AquantConversational AI (ACAI)
Privacy Policy
Last updated: July 27, 2026
1.Who We Are and Scope
Aquant, Inc. ("Aquant", "we", "us") provides the Aquant Conversational AI platform ("ACAI" or the "Service") — AI-powered voice and messaging agents that businesses (our "Customers") deploy to communicate with their own users and customers ("End Users"). This Privacy Policy describes how we collect, use, share, and protect personal information in connection with the Service, including its administration console, self-serve signup, in-product assistant, and the voice, SMS, chat, and email channels it operates.
This Policy does not cover the practices of our Customers. Each Customer is responsible for its own privacy notices and for obtaining any consents required for its use of the Service with its End Users.
2.Our Role in Processing
We act in two distinct roles:
- As a processor / service provider for communication content processed on behalf of our Customers — such as call recordings, transcripts, chat and SMS messages, and caller details. For this data, the Customer is the controller, and we process it under our agreement with them. End Users should direct privacy requests about this data to the business they interacted with; we will assist that business in fulfilling them.
- As a controller for the information of people who hold accounts on the platform (Customer administrators and users), visitors who sign up for self-serve accounts, and operational data we generate to run and bill the Service.
3.Information We Collect
3.1. Account and Registration Information
- Name, email address, and username when an account is created — by invitation, by an administrator, or through self-serve signup.
- Authentication data: passwords are hashed before transmission and are managed by our identity provider; we do not store plaintext passwords.
- Organization details: organization name, environment (project) names, roles and permissions, and branding assets uploaded by administrators.
3.2. Communication Content (Processed for Customers)
- Voice calls: audio recordings, real-time and post-call transcripts, caller phone numbers, and call metadata (time, duration, agent, disposition).
- Messaging: SMS, web chat, and WhatsApp message content and associated identifiers (phone numbers, session identifiers).
- Outbound communications: recipient lists, message content, and delivery status for messages our Customers send through the Service.
- Uploaded knowledge: documents and data Customers upload for their agents to reference.
3.3. Usage and Billing Information
- Consumption metering: call minutes, message counts, interaction outcomes, and related billing ledger entries, including prepaid credit balances and debits.
- Platform activity: administrative actions are recorded in audit logs (who did what, when, from which organization) for security and accountability.
- Technical data: IP addresses, browser and device information, and diagnostic logs generated in operating the Service.
3.4. Feedback
Feedback about the platform submitted by users, including feedback captured conversationally through our in-product assistant.
4.How We Use Information
- To provide, operate, secure, and support the Service, including routing calls and messages, generating agent responses, and delivering notifications.
- To measure consumption and administer billing, including per-minute and per-outcome charges, prepaid credits, and invoicing.
- To assess interaction outcomes where outcome-based pricing applies (see Section 5).
- To detect, investigate, and prevent abuse, fraud, and security incidents, including through audit logging and rate limiting.
- To communicate with account holders about the Service — verification emails, password resets, service notifications, and product updates.
- To improve and develop the Service, using aggregated and anonymized data wherever practicable.
- To comply with legal obligations.
5.AI Processing
The Service uses artificial intelligence, including large language models, to:
- Generate conversational responses in voice and text channels;
- Transcribe and summarize calls and conversations;
- Evaluate whether service interactions achieved their intended outcome, including for billing purposes where outcome-based pricing applies (with confidence thresholds and human review); and
- Analyze conversations for quality, safety, and reporting.
Model training. We do not use our Customers' communication content to train generalized AI models made available to other customers, except with consent or using data that has been aggregated and anonymized so that it no longer identifies any person or Customer.
No biometric identification. The Service does not create voiceprints and does not use voice recordings to biometrically identify individuals.
6.Call Recording and Transcription
Calls handled by the Service may be recorded, transcribed, and analyzed as described above. Recording is performed on behalf of, and under the direction of, the Customer whose agent handles the call. The Customer is responsible for providing any legally required recording notices to call participants and for obtaining any required consents. Where an End User objects to recording, they should end the call and contact the business through another channel.
7.How We Share Information
We do not sell personal information. We share information only with:
| Category | Purpose | Examples |
| Cloud infrastructure | Hosting, storage, and databases | Microsoft Azure |
| Telephony and messaging carriers | Connecting calls, delivering SMS and WhatsApp messages | Twilio |
| AI model providers | Language model inference for agent responses, transcription, and assessment | Azure OpenAI / OpenAI |
| Identity and authentication | Account login and identity management | Okta |
| Email delivery | Transactional and notification email | SendGrid (Twilio) |
| Customer-directed integrations | Systems the Customer connects to its agents | Slack, CRM/FSM connectors configured by the Customer |
We may also disclose information: to comply with law or valid legal process (with notice to the affected Customer where legally permitted); to protect the rights, safety, and property of Aquant, our Customers, or the public; and in connection with a merger, acquisition, or sale of assets, subject to this Policy's protections.
8.Data Retention
- Communication content (recordings, transcripts, messages) is retained for the duration of our agreement with the applicable Customer and any retention period it specifies.
- Customer-initiated deletion. When a Customer deletes data or terminates the Service, the deleted data is first retained for thirty (30) days in recoverable form, so that accidental deletions can be reversed. It is then moved to a restricted-access archive for a further one hundred eighty (180) days, held solely for auditing and dispute-resolution purposes, after which it is permanently and irreversibly deleted. Archived data is not used for any operational purpose and remains protected by the safeguards described in Section 9 throughout.
- Billing and audit records — invoices, consumption and outcome ledgers, payment and credit history, and related audit logs — are retained for up to seven (7) years to satisfy financial auditing and tax requirements, even where the underlying communication content has been deleted.
- Account information is retained while the account is active and for a reasonable period afterward as needed for legal and operational purposes.
- Residual copies in backups are protected until deleted in the ordinary backup cycle.
9.Security
We maintain administrative, technical, and physical safeguards designed to protect personal information, including encryption in transit, role- and capability-based access controls, organization-level data isolation, audit logging of administrative actions, secrets management, and rate limiting on sensitive endpoints. No system is perfectly secure; we encourage account holders to use strong, unique passwords and to report suspected issues to us immediately.
10.International Transfers
We are a U.S. company and process data in the United States and in other regions where we or our service providers operate. Where personal data subject to the GDPR or similar laws is transferred internationally, we rely on appropriate safeguards such as Standard Contractual Clauses, as set out in our Data Processing Addendum.
11.Your Rights and Choices
Depending on your location, you may have rights to access, correct, delete, or receive a copy of your personal information, to object to or restrict certain processing, and to lodge a complaint with a supervisory authority.
- Account holders may exercise these rights by contacting us at the address in Section 14.
- End Users of businesses that use the Service should direct requests to that business (the data controller); we will assist our Customers in responding, as required by our agreements and applicable law.
- Marketing choices: product-update emails include the ability to opt out; transactional messages (verification, password reset, billing alerts) are sent as needed to operate the Service.
We do not discriminate against anyone for exercising privacy rights.
12.Children
The Service is a business tool and is not directed to children under 16. We do not knowingly collect personal information from children. If you believe a child has provided personal information to us, contact us and we will delete it.
13.Changes to This Policy
We may update this Policy from time to time. Material changes will be announced through the Service or by email to account holders before they take effect. The "last updated" date at the top of this page reflects the current revision.
14.Contact Us
Aquant, Inc.
1234 Chestnut Street Suite 106
Newton Upper Falls, MA 02464
[email protected]