How we handle compliance

Built with patient-data
protection in mind.

We do not over-claim. Below is what is true, what is provable, and what we can show you before you go live.

Business Associate Agreement (BAA)

Our voice infrastructure is provided by Retell AI. We maintain a signed Business Associate Agreement (BAA) with Retell as our voice/telephony subprocessor. This is a real, executed document — not a promise or a plan.

Executed BAA on file

Voice/telephony provider: Retell AI

Envelope reference: 9685D204  ·  Countersigned: 2026-06-10

What this means: calls handled by Retell's infrastructure take place within a BAA-governed data path, which is a required component for handling protected health information (PHI) under HIPAA when using a covered service.

What this does not mean: a BAA alone does not make a platform "HIPAA certified" or guarantee compliance in every configuration — HIPAA compliance depends on the full operational picture, including policies, training, and how the system is deployed. We are honest about that.


Data minimization

Ava is designed to collect and process only what is needed to book and manage appointments. She does not ask for insurance details, medical history, or sensitive clinical data on the call. The information exchanged is limited to scheduling essentials: name, desired service, preferred time, and contact details for the confirmation.

Call summaries are transmitted to the clinic operator. We do not store, sell, or use caller information for any purpose outside delivering the service.


We'll walk you through it

Before any clinic goes live, we are glad to walk your team through exactly how data flows — from the incoming call, through Retell's infrastructure, to your calendar and the confirmation sent to the caller. If your practice requires a BAA directly with Ramelo (Luxury Living Contractors LLC), or needs to review our data-handling practices before onboarding, contact us and we will arrange it.

We will provide our BAA on request and answer compliance questions during onboarding. We have nothing to hide — we just do not print claims we cannot back up.


What we do not claim

Some compliance language has become marketing shorthand. We intentionally avoid phrases that are either meaningless, unprovable, or that over-represent our current status:

We do not claim
  • "HIPAA certified" — no such certification exists; using this phrase is a tell of dishonesty
  • "Fully HIPAA compliant" or "100% compliant" — absolute compliance claims are unprovable
  • "SOC 2" — we have not completed a SOC 2 audit
  • "Audited" — we have not undergone a third-party compliance audit
  • "Your data is 100% secure" — no system can honestly make this claim

The honest framing: we have executed the foundational step (a signed BAA with our voice provider), we have designed the system to minimize data collection, and we offer to show our work to any prospective clinic before they go live. That is what is true.


Questions about compliance?

Email us before you commit to anything. We will answer your specific questions, provide documentation, and walk through the data flow with your team.