Privacy Policy
Draft. This document is published for review and is not yet in force. Details in square brackets are still to be completed, and the text has not yet been reviewed by a lawyer. Questions to support@boldagents.co.
This policy explains what [Legal entity name], trading as Bold Agent Kit, collects about you, why, who sees it, how long it is kept and what you can ask us to do with it. It covers the website at boldagents.co, the Bold Agent Kit application, the Chrome extension and the members’ forum.
There are two kinds of people this policy is about, and the rules differ. Account holders and visitors are people whose data we decide how to use: for them we are the controller. The people your agents talk to are your contacts, customers and leads: for their data we act on your instructions, as your processor, and you are the controller. Section 6 covers them; the Data Processing Addendum covers it in the detail the law asks for.
1. What we collect about you
- Account details. Name, email address, password (stored as a hash), company name, and the billing details our payment processor needs. We do not see or store full card numbers.
- What you build. Your agents’ names, instructions, knowledge bases, templates, campaigns, schedules and settings.
- Connected accounts. The credentials you give us for mailboxes, phone numbers, social platforms, calendars, CRMs and AI providers. API keys and passwords are stored encrypted and used only to operate the connection you asked for.
- Conversations. Every message your agents send and receive, call recordings and transcripts, and the material each reply was generated from, so you can read them back.
- Usage. When you sign in, what you use, error logs, and the IP address and browser your requests arrive from.
- Forum posts. What you write in the members’ forum, which other members can see.
- The hire form. If you send the form on the Hire us page: your name, email, company, website, phone, what you need and what you wrote, plus the address it came from. It is saved so we can reply to you and emailed to our support inbox.
2. Why we use it
- To run the Service you signed up for: this is performance of our contract with you.
- To bill you, answer support, tell you about changes to the Service or these documents, and keep the Service secure: our legitimate interests, and in some cases a legal obligation.
- To understand how the website is used, through analytics (section 4): our legitimate interest, and consent where the law where you are requires it.
- To reply to a hire request you sent: the steps you asked us to take before a contract.
We do not sell your data, we do not use your content to train AI models, and we do not use one customer’s content to serve another.
3. Who sees it
- Providers you connect. Your agent sends conversation content to the AI provider on your key, and sends and receives messages through the mailbox, carrier, telephony and social accounts you connected. Those providers act under their own terms with you. We do not choose them; you do.
- Our subprocessors. The hosting where the application and database run, our payment processor, the analytics on the website, and the email provider that delivers hire-form notifications. The current list, with what each one does and where it is, is on the Subprocessors page.
- People you authorise. Anyone you invite into your account, and each client you give a login to, who sees that client’s agent and nothing else.
- The law. If we are required to by a court or a regulator, or to protect the rights and safety of people, and only as far as the requirement goes.
4. Cookies and analytics
The website sets a small number of cookies and similar storage. Necessary: a session cookie when you sign in to the admin, and a browser storage entry that remembers your light or dark theme choice. Analytics: Google Analytics, which sets its own cookies to count visits and page views. Google’s processing is described in its own policy, and you can opt out with Google’s browser add-on or by blocking the cookies in your browser. Where the law where you are requires consent for analytics cookies, we ask for it before they are set. The website chat widget stores an identifier in your browser so a returning visitor’s conversation continues.
5. How long we keep it
- Account data and what you build: for as long as the account is open, then deleted within 30 days of closure.
- Conversations, recordings and transcripts: for as long as you keep them in the account; you can delete a contact or a conversation yourself, and everything goes when the account closes.
- Billing records: for as long as tax law requires, typically seven years.
- Server logs: 30 days.
- Hire requests: until we have replied and the enquiry is closed, then up to 12 months so we can refer back to it if you write again.
6. The people your agents talk to
When your agent emails, texts, calls or messages someone, we store that person’s contact details, the conversation, and any handle we learn for them (an email address, a phone number, a social account id, a browser cookie) merged into one contact record, together with events such as page visits on your site if you installed the tracking snippet, bookings, and outcomes you record. We hold all of it on your instructions and delete it when you tell us to or when your account closes.
You are the controller of that data. You decide who is contacted and why, and you are responsible for having a lawful basis and for honouring their rights. We give you the tools: opt-outs that stop every channel, one-click unsubscribe on campaign email, deletion per contact, and an export. If one of your contacts writes to us directly, we will pass the request to you and help you answer it.
7. Security
Data is encrypted in transit. Passwords are stored as salted hashes; API keys and connected-account credentials are encrypted at rest and decrypted only to operate the connection. Access to production systems is limited to the people who run them. Client logins are scoped to one agent and deny everything else by default. If we learn of a breach that affects your data we will tell you without undue delay, and within 72 hours where the DPA applies.
8. International transfers
The application and its database run at [Hosting provider and region]. The providers you connect run wherever they run. Where personal data protected by the GDPR or the UK GDPR leaves the region it is protected in, we rely on the European Commission’s standard contractual clauses, the UK addendum to them, or an adequacy decision, as the DPA sets out.
9. Your rights
Depending on where you live you may have the right to access the data we hold about you, correct it, delete it, take a copy of it, restrict or object to how we use it, and withdraw consent where consent is the basis. You can do most of this from the account. For anything else, email support@boldagents.co; we answer within a month. You can also complain to your data protection authority. If you are in California, the rights above include those under the CCPA; we do not sell or share personal information as that law defines it.
10. Children
The Service is for businesses and is not directed at anyone under 18. We do not knowingly collect data from children; if you believe we have, tell us and we will delete it.
11. Changes
When this policy changes materially we tell account holders by email and update the date at the top. The current version is always at boldagents.co/legal/privacy.
12. Contact
[Legal entity name], [Registered address]. Privacy questions and requests: support@boldagents.co.
Related documents. Terms of Service · Data Processing Addendum · Acceptable Use Policy · Subprocessors
