Privacy Policy
Last Updated: September 1, 2026
Effective Date: September 1, 2026
Table of Contents:
- 1. Introduction and Scope
- 2. Two Roles: When We Are a Controller and When We Are a Processor
- 3. Definitions
- 4. Personal Data We Collect as a Controller
- 5. Personal Data End Users Provide Directly
- 6. Data from Connected Messaging and Social Platforms
- 7. Voice Calls and Call Recordings
- 8. How We Use Personal Data
- 9. Sensitive Personal Information
- 10. Legal Bases for Processing
- 11. AI Features and Personal Data
- 12. Cookies and Tracking Technologies
- 13. How We Share Personal Data
- 14. Enterprise and Organizational Use
- 15. Subprocessors
- 16. International Data Transfers
- 17. Data Retention
- 18. Data Security
- 19. Your Privacy Rights
- 20. California and U.S. State Privacy Disclosures
- 21. Children's Privacy
- 22. Changes to This Privacy Policy
- 23. Contact Us
1. Introduction and Scope
1.1. About This Privacy Policy
This Privacy Policy explains how Pleased Inc. collects, uses, shares, and protects personal data in connection with the Platform, the Services, and our website. Pleased, we, us, and our have the meaning given to Company in the Terms of Service. Customer, Authorized User, Agent, End User, Platform, and Services also have the meanings given to them in the Terms of Service.
1.2. Who This Applies To
This Privacy Policy applies to personal data we collect from visitors to our website, from Customer and its Authorized Users, and to personal data we process on behalf of Customer in providing the Services, including data relating to End Users. Section 2 explains the differences between these categories and how they affect your rights and our obligations.
1.3. Relationship to Our Other Documents
This Privacy Policy works together with the Terms of Service and the Data Processing Agreement. The Terms of Service govern the contractual relationship between Pleased and Customer, including acceptable use, intellectual property, and liability. The Data Processing Agreement governs the specific obligations that apply when Pleased processes personal data on Customer's behalf as a processor. This Privacy Policy focuses on what personal data we collect, why we collect it, and the rights available to individuals.
1.4. Where We Operate
Pleased is a Delaware corporation based in the United States. Our infrastructure and personnel are located in multiple countries, and Section 14 explains how we handle personal data that is processed or accessed outside the United States.
1.5. Updates to This Privacy Policy
We may update this Privacy Policy from time to time, as described in Section 20, which explains how we handle changes to our privacy practices.
2. Two Roles: When We Are a Controller and When We Are a Processor
2.1. Why This Distinction Matters
Depending on the type of personal data involved, Pleased acts either as a controller, meaning we decide why and how that data is processed, or as a processor, meaning we process the data on Customer's behalf to provide the Services. This distinction determines who you should contact with a request, and which document, this Privacy Policy or the Data Processing Agreement, governs the details of that processing.
2.2. When We Act as a Controller
We act as a controller for personal data relating to visitors to our website and for Account Data, meaning information about Customer's representatives and Authorized Users that we collect to operate their Account, communicate with them, and provide the Services. Sections 3 and 11 describe this data in more detail.
2.3. When We Act as a Processor
We act as a processor for End User Data, meaning personal data about Customer's own customers and contacts that flows through the Services, for example, through live chat, voice calls, email, or connected messaging channels. In this role, Customer is the controller, and we process End User Data to provide, secure, and support the Services, in accordance with Customer's instructions and the terms of the Data Processing Agreement. Sections 4 through 6 describe End User Data by channel.
2.4. Contacting Us About End User Data
If you are an End User and have a question about how your personal data is handled, you should first contact the Customer whose Services you interacted with, since Customer controls that data and is primarily responsible for responding to your request. We will support Customer in responding to your request as required under the Data Processing Agreement. If you are unable to reach Customer or do not receive a response, you may contact us at the address in Section 21, and we will take reasonable steps to assist.
2.5. Records That Combine Both Categories
Some records we generate while providing the Services may contain both Account Data and End User Data together, for example a call log that includes both an Agent identifier and an End User's phone number. In these cases, each element of the record is treated according to its own category, Account Data elements under Section 2.2, and End User Data elements under Section 2.3, rather than treating the entire record as one category.
2.6. If We Ever Use End User Data for Our Own Purposes
If we use End User Data for a purpose of our own, rather than solely to provide the Services to Customer, for example to improve or train our own systems, we act as a controller for that specific use, separately from our processor role described in Section 2.3. Section 10 explains our current practice regarding the use of data in connection with AI Features.
3. Definitions
Terms Defined in the Terms of Service. Capitalized terms used in this Privacy Policy that are not defined below have the meanings given to them in the Terms of Service, including Customer, Authorized User, Agent, End User, Platform, Services, Content, Brand, AI Features, and AI Output.
Personal Data means any information relating to an identified or identifiable individual.
Account Data means personal data about Customer's representatives and Authorized Users that we collect to operate their Account, as described in Section 4.
End User Data means personal data about Customer's own End Users that flows through the Services, as described in Sections 5 through 7.
Website Visitor Data means personal data we collect from visitors to our website, as described in Section 12.
Sensitive Personal Information has the meaning given in Section 9.
Controller and Processor. In this Privacy Policy, controller means the party that determines the purposes and means of processing personal data, and processor means the party that processes personal data on behalf of, and following the instructions of, a controller. Section 2 explains when each role applies to us.
Knowledge Base means the collection of articles, documents, and other reference materials that Customer maintains within the Services to support its support operations, including content used by AI Features as described in Section 10.
4. Personal Data We Collect as a Controller
4.1. Registration Information
When an Authorized User registers for an Account, we collect their name and work email address.
4.2. Google Sign-In Information
If an Authorized User signs in using Google, we receive their Google account identifier, email address, email verification status, first and last name, profile picture, and the domain associated with their Google Workspace account, where applicable.
4.3. Custom Agent Information
Customer administrators can add custom fields containing additional information about their Agents. Any personal data added this way is collected and stored as part of the Account.
4.4. Billing Information
We collect billing-related information as part of your Account, including the identity information described in Section 3.1. Payment card details are handled directly by Stripe and are not stored by us, as described in Section 12.
4.5. Communications With You
When you contact us directly, for example to ask a question about your Account or these Services, we collect the information you provide in that communication.
4.6. Website Visitors
Section 11 explains what information we collect from visitors to our website, including through cookies and similar technologies.
5. Personal Data End Users Provide Directly
5.1. Live Chat
When an End User uses live chat, we process their name, email address, phone number, and any profile image they provide, along with any custom fields Customer has configured. We also process technical session data, including IP address and browser information, any files the End User attaches, and, where provided, a satisfaction rating and written feedback about the conversation. While a chat is active, presence and typing status are processed in real time. Where Customer has enabled AI Features for live chat, this data may also be processed by an AI Feature, as described in Section 10.
5.2. Email and Tickets
When an End User contacts Customer by email, we process the sender and recipient email addresses, the subject line, the message content, email headers, the sender's IP address, and any attachments. This data is stored as a ticket, and the message content becomes part of that ticket's record.
5.3. Web Forms
Every web form includes three fields at minimum, the End User's email address, a description, and an optional attachment. Customer can configure additional fields to collect further information, so the exact data collected through a specific web form depends on how Customer has set it up.
5.4. File Attachments
Section 5.3 of the Terms of Service describes the file types and size limits that currently apply to attachments submitted through these channels.
5.5. Free Text Content
The message content, descriptions, and feedback described in this Section are provided by End Users in free text form and may occasionally include sensitive personal information. Section 8 explains how we handle this.
6. Data from Connected Messaging and Social Platforms
6.1. What This Section Covers
When Customer connects the Services to a third party messaging or social platform, we receive certain information about End Users directly from that platform, separate from what End Users provide directly through Pleased as described in Section 4.
6.2. Telegram
We receive the End User's Telegram user identifier and username.
6.3. X
We receive the End User's X user identifier and username, along with public profile information such as their profile picture, verification status, follower count, and post count. This public profile information reflects what the End User has made visible on X itself, rather than information provided specifically to Customer. We also receive the content of direct messages and mentions directed at Customer.
6.4. WhatsApp
We receive the End User's phone number, Customer's connected WhatsApp business phone number, and the text and media content of messages.
6.5. App Store Reviews
We receive the reviewer's nickname, the content and rating of their review, and their territory.
6.6. Facebook
We receive a page scoped user identifier and the content of messages and comments directed at Customer's page.
6.7. Google Play
This integration is not currently implemented.
6.8. What We Send Back
We send Agent reply text and attachments back to each connected platform, so the End User receives Customer's response through the same channel they used to reach out.
6.9. Free Text Content
Message content received through these platforms, including direct messages, mentions, comments, and review text, may occasionally include sensitive personal information. Section 8 explains how we handle this.
7. Voice Calls and Call Recordings
7.1. What We Collect
When a call is made or received through the Services, we process the phone numbers of both parties, the call duration, call status, and technical identifiers used to route and manage the call. Where the End User leaves a description of their inquiry, we process that as well. Recording is enabled automatically for all calls made through the Services. A call record may contain both End User Data and Account Data together, and Section 2.5 explains how we treat records of this kind.
7.2. Call Recordings
Calls made through the Services are recorded automatically. The recording is initially processed through our voice provider and then stored on our own infrastructure, as described in Section 12. In rare cases where this transfer does not complete successfully, the recording may remain accessible through our voice provider rather than our own infrastructure. We retain a technical record of the recording's status and duration alongside the call itself.
7.3. Notice to Callers
Callers are notified that the call may be recorded through an automated voice prompt at the start of the call. This notice is provided automatically and does not depend on any action by Customer.
7.4. Consent Responsibility
Recording is enabled by default for all calls made through the Services, and the recording itself is initiated and stored by Pleased, not by Customer. Because of this, Pleased provides the notice described in Section 7.3 as a baseline measure. Customer remains responsible for any additional consent required by applicable law beyond that baseline notice, including laws that require the express consent of all parties to a call before it is recorded.
7.5. Disabling Recording
If Customer needs call recording disabled for its account, Customer can request this by contacting our support team, and we will disable recording for that account.
7.6. Multi-Brand Routing
Where Customer operates multiple Brands, caller and called numbers are associated with the relevant Brand's phone configuration to route calls correctly.
7.7. AI Voice Features
If Customer enables an AI Feature for voice calls, call data described in this Section may also be processed by that AI Feature, as described in Section 11.
7.8. Free Text Content
The description an End User provides when calling, and the content of the call itself, may occasionally include sensitive personal information. Section 8 explains how we handle this.
8. How We Use Personal Data
8.1. Account Data
We use Account Data to operate your Account, communicate with you, process billing, provide customer support, and maintain the security of the Platform. Technical data such as IP addresses supports rate limiting and account verification, helping us prevent abuse of the Services. Where a conversation is handed off from an AI Feature to an Agent, we log that handoff. This log may contain both Account Data and End User Data together, and Section 2.5 explains how we treat records of this kind. Section 10 explains more about how AI Features process data.
8.2. End User Data
We use End User Data solely to provide, secure, and support the Services to Customer, in accordance with Customer's instructions and the Data Processing Agreement, as described in Section 2.3. Our support and engineering personnel access a specific Customer workspace only when responding to an escalation involving degraded platform or feature performance.
8.3. Website Visitor Data
We use information collected from website visitors to operate and improve our website, and for analytics purposes, as described in Section 11.
8.4. Internal Analytics
We use internal tools to analyze how the Platform is used, which may involve access to Account Data or End User Data as part of that analysis, as described in Section 12.
9. Sensitive Personal Information
9.1. What This Section Covers
Sensitive personal information includes categories such as health information, religious beliefs, racial or ethnic origin, sexual orientation, citizenship or immigration status, precise geolocation, biometric data, and government identifiers, along with similar categories that receive heightened protection under applicable law.
9.2. How This May Appear
We do not intentionally collect sensitive personal information. Because End Users communicate with Customer in free text through channels described in Sections 4, 5, and 6, sensitive personal information may occasionally appear in that content without us seeking it out.
9.3. How We Handle It
Where sensitive personal information appears in End User Data, we process it only as part of providing the Services to Customer, following Customer's instructions, in the same way we handle other End User Data described in Section 2.3. We do not use sensitive personal information for any purpose beyond providing the Services. Internal tools described in Section 13.6 have broad access to Customer Data as part of their function, and this may include sensitive personal information where it is present, though these tools are not designed to specifically target or single out that category of data.
9.4. Customer's Responsibility
Customer is responsible for ensuring that its use of the Services, including any collection of sensitive personal information from End Users, complies with applicable law.
9.5. Future PII Features
We plan to introduce features that help identify and manage personal information, including sensitive personal information, within the Platform. Section 22 explains how we will notify you of material changes to this Privacy Policy, including changes related to these features.
9.6. Voice AI Risk
Voice AI Features in particular carry a higher risk in this respect, since live voice audio may reach our AI provider before any redaction takes place, as described in Section 11.2.
10. Legal Bases for Processing
10.1. Our Approach
We currently operate under United States law and describe our purposes for processing personal data in Section 8. Unlike some other legal frameworks, United States privacy and consumer protection law generally does not require us to identify a separate, named legal basis for each processing activity. Having a legitimate business purpose for processing, as described throughout this Privacy Policy, is sufficient under the law that currently applies to us.
10.2. If We Expand to Markets That Require This Framework
If we begin to target customers in the European Union, the European Economic Area, or the United Kingdom, we will identify the specific legal basis, such as consent, contract, or legitimate interest, that applies to each category of processing described in this Privacy Policy, consistent with the General Data Protection Regulation.
11. AI Features and Personal Data
11.1. AI Providers
AI Features are powered by third party providers, including OpenAI and AWS Bedrock, as described in Section 13.
11.2. What We Send to OpenAI
Where needed to answer a request, we send OpenAI customer messages or live voice audio, relevant conversation context, relevant Knowledge Base content, and case data. Live voice audio may reach OpenAI before any redaction takes place.
11.3. OpenAI Retention
OpenAI does not use this data to train its models. Zero Data Retention is not currently enabled for our use of OpenAI, and OpenAI may retain content for abuse monitoring purposes for up to 30 days.
11.4. What We Send to AWS Bedrock
Text based AI Features may send search queries and relevant Knowledge Base content to AWS Bedrock to rerank results or generate a response. Voice AI Features do not use Bedrock, and we do not send voice audio or stored vectors to it. Bedrock invocation logging is not enabled, so we do not retain Bedrock prompts or responses through that mechanism. Data sent to Bedrock is not used to train models and is not shared with model providers.
11.5. Knowledge Base and Embeddings
Knowledge Base content and the embeddings generated from it are stored in AWS OpenSearch, separated by Customer and by Brand. Deleting Knowledge Base content does not automatically delete the related embeddings.
11.6. Voice AI Recordings
Where a Voice AI Feature is used, recordings and transcripts are stored in AWS S3. There is currently no automatic deletion schedule for this data, and it remains until deleted manually.
11.7. No Training Without Consent
We do not use Customer Data, prompts, outputs, or Knowledge Base content to improve or train our own AI systems, or those of any third party AI provider, without explicit consent, consistent with Section 6.8 of the Terms of Service.
11.8. Automated Decision-Making
AI Features can generate responses to End Users without human review, as described in Section 6.2 of the Terms of Service. We do not currently use AI Features to make decisions that produce legal or similarly significant effects for End Users.
12. Cookies and Tracking Technologies
12.1. Overview
We use cookies and similar technologies on our website and within the Platform. This Section provides an overview, and our Cookie Policy provides full details, including how to manage your preferences.
12.2. Our Website
Our website uses session storage to track signup timing, and cookies placed by Stripe on our payment page to process payments. We do not set first party cookies through our own code.
12.3. Session Recording
We use ContentSquare, a third party analytics provider, on our website and within parts of the Platform, including tenant consoles, though we are in the process of removing it as part of a transition to a new analytics setup. On our website, our Cookie Policy explains how consent is managed for this technology.
12.4. The Platform
Once you are signed in, the Platform uses cookies and similar technologies necessary for it to function, including an authentication token that expires after 9 hours, identifiers that associate your session with your Brand and Account, and technical parameters used during Google sign in.
12.5. Your Choices
Our Cookie Policy explains what choices are available to you regarding cookies and similar technologies, including any technologies that require your consent under applicable law.
13. How We Share Personal Data
13.1. Overview
We share personal data with the categories of third parties described in this Section, consistent with Section 17 of the Terms of Service, which describes these providers in the context of delivering the Services.
13.2. Infrastructure Providers
We use Amazon Web Services for our core cloud infrastructure, Google Firebase to support real time chat functionality, and Cloudflare for domain name services.
13.3. Communication Providers
We use Twilio to support voice calls and WhatsApp messaging, and SendGrid to support email delivery.
13.4. Payment Provider
We use Stripe to process subscription payments and manage billing.
13.5. AI Providers
We use OpenAI and AWS Bedrock to power AI Features, as described in Section 11.
13.6. Internal Tools
We use tools such as Slack, Metabase, Jaeger, and GlitchTip to support our own internal operations, including notifications, analytics, error tracking, and system monitoring.
13.7. Connected Channels
Where Customer connects the Services to a channel such as WhatsApp, Telegram, X, Facebook, or the App Store, that channel's provider is also involved in delivering messages between Customer and its End Users, as described in Section 6.
13.8. Legal Disclosures
We may disclose personal data where required by law, court order, or governmental authority, where necessary to establish, exercise, or defend legal claims, or where necessary to protect the rights, property, or safety of Pleased, our Customers, or others.
13.9. Business Transfers
If we are involved in a merger, acquisition, or sale of assets, personal data may be transferred as part of that transaction, subject to this Privacy Policy or a successor policy.
13.10. Third Party Responsibility
We are not responsible for the privacy practices of third parties beyond what we instruct them to do in connection with the Services, consistent with Section 13.6 of the Terms of Service.
14. Enterprise and Organizational Use
14.1. Enterprise Customers
Where Customer accesses the Services under a negotiated Order Form, Enterprise Subscription Agreement, or Master Services Agreement, additional or different terms governing the processing of personal data may apply, as set out in those agreements or in a separately negotiated Data Processing Agreement.
14.2. Order of Precedence
Where a negotiated agreement described in Section 14.1 conflicts with this Privacy Policy, that agreement controls with respect to the specific processing activities it covers, consistent with the Document Hierarchy described in Section 1.4 of the Terms of Service.
14.3. Isolated Infrastructure
Some Enterprise Customers are provided with isolated infrastructure separate from other Customers, as described in the Terms of Service. This Privacy Policy continues to apply to personal data processed within that infrastructure, except where a negotiated agreement expressly provides otherwise.
14.4. Administrator Controls
Where Customer's administrators configure roles, permissions, retention settings, or other account-level controls, those configurations are made by Customer, not by us, and Customer is responsible for their use in accordance with its own obligations to its Authorized Users and End Users.
15. Subprocessors
15.1. What Subprocessors Are
Where we process End User Data as a processor, as described in Section 2.3, we may engage other companies, called subprocessors, to help us provide the Services. Subprocessors process End User Data only to the extent necessary to perform the function they have been engaged for.
15.2. Our Subprocessors
The infrastructure, communication, and AI providers described in Section 13 act as subprocessors to the extent they process End User Data on our behalf, under our instructions. Some providers, such as Stripe when processing billing information, act as independent controllers of the data they receive, subject to their own privacy practices, rather than as our subprocessors. Internal tools described in Section 13.6 support our own operations and are not subprocessors, since they do not provide the Services to Customer directly.
15.3. Contractual Protections
We have data processing agreements in place with our subprocessors that require them to protect End User Data consistent with our own obligations to Customer.
15.4. Changes to Subprocessors
Where we add or replace a subprocessor, the Data Processing Agreement governs how we notify Customer and, where applicable, any right Customer has to object.
15.5. Full List
The complete, current list of subprocessors is maintained in the Data Processing Agreement, which Customer receives as part of its agreement with us. We do not publish a separate public list of subprocessors on our website.
16. International Data Transfers
16.1. Overview
Personal data processed through the Services may be stored in, or accessed from, countries other than the country where you or your End Users are located. This Section explains how and why that happens.
16.2. Where Our Infrastructure Is Located
Our core production infrastructure, including our primary databases, is located in Germany, within the AWS eu-central-1 region, as described in Section 13. This means personal data we process is physically stored on servers in Germany as part of our normal operations, regardless of where you or your End Users are located.
16.3. Access by Our Personnel and Contractors
Separately from where data is stored, our employees and contractors access personal data from multiple countries as part of providing the Services, including the United States, Germany, Spain, the United Kingdom, Turkey, North Macedonia, India, and the Philippines.
16.4. Why This Does Not Currently Require Additional Measures
Certain data protection laws, including the GDPR, generally apply based on whether a company targets individuals located in a particular jurisdiction, rather than based solely on where infrastructure is physically located or where personnel are based. We are a Delaware corporation and do not currently target customers or individuals in the European Union, the European Economic Area, or the United Kingdom. We will implement transfer mechanisms such as Standard Contractual Clauses, a UK International Data Transfer Addendum, or a representative under Article 27 of the GDPR where required by applicable law or where agreed with a Customer.
16.5. If You Are Located in the European Union, the European Economic Area, or the United Kingdom
We do not target the Services to individuals in these regions. If you access or use the Services from one of these regions despite this, you acknowledge that the Services are provided by a United States company, that your data will be processed as described in this Section, and that you may be asked to confirm this understanding as part of using the Services, consistent with Section 19.5 of the Terms of Service.
16.6. If Our Approach Changes
If we begin to target customers in the European Union, the European Economic Area, or the United Kingdom, or where otherwise required by law or by agreement with a Customer, we will implement the compliance and transfer mechanisms applicable at that time. We will update this Section when that occurs.
17. Data Retention
17.1. Our Current Approach
We do not currently have a single, formal data retention policy that applies uniformly across all categories of personal data. In practice, most personal data is retained until a deletion request is made or an Account is terminated, rather than being deleted automatically after a fixed period. Where we describe data as archived below, this means it is moved to separate storage but not deleted, archiving and deletion are different processes.
17.2. Where Specific Retention Periods Apply
Some categories of data do follow a defined schedule. Application and security logs are retained for 90 days in production. Backup copies of our production database are retained for 7 days. Closed tickets and conversations are archived after 90 days, and closed AI chats after 2 days.
17.3. Categories Without a Defined Period
Call recordings, file attachments, and backup copies other than those described in Section 17.2 do not currently have an automatic deletion schedule and are retained indefinitely unless deleted upon request.
17.4. Deletion Upon Request
You can request deletion of data through the process described in Section 18. Deletion currently requires contacting our support team, as described in Section 6.10 of the Terms of Service. Where your Account is terminated immediately, Section 12.2 of the Terms of Service explains that our ability to assist with data recovery beforehand is limited.
17.5. Data Retained After Termination
After your Account is terminated, your data is deleted in accordance with Section 12 of the Terms of Service and cannot generally be recovered, though a copy may briefly remain in backups for the period described in Section 17.2 before final deletion. We do not otherwise retain a defined category of data specifically for legal, security, or accounting purposes after termination.
17.6. Short Lived Technical Data
Authentication tokens and similar short lived technical identifiers described in Section 12.4 follow their own, much shorter lifespan, separate from the retention periods described in this Section.
17.7. Voice AI Recordings
Voice AI recordings and transcripts are stored until deleted manually, as described in Section 11.6, since no automatic deletion schedule currently applies to them.
17.8. Planned Automatic Deletion
We do not currently delete Customer Data automatically when a subscription ends. We plan to introduce automatic deletion of Customer Data within 7 days after a subscription ends.
18. Data Security
18.1. Our Approach to Security
We maintain technical, administrative, and organizational measures designed to protect personal data against unauthorized access, disclosure, alteration, loss, and destruction. The specific measures we apply depend on the nature of the data involved, the systems that process it, and the risks reasonably associated with that processing.
18.2. Encryption
Data stored in our primary databases and in our object storage is encrypted at rest. There are currently two exceptions, data associated with GlitchTip, our internal error tracking tool, and one legacy shared Redis instance. We are working to extend encryption at rest to these remaining systems.
18.3. Access Controls
Access to production systems and personal data is managed through identity and access management controls, and administrative access to our infrastructure is routed through restricted, IP limited channels. Application components retrieve credentials through a dedicated secrets management process rather than storing them directly. Multi factor authentication is currently required for several critical systems, including our cloud infrastructure console and other third party administrative systems, but is not yet enforced uniformly across every internal administrative system.
18.4. Tenant Isolation
Customer workspaces are logically isolated from one another, and data belonging to one Customer is not shared with another. Some Enterprise Customers are provided with fully isolated infrastructure, separate from other Customers, as described in Section 14.
18.5. Limits on Personnel Access
Our support and engineering personnel do not have standing access to Customer workspaces or End User Data as a matter of course. Access to a specific Customer's data is granted only when responding to an escalation involving degraded platform or feature performance, and only for as long as necessary to resolve that issue.
18.6. Security Certifications
We do not currently hold SOC 2, ISO 27001, or similar third party security certifications. If we obtain any such certification in the future, we will update this Section.
18.7. Incident Response
We maintain a formal security incident response procedure. If we determine that a security incident affects your data, we aim to notify Customer promptly. The Data Processing Agreement sets out the specific notification timeframe and procedure that applies to Customer. Where applicable law separately requires notification to you, a regulator, or affected individuals, we will provide that notification in accordance with the timeframes and requirements of that law.
18.8. No Guarantee of Absolute Security
No method of storing or transmitting data over the internet is completely secure. While we take the measures described in this Section seriously, we cannot guarantee that unauthorized access, a security incident, or another event beyond our reasonable control will never occur.
18.9. Your Role in Security
You are responsible for keeping your Account credentials confidential and for the security practices described in Section 4.6 of the Terms of Service. If you become aware of a security incident affecting your Account, please contact us as described in Section 23.
19. Your Privacy Rights
19.1. Overview
Depending on applicable law and whether we act as controller or processor for the relevant data, as described in Section 2, you may have certain rights regarding your personal data. This Section explains what those rights generally are, who can exercise them, and how.
19.2. Rights Regarding Account Data
Because we act as a controller for Account Data, as described in Section 2.2, an Authorized User may generally request access to, correction of, or deletion of their own Account Data, subject to the limitations described in this Section. What an Authorized User can do directly through Account settings depends on the role and permissions assigned to them by their Customer administrator. Deletion currently requires contacting us, as described in Section 17.4.
19.3. Rights Regarding End User Data
Because we act as a processor for End User Data, as described in Section 2.3, an End User seeking to exercise a privacy right regarding their own data should first contact the Customer they interacted with, since Customer controls that data and determines how such requests are handled. Section 2.4 explains what happens if Customer is unreachable or unresponsive. Customer administrators can access and search End User Data directly through the Platform console, and can export certain records through our export functionality. Correcting a record generally means editing the relevant ticket or user field directly. Deleting specific records, including call recordings, file attachments, and AI interaction history, does not currently have a self service option and requires contacting our support team.
19.4. Limitations on These Rights
We may decline or limit a request where doing so is necessary to comply with a legal obligation, to establish, exercise, or defend a legal claim, to protect the security or integrity of the Platform, or where the request is manifestly unfounded, excessive, or where applicable law otherwise permits us to decline. Where we decline a request, we will explain why to the extent required by applicable law.
19.5. Verifying Your Identity
Before fulfilling a request under this Section, we may take reasonable steps to verify the identity of the person making the request, to protect against fraudulent or unauthorized requests.
19.6. No Fee for Most Requests
We do not generally charge a fee to process a privacy request. Where applicable law permits it, we may charge a reasonable fee for requests that are repetitive, manifestly unfounded, or excessive.
19.7. Response Time
We aim to respond to privacy requests within a reasonable time, and in any event within the timeframe required by applicable law where such a timeframe applies. Some requests, particularly deletion of specific records such as call recordings or file attachments, are currently handled manually by our support team rather than through an automated process, which may affect how quickly we can complete them.
19.8. State Specific Rights
Certain U.S. states, including California, have enacted their own privacy laws that provide residents with specific, additional rights beyond those described generally in this Section, along with particular disclosure requirements that apply to businesses like ours. Section 20 sets out these state specific rights and disclosures in detail.
20. California and U.S. State Privacy Disclosures
20.1. Who This Section Is For
This Section provides additional disclosures required under the California Consumer Privacy Act and similar laws in other U.S. states, for residents of those states. Our applicability under these laws depends on factors including our state of incorporation, Delaware, whether we meet applicable revenue or data volume thresholds, and the categories of individuals whose data we process. We have not independently confirmed whether we currently meet every threshold that triggers applicability under these laws, and we provide the disclosures in this Section as a matter of best practice regardless.
20.2. Applicable State Privacy Laws
As of the date of this Privacy Policy, twenty U.S. states have enacted comprehensive consumer privacy laws, including California, Colorado, Connecticut, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, Virginia, and Washington. Most of these laws share a common framework, granting residents rights to access, delete, correct, and port their personal information, requiring opt-in consent before processing sensitive personal information, and prohibiting discrimination against individuals who exercise these rights. The rights described in this Section and in Section 19 are built on this common framework and are intended to address the requirements shared across these laws, using the California Consumer Privacy Act as the primary model because it is the most established and most stringent. Whether a specific state law applies to us at a given time depends on factors such as the number of that state's residents whose data we process and other thresholds set by that state's law, which we have not independently confirmed we currently meet.
20.3. Delaware
Because Pleased Inc. is a Delaware corporation, we note specifically that the Delaware Personal Data Privacy Act applies based on the personal data of Delaware residents we process, not merely because we are incorporated in Delaware. The rights described in this Section apply equally to Delaware residents to the extent that law applies to us.
20.4. No Comprehensive Federal Law
There is currently no comprehensive federal privacy law in the United States. Certain federal laws apply to specific contexts, such as the Children's Online Privacy Protection Act described in Section 21, and the Federal Trade Commission enforces against unfair or deceptive data practices generally under the FTC Act.
20.5. Categories of Personal Information We Collect
In the preceding 12 months, we have collected the following categories of personal information, as described in Sections 3 through 12: identifiers, such as name and email address; internet or network activity, such as IP address and device information; audio or visual information, such as call recordings; commercial information, such as subscription and billing details; and professional information that may appear in support conversations.
20.6. Sensitive Personal Information
As described in Section 9, sensitive personal information may occasionally appear in End User communications through channels such as live chat, email, voice calls, and connected messaging platforms, without us seeking it out. Where applicable law gives you the right to limit our use of sensitive personal information, we do not use it for any purpose beyond providing the Services, consistent with Section 9.3, so no additional action is generally necessary to limit that use.
20.7. Sources of Personal Information
We collect personal information directly from Authorized Users, End Users, and website visitors, and from the third parties described in Section 12.
20.8. Purposes for Collection
We collect and use personal information for the purposes described in Section 7.
20.9. No Sale or Sharing of Personal Information
We do not sell personal information, and we do not share personal information for cross context behavioral advertising, as those terms are defined under applicable law. The analytics technology described in Section 11 is used to understand how our website performs, not for advertising purposes.
20.10. Retention
Section 17 describes how long we retain personal information.
20.11. Your California Rights
In addition to the rights described in Section 19, California residents have the right to know the specific pieces of personal information we hold about them, the right to request that we correct inaccurate personal information, and the right to receive a copy of certain personal information in a portable format. These rights are exercised through the same process described in Section 19.
20.12. Non Discrimination
We will not discriminate against you for exercising any right described in this Section or in Section 19, including by charging different prices or providing a different level of service. Where fulfilling a request, such as deletion, means we can no longer identify you or continue providing a specific feature that depends on the deleted data, that is a necessary technical consequence of the request rather than discrimination.
20.13. Authorized Agent
You may designate an authorized agent to make a request on your behalf, subject to the identity verification process described in Section 19.5.
20.14. Automated Decision Making
Automated decision making, including AI Features that generate responses without human review, is described in Section 11.6. We do not currently use automated decision making to produce legal or similarly significant effects regarding California residents.
21. Children's Privacy
21.1. Not Directed to Children
The Platform and our website are not directed to children under the age of 13, and we do not knowingly collect personal information from children under 13.
21.2. End User Data May Include Minors
Because Customer's own End Users interact with Customer through the Services, and Pleased does not independently verify the age of End Users, personal information belonging to a minor may be processed as End User Data. As described in Section 2.3, we process this data as a processor, on Customer's instructions, and Customer is responsible for complying with applicable law regarding minors, consistent with Section 3.3 of the Terms of Service.
21.3. If We Learn of Data From a Child Under 13
If we become aware that we have collected personal information directly from a child under 13 in a context where we act as a controller, as described in Section 2.2, we will take steps to delete that information.
21.4. Parental Rights
If you are the parent or guardian of a child under 13 and believe we have collected personal information directly from that child in a context where we act as a controller, you may contact us to request that we review and delete that information, as described in Section 23.
22. Changes to This Privacy Policy
22.1. Updates
We may update this Privacy Policy from time to time to reflect changes in our practices, the Services, or applicable law. Minor or non-material updates, such as clarifications or corrections, may be made without separate notice.
22.2. Notice of Material Changes
Where we make a material change to this Privacy Policy, we will notify you by email or through the Platform, consistent with the notice process described in Section 21.3 of the Terms of Service.
22.3. Continued Use
Your continued use of the Services after a change to this Privacy Policy takes effect means you accept the updated Privacy Policy, except where Section 11.4 requires your explicit consent for a specific change, such as a change to how we use data for training purposes.
22.4. Effective Date
This Privacy Policy is effective as of the date it is published, and we will indicate that date at the top of this document.
23. Contact Us
23.1. General Privacy Inquiries
If you have a question about this Privacy Policy or our privacy practices, contact us at support@pleased.com.
23.2. Company Information
Pleased Inc., the company described in Section 1.1 of the Terms of Service, is located at 131 Continental Dr, Suite 305, Newark, DE 19713.
23.3. Exercising Your Rights
To exercise a right described in Section 19 or Section 20, contact us at support@pleased.com or follow the process described in those Sections.