This is a draft, working document. It has not yet been reviewed by a lawyer and is not yet in force.

Privacy Policy

1. Who controls your data

We are finalizing our registered legal entity details (name, address, company and VAT registration numbers) and a dedicated data-protection contact, and will publish them here.

Controller/processor split. For your own business data and for the third-party personal data you upload or generate through the Service (leads, contacts, inbound email senders), you are the controller and we are the processor, acting on your documented instructions under a Data Processing Agreement. For your own account and administrator data, we are the controller. This notice covers both roles and flags which applies where.

2. What data we collect

We collect and process the following categories of data:

3. Why we process your data

4. Who else processes your data

We use a number of sub-processors to run the Service — Anthropic, Deepgram, ElevenLabs, Supabase, Hetzner, Resend, an S3-compatible backup provider, and our payment Merchant of Record, Polar. LiveKit, which carries live voice and video, is self-hosted and not an external recipient. Each sub-processor is engaged under a data-processing agreement and may only use your data to help us provide the Service.

5. International data transfers

Some of your data is processed by US-headquartered providers (Anthropic, Deepgram, ElevenLabs, Resend, and our payment Merchant of Record, Polar, for customer/subscription/payment data); all stored data stays in the EU (our database provider's EU region and our EU-based host), and live voice-call media is carried by our own self-hosted EU server. We use appropriate international-transfer safeguards — such as the EU Standard Contractual Clauses and, where available, the EU–US Data Privacy Framework — for each of these providers; the specific mechanism per provider will be published here once finalized.

6. How long we keep your data

We retain personal data only as long as needed for the purposes above, then delete or prune it. Transcripts, audit logs, and agent-run records are automatically time-pruned across your workspace after a configurable age. We are finalizing the exact retention period for each data category and will publish the specific day-counts here. When you close your account, see the offboarding section of our Terms of Service.

7. Your data-subject rights

You have the rights of access, rectification, erasure, restriction, portability, and objection over your personal data. We have built tools that let you, or your users, request a copy of personal data we hold, or ask us to erase it — erasure requests are confirmed in two steps before they take effect, and every request is logged. Because we are often the processor, a data subject's request usually goes to you (the controller), and we assist you in fulfilling it. We are finalizing the exact request channel, identity-verification steps, and response timeline, and will publish them here; by law, we respond within one month. You may also lodge a complaint with the Slovenian supervisory authority (Informacijski pooblaščenec) or your own local data-protection authority.

8. Automated decision-making and AI

The Service uses AI — the CEO agent and department agents — to generate drafts and suggestions. You review AI output before acting on it. We do not make any decision with a legal or similarly significant effect about you or your customers solely by automated means.

9. Security

We isolate each tenant's data with per-tenant schema isolation and row-level security, encrypt data in transit, encrypt backups, and restrict access through strict access controls and secrets management.

10. Cookies and tracking technologies

We are finalizing our cookie and tracking-technology policy and will publish it here.

11. Children

This is a business-to-business (B2B) service and is not directed at children. We are finalizing the specific age threshold and will publish it here.

12. Changes to this policy

We are finalizing how we will notify you of changes to this policy and when they take effect, and will publish that process here.

13. Google API Services User Data Policy — Limited Use

Where you choose to connect a Google account to the Service, Strady's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy , including the Limited Use requirements. This applies to both Google-authorized connectors the Service offers:

For data accessed through either scope, we: