> ## Documentation Index
> Fetch the complete documentation index at: https://docs.nedzo.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Privacy Policy

> How Nedzo handles personal data as a controller — for website visitors and customers — under GDPR Art. 13/14. Version 2026-06-11, effective 2026-06-11.

<Info>
  **Version 2026-06-11** · Effective **2026-06-11** · Languages: [English](/privacy) · [Deutsch](/privacy/de) · [Français](/privacy/fr) · [Español](/privacy/es)
</Info>

Nedzo ("we", "us") provides an AI communications platform that our customers use to
talk to their own end-users by voice, chat and messaging. This Privacy Policy
explains how we handle personal data **as a controller** — for visitors to our
website and for our customers (the organizations that sign up for Nedzo). When our
customers use Nedzo to process their end-users' personal data, **they** are the
controller and we act as their **processor** under a Data Processing Agreement; that
processing is described in our customers' own privacy notices and in our
[customer Data Processing Agreement](https://app.nedzo.ai).

We provide this notice under Articles 13 and 14 of the General Data Protection
Regulation (EU) 2016/679 ("GDPR").

## 1. Who we are

Nedzo is the controller for the personal data described in this policy. For any
privacy question, or to exercise your rights, contact us at
[privacy@nedzo.ai](mailto:privacy@nedzo.ai).

## 2. What personal data we collect

Depending on how you interact with us, we may collect:

* **Account and identity data** — name, business name, email address, phone number,
  and the region you choose for your data.
* **Authentication data** — sign-in events, multi-factor authentication factors
  (we store only an opaque identifier and factor reference, never your secret).
* **Billing data** — billing contact, address, and payment-method details (processed
  by our payment provider; we do not store full card numbers).
* **Usage and device data** — log data, IP address, browser and device information,
  and how you use the dashboard.
* **Content you provide** — agent configuration, knowledge-base documents, contacts
  you upload, and messages you send through the platform.

## 3. Why we use it and our legal bases

We process personal data to:

* **provide and operate the service** (performance of our contract with you);
* **secure the platform**, prevent abuse and authenticate users (legitimate
  interests and legal obligation);
* **bill and collect payment** (performance of contract / legal obligation);
* **communicate with you** about the service, including transactional and compliance
  notices (legitimate interests / legal obligation);
* **comply with law**, including GDPR record-keeping and tax obligations (legal
  obligation).

We do not sell personal data, and we do not use the content our customers process
through the platform to train general-purpose AI models.

## 4. Where your data is stored (regions)

You choose a data region — **European Union** or **United States** — when you sign
up. Personal data for an EU account is stored in the EU (databases, queues, logs,
AI inference, email and vector storage are region-isolated). The region is fixed for
the life of the account. Where a transfer outside the EEA is unavoidable, we rely on
an adequacy decision or the Standard Contractual Clauses with appropriate
supplementary measures.

## 5. Sub-processors

We use a small number of vetted third-party providers ("sub-processors") to deliver
the service — for example for telephony, AI inference, email delivery, storage and
logging. Each is bound by a data-protection agreement no less protective than ours.
The current list, the purpose of each, the categories of data shared and the data
location(s) is published, and you can subscribe to be notified at least 30 days
before we add a new one, on our [Sub-processor list](https://docs.nedzo.ai/subprocessors).

## 6. How long we keep it

We keep personal data only as long as necessary for the purposes above. Workspace
owners can configure shorter retention windows for high-sensitivity data (call
recordings, transcripts, conversations and inactive contacts), subject to a
platform maximum, and an automated process deletes or anonymizes data past its
window. Compliance and audit records are retained for the statutory period.

## 7. Security

We maintain appropriate technical and organizational measures, including encryption
in transit and at rest, regional network isolation, access controls, multi-factor
authentication for privileged accounts, audit logging, PII scrubbing in logs, and a
tested backup-and-restore procedure.

## 8. Your rights

Subject to the GDPR, you have the right to **access** your data, to **rectify** it,
to **erase** it, to **restrict** or **object** to its processing, and to **data
portability**. You can exercise these rights at any time through our
[data-subject request form](https://app.nedzo.ai/privacy/dsr) or by emailing
[privacy@nedzo.ai](mailto:privacy@nedzo.ai). We respond within one month. You also
have the right to lodge a complaint with your supervisory authority.

If your personal data is processed by one of our customers (for example, you
received a call or message from a business using Nedzo), that business is the
controller — please direct your request to them; we will assist them as their
processor.

## 9. Cookies

Our marketing site and dashboard use strictly necessary cookies to operate. We do
not use advertising cookies.

## 10. Changes to this policy

We may update this policy. Each version is published with a version identifier and an
effective date, and the change history is kept in our public documentation
repository. When we make a material change we notify account Owners in advance.

## 11. Contact

Questions about this policy or our data practices? Email
[privacy@nedzo.ai](mailto:privacy@nedzo.ai).

***

*See the third-party providers we use on our [Sub-processor list](https://docs.nedzo.ai/subprocessors).*
