Privacy Policy
Last updated: 2026-05-26
1. Data controller
The controller within the meaning of GDPR Art. 4(7) is the operator of prezio.app — registered address and contact details are listed in the Imprint. For questions about this policy, reach out to privacy@prezio.app.
2. What we collect
Account data (email, name, encrypted password hash). Agent configuration (prompts, branding, channel integrations). Conversation data (messages, contacts, leads — both sides of the conversation). Usage and cost telemetry (token counts, segment counts). Technical logs (IP address, user agent, timestamps) for the duration of a request lifecycle.
3. Why we process it
To provide and operate the service you signed up for. To generate AI responses (requires sending message content to OpenAI / Vapi as detailed in our Subprocessors page). To deliver outbound messages via Twilio / SES. To compute usage-based billing. To detect and prevent abuse, fraud, and security incidents. To fulfil legal obligations (tax retention, court orders).
4. Legal basis (GDPR Art. 6)
Art. 6(1)(b) — performance of the contract you entered into when signing up. Art. 6(1)(c) — legal obligations (tax, AML, requests from authorities). Art. 6(1)(f) — our legitimate interest in operating, securing, and improving the platform; balanced against your interests. We do not use 6(1)(a) consent-based processing for the core service. Consent under Art. 6(1)(a) / §25 TDDDG applies to the optional payment-security cookies that Stripe sets on the booking and order payment step — we obtain it via the cookie banner before Stripe is loaded (see section 8).
5. Who else processes your data
See our Subprocessors page for the complete list. Notable: Stripe (payment processing), AWS (hosting, email/SES, storage), Hetzner (compute + database hosting), Twilio (voice/telephony delivery), Meta (WhatsApp message delivery), OpenAI (LLM inference + embeddings), Vapi (voice synthesis), and Sentry (error tracking). Each is bound by a Data Processing Agreement and, where transfers outside the EU/EEA apply (notably to US processors such as Stripe, OpenAI and Vapi), by Standard Contractual Clauses; you can request a copy of the safeguards for a specific transfer at privacy@prezio.app.
6. How long we keep it
Account data: for the duration of the contract plus 30-day deletion grace, then hard-deleted (see GDPR Art. 17 implementation in your Account page). Conversation messages: for the duration of the contract. Usage records: 13 months for billing audit + customer support. Email suppression list: indefinitely, on legitimate-interest grounds (preventing reputational damage from sending to known-bouncing addresses). Audit logs: 12 months.
7. Your rights
Under GDPR you have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), portability (Art. 20), objection (Art. 21), and to lodge a complaint with a supervisory authority (Art. 77). Operators: exercise rights 15, 17, 20 directly via your Account page. Anyone else (end-users of operators' agents): contact privacy@prezio.app — we will route the request to the relevant operator and assist with technical execution.
8. Cookies and tracking
Strictly necessary: `ua_token`, a JWT-bearing session cookie that keeps you logged in to the dashboard. On the booking and order payment step, once you consent via the cookie banner, Stripe sets third-party cookies used for fraud prevention and Strong Customer Authentication (this also transmits your IP address to Stripe in the US); the basis is your consent under Art. 6(1)(a) GDPR / §25 TDDDG, which you can withdraw at any time via the 'Withdraw cookie consent' control in the widget. We use no advertising cookies and no third-party web analytics on the public site. The Sentry SDK on the dashboard sends error reports without setting identifier cookies.
9. Automated decision-making and profiling
Prezio's AI classifies and scores leads (BANT scoring, ICP matching) to help operators prioritise follow-up — a form of profiling under Art. 4(4) GDPR. This supports human decision-making and does not, by itself, produce legal or similarly significant effects on you within the meaning of Art. 22(1) GDPR: a human operator decides how to act on any lead. TODO(legal): confirm this assessment for your configuration; if any solely-automated decision with legal or similarly significant effect exists, disclose its logic and consequences here.
10. Data protection officer
At Prezio's current size we are not legally required to designate a DPO. For all data protection matters, contact privacy@prezio.app. A formal DPO will be appointed if and when team size, processing scale, or data category requires it under GDPR Art. 37.