Privacy Policy
This is an unreviewed engineering stub. The wording is not legal advice and is not binding. Every [BRACKETED]item needs counsel's input — 7 placeholders on this page. It is not enforced against customers until reviewed and this banner is removed.
⚠️ DRAFT — PENDING LEGAL REVIEW
Standard boilerplate, not reviewed by counsel and not legal advice. It must be validated against Agent Dojo's actual data flows. Items marked
[CONFIRM: …]need your decision. See the "Needs your input" checklist at the end.
Effective date: 2026-06-01 · Version: 2026.06.01-draft
This Privacy Policy explains how
[CONFIRM: legal entity — "Agent Dojo, Inc."] ("Agent Dojo," "we") collects,
uses, and shares personal information in connection with the Service. For
personal data we process on a customer's behalf as a processor, the
Data Processing Agreement and the customer's own privacy notice
govern.
Who this applies to
This notice covers personal information of website visitors, account holders, and Users of the Service. Where we act as a processor for a customer (e.g. trainees' call data), the customer is the controller and you should consult their privacy notice.
Categories of data we collect
- Account data — name, work email, organization, role.
- Usage data — sessions, scores, progress, log and device metadata (IP, browser, timestamps).
- Voice data — audio of mock calls and their transcripts (processed on the Tenant's behalf — see the DPA).
- Billing data — plan, billing contact, and the last four digits / card brand from our payment processor. We do not store full card numbers.
- Support and communications — messages you send us.
How we use it
To provide, secure, maintain, and improve the Service; to score calls and generate feedback; to authenticate Users and prevent abuse; to process payments; to communicate about the account and respond to support; and to comply with law. We use analytics and product telemetry only with consent where required (see the Cookie Policy). We do not sell personal information.
Legal bases (GDPR/UK GDPR)
Where the GDPR applies and we act as a controller, we rely on:
- Performance of a contract — to create your account and provide the Service.
- Legitimate interests — to secure, maintain, and improve the Service and prevent abuse (balanced against your rights).
- Consent — for analytics/marketing cookies and optional communications (withdrawable at any time).
- Legal obligation — to meet tax, accounting, and legal requirements.
Sharing
We share personal information with subprocessors that help us run the Service (see Subprocessors), with professional advisors, in a corporate transaction, and where required by law. Each subprocessor is bound by appropriate data-protection terms.
International transfers
Where personal data is transferred out of the EEA/UK, we rely on the European Commission's Standard Contractual Clauses (and the UK IDTA/Addendum for UK transfers), together with supplementary measures as needed. See the DPA.
Retention
We retain personal data for as long as needed to provide the Service and for legitimate or legal purposes:
- Account data — for the life of the account and up to 90 days after closure (longer where required by law).
- Voice recordings and transcripts — per the Tenant's configuration; default
12 months, then deletion.
[CONFIRM: default voice retention — confirm with eng/security] - Backups — rolling 35 days.
[CONFIRM: full retention schedule per data category — validate against actual systems]
Your rights
Subject to applicable law, you may request to access, correct, delete, port, or
restrict processing of your personal data, or object to certain processing, and
to withdraw consent. Where we act as a processor, we will route your request to
the relevant customer (controller). To exercise rights, contact
privacy@agentdojo.app [CONFIRM: privacy contact / DPO email + EU/UK representative if required]. You may also lodge a complaint with your supervisory
authority.
Cookies
See the Cookie Policy for the cookies we set, their purposes, and how to manage consent.
Security
We maintain administrative, technical, and organizational safeguards designed to protect personal data; see the security measures referenced in the DPA. No method of transmission or storage is 100% secure.
Children
The Service is for business use and is not directed to children under 16. We do not knowingly collect their personal data.
Changes & contact
We may update this notice and will post the new effective date. Questions:
privacy@agentdojo.app · [CONFIRM: company mailing address].
⚑ Needs your input
[CONFIRM]Legal entity name + (if GDPR) EU/UK representative.[CONFIRM]Privacy/DPO contact email + mailing address.[CONFIRM]Retention schedule per data category (esp. default voice-recording retention).- Confirm the "we do not sell personal information" statement and any US state-law (CCPA/CPRA) disclosures counsel wants to add.
- v2026.06.21-draft — effective June 21, 2026