Legal
Privacy Policy
1. Who we are
Boundless is operated by Boundless Labs, Inc. ("Boundless", "we", "us"). We provide an AI-powered call handling service that answers, qualifies, and routes telephone calls on behalf of our business customers.
This policy explains what we do with personal information when you visit this website, when you use Boundless as a customer, and when you call a phone number operated by one of our customers using Boundless.
2. Our role: controller and processor
Our obligations depend on whose data is involved.
- When you are our customer — for account details, billing, and support, we act as a controller. This policy governs that data.
- When you call one of our customers — the call audio, transcript, and any details you give during the call are handled by us as a processor on that customer's instructions. They are the controller and their own privacy notice governs that data. Our Data Processing Addendum sets out those terms.
3. What we collect
We collect the following categories of personal information.
Call data
- Call audio and recordings
- Transcripts and AI-generated summaries
- Caller telephone number and, where available, carrier-supplied location
- Call metadata: time, duration, outcome, routing decisions
- Any information a caller volunteers during a call, which may include name, address, appointment details, or account references
Customer account data
- Name, work email, company, and phone number
- Billing details, handled by our payment processor Stripe
- Configuration you create: agents, scripts, routing rules, numbers
Website data
- Information you submit through our demo request form
- We do not use third-party analytics, advertising, or tracking scripts on this website
Callers sometimes volunteer sensitive information — health details to a clinic, financial details to a billing line. We do not ask for it, and we treat anything volunteered with the same protections as the rest of the call.
4. Call recording and consent
Boundless records and transcribes telephone calls. Recording laws differ by jurisdiction: some require only one party's consent, others require every party's consent. Calls that cross state or national borders may be subject to the stricter rule.
- Our customers are responsible for ensuring calls placed to or received on their Boundless numbers may lawfully be recorded, and for providing any disclosure the law requires.
- We provide configurable call-start announcements to support that obligation. The announcement is enabled by default and can be configured per number.
- If you are a caller and do not consent to recording, tell the agent and ask to be transferred or to end the call.
Recording rules differ by state and country, and the stricter rule applies when a call crosses a border. If you are unsure whether a call may be recorded, treat it as though every party must consent.
5. Why we use it
We use personal information to:
- Provide the service — answer, transcribe, qualify, and route calls
- Produce summaries, analytics, and transcripts for the customer whose number was called
- Bill for usage, including minutes beyond a plan's included allowance
- Support customers and investigate faults
- Keep the service secure and prevent abuse
- Meet legal obligations
We do not use customer call data to train or fine-tune AI models. Recordings, transcripts, and summaries are used only to deliver the service to the customer whose number was called, and to support and secure it. Our agreements with these providers prohibit them from training on data we submit.
Where GDPR applies, our legal bases are performance of a contract, legitimate interests, consent where required, and compliance with legal obligations. Delivering the service and billing rely on performance of a contract; security, abuse prevention, and service improvement rely on legitimate interests; call recording relies on consent where the law requires it; and retention of billing records relies on legal obligation.
7. How long we keep it
Customers control their own retention. You can shorten how long call recordings, transcripts, and summaries are kept, and you can delete them entirely — either individually or by turning retention off, so nothing is stored after a call ends.
Until you change it, recordings, transcripts, and summaries are retained for 90 days and call metadata for 24 months. Deleted data is removed from active systems immediately and expires from encrypted backups within 30 days.
Customers can request deletion of their data at any time. Where we act as processor, we delete or return data on the controller's instruction as set out in the Data Processing Addendum.
8. How we protect it
Data is encrypted in transit with TLS and at rest. Access is restricted to personnel who need it, granted on a least-privilege basis, protected by multi-factor authentication, and logged. Personnel are bound by confidentiality obligations.
We do not currently hold SOC 2, ISO 27001, or HIPAA certification. We will say so here if that changes.
9. Your rights
Depending on where you live you may have the right to access, correct, delete, port, or restrict use of your personal information, and to object to certain processing.
- EEA and UK residents — rights under GDPR, including the right to complain to a supervisory authority.
- California residents — rights under the CCPA as amended, including the right to know, delete, correct, and opt out of sharing. We do not sell personal information.
- Other US states — residents of states with comprehensive privacy laws, including Virginia, Colorado, Connecticut, Utah, and Texas, have comparable rights to access, correct, delete, and port their information, and to opt out of targeted advertising and profiling. We do not conduct targeted advertising or profiling.
To exercise a right, contact [email protected]. If your data was collected because you called one of our customers, we will route your request to that customer, who is the controller.
11. Children
The service is not directed at children and we do not knowingly collect their personal information. If you believe a child's information has reached us, contact us and we will delete it.
12. Changes to this policy
We will post any change on this page and update the date above. Material changes will be notified to customers directly. We will give at least 30 days notice of material changes.
13. Contact us
Boundless Labs, Inc.
[email protected]
We have not appointed an EU or UK representative or a Data Protection Officer, as we are not currently required to. Privacy enquiries go to the address above.