree to these terms.

This policy applies to all individuals whose data we process, including customers, end users, website visitors, and partners across all services provided by Summit:

  • Clinic Customers (Data Controllers / Primary Agencies): Healthcare practices, medical clinics, allied health providers, practitioners, and administrative staff who utilize our Services.

  • End Users & Patients: Callers and patients whose personal data or voice interactions are processed through our platform on behalf of our Clinic Customers.

  • Website Visitors & Leads: Individuals who browse our website, request demonstrations, or communicate with our sales and support teams.

  • Business Partners & Vendors: Sub-processors and third-party technology integration partners.


Regulatory Alignment & Legal Roles
Summit operates in full compliance with applicable privacy and health data legislation across our primary operating jurisdictions, including the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth) and the New Zealand Information Privacy Principles (NZPPs) under the Privacy Act 2020.

  • Australia: The healthcare clinic is the primary APP Entity and Data Controller. Summit acts as a Service Provider / Data Processor processing data solely on the clinic’s documented instructions.

  • New Zealand: The healthcare clinic is the Principal Agency. Summit acts as a Secondary Agency under Sections 11 and 12 of the Privacy Act 2020. Information held by Summit is legally treated as being held by the primary clinic agency, meaning data processing by Summit does not constitute an unauthorized third-party disclosure by the clinic.

  • United Kingdom & European Union: The clinic is the Data Controller. Summit operates strictly as a Data Processor under UK/EU GDPR guidelines (Article 28).


Collection Of Personal Information


We collect personal data directly when individuals interact with our services. We collect this data in three main ways: directly from individuals, automatically during service use, and from third-party systems.

Personal Information We Collect

We collect and process only the personal information necessary to provide, maintain, secure, and improve our AI-powered phone answering services:

A. Customer & Account Information

  • Business Data: Clinic legal entity name, business address, phone numbers, primary contact details, and clinic staff names/emails.

  • Credentials & Integration Tokens: Encrypted API access keys for connected Practice Management Systems.

  • Financial Data: Invoicing details, transaction history, and credit card credentials (processed securely via Airwallex; raw card numbers are never stored on Summit servers).

B. Patient & Call Interaction Data (Processed on Behalf of Clinics)

  • Caller Identifiers: Patient full name, phone number, date of birth, and email address.

  • Interaction Data: Phone call audio recordings, real-time speech-to-text transcripts, call duration, timestamp metadata, and caller intent tags.

  • Health Information: Appointment reasons, practitioner preferences, clinical triage notes, or health context voluntarily disclosed by callers during phone interactions.

C. Automatically Collected & Technical Data

  • Log Data: IP addresses, browser types, operating systems, mobile network data, access times, and error/latency logs.

  • Cookies & Tracking: Essential session cookies, analytical tracking pixels (Google Analytics), and first-party attribution tokens.


Note: You may choose not to disclose requested information to us. However, doing so may restrict or prevent us from providing our Services to you or your clinic.

How We Use Personal Data

We process personal data to provide and improve our services, communicate effectively, and meet legal requirements. Specifically, we process data to:

  • Deliver requested Services and automate appointment routing into connected Practice Management Systems,

  • Market our Services (with consent) and send operational updates or newsletters via text or email (opt-out available at any time),

  • Analyze the effectiveness of marketing campaigns and platform adoption,

  • Evaluate service utilization, platform latency, and system performance,

  • Conduct internal personnel training related to customer support and service delivery,

  • Ensure full compliance with laws and regulations across applicable jurisdictions,

  • Maintain open communication lines with clinics for support, technical assistance, or dispute resolution,

  • Manage billing, invoicing, and payment processing via authorized payment gateways,

  • Enforce adherence to our Terms of Service and protect against platform abuse or fraud.


Legal Basis for Processing

We process personal data only when we have a valid legal ground under applicable privacy legislation (including the Privacy Act 1988 (Cth) and the New Zealand Privacy Act 2020):

  • Contractual Necessity: Processing is required to fulfil our service agreements with Healthcare Clinics, manage client accounts, process subscription payments, deliver technical support, send post-call administrative alerts, and route appointment bookings into connected Practice Management Systems.

  • Consent (Clinic & Caller): We process data based on explicit or implied consent for:

    • Inbound Call Reception: Processing caller voice audio, speech-to-text transcripts, and scheduling parameters (obtained via upfront call disclosures and clinic customer agreements).

    • Marketing & Cookies: Sending promotional communications and using non-essential analytical cookies (which can be withdrawn or opted out of at any time).

  • Legitimate Interests: Processing is necessary for our legitimate operational interests, provided these do not override individual privacy rights. This includes maintaining web application firewalls, enforcing rate-limiting, preventing system fraud, and evaluating platform latency to optimize AI phone answering performance.

  • Legal & Regulatory Obligations: Processing is required to comply with statutory accounting, tax compliance, health record retention laws, and responding to lawful requests from regulatory authorities (such as the Office of the Australian Information Commissioner or the New Zealand Privacy Commissioner).

Sharing & Disclosure of Data

Summit AI does not sell, rent, or trade personal or sensitive health data to third parties. We only share, disclose, or transfer personal data as necessary to deliver our Services, satisfy contractual commitments with Healthcare Clinics, or comply with statutory legal obligations.

We disclose personal information under the following strict operational boundaries:

  • Authorized Internal Use: Access to client and patient data is strictly limited to authorized Summit personnel (such as senior engineering and dedicated technical support staff) on a verified need-to-know basis. All internal access is secured via Multi-Factor Authentication (MFA) and Role-Based Access Controls (RBAC).

  • Third-Party Sub-Processors & Infrastructure: To deliver our reception services, we rely on vetted sub-processors (such as OpenAI and Telnyx) for specialized technical functions like call routing, AI voice processing, and practice management integrations.

  • Cross-Border Data Transfers (APP 8 / NZPP 12): Where service delivery requires processing through cloud infrastructure located outside Australia or New Zealand, transfers are governed by our providers' commercial API terms and online Data Processing Agreements. We configure our integrations to utilize enterprise API endpoints that enforce zero-retention policies and strictly prohibit data from being used for AI model training, aligning with the standards required by the Australian Privacy Principles and New Zealand Information Privacy Principles.

  • Legal & Regulatory Compliance: We may disclose personal data if required to do so by applicable laws, court orders, subpoenas, or lawful requests from regulatory authorities, or to enforce our Terms of Service and safeguard system security.

Live Sub-Processor Directory: For a real-time, comprehensive list of our third-party sub-processors, processing functions, and data residency locations, please visit our live Trust Centre.


Data Retention & Accuracy


Retention Periods

We retain personal data only as long as necessary.

  • Call Recordings & Transcripts: Our system automatically executes a hard deletion of all call recordings and transcripts 30 days post-call. If you cancel your trial or subscription before 30 days, active production deletion is triggered immediately upon cancellation.

  • Workflow & Integration Logs (Make.com): Automatically deleted on rolling 30-day cycles.

  • Website Logs: Automatically deleted on rolling 90-day cycles.

  • Account Information: Retained for the duration of the active subscription; complete deletion across historical system backups is finalised within a maximum of 30 days post-cancellation.

Purpose and Scope
Summit AI Limited (“Summit”, “we”, “us”, or “our”) provides AI-powered phone answering, appointment scheduling, and administrative workflow automation services designed specifically for healthcare clinics and allied health practices. We are committed to maintaining strict privacy, security, and confidentiality standards for all personal information processed across our platform.


This Privacy Policy does not limit your existing rights under relevant privacy and data protection laws.

Purpose of This Policy & Who It Applies To

Summit is committed to protecting the privacy of everyone who interacts with our services. This Privacy Policy explains how Summit collects, holds, uses, discloses, transfers, and safeguards personal information across our operations, website (www.usesummitai.com), applications, and automated phone answering platform (collectively, the “Services”). By using our services, you acknowledge that you have read, understood, and agree to these terms.

This policy applies to all individuals whose data we process, including customers, end users, website visitors, and partners across all services provided by Summit:

  • Clinic Customers (Data Controllers / Primary Agencies): Healthcare practices, medical clinics, allied health providers, practitioners, and administrative staff who utilize our Services.

  • End Users & Patients: Callers and patients whose personal data or voice interactions are processed through our platform on behalf of our Clinic Customers.

  • Website Visitors & Leads: Individuals who browse our website, request demonstrations, or communicate with our sales and support teams.

  • Business Partners & Vendors: Sub-processors and third-party technology integration partners.


Regulatory Alignment & Legal Roles
Summit operates in full compliance with applicable privacy and health data legislation across our primary operating jurisdictions, including the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth) and the New Zealand Information Privacy Principles (NZPPs) under the Privacy Act 2020.

  • Australia: The healthcare clinic is the primary APP Entity and Data Controller. Summit acts as a Service Provider / Data Processor processing data solely on the clinic’s documented instructions.

  • New Zealand: The healthcare clinic is the Principal Agency. Summit acts as a Secondary Agency under Sections 11 and 12 of the Privacy Act 2020. Information held by Summit is legally treated as being held by the primary clinic agency, meaning data processing by Summit does not constitute an unauthorized third-party disclosure by the clinic.

  • United Kingdom & European Union: The clinic is the Data Controller. Summit operates strictly as a Data Processor under UK/EU GDPR guidelines (Article 28).


Collection Of Personal Information


We collect personal data directly when individuals interact with our services. We collect this data in three main ways: directly from individuals, automatically during service use, and from third-party systems.

Personal Information We Collect

We collect and process only the personal information necessary to provide, maintain, secure, and improve our AI-powered phone answering services:

A. Customer & Account Information

  • Business Data: Clinic legal entity name, business address, phone numbers, primary contact details, and clinic staff names/emails.

  • Credentials & Integration Tokens: Encrypted API access keys for connected Practice Management Systems.

  • Financial Data: Invoicing details, transaction history, and credit card credentials (processed securely via Airwallex; raw card numbers are never stored on Summit servers).

B. Patient & Call Interaction Data (Processed on Behalf of Clinics)

  • Caller Identifiers: Patient full name, phone number, date of birth, and email address.

  • Interaction Data: Phone call audio recordings, real-time speech-to-text transcripts, call duration, timestamp metadata, and caller intent tags.

  • Health Information: Appointment reasons, practitioner preferences, clinical triage notes, or health context voluntarily disclosed by callers during phone interactions.

C. Automatically Collected & Technical Data

  • Log Data: IP addresses, browser types, operating systems, mobile network data, access times, and error/latency logs.

  • Cookies & Tracking: Essential session cookies, analytical tracking pixels (Google Analytics), and first-party attribution tokens.


Note: You may choose not to disclose requested information to us. However, doing so may restrict or prevent us from providing our Services to you or your clinic.

How We Use Personal Data

We process personal data to provide and improve our services, communicate effectively, and meet legal requirements. Specifically, we process data to:

  • Deliver requested Services and automate appointment routing into connected Practice Management Systems,

  • Market our Services (with consent) and send operational updates or newsletters via text or email (opt-out available at any time),

  • Analyze the effectiveness of marketing campaigns and platform adoption,

  • Evaluate service utilization, platform latency, and system performance,

  • Conduct internal personnel training related to customer support and service delivery,

  • Ensure full compliance with laws and regulations across applicable jurisdictions,

  • Maintain open communication lines with clinics for support, technical assistance, or dispute resolution,

  • Manage billing, invoicing, and payment processing via authorized payment gateways,

  • Enforce adherence to our Terms of Service and protect against platform abuse or fraud.


Legal Basis for Processing

We process personal data only when we have a valid legal ground under applicable privacy legislation (including the Privacy Act 1988 (Cth) and the New Zealand Privacy Act 2020):

  • Contractual Necessity: Processing is required to fulfil our service agreements with Healthcare Clinics, manage client accounts, process subscription payments, deliver technical support, send post-call administrative alerts, and route appointment bookings into connected Practice Management Systems.

  • Consent (Clinic & Caller): We process data based on explicit or implied consent for:

    • Inbound Call Reception: Processing caller voice audio, speech-to-text transcripts, and scheduling parameters (obtained via upfront call disclosures and clinic customer agreements).

    • Marketing & Cookies: Sending promotional communications and using non-essential analytical cookies (which can be withdrawn or opted out of at any time).

  • Legitimate Interests: Processing is necessary for our legitimate operational interests, provided these do not override individual privacy rights. This includes maintaining web application firewalls, enforcing rate-limiting, preventing system fraud, and evaluating platform latency to optimize AI phone answering performance.

  • Legal & Regulatory Obligations: Processing is required to comply with statutory accounting, tax compliance, health record retention laws, and responding to lawful requests from regulatory authorities (such as the Office of the Australian Information Commissioner or the New Zealand Privacy Commissioner).



Sharing & Disclosure of Data

Summit AI does not sell, rent, or trade personal or sensitive health data to third parties. We only share, disclose, or transfer personal data as necessary to deliver our Services, satisfy contractual commitments with Healthcare Clinics, or comply with statutory legal obligations.

We disclose personal information under the following strict operational boundaries:

  • Authorized Internal Use: Access to client and patient data is strictly limited to authorized Summit personnel (such as senior engineering and dedicated technical support staff) on a verified need-to-know basis. All internal access is secured via Multi-Factor Authentication (MFA) and Role-Based Access Controls (RBAC).

  • Third-Party Sub-Processors & Infrastructure: To deliver our reception services, we rely on vetted sub-processors (such as OpenAI and Telnyx) for specialized technical functions like call routing, AI voice processing, and practice management integrations.

  • Cross-Border Data Transfers (APP 8 / NZPP 12): Where service delivery requires processing through cloud infrastructure located outside Australia or New Zealand, transfers are governed by our providers' commercial API terms and online Data Processing Agreements. We configure our integrations to utilize enterprise API endpoints that enforce zero-retention policies and strictly prohibit data from being used for AI model training, aligning with the standards required by the Australian Privacy Principles and New Zealand Information Privacy Principles.

  • Legal & Regulatory Compliance: We may disclose personal data if required to do so by applicable laws, court orders, subpoenas, or lawful requests from regulatory authorities, or to enforce our Terms of Service and safeguard system security.

Live Sub-Processor Directory: For a real-time, comprehensive list of our third-party sub-processors, processing functions, and data residency locations, please visit our live Trust Centre.


Data Retention & Accuracy


Retention Periods

We retain personal data only as long as necessary.

  • Call Recordings & Transcripts: Our system automatically executes a hard deletion of all call recordings and transcripts 30 days post-call. If you cancel your trial or subscription before 30 days, active production deletion is triggered immediately upon cancellation.

  • Workflow & Integration Logs (Make.com): Automatically deleted on rolling 30-day cycles.

  • Website Logs: Automatically deleted on rolling 90-day cycles.

  • Account Information: Retained for the duration of the active subscription; complete deletion across historical system backups is finalised within a maximum of 30 days post-cancellation.


Security & Encryption Controls


Summit implements multi-layered technical, administrative, and physical security measures to safeguard personal data:

  • Encryption in Transit: All network traffic moving between callers, browsers, Summit systems, and API sub-processors is encrypted using TLS 1.3 / HTTPS.

  • Encryption at Rest: All sensitive database records, call recordings, and transcripts are encrypted at rest using AES-256 bit encryption.

  • Credential Protection: Practice Management System API keys and integration tokens are encrypted via AES-256 prior to database storage and are never logged or displayed in raw text.

  • Access Control: Internal staff access to production environments is strictly limited via Multi-Factor Authentication (MFA) and Single Sign-On (SSO) under the principle of least privilege.

  • Network Defense: Production hosting environments utilize Web Application Firewalls (WAF), automated rate-limiting, and continuous intrusion logging.


Your Rights


We respect your rights to access, rectify, erase, or restrict, port and object to the use of your personal data. Under applicable data protection laws, you have several rights regarding your personal data. These rights include:

  • Right of Access: You may request a copy and access your personal data that we hold.

  • Right to Rectification: You may ask us to correct any personal information that is inaccurate or incomplete.

  • Right to Erasure: You may request deletion of your personal data in certain circumstances, subject to applicable legal retention obligations.

  • Right to Restrict Processing: You may request that we limit how we process your personal data in specific situations.

  • Right to Data Portability: You may request your personal data in a structured, portable, and machine-readable format, and have it transferred to another provider where applicable.

  • Right to Object: You may object to certain processing activities of your personal data, including marketing.


Handling Patient Requests

Because Summit is a Data Processor / Secondary Agency:

  • Direct Inquiries: Patients seeking to exercise their privacy rights regarding call recordings or health records must contact their healthcare clinic (the Data Controller) directly.

  • Forwarding Protocol: If a patient submits a request directly to Summit, we will log the request and forward it to the relevant clinic within 3 business days.

  • Technical Execution: Summit will technically execute data extractions, corrections, or purges within 1-2 business days following verified, written instructions from the clinic controller.

Complaints & Escalations
If you have questions, concerns, or wish to lodge a complaint, please contact our Privacy Officer, contact details below. We will investigate and respond promptly. If you are not satisfied, you can escalate your complaint to the relevant data protection authority in New Zealand or Australia.

Privacy Policy Updates

We may review and update this Privacy Policy periodically. Customers will be notified of any material changes via email, and the updated policy will be published on our website with the effective date indicated. For minor updates, notifications may also be provided to our customers via our client portal.

If you have any questions or concerns about this Privacy Policy, please provide us with the full details of your concern along with any supporting documentation to:


GDPR Addendum

If you are located in the United Kingdom (“UK”) or the European Union (“EU”), and wish to use our website and/or Services, the GDPR applies to you. These additional terms (“GDPR Addendum”) apply to this and make up part of our Privacy Policy.

The UK Data Protection Act 2018 (“DPA”) and the EU General Data Protection Regulation (“EU GDPR”) were set up to control the collection, processing and transfer of UK and EU individuals’ personal data (as defined in the GDPR). The personal information described in the Summit Privacy Policy comes under the personal data in the GDPR. It is important to us that we comply with the GDPR when dealing with the personal data of UK and EU-based visitors to our website.

This GDPR Addendum was drafted to be concise and easy to understand. It does not outline in exhaustive detail all aspects of our collection and use of personal data. If you wish to have more information or need an explanation, please contact us. Your request should be sent to Rubin Saini, CEO of Summit AI.

For the purposes of the GDPR:

  • Summit is the data controller (as defined in the GDPR) when processing personal information.

  • Our third party vendors are the data processors when processing personal information.

Processing personal data

The personal information outlined in this Privacy Policy is the personal data that Summit may process. Any processing done will be to achieve the purposes set out in this Privacy Policy.

As permitted under the GDPR we can process your information for the purposes described in the body of the Privacy Policy by relying on one or more of the following lawful grounds:

  • You have agreed with us explicitly that we may process your information for a specific reason;

  • The processing of personal information is necessary to perform the agreement we have with you (or to take steps to enter into an agreement with you);

  • The processing is necessary for us to comply with our legal obligations; or

  • The processing is actually necessary for our legitimate interests, which include:
    (i) to protect our business interests;
    (ii) to ensure that complaints are appropriately investigated;
    (iii) to evaluate, develop or improve products and services we offer; or
    (iv) to keep you informed of relevant products and services, unless you indicate that you do not wish us to be kept updated. While we will generally rely on your specific consent to process special categories of personal data (i.e., ‘sensitive information’), in some cases (for example, relating to an alleged offence), we may need to use some information to comply with our legal obligations.

It is possible to use access and use our website without providing us with data. However some of our services will require you to provide us with your name and email address, for example if you sign up to any newsletters. If you choose not to divulge that information, we will be unable to provide you with our full services.

Your rights

The GDPR grants you certain rights in relation to your personal data. These include:

  • Right of access

  • Right to rectification

  • Right to erasure

  • Right to withdraw consent

  • Right to restrict processing

  • Right to object to processing

  • Rights related to automated decision making, including profiling

  • Right to data portability

  • The right to complain to a supervisory authority

If your personal data is used or obtained for direct marketing purposes, you have the right to object.

If you wish to exercise any of your rights listed above, please contact our Privacy Officer. If you are dissatisfied with how we deal with your request, you may refer your query to your local data protection supervisory authority e.g. in the United Kingdom, this is the Information Commissioner’s Office.

Children

It is not our intention to collect personal data from children under the age of 16. If you believe that a child under 16 has given us their personal data either through our website and/or by using our Services, please contact our Privacy Officer. If they can access it, then it is your responsibility to obtain the consent of any Guardian of any children who can access the website or the Services and you agree to do so.

International transfer of data

As Summit is based in New Zealand, the personal information that we collect through our website and our Services will be transferred to, and stored in, a country operating outside the United Kingdom or the European Economic Area (EEA). According to the GDPR, this transfer may only take place if the European Commission has decided that the country maintains an adequate level of protection. If this adequacy status is not granted to us we may transfer the personal data, so long as there are suitable safeguards.

The Summit Privacy Policy states that some of the personal information we collect is processed by third party data processors in other countries, including Australia. We will only transfer this data outside the United Kingdom or the EEA if that country has been given the adequacy status mentioned above, or if we have approved transfer instruments set up to protect your personal data. If you wish to know more, please contact us using the details in our Privacy Policy.

Data Retention Privacy Policy

We will only keep personal information for as long as is needed to achieve its purpose, or to comply with relevant law, whichever is longer.

Contacting us

Please contact us via the details as set out in our Privacy Policy.

Purpose and Scope
Summit AI Limited (“Summit”, “we”, “us”, or “our”) provides AI-powered phone answering, appointment scheduling, and administrative workflow automation services designed specifically for healthcare clinics and allied health practices. We are committed to maintaining strict privacy, security, and confidentiality standards for all personal information processed across our platform.


This Privacy Policy does not limit your existing rights under relevant privacy and data protection laws.

Purpose of This Policy & Who It Applies To

Summit is committed to protecting the privacy of everyone who interacts with our services. This Privacy Policy explains how Summit collects, holds, uses, discloses, transfers, and safeguards personal information across our operations, website (www.usesummitai.com), applications, and automated phone answering platform (collectively, the “Services”). By using our services, you acknowledge that you have read, understood, and agree to these terms.

This policy applies to all individuals whose data we process, including customers, end users, website visitors, and partners across all services provided by Summit:

  • Clinic Customers (Data Controllers / Primary Agencies): Healthcare practices, medical clinics, allied health providers, practitioners, and administrative staff who utilize our Services.

  • End Users & Patients: Callers and patients whose personal data or voice interactions are processed through our platform on behalf of our Clinic Customers.

  • Website Visitors & Leads: Individuals who browse our website, request demonstrations, or communicate with our sales and support teams.

  • Business Partners & Vendors: Sub-processors and third-party technology integration partners.


Regulatory Alignment & Legal Roles
Summit operates in full compliance with applicable privacy and health data legislation across our primary operating jurisdictions, including the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth) and the New Zealand Information Privacy Principles (NZPPs) under the Privacy Act 2020.

  • Australia: The healthcare clinic is the primary APP Entity and Data Controller. Summit acts as a Service Provider / Data Processor processing data solely on the clinic’s documented instructions.

  • New Zealand: The healthcare clinic is the Principal Agency. Summit acts as a Secondary Agency under Sections 11 and 12 of the Privacy Act 2020. Information held by Summit is legally treated as being held by the primary clinic agency, meaning data processing by Summit does not constitute an unauthorized third-party disclosure by the clinic.

  • United Kingdom & European Union: The clinic is the Data Controller. Summit operates strictly as a Data Processor under UK/EU GDPR guidelines (Article 28).


Collection Of Personal Information


We collect personal data directly when individuals interact with our services. We collect this data in three main ways: directly from individuals, automatically during service use, and from third-party systems.

Personal Information We Collect

We collect and process only the personal information necessary to provide, maintain, secure, and improve our AI-powered phone answering services:

A. Customer & Account Information

  • Business Data: Clinic legal entity name, business address, phone numbers, primary contact details, and clinic staff names/emails.

  • Credentials & Integration Tokens: Encrypted API access keys for connected Practice Management Systems.

  • Financial Data: Invoicing details, transaction history, and credit card credentials (processed securely via Airwallex; raw card numbers are never stored on Summit servers).

B. Patient & Call Interaction Data (Processed on Behalf of Clinics)

  • Caller Identifiers: Patient full name, phone number, date of birth, and email address.

  • Interaction Data: Phone call audio recordings, real-time speech-to-text transcripts, call duration, timestamp metadata, and caller intent tags.

  • Health Information: Appointment reasons, practitioner preferences, clinical triage notes, or health context voluntarily disclosed by callers during phone interactions.

C. Automatically Collected & Technical Data

  • Log Data: IP addresses, browser types, operating systems, mobile network data, access times, and error/latency logs.

  • Cookies & Tracking: Essential session cookies, analytical tracking pixels (Google Analytics), and first-party attribution tokens.


Note: You may choose not to disclose requested information to us. However, doing so may restrict or prevent us from providing our Services to you or your clinic.

How We Use Personal Data

We process personal data to provide and improve our services, communicate effectively, and meet legal requirements. Specifically, we process data to:

  • Deliver requested Services and automate appointment routing into connected Practice Management Systems,

  • Market our Services (with consent) and send operational updates or newsletters via text or email (opt-out available at any time),

  • Analyze the effectiveness of marketing campaigns and platform adoption,

  • Evaluate service utilization, platform latency, and system performance,

  • Conduct internal personnel training related to customer support and service delivery,

  • Ensure full compliance with laws and regulations across applicable jurisdictions,

  • Maintain open communication lines with clinics for support, technical assistance, or dispute resolution,

  • Manage billing, invoicing, and payment processing via authorized payment gateways,

  • Enforce adherence to our Terms of Service and protect against platform abuse or fraud.


Legal Basis for Processing

We process personal data only when we have a valid legal ground under applicable privacy legislation (including the Privacy Act 1988 (Cth) and the New Zealand Privacy Act 2020):

  • Contractual Necessity: Processing is required to fulfil our service agreements with Healthcare Clinics, manage client accounts, process subscription payments, deliver technical support, send post-call administrative alerts, and route appointment bookings into connected Practice Management Systems.

  • Consent (Clinic & Caller): We process data based on explicit or implied consent for:

    • Inbound Call Reception: Processing caller voice audio, speech-to-text transcripts, and scheduling parameters (obtained via upfront call disclosures and clinic customer agreements).

    • Marketing & Cookies: Sending promotional communications and using non-essential analytical cookies (which can be withdrawn or opted out of at any time).

  • Legitimate Interests: Processing is necessary for our legitimate operational interests, provided these do not override individual privacy rights. This includes maintaining web application firewalls, enforcing rate-limiting, preventing system fraud, and evaluating platform latency to optimize AI phone answering performance.

  • Legal & Regulatory Obligations: Processing is required to comply with statutory accounting, tax compliance, health record retention laws, and responding to lawful requests from regulatory authorities (such as the Office of the Australian Information Commissioner or the New Zealand Privacy Commissioner).



Sharing & Disclosure of Data

Summit AI does not sell, rent, or trade personal or sensitive health data to third parties. We only share, disclose, or transfer personal data as necessary to deliver our Services, satisfy contractual commitments with Healthcare Clinics, or comply with statutory legal obligations.

We disclose personal information under the following strict operational boundaries:

  • Authorized Internal Use: Access to client and patient data is strictly limited to authorized Summit personnel (such as senior engineering and dedicated technical support staff) on a verified need-to-know basis. All internal access is secured via Multi-Factor Authentication (MFA) and Role-Based Access Controls (RBAC).

  • Third-Party Sub-Processors & Infrastructure: To deliver our reception services, we rely on vetted sub-processors (such as OpenAI and Telnyx) for specialized technical functions like call routing, AI voice processing, and practice management integrations.

  • Cross-Border Data Transfers (APP 8 / NZPP 12): Where service delivery requires processing through cloud infrastructure located outside Australia or New Zealand, transfers are governed by our providers' commercial API terms and online Data Processing Agreements. We configure our integrations to utilize enterprise API endpoints that enforce zero-retention policies and strictly prohibit data from being used for AI model training, aligning with the standards required by the Australian Privacy Principles and New Zealand Information Privacy Principles.

  • Legal & Regulatory Compliance: We may disclose personal data if required to do so by applicable laws, court orders, subpoenas, or lawful requests from regulatory authorities, or to enforce our Terms of Service and safeguard system security.

Live Sub-Processor Directory: For a real-time, comprehensive list of our third-party sub-processors, processing functions, and data residency locations, please visit our live Trust Centre.


Data Retention & Accuracy


Retention Periods

We retain personal data only as long as necessary.

  • Call Recordings & Transcripts: Our system automatically executes a hard deletion of all call recordings and transcripts 30 days post-call. If you cancel your trial or subscription before 30 days, active production deletion is triggered immediately upon cancellation.

  • Workflow & Integration Logs (Make.com): Automatically deleted on rolling 30-day cycles.

  • Website Logs: Automatically deleted on rolling 90-day cycles.

  • Account Information: Retained for the duration of the active subscription; complete deletion across historical system backups is finalised within a maximum of 30 days post-cancellation.


Security & Encryption Controls


Summit implements multi-layered technical, administrative, and physical security measures to safeguard personal data:

  • Encryption in Transit: All network traffic moving between callers, browsers, Summit systems, and API sub-processors is encrypted using TLS 1.3 / HTTPS.

  • Encryption at Rest: All sensitive database records, call recordings, and transcripts are encrypted at rest using AES-256 bit encryption.

  • Credential Protection: Practice Management System API keys and integration tokens are encrypted via AES-256 prior to database storage and are never logged or displayed in raw text.

  • Access Control: Internal staff access to production environments is strictly limited via Multi-Factor Authentication (MFA) and Single Sign-On (SSO) under the principle of least privilege.

  • Network Defense: Production hosting environments utilize Web Application Firewalls (WAF), automated rate-limiting, and continuous intrusion logging.



Your Rights


We respect your rights to access, rectify, erase, or restrict, port and object to the use of your personal data. Under applicable data protection laws, you have several rights regarding your personal data. These rights include:

  • Right of Access: You may request a copy and access your personal data that we hold.

  • Right to Rectification: You may ask us to correct any personal information that is inaccurate or incomplete.

  • Right to Erasure: You may request deletion of your personal data in certain circumstances, subject to applicable legal retention obligations.

  • Right to Restrict Processing: You may request that we limit how we process your personal data in specific situations.

  • Right to Data Portability: You may request your personal data in a structured, portable, and machine-readable format, and have it transferred to another provider where applicable.

  • Right to Object: You may object to certain processing activities of your personal data, including marketing.


Handling Patient Requests

Because Summit is a Data Processor / Secondary Agency:

  • Direct Inquiries: Patients seeking to exercise their privacy rights regarding call recordings or health records must contact their healthcare clinic (the Data Controller) directly.

  • Forwarding Protocol: If a patient submits a request directly to Summit, we will log the request and forward it to the relevant clinic within 3 business days.

  • Technical Execution: Summit will technically execute data extractions, corrections, or purges within 1-2 business days following verified, written instructions from the clinic controller.

Complaints & Escalations
If you have questions, concerns, or wish to lodge a complaint, please contact our Privacy Officer, contact details below. We will investigate and respond promptly. If you are not satisfied, you can escalate your complaint to the relevant data protection authority in New Zealand or Australia.

Privacy Policy Updates

We may review and update this Privacy Policy periodically. Customers will be notified of any material changes via email, and the updated policy will be published on our website with the effective date indicated. For minor updates, notifications may also be provided to our customers via our client portal.

If you have any questions or concerns about this Privacy Policy, please provide us with the full details of your concern along with any supporting documentation to:


GDPR Addendum

If you are located in the United Kingdom (“UK”) or the European Union (“EU”), and wish to use our website and/or Services, the GDPR applies to you. These additional terms (“GDPR Addendum”) apply to this and make up part of our Privacy Policy.

The UK Data Protection Act 2018 (“DPA”) and the EU General Data Protection Regulation (“EU GDPR”) were set up to control the collection, processing and transfer of UK and EU individuals’ personal data (as defined in the GDPR). The personal information described in the Summit Privacy Policy comes under the personal data in the GDPR. It is important to us that we comply with the GDPR when dealing with the personal data of UK and EU-based visitors to our website.

This GDPR Addendum was drafted to be concise and easy to understand. It does not outline in exhaustive detail all aspects of our collection and use of personal data. If you wish to have more information or need an explanation, please contact us. Your request should be sent to Rubin Saini, CEO of Summit AI.

For the purposes of the GDPR:

  • Summit is the data controller (as defined in the GDPR) when processing personal information.

  • Our third party vendors are the data processors when processing personal information.

Processing personal data

The personal information outlined in this Privacy Policy is the personal data that Summit may process. Any processing done will be to achieve the purposes set out in this Privacy Policy.

As permitted under the GDPR we can process your information for the purposes described in the body of the Privacy Policy by relying on one or more of the following lawful grounds:

  • You have agreed with us explicitly that we may process your information for a specific reason;

  • The processing of personal information is necessary to perform the agreement we have with you (or to take steps to enter into an agreement with you);

  • The processing is necessary for us to comply with our legal obligations; or

  • The processing is actually necessary for our legitimate interests, which include:
    (i) to protect our business interests;
    (ii) to ensure that complaints are appropriately investigated;
    (iii) to evaluate, develop or improve products and services we offer; or
    (iv) to keep you informed of relevant products and services, unless you indicate that you do not wish us to be kept updated. While we will generally rely on your specific consent to process special categories of personal data (i.e., ‘sensitive information’), in some cases (for example, relating to an alleged offence), we may need to use some information to comply with our legal obligations.

It is possible to use access and use our website without providing us with data. However some of our services will require you to provide us with your name and email address, for example if you sign up to any newsletters. If you choose not to divulge that information, we will be unable to provide you with our full services.

Your rights

The GDPR grants you certain rights in relation to your personal data. These include:

  • Right of access

  • Right to rectification

  • Right to erasure

  • Right to withdraw consent

  • Right to restrict processing

  • Right to object to processing

  • Rights related to automated decision making, including profiling

  • Right to data portability

  • The right to complain to a supervisory authority

If your personal data is used or obtained for direct marketing purposes, you have the right to object.

If you wish to exercise any of your rights listed above, please contact our Privacy Officer. If you are dissatisfied with how we deal with your request, you may refer your query to your local data protection supervisory authority e.g. in the United Kingdom, this is the Information Commissioner’s Office.

Children

It is not our intention to collect personal data from children under the age of 16. If you believe that a child under 16 has given us their personal data either through our website and/or by using our Services, please contact our Privacy Officer. If they can access it, then it is your responsibility to obtain the consent of any Guardian of any children who can access the website or the Services and you agree to do so.

International transfer of data

As Summit is based in New Zealand, the personal information that we collect through our website and our Services will be transferred to, and stored in, a country operating outside the United Kingdom or the European Economic Area (EEA). According to the GDPR, this transfer may only take place if the European Commission has decided that the country maintains an adequate level of protection. If this adequacy status is not granted to us we may transfer the personal data, so long as there are suitable safeguards.

The Summit Privacy Policy states that some of the personal information we collect is processed by third party data processors in other countries, including Australia. We will only transfer this data outside the United Kingdom or the EEA if that country has been given the adequacy status mentioned above, or if we have approved transfer instruments set up to protect your personal data. If you wish to know more, please contact us using the details in our Privacy Policy.

Data Retention Privacy Policy

We will only keep personal information for as long as is needed to achieve its purpose, or to comply with relevant law, whichever is longer.

Contacting us

Please contact us via the details as set out in our Privacy Policy.

Security & Encryption Controls


Summit implements multi-layered technical, administrative, and physical security measures to safeguard personal data:

  • Encryption in Transit: All network traffic moving between callers, browsers, Summit systems, and API sub-processors is encrypted using TLS 1.3 / HTTPS.

  • Encryption at Rest: All sensitive database records, call recordings, and transcripts are encrypted at rest using AES-256 bit encryption.

  • Credential Protection: Practice Management System API keys and integration tokens are encrypted via AES-256 prior to database storage and are never logged or displayed in raw text.

  • Access Control: Internal staff access to production environments is strictly limited via Multi-Factor Authentication (MFA) and Single Sign-On (SSO) under the principle of least privilege.

  • Network Defense: Production hosting environments utilize Web Application Firewalls (WAF), automated rate-limiting, and continuous intrusion logging.



Your Rights


We respect your rights to access, rectify, erase, or restrict, port and object to the use of your personal data. Under applicable data protection laws, you have several rights regarding your personal data. These rights include:

  • Right of Access: You may request a copy and access your personal data that we hold.

  • Right to Rectification: You may ask us to correct any personal information that is inaccurate or incomplete.

  • Right to Erasure: You may request deletion of your personal data in certain circumstances, subject to applicable legal retention obligations.

  • Right to Restrict Processing: You may request that we limit how we process your personal data in specific situations.

  • Right to Data Portability: You may request your personal data in a structured, portable, and machine-readable format, and have it transferred to another provider where applicable.

  • Right to Object: You may object to certain processing activities of your personal data, including marketing.


Handling Patient Requests

Because Summit is a Data Processor / Secondary Agency:

  • Direct Inquiries: Patients seeking to exercise their privacy rights regarding call recordings or health records must contact their healthcare clinic (the Data Controller) directly.

  • Forwarding Protocol: If a patient submits a request directly to Summit, we will log the request and forward it to the relevant clinic within 2 business days.

  • Technical Execution: Summit will technically execute data extractions, corrections, or purges within 5 business days following verified, written instructions from the clinic controller.

Complaints & Escalations
If you have questions, concerns, or wish to lodge a complaint, please contact our Privacy Officer, contact details below. We will investigate and respond promptly. If you are not satisfied, you can escalate your complaint to the relevant data protection authority in New Zealand or Australia.

Privacy Policy Updates

We may review and update this Privacy Policy periodically. Customers will be notified of any material changes via email, and the updated policy will be published on our website with the effective date indicated. For minor updates, notifications may also be provided to our customers via our client portal.

If you have any questions or concerns about this Privacy Policy, please provide us with the full details of your concern along with any supporting documentation to:


GDPR Addendum

If you are located in the United Kingdom (“UK”) or the European Union (“EU”), and wish to use our website and/or Services, the GDPR applies to you. These additional terms (“GDPR Addendum”) apply to this and make up part of our Privacy Policy.

The UK Data Protection Act 2018 (“DPA”) and the EU General Data Protection Regulation (“EU GDPR”) were set up to control the collection, processing and transfer of UK and EU individuals’ personal data (as defined in the GDPR). The personal information described in the Summit Privacy Policy comes under the personal data in the GDPR. It is important to us that we comply with the GDPR when dealing with the personal data of UK and EU-based visitors to our website.

This GDPR Addendum was drafted to be concise and easy to understand. It does not outline in exhaustive detail all aspects of our collection and use of personal data. If you wish to have more information or need an explanation, please contact us. Your request should be sent to Rubin Saini, CEO of Summit AI.

For the purposes of the GDPR:

  • Summit operates strictly as a Data Processor on behalf of our customers. We process personal data (including call data, transcripts, and recordings) solely under the documented instructions of our customers.

  • Our customers (the healthcare clinics) remain the Data Controllers (as defined in the GDPR) at all times when processing personal information.

  • Third-party vendors engaged by Summit (such as our infrastructure and AI model providers listed in our Trust Centre) act as Sub-processors and are bound by strict data processing agreements to protect your information.

Processing personal data

The personal information outlined in this Privacy Policy is the personal data that Summit may process. Any processing done will be to achieve the purposes set out in this Privacy Policy.

As permitted under the GDPR we can process your information for the purposes described in the body of the Privacy Policy by relying on one or more of the following lawful grounds:

  • You have agreed with us explicitly that we may process your information for a specific reason;

  • The processing of personal information is necessary to perform the agreement we have with you (or to take steps to enter into an agreement with you);

  • The processing is necessary for us to comply with our legal obligations; or

  • The processing is actually necessary for our legitimate interests, which include:
    (i) to protect our business interests;
    (ii) to ensure that complaints are appropriately investigated;
    (iii) to evaluate, develop or improve products and services we offer; or
    (iv) to keep you informed of relevant products and services, unless you indicate that you do not wish us to be kept updated. While we will generally rely on your specific consent to process special categories of personal data (i.e., ‘sensitive information’), in some cases (for example, relating to an alleged offence), we may need to use some information to comply with our legal obligations.

It is possible to use access and use our website without providing us with data. However some of our services will require you to provide us with your name and email address, for example if you sign up to any newsletters. If you choose not to divulge that information, we will be unable to provide you with our full services.

Your rights

The GDPR grants you certain rights in relation to your personal data. These include:

  • Right of access

  • Right to rectification

  • Right to erasure

  • Right to withdraw consent

  • Right to restrict processing

  • Right to object to processing

  • Rights related to automated decision making, including profiling

  • Right to data portability

  • The right to complain to a supervisory authority

If your personal data is used or obtained for direct marketing purposes, you have the right to object.

If you wish to exercise any of your rights listed above, please contact our Privacy Officer. If you are dissatisfied with how we deal with your request, you may refer your query to your local data protection supervisory authority e.g. in the United Kingdom, this is the Information Commissioner’s Office.

Children

It is not our intention to collect personal data from children under the age of 16. If you believe that a child under 16 has given us their personal data either through our website and/or by using our Services, please contact our Privacy Officer. If they can access it, then it is your responsibility to obtain the consent of any Guardian of any children who can access the website or the Services and you agree to do so.

International transfer of data

As Summit is based in New Zealand, the personal information that we collect through our website and our Services will be transferred to, and stored in, a country operating outside the United Kingdom or the European Economic Area (EEA). According to the GDPR, this transfer may only take place if the European Commission has decided that the country maintains an adequate level of protection. If this adequacy status is not granted to us we may transfer the personal data, so long as there are suitable safeguards.

The Summit Privacy Policy states that some of the personal information we collect is processed by third party data processors in other countries, including Australia. We will only transfer this data outside the United Kingdom or the EEA if that country has been given the adequacy status mentioned above, or if we have approved transfer instruments set up to protect your personal data. If you wish to know more, please contact us using the details in our Privacy Policy.

Data Retention Privacy Policy

We will only keep personal information for as long as is needed to achieve its purpose, or to comply with relevant law, whichever is longer.

Contacting us

Please contact us via the details as set out in our Privacy Policy.

Summit is built for:

Physiotherapists - Podiatrists - Chiropractors - Osteopaths - Psychologists - Naturopaths - Occupational Therapists - Speech Pathologists - Massage Therapists - Exercise Physiologists - Allied Health Clinics - NDIS Service Providers

© 2026 Summit AI Limited. All rights reserved.

Summit is built for:

Physiotherapists - Podiatrists - Chiropractors - Osteopaths - Psychologists - Naturopaths - Occupational Therapists - Speech Pathologists - Massage Therapists - Exercise Physiologists - Allied Health Clinics - NDIS Service Providers

© 2026 Summit AI Limited. All rights reserved.