Privacy Policy
Last updated: 2026-08-03
1. Who we are
This Privacy Policy describes how AI Agency Group ("AI Agency", "we", "us", "our") collects, uses, and protects personal data when you use the AI Employees platform at myemployees.ai and our related services (the "Service").
For the personal data we process about our customers' end-users on behalf of those customers, AI Agency acts as a processor under the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR") and the UK GDPR. Our customers are the controllers of that data. For data we collect directly about you when you sign up, sign in, or use the Service yourself, AI Agency is the controller.
For privacy-related questions, requests, or complaints contact:
2. What personal data we process
We process the following categories of personal data:
| Category | Examples | Source |
|---|---|---|
| Account & contact information | name, work email, organization, role, hashed password (admin accounts); email one-time-passcode for end-customer portal sessions | Provided by you when you sign up |
| Conversation transcripts | text exchanged with AI agents in chat, ticket bodies, agent responses | Generated as you use the Service |
| Call transcripts and metadata | voice call audio, machine transcripts, caller phone number, call duration | Generated when you use the voice agent feature |
| Customer / contact records | the names, emails, phone numbers, and CRM custom fields belonging to your own customers, when you sync a CRM or upload contacts | Provided by you / your integrations |
| Audit and access logs | timestamps, IP addresses, user agents, actions taken, before/after diffs of changed records, request IDs | Generated automatically by the Service |
| Payment metadata | billing email, subscription tier, invoice timestamps, payment status — never card numbers (those are handled directly by our payment processors) | Webhooks from Stripe / Square / Whop |
| Service usage data | feature usage counts, error events, performance metrics | Generated automatically by the Service |
| Time zone | the IANA time zone your browser reports (for example America/New_York) and when we last observed it. We keep only the most recent value, never a history, so this is a current setting and not a record of your movements | Detected automatically in your browser each time you sign in to the dashboard |
| Product analytics and session recordings | pages visited, clicks and other interactions, device and browser type, approximate location derived from IP, a pseudonymous visitor identifier, and masked recordings of your screen while you use the dashboard — see Section 11.1 for what "masked" means and which areas are never recorded | Generated automatically in your browser by our analytics provider |
| Bug report diagnostics | when you report a bug, the page you were on, which recent API requests succeeded or failed (method, path, status code, request ID), JavaScript errors your browser encountered, a content-free trail of actions such as page changes, your feature-flag configuration, and the app version | Attached to the report you submit, subject to the checkbox on the report form |
| Knowledge base content | documents, transcripts, embeddings, and metadata you upload for retrieval-augmented generation | Provided by you |
| Gmail mailbox content (when connected) | message headers, plaintext body, sanitised HTML, label state, message IDs, sender/recipient — limited to messages in INBOX that arrive after you connect | Pulled from your Google Workspace mailbox under the OAuth scopes you grant; see Section 5 |
We do not intentionally collect special-category personal data (health, biometrics, religious beliefs, etc.). If such data appears in content you upload (for example, a customer support transcript), it is processed only to the extent necessary to provide the Service and is subject to the same protections as other data.
2.1 Source of Personal Data (GDPR Art. 14)
Most Personal Data described in Section 2 is provided directly by you when you sign up, configure the Service, or upload content. However, some Personal Data we process is provided indirectly — for example, when our customers (your employer, your service provider, or a business you have contacted) upload contact records about you, sync a CRM, or have a conversation with one of our AI agents that involves you. In those cases, AI Agency acts as a processor on the customer's behalf, and the customer is the controller responsible for informing you under GDPR Art. 14. If you wish to exercise rights against your data, we will route your request to the relevant customer; you can also contact privacy@myemployees.ai and we will help you identify them.
2.2 Whether providing data is required
Where we collect Personal Data on a contractual basis (account, billing, authentication), providing that data is a requirement of using the Service — without it we cannot create your account or provide the contracted services. Where we collect Personal Data on the basis of consent (for example, marketing emails), providing that data is voluntary and you may withdraw consent at any time without affecting the lawfulness of prior processing.
3. Why we process it (legal bases under GDPR Art. 6)
| Purpose | Legal basis |
|---|---|
| Providing the Service — running AI agents, syncing CRMs, sending email, storing knowledge base, providing the dashboard | Contractual necessity (Art. 6(1)(b)) |
| Account creation, authentication, and access control | Contractual necessity (Art. 6(1)(b)) |
| Security, fraud detection, and service integrity — audit logging, rate-limiting, abuse prevention | Legitimate interest (Art. 6(1)(f)) — running a secure service |
| Service analytics and reliability — error monitoring, performance metrics, capacity planning | Legitimate interest (Art. 6(1)(f)) |
| Session recording — masked recordings of dashboard use, to reproduce reported problems and diagnose faults. All text and form inputs are masked, and chat, inbox, ticket, billing and usage areas are excluded entirely — see §11.2 | Legitimate interest (Art. 6(1)(f)) — diagnosing faults in a service you rely on, balanced against the masking described in §11.2 and the right to switch it off in §11.3 |
| Scheduling communications sensibly — detecting your time zone so scheduled emails such as your weekly summary arrive during your working day rather than in the middle of your night | Legitimate interest (Art. 6(1)(f)) — sending messages you asked for at an hour you can actually read them, balanced against the fact that we store only the current zone and never a movement history |
| Billing and invoicing | Contractual necessity (Art. 6(1)(b)) and legal obligation (Art. 6(1)(c)) |
| Marketing communications about new features and offers | Consent (Art. 6(1)(a)) — opt-in, with one-click unsubscribe |
| Service improvement — producing aggregated and de-identified statistics about how the Service is used, and using them to improve it. We do not review identifiable customer content for this purpose | Legitimate interest (Art. 6(1)(f)) — improving a service our customers rely on, balanced against the fact that the output identifies no individual and the right to object below |
| Compliance with legal obligations — responding to lawful requests, retaining tax records | Legal obligation (Art. 6(1)(c)) |
For data we process on behalf of our customers (their end-users' data), the legal basis is set by the customer in their own privacy notice. We process that data only on the customer's documented instructions, as defined in our Data Processing Agreement.
4. How we use AI
The Service uses large language models ("LLMs") and embedding models from third-party providers (Anthropic, OpenAI) to generate AI agent responses, classify intent, and retrieve relevant knowledge. When the Service sends content to those providers, the content is processed under their zero-retention API terms and is not used to train their public models. AI Agency itself does not use your Personal Data or your content to train general-purpose AI models. See our Sub-processor list for transfer mechanisms.
Automated decision-making (GDPR Art. 22)
The Service does not make decisions about you that produce legal or similarly significant effects without human oversight. AI agent outputs are intended to be reviewed and supervised by you or your service provider. If you believe an AI-generated action has affected your legal rights or has produced a similarly significant effect on you, contact privacy@myemployees.ai to request human review, an explanation of the logic involved, and the right to contest the outcome.
5. Google Workspace and Gmail data
When you connect a Google Workspace mailbox to AI Employees (currently Gmail only), we receive limited information from Google APIs scoped to what you grant during the OAuth consent flow. The scopes we request and what we do with the data are summarized below.
5.1 Scopes and uses
| Google API scope | What we receive | What we use it for |
|---|---|---|
https://www.googleapis.com/auth/gmail.modify | Read messages, send replies, and modify labels in your connected mailbox | (1) Read incoming customer emails so an AI Employee can draft, send, or assist with replies inside the AI Employees ticket flow; (2) send those replies on your behalf when you click Send; (3) apply label changes (for example, archive or mark-as-handled) that reflect your in-app actions. We do not read messages outside your INBOX label, and we do not modify mail that we did not originate. |
openid, email, profile | Your Google account ID, primary email address, and basic profile (name, picture) | Identify the connected mailbox in the dashboard so you can confirm which Google account is authorised, and detect a re-auth when you sign in to AI Employees with Google. |
5.2 Limited Use disclosure
AI Employees' use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically:
- We do not transfer or sell Google user data to third parties for advertising, ad targeting, data brokerage, market research, training general-purpose AI models, or any purpose unrelated to providing you the AI Employees Service.
- We do not allow humans to read your Google user data except (a) with your explicit consent for a specific message (for example, you ask Support to review a ticket); (b) where it is necessary for security, abuse prevention, or fraud investigation; (c) where required by applicable law; or (d) where the data has been aggregated and anonymised for internal operations.
- We use Google user data only to provide or improve the user-facing AI Employees features you have explicitly requested by connecting your mailbox.
5.3 Storage, encryption, and retention
- OAuth access and refresh tokens are encrypted at rest with AES-256-GCM using a per-tenant key derivation, stored only on AI Employees infrastructure, and never exposed to other tenants or to third parties beyond Google itself when we refresh them.
- Message metadata and content that we ingest into a ticket (headers, plaintext body, sanitised HTML) are stored under your tenant's row-level security boundary and retained on the same schedule as other conversation data — see Section 8 (How long we keep it). Original messages remain in your Google account; we do not retain copies of the raw RFC 822 message bodies.
- The Gmail watch / Pub/Sub registration stores a Google
historyIdcursor so we know which messages are new. The cursor is overwritten on every notification; nothing about the content of un-ingested messages is retained.
5.4 Disconnect and deletion
You can disconnect Gmail at any time from Settings → Integrations. On disconnect we (a) revoke the OAuth token with Google, (b) stop the Pub/Sub watch, and (c) hard-delete the access/refresh tokens and the watch cursor from our database within 30 days. Ingested ticket content remains visible in your AI Employees workspace so you can finish handling those tickets; you can purge ticket content via the dashboard or via a deletion request to privacy@myemployees.ai.
If you revoke the connection directly from your Google account at myaccount.google.com/permissions, the same effects apply on our side the next time we attempt a refresh — typically within an hour.
6. Who we share it with
We share personal data with the sub-processors listed at /subprocessors. Each sub-processor is bound by a contractual agreement that requires GDPR-equivalent protections. We do not sell personal data, and we do not share personal data with third parties for their own marketing.
We may disclose personal data when legally required (subpoena, court order, regulatory request) or to protect the rights, property, or safety of AI Agency, our users, or the public — and in connection with a corporate transaction such as a merger, in which case the acquirer will be bound by this Policy.
7. International transfers
AI Agency and most of our sub-processors are based in the United States. When personal data of EU/UK/EEA data subjects is transferred to the United States, we rely on one or more of:
- EU Standard Contractual Clauses (SCCs) with each sub-processor;
- EU-US Data Privacy Framework (DPF) for sub-processors that have self-certified;
- UK International Data Transfer Agreement (IDTA) or UK Addendum to the SCCs for UK transfers.
The transfer mechanism for each sub-processor is listed at /subprocessors. On request, we can provide copies of our SCCs or DPA at privacy@myemployees.ai.
8. How long we keep it
| Data | Retention |
|---|---|
| Account data | For the duration of your subscription, plus a 30-day grace period after account deletion |
| Audit logs | 90 days from the event timestamp, then automatically purged |
| Conversation and call transcripts | 24 months, unless you delete them sooner via the dashboard |
| Knowledge base documents | Until you delete them, or 30 days after account deletion |
| Product analytics events | 12 months from the event, then purged by our analytics sub-processor |
| Session recordings | 30 days from capture, then automatically deleted |
| Bug report diagnostics | Retained with the bug report itself; deleted when the report is deleted, and in any event within 24 months |
| Backups | Up to 35 days, automatically rotated |
| Tax / billing records | 7 years (US tax law) |
| Marketing list | Until you unsubscribe, plus a suppression record indefinitely (so we don't email you again) |
When you delete your account via the dashboard or via privacy@myemployees.ai, we soft-delete immediately (your data becomes inaccessible) and hard-delete after a 30-day grace period to allow accidental-deletion recovery. Backups containing your data continue to roll off on the schedule above.
9. Your rights under GDPR / UK GDPR
Subject to applicable law, you have the right to:
- Access — request a copy of the personal data we hold about you (Art. 15);
- Rectification — ask us to correct inaccurate or incomplete data (Art. 16);
- Erasure — ask us to delete your personal data ("right to be forgotten") (Art. 17);
- Restriction — ask us to pause processing while we investigate a complaint (Art. 18);
- Portability — receive your data in a structured, machine-readable format (Art. 20);
- Objection — object to processing based on legitimate interest, including profiling (Art. 21);
- Withdraw consent — at any time, where processing is based on consent (Art. 7(3));
- Lodge a complaint with your supervisory authority (Art. 77).
For California residents, equivalent rights are provided under the CCPA / CPRA, including the right to know, delete, correct, and opt out of "sales" or "sharing" (we do neither).
Improvement processing (Art. 21 objection). We produce aggregated and de-identified statistics about how the Service is used, and use them to improve it — the "Service improvement" legitimate interest in §3. You may object at any time — email privacy@myemployees.ai and we will exclude your workspace. Processing needed to operate, secure and support the Service continues; excluding your workspace means we will have less information available when diagnosing problems you report.
To exercise any of these rights, email privacy@myemployees.ai or use the "Export account data" and "Delete account" buttons under Settings → Account. We will respond within 30 days; complex requests may be extended once by an additional 60 days, with notice. We may need to verify your identity before fulfilling sensitive requests.
If you believe you have a privacy complaint we have not resolved, you may contact your local supervisory authority — for the UK that is the Information Commissioner's Office, and a list of EU authorities is available at edpb.europa.eu.
10. Security
We protect personal data using technical and organizational measures including:
- AES-256-GCM encryption at rest for sensitive credentials, with HKDF-SHA256 per-tenant key derivation and key rotation support;
- TLS 1.2+ encryption in transit for all customer traffic;
- PostgreSQL Row-Level Security on all tenant-scoped tables, enforced by
FORCE ROW LEVEL SECURITYand a CI coverage test — tenants cannot read each other's data even if an application bug occurred. Cross-tenant-by-design tables (portal session, admin settings, etc.) use application-layer scoping; - Audit logging covering authentication, GDPR requests, credential access, role/permission changes, and admin actions, with rollback-safe persistence so security events are recorded even if a transaction fails;
- Webhook signature verification (HMAC / Ed25519) on every inbound webhook;
- JWT-based authentication with revocation, JWKS rotation, and role-based access control.
You can read more in our public Service Status page and we describe our technical and organizational measures in detail in our Data Processing Agreement.
No security control is perfect. If you believe you have discovered a vulnerability, please email security@myemployees.ai. If a personal data breach occurs that is likely to result in a risk to your rights, we will notify you without undue delay in accordance with GDPR Art. 33–34.
11. Cookies, local storage, and session recording
11.1 What we set, and why
| Purpose | What is stored | Set by |
|---|---|---|
| Strictly necessary — keeping you signed in | Session and authentication cookies, for example portal_session for customer-portal sessions | AI Agency (first party) |
| Preferences — remembering your settings between visits | Browser local storage holding UI preferences and your last-known feature configuration | AI Agency (first party) |
| Product analytics and session recording — understanding how the dashboard is used, diagnosing errors, and reproducing reported bugs | A cookie and browser local-storage entry holding a pseudonymous visitor identifier, plus the interaction and recording data described below | PostHog (see Sub-processors) |
We do not use advertising cookies, advertising pixels, or cross-site tracking, and we do not sell or share personal data for behavioural advertising.
11.2 Session recording — what it does and does not capture
We record how the dashboard is used so we can reproduce problems that are otherwise very hard to diagnose from a written bug report. These recordings are masked by default:
- All text is masked. Every piece of text on the page — including anything you or your customers wrote — is replaced before the recording leaves your browser. A recording shows layout, cursor movement, and which elements were interacted with; it does not show readable content.
- All form inputs are masked. Anything you type into a field is never captured.
- Entire areas are excluded. Executive and department chat, the inbox, tickets and ticket detail, billing, and usage are blocked from recording completely — not masked, but omitted. Recording is stopped while you are on those pages, and their content is additionally blanked at the element level.
Recordings are held by our analytics sub-processor and are subject to the retention period in Section 8.
11.3 Your choices
- Bug report diagnostics can be turned off per report, using the checkbox on the bug-report form before you submit it.
- Browser controls. You can block or delete cookies and clear local storage through your browser settings. Blocking the strictly necessary cookies will prevent you from signing in; blocking the analytics cookie does not affect your use of the Service.
- Do Not Track / Global Privacy Control. Where your browser sends a recognised opt-out signal, we honour it for analytics and session recording.
- Switch it off entirely. Email
privacy@myemployees.aiand we will exclude your organisation from product analytics and session recording. This is enforced in the platform, not by hand: once set, your browser stops sending analytics and recording data altogether. Error monitoring needed to keep the Service running continues, and bug reports you choose to send still carry the diagnostics described on the report form.
Where applicable law requires consent for non-essential cookies or similar technologies, we will obtain it before those technologies are used; if you are reading this and have not been asked, contact privacy@myemployees.ai and we will confirm the position for your jurisdiction and disable analytics for your account on request.
12. Children's privacy
The Service is not directed to children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact privacy@myemployees.ai and we will delete it.
13. Changes to this Policy
We may update this Policy from time to time. Material changes will be communicated via email to active customer admins and posted at the top of this page with a new "Last updated" date. Your continued use of the Service after the effective date of a change constitutes acceptance of the updated Policy.
14. Contact
| Topic | |
|---|---|
| Privacy questions, data subject requests, complaints | privacy@myemployees.ai |
| Security vulnerabilities | security@myemployees.ai |
| Legal / contracts (incl. DPA requests) | legal@myemployees.ai |
| General support | support@myemployees.ai |
AI Agency Group does not currently maintain an EU-based representative. We will appoint one under GDPR Art. 27 if and when our processing activities require it.