Privacy Policy
Last updated: [TODO: date]
This is a template provided with the software, not legal advice. Review and adapt it with qualified counsel before you rely on it. Items marked [TODO] must be completed with your own details.
This Privacy Policy explains how [TODO: legal entity name] ("we", "us") collects and processes personal data when you use objected.ai, an AI sales-roleplay practice tool. It is written to meet the transparency requirements of Articles 13 and 14 of the EU General Data Protection Regulation (GDPR).
Who is responsible (controller)
The controller for the processing described here is: [TODO: legal entity name] [TODO: postal address] [TODO: contact email] If your organization runs objected.ai on its own infrastructure (self-hosting), that organization is the controller for the data in its instance and should adapt this template accordingly.
What we process
• Account data: your name, email address, hashed password, language and interface preferences, and organization membership. • Practice content: the transcripts of your spoken roleplay calls with the AI prospect. Your microphone audio is streamed live to our model provider to power the conversation; we store the resulting text transcript, not the audio. • Scorecards: the AI-generated evaluation of each practice call, including scores, written feedback, and short verbatim quotes from your transcript. • Usage and billing data: session counts and durations, and, if billing is enabled, subscription and payment identifiers handled by our payment provider. • Technical data: the minimal server logs needed to operate and secure the service.
Why we process it, and our legal basis
• To provide the service you signed up for - running practice calls, generating scorecards, and keeping your history (Art. 6(1)(b) GDPR, performance of a contract). • To score and improve your practice and to keep the service secure and reliable (Art. 6(1)(f) GDPR, our legitimate interests). • To handle billing where applicable (Art. 6(1)(b) and 6(1)(c) GDPR). • To send you a single reminder after sign-up if you have not run a practice call yet (Art. 6(1)(f) GDPR, our legitimate interest in helping you get started). Every such message carries a link to stop them, and stopping them never affects account emails like password resets or invitations. We do not use your practice content to train third-party AI models, and we do not sell personal data.
Recipients and sub-processors
To run the service we share the minimum necessary data with the following processors, each under a data-processing agreement and acting only on our instructions: • OpenAI - powers the live AI prospect (your microphone audio and transcript) and may perform post-call scoring. United States. • Anthropic - alternative provider for post-call scoring, used when configured by the operator. United States. • Polar - subscription billing and payments, used when billing is enabled. United States / EU. • Discord - optional operational notifications, used only if the operator configures a feedback webhook. United States. A current sub-processor list and the relevant agreements are available on request at [TODO: contact email].
International data transfers
Some of the processors above are located in the United States, so your personal data (including practice transcripts) may be transferred outside the European Economic Area. These transfers rely on appropriate safeguards under Chapter V GDPR - the EU Standard Contractual Clauses and/or the providers' EU-U.S. Data Privacy Framework certification, as applicable [TODO: confirm the mechanism for each provider]. You can request a copy of the safeguards at [TODO: contact email].
How long we keep it
• Account data is kept while your account is active. • Practice transcripts are automatically deleted [TODO: 180] days after each session; aggregate scores may be kept longer so you can see your progress over time. • When you delete your account, your personal data - including transcripts and scorecards - is erased after a short grace period, and identifying details are removed from our operational audit log. The transcript retention period is configurable by the operator; this instance is set to [TODO: 180] days.
Cookies
We use only strictly necessary and functional cookies: your sign-in session, and your language, theme, and practice-language preferences. We use no advertising or third-party analytics cookies, so no cookie-consent banner is required. You can clear these cookies in your browser at any time, though doing so will sign you out.
Your rights
Under the GDPR you have the right to access, rectify, erase, restrict, and object to the processing of your personal data, and the right to data portability. You can exercise the main rights directly in the app from your account page: • Download a copy of your data. • Delete your account and the data associated with it. For any other request, contact us at [TODO: contact email]. You also have the right to lodge a complaint with your local data-protection supervisory authority.
Security
We use access controls, encryption in transit, and strict separation between tenants so that one organization can never see another's data. Self-hosting operators are responsible for securing their own infrastructure, including disk encryption and database backups.
Children
objected.ai is a workplace tool intended for adults and is not directed at children. We do not knowingly collect personal data from anyone under 16.
Changes to this policy
We may update this policy as the service evolves. We will communicate material changes through the app or by email where appropriate. The "last updated" date above always reflects the current version.