Draft — not reviewed by legal counsel
This page lays out the sections a Privacy Policy typically needs, with the actual third-party processors this product integrates, so nothing is missing structurally. It is not a substitute for review by a lawyer covering the specific regulations of your target markets (e.g. GDPR, CCPA, state-level call recording laws) before real customer data is processed.
Account & organization data: name, email, company info, and billing details you provide at signup.
Call data: caller phone number, call recordings, transcripts, and AI-generated summaries for calls handled by your agent.
Chat & social data: messages exchanged through your website chat widget or connected social accounts, and visitor-provided contact details.
Usage data: minutes used, API activity, and log data needed to operate and secure the Service.
When your AI agent handles a call, the conversation may be recorded and transcribed to power call summaries, lead capture, and appointment booking. This is one of the most legally sensitive parts of this product — recording consent requirements vary by jurisdiction, and it is your organization's responsibility (as the account holder) to ensure callers receive any legally required disclosure. See the Terms of Service, Section 5.
To provide and improve the Service, generate AI responses and call summaries, process payments, send transactional emails (booking confirmations, billing notices, password resets), detect abuse, and comply with legal obligations. We do not sell personal data.
Data is processed by the following providers as necessary to deliver the Service: Twilio (telephony, call routing), OpenAI (AI response generation, from call/chat/social message content), ElevenLabs (text-to-speech voice synthesis), Google (calendar access, only if your organization connects a calendar for appointment booking), Meta (Facebook/Instagram/WhatsApp messaging, only if connected), Supabase (authentication, database hosting), Stripe (payment processing), and Resend (transactional email delivery). Each provider processes only the data necessary for its function and is bound by its own privacy terms.
[Retention periods for call recordings, transcripts, and chat history to be defined — e.g. "retained for the duration of your subscription plus N days" — and whether customers can configure shorter retention. Needs a decision before launch, not just legal review.]
Depending on your jurisdiction (e.g. GDPR in the EU/UK, CCPA in California), individuals may have rights to access, correct, delete, or export their personal data, and to object to certain processing. Requests can be directed to your account administrator or [privacy contact email], who can route them appropriately.
We use essential cookies for authentication (session tokens) and may use additional cookies for analytics. [Full cookie inventory and consent-banner requirements to be confirmed for target markets, e.g. EU ePrivacy rules.]
The Service is intended for business use and is not directed at children. We do not knowingly collect personal data from children.
We use industry-standard measures (encryption in transit, access controls, webhook signature verification) to protect data, but no system is completely secure. Report suspected security issues to [security contact email].
[To be confirmed based on where the company and its processors host data, relative to where customers and their callers are located — relevant if serving EU/UK customers.]
We may update this Privacy Policy from time to time. Material changes will be communicated via email or in-app notice before taking effect.
Questions about this Privacy Policy or your data can be directed to [privacy contact email], or to your account administrator.