Privacy Policy
This Privacy Policy explains how *AI Build Agents* app of Jewelry Website Designers Agency, operated by SOS Web Design LLC, a company based in Linden, Michigan, USA, collects, uses, discloses, and protects information in connection with our software-as-a-service platform available at https://www.ai.jewelrywebsitedesigners.com, which allows registered clients — including agencies and companies ("Clients," "you") — to create, configure, and deploy AI-powered voice agents using third-party AI and speech technologies, including OpenAI and Deepgram.
This Policy applies to the Service itself. It does not govern the privacy practices of Clients or of any end users that a Client's voice agents interact with ("End Users" / "Callers"), except where noted below.
---
1. Scope and Roles
Our Service is a B2B platform. Our direct customers are Clients (agencies/companies), who in turn may deploy voice agents that interact with their own customers or callers.
- As to Clients: We act as the data controller for account, billing, and platform-usage information.
- As to End Users/Callers who interact with a Client's voice agent: We generally act as a data processor / service provider on behalf of the Client, who controls what the voice agent is used for and what disclosures or consents are obtained from callers. Clients are responsible for ensuring their own use of the Service complies with applicable law, including obtaining any consents required from their End Users (see Section 8).
2. Information We Collect
2.1 Information You Provide
- Account details: name, business/agency name, email address, phone number, billing address.
- Payment information (processed by our third-party payment processor; we do not store full card numbers).
- Configuration data you input to build voice agents: scripts, prompts, knowledge base content, call flows, phone numbers, integrations, and API keys you connect (e.g., your own OpenAI/Deepgram keys, if applicable).
- Support communications.
2.2 Information Collected Through Use of the Service
- Call audio and transcripts: When a voice agent created on our platform is used, the audio of the call and/or its transcript may be processed and, depending on your configuration, temporarily or persistently stored to provide the Service (e.g., call logs, analytics, quality review, transcript generation).
- Metadata: call duration, timestamps, phone numbers or caller IDs (where applicable), call outcomes, and agent performance metrics.
- Usage data: log data, device/browser information, IP address, pages visited, and actions taken within the platform dashboard.
- Cookies and similar technologies: used for authentication, session management, and analytics (see Section 9).
2.3 Information from Third Parties
- Data received from integrations you authorize (e.g., CRM systems, telephony providers, calendar tools).
- Data from our sub-processors, described in Section 4.
3. How We Use Information
We use collected information to:
- Provide, operate, maintain, and improve the Service;
- Process voice input/output through third-party AI models (speech-to-text, text-to-speech, and language models) to power your voice agents;
- Generate call transcripts, summaries, and analytics for Clients;
- Process payments and manage subscriptions/billing;
- Provide customer support and respond to inquiries;
- Detect, prevent, and investigate fraud, abuse, or violations of our Terms of Service;
- Comply with legal obligations; and
- Send administrative communications (service updates, security notices) and, where permitted, marketing communications (opt-out available at any time).
We do not use call audio or transcript content to train our own general-purpose AI models without your explicit, separate consent. Note that our third-party AI subprocessors have their own data usage terms, described below.
4. Third-Party Service Providers (Sub-Processors)
To deliver the Service, we rely on third-party providers who may process data on our behalf, including but not limited to:
| Provider | Purpose |
|---|---|
| OpenAI | Natural language understanding/generation powering conversational AI logic |
| Deepgram | Speech-to-text (transcription) and/or text-to-speech processing |
| Telephony/SIP providers (e.g., Twilio-type carriers, if applicable) | Call routing and telephony infrastructure |
| Cloud hosting providers | Application hosting and data storage |
| Payment processor | Subscription billing |
| Analytics providers | Product usage analytics |
These providers process data under their own privacy policies and data processing terms, and may process data outside your country of residence, including in the United States. We enter into appropriate data processing agreements with sub-processors where required. A current list of sub-processors is available upon request at [info@soswebdesign.com].
4.1 Google Workspace API Services and Limited Use Disclosure
Our application does not access, request, or interact with Google Workspace products such as Gmail, Google Drive, Google Docs, or Google Contacts, and does not access, request, or interact with Google Photos data in any way.
The only Google integration our Service uses is the Google Calendar API, and only through the narrow https://www.googleapis.com/auth/calendar.events scope. This scope is used exclusively to perform three core actions that an End User explicitly requests during a live phone call or chat session with a Voice Agent:
- Check Availability — reading existing calendar events solely to identify open time slots and prevent double-booking.
- Create Bookings — creating a new calendar event when an End User successfully books an appointment through the Voice Agent.
- Manage Existing Bookings — updating or deleting a calendar event when an End User explicitly asks to reschedule or cancel their own appointment.
We request this specific scope, rather than a narrower read-only scope, because a read-only scope would prevent the Voice Agent from writing, modifying, or deleting appointments as directly instructed by the End User — which is the core function of the Service.
Our use and transfer of any information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- We do not use Google user data — including Calendar event data, whether raw, aggregated, or derived — to develop, train, or improve foundational or generalized artificial intelligence or machine learning models, whether our own or any third party's (including OpenAI or Deepgram models).
- We do not sell Google user data.
- We do not transfer Google user data to any third party, except: (a) where necessary to provide or improve user-facing features that were requested by and are prominently visible to the End User (e.g., confirming a booked appointment time back to them); (b) to comply with applicable law, regulation, or legal process; or (c) as part of a merger, acquisition, or asset sale, in which case the receiving entity remains bound by these same restrictions.
- We do not use Google user data for serving advertisements of any kind, including retargeted, personalized, or interest-based advertising.
- Any incidental AI processing (via OpenAI, Deepgram, or similar) during a call or chat session is limited to interpreting the End User's spoken or typed scheduling request (e.g., "book me for 3pm Tuesday") so it can be translated into the corresponding Calendar API call in real time. Calendar data is not stored by, or used to train, any underlying AI model beyond what is strictly necessary to complete that single, user-initiated scheduling action.
- Human access to Google Calendar data obtained through this scope is limited to instances necessary for security purposes, to comply with law, or with your explicit consent for support/debugging — never to train AI/ML models.
5. How We Share Information
We do not sell personal information. We may share information:
- With sub-processors as described above, strictly to provide the Service;
- With Clients, regarding data generated by their own voice agents;
- With professional advisors (legal, accounting) as needed;
- With law enforcement or regulators when required by law, subpoena, or legal process;
- In connection with a merger, acquisition, financing, or sale of assets, subject to standard confidentiality protections;
- With your consent, or at your direction (e.g., via an integration you enable).
6. Data Retention
We retain account and billing information for as long as your account is active and as needed to comply with legal, tax, and accounting obligations. Call recordings and transcripts are retained according to the retention settings configured by the Client, or, absent a specific configuration, for [X days/months — specify your default, e.g., 90 days], after which they are automatically deleted unless retention is required by law or an active dispute. Clients may request deletion of their data at any time, subject to Section 8 responsibilities.
7. Data Security
We implement industry-standard technical and organizational measures — including encryption in transit, access controls, and monitoring — to protect information against unauthorized access, alteration, disclosure, or destruction. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
8. Client Responsibilities Regarding End Users / Call Recording
Because Clients configure and control what their voice agents say and do, Clients are solely responsible for:
- Providing any legally required notice to, and obtaining any consent from, End Users/Callers before recording or processing their voice, including compliance with state and federal call-recording and wiretap laws (many U.S. states require two-party/all-party consent);
- Complying with the Telephone Consumer Protection Act (TCPA), CAN-SPAM, CTIA guidelines, Do-Not-Call registries, and equivalent laws in their jurisdiction and their End Users' jurisdictions when using voice agents for outbound calling, marketing, or automated communications;
- Ensuring lawful bases exist for any processing of End User personal data, including under GDPR, CCPA/CPRA, or other applicable privacy laws;
- Including appropriate disclosures (e.g., "this call may be recorded," "you are speaking with an AI assistant," where required by law) in their own call scripts.
We provide tools that may assist with disclosures (e.g., configurable consent messages), but the legal adequacy of any such disclosure is the Client's responsibility.
9. Cookies and Tracking
We use cookies and similar technologies on our dashboard/website for authentication, session persistence, preference storage, and product analytics. You can control cookies through your browser settings; disabling certain cookies may affect functionality.
10. Your Privacy Rights
Depending on your location, you may have rights to:
- Access, correct, or delete personal information we hold about you;
- Object to or restrict certain processing;
- Request portability of your data;
- Withdraw consent where processing is based on consent;
- Lodge a complaint with a supervisory authority.
To exercise these rights, contact us at [info@soswebdesign.com]. If you are an End User of a Client's voice agent and want to exercise privacy rights over data collected via that agent, please contact the Client directly, as they control that data; we will assist Clients in fulfilling such requests as required by our data processing terms.
California Residents (CCPA/CPRA)
California residents may have additional rights, including the right to know categories of personal information collected, the right to delete, the right to opt out of "sale" or "sharing" of personal information (we do not sell personal information), and the right to non-discrimination for exercising these rights.
European Users (GDPR)
If you are located in the European Economic Area or UK, we process personal data on legal bases including contract performance, legitimate interests, consent, and legal obligation. International transfers of data outside the EEA/UK are safeguarded via appropriate mechanisms such as Standard Contractual Clauses.
11. Children's Privacy
The Service is intended for business use by adults and is not directed at children under 16. We do not knowingly collect personal information from children. If you believe a child has provided us information, contact us to request deletion.
12. International Data Transfers
Because our infrastructure and sub-processors (including OpenAI and Deepgram) may operate in the United States and other countries, your information may be transferred to, stored, and processed in countries other than your own, which may have different data protection laws than your jurisdiction.
13. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be notified via the dashboard or email prior to taking effect. Continued use of the Service after changes take effect constitutes acceptance of the revised Policy.
## 14. Contact Us
SOS Web Design LLC
Email: info@soswebdesign.com
Linden, MI 48451
• Tel. 810-750-8082
• Fax 866-630-5937