01Who is responsible
[EESI legal entity name — TO CONFIRM WITH COUNSEL] ("EESI", "we") is the data controller for the personal data described in this policy — your account, your billing, your use of the platform.
One distinction matters: when your organization runs voice agents or records calls through the Service, the people on those calls are your users, and your organization is the controller of their data. EESI processes it on your instructions, as a processor. This policy covers what EESI does; what you announce to your callers and how you use their recordings is governed by your own privacy policy and our Terms.
02What we collect
- Account data. Name, email address, organization membership, and sign-in metadata, managed through Clerk, our identity provider.
- Billing data. Payments are handled by Stripe; your card details go to Stripe directly and never touch EESI's systems. We keep your plan, credit balance, and transaction history.
- Audio and transcripts. The audio you send to our APIs and the audio our models generate; recordings and transcripts of sessions and calls where recording is enabled and announced; reference clips you upload for voice cloning.
- Usage data. API request metadata — model, duration, characters, latency, errors — and per-session event logs, kept so we can meter your usage, bill it, debug it, and let you replay your own sessions.
- Website analytics. Aggregate, cookieless page analytics through Umami, self-hosted at analytics.eesi.ai. The data stays on our infrastructure. No third-party advertising trackers, anywhere.
03What we use it for
- Providing and operating the Service — running your requests, sessions, and agents;
- metering usage and billing it against your credits;
- securing the Service and preventing abuse and fraud;
- debugging: replaying a session's event stream to find out what went wrong, when you ask us to or when the Service fails;
- improving the Service using aggregate metrics — never your audio without consent (section 05);
- sending transactional email — receipts, security notices, service changes — through Resend;
- complying with legal obligations, such as tax and accounting.
04Legal bases (GDPR)
Where the GDPR applies, we rely on:
- Contract — operating your account, delivering API output, billing;
- legitimate interests — securing the Service, preventing abuse, and measuring the product with self-hosted, cookieless analytics;
- consent — the training corpus (section 05) and any marketing;
- legal obligation — records we are required to keep.
05Training data is consent-gated
We do not train models on your API traffic, your recordings, or your cloned voices by default. Audio enters our training corpus only when the person speaking — or the customer who holds the rights, with that speaker's consent — has explicitly opted in. Each consent is recorded alongside the audio it covers, and it is revocable: revoke it and the audio is excluded from future training runs. This is the whole policy; there is no quiet exception to it.
06Retention and deletion
- Recordings and transcripts are kept while you keep them. You can delete any recording, or all of them, from the platform or the API at any time.
- Account deletion — close your account from your account settings and the deletion is honored through Clerk. Your account data is removed and your stored content is scheduled for deletion within 30 days, except records we must keep by law (such as billing history), which are kept only as long as that law requires.
- Usage logs are retained for as long as needed for billing, security, and debugging, then deleted or reduced to aggregates.
- Backups — residual copies in encrypted backups are purged on the backup rotation schedule.
07Subprocessors
We use a small set of subprocessors, each for one job:
- Google Cloud Platform — hosting, compute, and storage, in the us-central1 region (United States);
- Clerk — identity and authentication (United States);
- Stripe — payments and subscription billing (United States);
- Resend — transactional email (United States).
We will update this list before adding a subprocessor that handles personal data.
08International transfers
The Service is hosted on Google Cloud in the United States (us-central1). Where your data originates in the EU, UK, or another jurisdiction with transfer rules, we rely on appropriate safeguards with each subprocessor — Standard Contractual Clauses and, where a provider is certified, the EU–US Data Privacy Framework. [SCC modules and DPF status per subprocessor — TO CONFIRM WITH COUNSEL]
09Your rights
Depending on where you live, you have the right to access, correct, export, restrict, object to the processing of, and erase your personal data, and to withdraw any consent — including training consent — without affecting what happened before you withdrew it. Write to founders@eesi.ai from your account email and we will act on it; most of these rights you can also exercise directly from the platform. If you are in the EU or UK, you also have the right to lodge a complaint with your supervisory authority.
10Security
Data is encrypted in transit and at rest. Access inside EESI is least privilege and logged; API keys are scoped to your organization. Reference audio and voiceprints live in access-controlled storage. No system is perfectly secure — if a breach affects your data, we will notify you and the authorities the law requires, without undue delay.
11Cookies
The platform sets the cookies needed to keep you signed in, through Clerk. Our website analytics (Umami, self-hosted) are cookieless. We set no advertising or cross-site tracking cookies.
12Children
The Service is not directed to children, and we do not knowingly collect personal data from anyone under 16 — or under the age of digital consent where they live, if higher. If you believe a child has given us personal data, tell us and we will delete it.
13Changes to this policy
We may update this policy as the Service evolves. If a change is material, we will notify you by email or in the platform before it takes effect, and this page always carries the current date at the top.
14Contact
Privacy questions and requests: founders@eesi.ai. The founders read this inbox. [Whether an Art. 27 EU representative or Art. 37 DPO appointment is required — TO CONFIRM WITH COUNSEL]