Sylo Privacy Policy
Effective date: July 25, 2026 Version: 2026-07-25
In plain words
- Sylo is an AI receptionist that answers calls, texts, and web chats for the businesses that subscribe to it. Wayhow runs Sylo.
- If you are one of those businesses, we are responsible to you directly for your account, billing, and support data.
- If you called, texted, or chatted with a business that uses Sylo, that business decides how your information is used. We process it only on that business's instructions. Contact the business first; we will help.
- The AI always tells you it is an AI. It never pretends to be human.
- We do not sell personal information, we do not share it for advertising, and one business's data never trains another business's AI.
- Card numbers go to Stripe, our payment processor. We never store them.
- When a subscription ends, the business can export its data, and we purge it 30 days after cancellation.
- Questions: info@wayhow.ai.
1. Who we are and what this policy covers
Sylo is an AI receptionist service for small businesses, operated by Wayhow Technology Solutions Inc. ("Wayhow", "we", "us", "our"), a corporation incorporated under the laws of Ontario, Canada. Sylo answers a subscribing business's phone line with an AI agent, responds to SMS messages, and powers an embeddable website chat widget. It can book appointments, take orders, take messages, answer questions from the business's knowledge base, and hand the conversation to a human.
This Privacy Policy explains how we collect, use, disclose, and protect personal information in connection with Sylo, including the sylo.wayhow.ai website and dashboard. It applies to:
- Tenants: the businesses that subscribe to Sylo, and the individuals who use Sylo on a Tenant's behalf (owners, staff, authorized users);
- End Users: the people who call, text, or chat with a Tenant's business through Sylo;
- Visitors: people who browse our websites.
Words like "personal information" mean information about an identifiable individual, as defined by the privacy law that applies to you.
2. Two roles: when we answer to you, and when the business you contacted does
Wayhow plays two distinct roles, and your rights flow differently depending on which one applies.
2.1 Wayhow as controller. For Tenant account data, billing data, website visitor data, and support communications, Wayhow decides why and how the information is processed. In the language of privacy laws, Wayhow is the "controller" (GDPR), the "business" (California), and the accountable organization (PIPEDA). Sections of this policy about our own purposes, lawful bases, and marketing apply to this data.
2.2 Wayhow as processor and service provider. When an End User calls, texts, or chats with a business that uses Sylo, that business (the Tenant) decides why and how the End User's personal information is processed. The Tenant is the controller or business; Wayhow is the Tenant's processor, service provider, and contractor. We process End User personal information only to provide Sylo to that Tenant, under the instructions in our Data Processing Addendum (available at /legal/dpa), and never for our own advertising or for training AI across customers.
2.3 If you are an End User. The privacy practices of the business you contacted govern your information, including how long it is kept and how requests are handled. Please direct privacy questions and requests (access, correction, deletion) to that business first. If you cannot reach the business, or you are not sure which business it was, contact us at info@wayhow.ai and we will help route your request and will assist the business in fulfilling it.
3. Personal information we collect
3.1 Tenant account data (Wayhow as controller): name, business name and address, email address, phone number, login credentials (passwords are stored hashed), multi-factor authentication settings, subscription plan, account settings, and support history.
3.2 Billing data (Wayhow as controller): payments are processed by Stripe. We receive payment metadata such as payment status, amounts, invoice history, card brand, and the last four digits of the card. We never receive or store full card numbers or security codes. If a Tenant connects its own Stripe account to accept payments from its customers, those payments go directly to the Tenant's Stripe account; Wayhow never holds those funds.
3.3 Conversation content (Wayhow as processor for the Tenant): the content of voice calls (transcripts of every conversation; audio recordings only where the Tenant has turned recording on, see Section 6), SMS messages, and web chat messages, together with metadata such as phone number, channel, timestamps, call duration, AI confidence scores, and knowledge citations. Transcripts are shown to the Tenant in its dashboard inbox.
3.4 Customer memory (Wayhow as processor for the Tenant): Tenants keep profiles of their customers, such as name, phone number, notes, booking history, and order history. Returning callers may be recognized by phone number so the business can greet them by name. Tenants can erase an individual customer's profile at any time (see Section 10).
3.5 Knowledge base content (Wayhow as processor for the Tenant): the business information a Tenant provides so the AI can answer questions, such as hours, services, prices, menus, policies, and FAQs. Tenants should not put personal information in knowledge base content unless it is necessary and lawful for their use of Sylo.
3.6 Usage and telemetry data (Wayhow as controller): logs of errors, latencies, and call and message metadata used to run and secure the service. Our logs are metadata only: they never contain the content of conversations, and AI prompts and responses are never sent to telemetry.
3.7 Cookies and similar technologies: our websites use cookies for sign-in, preferences, and analytics. Details, including your choices, are in our Cookie Policy (available at /legal/cookie-policy).
4. How we use personal information, and our lawful bases
Where GDPR or UK GDPR applies to processing for which we are the controller, our lawful bases are noted in parentheses.
- Provide the service: operate the AI receptionist, deliver conversations to the Tenant's dashboard, book appointments, take orders and messages, and route escalations (performance of a contract; for End User data, we act on the Tenant's instructions).
- Accounts and billing: create and secure accounts, process subscriptions and any usage charges through Stripe, and send invoices and renewal notices (performance of a contract; legal obligation for tax and accounting records).
- Service communications: send transactional emails and messages such as booking confirmations, security notices, purge warnings, and renewal reminders (performance of a contract; legitimate interests). SMS recipients can opt out of messages by replying STOP, which we honor.
- Security and abuse prevention: authenticate users, enforce tenant isolation, monitor for fraud and abuse, and keep audit logs (legitimate interests; legal obligation).
- Service improvement: analyze metadata about reliability, latency, and usage to improve Sylo (legitimate interests). This does not include using one Tenant's content to benefit another Tenant, see Section 7.
- Legal compliance: comply with applicable law, respond to lawful requests, and establish or defend legal claims (legal obligation; legitimate interests).
- With your consent, where consent is the required basis, for example optional marketing emails or non-essential cookies (consent, which you can withdraw at any time).
We do not use personal information for purposes incompatible with these, and we collect only what we need for them.
5. AI transparency
- The AI always discloses itself. Every Sylo conversation begins with a disclosure that the caller or writer is interacting with an AI assistant (a spoken greeting on calls, a visible banner on chat). If asked, the AI confirms it is an AI. It never pretends to be human.
- Humans stay in the loop. Every conversation, with its transcript, is visible to the Tenant in its dashboard inbox for review. The AI escalates or transfers to a human when the Tenant has configured it to, or when the situation calls for it.
- No automated decisions with legal effects. Sylo answers questions, takes bookings, orders, and messages. It does not make automated decisions that produce legal or similarly significant effects on End Users, such as decisions about credit, employment, housing, insurance, or eligibility for services.
- Not a substitute for professionals or emergency services. Sylo is a communications tool. It does not provide legal, medical, or other professional advice, and it is not an emergency service; it directs emergencies to the appropriate emergency number.
6. Call recording
Call recording is off by default. A Tenant may turn it on. When recording is on:
- callers hear a recording disclosure at the start of the call, and recording is consent-gated according to the caller's jurisdiction, including two-party consent rules where they apply;
- every disclosure played is logged per call;
- recordings are available only to the Tenant, played back through an access-controlled proxy in the Tenant's dashboard;
- recordings are retained as the Tenant configures, and are deleted with the rest of the Tenant's data under Section 10.
Sylo does not create voiceprints, identify or verify anyone by their voice, or use voice audio for biometric identification.
7. What we never do with your information
- No sale. We do not sell personal information, and we have not done so.
- No advertising sharing. We do not share personal information for cross-context behavioral advertising or targeted advertising.
- No cross-tenant AI training. One Tenant's data (knowledge base, conversations, customer profiles) never trains or informs another Tenant's AI, and we do not use End User conversation content to train models across customers.
8. How we disclose personal information
8.1 To the Tenant. End User conversations, profiles, bookings, and orders are disclosed to the Tenant whose business the End User contacted. That is the point of the service.
8.2 To sub-processors. We use a small, vetted set of third-party providers to run Sylo, in these categories: cloud hosting and content delivery; database and storage; telephony and messaging carriage; speech-to-text and text-to-speech; large language model providers; transactional email delivery; payment processing (Stripe); and error monitoring. Each is bound by a data processing agreement with confidentiality, security, and use-limitation obligations at least as protective as ours, and international transfers to them are governed by Standard Contractual Clauses where required. We do not publish an itemized vendor list; where a Tenant's contract requires vendor disclosure, we provide it under NDA. Tenants receive 30 days' notice before any new category of sub-processor begins processing their data. Full terms are in the Data Processing Addendum.
8.3 Legal and safety. We may disclose personal information where required by law, regulation, legal process, or enforceable governmental request, or where necessary to protect the rights, safety, or property of Wayhow, our Tenants, or others. Where the request concerns a Tenant's End User data, we will direct the requester to the Tenant and notify the Tenant unless legally prohibited.
8.4 Corporate transactions. If Wayhow is involved in a merger, acquisition, financing, or sale of assets, personal information may be transferred as part of that transaction, subject to safeguards and to this policy or one at least as protective.
We do not disclose personal information to anyone else.
9. Where your information is processed, and cross-border transfers
Wayhow is a Canadian company. Sylo's primary infrastructure is cloud-hosted in the United States, so personal information is processed in the United States and may be accessed from Canada. These countries may have privacy laws that differ from those where you live, and information there may be accessible to local authorities under local law.
- Canada (PIPEDA and Quebec Law 25). We remain accountable for personal information we transfer to service providers, and we use contracts to require comparable protection. For individuals in Quebec: personal information may be communicated outside Quebec as described above; we assess the privacy impact of such transfers, and the person responsible for the protection of personal information at Wayhow can be reached at info@wayhow.ai.
- EEA and UK. Where GDPR or UK GDPR applies, transfers outside the EEA or UK rely on the European Commission's Standard Contractual Clauses, supplemented by the UK International Data Transfer Addendum for UK transfers, together with transfer risk assessments and supplementary measures where needed. Tenants can obtain these terms through the Data Processing Addendum.
- United States. State privacy laws applicable to our Tenants' End User data are addressed through our service-provider commitments in the Data Processing Addendum and, for California, in our California Privacy Notice (available at /legal/ccpa-notice).
10. Retention and deletion
- During the subscription: we retain Tenant data, including conversation content, customer profiles, and knowledge base content, for as long as the Tenant's subscription is active, so the Tenant can use it.
- After cancellation: the Tenant's data remains available for export for 30 days after cancellation, and we send a warning email about a week before the purge. After the 30-day window, an automatic purge permanently deletes the Tenant's data.
- Self-serve deletion: a Tenant can export all of its business data as a single file, or delete its entire account and all of its data, at any time from the dashboard, no support ticket required.
- Per-customer erasure: a Tenant can erase an individual End User in one confirmed step. This removes that person's transcripts, learned details, and messages; aggregate booking counts retain numbers only, with no personal information.
- Recordings: retained as the Tenant configures, and always covered by the deletion mechanisms above.
- Billing and tax records: retained for the periods required by tax and accounting law.
- Legal hold: we may retain specific information longer where required by law, legal process, or the establishment or defense of legal claims, and we delete it when the requirement ends.
11. Security
We protect personal information with safeguards that include:
- Tenant isolation by design: every row of data carries a tenant identifier, and row-level security in the database enforces that boundary on every read and write, with a second tenant-scope check in the AI retrieval layer before any model sees data.
- Encryption: TLS 1.3 in transit; encryption at rest for the database, file storage, and backups. Recordings and transcripts inherit the same posture.
- Least privilege: runtime AI services use least-privilege scoped tokens, with no master credentials on edge services; secrets live in a dedicated store, never in source code or logs.
- Access controls: multi-factor authentication is available on every Tenant account, with recovery codes. Wayhow staff access to production systems is least-privilege and protected by multi-factor authentication, and staff reach Tenant data only through a privileged internal credential, used when a Tenant asks us to look into something. There is no staff "log in as you" impersonation feature.
- Metadata-only logging: monitoring captures errors, latencies, and call metadata, never conversation content; a redaction filter drops known-sensitive fields before logs leave our systems.
- Honest audit posture: SOC 2 is planned, not certified. We do not claim SOC 2, ISO 27001, HIPAA, or HITRUST today, and we will not until we have earned them. Current status is on our security page at /security.
No service can guarantee absolute security. Tenants and their users must protect their credentials and promptly report suspected unauthorized access to info@wayhow.ai.
12. If something goes wrong: breach notification
If a security breach affects personal information, we will act promptly to contain it, assess the risk of harm, and notify affected Tenants without undue delay so they can meet their own obligations to their End Users and regulators. We will notify individuals and regulators where and as required by applicable law, including reporting to the Office of the Privacy Commissioner of Canada for breaches creating a real risk of significant harm under PIPEDA, and to the Commission d'acces a l'information du Quebec for confidentiality incidents presenting a risk of serious injury under Quebec Law 25, and we keep records of breaches as those laws require. Our notices will be accurate and timely, not speculative.
13. Your rights
13.1 Tenants (self-serve). Tenants can access, export, and correct their data in the dashboard, export everything as a single file, delete individual customers, and delete the entire account, all self-serve. For anything the dashboard does not cover, email info@wayhow.ai.
13.2 End Users. Your rights are exercised through the business you contacted (the Tenant), which controls your information. Ask that business to access, correct, or delete your information; Sylo gives it the tools to do so, including one-step per-customer erasure. We assist Tenants in responding to requests, and if you contact us directly we will forward your request to the Tenant and help, or respond ourselves where the law requires us to.
13.3 EEA and UK (GDPR and UK GDPR). Where these laws apply, you have the rights of access, rectification, erasure, restriction of processing, data portability, and objection (including to processing based on legitimate interests), and the right to withdraw consent at any time without affecting prior processing. You also have the right to lodge a complaint with your national supervisory authority in the EEA, or with the Information Commissioner's Office (ICO) in the UK.
13.4 Canada (PIPEDA and provincial laws). You may request access to your personal information, request correction of inaccuracies, withdraw consent subject to legal or contractual restrictions, and ask questions or make complaints about our practices. You may also challenge our compliance and complain to the Office of the Privacy Commissioner of Canada, or in Quebec to the Commission d'acces a l'information.
13.5 California and other US states. California residents should see our California Privacy Notice at /legal/ccpa-notice. Residents of other states with comprehensive privacy laws (such as Virginia, Colorado, Connecticut, and Utah) have similar rights of access, correction, deletion, and portability, exercisable as described in this Section 13; where we act as a Tenant's processor, requests are routed through the Tenant.
13.6 How we handle requests. We verify requests before acting on them, respond within the time limits of the applicable law, and never discriminate against anyone for exercising a privacy right.
14. Children
Sylo is a business-to-business service and is not directed to children. We do not knowingly collect personal information from anyone under 16 for our own purposes, and Tenants must not use Sylo to knowingly collect children's personal information without a lawful basis. If you believe a child's personal information has been provided to us, contact info@wayhow.ai and we will delete it.
15. Changes to this policy
We may update this policy from time to time. If we make material changes, we will notify Tenants by email or through the dashboard before the changes take effect, and we will update the effective date and version above. The current version is always at /legal/privacy-policy.
16. Contact us
Wayhow, Ontario, Canada Email: info@wayhow.ai
This address reaches our privacy team, our security team, and, for the purposes of Quebec Law 25, the person responsible for the protection of personal information at Wayhow. If you are an End User, remember that the fastest route for most requests is the business you contacted (Section 2.3); we are your backstop.