Privacy Policy
Effective: September 2, 2026
This Privacy Policy explains how Agent 20SEVEN ("we", "us", "our") collects, uses, stores, discloses, and protects personal information when you interact with our website, voice calls, WhatsApp conversations, forms, and related services (collectively, the "Services"). We are committed to handling your data lawfully, fairly, and transparently.
1. Information We Collect
- Identity & contact data: name, email, phone number, company, job title.
- Conversation data: audio recordings, transcripts, chat messages, message metadata (timestamps, phone numbers, delivery status).
- Appointment data: preferred times, meeting purpose, notes you provide.
- Technical data: IP address, device type, browser, operating system, referring URLs, and interaction events.
- Cookies & similar technologies: for essential site function, analytics, and performance.
2. How We Use Your Information
- Respond to inquiries and deliver requested Services.
- Schedule, confirm, reschedule, and follow up on appointments.
- Operate, maintain, secure, and improve the Services.
- Train and quality-assure our AI models on lawful bases (see Section 4).
- Send transactional communications and, with consent, marketing communications.
- Comply with legal obligations, enforce our Terms, and prevent fraud or abuse.
3. Call & Message Recording
Voice calls and messaging sessions may be recorded and transcribed. Where required by law, we provide a notice at the start of the call and rely on your continued participation as consent. Recordings are stored securely with restricted access and are retained only as long as needed for the purposes described here.
4. Legal Bases for Processing
Where GDPR, UK GDPR, or similar laws apply, we process personal data on one or more of these bases: (a) your consent; (b) performance of a contract with you; (c) compliance with a legal obligation; (d) protection of vital interests; and (e) our legitimate interests in operating, securing, and improving the Services, balanced against your rights.
5. Data Protection & Security
- Encryption in transit: TLS 1.2+ for all web, API, and messaging traffic.
- Encryption at rest: AES-256 (or equivalent) for stored recordings, transcripts, and databases.
- Access controls: role-based access, least-privilege permissions, unique credentials, and multi-factor authentication for administrative accounts.
- Network security: firewalls, isolated environments, and continuous monitoring for anomalous activity.
- Secure development: code review, dependency scanning, and regular security testing.
- Vendor due diligence: processors are contractually bound to appropriate technical and organizational measures.
- Backups & resilience: encrypted backups and recovery procedures to protect against loss or corruption.
- Personnel: confidentiality agreements, background checks where lawful, and privacy/security training.
- Incident response: documented procedures to detect, contain, investigate, and notify affected users and regulators as required by law.
No system is 100% secure. While we use reasonable measures aligned with industry standards, we cannot guarantee absolute security.
6. Sharing & Disclosure
We share personal data only with:
- Service providers (processors): telephony, messaging, AI/LLM, calendar, email delivery, hosting, and analytics vendors, all bound by written data-processing agreements.
- Professional advisors: lawyers, auditors, and insurers under confidentiality obligations.
- Authorities: when required by law, valid legal process, or to protect rights, safety, and property.
- Business transfers: in connection with a merger, acquisition, or sale of assets, with continued protection of your data.
We do not sell personal information and we do not share it for cross-context behavioral advertising.
7. International Data Transfers
Your data may be processed in countries other than your own. Where personal data is transferred outside the EEA, UK, or other regulated regions, we rely on appropriate safeguards such as Standard Contractual Clauses, adequacy decisions, or equivalent mechanisms.
8. Data Retention
We retain personal data only as long as necessary for the purposes described here or as required by law. Typical retention windows:
- Contact and appointment records: for the duration of our relationship plus a reasonable period for legal and tax obligations.
- Call recordings and transcripts: a limited period for quality assurance, dispute resolution, and model improvement, after which they are deleted or anonymized.
- Website analytics: aggregated and retained only as needed for reporting.
9. Your Rights
Depending on your jurisdiction (including GDPR, UK GDPR, CCPA/CPRA, and similar laws), you may have the right to:
- Access the personal data we hold about you.
- Rectify inaccurate or incomplete data.
- Request deletion ("right to be forgotten") subject to legal limits.
- Restrict or object to certain processing, including profiling.
- Withdraw consent at any time without affecting prior processing.
- Port your data to another provider in a structured, machine-readable format.
- Opt out of the "sale" or "sharing" of personal information (we do not engage in either).
- Lodge a complaint with a supervisory authority.
To exercise these rights, contact us using the details in Section 14. We will verify your identity before acting on requests and respond within the timeframes required by applicable law.
10. Automated Decision-Making & AI
Our Services use AI to generate responses, summarize conversations, and schedule appointments. We do not use these systems to make decisions producing legal or similarly significant effects about you without human involvement. You may request human review of any AI-generated interaction that affects you.
11. Children's Privacy
Our Services are not directed to children under 16 (or the age required by local law). We do not knowingly collect personal data from children. If you believe a child has provided us data, contact us for prompt deletion.
12. Cookies & Tracking
We use strictly necessary cookies to operate the site and, where permitted, analytics cookies to understand usage. You can control cookies through your browser settings; disabling some cookies may affect functionality.
13. Data Breach Notification
If a personal data breach is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority and, where required, affected individuals without undue delay in accordance with applicable law.
14. Contact Us
Questions, requests, or complaints about this Policy or your data can be submitted through the contact form on our home page. We will respond as promptly as reasonably possible and within any legally required period.
15. Changes to This Policy
We may update this Policy from time to time. Material changes will be indicated by updating the effective date above and, where appropriate, by additional notice.