Privacy Policy

Last updated: August 25, 2026

This Privacy Policy explains how Oversee AI LLC ("Oversee", "we", "us") collects, uses, discloses and retains personal data in connection with the Oversee platform and the getoversee.ai website.

Two different roles — read this first

Oversee plays two distinct roles, and your rights differ depending on which applies:

When our customer's data flows through the Platform, we are a processor. A business subscribes to Oversee and connects its WhatsApp numbers, calendars and call recordings. The messages, contacts, recordings and transcripts that result belong to that business, which decides what to collect and why. Oversee only processes them on that business's instructions. If you exchanged WhatsApp messages with a company that uses Oversee, or took part in a meeting it recorded, that company — not Oversee — is the controller of your data, and your requests should go to them. We will help them respond, and we will forward requests we receive directly.

When you deal with Oversee itself, we are the controller. This covers account registration, billing, support correspondence, and browsing our website.


1. Data we collect

1.1. Account and billing data (we are the controller)

  • Name, email address and organization details supplied at registration or invitation.
  • Authentication identifiers from our identity provider. We never receive or store your password.
  • Billing contact details and a payment-card token. Full card numbers go directly to our payment processor; Oversee never receives or stores them.
  • Records of your acceptance of our Terms of Service and this Policy: the version accepted, the person who accepted, the date and time, the IP address and the user agent. We keep these as proof of agreement.
  • Support correspondence.

1.2. WhatsApp conversations (we are the processor)

Our customers connect WhatsApp Business numbers through Meta's official WhatsApp Business API. We receive, through that API:

  • message content — text, and media files including images, audio, video and documents, which we download and store in our object storage;
  • message metadata — sender phone number, direction, timestamps, delivery and read status;
  • contact names, WhatsApp profile names and phone numbers;
  • chat and group information.

When a number is connected from the WhatsApp Business app, the customer's associated contact list is imported, and the customer may additionally choose to import up to 180 days of prior conversation history.

Customers control, per contact, whether messages are stored at all and whether the AI agent replies.

1.3. Meetings and phone calls (we are the processor)

  • Where a customer connects a calendar and enables recording, a recording bot joins video meetings and captures audio and video, participant names and email addresses, and meeting metadata. The bot announces itself when joining.
  • Customers may upload phone-call recordings, or connect a telephony provider that delivers them automatically.
  • We generate transcripts with speaker separation from this audio.

1.4. Knowledge base (we are the processor)

Documents customers upload (PDF, TXT, Markdown, CSV), and the numerical vector representations we derive from them to power search.

1.5. Content generated by artificial intelligence (we are the processor)

From the data above, the Platform generates and stores: conversation summaries, topic, category, sentiment and tone classifications, action items, risk and opportunity signals, per-contact profiles and briefings, writing-style profiles, draft reply suggestions, quality evaluations and scores attributed to individual users, and prospecting match scores with rationales. Descriptions of images and transcriptions of audio are also generated so the AI can process non-text messages.

1.6. Automatically collected data

IP address, browser and device type, operating system, access times, pages viewed, and feature usage. Server logs of API requests, including source IP and user agent.

1.7. Sensitive data

We do not intentionally collect sensitive data. Because the Platform processes free-form conversations, sensitive information may appear in message content — our customers are contractually responsible for limiting what they send us.

Voice profiles. Where a customer enables voice replies, we build a voice profile for a number from audio samples of the user assigned to it, including that user's own WhatsApp voice messages, and use it to generate the assistant's audio replies. A voice profile is a biometric identifier. We act as processor: the customer decides whose voice is used and is responsible for obtaining that person's consent beforehand. A profile can be deleted at any time from the portal. We do not create faceprints or any other biometric identifier.


2. How we use data

To deliver the service: transmit and store messages; import contacts and history; record and transcribe meetings and calls; classify, summarize and analyze conversations; generate replies and drafts; evaluate quality; run prospecting scans; power semantic search; and produce reports.

To operate and secure the Platform: authenticate users, prevent abuse and fraud, monitor availability, diagnose faults, and maintain audit records.

To bill: meter usage, issue invoices and collect payment.

To communicate: service announcements, security and legal notices, and support responses. Marketing emails only where permitted, and you can unsubscribe at any time.

To improve: we analyze aggregated and anonymized data — from which no customer, user or contact can be identified — to measure and improve the Platform.

We do not use customer content to train general-purpose AI models, whether our own or our vendors'. Our AI vendors are contractually bound not to use data submitted through our accounts to train their models.


3. Legal bases

Where LGPD or GDPR applies, we rely on:

PurposeLegal basis
Providing the Platform to a customerPerformance of a contract
Billing and tax recordsLegal obligation and contract performance
Security, abuse prevention, audit logsLegitimate interest
Aggregated and anonymized product analyticsLegitimate interest
Marketing communicationsConsent
Processing on a customer's behalfThe customer's legal basis, which the customer warrants it has

4. Who we share data with

We do not sell personal data, and we do not share it for cross-context behavioural advertising.

Subprocessors. We use third parties to deliver the service — cloud infrastructure, AI model providers, meeting recording, telephony, authentication, email and payments. Each is listed, with its purpose and the data it receives, at getoversee.ai/en/subprocessors. They are contractually bound to protect the data and may use it only to provide services to us.

Workspace isolation. Data in one customer's workspace is not accessible from another.

Legal requests. We may disclose data where legally required. Our procedure, including our commitment to challenge improper requests and to notify affected users where permitted, is set out in our Law Enforcement Policy.

Corporate transactions. In a merger, acquisition or sale of assets, data may transfer. We will notify you before it becomes subject to a different policy.


5. How long we keep data

CategoryRetention
Messages, contacts and conversation metadataWhile the workspace is active, then up to 24 months
Media files received on WhatsAppSame as the message they belong to
Meeting and call recordings12 months
TranscriptsUp to 24 months
AI-derived content (summaries, profiles, scores)As long as the source data
Voice profiles (biometric) and their audio samplesUntil deleted by the customer, or on termination
Draft reply suggestions72 hours
AI agent session state24 hours after inactivity
Knowledge-base documents and their vectorsUntil deleted by the customer
Account and billing recordsTerm of the agreement plus 5 years (tax and legal)
Terms acceptance recordsTerm of the agreement plus 5 years (proof of agreement)
Access and API logs12 months
Government data request log5 years

On termination, customers have 30 days to export their content, and it is deleted from production systems within 90 days — except where retention is required by law or necessary to exercise legal rights.

Note on contact deletion: deleting a contact from a phone's address book does not delete that contact's data from the Platform. Deletion must be requested through the controller (our customer) or through the channels in Section 9.


6. Security

Data is hosted on Google Cloud Platform in the United States. We maintain:

  • encryption in transit (TLS) and at rest;
  • role-based access control and least-privilege access;
  • logical isolation between workspaces;
  • logging, monitoring and audit records;
  • vulnerability management and dependency scanning.

No system is perfectly secure. We will notify affected customers without undue delay of a security incident presenting a material risk, with the information they need to meet their own notification duties.


7. International transfers

Our infrastructure is in the United States. If you are outside the United States, your data is transferred there.

For transfers from Brazil, we rely on Article 33 of the LGPD together with the contractual safeguards in our Data Processing Addendum. For transfers from the European Economic Area and the United Kingdom, we rely on Standard Contractual Clauses.


8. Cookies

Our website uses cookies necessary for it to function and to understand aggregate usage. You can configure your browser to refuse cookies, though parts of the site may not work correctly. We do not use cookies for cross-context behavioural advertising.


9. Your rights

To exercise any right below, write to privacy@getoversee.ai. We will verify your identity before acting, and we respond within 30 days, extendable where the law allows and the request is complex.

If your data reached us through one of our customers, we are the processor. Send your request to that company. If you send it to us, we will forward it to them and assist them in responding.

9.1. Brazil (LGPD)

You have the right to confirmation of processing; access; correction of incomplete or outdated data; anonymization, blocking or deletion of unnecessary or unlawfully processed data; portability; information about with whom we share data; information about the consequences of refusing consent; revocation of consent; and review of decisions made solely on automated processing that affect your interests.

You may also lodge a complaint with the Autoridade Nacional de Proteção de Dados (ANPD).

Our data protection contact: privacy@getoversee.ai.

9.2. California (CCPA/CPRA)

In the past 12 months we have collected the categories of personal information described in Section 1: identifiers, commercial information, internet activity, geolocation inferred from IP, audio and visual information, professional information, and inferences. Sources, purposes and disclosures are described in Sections 1, 2 and 4, and retention in Section 5.

We do not sell personal information and we do not share it for cross-context behavioural advertising, and we have not done so in the preceding 12 months. We do not knowingly sell or share the personal information of anyone under 16.

You have the right to know, to delete, to correct, to opt out of sale or sharing, to limit the use of sensitive personal information, and not to be discriminated against for exercising these rights. You may use an authorized agent. We honour Global Privacy Control signals as an opt-out where applicable.

Where we act as a service provider to a business customer, requests should be directed to that business.

9.3. Other U.S. states

Residents of states with comprehensive privacy laws — including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey and Maryland — have rights to confirm processing and access, correct, delete, obtain a portable copy, and opt out of targeted advertising, sale, and certain profiling. We do not conduct targeted advertising or sell personal data.

Appeals. If we decline your request, you may appeal by replying to our decision or writing to privacy@getoversee.ai with the subject "Privacy Appeal". We will respond within 45 days with our decision and reasons. If we deny the appeal, you may contact your state Attorney General.

9.4. European Economic Area and United Kingdom (GDPR)

You have the rights of access, rectification, erasure, restriction, portability, objection to processing based on legitimate interest, and withdrawal of consent, and the right to lodge a complaint with your supervisory authority.


10. Children

The Platform is not directed to individuals under 18, and we do not knowingly collect their data. If you believe a minor has provided us with personal data, write to privacy@getoversee.ai and we will delete it.


11. Changes to this Policy

We may update this Policy. The version date appears at the top. Material changes will be announced to workspace administrators by email and signalled within the Platform before they take effect.


12. Contact

Oversee AI LLC 951 Brickell Ave, Miami, FL 33131, United States Privacy and Data Protection privacy@getoversee.ai

General enquiries: contact@getoversee.ai

Related documents: Terms of Service · Subprocessors · Data Deletion · Law Enforcement Policy