Let’s talk
Back to Halo Halo Services Ltd · Updated 29 September 2026

Privacy policy

1. Who we are and when this policy applies

Halo Services Ltd (“Halo”, “we”, “us”) provides AI reception technology for healthcare practices in New Zealand and Australia. We are responsible for information we collect for our own website, demonstration and business enquiries. When a practice uses Halo to handle patient calls, we generally process that information on its instructions. The practice remains responsible for its care, patient records, collection notices and lawful instructions. Our own legal obligations still apply.

This policy describes the public demonstration currently available. A live practice deployment requires a separate service agreement and data-processing schedule setting out approved purposes, suppliers, locations, access and retention. The public demo is not a patient service. Email bilal@heyhalo.net or saif@heyhalo.net, with “Privacy” in the subject line.

2. Information we collect

Website: our hosting provider processes technical information such as your IP address, browser, requested pages, timestamps and security events to deliver and protect the site. We have not installed advertising trackers or marketing analytics.

Enquiries: when you email us, we receive your name, address, message and any information you choose to provide. Please do not send patient records or sensitive health information in an initial enquiry.

Voice demo: if you choose to start a call, our providers process microphone audio to recognise speech and generate a response. We retain a text transcript and call metadata, such as time, duration, status and your example practice configuration. Audio recording is disabled for this demo. Audio is still transmitted and processed during the call. Live captions shown in your browser are not saved to browser storage by Halo.

Practice services: depending on the agreed setup, information may include caller contact details, appointment requests, practice instructions, call notes and relevant health information volunteered by a caller. Audio recordings require a separately agreed purpose, lawful recording arrangements and clear notice. Do not use the public demo for real patient information, identifiers, payment card details or emergencies.

3. How and why we collect it

We collect information directly when you use the demo, email us or interact with a practice’s Halo service. A practice may also supply information needed for an authorised workflow. Where information is collected indirectly, we and the practice must consider applicable notification requirements, including New Zealand’s indirect-collection requirements effective from 1 May 2026.

We use information to answer enquiries, provide and troubleshoot the agreed service, maintain security, investigate misuse, manage our business relationship and meet legal obligations. We limit collection to information reasonably necessary for those purposes. Sensitive information requires consent or another applicable lawful basis. A practice must arrange appropriate notices and permissions before sending patient information to Halo.

Halo does not sell personal information. We do not use patient conversations to train a general-purpose AI model ourselves. Supplier processing and any supplier model-improvement settings must be assessed and agreed before a practice deployment; the public demo is not a promise of zero retention by all suppliers.

4. Choice, AI disclosure and recording

The demo does not activate your microphone until you choose to start the call and allow microphone access in your browser. You can stop the call at any time. If you decline, you can still browse the site or contact us by email. You may use a fictional name and fictional practice details.

The receptionist identifies itself as AI. AI can misunderstand speech and produce incorrect information. Do not rely on it for diagnosis, treatment, clinical triage or an emergency response. Example appointments are not real bookings. Practices must provide a suitable human contact option and meet applicable recording and surveillance laws in each relevant jurisdiction. A general website notice does not replace call-specific notice or consent where required.

5. Who processes information and where

This website is hosted by Vercel. The demonstration uses Vapi to coordinate calls, Daily for browser audio transport, Deepgram for speech recognition, OpenAI for language processing, and ElevenLabs for speech generation. Only information needed for the relevant processing step is sent to each provider. Our authorised personnel may access records for support, security and service review. Email is handled by our configured email service.

These suppliers may process information outside New Zealand and Australia, including in the United States, and may use international infrastructure or subprocessors. We do not represent that this demo is hosted solely in New Zealand or Australia. Supplier locations and terms may change; contact us for the current deployment-specific list before providing sensitive information.

Before a live practice deployment, we assess supplier terms and safeguards and document applicable overseas-transfer arrangements. New Zealand Privacy Act requirements (including relevant overseas-disclosure rules) and Australian Privacy Principle 8 must be considered where applicable. Consent to this demo is not a blanket waiver of those protections.

We may disclose information when legally required, to professional advisers under duties of confidentiality, to investigate unlawful activity where permitted, or to protect lawful rights. Any business transfer must preserve applicable privacy protections and appropriate notice.

6. Retention and deletion

Public demo: the intended retention period for transcripts and call records is 7 days from creation. The site includes a daily deletion task for this demo’s records, so routine deletion may occur on the next daily run after that period. Audio recording is disabled. If a deletion task fails, records remain until the failure is corrected; we do not promise immediate erasure from every supplier backup.

Business enquiries: our recommended operational schedule is deletion or de-identification 12 months after the last meaningful contact where no customer relationship or ongoing need exists. Contract, accounting and dispute records may need longer retention to satisfy applicable legal duties. These email and business-record schedules require operational administration.

For live practice deployments, we recommend audio recording off by default; where lawfully required, a short, documented period such as 30 days; and transient transcripts or operational summaries normally no longer than 90 days unless a documented purpose requires otherwise. The signed schedule must specify actual periods and backup expiry. These are starting points for assessment, not universal legal retention periods.

Information forming part of a patient’s clinical record may have a different legally required retention period. The practice must identify which records belong in its clinical record system and preserve them for the period that applies to that practice, patient and jurisdiction. Deleting an operational copy from Halo does not authorise deletion of a required clinical record.

Legal holds, investigations or statutory obligations may justify longer retention of specific records with restricted access. Supplier security logs and backups can follow separate contractual schedules. We aim to remove or de-identify data when no lawful purpose remains and require the relevant supplier to handle deletion requests under its applicable terms.

7. Security and incidents

We use proportionate safeguards and seek to improve them as the service develops. The website uses HTTPS; private service credentials are kept on the server; the public demo is separated from existing practice assistants; and deletion access requires server-side authentication. Access to personal information should be limited to authorised people who need it. We do not claim an independent certification, complete legal compliance by default, or that any system is immune from compromise.

A production practice deployment must confirm supplier encryption, access controls, multi-factor authentication, logging, incident response and backup arrangements in its data-processing schedule. Security is a shared operational responsibility, not something a policy alone can guarantee.

If we become aware of a suspected personal-information breach, we will investigate, contain it and cooperate with affected practices. We will make notifications to individuals and regulators where legally required, including under New Zealand’s notifiable privacy-breach rules and Australia’s Notifiable Data Breaches scheme where applicable.

8. Access, correction and complaints

You can ask us what information we hold about you, request access or correction, raise a concern or request deletion where permitted. We may verify your identity in a proportionate way and explain any lawful limits. If a request concerns a practice’s patient records, contact that practice first; we will assist it or direct your request as appropriate. Email bilal@heyhalo.net or saif@heyhalo.net, with “Privacy” in the subject line.

For information we control, we aim to acknowledge requests promptly and respond within the time required by applicable law. New Zealand access decisions are generally required within 20 working days, subject to lawful extensions. In Australia, we aim to respond within 30 days. Deletion is not an unconditional right where continued retention is legally required.

If a concern is not resolved, you can contact the New Zealand Office of the Privacy Commissioner or the Office of the Australian Information Commissioner. Relevant state or territory health-privacy complaint pathways may also apply.

9. Changes and further information

We will update this policy when the service or our information-handling practices change. Material changes should be communicated before information is used for a materially different purpose; additional consent will be sought where required. The date above identifies this version.

The service must be assessed against the NZ Health Information Privacy Code, where applicable, and the Australian Privacy Principles, alongside relevant state and territory law. Production healthcare use requires deployment-specific legal and privacy review.