1. Who we are

AI Employee ("we", "us", "the Service") provides an AI assistant that business owners embed on their websites to answer visitor questions, book appointments, and capture enquiries.

The Service is operated by [LEGAL COMPANY NAME], registered at [REGISTERED ADDRESS]. You can reach us at [PRIVACY CONTACT EMAIL].

2. Controller and processor roles

This distinction matters because two different groups of people are involved:

If you are a website visitor and want your conversation or contact details deleted, contact the business you were chatting with. If they ask us, we will action it on their behalf.

3. Information we collect

We do not intentionally collect special category data (such as health, biometric, or financial account information). Please do not train your assistant on it, and configure your assistant not to request it.

Payments

Card details are never sent to or stored on our servers. Payments are handled by our payment provider, [PAYMENT PROVIDER], under their own privacy policy.

4. How we use information

We do not sell personal data, and we do not use your business knowledge or your visitors' conversations to train foundation models for anyone else.

6. Sharing and sub-processors

We share data only with providers needed to run the Service:

If an AI language model provider is enabled for your account, conversation content is sent to that provider to generate a reply. If no model provider is configured, replies are generated on our own servers from your trained knowledge and no conversation content leaves our infrastructure.

We may also disclose data where required by law, or as part of a merger or acquisition — in which case we will notify you before your data becomes subject to a different policy.

7. Data retention

8. Your rights

Depending on where you live, you may have the right to:

To exercise any of these, email [PRIVACY CONTACT EMAIL]. We respond within [30] days. We may ask you to verify your identity first.

9. Security

Passwords are stored using a one-way hash, never in plain text. Sessions use random tokens. Traffic is served over HTTPS in production, and API credentials are held in server-side environment variables that are never exposed to the browser. See our Security page for detail.

No system is perfectly secure. If we become aware of a breach affecting your personal data, we will notify affected users and the relevant authority as required by law.

10. Children

The Service is intended for businesses and is not directed at children under 16. We do not knowingly collect their data. If you believe a child has provided us personal data, contact us and we will delete it.

11. Changes to this policy

We may update this policy as the Service evolves. We will change the "last updated" date above, and for material changes we will notify account holders by email before the change takes effect.

12. Contact us

Questions about this policy or your data:
[LEGAL COMPANY NAME]
[REGISTERED ADDRESS]
[PRIVACY CONTACT EMAIL]