Privacy Policy — Aelo — AI Call & Chat Analytics
1. What This Policy Covers
This policy describes the Aelo — AI Call & Chat Analytics application ("the Application") published by Auspex Streamline S.L.: what it accesses in your Bitrix24 portal, what it transmits outside it, what it writes back, and how long the resulting data is kept.
The Application is a client for the Aelo cloud service. Processing performed by the service as a whole — including for customers who do not use Bitrix24 — is described in the general Aelo Privacy Policy, the Data Processing Agreement and the Sub-processors register. Where this policy is silent, those documents apply.
2. Who Is Responsible for What
Under the GDPR, the organization that installs the Application on its Bitrix24 portal is the controller of the call, chat and employee data it submits for analysis. Auspex Streamline S.L. is the processor, acting on the controller's documented instructions.
| Responsibility | Party |
|---|---|
| Deciding to install the Application and which data it may access | Portal administrator (Controller) |
| Obtaining consent from call participants before recording | Portal administrator (Controller) |
| Informing employees that their calls are analyzed using AI | Portal administrator (Controller) |
| Processing and storing the data securely | Auspex (Processor) |
| Providing deletion and data-subject-request tooling | Auspex (Processor) |
3. What the Application Reads From Your Bitrix24
The Application requests only the Bitrix24 permissions (scopes) it uses. Each is listed below with the reason it is required.
| Permission | What is read | Why |
|---|---|---|
| Telephony | Call records and their metadata — direction, duration, timestamps, participant phone numbers, the responsible employee, and the location of the recording file | To find the calls to analyze and to retrieve the audio |
| Drive | The recording file for a call being analyzed | Bitrix24 stores call recordings on Drive; the audio itself is the input to the analysis |
| CRM | The call activity and the linked lead, deal, contact or company — names, the deal's pipeline, stage and stage history, and the labels of custom fields. Immediately before writing results back, the current values and type definitions of the fields you designated (see Section 5.1), so that a populated field is not overwritten | To attach the analysis to the correct record, to select the evaluation scorecard matching the deal stage, and to write results without destroying data already in the record |
| Chat / Open Channels | Message history of open-channel conversations, when text-conversation analysis is enabled | Aelo analyzes written customer conversations in the same way as calls |
| Users (minimal) and company structure | For the person opening the Application: their identifier in your portal and their name — no e-mail address and no other contact detail. For employees linked to analyzed conversations: identifier, name and department membership. On an administrator-initiated import: the portal's department tree and the department heads it names | The identifier in your portal is what identifies the employee's Aelo account, so no address needs to be read to sign them in. Names attribute a conversation to the employee who handled it; the department tree determines which records a department head may open |
| Tasks | Nothing is read — this permission is used only to create tasks (see Section 5) | To create a follow-up task on a flagged conversation |
The Application also subscribes to the portal events ONCRMACTIVITYADD and ONCRMACTIVITYUPDATE so it learns when a new call appears, and it reads its own installation record via app.info.
4. What Leaves Your Bitrix24
- The recording of a call selected for analysis is downloaded from your portal and stored encrypted (Cloudflare R2, AES-256-GCM server-side encryption) in the Aelo service.
- The audio is sent to a speech-to-text provider (ElevenLabs) to produce a transcript.
- Personal data is redacted from the transcript — phone numbers, e-mail addresses, payment card numbers and IBANs — before the transcript is stored and before it is sent for analysis.
- The redacted transcript is sent to a large language model provider (OpenAI) which produces the analysis: quality score, sentiment, key points, flags with quotes and timecodes.
- If your organization has defined criteria — its own questions asked of every conversation — the redacted transcript is sent to the same provider again, together with the text of the criteria that apply to the conversation, to answer them. The answers, their quotes from the redacted transcript, the model's short explanation and — when known — the identifier of the employee who handled the conversation are kept with the record and deleted together with it. When the organization owner checks a criterion's wording before saving it, up to 20 recent analysed conversations are sent the same way with the draft wording; those answers are shown and not kept.
- If your organization has the Voice of Customer section (Pro plan and above), the redacted transcript of each newly analysed conversation is sent to the same provider again, in a separate request, to find the questions the customer asked (up to 10) and, for a sales conversation, how it ended and — when the customer declined — the reason. The results, with the customer's words quoted verbatim from the redacted transcript, are kept with the record and deleted together with it. Conversations analysed before this was introduced are not processed in bulk; a conversation your organization re-analyses is processed like a new one.
- Segments of the redacted transcript — or of a redacted chat conversation — are sent to the same provider to compute numerical vectors for search by meaning; only the vectors are kept, with identifiers of the record, project, organization and transcript, the record type and the segment’s length, and — when known — an identifier of the employee who handled it (their Bitrix24 user ID, or their ID in the connected telephony or in Aelo) and the record’s date, without the text. The text a user types into search is sent to the same provider, redacted the same way, to compute a vector used for that search only.
- When an employee asks the AI assistant (Pro plan and above) a question — about one call, about a CRM deal, lead, contact or company across its linked calls and chats, or about all the analysed calls and chats the employee may see — the question, redacted the same way, is sent to the same provider together with the redacted transcripts and analyses the answer is built from. For a question about all records, the question is first matched by meaning against the search index (its vector is not kept), up to 12 of the closest records are used, and the filters it was asked under — period, record type, category, customer name — are sent with it. Only records the employee may see are ever used. The question and its answer are kept for the employee to return to for your organization's retention period, and are deleted with any record the answer was built from.
- CRM context needed to interpret the conversation — the linked record's identifier, the deal's pipeline and stage, the employee's name — accompanies the analysis inside the Aelo service.
Every third party involved, the data each receives, its location and the transfer safeguard applied are listed in the Sub-processors register, which we update at least 30 days before adding a new sub-processor.
5. What the Application Writes Back
Results are returned into your portal so that they are usable where your team already works:
- A comment or note on the CRM record's timeline carrying the verdict of the analysis.
- An item in a dedicated smart process ("Call data") holding the full breakdown. On first use the Application creates this smart process and its custom fields on the CRM module. It does not create or modify custom fields in employee profiles.
- Values in the CRM fields you designate. You decide, per data source, which output of the analysis goes into which field of your lead, deal, contact or company — for example the transcript into one custom field and the summary into another. The Application writes only into the fields you have mapped.
- The transcript attached to the call in Bitrix24 telephony.
- A task for the responsible employee when a conversation triggers a rule that calls for follow-up.
- A notification or chat message inside the portal, when in-portal delivery is configured.
5.1 How existing values are treated
Before writing, the Application reads the record's current field values and field definitions so that it never silently destroys data. Per field:
- an empty field receives the new value;
- a filled text field keeps its content and the new value is appended below it;
- a filled non-text field (number, date, list, and similar) is left untouched and the value is not written.
One exception, stated plainly: if that read of the current values fails — for example the portal is unreachable at that moment — the Application cannot tell which fields are populated. In that case values extracted from the conversation (Section 5.2) are discarded entirely, while the fields you designated for Aelo's own output are written directly and may replace what was in them. Fields you never mapped are unaffected either way.
5.2 Filling empty fields from the conversation (optional, off by default)
Your administrator can additionally enable auto-fill of empty CRM fields and choose which fields are eligible. When this is on, the language model is asked to extract values for those specific fields from the conversation itself — for instance a delivery address, a budget or a requirement that the customer stated out loud — and the Application writes them into your CRM.
Two limits apply to this mode and are enforced in code, not by policy alone:
- Extracted values are written only into fields that are empty. A field that already holds a value is never overwritten or appended to by auto-fill.
- Only the fields your administrator selected are eligible. If the Application cannot determine which fields are already populated, or if delivery was redirected to a different CRM record than the one the conversation belongs to, auto-fill is skipped entirely rather than applied on a guess.
This setting is disabled by default. Enabling it means content spoken by a call participant may be stored in your CRM's structured fields, so the decision — and informing the participants about it — rests with you as controller.
6. What the Application Does Not Do
- It does not create, invite, modify or deactivate users in your Bitrix24.
- It does not read or write custom fields in employee profiles.
- It does not read employees' personal contact details at all — no e-mail addresses, personal phone numbers, addresses or birthdays. If you choose to give Aelo an address so it can send you reports, you type it into the Application yourself; it is never read from your portal.
- It does not delete CRM records, calls or files in your portal.
- It does not sell, rent or share your data with advertisers or data brokers.
7. Storage and Retention
| Data | Retention |
|---|---|
| Audio recordings retrieved from your portal | 365 days, then deleted together with the transcript |
| Transcripts (with personal data redacted) | 365 days |
| Analyses, metrics and conversation metadata | Follows transcript retention |
| Search vectors (no text) | Rebuilt from the current transcript when the call is transcribed again (if that build fails, the earlier vectors stay until the next index rebuild) or the index is rebuilt; removed from the index after the record is deleted — by a user, at the end of the retention period or together with its project — normally within a few hours; while a large volume of deletions is being processed, removal can take several days |
| Employee accounts and the imported department tree | Duration of the account; the tree is replaced in full on each import |
| OAuth tokens for your portal | Marked inactive the moment the Application is removed — Bitrix24 revokes them at that point, so they cannot be used afterwards. The installation record itself is erased on request, or together with the account |
Data is stored on Cloudflare and Neon infrastructure; the database and the audio storage are in the EU. The search index (numerical vectors with record and employee identifiers, no text) and Cloudflare's processing state, queues, logs, caches and coordination state are not pinned to the EU; some of them hold call transcript and chat text while a conversation is processed and for a few days after. The full security description is in the Aelo Privacy Policy and the DPA.
8. Removing the Application and Deleting Data
Removing the Application from your Bitrix24 stops all access to your portal: its event subscriptions are cancelled and its installation record is deactivated, so no further data is read.
Removal does not by itself erase data already analyzed. Recordings, transcripts and analyses remain in your Aelo account and are deleted on the retention schedule above. To have them erased sooner, request deletion of your Aelo account or of specific records by writing to privacy@aelo.cloud. We act on such requests without undue delay and within the periods required by applicable data protection law.
9. Rights of Employees and Call Participants
Employees whose conversations are analyzed, and customers who took part in them, are data subjects. Because the organization operating the portal is the controller, requests to access, correct, delete or object should be addressed to that organization, which uses Aelo's tooling to fulfil them.
If you cannot identify or reach the controller, write to privacy@aelo.cloud and we will help route the request.
10. Changes to This Policy
We may update this policy as the Application changes. Material changes affecting what is read from your portal or what leaves it will be communicated to customers by e-mail at least 30 days before they take effect.
11. Contact
Publisher / Processor:
Auspex Streamline S.L.
C.I.F.: B56341829
Calle Velarde 13, 4B
35010 Las Palmas de Gran Canaria
Canarias, Spain
Privacy inquiries: privacy@aelo.cloud
Application support: support@aelo.cloud
Document ID: PP-Aelo-B24-2026-001 · Version: 1.6