PRIVACY POLICY

Last Updated: March 25, 2025

1. INTRODUCTION

This Privacy Policy ("Policy") explains how Resonant Systems LLC ("Resonant," "we," "us," or "our") collects, uses, discloses, and protects your information when you use our AI voice agent service for customer research and discovery interviews (the "Service").

1.1 Scope and Application

This Privacy Policy applies to all users of our Service and to all information collected through your interaction with our platform, website, and related services. Our Service is intended for use within the United States, and we process and store all data within the United States.

1.2 Definitions

Throughout this Policy:

a) "Personal Information" means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular individual or household.

b) "Account Information" means information provided during account registration and management.

c) "Service Usage Information" means data collected about how you interact with our Service.

d) "Interview Data" means recordings, transcripts, and related information collected during interviews conducted through our Service.

e) "Interview Subject" means any individual participating in interviews conducted through the Service who is not a user of the Service.

f) "User" or "you" means any individual or entity that registers for and uses the Service.

1.3 Policy Updates

We may modify this Privacy Policy from time to time as detailed in Section 7. Your continued use of the Service after any modification indicates your acceptance of the updated Policy.

2. INFORMATION COLLECTION AND USE

2.1 Account Information

When you create and manage your account, we collect:

a) Account Credentials:

- For direct registration: Your first name, last name, email address, and password (stored in encrypted form).

- For Google OAuth registration: Your email address (password authentication is handled by Google and not stored by us).

b) Billing Information: Company name, billing address, and payment information. Credit card data is processed securely through our payment processing partner, Stripe, and we do not store complete credit card numbers on our servers.

c) Company Information: Company size, industry, website URL, and other business details you choose to provide.

d) Account Preferences: Custom settings, notification preferences, branding options, and other configuration choices.

e) Communication Data: Records of communications between you and our customer support team.

We use Account Information to:

- Create and maintain your account

- Process payments and manage billing

- Authenticate your identity when you log in

- Customize your Service experience

- Communicate with you about your account, the Service, and updates

- Provide customer support

- Send service-related notifications

2.2 Service Usage Information

We automatically collect information about how you use our Service, including:

a) Access Logs: Dates and times of access, pages visited, features used, and session duration.

b) Device Information: Device type, operating system, browser type and version, screen resolution, and other technical identifiers.

c) Location Data: General location information derived from IP addresses (not precise geolocation).

d) Network Information: IP addresses, referring URLs, and exit pages.

e) Performance Metrics: Load times, error rates, and system performance indicators.

f) Feature Usage Patterns: How you configure and use the AI agents, frequency of interviews, and interaction patterns.

We use Service Usage Information to:

- Maintain and improve our Service

- Troubleshoot technical issues

- Monitor and ensure security

- Analyze usage patterns to enhance features

- Optimize performance and user experience

- Detect and prevent fraudulent or abusive activity

- Generate aggregated, non-identifying analytics

2.3 Interview Data

Through our Service, we collect:

a) Audio Recordings: Complete audio files of interviews conducted through our platform.

b) Transcripts: Text transcriptions of interview conversations.

c) AI Agent Configuration Data: Custom instructions, scripts, and prompts used to configure the AI agent.

d) Interview Metadata: Duration, completion status, timestamps, question sequences, and other operational data.

e) Performance Analytics: Response times, question effectiveness, interview completion rates, and similar metrics.

f) Derived Insights: Patterns, sentiment analysis, and other analytical outputs generated from interviews.

We use Interview Data to:

- Provide the core interview Service functionality

- Generate transcripts and reports for users

- Improve AI agent performance through aggregate learning

- Enhance the natural language capabilities of our system

- Generate usage statistics and performance metrics

- Analyze effectiveness of different interview approaches (in anonymized, aggregated form)

- Develop and improve AI agent empathy and responsiveness

3. DATA PROTECTION AND SECURITY

We implement appropriate technical and organizational measures to protect your information from unauthorized access, alteration, disclosure, or destruction. Our security practices include:

3.1 Technical Safeguards

a) Encryption: All data transmitted between your browser and our Service is encrypted using TLS/SSL technology. Sensitive stored data is encrypted at rest using industry-standard encryption methods.

b) Access Controls: Role-based access control systems limit data access to authorized personnel only. Multi-factor authentication is required for administrative access.

c) Infrastructure Security: Our hosting environment employs advanced firewall protection, intrusion detection systems, and regular security patching.

d) Monitoring: We maintain 24/7 monitoring systems to detect and respond to unusual activity that could indicate security incidents.

3.2 Organizational Safeguards

a) Security Policies: Comprehensive information security policies governing data handling practices.

b) Personnel Practices: Background checks for employees with data access, security awareness training, and confidentiality agreements.

c) Regular Assessments: Periodic vulnerability assessments and security reviews of our systems and practices.

d) Incident Response: Documented procedures for promptly addressing and remediating security incidents.

3.3 Limitations

While we implement reasonable security measures, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security, but we continuously work to enhance our protections.

4. DATA MANAGEMENT AND DELETION

4.1 Data Access and Control

You maintain full control over your data and can exercise the following rights through your account dashboard:

a) Access Rights: You can access and download interview transcripts, AI-generated summaries, key insights, and key quotes directly through your dashboard. Audio recordings and raw account data are not available for download.

b) Export Capabilities: Export interview data in common formats for your own records or analysis.

c) Specific Deletion: Delete specific interviews, recordings, or other data components individually.

d) Data Correction: Update and correct your account information and preferences.

4.2 Account Deletion Process

To delete your account completely:

1. Cancel any active subscription and pay any outstanding balances.

2. Request account deletion through your dashboard settings or by contacting support@useresonant.com.

3. Upon verification of your identity and account ownership, we will:

- Delete your payment information from our payment processor

- Remove your account and all associated data from our active systems

- Permanently delete all company information, agent configurations, and interview data

4. Deletion Timeline: We will process your deletion request within 14 days. Once complete, deletion is permanent and cannot be reversed.

We do not maintain backups of deleted data, and deletion is immediate and permanent once processed.

4.3 Data Retention

Unless you delete your account or specific data:

a) Account Information is retained for as long as you maintain an active account.

b) Interview Data is retained for the duration of your account.

c) Service Usage Information may be retained in anonymized form indefinitely for analytical purposes.

d) Communication records may be retained for up to seven years for business continuity, support quality, and legal compliance purposes.

5. DATA PROCESSING AND USER RESPONSIBILITIES

5.1 Our Role

We act as a data processor for interview recordings and transcripts, while functioning as a data controller for account information. In our role as a processor, we:

a) Process data only as instructed by our users through the Service interface and settings.

b) Maintain appropriate technical and organizational security measures.

c) Enable prompt data deletion upon request through self-service tools or support channels.

d) Assist users with their data protection obligations through documentation, tools, and support.

e) Process data in accordance with applicable laws and our contractual commitments.

f) Do not use interview data for purposes beyond those specified in this Policy.

5.2 User Responsibilities

As a user of our Service, you are responsible for:

a) Consent Management: Obtaining valid, documented consent from interview subjects before conducting interviews, including specific consent for:

- Participation in an AI-conducted interview

- Recording of voice and conversation

- Processing of personal information shared during the interview

- Any specific uses of the interview data you intend

b) Transparency: Providing appropriate privacy notices to interview subjects that clearly explain:

- That they will be speaking with an AI agent

- What data will be collected

- How their data will be used

- Who will have access to their information

- How long their data will be retained

- How they can exercise their rights regarding their data

c) Rights Fulfillment: Managing and responding to interview subjects' data rights requests, including:

- Access to their interview recordings and transcripts

- Correction of inaccurate information

- Deletion of their data

- Withdrawal of consent

d) Regulatory Compliance: Ensuring your use of our Service complies with all applicable data protection laws and regulations, including industry-specific requirements that may apply to your business.

e) Data Minimization: Configuring interviews to collect only the information necessary for your legitimate business purposes.

f) Security: Maintaining appropriate security for any downloaded or exported interview data.

5.3 Interview Subject Rights

While we provide tools for you to honor interview subjects' rights, you remain primarily responsible for fulfilling these requests. We will:

a) Provide technical means to access, export, and delete specific interview data.

b) Process data subject requests you relay to us within a reasonable timeframe.

6. DATA SHARING

We do not sell your personal information or interview data to third parties. We share your information only in the following limited circumstances:

6.1 Service Providers

We share data with select third-party service providers who help us operate, provide, improve, and market our Service. These include:

a) Infrastructure Providers: Cloud hosting, storage, and computing services.

b) Payment Processors: To process subscription fees and other payments.

c) Analytics Providers: To help us understand Service usage patterns.

d) Customer Support Tools: To assist with support requests and communications.

All service providers are contractually obligated to use the data only for the specific services they provide to us, maintain appropriate security, and not use data for their own purposes.

6.2 Legal Requirements

We may disclose your information if required to do so by law or in response to valid requests by public authorities (e.g., court orders, subpoenas, or government regulations). We will attempt to notify you about such requests unless prohibited by law.

6.3 Business Transactions

If we are involved in a merger, acquisition, or sale of all or a portion of our assets, your information may be transferred as part of that transaction. In such an event, we will notify you via email and/or a prominent notice on our website of any change in ownership or uses of your information, as well as any choices you may have regarding your information.

6.4 With Your Consent

We may share your information with third parties when you explicitly consent to such sharing.

6.5 Aggregated or De-identified Data

We may share aggregated, non-personal information, or de-identified data that cannot reasonably be used to identify you with third parties for industry analysis, research, and similar purposes.

7. CHANGES TO PRIVACY POLICY

7.1 Policy Updates

We may modify this Privacy Policy from time to time to reflect changes in our practices, the Service, or legal requirements. When we make changes:

a) We will update the "Last Updated" date at the top of this Policy.

b) We will notify you of material changes through:

- A prominent notice in your dashboard

- Email notification to your registered email address

- In-app notifications when you next log in

c) For significant changes, we will provide at least 30 days' notice before the changes take effect.

7.2 Acceptance of Changes

Your continued use of the Service after the effective date of a revised Policy constitutes your acceptance of the changes. If you do not agree to the revised Policy, you should discontinue use of the Service and delete your account as described in Section 4.2.

8. CHILDREN'S PRIVACY

8.1 Age Restrictions

Our Service is not intended for use by children under 13 years of age, and we do not knowingly collect personal information from children under 13. If you are under 13, please do not use the Service or provide any information on or through the Service.

8.2 Parental Notice

If we learn we have collected personal information from a child under 13 without verification of parental consent, we will take steps to delete that information as quickly as possible. If you believe we might have any information from or about a child under 13, please contact us at support@useresonant.com.

9. ADDITIONAL INFORMATION

9.1 Cookies and Similar Technologies

We use cookies and similar technologies to enhance your experience with our Service:

a) Essential Cookies: Required for the Service to function properly.

b) Functional Cookies: Remember your preferences and settings.

c) Analytics Cookies: Help us understand how users interact with our Service.

You can manage cookie preferences through your browser settings. Blocking essential cookies may impact the functionality of the Service.

9.2 Do Not Track Signals

We do not currently respond to "Do Not Track" signals from web browsers as there is no consistent industry standard for compliance.

9.3 California Privacy Rights

California residents may have additional rights regarding their personal information under California law. Please contact us for more information about specific rights that may apply.

9.4 Data Breach Notification

In the event of a data breach that compromises the security of your personal information, we will:

a) Investigate the incident and take remedial measures

b) Notify affected users without undue delay

c) Provide information about the breach, including the categories of data affected and steps we are taking to address the incident

d) Comply with all legal notification requirements

10. CONTACT INFORMATION

For questions about this Privacy Policy or our data practices, please contact us at:

Resonant Systems LLC

support@useresonant.com