1.Scope and Who We Are
Emphis AI LLC, a Texas limited liability company doing business as Inferline AI (“Inferline,” “we,” “us”) provides a voice-AI platform that answers inbound phone calls for restaurants, converses with callers, takes orders, sends messages, and writes orders to point-of-sale (“POS”) systems. This policy covers two groups of people:
- Customers, the restaurant owners, operators, and their staff who subscribe to and configure the Services; and
- Callers / End Users, the consumers who call a Customer’s phone number and interact with the AI.
For Caller personal information processed through the Services, the restaurant Customer is generally the business / controller and Inferline acts as a service provider / processor that processes that information on the Customer’s behalf and under our agreement with them. This policy also describes our own practices as a business for the information we collect directly.
2.Information We Collect
From callers (consumers)
- Call audio and recordings. The AI-generated voice interaction, and, where enabled, a recording of the call.
- Transcripts and conversation content. Text transcriptions and the substance of what is said, including any information a caller volunteers.
- Contact and identity details. Name and phone number (including caller ID / ANI), and where relevant for delivery, a delivery or service address.
- Order details. Items ordered, special requests, quantities, timing, and related notes.
- Payment-related data. Where configured, information needed to route a payment to a processor. Full card numbers are handled by our payment processor, not stored by Inferline.
- Messaging data. Phone number and message content for any SMS confirmations or follow-ups, and opt-in/opt-out status.
From customers (restaurant accounts)
- Account, contact, and billing information.
- Configuration data, menus, pricing, hours, scripts, routing rules, and connected-integration credentials.
- Usage, log, device, and diagnostic data for the console and APIs.
3.Call Recording, AI Voice, and Consent
Calls are answered by a synthesized, AI-generated voice, not a live person (until and unless transferred to staff). Where enabled, calls are recorded and transcribed to operate the AI, confirm orders, and improve quality.
Call recording is regulated differently across U.S. states. Some states require only one party to consent, while others require all parties to consent (two-party / all-party consent states such as California, Florida, Illinois, Pennsylvania, and Washington, among others). The Services provide a configurable recording-consent notice at the start of a call (for example, “This call may be recorded”). The restaurant Customer is responsible for enabling appropriate disclosures and for the lawfulness of recording for its location and its callers. If a caller declines, they may ask the restaurant not to record or to delete a recording (see Your Rights below).
4.How We Use Information
- To answer calls, understand requests, and take and confirm orders.
- To write orders and data to the Customer’s POS and connected systems.
- To send transactional or, with consent, marketing SMS messages.
- To provide, secure, maintain, troubleshoot, and improve the Services.
- To prevent fraud and abuse, and to comply with legal obligations.
- To create de-identified or aggregated data that does not identify any individual.
We do not sell personal information for money. We disclose information to the sub-processors listed below to deliver the Services.
5.Automated Decision-Making
The Services use automated processing, including speech recognition, large-language-model interpretation, and rules, to understand callers, route or transfer calls, confirm or decline orders, and decide whether to send messages. These decisions are made by software in real time without human review. Callers can request a transfer to a human, and, where applicable law provides rights regarding automated decision-making (including under CCPA/CPRA and the GDPR), those rights are described in the “Your Rights” section.
6.SMS Messaging and TCPA
When the Services send text messages, message and data rates may apply. Marketing and automated texts are subject to the Telephone Consumer Protection Act (TCPA) and carrier rules. Messages are sent based on the consent obtained by the restaurant Customer, and recipients can opt out at any time by replying with a standard keyword such as STOP. We process opt-outs and do not use a caller’s number for messaging beyond the purpose for which it was provided, except as permitted by law.
7.Payments and POS Data
Where a Customer enables ordering or payment, order data is transmitted to the Customer’s POS or ordering provider, and payment data is handled by a third-party payment processor. Inferline does not seek to store full card numbers. Customers are responsible for their own PCI-DSS obligations and for the privacy practices of POS and payment providers they connect.
8.Sub-Processors We Use
We rely on a small set of trusted sub-processors, grouped below by the function they perform. Each processes personal information only to perform that function and under contractual confidentiality and security obligations.
| Type of sub-processor | Purpose | Primary location |
|---|---|---|
| Cloud hosting & infrastructure | Application hosting, storage, and compute | United States |
| Telephony & messaging | Phone numbers, call connectivity, and SMS delivery | United States |
| Real-time voice media | Streaming live call audio during a call | United States |
| Speech recognition (speech-to-text) | Transcribing call audio | United States |
| Conversational AI / language models | Understanding requests and generating responses | United States |
| Voice synthesis (text-to-speech) | Producing the assistant's spoken voice | United States |
| Payment processing | Billing and, where enabled, routing a payment | United States |
A current list naming the specific sub-processors in each category is available to Customers on request and as part of our data processing addendum (“DPA”). This list may be updated from time to time.
Where any sub-processor processes data outside a Caller’s region, we rely on appropriate transfer mechanisms (such as Standard Contractual Clauses) where required by applicable law.
9.Data Retention and Deletion
We retain personal information for as long as needed to provide the Services and for the periods configured by the Customer, after which it is deleted or de-identified, subject to legal retention requirements. Customers can configure retention windows for call recordings and transcripts in the console. On account termination, we make Customer Data available for export for a limited period and then delete it as described in our Terms of Service and any data processing addendum.
Callers may ask the restaurant they called, or contact us at legal@inferline.ai, to request deletion of a recording or transcript. Because the restaurant is the controller of that data, we may direct or forward the request to them.
10.Data Security
We use administrative, technical, and physical safeguards designed to protect personal information, including encryption in transit, signature-verified webhooks, per-tenant isolation of call sessions, access controls, and audit logging. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
11.Your Rights and Choices
California (CCPA/CPRA) and other U.S. state laws
Depending on your state, you may have the right to know/access, correct, delete, and obtain a portable copy of your personal information; to opt out of “sale” or “sharing” for cross-context behavioral advertising; to limit the use of sensitive personal information; and to not be discriminated against for exercising these rights. Inferline does not sell personal information for money. To exercise rights with respect to a specific restaurant’s data, we may route your request to that restaurant as the business.
EU/UK (GDPR / UK GDPR)
Where the GDPR or UK GDPR applies, you may have the right to access, rectify, erase, restrict, or object to processing of your personal data; the right to data portability; the right to withdraw consent; and the right to lodge a complaint with a supervisory authority. Our legal bases include performance of a contract, legitimate interests, consent (for example, for marketing messages), and compliance with legal obligations. For Caller data, the restaurant is typically the controller and Inferline the processor.
To submit a request, email legal@inferline.ai. We will verify your identity before acting and respond within the timeframes required by applicable law.
12.Children's Privacy
The Services are intended for businesses and adults. We do not knowingly collect personal information from children under [13]. If you believe a child has provided personal information, contact us so we can delete it.
13.Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated by updating the effective date and, where appropriate, by additional notice. Your continued use of the Services after an update constitutes acceptance of the revised policy.
14.Contact Us
For privacy questions or to exercise your rights, contact our Legal & Privacy team.
Questions about this document, or a request to exercise your privacy rights? Contact us:
Emphis AI LLC (d/b/a Inferline AI)
Attn: Legal & Privacy
Texas, United States
Email: legal@inferline.ai