Privacy policy
What we collect, why we have it, who else touches it, and how to make us delete it.
Last updated August 1, 2026
1.Who is responsible for what
Two different relationships run through this product, and they carry different obligations.
- Your account data — your name, email, company, billing details. We are the controller. This policy governs it.
- Your customers' data — the people your AI employees call, text and email, and the content of those conversations. You are the controller. We are your processor, acting on your instructions. Your own privacy notice governs what you tell those people.
If you need a data processing agreement, write to privacy@teamaiops.com.
2.What we collect
From you, directly: name, email address, password (stored only as a hash we cannot reverse), company name, time zone, and the business information you configure your AI employees with.
From your use of the service: IP address, browser and device information, pages visited, and timestamps of actions taken in your account.
Through your AI employees: phone numbers, names and contact details of the people they interact with; call audio where recording is enabled; transcripts; message content; and metadata such as call duration and outcome.
Through Stripe: billing address and the last four digits and expiry of your card. We never receive or store full card numbers.
3.Why we have it
- To run the service you are paying for.
- To bill you, and to chase payment if it fails.
- To send transactional email — verification, receipts, alerts.
- To investigate faults, abuse and security incidents, and to keep an audit trail of who changed what.
- To meet legal and tax obligations.
Where the GDPR applies, our legal bases are performance of a contract, legitimate interests in securing and improving the service, and legal obligation.
4.What we do not do
Three commitments.
We do not sell personal data, and we do not share it for cross-context behavioral advertising.
We do not use your conversation content to train our own models, and we contract with model providers on terms that do not permit them to train on it either.
We do not run advertising or third-party analytics trackers on this website.
5.Who else processes it
Running the service means passing data to the providers below. Adding a new one is a change to this list.
| Provider | Purpose | Data involved |
|---|---|---|
| Vercel | Application hosting and content delivery | Request metadata, IP addresses |
| Neon | Database hosting | All account and conversation data |
| Stripe | Payment processing | Billing contact and payment details |
| Postmark | Transactional email delivery | Recipient email addresses and message content |
| OpenAI, Anthropic, Google | Language model inference for AI employee replies | Conversation content and configured business context |
| Telnyx, Twilio | Telephone numbers, call and SMS delivery | Phone numbers, call metadata, call audio |
| Upstash | Rate limiting and caching | Account identifiers and request counts |
| Inngest | Background job processing | Job payloads referencing conversation identifiers |
We also disclose data where the law requires it, and to advisers or an acquirer in a sale of the business, under confidentiality.
6.How long we keep it
- Account data — while your account is open, then 30 days after closure.
- Conversations, recordings and transcripts — while your account is open, unless you delete them sooner. You control this.
- Audit logs — 24 months, because their value is in answering questions about the past.
- Billing records — seven years, as tax law requires.
7.Your rights
Depending on where you live you may have the right to access your data, correct it, delete it, receive a portable copy, object to processing, or withdraw consent. Residents of California may also request disclosure of what we collect and opt out of sale or sharing — we do neither, but the right exists regardless.
Exercise any of these by writing to privacy@teamaiops.com. We will respond within 30 days and will not treat you worse for asking.
If you are one of your customers' contacts rather than an account holder, your request should go to the business that contacted you — we hold that data on their behalf. Write to us anyway if you cannot reach them and we will help route it.
8.Security
Data is encrypted in transit and at rest. Passwords are hashed. Access to production data is limited to staff who need it, and staff actions on a customer account are written to that customer's own audit log. Payment details never reach our servers.
No system is perfectly secure. If we suffer a breach affecting your data we will tell you promptly and tell you what we know.
9.International transfers
Our providers operate in the United States and may process data elsewhere. Where data moves out of the UK or EEA we rely on standard contractual clauses or an adequacy decision.
10.Children
The service is for businesses. It is not directed at children and we do not knowingly collect data from anyone under 16. If you believe we have, write to privacy@teamaiops.com and we will delete it.
11.Changes
We will post updates here and change the date at the top. For material changes we will email account holders.
12.Contact
privacy@teamaiops.com — or see our cookie policy and terms of use.
TeamAIOps
[Registered business address]