Controller and scope
This template describes the intended operational privacy posture for the Voice AI application. It covers public website visitors, customers, tenant users, dashboard users, and end users who interact with customer-configured voice or chat assistants.
The customer remains responsible for telling their own end users how the customer's assistant is deployed and what customer-specific data is collected.
Data we process
Account data includes name, email, tenant identifiers, authentication state, preferences, and role assignments.
Product data includes assistant configuration, widget settings, knowledge spaces, uploaded or crawled content, conversations, transcripts, tool calls, and usage metrics.
Operational data includes security logs, audit records, request metadata, billing records, consent choices, and support correspondence.
AI processing may conditionally use Google Gemini, OpenAI, and Anthropic according to platform configuration. Data categories can include prompts, retrieved knowledge context, transcripts, embeddings input, images, PDFs, screenshots, and diagnostic metadata when those features are enabled.
Purposes and lawful bases
We process account and product data to provide the service, secure accounts, maintain tenant isolation, troubleshoot incidents, calculate usage, and support customer requests.
Optional analytics and marketing cookies are used only where the user has consented. Essential cookies and security logs are used to operate and protect the service.
External AI providers may process content for text generation, vision extraction, embeddings, safety enforcement, abuse monitoring, and service reliability. Provider use is subject to configured policy gates, tenant isolation, redaction, and retention settings.
Retention and erasure
Conversation retention defaults to 30 days and can be configured within the product where available. Security and API logs use operational retention windows unless a shorter customer setting or legal hold applies.
Account deletion first marks tenant records as pending deletion, then a cron process performs final deletion after the configured grace period using the account deletion finalizer.
Data subject rights
Users may request access, export, correction, restriction, portability, objection, withdrawal of consent, and deletion through the product privacy tools or support channel.
Where Voice AI acts as processor for customer-controlled assistant data, requests may need to be handled by the customer as controller.