Legal
Privacy policy
What we do with the data that passes through Appela, who can see it, and how long it stays.
Last updated : 10 October 2026
Who is responsible for what
Soclic Group Sàrl, Rue de la Navigation 1, 1201 Genève, Suisse (CHE-430.016.769), publishes Appela.
Two roles overlap, and the difference matters. For your account data — your name, your business, your billing — we are the controller. For your customers’ data — the people who call your business — you are the controller, and we act as your processor: we handle that data only to provide the service, according to your settings.
In practice, it is up to you to tell your customers how you use their data and to answer their requests. We give you the means to do so, and we assist you.
The data we handle
For your account:
- Identity and contact details: name, email address, business name and address, phone number.
- Service settings: opening hours, services or tables, staff, prices, the agent’s voice and language.
- Billing: plan, payment history, billing details.
- Technical logs: sign-ins, errors — needed to run and secure the service.
For the people who call your business:
- The caller’s number, and the date, time and length of the call.
- What the request was about: what was said and what the agent replied, as a transcript and a summary.
- Appointment or booking details: name, service or number of covers, date, time, any notes.
- No audio recording: calls are never recorded.
We never ask the agent to collect sensitive data, and we advise you against configuring it to do so.
No call recording
Calls are never recorded. No audio file is kept, neither by us nor by our providers: only a written transcript and a summary of each call are kept, so you know what was asked. In Switzerland, art. 179ter of the Criminal Code punishes recording a conversation without the participants’ knowledge: we chose not to record at all.
You choose how long transcripts are kept — 30, 90, 180 or 365 days. After that, they are deleted automatically, on our side and at our provider.
Why we handle it
- To perform the contract: answering calls, saving appointments, sending reminders, billing the subscription.
- To meet our legal obligations, accounting ones in particular.
- Our legitimate interest in running and securing the service: technical logs, abuse prevention.
- Your consent, where it applies: connecting your Google Calendar.
Who else can see it
Nobody looks at your data for their own purposes. We use the providers below, each for one specific task and with no right to do anything else with it:
Twilio
Telephony: receiving calls and sending SMS.
Caller’s number, time and length of the call, SMS content.
ElevenLabs
Voice agent: understanding the request and answering.
Content of the conversation, as a written transcript (no audio recording).
Stripe
Subscription payments.
Billing details. No card number passes through our servers.
Brevo
Sending the service’s emails: confirmations, reminders, alerts.
Email address and content of the message sent.
Google Calendar
Calendar synchronisation, if you connect it.
Events in your primary calendar: date, time, title, description.
Base44
Hosting of the application and the database.
All account data.
Some of these providers are established outside Switzerland and the European Union, notably in the United States. Those transfers rely on the European Commission’s standard contractual clauses and on the safeguards recognised by the Federal Data Protection Commissioner. We pass your data to no other company, and we do not sell it.
Google data (Google Calendar)
If you connect your Google Calendar, Appela requests a single permission on your calendar: to see and edit its events. Appela also accesses the email address of your Google account, to know which calendar is connected. Appela does not access any other Google data (emails, contacts, files, other calendars).
Use: adding the appointments and reservations taken by Appela to your primary calendar, updating or removing them, and reading the events in that calendar (date, time, title, description) to show them in your Appela calendar and avoid offering a customer a time that is already taken. Nothing else.
Sharing: this data is never sold, rented, transferred to advertisers or data brokers, or used for advertising. It is never sent to the artificial intelligence or voice services we use, and it is not used to train any artificial intelligence model. Only our technical hosting provider processes it, on our behalf and solely to operate the service. Nobody at Appela reads it, except with your consent to solve a problem, for security reasons, or when required by law.
Protection: exchanges with Google are encrypted (HTTPS) and data is encrypted at rest. The Google access token is stored server-side, never exposed to the browser, and an account’s data is only accessible to that account.
Retention and deletion: events read or created stay in Appela while your account is active. You can withdraw access at any time from Settings in Appela or from your Google account: synchronisation stops immediately and Appela reads nothing more. On request to contact@appela.ai, or when the account is closed, this data is deleted within thirty days.
Appela’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
How long we keep it
- Call transcripts and summaries: the period you chose, then automatic deletion.
- Appointments, bookings and customer records: for as long as your account is active.
- Accounting records and invoices: ten years, as Swiss law requires.
- After the account is closed: service data is deleted within thirty days, accounting records aside.
Your rights
You may ask to access your data, to have it corrected, deleted or ported, or object to a given use. Write to contact@appela.ai: we reply within thirty days.
If someone who called your business writes to us directly, we pass their request on to you — you are the controller for that data — and we help you answer it.
These rights are set out in detail on the GDPR and FADP page.
Security
Traffic is encrypted in transit, data at rest is encrypted at our hosting providers, and access to an account’s data is walled off: one customer cannot see another’s. The keys to our providers are held server-side and are never exposed to the browser.
No system is infallible. In the event of a data breach that presents a risk, we inform the people concerned and the Federal Data Protection and Information Commissioner as quickly as we can.
Cookies
The site uses the cookies it needs to work: keeping your session open and remembering your language. We set no advertising cookie and do not track your browsing on other sites. With your consent, given in the site banner, we also measure visits anonymously. You can change your mind at any time with the “Cookies” link at the bottom of the page.
Changes and contact
Any substantial change is notified to you by email or in the application before it takes effect. For any question: contact@appela.ai.
You may also complain to the Federal Data Protection and Information Commissioner (FDPIC), or to the supervisory authority in your country if the GDPR applies to you.
