Privacy policy

Last updated: 19 August 2026. This policy is provided in English and German; the English version prevails.

1. Who we are

The visibleIT Agent Platform ("the platform", "we", "us", "our") is operated by two affiliated companies. The company that invoices you is the controller of your data.

visibleIT GmbH
Controller for EU, UK, EEA and Switzerland customers.
Hunoldstr. 13, 34479 Breuna, Germany.
Phone: +49 5641 929910-0 · USt-IdNr. DE355602586
Email: info@visible-it.de
visibleIT Inc.
Controller for United States and Rest-of-World customers.
12625 Caballo Ct, Estero, FL 33928, USA.
Florida profit corporation, incorporated 26 May 2026, effective 1 June 2026 · EIN 42-2877813
Email: info@visible-it.io

visibleIT GmbH and visibleIT Inc. are affiliated companies. They share platform infrastructure under an intra-group data-transfer agreement that uses the European Commission's Standard Contractual Clauses. Where staff in one company access data of customers contracted with the other, the transfer is governed by that agreement.

Data protection contact. Responsibility for data protection within each company is held by its Managing Director. To exercise any of your rights or ask a privacy question, write to the address above for the company that invoices you.

2. What this policy covers

How we handle personal data when:

  • you visit our website,
  • you sign up for an account,
  • you configure and run AI agents on the platform,
  • people interact with your AI agents (callers, email senders, web-chat users).

We do not sell your personal data. We do not "share" it for behavioural advertising as defined by the California Consumer Privacy Act. We never use the conversations your agents handle to train AI models for other customers.

3. What we collect

You — when you sign up and use the platform

  • Account details: first name, last name, email, hashed password (or passkey credential id), and your authenticator-app secret if you enable that second factor.
  • Organisation details: company name, legal name, country, full billing address, VAT or tax ID, billing email and phone.
  • Sign-in metadata: IP address, browser user agent, sign-in timestamps. Used to detect account takeover and throttle abuse.
  • Things you configure: agent name and system prompt, voice and language choices, routing categories, knowledge documents you upload, attachments, webhooks, custom connector definitions, allow-listed phone numbers and email addresses.
  • Things you ask the in-product help assistant. Stored for your own history (last 20 questions) and, without your identity attached, used in aggregate to spot gaps in the documentation.

Your end users — when they interact with your agents

  • Voice agents: caller's phone number, the call's audio and transcript, structured fields the agent extracted (e.g. an appointment time, a name they gave), call outcome. The audio is recorded only while the call runs and only to produce an accurate written transcript; once the transcript is made, the recording is deleted. We do not keep call recordings.
  • Email agents: the email message, the agent's draft or sent reply, classification result, calendar booking made on your behalf.
  • Web chat: chat transcript and the visitor's IP for rate-limiting and abuse defence.

You are the controller of your end users' personal data; we are the processor. Our Data Processing Agreement covers that relationship — it is accepted when an organisation is created, and we can provide a signed copy or agree a negotiated one on request.

Connected systems you opt into

When you connect your own Microsoft 365 mailbox or calendar (and, later, Google Workspace), the platform reads only what's needed to do the agent's job: incoming mail, free / busy times, and the ability to create events or send replies on your behalf. We never read mail unrelated to the agent's task. You can disconnect at any time; we then delete the OAuth tokens and stop receiving any further data from those systems.

Payments

Card details are handled directly by Stripe. We never see or store full card numbers. We receive only the last four digits, card brand, and a customer ID that lets us look up your subscription.

Cookies and similar storage

We use a small number of essential browser-local items only:

  • A session cookie set by our authentication provider so you stay signed in.
  • Browser localStorage entries for your theme preference, your most recent commands, and a flag remembering that you've seen the cookie notice.

We do not run analytics that profile you, marketing trackers, or third-party cookies. If we ever add analytics it will be self-hosted, anonymised, and disclosed here first.

4. Why we process your data — and our legal basis (GDPR)

Run the platform you signed up for
Contract (Art. 6(1)(b) GDPR)
Bill you, send invoices, recover failed payments
Contract + legal obligation (Art. 6(1)(b), (c))
Keep accounting records for the statutory period
Legal obligation (Art. 6(1)(c))
Run conversations and drafts through AI models on your behalf
Contract
Detect abuse, throttle bots, block credential-stuffing
Legitimate interest (Art. 6(1)(f))
Send transactional emails about your account (security, billing)
Contract
Improve documentation from aggregate help-assistant usage
Legitimate interest
Respond to your rights requests
Legal obligation

We do not deliberately process special-category data (Art. 9 GDPR). If your knowledge base or your agents' transcripts happen to contain such data — for example, a caller volunteers health information — it is processed only as needed to deliver the service.

5. Who we share your data with

We share only what is necessary, only with the providers we need to run the platform. None of these providers may use your data for their own purposes.

Google Ireland Limited / Google LLC
Cloud infrastructure — hosting, databases, authentication, file storage, scheduling and logging — together with speech-to-text and the AI models behind our voice, email and analysis features. Processing takes place in the European Union; individual AI features may be served from the provider's global infrastructure. Certified under the EU-US Data Privacy Framework.
cloud.google.com/terms/cloud-privacy-notice · policies.google.com/privacy
Twilio Ireland Limited
Telephone numbers and call connectivity for voice agents.
twilio.com/legal/privacy
ActiveCampaign, LLC (Postmark)
Sending and receiving email for the platform and for agents' mailboxes. Certified under the EU-US Data Privacy Framework.
postmarkapp.com/eu-privacy · postmarkapp.com/privacy-policy
Cloudflare, Inc.
Protection and delivery of our public website. Only public marketing pages pass through it.
cloudflare.com/privacypolicy
Stripe Payments Europe Limited
Card payments and invoicing for customers contracted with visibleIT GmbH.
stripe.com/privacy
Stripe, Inc.
Card payments and invoicing for customers contracted with visibleIT Inc.
stripe.com/privacy

Customer-initiated integrations. When you connect your own Microsoft 365 (and, later, Google Workspace), data flows between the platform and that provider under your existing contract with them. Their privacy practices govern that processing, not ours:

We may also share information if compelled by law, court order, or to protect the rights and safety of users — but only the minimum required, and we notify you where the law allows.

Sub-processor changes. Before we add or replace a sub-processor that handles personal data, we give customers at least 30 days' advance notice by email or via the platform. If you reasonably object on data-protection grounds, we work with you to find an alternative; if no alternative is workable you may terminate the affected service without penalty.

Google Workspace data — Limited Use

Our use of information received from Google Workspace APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Concretely: calendar and mailbox data reached through those APIs is used only to provide the features you switched on — checking availability, booking, changing and cancelling appointments, and preparing email drafts for a person to review. It is never used, transferred or sold to create, train or improve any generalised or foundational AI model, ours or anyone else's. The AI models we use are operated by Google (Vertex AI and the Gemini API on paid terms), which contractually do not train on the content we send them; we transfer Workspace data to no other AI provider.

6. International transfers

If you are based in the European Economic Area, the United Kingdom, or Switzerland and your data leaves that area (for example because an AI feature is served from outside that area, or because visibleIT Inc. staff access it for support), we use:

  • the European Commission's Standard Contractual Clauses, in the modules appropriate to the role of each party; and
  • the EU-US Data Privacy Framework where the recipient is certified — currently Google, Stripe Inc., Postmark and Cloudflare.

We complete a transfer impact assessment before relying on these mechanisms and keep it under review.

7. How long we keep your data

Unless you change the setting per agent or your plan shortens the window, the platform's default retention is 365 days for conversation transcripts, email content and drafts, sales-CRM analyser output, and activity logs. Some categories have their own rules:

Account profile (name, email, role)
While you have an active account, plus a short grace period after closure for support.
Organisation profile (legal name, address, VAT)
While the organisation is active, then for the statutory retention of the related invoice.
Conversation transcripts, email content and drafts, sales-CRM output, activity logs
365 days by default, unless you set a shorter window per agent.
Help-assistant question log
90 days raw; aggregate clusters retained for product improvement.
Compliance log + operator action log
Append-only for the statutory retention period.
Stripe invoice records
10 years (German commercial and tax law).
Soft-deleted organisations
90-day grace period; then permanent deletion.
Unmasked working copy of a conversation (only when transcript masking is switched on for an agent)
Deleted as soon as the after-call steps finish, and in every case within 2 days. Not readable from the app.
Temporary call recording (voice agents)
Deleted as soon as the transcript has been produced, and in every case within 1 day. Kept only to make the transcript accurate; not readable from the app and never used for anything else.

Once a retention window closes we delete or anonymise the data, except where law requires us to keep it longer (e.g. tax records).

A note on masking: where you switch on transcript masking for an agent, the stored conversation hides phone numbers, email addresses and long numbers. The after-call steps that need the real values — saving a lead, sending a follow-up, creating a ticket — run first, on a short-lived unmasked working copy that is then deleted. Masking controls what is kept, not what the agent can do during or straight after the conversation.

8. Your rights

Wherever the law gives you these rights — under GDPR, UK GDPR, the Swiss FADP, the California Consumer Privacy Act and similar laws — you can:

  • ask what we hold about you and get a copy (right of access);
  • correct anything that's wrong (rectification);
  • ask us to delete it (erasure), subject to legal retention;
  • limit how we process it (restriction);
  • receive it in a portable format (data portability);
  • object to processing based on legitimate interest;
  • withdraw consent at any time, for anything we process on that basis;
  • complain to a supervisory authority. For German customers, that is typically the Hessischer Beauftragte für Datenschutz und Informationsfreiheit (HBDI).

To exercise any right, write to the email shown for your controller at the top of this page. We may need to verify your identity to protect your data.

9. Data of your end users

When someone calls, emails or chats with an agent you have set up:

  • You are the controller of that person's personal data; we are the processor.
  • You are responsible for telling them, at the start of the interaction, that they are interacting with an AI — as required by your local law and the EU AI Act.
  • You are also responsible for telling them that the conversation will be recorded (where applicable), transcribed and stored on the platform, and for how long, based on the retention you have configured per agent. This transparency duty applies in every jurisdiction — including ones that do not require all-party consent to record — because it is a separate obligation under GDPR Art. 13, the EU AI Act, and equivalent rules elsewhere.
  • When they ask what is collected and want to exercise their rights, you handle the request and we'll provide the technical support to help you fulfil it.

Our Data Processing Agreement sets out the detail — including what we process, the security measures, the approved sub-processors, and how we help you answer your end users' requests.

Managed / professional services. The plans are self-service, but if you engage our optional done-for-you setup or ongoing management (see the Terms §2), authorised visibleIT staff access your workspace on your instructions to configure and maintain your agents. That access is limited to what the agreed work requires, is logged, and is subject to the same confidentiality and security obligations as the rest of the platform. We remain your processor and do not use your data for any purpose beyond the work you asked for.

Call recording and consent. Voice agents process the audio of incoming calls in real time. Where you operate in a jurisdiction that requires the consent of every party to a call before it is recorded or transcribed — including California, Florida, Illinois, Maryland, Massachusetts, Montana, New Hampshire, Pennsylvania and Washington in the United States, and many EU member states — you are responsible for obtaining that consent before the call begins. Our recommended pattern is a short opening announcement by the agent. We support this with the agent's greeting feature.

10. Automated decision-making and the right to a human

The AI agents you configure on the platform do not, on their own, take decisions that produce legal effects or similarly significant effects on a person within the meaning of Art. 22 GDPR. If you configure an agent to make such a decision — for example, automatically denying service based on a credit or fraud signal — you are responsible for providing the safeguards Art. 22 requires (meaningful human involvement on request, the right to express a point of view, the right to contest the decision).

Where you operate a voice agent, we recommend offering a clear way for the caller to ask for a human (for example, the agent's forwarding rules). Where you operate an email agent, the same applies — a reply path that reaches a person.

We comply with applicable transparency obligations under the EU AI Act for AI systems that interact with natural persons. You are responsible for telling your end users that they are interacting with an AI; see section 9.

11. Security

We treat security as a continuous engineering practice, not a checkbox.

  • All traffic is encrypted in transit (TLS 1.2 or higher).
  • Data at rest is encrypted using our infrastructure provider's built-in encryption.
  • Sign-in supports passkeys (WebAuthn) and authenticator-app codes. Operator-level access requires a passkey.
  • Tenant isolation is enforced by the platform — one organisation cannot read or write another organisation's data.
  • Secrets (API keys, OAuth refresh tokens) are held in a dedicated secrets manager, not in the database.
  • Every state-changing action by our operators is logged with a reason and is auditable.
  • We never reuse customer conversations to train AI models for other customers.
  • No voiceprints, no biometric identifiers. We do not extract, generate or store voiceprints, faceprints or any other biometric identifier from your end users' audio, and we do not use audio to recognise the same person across calls. Our underlying infrastructure providers inherit the same instruction.
  • Contact details are masked in stored transcripts by default — phone numbers, email addresses and long numbers are replaced with markers in the saved conversation. The after-call steps that need the real values run first, on a short-lived unmasked working copy that is then deleted and is never readable from the application.

No system is unbreakable. If we ever suffer a personal-data breach we will notify the relevant supervisory authority within 72 hours where required, and notify affected customers without undue delay.

12. Children

The platform is built for businesses. We do not knowingly collect personal data from anyone under the age of 16 (under 13 where US law applies). If you believe a minor has signed up, write to us and we will close the account.

13. Changes to this policy

We may update this policy from time to time. Material changes will be announced via email or a notice in the platform at least 30 days before they take effect. Older versions remain available on request.

14. Contact

Write to info@visible-it.de if you are a visibleIT GmbH customer or info@visible-it.io if you are a visibleIT Inc. customer. Postal addresses are at the top of this page.