Legal

Privacy Policy

What Founders Nation collects, why, and who it reaches — including the recordings and transcripts of conversations the platform handles on your behalf.

Effective
25 August 2026
Last updated
25 August 2026
Sections
15
01

Overview

This policy explains what personal data Founders Nation collects, why, who it is shared with and what you can do about it. It covers the website, the dashboard, the APIs and widgets, and the voice and messaging conversations the platform handles.

Because this is a platform that answers calls, a lot of the data involved is not about our customers at all — it is about the people who call them. The section on roles below explains who is responsible for what, and it is the part worth reading first.

02

Who is responsible for what

We are the controller
for data about our own customers — the account you register, who signs in, how the dashboard is used, billing records and support conversations.
We are the processor
for the conversations you run through the platform — your contacts, call recordings, transcripts, messages and CRM records. You decide what is collected and why; we process it on your instructions.

If you are a caller, a customer or a contact of a business that uses this platform, that business is the controller of your data, not us. Requests to see, correct or delete it should go to them; if you send one to us we will pass it on and support them in answering it.

03

What we collect

Account data
Name, work email, password hash, workspace name, role and the members you invite.
Billing data
Plan, usage counters, invoices and payment status. Card details go directly to our payment processor — we never see or store a full card number.
Conversation data
Call audio where recording is enabled, transcripts, chat messages, attachments, call metadata (numbers, direction, duration, disposition, cost) and derived signals such as sentiment and intent.
Contact records
The contacts, CRM fields, notes and history you import or that a conversation creates.
Agent configuration
Prompts, knowledge base documents, tools, voices and channel settings.
Technical data
IP address, browser and device type, timestamps, pages and API endpoints used, and error diagnostics.
Support data
Messages you send us and the context attached to them.

Conversation data can contain anything a caller chooses to say. Please configure your agents so they do not ask for more than you need — particularly payment details, health information or government identifiers.

04

How we use it

  • Run the Service — connect calls, generate replies, transcribe audio, deliver messages, sync integrations, show live monitoring and reporting.
  • Authenticate and secure — sign you in, apply role permissions, detect abuse, fraud and account takeover, and keep audit trails.
  • Bill accurately — meter minutes, messages and tokens, and produce invoices and cost telemetry.
  • Support you — answer tickets and investigate faults, using the minimum data needed and only with the access controls described below.
  • Improve reliability — aggregated, de-identified metrics about latency, error rates and capacity.
  • Communicate — service notices, security alerts, and billing messages. Marketing email only where you have opted in, with an unsubscribe link every time.
  • Meet legal obligations — tax, accounting and lawful requests.
05

Voice recordings, transcripts and AI processing

When a call runs, audio streams through speech recognition, then to a language model, then to speech synthesis, and back to the caller. That pipeline means the audio and its transcript are processed by the providers you have enabled for your workspace.

  • Recording is a setting you control, per workspace and per agent. When it is off, we keep call metadata and the transcript only if transcription is on.
  • Consent is yours to obtain. Notifying callers that a call is recorded or handled by an AI system, where the law requires it, is the customer's obligation under the Terms of Service.
  • Transcripts are estimates. Speech recognition mishears; sentiment and intent readings are inferences, not facts, and should not be relied on as a record of what a person said or felt.
  • Provider keys. Where you bring your own model or voice provider key, data goes to that provider under your agreement with them, and their retention rules apply, not ours.
07

Sharing and sub-processors

We share data only with providers that make the Service work, and only what each one needs. Which providers are in play depends on the channels and integrations your workspace has enabled.

Telephony carriers
Place and receive calls, provision numbers, bridge SIP trunks. They receive call metadata and audio in transit.
Messaging platforms
WhatsApp, Instagram, Messenger and Telegram receive the messages you exchange on their channels, under their own terms.
AI and speech providers
Language models, speech recognition and voice synthesis receive the conversation content needed to produce a reply.
Cloud hosting
Runs the application and stores the database, object storage and backups.
Payment processing
Handles cards and invoices. They receive billing identifiers, not conversation data.
Email delivery
Sends transactional email such as invitations, alerts and password resets.
Product analytics and error tracking
Receives technical and usage data about the dashboard, not conversation content.

We may also disclose data where the law requires it, to enforce our terms, or to protect the rights and safety of users and the public — and, if we are ever party to a merger or acquisition, to the acquirer, with notice before your data becomes subject to a different policy.

A current list of sub-processors is available on request at privacy@foundersnation.com. Customers under a Data Processing Addendum are notified of new sub-processors before they start.

08

International transfers

Calls cross borders, and so does the infrastructure behind them. Your data may be processed in countries other than your own, including where our providers and their networks operate.

Where data leaves a region with transfer restrictions, we rely on an approved mechanism — Standard Contractual Clauses, the UK Addendum, or an adequacy decision — together with technical measures such as encryption in transit and at rest.

09

How long we keep it

Account data
For as long as the workspace is active, then 30 days after termination, then deleted.
Recordings and transcripts
For the retention period configured on your workspace. You can delete an individual recording or transcript at any time, and deletion propagates to backups within 30 days.
Contacts and CRM records
Until you delete them or close the workspace.
Billing records
Kept for as long as tax and accounting law requires, typically several years, regardless of account closure.
Security and audit logs
Up to 12 months.
Backups
Rolling encrypted backups expire within 30 days.
10

Security

  • Encryption in transit (TLS) and at rest for stored data, recordings and backups.
  • Tenant isolation — every query is scoped to a workspace, so one tenant cannot read another's data.
  • Role-based access in the product, and least-privilege, logged access internally. Support staff access customer conversation data only when needed to resolve a request.
  • Credentials and provider API keys stored encrypted; passwords stored only as salted hashes.
  • Short-lived access tokens with rotating refresh tokens, revoked on sign-out.

No system is perfectly secure. If we discover a breach affecting your personal data we will notify you and, where required, the relevant regulator without undue delay. Report a suspected vulnerability to security@foundersnation.com — we will not pursue good-faith security research that respects user privacy and does not degrade the Service.

11

Your rights

Depending on where you live, you may have the right to access your data, correct it, delete it, restrict or object to processing, receive a portable copy, withdraw consent, and not be subject to solely automated decisions with legal effects.

If you are in California, you may also request disclosure of the categories of personal information collected and shared, request deletion or correction, and not be discriminated against for exercising those rights. We do not sell or share personal information for cross-context behavioural advertising.

Exercise a right by emailing privacy@foundersnation.com from the address on your account, or by using the export and delete tools in your dashboard. We respond within 30 days, or tell you why we need longer. You may also complain to your local supervisory authority.

12

Cookies and tracking

We use a small number of cookies and equivalents:

  • Essential — the session and refresh cookies that keep you signed in, and the tenant resolution that serves the right brand. These cannot be turned off without breaking sign-in.
  • Preferences — theme, layout and dismissed prompts, stored locally in your browser.
  • Analytics — aggregate product usage, where you have consented or where local law permits it.

We do not run third-party advertising cookies. Blocking essential cookies in your browser will prevent you from signing in.

13

Children

The Service is built for businesses and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child's data has reached us, write to us and we will delete it.

14

Changes to this policy

We update this policy as the platform changes. The effective date at the top of the page always reflects the current version. Material changes are announced by email or in the product at least 30 days before they take effect.

15

Contact

Privacy questions, requests and DPA enquiries go to privacy@foundersnation.com. Security reports go to security@foundersnation.com. Everything else about the agreement itself is covered by the Terms of Service.

Privacy Policy — Founders Nation