This page sets out the commitments that govern how Enquiry 360 behaves. It is published so that a procurement, governance or information-security team can assess the product without having to ask for a document first. The full contractual licence terms are provided with an order form (see section 10).
1. How the software is delivered
Enquiry 360 is an AI voice agent that answers your inbound calls: a voicebot, a virtual agent and a natural-language IVR in one application. It is software you licence, not a service that processes your data on someone else's infrastructure. Maya Information Systems Ltd supplies the application image and the managed Dataverse solution. You deploy and run them inside your own Microsoft Azure subscription and Microsoft Dataverse environment, on infrastructure you own and pay for.
The underlying Microsoft services (Azure Communication Services, Azure Speech, Azure OpenAI, Azure Container Apps, Storage and Dataverse) are yours, billed to you directly by Microsoft, and are not marked up by us.
2. Where your data lives
- Every call recording, transcript, captured field and item of caller information stays inside your Microsoft tenant, under your access controls and your retention policy.
- You are the data controller for every caller interaction.
- Microsoft is your sub-processor for the Azure services in scope, under the agreements you already hold, unchanged. No new vendor cloud, no new data path.
- The software transmits nothing to us, and we hold no copy of your callers' data. We do not access your environment on our own initiative. Where you engage us to set up or support your configuration, any access is granted by you, under your controls, logged, and revocable. It is directed at your configuration, not at reading your callers' data.
3. What the AI does
The language model runs on your own Azure OpenAI resource and is used only to interpret each turn of the conversation as it happens.
It is used at inference only. It is not fine-tuned on your data, and is never trained or improved using your callers' words.
The agent is a faithful executor of the forms you configure, not an independent decision-maker. It asks the questions you defined, in the order you set, following the branches you specified, and records the answers where you told it to. It does not generate scripts, invent questions, decide policy, or capture fields you did not define.
4. What it does not promise
Language-model output is probabilistic. Rather than claim otherwise, the product does not leave captured data to the model's judgement alone:
- what the caller says is what is recorded;
- your validation rules (format, range, mandatory fields) are applied independently on every turn;
- critical values are read back to the caller for confirmation where you configure it;
- a value the agent has just told the caller was wrong is not stored.
These measures make captured data dependable in practice. They are safeguards, not a warranty. We do not warrant that every captured value or spoken response will be free of interpretation error, and you should review captured enquiries in the ordinary course of running your service, exactly as you do for your other channels. The per-call transcript and outcome record, in your own Dataverse, supports that review.
The agent is designed to capture and route enquiries. It is not designed to make, and must not be configured to deliver, automated decisions that produce legal or similarly significant effects on an individual: an eligibility refusal, for example, or an adverse determination. This boundary is deliberate: it is what keeps the product in scope as a limited-risk AI system rather than a high-risk one.
5. Escalation to a person
The agent escalates on conditions you configure and on bounded, observable states: when a caller asks for a person, when your configuration reaches a handover point you designated, when the conversation is not progressing, or when a platform error occurs.
There is no tunable "confidence threshold" governing escalation, and none is offered. We state this plainly because the term is common in this market, and it does not describe how escalation works here.
Where you have configured a valid transfer destination, the agent transfers the caller to it. Where you have not, it says so honestly and closes the call courteously. It never tells a caller it is putting them through to a person when it cannot. Configuring appropriate escalation destinations, and ensuring they are attended, is your responsibility.
6. Transparency and disclosures
At the start of every call, the agent states clearly that the caller is speaking with an automated assistant. This is always on and cannot be silently dropped.
Where call recording is switched on, a recording notice is spoken as well. The two are coupled. A caller is not recorded without being told. Switch recording off and the notice is not spoken, because there is nothing to disclose.
This supports the transparency duties that fall on you as the operator, including Article 50 of the EU AI Act (effective 2 August 2026, where applicable) and UK ICO guidance. The wording is yours: accept the built-in default or author your own. The lawful-basis decisions are yours too.
7. Call recording
Recording is off by default. When you enable it, recordings are written to storage you provide and control, inside your own Azure subscription. The software only ever writes a recording; it never reads one back.
Retention, access control, archiving and deletion of recordings are yours to set, on your own storage.
8. Configuration accountability
You retain complete control of what the agent says, asks and captures on every call, the same control you already hold over your web and human-agent channels. The behaviour of the service is a product of the forms you configure, and is transparent and reviewable because it lives in your Dataverse, not in our code.
It follows that the accuracy, appropriateness and regulatory compliance of the configured content (scripts, questions, captured fields, disclosures, navigation logic, escalation destinations) remain your responsibility. We provide the platform, the configuration tools, and ongoing maintenance.
9. What belongs to you
Your configuration is yours. The forms, questions, branching logic and process design you author, and all data captured through them, belong to you. You are not locked into a proprietary flow language owned by us. If you stop using the product, your configuration and your data remain in your own Dataverse environment. There is nothing to migrate and nothing to request.
The platform is ours in the same way. The software, the application image, the managed Dataverse solution and all intellectual property in them remain the property of Maya Information Systems Ltd and its licensors, and are licensed to you, not sold. Owning your configuration and your data does not extend to owning the platform, its features or its underlying code.
Frequently asked
Does an AI receptionist have to tell callers it is AI?
Yes. Enquiry 360 discloses that the caller is speaking to an automated assistant on every call, and the disclosure cannot be silently switched off by configuration. This supports the transparency duties that fall on you as the operator, including Article 50 of the EU AI Act and UK ICO guidance. The exact wording is yours to author.
Who is the data controller when an AI answers my phone?
You are. Enquiry 360 is software you license and run in your own Microsoft tenant, not a service that processes your data elsewhere. Every recording, transcript and captured field stays inside your tenant, under your access controls and your retention policy.
Are AI receptionist calls recorded?
Recording is off by default. When you enable it, recordings are written to storage you provide and control, inside your own Azure subscription. The software only ever writes a recording; it never reads one back.
When does the AI hand the caller to a person?
On rules you configure, not on a hidden score. There is no tunable confidence threshold governing escalation, and none is offered. We state this plainly because the term is common in this market, and it does not describe how escalation works here.
What does Enquiry 360 deliberately not promise?
It does not warrant that every captured value or spoken response will be free of error. It is an AI, it can mishear, and the product is built to know that and to behave well when it happens rather than to claim it never will.
If I stop using it, what happens to my configuration and my data?
They stay where they already are. The forms, questions, branching logic and process design you author, and all data captured through them, belong to you and remain in your own Microsoft Dataverse environment. There is nothing to migrate and nothing to request.
10. The full licence terms
This page covers how the product behaves and who is responsible for what. The full contractual terms, covering licence grant, commercial terms, warranties, liability and termination, are set out in the End User Licence Agreement, which is provided with an order form and forms part of the agreement between us. Existing Enquiry 360 customers licence the AI module by addendum to their current agreements.
To discuss any of the above with your governance or information-security team, contact info@enquiry360.com.