Privacy Policy
Last updated: July 31, 2026 | Effective: July 10, 2026
AYBIZA LLC operates the AYBIZA platform, where AI agents handle customer conversations for your business through voice and chat, plus a CRM and service desk, automations, analytics, and internal channels where your team directs and oversees its agents. This policy explains what data we collect, how we use it, who we share it with, and what rights you have. AYBIZA serves businesses only. We do not knowingly provide services to individuals acting in a personal capacity. References to “AYBIZA,” “we,” “us,” or “our” mean AYBIZA LLC.
1. Who We Are and Our Roles
AYBIZA LLC is a Wyoming limited liability company. We act in two legally distinct roles, and the split is straightforward:
- Controller for the data we collect to run our business relationship with you: account, business verification (KYB), legal-acceptance, and platform usage data. We decide why and how this data is processed.
- Processor for the customer content you and your AI agents create or store on the platform: conversations, voice recordings, CRM records, uploaded knowledge, agent memory, and widget-visitor data. We process this only on your documented instructions. You are the controller of your end-customers’ data. Our Data Processing Agreement (DPA) at /dpa, incorporated into our Terms, governs this processing.
2. What We Collect
Data we collect as controller:
- Account data: your name, work email, job title, company name, and authentication credentials. A work email from a verified business domain is required; consumer email addresses are not accepted.
- Business verification (KYB) data: legal business name, tax identification number, registered address, authorized representative details, declared use cases, estimated volumes, and markets served. This is required for telecommunications carrier registration (STIR/SHAKEN, A2P 10DLC), fraud prevention, and regulatory compliance.
- Legal-acceptance records: the agreement version, timestamp, and IP address recorded when you accept our Terms, this policy, the DPA, or another agreement.
- Usage data: feature usage, API call volumes, credit consumption, session activity, IP addresses, browser and device information, and performance metrics. On the marketing website we collect only the request metadata and abuse-prevention signals needed to keep the site secure and available.
Customer content we process as processor (you are the controller of all of it):
- Conversations: transcripts, messages, and interaction outcomes from your agents and channels.
- Voice recordings: audio captured when you enable call recording, stored under your retention settings.
- CRM records: contacts, deals, support tickets, tasks, and other business records you enter.
- Uploaded knowledge content: documents and files you provide for retrieval and agent grounding.
- Agent memory: the long-term notes an agent retains to maintain context across conversations.
- Widget-visitor data: identifiers, messages, and verification details from visitors who interact with an agent you embed on your own site.
3. How We Use Information
We use the data we control to create and manage your account and workspace, verify your business and activate production access, deliver the platform, process billing and credits, send service communications, provide support, detect and prevent fraud and abuse, comply with legal obligations (including TCPA, FCC rules, STIR/SHAKEN, carrier registration, and OFAC sanctions screening), and improve platform performance using aggregated, non-identifying analytics.
AI agents and automation. Our platform lets your AI agents carry out tasks you configure, such as answering questions, updating records, and routing conversations. This is automation you direct and control. AYBIZA does not make solely automated decisions that produce legal or similarly significant effects about you. Where an agent acts on your end-customers, you as controller are responsible for any automated-decision disclosures and human-review measures that apply to your use.
No training on your content. AYBIZA does not use customer content to train AI models, and the model providers we engage on the platform are contractually barred from training on it. When you bring your own API keys (BYOK), your data flows to the provider you chose under your own agreement with them, and that agreement — not this policy — governs how they may use it.
4. Legal Basis for Processing (GDPR)
For data subject to the EU GDPR or UK GDPR, we rely on:
- Contract performance (Article 6(1)(b)): processing account, KYB, and billing data to provide the services you contracted for.
- Legal obligation (Article 6(1)(c)): processing required for telecommunications law, carrier registration, sanctions screening, and financial regulation.
- Legitimate interests (Article 6(1)(f)): security monitoring, fraud prevention, and aggregated analytics, where not overridden by your rights. You may object at any time (see Section 9).
Customer content we process on your behalf is governed by the DPA; you as controller establish the lawful basis for your end-customers’ data. We do not rely on consent to process business customer data. Where consent is required, it is obtained separately and can be withdrawn at any time.
5. Cookies and Tracking
The marketing website uses only essential cookies and browser storage required for core functionality, CSRF protection, and security. We use no analytics cookies, no advertising cookies, and no cross-site tracking pixels. Public forms may use a human-verification service (Cloudflare Turnstile) that processes browser and device signals to tell human traffic from automated abuse; it is used for security, not advertising. Because we do not track you across other sites, we do not act on Do Not Track signals, which are designed to limit exactly that kind of cross-site tracking. You can manage cookies in your browser, though disabling essential cookies may break core functionality.
6. Sub-Processors and Sharing
We do not sell personal data, and we do not share it for cross-context behavioral advertising. To deliver the platform we engage vetted sub-processors for infrastructure, payments, telephony, AI and language models, speech processing, and web search, each under a data processing agreement. The current named list, with the role of each provider, is maintained in our DPA subprocessor schedule. When you use BYOK, the provider you chose is not an AYBIZA sub-processor; you control that relationship.
We may disclose data where required by law, valid court order, or regulatory demand, or to protect the rights, property, or safety of AYBIZA, our customers, or the public; where legally permitted, we notify you first. If AYBIZA is involved in a merger, acquisition, or asset sale, personal data may transfer as part of the transaction, and we will notify you of any change in ownership or use of your data.
7. International Data Transfers
AYBIZA hosts data in the United States on Amazon Web Services. Encrypted backup copies are held with a second cloud provider in the same jurisdiction as the data they protect, so backups introduce no additional cross-border transfer. For transfers from the EEA, United Kingdom, or Switzerland, we rely on the European Commission’s Standard Contractual Clauses (Module 2) and, for the UK, the ICO’s International Data Transfer Addendum; the mechanics and supplementary measures are set out in our DPA.
8. Data Retention
We keep personal data only as long as needed for the purpose it was collected, or as required by law. Where a window is configurable, your organization sets it.
| Data | Retention |
|---|---|
| Account data | Duration of your subscription, plus 30 days after closure for export, then deleted |
| Chat and text messages | 730 days by default; configurable from 30 days up to 10 years |
| Internal workspace messages | 730 days by default; configurable from 30 days up to 10 years |
| Call recordings | 90 days by default; configurable from 1 day up to 2 years. Deleted recordings are purged from storage after a 30-day grace period |
| Meeting transcripts | Follows your call retention setting |
| Call records, transcripts, and agent memory | Retained until you ask us to delete them, or until you close your account |
| Analytics and usage records | Retained until you ask us to delete them, or until you close your account |
| KYB, billing, and legal-acceptance records | 7 years |
| Support communications | 3 years from last contact |
| Audit and access logs | Retained for security and regulatory purposes, including support-access metadata recording who accessed data, what, and when — never the content itself. These records are not removed on request; the account they reference is anonymized instead |
When a retention period expires, data is permanently deleted or irreversibly anonymized. When you request erasure, we delete your account content, including support-channel messages, but retain the audit metadata above for security and regulatory reasons.
9. Your Rights
To exercise any right below, contact privacy@aybiza.com. We verify your identity, respond within 30 days (extendable by 60 days for complex requests, with notice), and do not charge for reasonable requests.
GDPR rights (EEA and UK). You may request access (Article 15), rectification (Article 16), erasure (Article 17), portability in a machine-readable format such as JSON or CSV (Article 20), restriction (Article 18), and objection to processing based on legitimate interests (Article 21). Where processing is based on consent, you may withdraw it at any time. You may lodge a complaint with your data protection authority; UK residents may contact the Information Commissioner’s Office at ico.org.uk.
CCPA/CPRA rights (California). You have the right to know what personal information we collect and why, to delete it (subject to legal exceptions), to correct it, and to non-discrimination for exercising these rights. AYBIZA does not sell personal information or share it for cross-context behavioral advertising, and does not use sensitive personal information beyond the purposes CCPA/CPRA permits. To submit a request, email privacy@aybiza.com with the subject “California Privacy Request.” You may use an authorized agent with written authorization.
Other US state privacy rights. Residents of states with comprehensive privacy laws have comparable rights to access, delete, correct, and obtain a portable copy of their personal data, to opt out of targeted advertising and profiling, and to appeal a declined request. AYBIZA does not conduct targeted advertising or profiling with legal effects, but you may still submit these requests. We honor the Global Privacy Control and other recognized universal opt-out signals as a valid opt-out of sale and targeted advertising.
End-customer requests. These rights cover data for which AYBIZA is the controller. If your end-customer asks about data we process on your behalf, they should contact you as their controller; we assist you in fulfilling valid requests as required by the DPA.
10. Voice and Biometric Data
When you enable voice, audio is processed by our speech sub-processors to run real-time conversations, and recordings are stored only when you turn on call recording. AYBIZA does not create voiceprints and does not use voice to uniquely identify any individual. Recordings are treated as ordinary audio, not as biometric identifiers. You are responsible for obtaining any recording consent the law requires in the jurisdictions you and your contacts are in. If you use a voice-cloning feature, you must have the written consent of the person whose voice is used.
11. Security
We apply technical and organizational safeguards appropriate to the risk, including encryption in transit and at rest, organization-level data isolation, least-privilege access controls, multi-factor authentication, and immutable audit logging. Our architecture is designed following the SOC 2 Trust Services Criteria; a third-party assessment is planned. Full details are at /security. To report a security vulnerability, email security@aybiza.com.
12. Children
AYBIZA is a business-to-business platform and is not directed to anyone under 18. Account registration requires verified business information. We do not knowingly collect personal data from individuals under 18, and any agent or widget you deploy must not target or be directed to children. If we learn we have collected data from someone under 18, we delete it promptly.
13. Contact and Changes
We may update this policy from time to time. We notify you of material changes by email to your registered work address at least 30 days before they take effect; minor changes such as formatting may be made without notice. The current version is always at /privacy, and the “Last updated” date reflects the latest revision. Continuing to use AYBIZA after a material change takes effect means you accept it; if you do not agree, you may close your account before the effective date.
Contact routing:
- Privacy and data-subject requests: privacy@aybiza.com
- EU and UK privacy inquiries: eu-privacy@aybiza.com
- Security and vulnerability reports: security@aybiza.com
- Legal notices: legal@aybiza.com
- General inquiries: info@aybiza.com
AYBIZA LLC, a Wyoming limited liability company. Business address: 32222 Tamina Rd Ste A5-11, The Woodlands, TX 77354. Registered agent: Registered Agents Inc, 30 N Gould St Ste R, Sheridan, WY 82801.