Privacy Policy
Last updated: September 2, 2026
Our role changes depending on which data we are talking about
Jelliu is a PROCESSOR of the personal data its customers upload to or generate through the platform (the data of those customers’ own end customers). Jelliu is a CONTROLLER only of its own account, billing and marketing data. If you received a call or a message from a Jelliu agent, the controller is the business that contacted you, not Jelliu; section 2 explains who to approach.
1. Who is responsible for this policy
This Privacy Policy is published by Jelliu Corporation, a corporation incorporated on 4 August 2026 under the laws of the State of Delaware, United States, filed with the Delaware Division of Corporations under file number 10722311, with its registered office at 131 Continental Dr, Suite 305, Newark, DE 19713, United States, trading as Jelliu. Jelliu Corporation is the controller of the data described in section 2 and operates the AI agent platform available at jelliu.co and app.jelliu.co, which answers and places phone calls and handles WhatsApp, web chat and email conversations on behalf of its business customers.
For any matter concerning personal data, including submitting a query ("consulta") or a complaint ("reclamo"), the contact channel is the email address in section 18. We respond in Spanish and English.
2. Our dual role: processor and controller
This is the most important distinction in this document and it determines who a data subject should approach.
Jelliu acts as a PROCESSOR (processor under GDPR Article 4(8); service provider under California Civil Code § 1798.140(ag)) for all personal data a business customer uploads to the platform, or that the platform generates while carrying out that customer’s instructions: contact lists, phone numbers, recordings, transcripts, messages, conversation outcomes and derived analysis. For that data the business customer is the controller. Jelliu processes it only on their documented instructions and does not decide its purposes.
Jelliu acts as a CONTROLLER solely with respect to: its customers’ account registration and administration data, billing and payment data, technical support data, website visitor and sales prospect data, and dashboard usage analytics.
- If you received a call, a WhatsApp message or an email from an agent built on Jelliu, you exercise your rights against the business that contacted you. If you write to us, we will pass your request to that business without undue delay and confirm that we have done so.
- If you are a Jelliu customer or represent one, you exercise your rights over account and billing data directly against us.
- If you are a website visitor, section 15 describes which cookies we use and how to withdraw your consent.
The Data Processing Addendum is binding
The Data Processing Addendum published at jelliu.co/dpa is incorporated by reference into the service agreement and governs, with enforceable obligations, everything Jelliu does with the personal data of its customers’ end customers.
Jelliu’s obligations as a processor are set out in a Data Processing Addendum that forms part of the contract with every customer and is accepted on use of the platform.
3. What data we process
Data processed as a PROCESSOR, on behalf of our business customers:
- End-customer identification and contact data: name, phone number, email address, WhatsApp identifier and any additional field the customer chooses to upload to its contact list.
- Conversation content: call audio, transcript, text messages, attachments and receipts the other party sends.
- Conversation metadata: date, time, duration, direction, outcome, originating and destination number, agent used, associated campaign.
- Analysis derived from the conversation: summary, sentiment, evaluation criteria and the data fields the customer configured for extraction.
- Encrypted integration credentials and the data the customer chooses to sync with its own tools.
Data processed as a CONTROLLER: name, email address, company and identity-provider identifier of account users; billing and payment data; the content of support requests; IP address, user agent, pages visited and dashboard usage events; and the contact details of prospects who write to us or book a demo.
4. Voice data: a category with its own rules
Voice deserves separate treatment because, unlike a phone number, it can identify a person by their physical characteristics.
What is captured: the call audio while the call is in progress, the textual transcript of both parties, and the prosodic features the model uses to respond in real time. The other party’s voice is processed ephemerally to produce the transcript.
What we do NOT do: we do not create or store voiceprints, voice templates or biometric vectors of the people called; we do not identify or verify anyone by their voice; we do not match a voice against a database of voices; and we do not use any caller’s voice to clone voices or to train models.
Express acknowledgement: in jurisdictions such as Illinois (Biometric Information Privacy Act), Texas (CUBI) and Washington (HB 1493), a voice recording may qualify as a biometric identifier regardless of whether the party processing it intends to use it as one. For that reason audio is kept for the minimum technically necessary period and destroyed on the schedule in section 9.
Legal basis and responsibility: the legal basis for processing the other party’s voice is determined by the business customer placing or receiving the call, not by Jelliu. Where applicable law requires all-party consent to record, it is for that customer to obtain it; the platform provides the recording announcement described in section 11.
Destruction: Jelliu does not store call audio in its own infrastructure. Audio remains for approximately 14 days in the voice provider’s infrastructure and is purged there. Transcripts are encrypted at rest and deleted according to the period of the subscribed plan.
5. Purposes and legal bases
As a processor, the purpose and legal basis are set by the business customer acting as controller. As a controller of our own data, we process on the following bases:
- Performance of a contract (Article 6(1)(b) GDPR): creating and administering the account, providing the service, billing, support and operational service communications.
- Legal obligation (Article 6(1)(c)): retaining accounting and tax records, responding to requests from competent authorities and meeting fraud-prevention obligations.
- Legitimate interests (Article 6(1)(f)): platform security, abuse and fraud prevention, and error logging to diagnose failures. That last one is why error monitoring is not conditioned on cookie consent: without it we would not know the application had failed.
- Consent (GDPR Article 6(1)(a), and the consent required by US state law where applicable): product analytics and session replay, marketing communications to prospects, and any cookie that is not strictly necessary. Consent can be withdrawn at any time from the “Cookie preferences” link in the footer, as easily as it was given.
6. We do not train models on customer content
Jelliu does not train, fine-tune, distil or otherwise develop artificial-intelligence models — its own or anyone else’s — on its customers’ recordings, transcripts, messages, contact lists, knowledge documents or any other content. We contractually require our AI sub-processors not to use that content to train their models.
What "improving the service" does cover: aggregate, non-identifying metrics (call volume, error rates, latency, feature usage), failure analysis from technical traces, and manual review of a specific conversation when a customer opens a support ticket and authorises us to look at it.
What it does NOT cover: reading a customer’s conversations to build new features, feeding a training dataset, showing one customer’s content to another, or using one customer’s data to benefit a competitor of theirs. None of that is covered by the phrase "improving the service".
7. Sub-processors
Jelliu relies on providers that process personal data on its behalf in order to deliver the service. By category: cloud infrastructure and managed databases; telephony and messaging; speech synthesis and recognition; language models; authentication and session management; payment processing and billing; transactional email; connectors to the applications the Customer authorises; and error monitoring, metrics and product analytics.
Each is bound by a contract imposing data protection obligations no less demanding than those Jelliu itself has accepted, and access is limited to what its function strictly requires. Jelliu remains liable to the Customer for a sub-processor’s failure to meet those obligations as if the failure were its own. Processing takes place in the United States.
Jelliu does not publish the identity of its providers. A Customer who needs it may request it in writing at the address in section 18 and will receive it together with each provider’s purpose, data categories and location. Jelliu gives at least thirty (30) days’ notice before adding or replacing a sub-processor, and the Customer may object within that period under the Data Processing Addendum.
8. International transfers
The service is provided from the United States: that is where the platform is hosted, where its providers operate, and where the information is processed. For a customer contracting from the United States there is no international transfer to cover. For one contracting from the European Economic Area or the United Kingdom there is, which is why we name the specific mechanism we rely on rather than gesturing at “applicable law”.
- From the European Economic Area and the United Kingdom: the Standard Contractual Clauses of Commission Implementing Decision (EU) 2021/914, module 3 (processor to sub-processor), supplemented by the ICO UK Addendum where applicable and by a transfer impact assessment per destination.
- Within the United States: processing is governed by applicable federal and state law, including California’s CCPA/CPRA and equivalent state statutes. Every provider is contractually bound as a service provider, barred from selling the data, from retaining it outside the relationship, and from using it for its own purposes.
- Supplementary measures: encryption in transit and at rest, minimisation of the data sent to each provider, and a commitment to notify the customer of any access request from a foreign authority unless legally prohibited from doing so.
We do not rely on the EU-US Data Privacy Framework alone. Some of our providers are certified under it, but given that its predecessor was annulled in 2020 and that the framework remains subject to challenge, the Standard Contractual Clauses are maintained as a standalone and sufficient mechanism in every case.
9. Retention periods
We retain each category of data for the period stated below. Where the period depends on a criterion, the criterion is stated.
| Data category | Retention period | Criterion |
|---|---|---|
| Account and user data (name, email, organisation) | For as long as the account is active, plus 90 days after closure | Necessary to provide the service; the margin allows an account closed by mistake to be restored |
| Billing data and accounting records | 5 years from the close of the financial year | 26 U.S.C. § 6001 and the IRS record-retention regulations |
| Call audio | Approximately 14 days, held in the voice provider’s infrastructure. Jelliu does not store call audio in its own systems | Audio is retained only for as long as the voice provider keeps it available for on-demand download |
| Call transcripts and summaries | 7 days on Starter, 30 on Growth, 90 on Business; on Enterprise, the period agreed in the contract | Automated daily purge according to the subscribed plan |
| Call and contact records (metadata, outcomes) | 365 days by default, or 730 days for United States numbers. The Customer may configure any value between 30 and 3,650 days | Default set by the destination country of the line called; the Customer may shorten or extend it within those bounds |
| WhatsApp, web chat and email messages | For the term of the contract; deleted on termination or on receipt of an erasure request | There is no automated purge for these channels today; deletion is on request or on termination |
| Audit logs | 730 days. IP address and user agent are anonymised at 90 days | Automated daily purge; the Customer may set a shorter period from the compliance settings |
| In-app notifications | 90 days | Automated purge every 24 hours |
| Third-party connector events | 30 days | Automated purge |
| Product analytics (consent only) | 12 months | Retention period configured in the analytics tool |
On termination of the contract, personal data processed on the customer’s behalf is deleted within 30 days, unless the customer requests its return before that deadline or the law requires longer retention. Backups are overwritten in the ordinary rotation cycle.
10. Security measures
These are the measures actually implemented. They are described in enough detail to be verified and for a failure to meet them to be enforceable.
| Measure | Implementation |
|---|---|
| Encryption in transit | TLS on all web and API traffic, with HSTS set to 12 months, includeSubDomains and preload. Database connections validate a pinned certificate authority; the cache and queue store rejects any connection that is not TLS or private-network |
| Encryption at rest | AES-256-GCM envelope encryption with a per-record key derived via scrypt from a unique 16-byte salt. Additional authenticated data binds every ciphertext to its tenant, so one tenant’s ciphertext cannot be decrypted in another tenant’s context. Applied to transcripts, summaries, integration credentials, flagged content, identity certificates and post-call evidence |
| Data deliberately left unencrypted | The phone number is stored in the clear because it must remain queryable and indexable. This is documented here rather than described as "everything is encrypted" |
| Tenant isolation | PostgreSQL row-level security with USING and WITH CHECK policies on the tenant identifier, set per transaction with SET LOCAL from the request context and validated as a UUID before it is applied |
| Tamper-evident audit log | Every audit event is chained with HMAC-SHA256 over the canonical row and the previous row’s hash, serialised per tenant with an advisory lock. A verifier walks the chain and detects an altered or deleted row |
| Webhook authenticity | Inbound webhooks are signature-verified before processing. Outbound webhooks to the Customer are signed with a dedicated key and carry replay protection |
| Access control | Federated authentication through an identity provider, per-organisation sessions and role-based permissions within each workspace |
| Browser hardening | Content Security Policy with a per-request nonce, third-party framing denied, a permissions policy restricting camera and geolocation, and a restricted referrer policy |
| Logging and traceability | Every administrative action and every access to personal data is logged with actor, tenant, resource and timestamp |
| Continuity | Backups managed by the database provider with point-in-time recovery |
What we do not claim
Jelliu does not hold a SOC 2, ISO 27001 or HIPAA certification today, and does not run periodic third-party penetration tests. We would rather say so than imply otherwise: a security claim we cannot substantiate is itself a legal risk. The measures described above are the ones actually implemented and verifiable.
11. Call recording and consent
The obligation to obtain consent to record a call rests with the business customer placing or receiving it, because that customer decides to call, whom to call and why. Jelliu cannot know the other party’s jurisdiction with enough certainty to take on that obligation in their place.
What the platform does technically: it includes a recording announcement at the start of the call where the compliance configuration for the destination country requires one, and the default configuration requires that announcement in every country. The announcement is spoken in the language of the conversation and the customer does not have to draft it.
The platform also records a number’s opt-out when the other party asks for it and honours that opt-out in that customer’s later campaigns, and it exposes per-country contact hour and frequency settings to each customer.
What the platform does not do: it does not verify that the customer obtained prior consent, it does not check the National Do Not Call Registry or equivalent state and internal suppression lists on their behalf, and it is not a substitute for the legal advice a customer may need on the all-party recording consent laws in force in the United States.
12. AI transparency and automated decision-making
Our agents identify themselves as artificial intelligence when the person asks, and never claim or imply that they are human. They do not volunteer that identification when opening the conversation: the opening message is configured by each customer.
Agents are forbidden by system instruction from claiming or implying that they are people. Asked directly, they answer that they are an artificial intelligence system.
Agents do not take decisions producing legal effects or similarly significantly affecting a person within the meaning of Article 22 GDPR. They classify a conversation outcome, qualify commercial interest and book appointments; none of those functions approves credit, denies a service or determines an entitlement. If a customer were to configure an agent to take such a decision, that customer would be responsible for providing the human intervention Article 22 requires.
13. Your rights and how to exercise them
If you live in a US state with a consumer privacy law — California, Virginia, Colorado, Connecticut, Utah, Texas and the others that have adopted one — you may find out what data we process, obtain a portable copy, correct it, request its deletion, and opt out of its sale or of targeted advertising. Jelliu does not sell personal data and does not share it for cross-context behavioural advertising. We will not treat you worse for exercising any of these rights, and you may complain to your state attorney general. The deadlines we hold ourselves to are below, and we meet them when acting as a processor on a customer’s behalf as well:
- Queries ("consultas"): answered within a maximum of ten (10) business days. If that is not possible, we will tell you before the deadline expires, stating the reasons and the date of our reply, which will be no later than five (5) business days after that.
- Complaints ("reclamos"): answered within a maximum of fifteen (15) business days counted from the day after receipt. If that is not possible, we will tell you before the deadline expires, stating the reasons and the date of our reply, which will be no later than eight (8) business days after that.
- Under the GDPR: access, rectification, erasure, restriction, portability, objection and the right not to be subject to automated decisions. We respond within one (1) month, extendable by two (2) further months where the request is complex, telling you about the extension within the first month.
- Under the California CCPA/CPRA: to know, access, delete, correct, port, limit the use of sensitive personal information and opt out of sale or sharing. We acknowledge receipt within ten (10) business days and respond within forty-five (45) calendar days, extendable by a further forty-five (45). Jelliu does not sell or share personal information within the meaning of that law.
- We apply no adverse consequence for exercising a right, and we do not charge for it unless the request is manifestly unfounded or excessive.
To exercise them, write to the address in section 18 from the email address associated with your data, or tell us a reasonable way to verify your identity. If your data was processed on behalf of a business customer, we will identify that controller to you and pass on your request without undue delay.
14. Security incidents
If a personal data breach occurs, we will notify the affected customer without undue delay and in any event within forty-eight (48) hours of becoming aware of it. That deadline is deliberately set below the seventy-two (72) hours Article 33 GDPR allows the controller, so that the customer has real time to meet its own obligation to notify the supervisory authority.
The notification will describe the nature of the incident, the categories and approximate number of data subjects and records affected, the likely consequences, the measures taken or proposed, and a point of contact. If we do not have all of that information, we will send it in phases rather than delay the first communication.
When acting as a controller, we will notify state authorities and affected individuals within the deadlines set by the breach-notification law of each affected person’s state of residence: without undue delay in every case, and within thirty (30) days in the states that set that maximum. When acting as a processor, notifying authorities and data subjects is the controlling customer’s to do, starting from the notice we give them under the first paragraph of this section.
We keep an internal record of every incident, including those that require no notification, with its facts, effects and remedial action, and we make it available to any customer who asks.
15. Cookies and similar technologies
We use three categories, and no non-essential cookie is set before you accept it.
- Strictly necessary (always on, no consent): the authentication session cookie, the language cookie that decides whether you see the site in Spanish or English, and the cookie that stores your own cookie decision. The site does not work without them.
- Analytics (requires your consent): dashboard product analytics and session replay. The analytics code is not even downloaded until you give consent; it is not loaded and left quiet.
- Marketing and advertising (requires your consent): we currently load no cookie in this category and no advertising pixel. The category is declared so that one cannot be added in future without asking you first.
You can change your decision at any time from the "Cookie preferences" link in the footer. If your browser sends the Global Privacy Control signal (via the navigator.globalPrivacyControl property or the Sec-GPC header), we treat it as a valid opt-out of every non-essential category, apply it automatically and confirm it visibly in the preference centre, as California law has required since 1 January 2026. Error monitoring is not subject to consent because it relies on the legitimate interests basis in Article 6(1)(f) GDPR.
16. Children
Jelliu is a business-to-business service. It is not directed at anyone under eighteen (18), we do not allow them to create accounts, and we do not knowingly collect their data as a controller.
If a minor turns out to be on the other end of a conversation run by a customer’s agent, the party responsible for holding verifiable parental consent — under the Children’s Online Privacy Protection Act (15 U.S.C. §§ 6501-6506) and GDPR Article 8 where it applies — is that customer. If we learn that we have collected a minor’s data as a controller, we will delete it without delay.
17. Changes to this policy
We will publish every change on this page with a new last-updated date. Where the change is material — a new purpose, a new data category, a longer retention period or a new sub-processor with access to conversation content — we will notify customers by email and in the application at least thirty (30) days before it takes effect.
We keep previous versions and provide them on request.
18. Contact
The data controller is Jelliu Corporation, a Delaware corporation with its registered office at 131 Continental Dr, Suite 305, Newark, DE 19713, United States, which operates jelliu.co and app.jelliu.co. For queries, complaints and to exercise your rights over personal data, write to us at:
contact@jelliu.com