Home / Privacy

Clear about your information.

How we collect, use and protect personal data, and the choices available to you.

This notice covers two things: the enquiry you send us through this website, and personal data handled inside Attendo, our assistant service. We use your enquiry to reply and browser and network signals to protect the website from abuse. No advertising, no marketing tracking, no sale of your information.

Last updated · 20 September 2026

What we collect through this website

When you submit the contact form we receive the name, work email address, company, area of interest, and message you enter. We also record the network address the submission came from, which we use only to limit automated abuse of the form.

How it is handled

We use Cloudflare Turnstile to protect contact forms and Attendo public forms, chats and browser calls from automated abuse. Cloudflare processes browser and network signals for verification under its privacy policy and Turnstile Privacy Addendum (https://www.cloudflare.com/turnstile-privacy-policy/). We do not store verification tokens with your enquiry. Hashed network-address and email abuse counters expire automatically; contact-form counters expire within 25 hours and are then removed automatically by our database provider. These checks are used for security, not advertising.

Your submission is sent over an encrypted connection to our own infrastructure on Amazon Web Services in the Asia Pacific (Singapore) region. It is delivered by email to our enquiries inbox. We use your email address to reply to your enquiry. The website does not write your enquiry to a database, and it is not passed to any advertising, marketing, or data broker service. Amazon Web Services acts as our processor for delivery, and short-lived operational logs are retained to keep the service running and secure.

Cookies and analytics

This website sets no cookies, runs no advertising or analytics trackers, and loads no third-party scripts or fonts. Nothing about your visit is shared with another company.

What not to include

Please do not enter passwords, authentication details, confidential records, financial information, health information, or other sensitive personal data. A short, non-sensitive description of the business outcome or challenge is enough to begin a conversation.

Retention and your choices

Enquiries are kept in our business correspondence for as long as needed to respond and to maintain a record of the relationship, then deleted. You may ask us for a copy of what you sent, ask us to correct it, or ask us to delete it, by replying to the acknowledgement email or contacting us directly. 6th Meridian Pte. Ltd. is the party responsible for this information under Singapore's Personal Data Protection Act.

Attendo, our assistant service

Attendo is our AI front-office assistant. Businesses use it to answer their customers' questions, take appointments and pass on anything that needs a person. The sections below describe personal data handled inside Attendo, which is separate from the website enquiry data above.

Attendo sits between two groups, and our responsibility differs for each. For the businesses that use Attendo we hold account details and the content they give their assistant, and we decide the purposes. For the customers of those businesses we act on the business's instructions as a data intermediary under Singapore's Personal Data Protection Act: the business decides what its assistant asks for and how long it keeps records. If you spoke to an assistant and want your information removed, the fastest route is to ask that business directly; you can also contact us and we will pass the request on.

Inside Attendo we hold:

  • account and sign-in details for a business owner and their staff
  • the business information an owner enters, and documents they connect as knowledge
  • contact details a customer provides, or that a messaging channel supplies
  • the messages exchanged with an assistant, across web chat, WhatsApp, Telegram, Facebook Messenger and Instagram
  • transcripts of phone calls handled by the voice assistant
  • appointment details, and answers to questions the business configured its assistant to ask

When the voice assistant answers a call, the caller hears an announcement that the call is recorded and transcribed before the assistant speaks. The transcript is stored with the conversation. We do not keep the call audio ourselves: it is carried by our telephony provider and converted to and from speech by our voice provider, each under their own terms.

Attendo and your Google account

Connecting Google is optional and requires the business owner's authorisation through Google's consent screen.

  • Google Calendar: We request calendar.events and calendar.freebusy. We use the integration to check busy times and create, update and cancel appointments booked through Attendo, including creating Google Meet links when requested. Availability checks use busy intervals rather than titles or descriptions of unrelated events. The permission itself permits event access; it is not technically limited to events created by Attendo.
  • Google Drive: We request drive.file to access files the owner selects or otherwise authorises for Attendo. We import their contents as assistant knowledge, inventory or appointment information, depending on the selected feature. This does not grant unrestricted access to the owner's entire Drive.

These integrations do not request Gmail or Google Photos access. Imported content and derived information may be stored as business records, searchable knowledge, embeddings or conversation records.

Google user data and AI

With the user's consent, information necessary for connected features may be processed by the AI and voice service providers identified below. Selected Drive content is embedded through Amazon Bedrock for knowledge search, and relevant excerpts may be included in a prompt to generate an answer. Calendar availability is reduced to busy intervals and used by server-side scheduling logic. On a voice call, an answer may pass through Twilio and ElevenLabs or Amazon Polly to be spoken. These uses are inference, retrieval and speech processing needed to deliver the service.

We do not use, sell or transfer Google Workspace API user data to create, train or improve foundational, generalized or non-personalized AI or machine-learning models. This includes raw data, aggregated or anonymized data, embeddings and other derived information. We permit providers to process this information only under terms and effective settings that prohibit such training. We do not use Google user data for advertising or sell it to data brokers.

Attendo's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements, and the Google Workspace API User Data and Developer Policy.

A business can disconnect Google in Attendo or revoke access in its Google Account. Successful disconnection in Attendo revokes the Google credential and removes the saved connection. If cleanup cannot finish, Attendo reports an error so the business can retry. Revocation directly at Google stops API access but does not itself delete previously imported records from Attendo. Imported knowledge, business records, conversations and backups follow the retention and erasure practices described below.

How Attendo data is kept safe

We protect Google user data, including sensitive information and connection credentials, with encryption and access controls. Connections between users, Attendo and Google use HTTPS/TLS. Our production database encrypts stored records at rest using AWS Key Management Service.

Long-lived Google refresh tokens are held on the server and excluded from ordinary settings responses and data exports. The Google OAuth client secret is managed using AWS Secrets Manager. The Drive file picker receives a short-lived access token so the owner can select files; this does not expose the refresh token or client secret.

Requests for business records are checked against the requesting account's permissions and scoped to the relevant business. Server access to storage and secrets is controlled by AWS identity and access permissions. Staff access to Google user data for support requires the owner's explicit permission for the specific support request.

AI and voice service safeguards

Attendo uses Amazon Bedrock as a managed model service for Anthropic Claude language models and Cohere embeddings. AWS states that Bedrock inputs and outputs are not shared with model providers and are not used by AWS or model providers to train their base models. We have also attached an AWS Organizations AI services opt-out policy to our organization root. It opts our organization out of service improvement using our content for every current and future AWS AI service that supports that policy, including the Amazon Polly speech service used by Attendo.

Attendo also uses ElevenLabs for speech-to-text, text-to-speech and conversational voice features. We have disabled ElevenLabs' use of our workspace data to improve models. Twilio currently provides telephony and ConversationRelay speech processing under terms that restrict use of customer inputs for training third-party base models unless the customer separately agrees. We have not authorised any provider to use Google user data for generalized model training. Attendo does not use a self-hosted or offline AI model.

Training restrictions do not mean that every provider has zero retention. Providers may process or retain limited information under their operational, security, abuse-prevention and contractual retention terms. We review these controls before routing Google user data or information derived from it through a service.

Where Attendo data is processed

Attendo's primary application database runs on Amazon Web Services in the Asia Pacific (Singapore) region. Amazon Bedrock cross-region inference may process information outside Singapore while generating a reply. Data transmitted between AWS Regions remains on the AWS network and is encrypted in transit. An inference provider may use temporary prompt caching or retain limited information under its applicable operational, security and retention terms.

A small number of service providers each receive only what their job needs: Amazon Web Services for hosting, storage, email, Bedrock AI and Polly speech; ElevenLabs for voice processing; Twilio for telephony and ConversationRelay; Meta and Telegram for their own messaging channels; Google, Microsoft and Zoom where a business has connected them; and Cloudflare to block bots on public chat pages.

Retention and erasure in Attendo

Conversations, contacts and appointments belong to the business and are kept while it keeps its account. Alerts in an owner's notification feed expire automatically after 30 days, and anti-abuse counters expire within hours. Closing an account removes that business's active data, including conversations, contacts and connected credentials. Residual copies may remain for a limited period in encrypted backups or provider systems under applicable retention schedules.

Attendo has a built-in erasure tool a business can run for any individual. It removes that person's contact record and every conversation they had with the assistant. Appointment history is kept because the business needs its schedule records, but the customer's name, phone number, email and notes are stripped from it. A business can also export information held about one person to answer an access request.

If this changes

If 6th Meridian introduces analytics, cookies, or other services that process personal information, this notice will be updated before those features go live to explain what is collected, why it is used, who processes it, and how long it is retained.