Privacy Policy

Last Updated: September 1, 2026

Effective Date: September 1, 2026

Table of Contents:

  1. 1. Introduction and Scope
  2. 2. Two Roles: When We Are a Controller and When We Are a Processor
  3. 3. Definitions
  4. 4. Personal Data We Collect as a Controller
  5. 5. Personal Data End Users Provide Directly
  6. 6. Data from Connected Messaging and Social Platforms
  7. 7. Voice Calls and Call Recordings
  8. 8. How We Use Personal Data
  9. 9. Sensitive Personal Information
  10. 10. Legal Bases for Processing
  11. 11. AI Features and Personal Data
  12. 12. Cookies and Tracking Technologies
  13. 13. How We Share Personal Data
  14. 14. Enterprise and Organizational Use
  15. 15. Subprocessors
  16. 16. International Data Transfers
  17. 17. Data Retention
  18. 18. Data Security
  19. 19. Your Privacy Rights
  20. 20. California and U.S. State Privacy Disclosures
  21. 21. Children's Privacy
  22. 22. Changes to This Privacy Policy
  23. 23. Contact Us

1. Introduction and Scope

1.1. About This Privacy Policy

This Privacy Policy explains how Pleased Inc. collects, uses, shares, and protects personal data in connection with the Platform, the Services, and our website. Pleased, we, us, and our have the meaning given to Company in the Terms of Service. Customer, Authorized User, Agent, End User, Platform, and Services also have the meanings given to them in the Terms of Service.

1.2. Who This Applies To

This Privacy Policy applies to personal data we collect from visitors to our website, from Customer and its Authorized Users, and to personal data we process on behalf of Customer in providing the Services, including data relating to End Users. Section 2 explains the differences between these categories and how they affect your rights and our obligations.

1.3. Relationship to Our Other Documents

This Privacy Policy works together with the Terms of Service and the Data Processing Agreement. The Terms of Service govern the contractual relationship between Pleased and Customer, including acceptable use, intellectual property, and liability. The Data Processing Agreement governs the specific obligations that apply when Pleased processes personal data on Customer's behalf as a processor. This Privacy Policy focuses on what personal data we collect, why we collect it, and the rights available to individuals.

1.4. Where We Operate

Pleased is a Delaware corporation based in the United States. Our infrastructure and personnel are located in multiple countries, and Section 14 explains how we handle personal data that is processed or accessed outside the United States.

1.5. Updates to This Privacy Policy

We may update this Privacy Policy from time to time, as described in Section 20, which explains how we handle changes to our privacy practices.

2. Two Roles: When We Are a Controller and When We Are a Processor

2.1. Why This Distinction Matters

Depending on the type of personal data involved, Pleased acts either as a controller, meaning we decide why and how that data is processed, or as a processor, meaning we process the data on Customer's behalf to provide the Services. This distinction determines who you should contact with a request, and which document, this Privacy Policy or the Data Processing Agreement, governs the details of that processing.

2.2. When We Act as a Controller

We act as a controller for personal data relating to visitors to our website and for Account Data, meaning information about Customer's representatives and Authorized Users that we collect to operate their Account, communicate with them, and provide the Services. Sections 3 and 11 describe this data in more detail.

2.3. When We Act as a Processor

We act as a processor for End User Data, meaning personal data about Customer's own customers and contacts that flows through the Services, for example, through live chat, voice calls, email, or connected messaging channels. In this role, Customer is the controller, and we process End User Data to provide, secure, and support the Services, in accordance with Customer's instructions and the terms of the Data Processing Agreement. Sections 4 through 6 describe End User Data by channel.

2.4. Contacting Us About End User Data

If you are an End User and have a question about how your personal data is handled, you should first contact the Customer whose Services you interacted with, since Customer controls that data and is primarily responsible for responding to your request. We will support Customer in responding to your request as required under the Data Processing Agreement. If you are unable to reach Customer or do not receive a response, you may contact us at the address in Section 21, and we will take reasonable steps to assist.

2.5. Records That Combine Both Categories

Some records we generate while providing the Services may contain both Account Data and End User Data together, for example a call log that includes both an Agent identifier and an End User's phone number. In these cases, each element of the record is treated according to its own category, Account Data elements under Section 2.2, and End User Data elements under Section 2.3, rather than treating the entire record as one category.

2.6. If We Ever Use End User Data for Our Own Purposes

If we use End User Data for a purpose of our own, rather than solely to provide the Services to Customer, for example to improve or train our own systems, we act as a controller for that specific use, separately from our processor role described in Section 2.3. Section 10 explains our current practice regarding the use of data in connection with AI Features.

3. Definitions

Terms Defined in the Terms of Service. Capitalized terms used in this Privacy Policy that are not defined below have the meanings given to them in the Terms of Service, including Customer, Authorized User, Agent, End User, Platform, Services, Content, Brand, AI Features, and AI Output.

Personal Data means any information relating to an identified or identifiable individual.

Account Data means personal data about Customer's representatives and Authorized Users that we collect to operate their Account, as described in Section 4.

End User Data means personal data about Customer's own End Users that flows through the Services, as described in Sections 5 through 7.

Website Visitor Data means personal data we collect from visitors to our website, as described in Section 12.

Sensitive Personal Information has the meaning given in Section 9.

Controller and Processor. In this Privacy Policy, controller means the party that determines the purposes and means of processing personal data, and processor means the party that processes personal data on behalf of, and following the instructions of, a controller. Section 2 explains when each role applies to us.

Knowledge Base means the collection of articles, documents, and other reference materials that Customer maintains within the Services to support its support operations, including content used by AI Features as described in Section 10.

4. Personal Data We Collect as a Controller

4.1. Registration Information

When an Authorized User registers for an Account, we collect their name and work email address.

4.2. Google Sign-In Information

If an Authorized User signs in using Google, we receive their Google account identifier, email address, email verification status, first and last name, profile picture, and the domain associated with their Google Workspace account, where applicable.

4.3. Custom Agent Information

Customer administrators can add custom fields containing additional information about their Agents. Any personal data added this way is collected and stored as part of the Account.

4.4. Billing Information

We collect billing-related information as part of your Account, including the identity information described in Section 3.1. Payment card details are handled directly by Stripe and are not stored by us, as described in Section 12.

4.5. Communications With You

When you contact us directly, for example to ask a question about your Account or these Services, we collect the information you provide in that communication.

4.6. Website Visitors

Section 11 explains what information we collect from visitors to our website, including through cookies and similar technologies.

5. Personal Data End Users Provide Directly

5.1. Live Chat

When an End User uses live chat, we process their name, email address, phone number, and any profile image they provide, along with any custom fields Customer has configured. We also process technical session data, including IP address and browser information, any files the End User attaches, and, where provided, a satisfaction rating and written feedback about the conversation. While a chat is active, presence and typing status are processed in real time. Where Customer has enabled AI Features for live chat, this data may also be processed by an AI Feature, as described in Section 10.

5.2. Email and Tickets

When an End User contacts Customer by email, we process the sender and recipient email addresses, the subject line, the message content, email headers, the sender's IP address, and any attachments. This data is stored as a ticket, and the message content becomes part of that ticket's record.

5.3. Web Forms

Every web form includes three fields at minimum, the End User's email address, a description, and an optional attachment. Customer can configure additional fields to collect further information, so the exact data collected through a specific web form depends on how Customer has set it up.

5.4. File Attachments

Section 5.3 of the Terms of Service describes the file types and size limits that currently apply to attachments submitted through these channels.

5.5. Free Text Content

The message content, descriptions, and feedback described in this Section are provided by End Users in free text form and may occasionally include sensitive personal information. Section 8 explains how we handle this.

6. Data from Connected Messaging and Social Platforms

6.1. What This Section Covers

When Customer connects the Services to a third party messaging or social platform, we receive certain information about End Users directly from that platform, separate from what End Users provide directly through Pleased as described in Section 4.

6.2. Telegram

We receive the End User's Telegram user identifier and username.

6.3. X

We receive the End User's X user identifier and username, along with public profile information such as their profile picture, verification status, follower count, and post count. This public profile information reflects what the End User has made visible on X itself, rather than information provided specifically to Customer. We also receive the content of direct messages and mentions directed at Customer.

6.4. WhatsApp

We receive the End User's phone number, Customer's connected WhatsApp business phone number, and the text and media content of messages.

6.5. App Store Reviews

We receive the reviewer's nickname, the content and rating of their review, and their territory.

6.6. Facebook

We receive a page scoped user identifier and the content of messages and comments directed at Customer's page.

6.7. Google Play

This integration is not currently implemented.

6.8. What We Send Back

We send Agent reply text and attachments back to each connected platform, so the End User receives Customer's response through the same channel they used to reach out.

6.9. Free Text Content

Message content received through these platforms, including direct messages, mentions, comments, and review text, may occasionally include sensitive personal information. Section 8 explains how we handle this.

7. Voice Calls and Call Recordings

7.1. What We Collect

When a call is made or received through the Services, we process the phone numbers of both parties, the call duration, call status, and technical identifiers used to route and manage the call. Where the End User leaves a description of their inquiry, we process that as well. Recording is enabled automatically for all calls made through the Services. A call record may contain both End User Data and Account Data together, and Section 2.5 explains how we treat records of this kind.

7.2. Call Recordings

Calls made through the Services are recorded automatically. The recording is initially processed through our voice provider and then stored on our own infrastructure, as described in Section 12. In rare cases where this transfer does not complete successfully, the recording may remain accessible through our voice provider rather than our own infrastructure. We retain a technical record of the recording's status and duration alongside the call itself.

7.3. Notice to Callers

Callers are notified that the call may be recorded through an automated voice prompt at the start of the call. This notice is provided automatically and does not depend on any action by Customer.

Recording is enabled by default for all calls made through the Services, and the recording itself is initiated and stored by Pleased, not by Customer. Because of this, Pleased provides the notice described in Section 7.3 as a baseline measure. Customer remains responsible for any additional consent required by applicable law beyond that baseline notice, including laws that require the express consent of all parties to a call before it is recorded.

7.5. Disabling Recording

If Customer needs call recording disabled for its account, Customer can request this by contacting our support team, and we will disable recording for that account.

7.6. Multi-Brand Routing

Where Customer operates multiple Brands, caller and called numbers are associated with the relevant Brand's phone configuration to route calls correctly.

7.7. AI Voice Features

If Customer enables an AI Feature for voice calls, call data described in this Section may also be processed by that AI Feature, as described in Section 11.

7.8. Free Text Content

The description an End User provides when calling, and the content of the call itself, may occasionally include sensitive personal information. Section 8 explains how we handle this.

8. How We Use Personal Data

8.1. Account Data

We use Account Data to operate your Account, communicate with you, process billing, provide customer support, and maintain the security of the Platform. Technical data such as IP addresses supports rate limiting and account verification, helping us prevent abuse of the Services. Where a conversation is handed off from an AI Feature to an Agent, we log that handoff. This log may contain both Account Data and End User Data together, and Section 2.5 explains how we treat records of this kind. Section 10 explains more about how AI Features process data.

8.2. End User Data

We use End User Data solely to provide, secure, and support the Services to Customer, in accordance with Customer's instructions and the Data Processing Agreement, as described in Section 2.3. Our support and engineering personnel access a specific Customer workspace only when responding to an escalation involving degraded platform or feature performance.

8.3. Website Visitor Data

We use information collected from website visitors to operate and improve our website, and for analytics purposes, as described in Section 11.

8.4. Internal Analytics

We use internal tools to analyze how the Platform is used, which may involve access to Account Data or End User Data as part of that analysis, as described in Section 12.

9. Sensitive Personal Information

9.1. What This Section Covers

Sensitive personal information includes categories such as health information, religious beliefs, racial or ethnic origin, sexual orientation, citizenship or immigration status, precise geolocation, biometric data, and government identifiers, along with similar categories that receive heightened protection under applicable law.

9.2. How This May Appear

We do not intentionally collect sensitive personal information. Because End Users communicate with Customer in free text through channels described in Sections 4, 5, and 6, sensitive personal information may occasionally appear in that content without us seeking it out.

9.3. How We Handle It

Where sensitive personal information appears in End User Data, we process it only as part of providing the Services to Customer, following Customer's instructions, in the same way we handle other End User Data described in Section 2.3. We do not use sensitive personal information for any purpose beyond providing the Services. Internal tools described in Section 13.6 have broad access to Customer Data as part of their function, and this may include sensitive personal information where it is present, though these tools are not designed to specifically target or single out that category of data.

9.4. Customer's Responsibility

Customer is responsible for ensuring that its use of the Services, including any collection of sensitive personal information from End Users, complies with applicable law.

9.5. Future PII Features

We plan to introduce features that help identify and manage personal information, including sensitive personal information, within the Platform. Section 22 explains how we will notify you of material changes to this Privacy Policy, including changes related to these features.

9.6. Voice AI Risk

Voice AI Features in particular carry a higher risk in this respect, since live voice audio may reach our AI provider before any redaction takes place, as described in Section 11.2.

10.1. Our Approach

We currently operate under United States law and describe our purposes for processing personal data in Section 8. Unlike some other legal frameworks, United States privacy and consumer protection law generally does not require us to identify a separate, named legal basis for each processing activity. Having a legitimate business purpose for processing, as described throughout this Privacy Policy, is sufficient under the law that currently applies to us.

10.2. If We Expand to Markets That Require This Framework

If we begin to target customers in the European Union, the European Economic Area, or the United Kingdom, we will identify the specific legal basis, such as consent, contract, or legitimate interest, that applies to each category of processing described in this Privacy Policy, consistent with the General Data Protection Regulation.

11. AI Features and Personal Data

11.1. AI Providers

AI Features are powered by third party providers, including OpenAI and AWS Bedrock, as described in Section 13.

11.2. What We Send to OpenAI

Where needed to answer a request, we send OpenAI customer messages or live voice audio, relevant conversation context, relevant Knowledge Base content, and case data. Live voice audio may reach OpenAI before any redaction takes place.

11.3. OpenAI Retention

OpenAI does not use this data to train its models. Zero Data Retention is not currently enabled for our use of OpenAI, and OpenAI may retain content for abuse monitoring purposes for up to 30 days.

11.4. What We Send to AWS Bedrock

Text based AI Features may send search queries and relevant Knowledge Base content to AWS Bedrock to rerank results or generate a response. Voice AI Features do not use Bedrock, and we do not send voice audio or stored vectors to it. Bedrock invocation logging is not enabled, so we do not retain Bedrock prompts or responses through that mechanism. Data sent to Bedrock is not used to train models and is not shared with model providers.

11.5. Knowledge Base and Embeddings

Knowledge Base content and the embeddings generated from it are stored in AWS OpenSearch, separated by Customer and by Brand. Deleting Knowledge Base content does not automatically delete the related embeddings.

11.6. Voice AI Recordings

Where a Voice AI Feature is used, recordings and transcripts are stored in AWS S3. There is currently no automatic deletion schedule for this data, and it remains until deleted manually.

We do not use Customer Data, prompts, outputs, or Knowledge Base content to improve or train our own AI systems, or those of any third party AI provider, without explicit consent, consistent with Section 6.8 of the Terms of Service.

11.8. Automated Decision-Making

AI Features can generate responses to End Users without human review, as described in Section 6.2 of the Terms of Service. We do not currently use AI Features to make decisions that produce legal or similarly significant effects for End Users.

12. Cookies and Tracking Technologies

12.1. Overview

We use cookies and similar technologies on our website and within the Platform. This Section provides an overview, and our Cookie Policy provides full details, including how to manage your preferences.

12.2. Our Website

Our website uses session storage to track signup timing, and cookies placed by Stripe on our payment page to process payments. We do not set first party cookies through our own code.

12.3. Session Recording

We use ContentSquare, a third party analytics provider, on our website and within parts of the Platform, including tenant consoles, though we are in the process of removing it as part of a transition to a new analytics setup. On our website, our Cookie Policy explains how consent is managed for this technology.

12.4. The Platform

Once you are signed in, the Platform uses cookies and similar technologies necessary for it to function, including an authentication token that expires after 9 hours, identifiers that associate your session with your Brand and Account, and technical parameters used during Google sign in.

12.5. Your Choices

Our Cookie Policy explains what choices are available to you regarding cookies and similar technologies, including any technologies that require your consent under applicable law.

13. How We Share Personal Data

13.1. Overview

We share personal data with the categories of third parties described in this Section, consistent with Section 17 of the Terms of Service, which describes these providers in the context of delivering the Services.

13.2. Infrastructure Providers

We use Amazon Web Services for our core cloud infrastructure, Google Firebase to support real time chat functionality, and Cloudflare for domain name services.

13.3. Communication Providers

We use Twilio to support voice calls and WhatsApp messaging, and SendGrid to support email delivery.

13.4. Payment Provider

We use Stripe to process subscription payments and manage billing.

13.5. AI Providers

We use OpenAI and AWS Bedrock to power AI Features, as described in Section 11.

13.6. Internal Tools

We use tools such as Slack, Metabase, Jaeger, and GlitchTip to support our own internal operations, including notifications, analytics, error tracking, and system monitoring.

13.7. Connected Channels

Where Customer connects the Services to a channel such as WhatsApp, Telegram, X, Facebook, or the App Store, that channel's provider is also involved in delivering messages between Customer and its End Users, as described in Section 6.

We may disclose personal data where required by law, court order, or governmental authority, where necessary to establish, exercise, or defend legal claims, or where necessary to protect the rights, property, or safety of Pleased, our Customers, or others.

13.9. Business Transfers

If we are involved in a merger, acquisition, or sale of assets, personal data may be transferred as part of that transaction, subject to this Privacy Policy or a successor policy.

13.10. Third Party Responsibility

We are not responsible for the privacy practices of third parties beyond what we instruct them to do in connection with the Services, consistent with Section 13.6 of the Terms of Service.

14. Enterprise and Organizational Use

14.1. Enterprise Customers

Where Customer accesses the Services under a negotiated Order Form, Enterprise Subscription Agreement, or Master Services Agreement, additional or different terms governing the processing of personal data may apply, as set out in those agreements or in a separately negotiated Data Processing Agreement.

14.2. Order of Precedence

Where a negotiated agreement described in Section 14.1 conflicts with this Privacy Policy, that agreement controls with respect to the specific processing activities it covers, consistent with the Document Hierarchy described in Section 1.4 of the Terms of Service.

14.3. Isolated Infrastructure

Some Enterprise Customers are provided with isolated infrastructure separate from other Customers, as described in the Terms of Service. This Privacy Policy continues to apply to personal data processed within that infrastructure, except where a negotiated agreement expressly provides otherwise.

14.4. Administrator Controls

Where Customer's administrators configure roles, permissions, retention settings, or other account-level controls, those configurations are made by Customer, not by us, and Customer is responsible for their use in accordance with its own obligations to its Authorized Users and End Users.

15. Subprocessors

15.1. What Subprocessors Are

Where we process End User Data as a processor, as described in Section 2.3, we may engage other companies, called subprocessors, to help us provide the Services. Subprocessors process End User Data only to the extent necessary to perform the function they have been engaged for.

15.2. Our Subprocessors

The infrastructure, communication, and AI providers described in Section 13 act as subprocessors to the extent they process End User Data on our behalf, under our instructions. Some providers, such as Stripe when processing billing information, act as independent controllers of the data they receive, subject to their own privacy practices, rather than as our subprocessors. Internal tools described in Section 13.6 support our own operations and are not subprocessors, since they do not provide the Services to Customer directly.

15.3. Contractual Protections

We have data processing agreements in place with our subprocessors that require them to protect End User Data consistent with our own obligations to Customer.

15.4. Changes to Subprocessors

Where we add or replace a subprocessor, the Data Processing Agreement governs how we notify Customer and, where applicable, any right Customer has to object.

15.5. Full List

The complete, current list of subprocessors is maintained in the Data Processing Agreement, which Customer receives as part of its agreement with us. We do not publish a separate public list of subprocessors on our website.

16. International Data Transfers

16.1. Overview

Personal data processed through the Services may be stored in, or accessed from, countries other than the country where you or your End Users are located. This Section explains how and why that happens.

16.2. Where Our Infrastructure Is Located

Our core production infrastructure, including our primary databases, is located in Germany, within the AWS eu-central-1 region, as described in Section 13. This means personal data we process is physically stored on servers in Germany as part of our normal operations, regardless of where you or your End Users are located.

16.3. Access by Our Personnel and Contractors

Separately from where data is stored, our employees and contractors access personal data from multiple countries as part of providing the Services, including the United States, Germany, Spain, the United Kingdom, Turkey, North Macedonia, India, and the Philippines.

16.4. Why This Does Not Currently Require Additional Measures

Certain data protection laws, including the GDPR, generally apply based on whether a company targets individuals located in a particular jurisdiction, rather than based solely on where infrastructure is physically located or where personnel are based. We are a Delaware corporation and do not currently target customers or individuals in the European Union, the European Economic Area, or the United Kingdom. We will implement transfer mechanisms such as Standard Contractual Clauses, a UK International Data Transfer Addendum, or a representative under Article 27 of the GDPR where required by applicable law or where agreed with a Customer.

16.5. If You Are Located in the European Union, the European Economic Area, or the United Kingdom

We do not target the Services to individuals in these regions. If you access or use the Services from one of these regions despite this, you acknowledge that the Services are provided by a United States company, that your data will be processed as described in this Section, and that you may be asked to confirm this understanding as part of using the Services, consistent with Section 19.5 of the Terms of Service.

16.6. If Our Approach Changes

If we begin to target customers in the European Union, the European Economic Area, or the United Kingdom, or where otherwise required by law or by agreement with a Customer, we will implement the compliance and transfer mechanisms applicable at that time. We will update this Section when that occurs.

17. Data Retention

17.1. Our Current Approach

We do not currently have a single, formal data retention policy that applies uniformly across all categories of personal data. In practice, most personal data is retained until a deletion request is made or an Account is terminated, rather than being deleted automatically after a fixed period. Where we describe data as archived below, this means it is moved to separate storage but not deleted, archiving and deletion are different processes.

17.2. Where Specific Retention Periods Apply

Some categories of data do follow a defined schedule. Application and security logs are retained for 90 days in production. Backup copies of our production database are retained for 7 days. Closed tickets and conversations are archived after 90 days, and closed AI chats after 2 days.

17.3. Categories Without a Defined Period

Call recordings, file attachments, and backup copies other than those described in Section 17.2 do not currently have an automatic deletion schedule and are retained indefinitely unless deleted upon request.

17.4. Deletion Upon Request

You can request deletion of data through the process described in Section 18. Deletion currently requires contacting our support team, as described in Section 6.10 of the Terms of Service. Where your Account is terminated immediately, Section 12.2 of the Terms of Service explains that our ability to assist with data recovery beforehand is limited.

17.5. Data Retained After Termination

After your Account is terminated, your data is deleted in accordance with Section 12 of the Terms of Service and cannot generally be recovered, though a copy may briefly remain in backups for the period described in Section 17.2 before final deletion. We do not otherwise retain a defined category of data specifically for legal, security, or accounting purposes after termination.

17.6. Short Lived Technical Data

Authentication tokens and similar short lived technical identifiers described in Section 12.4 follow their own, much shorter lifespan, separate from the retention periods described in this Section.

17.7. Voice AI Recordings

Voice AI recordings and transcripts are stored until deleted manually, as described in Section 11.6, since no automatic deletion schedule currently applies to them.

17.8. Planned Automatic Deletion

We do not currently delete Customer Data automatically when a subscription ends. We plan to introduce automatic deletion of Customer Data within 7 days after a subscription ends.

18. Data Security

18.1. Our Approach to Security

We maintain technical, administrative, and organizational measures designed to protect personal data against unauthorized access, disclosure, alteration, loss, and destruction. The specific measures we apply depend on the nature of the data involved, the systems that process it, and the risks reasonably associated with that processing.

18.2. Encryption

Data stored in our primary databases and in our object storage is encrypted at rest. There are currently two exceptions, data associated with GlitchTip, our internal error tracking tool, and one legacy shared Redis instance. We are working to extend encryption at rest to these remaining systems.

18.3. Access Controls

Access to production systems and personal data is managed through identity and access management controls, and administrative access to our infrastructure is routed through restricted, IP limited channels. Application components retrieve credentials through a dedicated secrets management process rather than storing them directly. Multi factor authentication is currently required for several critical systems, including our cloud infrastructure console and other third party administrative systems, but is not yet enforced uniformly across every internal administrative system.

18.4. Tenant Isolation

Customer workspaces are logically isolated from one another, and data belonging to one Customer is not shared with another. Some Enterprise Customers are provided with fully isolated infrastructure, separate from other Customers, as described in Section 14.

18.5. Limits on Personnel Access

Our support and engineering personnel do not have standing access to Customer workspaces or End User Data as a matter of course. Access to a specific Customer's data is granted only when responding to an escalation involving degraded platform or feature performance, and only for as long as necessary to resolve that issue.

18.6. Security Certifications

We do not currently hold SOC 2, ISO 27001, or similar third party security certifications. If we obtain any such certification in the future, we will update this Section.

18.7. Incident Response

We maintain a formal security incident response procedure. If we determine that a security incident affects your data, we aim to notify Customer promptly. The Data Processing Agreement sets out the specific notification timeframe and procedure that applies to Customer. Where applicable law separately requires notification to you, a regulator, or affected individuals, we will provide that notification in accordance with the timeframes and requirements of that law.

18.8. No Guarantee of Absolute Security

No method of storing or transmitting data over the internet is completely secure. While we take the measures described in this Section seriously, we cannot guarantee that unauthorized access, a security incident, or another event beyond our reasonable control will never occur.

18.9. Your Role in Security

You are responsible for keeping your Account credentials confidential and for the security practices described in Section 4.6 of the Terms of Service. If you become aware of a security incident affecting your Account, please contact us as described in Section 23.

19. Your Privacy Rights

19.1. Overview

Depending on applicable law and whether we act as controller or processor for the relevant data, as described in Section 2, you may have certain rights regarding your personal data. This Section explains what those rights generally are, who can exercise them, and how.

19.2. Rights Regarding Account Data

Because we act as a controller for Account Data, as described in Section 2.2, an Authorized User may generally request access to, correction of, or deletion of their own Account Data, subject to the limitations described in this Section. What an Authorized User can do directly through Account settings depends on the role and permissions assigned to them by their Customer administrator. Deletion currently requires contacting us, as described in Section 17.4.

19.3. Rights Regarding End User Data

Because we act as a processor for End User Data, as described in Section 2.3, an End User seeking to exercise a privacy right regarding their own data should first contact the Customer they interacted with, since Customer controls that data and determines how such requests are handled. Section 2.4 explains what happens if Customer is unreachable or unresponsive. Customer administrators can access and search End User Data directly through the Platform console, and can export certain records through our export functionality. Correcting a record generally means editing the relevant ticket or user field directly. Deleting specific records, including call recordings, file attachments, and AI interaction history, does not currently have a self service option and requires contacting our support team.

19.4. Limitations on These Rights

We may decline or limit a request where doing so is necessary to comply with a legal obligation, to establish, exercise, or defend a legal claim, to protect the security or integrity of the Platform, or where the request is manifestly unfounded, excessive, or where applicable law otherwise permits us to decline. Where we decline a request, we will explain why to the extent required by applicable law.

19.5. Verifying Your Identity

Before fulfilling a request under this Section, we may take reasonable steps to verify the identity of the person making the request, to protect against fraudulent or unauthorized requests.

19.6. No Fee for Most Requests

We do not generally charge a fee to process a privacy request. Where applicable law permits it, we may charge a reasonable fee for requests that are repetitive, manifestly unfounded, or excessive.

19.7. Response Time

We aim to respond to privacy requests within a reasonable time, and in any event within the timeframe required by applicable law where such a timeframe applies. Some requests, particularly deletion of specific records such as call recordings or file attachments, are currently handled manually by our support team rather than through an automated process, which may affect how quickly we can complete them.

19.8. State Specific Rights

Certain U.S. states, including California, have enacted their own privacy laws that provide residents with specific, additional rights beyond those described generally in this Section, along with particular disclosure requirements that apply to businesses like ours. Section 20 sets out these state specific rights and disclosures in detail.

20. California and U.S. State Privacy Disclosures

20.1. Who This Section Is For

This Section provides additional disclosures required under the California Consumer Privacy Act and similar laws in other U.S. states, for residents of those states. Our applicability under these laws depends on factors including our state of incorporation, Delaware, whether we meet applicable revenue or data volume thresholds, and the categories of individuals whose data we process. We have not independently confirmed whether we currently meet every threshold that triggers applicability under these laws, and we provide the disclosures in this Section as a matter of best practice regardless.

20.2. Applicable State Privacy Laws

As of the date of this Privacy Policy, twenty U.S. states have enacted comprehensive consumer privacy laws, including California, Colorado, Connecticut, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, Virginia, and Washington. Most of these laws share a common framework, granting residents rights to access, delete, correct, and port their personal information, requiring opt-in consent before processing sensitive personal information, and prohibiting discrimination against individuals who exercise these rights. The rights described in this Section and in Section 19 are built on this common framework and are intended to address the requirements shared across these laws, using the California Consumer Privacy Act as the primary model because it is the most established and most stringent. Whether a specific state law applies to us at a given time depends on factors such as the number of that state's residents whose data we process and other thresholds set by that state's law, which we have not independently confirmed we currently meet.

20.3. Delaware

Because Pleased Inc. is a Delaware corporation, we note specifically that the Delaware Personal Data Privacy Act applies based on the personal data of Delaware residents we process, not merely because we are incorporated in Delaware. The rights described in this Section apply equally to Delaware residents to the extent that law applies to us.

20.4. No Comprehensive Federal Law

There is currently no comprehensive federal privacy law in the United States. Certain federal laws apply to specific contexts, such as the Children's Online Privacy Protection Act described in Section 21, and the Federal Trade Commission enforces against unfair or deceptive data practices generally under the FTC Act.

20.5. Categories of Personal Information We Collect

In the preceding 12 months, we have collected the following categories of personal information, as described in Sections 3 through 12: identifiers, such as name and email address; internet or network activity, such as IP address and device information; audio or visual information, such as call recordings; commercial information, such as subscription and billing details; and professional information that may appear in support conversations.

20.6. Sensitive Personal Information

As described in Section 9, sensitive personal information may occasionally appear in End User communications through channels such as live chat, email, voice calls, and connected messaging platforms, without us seeking it out. Where applicable law gives you the right to limit our use of sensitive personal information, we do not use it for any purpose beyond providing the Services, consistent with Section 9.3, so no additional action is generally necessary to limit that use.

20.7. Sources of Personal Information

We collect personal information directly from Authorized Users, End Users, and website visitors, and from the third parties described in Section 12.

20.8. Purposes for Collection

We collect and use personal information for the purposes described in Section 7.

20.9. No Sale or Sharing of Personal Information

We do not sell personal information, and we do not share personal information for cross context behavioral advertising, as those terms are defined under applicable law. The analytics technology described in Section 11 is used to understand how our website performs, not for advertising purposes.

20.10. Retention

Section 17 describes how long we retain personal information.

20.11. Your California Rights

In addition to the rights described in Section 19, California residents have the right to know the specific pieces of personal information we hold about them, the right to request that we correct inaccurate personal information, and the right to receive a copy of certain personal information in a portable format. These rights are exercised through the same process described in Section 19.

20.12. Non Discrimination

We will not discriminate against you for exercising any right described in this Section or in Section 19, including by charging different prices or providing a different level of service. Where fulfilling a request, such as deletion, means we can no longer identify you or continue providing a specific feature that depends on the deleted data, that is a necessary technical consequence of the request rather than discrimination.

20.13. Authorized Agent

You may designate an authorized agent to make a request on your behalf, subject to the identity verification process described in Section 19.5.

20.14. Automated Decision Making

Automated decision making, including AI Features that generate responses without human review, is described in Section 11.6. We do not currently use automated decision making to produce legal or similarly significant effects regarding California residents.

21. Children's Privacy

21.1. Not Directed to Children

The Platform and our website are not directed to children under the age of 13, and we do not knowingly collect personal information from children under 13.

21.2. End User Data May Include Minors

Because Customer's own End Users interact with Customer through the Services, and Pleased does not independently verify the age of End Users, personal information belonging to a minor may be processed as End User Data. As described in Section 2.3, we process this data as a processor, on Customer's instructions, and Customer is responsible for complying with applicable law regarding minors, consistent with Section 3.3 of the Terms of Service.

21.3. If We Learn of Data From a Child Under 13

If we become aware that we have collected personal information directly from a child under 13 in a context where we act as a controller, as described in Section 2.2, we will take steps to delete that information.

21.4. Parental Rights

If you are the parent or guardian of a child under 13 and believe we have collected personal information directly from that child in a context where we act as a controller, you may contact us to request that we review and delete that information, as described in Section 23.

22. Changes to This Privacy Policy

22.1. Updates

We may update this Privacy Policy from time to time to reflect changes in our practices, the Services, or applicable law. Minor or non-material updates, such as clarifications or corrections, may be made without separate notice.

22.2. Notice of Material Changes

Where we make a material change to this Privacy Policy, we will notify you by email or through the Platform, consistent with the notice process described in Section 21.3 of the Terms of Service.

22.3. Continued Use

Your continued use of the Services after a change to this Privacy Policy takes effect means you accept the updated Privacy Policy, except where Section 11.4 requires your explicit consent for a specific change, such as a change to how we use data for training purposes.

22.4. Effective Date

This Privacy Policy is effective as of the date it is published, and we will indicate that date at the top of this document.

23. Contact Us

23.1. General Privacy Inquiries

If you have a question about this Privacy Policy or our privacy practices, contact us at support@pleased.com.

23.2. Company Information

Pleased Inc., the company described in Section 1.1 of the Terms of Service, is located at 131 Continental Dr, Suite 305, Newark, DE 19713.

23.3. Exercising Your Rights

To exercise a right described in Section 19 or Section 20, contact us at support@pleased.com or follow the process described in those Sections.