Legal

Privacy Policy

Last updated: May 12, 2026

Introduction

This Privacy Policy describes how Aimna Technologies, Inc. ("Aimna," "we," "us," or "our") collects, uses, discloses, and protects your personal information when you use our website, platform, APIs, and related services (collectively, the "Services").

By accessing or using our Services, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with our practices, please do not use the Services.

This Privacy Policy should be read alongside our Terms of Service.

1. Controller & Processor Roles

Aimna acts as a data controller when we collect and process personal information for our own purposes, such as website analytics, account registration, direct marketing, and customer support.

Aimna acts as a data processor (or "service provider" under CCPA) when we process personal information on behalf of our enterprise customers through the voice agent platform. In such cases, our customers are the data controllers and our processing is governed by a Data Processing Addendum (DPA).

2. Information We Collect

2.1 Personal Data You Provide

When you create an account, contact us, or use our Services, we may collect:

  • Name, email address, phone number, and company name
  • Billing and payment information (processed by our payment processor)
  • Account credentials and profile information
  • Communications you send to us (support requests, feedback)
  • Any other information you voluntarily provide

2.2 AI Voice & Communications Data

When you use our voice agent platform, we may collect and process:

  • Audio recordings of phone calls processed through the Services
  • Call transcripts generated by speech-to-text processing
  • Call metadata (duration, timestamps, phone numbers, call direction)
  • Post-call analysis results (summaries, sentiment, extracted data)
  • Knowledge base content you upload (documents, URLs, text)
  • Agent configurations, prompts, and function definitions

Your responsibility: You are responsible for obtaining all necessary notices and consents from individuals whose calls are processed through the Services, including consent for AI-generated voice interaction and call recording, as required by applicable law.

We may use de-identified and aggregated communications data to improve and enhance our Services. We do not use data obtained through Google Workspace APIs for AI or machine learning model development.

2.3 Sensitive Personal Data

We only collect sensitive personal data when strictly necessary for the provision of Services and with your explicit consent. If you are a healthcare customer processing protected health information (PHI), you must execute a Business Associate Agreement (BAA) before using the Services.

3. Usage Data

We automatically collect certain information when you access the Services, including:

  • IP address, browser type and version, operating system
  • Pages visited, time and date of visits, time spent on pages
  • Device identifiers and diagnostic data
  • Referring URLs and search terms
  • Mobile device information (device type, mobile OS, mobile browser)

This information helps us understand how our Services are used and enables us to improve performance, diagnose technical issues, and optimize the user experience.

4. Cookies & Tracking Technologies

We use cookies and similar tracking technologies to collect and track information about your activity on our Services.

Types of Cookies We Use

  • Essential Cookies: Required for the Services to function (authentication, security, load balancing).
  • Preference Cookies: Remember your settings and preferences (language, timezone, display options).
  • Analytics Cookies: Help us understand how visitors interact with the Services (page views, navigation patterns).
  • Marketing Cookies: Used to deliver relevant advertisements and measure campaign effectiveness.

Cookie Management

You can instruct your browser to refuse all cookies or to indicate when a cookie is being sent. However, if you refuse cookies, some features of the Services may not function properly.

We honor Global Privacy Control (GPC) signals where required by applicable law. If we detect a GPC signal, we will treat it as a valid opt-out of the sale or sharing of personal information.

5. How We Use Your Information

We use the information we collect for the following purposes:

  • To provide, maintain, and improve the Services
  • To process transactions and manage your account
  • To send you service-related notices and updates
  • To provide customer support and respond to your requests
  • To monitor usage patterns and analyze trends
  • To detect, prevent, and address technical issues and security threats
  • To comply with legal obligations and enforce our Terms of Service
  • To send marketing communications (with your consent, where required)
  • To improve our AI models using de-identified, aggregated data
  • To fulfill contractual obligations including billing and collections

6. Data Retention

We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, including to satisfy legal, accounting, or reporting requirements.

The retention period depends on the nature of the data, the purposes of processing, and applicable legal requirements. When data is no longer needed, we securely delete or anonymize it.

  • Account data: Retained for the duration of your account and for a reasonable period after deletion to comply with legal obligations.
  • Call recordings & transcripts: Retained according to your account settings. You may delete recordings at any time via the dashboard or API.
  • Usage data: Retained for up to 24 months for internal analysis, then anonymized or deleted.
  • Billing records: Retained for 7 years as required by tax and accounting regulations.

7. International Data Transfers

Your information may be transferred to and processed in the United States, where our servers and primary operations are located. If you are located outside the United States, please be aware that data protection laws in the US may differ from those in your jurisdiction.

For transfers of personal data from the European Economic Area (EEA), United Kingdom, or Switzerland, we rely on appropriate safeguards, including Standard Contractual Clauses (SCCs) approved by the European Commission, the UK International Data Transfer Agreement (IDTA), and other approved transfer mechanisms.

8. Disclosure of Your Information

We may disclose your personal information in the following circumstances:

  • Service providers: Third-party companies that assist us in providing the Services (cloud hosting, payment processing, analytics). These providers are bound by confidentiality agreements and may only use your data to provide services to us.
  • Legal compliance: When required by law, regulation, legal process, or governmental request.
  • Business transfers: In connection with a merger, acquisition, reorganization, or sale of assets, your data may be transferred as part of the transaction.
  • With your consent: We may share your information with third parties when you have given us explicit consent to do so.
  • Protection of rights: To protect the rights, property, or safety of Aimna, our users, or the public.

We do not sell your personal information to third parties. We do not share your personal information for cross-context behavioral advertising.

9. Data Security

We implement and maintain reasonable administrative, technical, and physical safeguards designed to protect the security, confidentiality, and integrity of your personal information. Our security measures include:

  • Encryption of data in transit (TLS 1.2+) and at rest (AES-256)
  • Role-based access controls and least-privilege principles
  • Regular security assessments and penetration testing
  • Incident response procedures and breach notification protocols
  • SOC 2 Type II compliance program

While we strive to protect your personal information, no method of transmission over the Internet or method of electronic storage is 100% secure. We cannot guarantee absolute security.

In the event of a data security breach affecting your personal information, we will notify you without undue delay and within the timeframes required by applicable law.

10. Service Providers

We use the following categories of third-party service providers:

Analytics

Payment Processing

  • Our payment processor — Privacy Policy (link will be updated when payment processor is selected)

Cloud Infrastructure

  • Amazon Web Services (AWS)
  • Google Cloud Platform (GCP)

AI & Voice Processing

  • OpenAI (LLM, TTS, embeddings)
  • Anthropic (LLM)
  • Deepgram (speech-to-text)
  • ElevenLabs (text-to-speech)
  • Pinecone (vector database)

All service providers are bound by confidentiality agreements and are prohibited from using your data for any purpose other than providing services to Aimna. For an updated list of subprocessors, contact support@aimna.app.

11. Email Communications

We may send you the following types of email communications:

  • Transactional: Account confirmations, billing receipts, security alerts, and service notifications. These cannot be opted out of.
  • Product updates: Feature announcements, platform changes, and maintenance notices.
  • Marketing: Promotional content, newsletters, event invitations, and educational resources.

You can opt out of non-transactional emails at any time by clicking the "unsubscribe" link in any email or by contacting us at support@aimna.app.

12. Your Rights Under GDPR (EU/EEA)

If you are located in the European Economic Area, you have the following rights under the General Data Protection Regulation:

  • Right of access: Request a copy of the personal data we hold about you.
  • Right to rectification: Request correction of inaccurate or incomplete data.
  • Right to erasure: Request deletion of your personal data ("right to be forgotten").
  • Right to restrict processing: Request limitation of how we process your data.
  • Right to data portability: Receive your data in a structured, machine-readable format.
  • Right to object: Object to processing based on legitimate interests or for direct marketing.
  • Right to withdraw consent: Withdraw previously given consent at any time.

To exercise any of these rights, contact us at support@aimna.app. We will respond within 30 days. You also have the right to lodge a complaint with your local Data Protection Authority.

Legal bases: We process personal data based on: (a) performance of a contract, (b) legitimate interests, (c) consent, and (d) compliance with legal obligations.

13. Your Rights Under CCPA/CPRA (California)

If you are a California resident, you have the following rights under the California Consumer Privacy Act and California Privacy Rights Act:

Right to Know

You may request that we disclose the categories and specific pieces of personal information collected, the sources, the business purposes for collection, and the categories of third parties with whom we share it. You may submit up to 2 requests per 12-month period.

Right to Delete

You may request deletion of personal information we have collected, subject to certain exceptions (e.g., completing transactions, detecting security incidents, complying with legal obligations, exercising free speech rights, conducting research with informed consent).

Right to Correct

You may request correction of inaccurate personal information that we maintain about you.

Right to Opt-Out

We do not sell your personal information. We do not share your personal information for cross-context behavioral advertising. If this changes, we will provide a "Do Not Sell or Share My Personal Information" link and honor opt-out requests.

Right to Non-Discrimination

We will not discriminate against you for exercising any of your CCPA/CPRA rights.

Sensitive Personal Information

We limit our use of sensitive personal information to what is necessary for providing the Services. We do not use sensitive personal information for purposes beyond what is reasonably necessary.

To exercise any of these rights, email support@aimna.app with the subject line "CCPA Request."

14. Children's Privacy

The Services are not directed to children under the age of 13 (or 16 in the EEA). We do not knowingly collect personal information from children. If we become aware that we have collected personal information from a child without parental consent, we will take steps to promptly delete that information. If you believe a child has provided us with personal information, please contact us at support@aimna.app.

15. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated Privacy Policy on our website and, where practicable, by sending you an email notification.

We encourage you to review this Privacy Policy periodically. Your continued use of the Services after any changes constitutes your acceptance of the updated Privacy Policy. Where required by law, we will obtain your consent before making material changes.

16. Contact Information

If you have any questions or concerns about this Privacy Policy or our data practices, please contact us:

Governing Law: This Privacy Policy is governed by the laws of the State of Delaware, USA, except where otherwise required by applicable data protection laws (e.g., GDPR for EU/EEA residents).