Ah Va pays for itself, or your money back. 90-day guarantee. See how →

Privacy policy

Privacy Policy

Last updated: 26 August 2026

1. Who we are

VirtualAssistant SG (this site, www.virtualassistant.com.sg, and the product app at app.virtualassistant.com.sg) is operated by Best Marketing Agency Pte Ltd, UEN 201936773M, a Singapore-registered company. We comply with Singapore's Personal Data Protection Act (PDPA). The product brand name is Ah Va.

2. What we collect

When you sign up, we collect: your name, email, phone number, business name, and the information you enter about your business (services, hours, FAQs). When Ah Va handles a call or message on your behalf, we store the audio recording, transcript, and any contact details the caller or customer provides. When you pay, our payment processor (Stripe) handles card data; we never see or store full card numbers.

If you connect Google, we may also receive the Google account data described in section 4 (Sign-in, Calendar, and optional Gmail send).

3. How we use it

We use your data to provide the service: deploying your AI assistant, answering your customers' calls and messages, booking appointments, billing you, and sending operational notifications via email and WhatsApp. We do not sell your data. We do not share your call recordings with third parties except as needed to run the service (section 5) or when required by Singapore law.

4. Google user data

Our Google Cloud OAuth app ("VirtualAssistant SG" / Ah Va) requests only the Google scopes needed to run features you turn on:

  • Sign-in (openid, email, profile) — to authenticate you and show your name and email in the dashboard.
  • Google Calendar (https://www.googleapis.com/auth/calendar) — to check free/busy, create, update, and cancel booking events when you connect Calendar.
  • Gmail send (optional; https://www.googleapis.com/auth/gmail.send) — only if you connect Gmail so Ah Va can send email from your address. We do not read your inbox with this scope.

We use Google user data only to provide or improve user-facing features of Ah Va that you enable. We do not use Google user data for advertising. We do not sell Google user data. We do not use Google Workspace API user data (including Calendar data, or any raw, aggregated, or derived form of it) to create, train, or improve generalized or foundational machine learning or AI models.

5. Sharing, transfer, and disclosure of Google user data

We share or transfer Google user data only with the processors below, and only as needed to operate the features you use. We do not disclose Google user data to other categories of recipients except where required by law or with your instruction.

  • Our hosting and database providers (currently Railway and Postgres) — store account, token, and booking records encrypted at rest in our application database.
  • Retell AI — powers the live voice agent. When a call needs a booking, our servers may return calendar availability or booking results to the agent session so Ah Va can confirm a slot with the caller. That data is used only to complete the request; it is not used by us to train generalized AI models.
  • Anthropic (Claude) — used for optional product features such as call insights, WhatsApp reply drafts, and security screening. We do not send raw Google Calendar or Gmail mailbox contents to Anthropic for model training. Where a feature needs a short booking or contact summary, we send only what is required for that feature.
  • ElevenLabs — text-to-speech for some voice paths. Does not receive Google Calendar or Gmail content.
  • Stripe — billing only; does not receive Google Calendar or Gmail content.
  • Resend / Telnyx / Twilio — transactional email and telephony/WhatsApp delivery. Do not receive your Google OAuth tokens or full Calendar feeds.
  • Google — we call Google's own APIs with tokens you authorize; Google processes that traffic under your Google account terms.

Human support staff at Best Marketing Agency Pte Ltd may access a tenant account when you ask for help (for example to debug a failed booking). Access is limited to what is needed to resolve the issue.

6. Data protection for sensitive and Google user data

We apply the following protections to personal data and to Google user data (including OAuth tokens and Calendar-related records):

  • Encryption in transit (TLS) for all API and dashboard traffic.
  • Encryption at rest for application data stores and for stored OAuth refresh tokens (application-level encryption before database write).
  • Access control: tenant data is scoped by authenticated session or API token; staff access is restricted to support and operations roles.
  • Least-privilege OAuth scopes: we request only the Google scopes required for each feature.
  • Secret and credential handling: production secrets live in the host environment, not in client-side code.
  • Retention controls: call recordings and transcripts default to 90 days (customer-configurable). You may disconnect Google Calendar or Gmail at any time; we stop using those tokens and you may request deletion of related stored credentials.
  • Monitoring and abuse controls, including rate limits and security event logging on sensitive agent tools.

7. AI / ML use and Google Limited Use compliance

Ah Va uses third-party AI services to run voice conversations, drafts, and insights. Those integrations process customer conversation content and, where needed for booking, limited calendar availability or booking outcomes returned by our own servers.

The use of raw or derived user data received from Google Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements. We do not transfer Google Workspace or Photos API user data to third-party AI services for the purpose of training or improving their generalized or foundational models. We do not use that data ourselves to train generalized AI models. We use it only to provide or improve user-facing features of Ah Va (sign-in, calendar booking, optional email send).

Third-party AI providers we integrate with today (product features, not model training on your Google data): Retell AI (voice agent runtime), Anthropic Claude (insights, drafts, and safety checks), and ElevenLabs (speech synthesis where configured). We select paid / API plans intended for application use and configure them for service delivery, not for depositing Google user data into public model training corpora.

8. Analytics + advertising cookies

This marketing site uses the following tools to understand how visitors use it and to measure marketing performance:

  • Google Analytics 4 — anonymised page views, referral source, device type.
  • Google Ads — conversion tracking when our ads drive a signup.
  • Meta (Facebook) Pixel — conversion tracking for Meta ads campaigns.
  • Microsoft Clarity — anonymised session replays and heatmaps to improve site usability. We do not record form inputs containing personal data.

None of these marketing tools receive your Google OAuth tokens, Calendar contents, name/email from the app dashboard, phone, or call recordings. You can opt out at the browser level using ad-blocker extensions, or by enabling "Do Not Track".

9. Where the data lives

Our primary customer data store is hosted in Singapore. Call audio processing involves third-party voice infrastructure that may process audio in other regions; all transit is encrypted. Call recordings and transcripts are encrypted at rest and in transit. Default retention is 90 days, customer-configurable.

10. Your rights under PDPA

You have the right to access the personal data we hold about you, to correct it if it's wrong, and to request deletion (subject to legal retention obligations). Email hello@virtualassistant.com.sg and we will respond within 30 days. You may also disconnect Google from Google Account permissions.

11. Data Protection Officer

Our designated Data Protection Officer is Jim Ng, hello@virtualassistant.com.sg. For PDPA complaints you can also contact the Personal Data Protection Commission at pdpc.gov.sg.

12. Changes to this policy

We update this page when our practices change. The "Last updated" date at the top of this page is the version in effect.