Legal

Privacy Policy

Last updated: August 2026

EESI is a voice company, so we hold something unusually personal: recordings of people speaking. This policy says what we collect, why, how long we keep it, and the rights you have over it. The short version — your audio is yours, we never train on it without recorded consent, and you can delete it whenever you like.

01Who is responsible

[EESI legal entity name — TO CONFIRM WITH COUNSEL] ("EESI", "we") is the data controller for the personal data described in this policy — your account, your billing, your use of the platform.

One distinction matters: when your organization runs voice agents or records calls through the Service, the people on those calls are your users, and your organization is the controller of their data. EESI processes it on your instructions, as a processor. This policy covers what EESI does; what you announce to your callers and how you use their recordings is governed by your own privacy policy and our Terms.

02What we collect

03What we use it for

04Legal bases (GDPR)

Where the GDPR applies, we rely on:

05Training data is consent-gated

We do not train models on your API traffic, your recordings, or your cloned voices by default. Audio enters our training corpus only when the person speaking — or the customer who holds the rights, with that speaker's consent — has explicitly opted in. Each consent is recorded alongside the audio it covers, and it is revocable: revoke it and the audio is excluded from future training runs. This is the whole policy; there is no quiet exception to it.

06Retention and deletion

07Subprocessors

We use a small set of subprocessors, each for one job:

We will update this list before adding a subprocessor that handles personal data.

08International transfers

The Service is hosted on Google Cloud in the United States (us-central1). Where your data originates in the EU, UK, or another jurisdiction with transfer rules, we rely on appropriate safeguards with each subprocessor — Standard Contractual Clauses and, where a provider is certified, the EU–US Data Privacy Framework. [SCC modules and DPF status per subprocessor — TO CONFIRM WITH COUNSEL]

09Your rights

Depending on where you live, you have the right to access, correct, export, restrict, object to the processing of, and erase your personal data, and to withdraw any consent — including training consent — without affecting what happened before you withdrew it. Write to founders@eesi.ai from your account email and we will act on it; most of these rights you can also exercise directly from the platform. If you are in the EU or UK, you also have the right to lodge a complaint with your supervisory authority.

10Security

Data is encrypted in transit and at rest. Access inside EESI is least privilege and logged; API keys are scoped to your organization. Reference audio and voiceprints live in access-controlled storage. No system is perfectly secure — if a breach affects your data, we will notify you and the authorities the law requires, without undue delay.

11Cookies

The platform sets the cookies needed to keep you signed in, through Clerk. Our website analytics (Umami, self-hosted) are cookieless. We set no advertising or cross-site tracking cookies.

12Children

The Service is not directed to children, and we do not knowingly collect personal data from anyone under 16 — or under the age of digital consent where they live, if higher. If you believe a child has given us personal data, tell us and we will delete it.

13Changes to this policy

We may update this policy as the Service evolves. If a change is material, we will notify you by email or in the platform before it takes effect, and this page always carries the current date at the top.

14Contact

Privacy questions and requests: founders@eesi.ai. The founders read this inbox. [Whether an Art. 27 EU representative or Art. 37 DPO appointment is required — TO CONFIRM WITH COUNSEL]