Chatley AI — AI Agents for Calls, Chat & Messaging

Privacy Policy

Transparent, verified privacy practices for the Chatley platform, detailing roles, sub-processors, encryption standards, and retention schedules.

Effective Date: April 15, 2026
Last updated: April 15, 2026

Introduction & Scope

This Privacy Policy governs your access to and use of the Chatley.ai website, applications, APIs, products, and services (collectively, the “Services”). The Services are operated by Chatley AI, Inc., a Delaware corporation (“Chatley,” “Company,” “we,” “our,” or “us”).

Our Roles: Data Controller vs. Data Processor

Depending on how you interact with our platform, our legal role under data protection laws (including the GDPR, UK GDPR, and California CPRA) is defined as follows:

  • Chatley as Data Controller: We act as the Data Controller for direct account registration details (names, business emails, passwords), direct billing and transaction records, and direct website visitor logs and marketing inquiries.
  • Chatley as Data Processor (or Service Provider): For all conversational content, voice audio recordings, call transcripts, SMS message bodies, customer contact phone numbers, and custom AI agent workflows configured and transmitted by our business customers, Chatley acts strictly as a Data Processor. Our business customer is the Data Controller who decides what data is collected and how it is processed.

Table of Contents

  1. 1. Information We Collect
  2. 2. How We Use Your Information & AI Disclosure
  3. 3. How We Share Information & Verified Sub-processors
  4. 4. Cookies and Tracking Technologies
  5. 5. Data Security and Encryption
  6. 6. Incident Notification Procedures
  7. 7. Data Retention Schedule
  8. 8. Your Privacy Rights & Response Timelines
  9. 9. Data Processing Addendum (DPA) & International Transfers
  10. 10. Children's Privacy
  11. 11. Changes to This Privacy Policy
  12. 12. Contact Information

1. INFORMATION WE COLLECT

We collect information directly from you, automatically when you interact with our platform, and through our authorized business integrations:

1.1 Personal Information You Provide

  • Account Registration Data: Name, work email address, telephone number, business name, and authentication credentials.
  • Payment and Billing Details: Billing address and payment transaction tokens. Credit and debit card details are processed directly by our PCI-DSS Level 1 certified payment provider (Stripe, Inc.) and are never stored on Chatley servers.
  • Communications and Support: Content of feedback, technical support tickets, and scheduling communications.
  • Customer Configurations: System prompts, knowledge base documents, agent rules, and API connection keys you provide to configure AI agents.

1.2 Voice Audio, Transcripts, and Wiretap Disclosures

When your AI agents handle inbound or outbound telephone calls, audio data is transmitted, processed into text transcriptions, and analyzed in real time to generate conversational responses:

  • Call Recording & Wiretap Consent: The Chatley platform provides technical recording and transcription capabilities at your command. As the Data Controller, you represent, warrant, and agree that you are solely responsible for complying with all applicable federal, state, and international wiretapping, eavesdropping, and call-recording consent laws (such as the California Invasion of Privacy Act / CIPA, Illinois BIPA, and Florida Security of Communications Act). You must provide clear and prominent prior notice (e.g., “This call may be recorded for quality assurance”) before audio recording or transcription commences.
  • No Voice Biometric Identification: Voice audio is processed strictly to provide acoustic speech-to-text transcription and conversational generation. Chatley does not use voice audio to create voiceprints or perform biometric identification or verification.

1.3 Automatically Collected Usage Data

  • Telephony & Transmission Metrics: Call duration, timestamp, carrier error codes, SMS delivery statuses, and latency data.
  • System & Web Logs: IP address, browser type, operating system, referring URLs, and security event logs.

2. HOW WE USE YOUR INFORMATION & AI DISCLOSURE

We process information for the following legitimate business purposes:

  • Operating, hosting, and delivering our voice, web chat, and SMS agent platform.
  • Processing payments, subscription renewals, and administrative invoices.
  • Providing technical support, operational monitoring, and platform security.
  • Complying with regulatory obligations and legal requests.

Artificial Intelligence & Model Training Disclosures

Chatley AI utilizes advanced large language and speech models to interpret caller queries and synthesize real-time voice responses. We maintain strict data boundary policies:

  • No Foundational Model Training: We do not sell your customer data, transcripts, or call audio. Our core AI infrastructure partners are contractually prohibited from using your workspace conversation data to train their foundational public models.
  • Aggregated Analytics: We may analyze de-identified, aggregated usage statistics (such as average call duration, latency, and system error rates) to improve system reliability.
  • Zero-Retention Options: Enterprise customers with stringent compliance obligations may request zero-data-retention configurations via written addendum.

3. HOW WE SHARE INFORMATION & VERIFIED SUB-PROCESSORS

We do not sell personal data. To provide our real-time platform, we share data with verified third-party sub-processors under written data processing terms that meet or exceed applicable privacy laws.

3.1 Verified Sub-processor Directory

Every vendor listed below has been verified against our live production architecture. We do not maintain unverified claims:

Sub-processor Role / Service Location Security / Compliance
Amazon Web Services, Inc. (AWS) Cloud hosting, compute, object storage (S3) United States SOC 2 Type II, ISO 27001, HIPAA compliant
MongoDB, Inc. (Atlas) Cloud document database & encrypted storage United States SOC 2 Type II, ISO 27001, AES-256 at rest
Vapi, Inc. Voice AI orchestration, audio streaming & LLM pipeline United States SOC 2 Type II, HIPAA eligible, zero-training terms
Twilio, Inc. Telephony carrier, PSTN connectivity, SMS routing United States SOC 2 Type II, ISO 27001, CTIA/10DLC compliant
Stripe, Inc. Payment processing, subscription billing portal United States PCI-DSS Level 1 Service Provider
Cloudflare, Inc. Edge CDN, DDoS prevention, Turnstile bot verification Global / US SOC 2 Type II, ISO 27001
LeadConnector / GoHighLevel Interactive demo scheduling calendar widget United States Consent-gated; loaded only on demo requests
Google LLC (Google Analytics 4) Website traffic analytics (G-9V07PREMR5) United States Consent Mode v2 gated, max 14-month retention
Meta Platforms, Inc. (Meta Pixel) Marketing conversion attribution United States Explicit opt-in gated, 90-day retention

To receive automated notifications of sub-processor updates or to execute a Data Processing Addendum (DPA), please contact our security team at security@chatley.ai.

3.2 SMS Messaging Data Protection

Mobile telephone numbers collected strictly for SMS messaging consent are used exclusively for sending authorized communications. We do not sell, rent, or share mobile phone numbers or SMS consent records with third parties for their own marketing purposes.

4. COOKIES AND TRACKING TECHNOLOGIES

We use strictly necessary cookies for platform security, and optional functional, analytics, and marketing cookies only after affirmative user consent.

For our complete, itemized tracker inventory with provider domains, lifespans, and granular controls, please view our dedicated Cookie Policy.

5. DATA SECURITY & ENCRYPTION STANDARDS

We implement technical and organizational security controls designed to safeguard your information against unauthorized access, loss, or misuse:

  • Encryption in Transit: All web, API, and WebSocket communications are encrypted using Transport Layer Security (TLS 1.2 or higher). Telephony signaling and media streams utilize SIP-TLS and Secure Real-Time Transport Protocol (SRTP) where supported by terminating carriers.
  • Encryption at Rest: Customer database records and audio assets are encrypted at rest using industry-standard Advanced Encryption Standard (AES-256) through our certified cloud storage providers (AWS KMS and MongoDB Atlas encrypted engines).
  • Security Certifications & Architecture: Chatley operates on top of third-party cloud infrastructure certified under SOC 2 Type II, ISO 27001, PCI-DSS Level 1, and HIPAA compliance standards. Our application layer adheres to rigorous security standards and is currently undergoing SOC 2 Type II readiness.
  • Access Controls: Role-based access controls (RBAC) and mandatory multi-factor authentication (MFA) are enforced for all administrative and operational access.

6. INCIDENT NOTIFICATION PROCEDURES

We maintain written incident response and business continuity plans. In the event of a confirmed security incident or data breach resulting in unauthorized disclosure or destruction of customer personal data:

  • Customer Notification: We will notify affected account owners without undue delay, and no later than 72 hours after becoming aware of the breach, in accordance with applicable legal requirements.
  • Notification Content: The notification will describe the nature of the incident, the categories of data affected, immediate mitigation steps taken, and recommendations for affected individuals.
  • Regulatory Coordination: We will cooperate with applicable supervisory authorities and law enforcement in accordance with mandatory reporting thresholds.

7. DATA RETENTION SCHEDULE

We retain information only for as long as necessary to fulfill the purposes set out in this Policy, satisfy contractual commitments, and comply with legal requirements:

Data Category Retention Period Disposal Method
Account & Profile Data Active subscription term + 90 days after account termination Database purge; backup snapshots rotate out within 30 days
Call Audio & Transcripts Customer-configured (default 30 days; 0-day retention available for Enterprise) Automated programmatic deletion from object storage and database
Telephony & SMS Logs Up to 90 days for troubleshooting and fraud prevention Automated log lifecycle purge
Billing & Tax Records Up to 7 years in accordance with statutory accounting requirements Secure archival in PCI-compliant financial repository
Website Analytics (GA4) Maximum 14 months (Google Consent Mode v2 enforced) Automated Google Analytics retention expiration
Marketing Tracking (Meta) Up to 90 days (consent-gated) Automatic cookie expiration

8. YOUR PRIVACY RIGHTS & RESPONSE TIMELINES

Depending on your jurisdiction, you possess specific statutory rights regarding your personal information:

  • Right to Know / Access: Request disclosure of categories and specific pieces of personal information collected.
  • Right to Rectification: Request correction of inaccurate personal data.
  • Right to Deletion: Request erasure of your personal data, subject to lawful retention exceptions.
  • Right to Restrict or Object: Restrict or object to certain processing operations.
  • Right to Data Portability: Obtain your personal data in a structured, machine-readable format.
  • Non-Discrimination: We will never discriminate against you for exercising your lawful privacy rights.

Statutory Response Timelines

  • California Residents (CCPA/CPRA): We will confirm receipt of your verifiable consumer request within 10 business days and provide substantive response within 45 calendar days. If reasonably necessary, we may extend this period by an additional 45 calendar days with advance written notice explaining the delay.
  • EEA / UK Residents (GDPR): We will respond without undue delay and at least within 30 calendar days of receiving your request. For complex requests, this timeline may be extended by up to two additional months in accordance with Article 12(3) GDPR.
  • General Inquiries: All general privacy inquiries are answered within 30 days.

To submit a request, contact our privacy team at security@chatley.ai. If you are an end-user caller seeking deletion of conversation data handled by an AI agent operated by a Chatley business customer, please direct your request to the business that operates that agent (the Data Controller).

9. DATA PROCESSING ADDENDUM (DPA) & INTERNATIONAL TRANSFERS

Chatley is headquartered in the United States and our primary production servers are located in U.S. data centers.

Data Processing Addendum (DPA): We provide a standardized Data Processing Addendum incorporating the European Commission's Standard Contractual Clauses (SCCs) and UK International Data Transfer Addendum to govern international transfers of customer data. Customers subject to GDPR, UK GDPR, or CPRA may request and sign our DPA by emailing security@chatley.ai.

10. CHILDREN'S PRIVACY

Our Services are strictly designed for businesses and adults aged 18 and older. We do not knowingly solicit or collect personal information from children under 13 (or under 16 in the EEA/UK). If you become aware that a child has provided us with personal information, please alert us at security@chatley.ai so we can delete the data immediately.

11. CHANGES TO THIS PRIVACY POLICY

We may update this Privacy Policy from time to time to reflect changes in our legal obligations, platform features, or operational reality. If we make material modifications, we will notify registered account administrators via email or prominent website banner prior to the changes taking effect.

12. CONTACT INFORMATION

For any questions, requests, or notices regarding this Privacy Policy or our security practices, contact:

Chatley AI, Inc., a Delaware corporation

252 NW 29th St, Miami, FL 33127

Data Protection & Security: security@chatley.ai

General Legal Inquiries: security@chatley.ai