Privacy Policy
This is an unreviewed engineering stub. The wording is not legal advice and is not binding. Every [BRACKETED]item needs counsel's input. It is not enforced against customers until reviewed and this banner is removed.
This document is a draft pending final legal review. It reflects our current practices and is provided for transparency.
Effective date: 2026-06-21 · Version: 2026.06.21-draft
This Privacy Policy explains how 30th Century Media Holdings Corp ("Agent Dojo," "we") collects, uses, and shares personal information in connection with the Service. For personal data we process on a customer's behalf as a processor, the Data Processing Agreement and the customer's own privacy notice govern.
Jurisdiction, scope, and responsibility
Agent Dojo is operated by 30th Century Media Holdings Corp, a California, USA corporation, and the Service is provided — and personal data processed — from the United States. This Policy and your use of the Service are governed by the laws of the State of California and the United States, consistent with the Terms of Service. If you access the Service from outside the United States, you understand that your information is processed in the United States and you consent to that processing.
Agent Dojo's customers operate in multiple countries. For most personal data — including trainees' call recordings, transcripts, and scores — Agent Dojo acts as a processor on the customer's behalf and the customer is the controller. As between Agent Dojo and the customer, the customer is solely responsible for determining which laws apply to it and its Users — including data-protection, call-recording/consent, biometric, and employment laws — and for complying with them, including giving all required notices and obtaining all required consents (see Terms §11 and the DPA). The customer uses the Service at its own risk in its jurisdiction and is responsible for its and its Users' lawful use of the Service.
Where a customer or its end users are subject to particular laws — for example the Philippine Data Privacy Act (RA 10173), the GDPR/UK GDPR, CCPA/CPRA, or HIPAA — the protective provisions of this Policy and the DPA apply in addition to, not in place of, those laws, and the customer remains responsible for its own controller obligations under them. Agent Dojo does not direct the Service to, or offer it as a direct service to, consumers or to residents of the EEA/UK.
This section allocates responsibility for legal compliance between Agent Dojo and its customers; it does not limit rights that applicable law grants to individuals, and Agent Dojo's liability is limited as set out in the Terms.
Who this applies to
This notice covers personal information of website visitors, account holders, and Users of the Service. Where Agent Dojo acts as a processor for a customer (for example, trainees' call recordings, transcripts, and scores), the customer is the controller of that data and is responsible for notifying its Users and handling their requests — individuals should consult the customer's privacy notice for that data. Agent Dojo acts as a controller only for the data whose purposes it determines — such as account, billing, and website-visitor data — which this Policy covers.
Categories of data we collect
- Account data — name, work email, organization, role.
- Usage data — sessions, scores, progress, log and device metadata (IP, browser, timestamps).
- Voice data — audio of mock calls and uploaded call recordings, and their transcripts (processed on the Tenant's behalf — see the DPA).
- Learning data — course progress, quiz and assessment responses, and certificates.
- Billing data — plan, billing contact, payment-processor identifiers (your Stripe customer/subscription IDs), and the card brand and last four digits retained for display. Card details are entered with and held by our payment processor (Stripe); full card numbers, security codes, and expiry never reach Agent Dojo's systems.
- Support and communications — messages you send us.
How we use it
To provide, secure, maintain, and improve the Service; to score calls and generate feedback; to authenticate Users and prevent abuse; to process payments; to communicate about the account and respond to support; and to comply with law. We use analytics and product telemetry only with consent where required (see the Cookie Policy). We do not sell personal information.
Legal bases (GDPR/UK GDPR)
Where the GDPR applies and we act as a controller, we rely on:
- Performance of a contract — to create your account and provide the Service.
- Legitimate interests — to secure, maintain, and improve the Service and prevent abuse (balanced against your rights).
- Consent — for analytics/marketing cookies and optional communications (withdrawable at any time).
- Legal obligation — to meet tax, accounting, and legal requirements.
Sharing
We share personal information with subprocessors that help us run the Service (see Subprocessors), with professional advisors, in a corporate transaction, and where required by law. Each subprocessor is bound by appropriate data-protection terms.
International transfers
The Service is operated from, and personal data is processed and stored in, the United States. Because Agent Dojo serves customers in multiple countries, personal data is transferred from the customer's country to the United States.
- Philippines and other non-EEA countries. Where a customer is subject to the Philippine Data Privacy Act (RA 10173) or similar laws, the customer (as controller) remains accountable for the cross-border transfer, and Agent Dojo (as processor) protects the transferred data under the DPA using contractual and security safeguards consistent with those laws.
- EEA/UK. Where any personal data originating in the EEA or UK is involved, we rely on the European Commission's Standard Contractual Clauses (and the UK IDTA/Addendum for UK transfers), together with supplementary measures as needed, as set out in the DPA.
As between Agent Dojo and the customer, the customer is responsible for establishing a lawful basis for the transfer; Agent Dojo provides the safeguards described in the DPA.
Retention
We retain personal data for as long as needed to provide the Service and for legitimate or legal purposes:
- Account data — for the life of the account and up to 90 days after closure (longer where required by law).
- Voice recordings and transcripts — per the Tenant's configuration; default 12 months, then deletion.
- Backups — rolling 7 days.
Your rights
Subject to applicable law, you may request to access, correct, delete, port, or restrict processing of your personal data, or object to certain processing, and to withdraw consent. Where we act as a processor, we will route your request to the relevant customer (controller). To exercise rights, contact privacy@agentdojo.atlassian.net. Philippine data subjects may also lodge a complaint with the National Privacy Commission (https://www.privacy.gov.ph). EEA/UK data subjects (where applicable) may lodge a complaint with their supervisory authority.
Cookies
See the Cookie Policy for the cookies we set, their purposes, and how to manage consent.
Security
We maintain administrative, technical, and organizational safeguards designed to protect personal data; see the security measures referenced in the DPA. No method of transmission or storage is 100% secure.
Children
The Service is for business use and is not directed to children under 16. We do not knowingly collect their personal data.
Changes & contact
We may update this notice and will post the new effective date. Questions: privacy@agentdojo.atlassian.net · 30th Century Media Holdings Corp.
- v2026.06.01-draft — effective June 1, 2026