Privacy policy

What Placony holds, why, who else sees it, how long it stays, and how to have it removed. It describes how the product actually works.

1. Who is responsible

Placony, Registered address to be confirmed, operates Placony and is the controller of the account data described in section 2. For the leads a customer captures (section 3) the customer is the controller and we process that data on their instructions. Questions about this policy go to hello@placony.com.

2. What we collect about you, the customer

  • Account details: your name, email address, and the workspace name, industry, timezone and business hours you enter.
  • Your website content, which we read and index so the chat agent can answer from it, and the agent configuration you write.
  • Billing details: your plan, invoices, and the last four digits and expiry of your card. Full card numbers are held by Dodo Payments, never by us.
  • Usage: minutes used, messages sent, sign-ins, and an audit log of changes made in your workspace and by whom.
  • Support: messages you send us through the contact form or by email, with a truncated hash of the sending IP address to spot abuse.

3. What we hold about your leads

For each lead a customer captures: name, phone number, email and company where given; the page they were on; the record of how consent to contact them was obtained (the form or chat they submitted, their IP address, the time); call recordings and transcripts; the answers the AI collected; and any appointment booked.

Placony will not place an automated call to someone unless that consent record exists. Leads without it can be called only by a human decision, and that decision is logged. This exists because calling people who did not ask to be called is wrong and, in many places, illegal.

4. Why we use it

  • To run the service you bought: answering, calling, booking, and showing you the results. Legal basis: performance of a contract.
  • To bill you, to keep the service secure, and to keep records the law requires. Legal basis: legal obligation and legitimate interest.
  • To answer support requests. Legal basis: legitimate interest.
  • To email you about the service, your account, and changes to these terms. We do not send marketing email without asking first.

We do not sell personal data, we do not use it for advertising, and we do not use one customer's leads or content to train or improve anything for another customer.

5. Recordings

Calls are recorded by default, and every call opens by saying so. A customer can turn recording off for their workspace. Recordings are kept for 30 days on Starter, 90 days on Growth and one year on Scale, then deleted.

6. Who else sees it

The service runs on these providers. Each sees only what it needs for its part.

  • Supabase: database and authentication.
  • Vercel: application hosting.
  • Retell AI: telephony and the voice model.
  • OpenAI: chat answers and the search index.
  • Composio: the connections to your calendar, Slack, Gmail and Sheets.
  • Dodo Payments: payment processing, as merchant of record.

When a customer connects an integration (Google Calendar, Slack, Gmail, Google Sheets, Telegram, WhatsApp, Calendly), data flows to that service under its own terms and only for the purpose the customer chose.

7. Where it is stored and international transfers

Data is stored in the database region your workspace was provisioned in. Some providers above operate in the United States; where data leaves the region it was collected in, we rely on the provider's standard contractual clauses or an equivalent lawful transfer mechanism.

8. How long we keep it

  • Account and workspace data: for as long as the workspace exists, then deleted within 30 days of deletion.
  • Leads, transcripts and chat history: until the customer deletes the lead or the workspace.
  • Recordings: the retention period of the plan, above.
  • Invoices and billing records: seven years, as tax law requires.
  • Contact form messages: two years.

9. Cookies

We set only the cookies needed to keep you signed in and to protect forms against forgery. There are no advertising or cross-site tracking cookies, and no cookie banner because there is nothing to consent to. The embedded chat widget on a customer's site stores a session identifier in the visitor's browser so a conversation can continue across pages.

10. Your rights

You can ask for a copy of the personal data we hold about you, have it corrected, have it deleted, or object to how it is used. Email hello@placony.com and we answer within 30 days. If you are a lead whose data a Placony customer holds, contact that business first: they decide what happens to it, and we act on their instruction. You can also complain to the data protection authority where you live.

11. Deleting things

Deleting a lead deletes its calls, recordings, transcripts and chat history with it. Deleting a workspace deletes everything belonging to it. Both are immediate and cannot be undone, apart from the billing records in section 8.

12. Security

Data is encrypted in transit and at rest. Every customer's data is separated at the database level with row-level security, every change is logged, and access by our team is limited to what support requires. If a breach affects you we tell you without undue delay.

13. Children

Placony is a business tool and is not directed at anyone under 18.

14. Changes

When this policy changes, the revision date at the top changes, and material changes are emailed to the account owner. The terms of service and the refund policy sit beside this document.