Privacy Policy

Privacy Policy

Privacy Policy

Last updated on 29 December 2025.

Purpose and Scope

Purpose of This Policy and Who It Applies To

Summit AI Limited is committed to protecting the privacy of everyone who interacts with our services. This Privacy Policy explains our practices regarding the use, collection, disclosure, and safeguarding of your personal data. By using our services, you acknowledge that you have read, understood, and agree to these terms. Summit operates in compliance with applicable privacy frameworks including the Australian Privacy Principles (APP) and New Zealand Privacy Principles (NZPP), among other applicable regulations.

This policy applies to all individuals whose data we process, including customers, end users, website visitors, and partners. This covers all services provided by Summit.

  • Customers: Healthcare clinics and their staff

  • End users: Patients and callers whose data is processed through our platform

  • Website visitors: Individuals who visit our website at www.usesummitai.com

  • Partners: Business partners and vendors

Note: Summit processes personal data on behalf of our customers, which act as the data controllers. Our customers are responsible for their relationship with patients and for ensuring appropriate notices and consents are provided in accordance with applicable healthcare and privacy laws.


Types of Personal Data We Collect


We collect personal data directly when individuals interact with our services. We collect this data in three main ways: directly from individuals, automatically during service use, and from third-party systems.

Personal Information We Collect
We collect the following types of personal information in regards to providing our services:

  • Personal Identifiers: Full name, date of birth, phone number

  • Account Details: Account credentials, user preferences, and payment information for service purchases.

  • Call Data: Patient names, contact details and appointment details in our call recordings and transcripts,

  • Technical Data: IP addresses, browser type, operating system, and usage data from interactions with our platform.

We collect personal information directly from you when you sign up to use our services, or communicate with us for technical support. We may also collect information from third-party services such as practice management software, to enable appointment scheduling and management.

How We Use Personal Data

We use personal data to provide and improve our services, communicate effectively, and meet legal requirements. Specifically:

  • Service Delivery & Operations: Managing calls, scheduling appointments, and facilitating patient communication

  • Support and Communication: To respond to inquiries and provide customer support.

  • Legal Compliance: To comply with legal, regulatory, and contractual obligations, including APP and NZPP compliance.

  • Marketing (with Consent): To send updates or promotional communications, with your consent, related to our services.


Legal Basis for Processing

We process personal data based on:

  • Consent: When individuals provide clear consent, such as for call processing and marketing communications. This is withdrawable at any time.

  • Contractual Necessity: To fulfil Summit AI's service agreements with our customers.

  • Legitimate Interests: To improve Summit AI's services and ensure operational efficiency, while respecting individual rights.


Data Collection Practices and Data Sharing Notifications

We collect personal data through:

  • Direct interactions with patients during phone calls.

  • Integration with practice management and appointment booking software.

  • Automated tools that capture call recordings and metadata.

We notify individuals about data collection through:

  • Privacy notices on our website.

  • Onboarding materials shared with clinics.

  • Clear disclaimer messages during phone call interactions.

Clinics are responsible for informing patients about data collection and obtaining any required consents prior to using Summit's services.

Sharing and Disclosure of Data

We may share your personal information with third party service providers for the following purposes:

  • Internal Use: Data is accessed only by authorized personnel (executive leadership and authorized service providers) for service delivery and support.

  • Service Providers: To facilitate the operation of our services, we may share your data with trusted third-party providers such as payment processors, IT services or cloud storage providers.

  • Legal Compliance: We may disclose your information to comply with applicable laws and regulations or to respond to lawful requests from governmental authorities or regulatory bodies.

  • Health-Related Services: We may share information with authorized third parties as required to provide healthcare-related services or to meet our contractual obligations with you or your organization.

  • We ensure that all third-party providers we engage with are compliant with privacy laws, including HIPAA, GDPR, and the Australian Privacy Act, as appropriate.


Cross-Border Transfers: Where personal data is transferred internationally, Summit implements appropriate safeguards, including standard contractual data protection obligations, and other legal safeguards with service providers. We ensure that all third-party providers we engage with comply with privacy frameworks, including NZPP and the Australian Privacy Act, as appropriate.


Data Retention and Accuracy


Retention Periods

We retain personal data only as long as necessary:

Purpose and Scope


Purpose of This Policy and Who It Applies To


Summit AI Limited is committed to protecting the privacy of everyone

who interacts with our services. This Privacy Policy explains how Summit AI Limited (“Summit AI”, “we”, “us”, or “our”) collects, uses, discloses, and safeguards personal data.

The purpose of this policy is to:

  • Explain how personal data is collected, used, stored, and protected

  • Help individuals understand and exercise their privacy rights

  • Ensure compliance with applicable privacy and data protection laws

  • Build trust with our healthcare clinic customers and their patients

This policy applies to all individuals whose data we process, including customers, end users, website visitors, and business partners. This covers all services provided by Summit AI, such as our intelligent phone receptionist.

  • Customers: Healthcare clinics and their staff (admin team and clinicians)

  • End Users: Patients and callers whose data is processed through our AI receptionist

  • Website visitors: Individuals who visit our website at https://usesummitai.com/

  • Business Partners: Business partners and vendors

Note: Summit AI Limited processes personal data on behalf of healthcare clinics, which act as the data controllers. Clinics are responsible for their relationship with patients and for ensuring appropriate notices and consents are provided in accordance with applicable healthcare and privacy laws.

Types of Personal Data We Collect


We collect personal data directly when individuals interact with our services. We collect this data in three main ways: directly from individuals, automatically during service use, and from third-party systems.


Data Provided by Individuals (Patients and Clinic Staff)

Clinic Information

  • Clinic name and contact information

  • Staff names, role and contact details

  • Practice Management Software API key, token or equivalent credential

Account Details

  • Account credentials and user preferences

  • Payment information for service purchases

Call Data (processed on behalf of customers)

  • Call recordings and transcripts

  • Patient names, contact details and appointment details


Data Collected Automatically

When using our services, we may automatically collect:

  • Call recordings, transcripts, and metadata (e.g., timestamps, call duration)

  • Device information (type, operating system, browser)

  • Technical data such as IP addresses, device information, and usage patterns

  • Usage analytics and log data for security reasons and service improvement


Data from Third Parties

We may receive data from third-party systems, such as Practice Management Systems (PMS), to assist with appointment scheduling and patient communication.


Children's Data


Our services are intended for healthcare providers and not for children under 16. Clinics are responsible for obtaining parental consent when processing children’s data. Parents or guardians can contact us to access, correct, or delete their child’s data.

How We Use Personal Data

We use personal data to provide and improve our services, communicate effectively, and meet legal requirements. Specifically:

  • Service Delivery & Operations: Managing calls, scheduling appointments, and facilitating patient communication

  • Support and Communication: Responding to inquiries and providing customer support

  • Legal Compliance: Meeting regulatory requirements in New Zealand and Australia

  • Marketing (with Consent): Sending updates or promotional materials to clinics, where permitted


Legal Basis for Processing

We process personal data based on:

  • Consent: When individuals provide clear consent, such as for call processing and marketing communications. This is withdraw-able at any time.

  • Contractual Necessity: To fulfil Summit AI's service agreements with clinics.

  • Legitimate Interests: To improve Summit AI's services and ensure operational efficiency, while respecting individual rights.


Data Collection Practices and Data Sharing Notifications

We collect personal data through:

  • Direct interactions, such as phone calls, emails, or web forms.

  • Integration with third-party systems like PMS platforms.

  • Automated tools that capture call recordings and metadata.

We notify individuals about data collection through:

  • Privacy notices on our website.

  • Onboarding materials shared with clinics.

  • Disclaimer messages during AI receptionist interactions.

Clinics are responsible for informing patients about data collection and obtaining any required consents prior to using Summit AI services.


Sharing and Disclosure of Data

We share personal data only when necessary and with safeguards in place:

  • Internal Use: Data is accessed only by authorized personnel (executive leadership and authorized service providers) for service delivery and support.

  • Third-Party Service Providers: Trusted vendors help manage call recordings, transcripts, and appointment data. Key service providers:

    • Retell AI for call transcript and recording storage (GDPR, HIPAA, PCI-DSS, or SOC 2 compliant)

    • Make.com (Workflow automation, 45-day data retention)

    • OpenAI (Call transcript analysis)

    • Telnyx (Telephony provider)

    • Twilio (Telephony provider)

    • Nookal or Cliniko (Practice management software interfaces used to access and sync appointment and patient information)

    • Stripe (Payment processor)

  • Cross-Border Transfers: Where personal data is transferred internationally, Summit AI implements appropriate safeguards, including standard contractual data protection obligations, and other legal safeguards, with service providers.Data Retention and Accuracy


    Retention Periods


    We retain personal data only as long as necessary:


Purpose and Scope

Purpose of This Policy and Who It Applies To

Summit AI Limited is committed to protecting the privacy of everyone who interacts with our services. This Privacy Policy explains our practices regarding the use, collection, disclosure, and safeguarding of your personal data. By using our services, you acknowledge that you have read, understood, and agree to these terms. Summit operates in compliance with applicable privacy frameworks including the Australian Privacy Principles (APP) and New Zealand Privacy Principles (NZPP), among other applicable regulations.

This policy applies to all individuals whose data we process, including customers, end users, website visitors, and partners. This covers all services provided by Summit.

  • Customers: Healthcare clinics and their staff

  • End users: Patients and callers whose data is processed through our platform

  • Website visitors: Individuals who visit our website at www.usesummitai.com

  • Partners: Business partners and vendors

Note: Summit processes personal data on behalf of our customers, which act as the data controllers. Our customers are responsible for their relationship with patients and for ensuring appropriate notices and consents are provided in accordance with applicable healthcare and privacy laws.


Types of Personal Data We Collect


We collect personal data directly when individuals interact with our services. We collect this data in three main ways: directly from individuals, automatically during service use, and from third-party systems.

Personal Information We Collect
We collect the following types of personal information in regards to providing our services:

  • Personal Identifiers: Full name, date of birth, phone number

  • Account Details: Account credentials, user preferences, and payment information for service purchases.

  • Call Data: Patient names, contact details and appointment details in our call recordings and transcripts,

  • Technical Data: IP addresses, browser type, operating system, and usage data from interactions with our platform.

We collect personal information directly from you when you sign up to use our services, or communicate with us for technical support. We may also collect information from third-party services such as practice management software, to enable appointment scheduling and management.

How We Use Personal Data

We use personal data to provide and improve our services, communicate effectively, and meet legal requirements. Specifically:

  • Service Delivery & Operations: Managing calls, scheduling appointments, and facilitating patient communication

  • Support and Communication: To respond to inquiries and provide customer support.

  • Legal Compliance: To comply with legal, regulatory, and contractual obligations, including APP and NZPP compliance.

  • Marketing (with Consent): To send updates or promotional communications, with your consent, related to our services.


Legal Basis for Processing

We process personal data based on:

  • Consent: When individuals provide clear consent, such as for call processing and marketing communications. This is withdrawable at any time.

  • Contractual Necessity: To fulfil Summit AI's service agreements with our customers.

  • Legitimate Interests: To improve Summit AI's services and ensure operational efficiency, while respecting individual rights.


Data Collection Practices and Data Sharing Notifications

We collect personal data through:

  • Direct interactions with patients during phone calls.

  • Integration with practice management and appointment booking software.

  • Automated tools that capture call recordings and metadata.

We notify individuals about data collection through:

  • Privacy notices on our website.

  • Onboarding materials shared with clinics.

  • Clear disclaimer messages during phone call interactions.

Clinics are responsible for informing patients about data collection and obtaining any required consents prior to using Summit's services.

Sharing and Disclosure of Data

We may share your personal information with third party service providers for the following purposes:

  • Internal Use: Data is accessed only by authorized personnel (executive leadership and authorized service providers) for service delivery and support.

  • Service Providers: To facilitate the operation of our services, we may share your data with trusted third-party providers such as payment processors, IT services or cloud storage providers.

  • Legal Compliance: We may disclose your information to comply with applicable laws and regulations or to respond to lawful requests from governmental authorities or regulatory bodies.

  • Health-Related Services: We may share information with authorized third parties as required to provide healthcare-related services or to meet our contractual obligations with you or your organization.

  • We ensure that all third-party providers we engage with are compliant with privacy laws, including HIPAA, GDPR, and the Australian Privacy Act, as appropriate.


Cross-Border Transfers: Where personal data is transferred internationally, Summit implements appropriate safeguards, including standard contractual data protection obligations, and other legal safeguards with service providers. We ensure that all third-party providers we engage with comply with privacy frameworks, including NZPP and the Australian Privacy Act, as appropriate.


Data Retention and Accuracy


Retention Periods

We retain personal data only as long as necessary:

Loading...

Ensuring Data Accuracy

We work with clinics and third-party providers to keep data accurate and up-to-date. Individuals can request updates or corrections by contacting us.

Your Rights


We respect your rights to access, correct, delete, or restrict the use of your personal data. Under applicable data protection laws, you have several rights regarding your personal data. These rights include:

  • Right of Access: You may request a copy of the personal data we hold about you.

  • Right to Rectification: You may ask us to correct any personal information that is inaccurate or incomplete.

  • Right to Erasure: You may request deletion of your personal data in certain circumstances, subject to applicable legal retention obligations.

  • Right to Restrict Processing: You may request that we limit how we process your personal data in specific situations.

  • Right to Data Portability: You may request your personal data in a structured, commonly used, and machine-readable format, and have it transferred to another provider where applicable.

  • Right to Object: You may object to the processing of your personal data for certain purposes, including direct marketing.


To exercise these rights:

  • Contact us via email at contact@usesummitai.com.

  • We will verify your identity to protect your privacy.

  • We aim to process all requests within 30 calendar days, in collaboration with clinics and service providers.


Complaints and Escalations

If you have concerns about how we handle your data, contact us at contact@usesummitai.com. We will investigate and respond promptly. If you are not satisfied, you can escalate your complaint to the relevant data protection authority in New Zealand or Australia.


Privacy Policy Updates

We may review and update this Privacy Policy periodically. Customers will be notified of any material changes via email, and the updated policy will be published on our website with the effective date indicated. For material updates, notifications may also be provided through Summit AI's Client Portal.

If you have any questions or concerns about this Privacy Policy, please contact Sharad, VP of Operations, at contact@usesummitai.com

Ensuring Data Accuracy

We work with clinics and third-party providers to keep data accurate and up-to-date. Individuals can request updates or corrections by contacting us.

Your Rights


We respect your rights to access, correct, delete, or restrict the use of your personal data. Under applicable data protection laws, you have several rights regarding your personal data. These rights include:

  • Right of Access: You may request a copy of the personal data we hold about you.

  • Right to Rectification: You may ask us to correct any personal information that is inaccurate or incomplete.

  • Right to Erasure: You may request deletion of your personal data in certain circumstances, subject to applicable legal retention obligations.

  • Right to Restrict Processing: You may request that we limit how we process your personal data in specific situations.

  • Right to Data Portability: You may request your personal data in a structured, commonly used, and machine-readable format, and have it transferred to another provider where applicable.

  • Right to Object: You may object to the processing of your personal data for certain purposes, including direct marketing.


To exercise these rights:

  • Contact us via email at contact@usesummitai.com.

  • We will verify your identity to protect your privacy.

  • We aim to process all requests within 30 calendar days, in collaboration with clinics and service providers.


Complaints and Escalations

If you have concerns about how we handle your data, contact us at contact@usesummitai.com. We will investigate and respond promptly. If you are not satisfied, you can escalate your complaint to the relevant data protection authority in New Zealand or Australia.


Privacy Policy Updates

We may review and update this Privacy Policy periodically. Customers will be notified of any material changes via email, and the updated policy will be published on our website with the effective date indicated. For material updates, notifications may also be provided through Summit AI's Client Portal.

If you have any questions or concerns about this Privacy Policy, please contact Sharad, VP of Operations, at contact@usesummitai.com

Ensuring Data Accuracy

We work with clinics and third-party providers to keep data accurate and up-to-date. Individuals can request updates or corrections by contacting us.

Individual Rights and How to Exercise Them

We respect your rights to access, correct, delete, or restrict the use of your personal data. To exercise these rights:

  • Contact us via email at contact@usesummitai.com.

  • We will verify your identity to protect your privacy.

  • We aim to process all requests within 30 calendar days, in collaboration with clinics and service providers.

Complaints and Escalations

If you have concerns about how we handle your data, contact us at contact@usesummitai.com. We will investigate and respond promptly. If you are not satisfied, you can escalate your complaint to the relevant data protection authority in New Zealand or Australia.

Policy Updates

We may review and update this Privacy Policy periodically. Clinics will be notified of any material changes via email, and the updated policy will be published on our website with the effective date clearly indicated. For material updates, notifications may also be provided through our AI receptionist.

For questions or concerns about this Privacy Policy, contact us at contact@usesummitai.com.