Privacy and data use
Privacy notice
What information Engage AI handles, why it is used, who it may be shared with and the choices available to people.
- Version
- privacy-2026-08-03
- Effective date
- 3 August 2026
Read this document together with the related policies and any approved customer order form.
Scope and privacy roles
This notice covers the Engage AI public website, account and subscription journeys, and the Engage AI business workspace. It applies to website visitors, account users, billing contacts and people whose messages are handled through a customer workspace.
For account, security, billing and public-site information, the approved Engage AI legal entity will determine why and how the information is used. For customer conversation content and customer-managed records, the business customer generally determines the purpose and Engage AI processes the data to provide the configured service, subject to the customer agreement and applicable law.
Information we collect
The information handled depends on how the service is used. We aim to collect only what is reasonably needed for the relevant purpose.
- Account and contact information, such as name, work email, workspace name, role, language and authentication records.
- Billing and subscription information, such as legal or company name, billing address, tax details, plan, currency, invoices and provider references. Raw card details are handled by the payment provider.
- Customer engagement data, such as channel identifiers, messages, attachments, lead details, appointments, notes, status, assignment and handover history.
- Configuration and approved content, including service information, templates, automation rules, AI guidance and provider settings.
- Technical, security and usage records, such as request time, coarse network or risk signals, device and browser data, audit events, delivery events, errors and feature usage.
- Consent and preference records, including required legal acceptance, optional marketing choice, communication opt-outs and cookie choice.
Where information comes from
Information may come directly from a visitor or account user, from the business customer that administers a workspace, from a person communicating with that business, or from connected providers such as messaging, calendar, email and payment services.
We may also create operational records when the service validates access, delivers a message, applies a configured workflow, records consent or investigates an error or security event.
Why we use information
Information is used to provide and administer the service, authenticate users, deliver configured communications, maintain conversation history, support human handover, manage subscriptions, prevent abuse, troubleshoot issues, meet legal obligations and maintain auditable business records.
Depending on the context and applicable law, processing may be necessary to perform a contract, take requested pre-contract steps, comply with law, protect legitimate security and service interests, or act on consent. Customers are responsible for establishing an appropriate basis for the customer data and communications they control.
AI, automation and human review
Configured AI features may use relevant conversation context, approved business content and workflow state to prepare answers, classify intent or suggest a next action. Deterministic services perform business-critical writes, and authorized users can review history and take over a conversation.
Customers should not configure the service to make solely automated decisions with legal or similarly significant effects without completing their own legal, risk and human-review assessment.
When information is shared
Information may be shared with authorized customer users, service providers acting for Engage AI, connected providers selected or configured by the customer, professional advisers, and authorities where disclosure is legally required or necessary to protect rights and security.
We do not sell customer conversation content. A production subprocessor schedule naming approved providers, locations and purposes must be published before live personal-data collection begins.
International data transfers
Some customers, users or service providers may be located in different countries. Where personal data is transferred across borders, the responsible party must use an approved legal mechanism and assess whether the destination provides appropriate protection.
The production privacy schedule will identify material hosting and provider locations after infrastructure and subprocessor approval.
Retention and deletion
Information is kept only for as long as needed for the stated purpose, customer instructions, security, dispute resolution and legal or financial recordkeeping. Different records have different operational and statutory periods.
Pending signup data expires automatically and is erased or anonymized after the approved window. Authorized customer deletion workflows remove or de-identify linked customer records subject to backup, audit, legal-hold and billing obligations.
The production retention schedule must state approved periods for each material category before live collection is enabled.
How information is protected
Engage AI uses role-based access, tenant-scoped data boundaries, secure session controls, server-side secret handling, audit records and monitored operational workflows. No system can guarantee absolute security, so customers must also protect their users, devices and connected provider accounts.
See the Security page for a factual description of implemented safeguards and assurance limits.
Your rights and choices
Depending on applicable law and the processing context, a person may have rights to request access, correction, deletion, restriction, objection, portability or withdrawal of consent, and to complain to a regulator. Some rights are limited by law or by another person's rights.
If the information is controlled by an Engage AI business customer, contact that business first. Engage AI will support verified customer requests as required by the service agreement and applicable law.
- Use communication opt-out instructions for marketing or automated follow-up where provided.
- Use the cookie choices on the Cookie and storage notice for optional public-site analytics.
- Do not send passwords, payment card details or unnecessary conversation content in an initial privacy request.
Children, policy changes and contact
Engage AI is a business service and is not directed to children. Customers must not intentionally use it to collect children's data without an appropriate legal basis, safeguards and an approved use case.
We may update this notice when the service, providers or legal requirements change. Material changes will be versioned and communicated where required; new wording applies from its stated effective date.