Back to Home

Privacy Policy

Last updated: June 15, 2025

Introduction

DIYAI ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our conversational AI agent software and related services (collectively, the "Service").

We take your privacy seriously and have implemented robust measures to ensure the security and confidentiality of your data. By accessing or using our Service, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy.

Please read this Privacy Policy carefully. If you do not agree with the terms of this Privacy Policy, please do not access the Service.

Information Collection

We collect several types of information from and about users of our Service, including:

Personal Information

We may collect personally identifiable information, such as:

  • Name, email address, telephone number, and other contact details
  • Billing information and transaction data
  • Business information (company name, role, industry)
  • Account credentials
  • User preferences and settings

Usage Data

We automatically collect certain information when you access or use our Service:

  • IP address, device information, and browser type
  • Pages visited and features used
  • Time spent on the Service and interaction patterns
  • Conversation data and AI interactions
  • Performance metrics and error logs

Customer Communication Data

When you use our AI agent to manage customer communications, we process:

  • Call recordings and transcripts
  • Chat logs and email correspondence
  • Customer contact information
  • Appointment scheduling data
  • Customer inquiries and service requests

How We Use Your Information

We use the information we collect for various business and operational purposes:

Purpose Data Used Legal Basis
Providing and improving the Service Personal information, usage data, communication data Performance of contract
Processing transactions Personal information, billing information Performance of contract
Customer support Personal information, communication data Legitimate interest
Marketing and communications Personal information, usage data Consent or legitimate interest
AI training and improvement Usage data, communication data (anonymized) Legitimate interest
Security and fraud prevention Personal information, usage data Legal obligation, legitimate interest

Important Notice on AI Training

While we may use anonymized data to improve our AI models, you can opt out of having your data used for training purposes at any time through your account settings or by contacting our support team.

Data Security Measures

We implement robust security measures to protect your personal information from unauthorized access, alteration, disclosure, or destruction:

Encryption

All data is encrypted in transit using TLS and at rest using AES-256 encryption standards.

Access Controls

Strict access controls and authentication mechanisms limit data access to authorized personnel only.

Secure Infrastructure

Our services run on AWS infrastructure with comprehensive security protocols and compliance certifications.

Monitoring

Continuous monitoring systems detect and respond to suspicious activities and potential security threats.

Despite our best efforts, no method of transmission over the Internet or electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your personal information, we cannot guarantee its absolute security. You are responsible for maintaining the confidentiality of your account credentials.

Cookie Policy

We use cookies and similar tracking technologies to track activity on our Service and hold certain information. Cookies are files with a small amount of data that may include an anonymous unique identifier.

Types of Cookies We Use

Essential Cookies

Required for the Service to function properly, including authentication and security.

Preference Cookies

Remember your preferences and settings for a better user experience.

Analytics Cookies

Help us understand how visitors interact with the Service to improve functionality.

Marketing Cookies

Track your browsing habits to deliver targeted advertising.

Cookie Management

You can instruct your browser to refuse all cookies or to indicate when a cookie is being sent. However, if you do not accept cookies, you may not be able to use some portions of our Service.

You can manage your cookie preferences through our Cookie Consent Manager, which appears when you first visit our site and can be accessed at any time through the "Cookie Settings" link in the footer.

Your Rights

Depending on your location, you may have certain rights regarding your personal information:

Right to Access

You can request copies of your personal information that we hold.

Right to Rectification

You can ask us to correct inaccurate personal information or complete incomplete information.

Right to Erasure

You can ask us to delete your personal information in certain circumstances.

Right to Restrict Processing

You can ask us to limit the processing of your information in certain circumstances.

Right to Data Portability

You can ask us to transfer your information to another organization or to you.

Right to Object

You can object to the processing of your personal information in certain circumstances.

How to Exercise Your Rights

To exercise any of these rights, please contact us using the information provided in the "Contact Information" section. We will respond to your request within 30 days.

We may need to verify your identity before processing your request. In some cases, we may have legal grounds to deny your request, but we will explain our reasoning if this occurs.

Third-Party Sharing

We may share your information with third parties in the following circumstances:

Service Providers

We may employ third-party companies and individuals to facilitate our Service, provide the Service on our behalf, perform Service-related tasks, or assist us in analyzing how our Service is used.

These third parties have access to your personal information only to perform these tasks on our behalf and are obligated not to disclose or use it for any other purpose.

Business Transfers

If DIYAI is involved in a merger, acquisition, or asset sale, your personal information may be transferred. We will provide notice before your personal information is transferred and becomes subject to a different Privacy Policy.

Legal Requirements

We may disclose your personal information if required to do so by law or in response to valid requests by public authorities (e.g., a court or a government agency).

With Your Consent

We may share your personal information with third parties when we have obtained your explicit consent to do so.

Third-Party Service Providers

Our current key third-party service providers include:

  • Amazon Web Services (hosting and infrastructure)
  • Stripe (payment processing)
  • Google Analytics (usage analytics)
  • Twilio (communication services)
  • Zendesk (customer support)

Regulatory Compliance

We are committed to complying with applicable data protection laws and regulations:

GDPR Compliance

For users in the European Economic Area (EEA), we comply with the General Data Protection Regulation (GDPR). This includes:

  • Providing clear legal bases for processing your data
  • Implementing appropriate technical and organizational measures
  • Honoring data subject rights
  • Maintaining records of processing activities
  • Conducting data protection impact assessments when necessary

HIPAA Compliance

For healthcare customers in the United States, we offer HIPAA-compliant services:

  • We execute Business Associate Agreements (BAAs) with covered entities
  • We implement all required administrative, physical, and technical safeguards
  • We maintain an incident response plan for potential breaches
  • We conduct regular security risk assessments
  • We provide audit logs and access controls for PHI

CCPA/CPRA Compliance

For California residents, we comply with the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA):

  • We provide notice of collection and processing activities
  • We honor consumer rights to access, delete, and opt out
  • We do not sell personal information without explicit consent
  • We maintain reasonable security procedures
  • We provide a "Do Not Sell My Personal Information" option

Contact Information

If you have any questions about this Privacy Policy or our data practices, please contact us:

DIYAI, Inc.

123 AI Boulevard, Suite 500
San Francisco, CA 94105

privacy@diyai.com

+1 (800) 555-DIYAI

Data Protection Officer: Jane Smith

Changes to This Privacy Policy

We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date at the top of this Privacy Policy.

You are advised to review this Privacy Policy periodically for any changes. Changes to this Privacy Policy are effective when they are posted on this page.

For significant changes, we will provide a more prominent notice, which may include email notification to our registered users.