Skip to content
Tern

Legal

Privacy policy

How Tern collects, uses, stores and protects personal information, including the conversations, call recordings, transcripts and AI analyses held in our customers' workspaces.

Draft for legal review. Effective date to be set on review.

1.Who we are and what this policy covers

Tern is a sales operating system operated from Australia. It captures conversations a business has with its leads and customers, records and transcribes calls, keeps an outcome for every lead and helps agents decide who to contact next. This policy explains how we handle personal information when you use the Tern application, the Tern Bridge browser extension and this website.

We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles. Where we process information on behalf of a customer, we do so under the customer's instructions and the agreement between us.

This policy uses a few terms throughout:

  • Customer means the business that holds a Tern workspace and its authorised users, such as sales agents and managers.
  • Contact means a person the customer communicates with through Tern, such as a lead, client or enquirer.
  • Customer data means the messages, recordings, transcripts, notes, contact details and related records the customer brings into Tern or that Tern captures for the customer.

2.Our two roles: service provider and operator

We act in two distinct roles. The role determines what we may do with the information.

As a service provider to our customers. For customer data, including every conversation, recording, transcript and AI analysis, the customer decides what is collected and why. We process it only to provide the service, keep it secure and meet our legal obligations. The customer remains responsible for its own privacy obligations to its contacts, including notice and consent.

As an operator in our own right. For account information about our customers and their users, information about visitors to this website and information we need to bill, support and secure the service, we decide the purpose of collection and this policy applies directly.

3.Information we collect

Account and workspace information

  • Name, work email address, role and organisation of each user.
  • Sign in records, including the method used, the time and the network address.
  • Billing details, such as the billing contact, plan, invoices and the last four digits of a card. Full card details are held by our payment provider, not by us.
  • Settings the customer chooses, including the AI processing toggle, recording policy, retention period and quiet hours.

Customer data captured through the service

  • Messages and threads captured from messaging platforms and mailboxes the customer connects, including sender, recipient, time, text and attachment metadata.
  • Media the customer chooses to store, such as images, documents and voice notes from a captured thread.
  • Call records, including the number, direction, time and duration. Where the customer's recording policy is on, the call audio as well.
  • Transcripts produced from recordings.
  • Contact records: name, phone number, email address, messaging identifiers, social profile links and any fields the customer imports or enters.
  • Lead records: the outcome, playbook, stage, assigned agent, notes, tasks and the timeline of every event.
  • Lead data the customer imports from other systems, such as spreadsheets, forms and case management tools.

AI analyses

  • Summaries of conversations and calls, extracted commitments, message classifications, quality scorecards and priority scores with their reasons. These are derived from customer data and stored with the lead they describe.

Technical and usage information

  • Device and browser type, operating system, language, screen size and network address.
  • Application logs, error reports and performance measurements.
  • Which features are used and how often, at a level that helps us improve the product.
  • Extension telemetry: which connected site a capture came from, the version of the extension and whether capture succeeded. The extension does not send browsing history or the contents of sites that are not connected to Tern.

Information you send us directly

  • Support requests, sales enquiries, feedback and anything else you send to our email addresses.

4.How we collect it

We collect information in the following ways:

  • Directly from you when you create an account, sign in, change settings, import data or contact us.
  • Through the Tern Bridge extension, which reads message threads on the sites the customer connects while the agent is signed in and the tab is open. It sends them to the customer's workspace.
  • From the customer's phone system, which delivers call records and, where enabled, recordings to Tern.
  • From messaging platform interfaces the customer chooses to connect through an official channel.
  • Automatically through cookies and similar technologies described in section 10.

Where a customer brings a contact's information into Tern, we rely on the customer to have collected it lawfully and to have given any notice the law requires.

5.Why we collect and use information

We use personal information for the following purposes:

  • To provide the service: capturing conversations, keeping the lead timeline, running playbooks, scheduling, assigning work and producing the priority call list.
  • To record, store, transcribe and analyse calls where the customer has turned that on.
  • To produce AI analyses where the customer has AI processing enabled (section 6).
  • To operate accounts, authenticate users, send sign in links, notifications and reminders and provide support.
  • To bill, meter usage against plan caps and prevent fraud and abuse.
  • To keep the service secure, including monitoring, incident investigation and maintaining the audit trail.
  • To improve the product using aggregated and de-identified usage information.
  • To meet our legal obligations and respond to lawful requests.

We do not sell personal information. We do not use customer data to advertise to contacts. We do not use customer data to train general purpose AI models.

6.AI processing and the organisation level toggle

Tern can use machine learning models to summarise conversations, extract commitments, classify inbound messages, produce quality scorecards and score lead priority. This processing is controlled by an AI processing setting that applies to the whole organisation and can be changed by a workspace administrator at any time.

  • When AI processing is on, the relevant customer data, typically the recent messages on a lead, a call transcript and open commitments, is sent to an AI model provider to produce the analysis. The result is stored with the lead.
  • When AI processing is off, no customer data is sent to an AI model provider. Tern still captures everything and uses deterministic rules to score leads.
  • Transcription of call recordings runs on infrastructure we operate or on a provider under contract with us. It is governed by the same toggle.
  • AI analyses are aids to a human, not decisions. Every analysis is shown alongside the underlying conversation so an agent can check it. The customer can correct or delete it.
  • Our AI model providers are engaged under terms that prohibit using customer data to train their models and that require deletion after the request is served, subject to any short retention their abuse monitoring requires.

8.Who we share information with

We share personal information only where needed to provide the service and only with the following categories of recipient.

Sub processors

We use third party providers to run the service. Each is bound by contract to protect the information, to use it only on our instructions and to keep it confidential. By category:

CategoryWhat they processLocation
Cloud hosting and edge computeApplication servers, background workers, file storage for media and recordings, cachingAustralia and Singapore
DatabaseStructured customer data, account data, audit trailAustralia and Singapore
Email deliverySign in links, notifications, reminders and receiptsAustralia
TelephonyCall records and recordings from the customer's phone system plus SMS where enabledAs set by the customer's phone provider
AI model providersConversation excerpts and transcripts sent for analysis when AI processing is onAustralia, Singapore or the provider's nearest region
PaymentsCard details, billing address and invoicesProvider's global infrastructure
Error monitoringTechnical error reports with request metadataProvider's nearest region

A current list of named sub processors is available to customers on request at privacy@ternup.io. We give customers notice before adding a sub processor that would handle customer data.

Within the customer's organisation

Users in a workspace can see the customer data the customer's roles and permissions allow. The customer controls who has access.

Other disclosures

  • To professional advisers, insurers and auditors under confidentiality.
  • To a buyer or successor if our business is sold or reorganised, with notice to customers.
  • Where the law requires it, or to protect the rights, safety or property of Tern, our customers or others.

9.Where information is stored

Customer data is stored in Australia and Singapore. Recordings and media are stored in Australia. Some processing, such as AI analysis and error monitoring, may occur in the provider's nearest region where an Australian or Singaporean region is not available.

When we disclose personal information overseas we take reasonable steps to ensure the recipient handles it in a way that is consistent with the Australian Privacy Principles, including contractual protections and, for customer data, the terms described in section 8.

10.Cookies and similar technologies

The application uses strictly necessary cookies to keep you signed in and to protect against cross site request forgery. This website uses no advertising cookies. If we introduce analytics on the website, it will be privacy preserving and this section will say so.

The browser extension stores a short lived token in the browser's extension storage so it can send captured messages to your workspace. It does not read or set cookies on the sites it connects to.

11.Retention and deletion

We keep information only as long as needed for the purposes above, then delete or de-identify it.

  • Customer data is kept for as long as the customer's workspace is active and within the retention period the customer sets. Call recordings and transcripts follow the customer's recording retention setting.
  • Deletion by the customer. A workspace administrator can delete a lead, a contact, a recording, a transcript or an AI analysis at any time. Deleted items are removed from the live database immediately and from backups within 35 days.
  • When a subscription ends, customer data is kept for 30 days so it can be exported or the subscription resumed, then deleted. Enterprise agreements may set a different period.
  • Account information is kept while the account exists and for up to 7 years afterwards where needed for tax, accounting and legal purposes.
  • Audit trail and security logs are kept for 12 months.
  • Data sent to AI model providers is not retained by them beyond serving the request, except for short term abuse monitoring under their terms.

12.How we protect information

We take reasonable steps to protect personal information from misuse, interference, loss, unauthorised access, modification and disclosure. These include:

  • Every record is scoped to an organisation, enforced with row level security in the database so one customer can never read another's data.
  • Encryption in transit and at rest for databases, file storage and backups.
  • Recordings and media are served only through short lived signed links.
  • An append only audit trail of who viewed, changed or deleted what.
  • Passwordless sign in with expiring links plus role based access within a workspace.
  • Least privilege access for our staff, with access to customer data limited to support and incident response and recorded in the audit trail.

More detail is on our security page. If we become aware of a data breach likely to result in serious harm, we will notify affected customers and the Office of the Australian Information Commissioner as the Notifiable Data Breaches scheme requires.

13.Your rights and choices

Under the Privacy Act you may:

  • Ask for access to the personal information we hold about you.
  • Ask us to correct information that is inaccurate, out of date, incomplete, irrelevant or misleading.
  • Ask how we handle your information and complain if you think we have breached the Australian Privacy Principles.

If you are a contact of one of our customers, the customer controls your information. Please direct requests to the business you dealt with. If you contact us instead, we will pass your request to the customer and help them respond. Where the customer has turned on AI processing, you may ask the customer to have analyses of your conversations deleted.

If you are a user of a customer workspace, you can update your name and email address in settings. Deleting your user account removes your sign in, but the customer data you captured stays with the customer's workspace.

You can opt out of marketing email from us at any time using the link in the email. Service messages, such as sign in links and billing notices, are not marketing and continue while you have an account.

We respond to requests within 30 days. We may need to verify your identity first. We do not charge for access requests except where a request is unusually complex. We will tell you in advance if so.

14.Children

Tern is a business tool and is not directed at children. We do not knowingly collect personal information from anyone under 16 as a user. Customers are responsible for the information they bring into Tern about their own contacts.

15.Changes to this policy

We may update this policy as the product or the law changes. We will post the new version here with a new effective date and, for material changes, tell customers by email at least 14 days before they take effect.

16.Contact and complaints

Privacy questions, access requests and complaints go to our privacy contact at privacy@ternup.io. General support is at support@ternup.io.

We will acknowledge a complaint within 7 days and aim to resolve it within 30. If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner at oaic.gov.au.