AI disclosure
Avrosh answers your customers with software. This page states how that is disclosed on each channel, what the assistant is allowed to say, how it is stopped from making things up, where those controls are narrower than they sound, and how a person is reached. Avrosh is operated by PT Laras Teknologi International. Everything here describes the product as built. Where something is not built, this page says so rather than describing an intention. Questions go to hello@avrosh.com.
What is disclosed, and on which channel
In the chat that opens from a QR code or a link, the first message the customer sees names the assistant as the virtual assistant of your business, in each of the supported languages. The chat also tells them they may type in any language and the AI will follow. Nothing in that chat is presented as a named member of your staff.
On a phone call, the assistant answers in your business's name and asks how it can help. It does not announce, unaided, that it is automated. That is the honest state today: the spoken greeting is a fixed per language template with your business name as the only variable, and there is no per property setting that makes it announce automation. A design exists for a per property disclosure setting, with one mode that always announces and one mode that only answers honestly when asked. It has not been built.
Some jurisdictions require a spoken announcement on an automated call, and the requirement falls on you as the business placing or receiving the call. If you are in one of them, tell us before you go live so the greeting for your property is set accordingly as part of your setup, and treat that as a condition of using voice rather than an optional extra.
There is also no prompt line today that forces the assistant to admit it is software when a customer asks directly. In practice it does not claim to be a named human and it never claims to be a specific employee, but until the disclosure setting is built, the answer to "am I talking to a machine" is model behaviour rather than a guarantee we can make in writing.
It answers from your data, and only your data
The assistant answers from the business record you configure: your property profile, your services or room types and their prices, your menu or product catalogue, your policies, your opening hours, and your live availability. Answers about availability, prices and slots come from the booking engine at the moment of the question, not from anything the model remembers.
It has no outside world. It is instructed that it cannot check weather, traffic, news, flights, public holidays beyond today's date, or another business's prices, and that it must say so plainly instead of inventing an answer. The one exception is local information you have saved yourself, which is your content.
For every vertical other than hotel, an unconfigured service is a closed book. If a service has no hours and no slot configuration, the assistant offers nothing for it rather than guessing a time it might be free.
The assistant never writes to your knowledge base. It cannot teach itself a fact from a conversation. Everything it can say is something a person on your side entered, or something a tool read from your live data.
It refuses rather than guesses, and here is the real scope
Every reply passes a truth check before the customer sees it, including replies that stream out word by word. The check verifies that the specifics in the answer were actually returned by a tool or found in your content this turn. If something is ungrounded, the assistant is corrected once. If the corrected reply is still ungrounded, it does not go out: the customer gets a deterministic honest reply and the question is escalated to your staff.
What is checked mechanically: prices, clock times, durations and time estimates, bare opening and closing hours, calendar dates including invented months, and numbers written out in words. The price check covers common currency notations plus your own currency code. A booking is separately policed: the assistant cannot say a booking is confirmed or paid when what exists is a pending hold, and it cannot claim a hold it did not actually create in that turn.
What is not checked mechanically, stated plainly. The check on invented NAMES is hotel shaped only. It is a pattern over capitalised English phrases ending in words like Rooms, Villas, Suites, Studios or Apartments. A salon service, a dental procedure, a menu item, a product, and any name in a language other than English are not name checked. The same is true of attribute claims such as vegan, halal, organic, allergen free, or a material or certification. For those, the protection is instruction to the model, not a mechanical check, and instruction is weaker than a check. Treat the catalogue you configure as the thing that keeps names honest, and read your own transcripts.
What it can actually do
Answer questions from your data. Quote prices and availability that the engine returned. Hold a booking or an appointment, which it must describe as held and pending, never as confirmed or paid. Take an order from your menu or product list. Log a service request, a wake up, or an on site reservation. Collect a name and a contact number when a booking needs one. Hand a customer a link or a card to complete something themselves.
Anything with an effect must be recorded by calling the tool that records it before the assistant acknowledges it. A warm reply with nothing behind it is treated as a failure, not a nicety, because your staff would never see the request. If a tool is switched off or blocked, the assistant tells the customer it has alerted the team and escalates, rather than pretending the job is handled.
What it will not do
It will not give medical, clinical or legal advice, diagnose, prescribe, judge how urgent a symptom is, or say that a treatment is suitable for a particular person. In the dental and clinic configurations it is instructed to offer an appointment instead, and to tell someone describing an emergency to seek immediate medical care. In salon and similar settings it will not confirm that a treatment is safe for someone who mentions pregnancy, breastfeeding, medication, a medical condition or an allergy, and offers a consultation instead.
It will not confirm a payment, promise a delivery or arrival time, or promise how quickly staff will respond. It will not mirror a rude or provoking customer: it matches their language, never their manner.
It will not answer questions that belong to a person. When the honest answer is "I do not know", it says so.
When it cannot answer
The assistant tells the customer plainly that it does not have that detail, and that it has passed the question to your staff who will reply in the same thread. That is not a dead end for the customer: the escalation lands in your dashboard inbox as a live conversation, and a staff reply appears in the same conversation the customer is already looking at.
The same path is taken automatically when the truth check refuses a reply, when a conversation reaches its usage limit, and when a tool the assistant needed is unavailable.
Reaching a person
In chat, the customer can ask for a person at any time. That immediately pauses the AI for that conversation: no further automated reply is generated, the thread shows that they are connected with your team, and your staff answer by hand. Your staff can also pause the AI themselves from the inbox on any single conversation, and resume it later.
On a browser voice call, when the AI has been paused the caller hears a short spoken handoff line instead of an automated answer, and the conversation continues with your staff in the same thread.
On a telephone call there is no live warm transfer to a person today. The call is not bridged to a human line. What happens instead is that the request is recorded, your staff see it, and they follow up. If a live transfer matters to you, say so before you buy voice, because it is not something the product does yet.
Calls, transcripts and audio
No call audio is recorded or stored. What is kept is a written transcript of the conversation and a call record with its metadata, in the same place the chat conversations live. The spoken greeting audio is generated for the call and is not persisted.
This matters for expectations on both sides. A customer who assumes nothing is written down is wrong: the words are kept as text. A customer who assumes their voice is on file is also wrong: it is not.
There is no automatic retention period on conversations, chat sessions, call records or their transcripts today. They live for the life of the account. Other data is pruned on a schedule, but this category is not, and deletion is on request. If you need a fixed retention window for transcripts, ask, and do not assume one is running.
Clinical and other sensitive settings
The product ships dental and clinic configurations. A transcript in that setting can contain health information, because a person describing why they want an appointment is describing their health. Say plainly what that means. We hold no HIPAA business associate status, no health data certification, and no SOC 2 or ISO 27001. Do not use Avrosh in a way that requires any of those.
There are product level safeguards. In the dental configuration the chat refuses photographs and medical documents outright and tells the customer to bring them to the visit or contact the clinic directly, so clinical documents do not ride the guest thread. Booking pages for sensitive verticals are served with no index and no store headers. The assistant is instructed not to diagnose, assess or advise.
What you must not put in. Do not load patient records, clinical notes, diagnoses or treatment histories into the knowledge base the assistant reads: everything in there is material the assistant may repeat to whoever is in the chat. Do not use the assistant as a place to store clinical detail. Instruct your own staff not to paste clinical information into a customer thread. The minimum a booking needs is a name, a contact number and the service, and that is the amount of sensitive detail the system is designed to hold.
The same discipline applies wherever a booking carries identity documents, licence details or a home address. Those configurations are marked sensitive in the product, but marking is not a substitute for you deciding what belongs in a chat.
Outbound calling is a separate thing
Everything above describes a customer contacting your business. Outbound calling, where the assistant rings a list, is a separate capability with separate duties and it is not on by default.
The numbers come from you. We do not source, buy or scrape lists, and the consent behind every number is yours to hold. In the product, a list cannot run until someone on your side has attested to that consent and set a calling window, and an empty window means never rather than always. There is a cap on how many times one number may be tried. A suppression list outranks every other rule: a number on it is never dialled, and a person who refuses on a call is added to it automatically and permanently unless you lift it yourself.
Disclosure duties on an outbound automated call are stricter than on a call the customer placed, and in some countries a wrong call is priced per call. If you intend to run outbound, that belongs in a written agreement with us before a single number is loaded.
Which models answer, and where they run
The model serving each role, chat, voice, classification, speech to text, text to speech and knowledge base search, is chosen in your dashboard settings, and each option carries the region it is served from and the confidence we have in that. The origin of every model is also published on our security page, so the record is the same whether you read it as a customer or as a stranger.
Where those models run is not the same question as where your database sits. We serve databases from Northern Virginia, Singapore and Frankfurt. The models that are cleared for production today are not spread the same way: the language models and the knowledge base search run from Singapore, speech to text runs from the United States, and the text to speech vendor's origin is not verified. There is no cleared model serving from the EU today. A customer on the Frankfurt region gets a Frankfurt database and an answer path with nothing in the EU. Say that back to any auditor who asks, because we will.
No accuracy figure
We publish no accuracy percentage, and you should distrust any vendor who does without publishing the test set behind it. What we publish instead is the design: answers come from your data, specifics are checked before they leave, an unresolvable answer becomes an honest refusal and an escalation, a person can be reached, and the places where the checks are narrower than they sound are named on this page rather than buried.
The accuracy of what the assistant says about your business is a function of what you configured. If a price is stale in your catalogue, the assistant will quote the stale price and every check will pass, because it is grounded. Keeping the record right is your side of this.
Questions about anything on this page, including a written retention window for transcripts, a disclosure announcement on your phone line, or an outbound calling agreement, go to hello@avrosh.com. Avrosh is operated by PT Laras Teknologi International. This page describes the product as it is built on the review date above and is updated when the product changes.