This page covers Attendo, including account creation and demo requests in this portal. Attendo is provided by 6th Meridian Pte. Ltd. The service disclosures below are also published in our company privacy notice, which separately covers enquiries made through the 6th Meridian company website.
Accounts, demos and payments
When you create an account, we collect your name, business name, email address and sign-in information to verify your email and set up your access. Amazon Cognito handles account authentication. Your browser stores sign-in session information and signup progress so you can stay signed in and continue setup. If you start creating an account and don't finish, the signup record is deleted after 30 days; once we have issued you an invoice it is kept for 180 days, so a late payment can still be matched to it.
When you request a demo, we collect your name, business name, work email and any phone number or requirements you choose to provide. We store the request and use it to arrange your demo and send related correspondence. Demo request records are scheduled to expire after 180 days; related business correspondence is retained as needed to respond and maintain the relationship. Network-address rate limits help protect the form from automated abuse.
If you subscribe, we process the billing details and payment status needed to manage your subscription. Stripe processes our payments and issues and hosts our invoices. Card details are entered directly into Stripe's secure payment form and never reach us. The billing details you give us (company name, billing address, UEN, purchase order number and billing email) are shared with Stripe so it can issue your tax invoices. When you pay by bank transfer, we record the payment against your invoice once it arrives. Stripe handles this information under its own privacy policy.
We email the account owner, and the billing contact where you named one, about the subscription: receipts, invoices, a reminder before each renewal, and a notice if a payment fails or the plan ends.
Please keep demo messages to a short, non-sensitive description of what your business needs. Do not include passwords, authentication details, confidential customer records, financial information or health information in the demo form.
Information inside Attendo
Attendo is our AI front-office assistant. Businesses use it to answer their customers' questions, take appointments and pass on anything that needs a person.
Attendo sits between two groups, and our responsibility differs for each. For the businesses that use Attendo we hold account details and the content they give their assistant, and we decide the purposes. For the customers of those businesses we act on the business's instructions as a data intermediary under Singapore's Personal Data Protection Act: the business decides what its assistant asks for and how long it keeps records. If you spoke to an assistant and want your information removed, the fastest route is to ask that business directly; you can also contact us and we will pass the request on.
Inside Attendo we hold:
- account and sign-in details for a business owner and their staff
- the business information an owner enters, and documents they connect as knowledge
- contact details a customer provides, or that a messaging channel supplies
- the messages exchanged with an assistant, across web chat, WhatsApp, Telegram, Facebook Messenger and Instagram
- transcripts of phone calls handled by the voice assistant
- appointment details, and answers to questions the business configured its assistant to ask
When the voice assistant answers a call, the caller hears an announcement that the call is recorded and transcribed before the assistant speaks. The transcript is stored with the conversation. We do not keep the call audio ourselves: it is carried by our telephony provider and converted to and from speech by our voice provider, each under their own terms.
Attendo and your Google account
Connecting Google is optional and requires the business owner's authorisation through Google's consent screen.
- Google Calendar: We request
calendar.eventsandcalendar.freebusy. We use the integration to check busy times and create, update and cancel appointments booked through Attendo, including creating Google Meet links when requested. Availability checks use busy intervals rather than titles or descriptions of unrelated events. The permission itself permits event access; it is not technically limited to events created by Attendo. - Google Drive: We request
drive.fileto access files the owner selects or otherwise authorises for Attendo. We import their contents as assistant knowledge, inventory or appointment information, depending on the selected feature. This does not grant unrestricted access to the owner's entire Drive.
These integrations do not request Gmail or Google Photos access. Imported content and derived information may be stored as business records, searchable knowledge, embeddings or conversation records.
Google user data and AI
With the user's consent, information necessary for connected features may be processed by the AI and voice service providers identified below. Selected Drive content is embedded through Amazon Bedrock for knowledge search, and relevant excerpts may be included in a prompt to generate an answer. Calendar availability is reduced to busy intervals and used by server-side scheduling logic. On a voice call, an answer may pass through Twilio and ElevenLabs or Amazon Polly to be spoken. These uses are inference, retrieval and speech processing needed to deliver the service.
We do not use, sell or transfer Google Workspace API user data to create, train or improve foundational, generalized or non-personalized AI or machine-learning models. This includes raw data, aggregated or anonymized data, embeddings and other derived information. We permit providers to process this information only under terms and effective settings that prohibit such training. We do not use Google user data for advertising or sell it to data brokers.
Attendo's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements, and the Google Workspace API User Data and Developer Policy.
A business can disconnect Google in Attendo or revoke access in its Google Account. Successful disconnection in Attendo revokes the Google credential and removes the saved connection. If cleanup cannot finish, Attendo reports an error so the business can retry. Revocation directly at Google stops API access but does not itself delete previously imported records from Attendo. Imported knowledge, business records, conversations and backups follow the retention and erasure practices described below.
How Attendo data is kept safe
We protect Google user data, including sensitive information and connection credentials, with encryption and access controls. Connections between users, Attendo and Google use HTTPS/TLS. Our production database encrypts stored records at rest using AWS Key Management Service.
Long-lived Google refresh tokens are held on the server and excluded from ordinary settings responses and data exports. The Google OAuth client secret is managed using AWS Secrets Manager. The Drive file picker receives a short-lived access token so the owner can select files; this does not expose the refresh token or client secret.
Requests for business records are checked against the requesting account's permissions and scoped to the relevant business. Server access to storage and secrets is controlled by AWS identity and access permissions. Staff access to Google user data for support requires the owner's explicit permission for the specific support request.
AI and voice service safeguards
Attendo uses Amazon Bedrock as a managed model service for Anthropic Claude language models and Cohere embeddings. AWS states that Bedrock inputs and outputs are not shared with model providers and are not used by AWS or model providers to train their base models. We have also attached an AWS Organizations AI services opt-out policy to our organization root. It opts our organization out of service improvement using our content for every current and future AWS AI service that supports that policy, including the Amazon Polly speech service used by Attendo.
Attendo also uses ElevenLabs for speech-to-text, text-to-speech and conversational voice features. We have disabled ElevenLabs' use of our workspace data to improve models. Twilio currently provides telephony and ConversationRelay speech processing under terms that restrict use of customer inputs for training third-party base models unless the customer separately agrees. We have not authorised any provider to use Google user data for generalized model training. Attendo does not use a self-hosted or offline AI model.
Training restrictions do not mean that every provider has zero retention. Providers may process or retain limited information under their operational, security, abuse-prevention and contractual retention terms. We review these controls before routing Google user data or information derived from it through a service.
Where Attendo data is processed
Attendo's primary application database runs on Amazon Web Services in the Asia Pacific (Singapore) region. Amazon Bedrock cross-region inference may process information outside Singapore while generating a reply. Data transmitted between AWS Regions remains on the AWS network and is encrypted in transit. An inference provider may use temporary prompt caching or retain limited information under its applicable operational, security and retention terms.
A small number of service providers each receive only what their job needs: Amazon Web Services for hosting, storage, email, Bedrock AI and Polly speech; ElevenLabs for voice processing; Twilio for telephony and ConversationRelay; Meta and Telegram for their own messaging channels; Google, Microsoft and Zoom where a business has connected them; Cloudflare to block bots on public chat pages; and Stripe for payments, invoices and subscription billing, which Stripe may process outside Singapore. Account authentication and subscription payments in this portal are described under Accounts, demos and payments.
Retention and erasure in Attendo
Conversations, contacts and appointments belong to the business and are kept while it keeps its account. Alerts in an owner's notification feed expire automatically after 30 days, and anti-abuse counters expire within hours. Closing an account removes that business's active data, including conversations, contacts and connected credentials. Invoices and payment records are the exception: we and Stripe keep them for as long as Singapore law requires business records to be kept, currently five years. Residual copies may remain for a limited period in encrypted backups or provider systems under applicable retention schedules.
Attendo has a built-in erasure tool a business can run for any individual. It removes that person's contact record and every conversation they had with the assistant. Appointment history is kept because the business needs its schedule records, but the customer's name, phone number, email and notes are stripped from it. A business can also export information held about one person to answer an access request.
Your choices and requests
6th Meridian Pte. Ltd. is responsible for the information it handles under Singapore's Personal Data Protection Act. To request access, correction or deletion, email 6m.ops@6thmeridian.ai. If your request concerns a conversation with a business using Attendo, you can contact that business directly or ask us to pass your request on.
Changes to this policy
If 6th Meridian introduces analytics, cookies, or other services that process personal information, this notice will be updated before those features go live to explain what is collected, why it is used, who processes it, and how long it is retained.