Legal
Privacy Policy
01Who we are & scope
C3POperator.ai ("C3POperator", the "Platform") is an AI voice agent platform owned and operated by United Technology Services INC ("UTS", "we", "us", "our"). The Platform lets business customers ("Customers") build, deploy, and operate conversational AI agents that place and receive phone calls over the telephone network and in the browser via WebRTC.
This Privacy Policy describes how we collect, use, share, and protect personal information when you visit our websites, create an account, or use the Platform, and when AI agents operated by our Customers interact with people who call or are called by those agents ("End Callers").
This Policy is incorporated into and forms part of our Terms of Use.
02Our role: controller vs. processor
We act in two distinct roles:
- Data controller — for information about our website visitors and Customer account holders: account registration data, billing information, support communications, and usage analytics. For this data, we decide how and why it is processed.
- Data processor / service provider — for content processed through the Platform on a Customer's behalf: call audio, recordings, transcripts, campaign contact lists, scheduling bookings, data-table records, and knowledge-base documents ("Customer Content"). Our Customers control this data; we process it under their instructions and our agreements with them.
If you are an End Caller — someone who spoke with an AI agent powered by C3POperator — the business you interacted with controls that data. Please direct requests about call recordings, transcripts, or your personal information first to that business. We will support our Customers in honoring such requests.
03Information we collect
Account & billing data (we are the controller)
- Account information: name, email address, hashed password (we never store plaintext passwords), organization and team membership, and authentication identifiers.
- Billing information: payment transactions, credit balances, and usage records. Card details are collected and processed by our payment processor (Stripe); we store only payment references, never full card numbers.
- Usage & device data: IP address, browser and device information, pages visited, feature usage events, and log data used for security, debugging, and product analytics.
- Support communications: messages you send us and related contact details.
Platform data (we process on our Customers' behalf)
- Agent & workflow configurations: prompts, conversation flows, templates, model settings, and pre-recorded audio.
- Calls: caller and callee phone numbers, call metadata (start/end time, duration, status, disposition), call recordings and transcripts where the Customer enables them, structured data the agent gathers during a call, and call logs.
- Campaign contact lists: contact names, phone numbers, and custom fields Customers upload for outbound campaigns.
- Scheduling data: booking details such as customer name, phone number, email, and appointment notes.
- Data Tables & knowledge bases: records and documents Customers store in the Platform's built-in datastore and knowledge base, which may contain personal information the Customer chooses to store.
- Third-party credentials: API keys and tokens Customers connect (telephony, AI providers, integrations), stored for the sole purpose of operating the Customer's agents.
- Web-widget session data: IP address, user agent, and origin of end users who interact with a Customer's embedded web agent.
04How we use information
- Provide, operate, and maintain the Platform, including routing calls, running AI conversations, executing scheduling and data operations, and delivering recordings and transcripts to the Customer.
- Process payments, meter usage, and manage prepaid credits and invoicing.
- Secure the Platform: authentication, fraud and abuse detection and prevention, and enforcement of our Terms of Use.
- Monitor performance, diagnose issues, and improve reliability and quality of the Services.
- Communicate with you: transactional and operational notices, support responses, and — with your ability to opt out at any time — product news and marketing.
- Comply with legal obligations and enforce our legal rights.
Where GDPR or similar laws apply, we rely on: performance of a contract (providing the Services), legitimate interests (security, product improvement, B2B communications), consent (where required, e.g., certain marketing or cookies), and legal obligation.
05AI & model improvement
The Platform orchestrates third-party AI services (speech-to-text, large language models, and text-to-speech) to power voice conversations. Our posture on training is:
- We may use Customer Content to operate the Services and to improve Platform performance — such as speech-recognition accuracy, turn-taking, interruption handling, and latency — only in a manner that does not identify the Customer's business or any End Caller.
- We do not sell Customer Content and we do not share it with third parties for their independent model training.
- AI provider sub-processors receive Customer Content only as needed to process each conversation, under agreements or settings that restrict use to service provision.
- Where Customers connect their own AI provider accounts ("bring your own key"), the Customer's direct agreement with that provider governs that provider's use of the data.
07Data handling & security
We apply technical and organizational measures designed to protect personal information, including:
- Encryption in transit. Traffic to and within the Platform is protected with TLS/HTTPS, including secure media channels for browser-based calls.
- Tenant isolation. All Customer data is scoped to the Customer's organization; access controls are enforced at the application layer on every request.
- Credential protection. Account passwords are stored using strong one-way hashing (bcrypt). Platform API keys are stored hashed and can be expired and rotated; programmatic keys expire by default.
- Least-privilege access. Internal access to production systems and Customer Content is restricted to personnel who need it to operate and support the Services.
- Payment isolation. Card data is handled by our PCI-compliant payment processor and never touches our servers.
No method of transmission or storage is completely secure; we cannot guarantee absolute security, but we work continuously to protect your information and will notify affected Customers of any personal-data breach as required by applicable law.
08Data retention & deletion
- Account data is retained for as long as your account is active and as needed for legal, tax, and accounting obligations.
- Customer Content (recordings, transcripts, contact lists, data-table records, knowledge bases) is retained while the Customer's account remains active and per the Customer's configuration, and is deleted or de-identified upon verified deletion request or account closure, subject to legal retention requirements.
- Operational logs are kept for a short rolling window used for debugging and security.
- Billing records are retained as required by financial regulations.
Customers may delete recordings, contacts, data-table rows, and documents from within the Platform, or request deletion by contacting privacy@c3poperator.ai.
09Call recording notices
Call recording and transcription are features that each Customer controls and enables. Laws on recording and monitoring calls vary by jurisdiction, and some require the consent of all parties to the call. Customers are responsible for providing any required notices and obtaining any required consents from End Callers before recording, monitoring, or transcribing calls, as further described in our Terms of Use.
10International transfers
We are a U.S. company and process data in the United States and in other locations where we or our sub-processors operate. Where we transfer personal information from the European Economic Area, the United Kingdom, or Switzerland, we rely on appropriate safeguards such as Standard Contractual Clauses and, where applicable, adequacy decisions. We will execute a Data Processing Agreement (DPA) with Customers on request.
11Your privacy rights
All users
You may access and update your account information in the Platform, opt out of marketing at any time via the unsubscribe link or your settings, and contact us with any privacy request at privacy@c3poperator.ai.
European Economic Area, UK & Switzerland
Where GDPR or equivalent laws apply, you have the right to access, rectify, erase, restrict, and port your personal data, to object to processing based on legitimate interests, to withdraw consent at any time (without affecting prior processing), and to lodge a complaint with your supervisory authority.
United States state rights
Residents of California and other states with comprehensive privacy laws (including Colorado, Connecticut, Texas, Utah, and Virginia) have rights to know, access, correct, delete, and port personal information, to opt out of "sales" or "sharing" of personal information and targeted advertising, and to not be discriminated against for exercising these rights. We do not sell personal information for money. To exercise your rights, email privacy@c3poperator.ai; we will verify your request and respond within the legally required period. You may use an authorized agent where the law allows.
End Caller requests: where we act as a processor, we will redirect your request to the relevant Customer and support them in fulfilling it.
12Children
The Platform is a business tool and is not directed to children. You must be at least 18 years old to create an account. We do not knowingly collect personal information from children under 13 (or the equivalent minimum age in your jurisdiction), and Customers may not use the Platform to record or clone the voice of a minor. If you believe a child has provided us personal information, contact us and we will delete it.
13Changes to this policy
We may update this Policy from time to time. We will post the updated version on this page with a revised effective date, and for material changes we will provide notice — such as email to account holders or a prominent notice on the Platform — before the changes take effect. Your continued use of the Services after the effective date constitutes acceptance of the updated Policy.
14Contact us
United Technology Services INC
Privacy inquiries: privacy@c3poperator.ai
General support: support@c3poperator.ai