Skip to main content
Version 2026-06-11 · Effective 2026-06-11 · Languages: English · Deutsch · Français · Español
Nedzo (“we”, “us”) provides an AI communications platform that our customers use to talk to their own end-users by voice, chat and messaging. This Privacy Policy explains how we handle personal data as a controller — for visitors to our website and for our customers (the organizations that sign up for Nedzo). When our customers use Nedzo to process their end-users’ personal data, they are the controller and we act as their processor under a Data Processing Agreement; that processing is described in our customers’ own privacy notices and in our customer Data Processing Agreement. We provide this notice under Articles 13 and 14 of the General Data Protection Regulation (EU) 2016/679 (“GDPR”).

1. Who we are

Nedzo is the controller for the personal data described in this policy. For any privacy question, or to exercise your rights, contact us at privacy@nedzo.ai.

2. What personal data we collect

Depending on how you interact with us, we may collect:
  • Account and identity data — name, business name, email address, phone number, and the region you choose for your data.
  • Authentication data — sign-in events, multi-factor authentication factors (we store only an opaque identifier and factor reference, never your secret).
  • Billing data — billing contact, address, and payment-method details (processed by our payment provider; we do not store full card numbers).
  • Usage and device data — log data, IP address, browser and device information, and how you use the dashboard.
  • Content you provide — agent configuration, knowledge-base documents, contacts you upload, and messages you send through the platform.
We process personal data to:
  • provide and operate the service (performance of our contract with you);
  • secure the platform, prevent abuse and authenticate users (legitimate interests and legal obligation);
  • bill and collect payment (performance of contract / legal obligation);
  • communicate with you about the service, including transactional and compliance notices (legitimate interests / legal obligation);
  • comply with law, including GDPR record-keeping and tax obligations (legal obligation).
We do not sell personal data, and we do not use the content our customers process through the platform to train general-purpose AI models.

4. Where your data is stored (regions)

You choose a data region — European Union or United States — when you sign up. Personal data for an EU account is stored in the EU (databases, queues, logs, AI inference, email and vector storage are region-isolated). The region is fixed for the life of the account. Where a transfer outside the EEA is unavoidable, we rely on an adequacy decision or the Standard Contractual Clauses with appropriate supplementary measures.

5. Sub-processors

We use a small number of vetted third-party providers (“sub-processors”) to deliver the service — for example for telephony, AI inference, email delivery, storage and logging. Each is bound by a data-protection agreement no less protective than ours. The current list, the purpose of each, the categories of data shared and the data location(s) is published, and you can subscribe to be notified at least 30 days before we add a new one, on our Sub-processor list.

6. How long we keep it

We keep personal data only as long as necessary for the purposes above. Workspace owners can configure shorter retention windows for high-sensitivity data (call recordings, transcripts, conversations and inactive contacts), subject to a platform maximum, and an automated process deletes or anonymizes data past its window. Compliance and audit records are retained for the statutory period.

7. Security

We maintain appropriate technical and organizational measures, including encryption in transit and at rest, regional network isolation, access controls, multi-factor authentication for privileged accounts, audit logging, PII scrubbing in logs, and a tested backup-and-restore procedure.

8. Your rights

Subject to the GDPR, you have the right to access your data, to rectify it, to erase it, to restrict or object to its processing, and to data portability. You can exercise these rights at any time through our data-subject request form or by emailing privacy@nedzo.ai. We respond within one month. You also have the right to lodge a complaint with your supervisory authority. If your personal data is processed by one of our customers (for example, you received a call or message from a business using Nedzo), that business is the controller — please direct your request to them; we will assist them as their processor.

9. Cookies

Our marketing site and dashboard use strictly necessary cookies to operate. We do not use advertising cookies.

10. Changes to this policy

We may update this policy. Each version is published with a version identifier and an effective date, and the change history is kept in our public documentation repository. When we make a material change we notify account Owners in advance.

11. Contact

Questions about this policy or our data practices? Email privacy@nedzo.ai.
See the third-party providers we use on our Sub-processor list.