Introduction
Ninova AI ("we", "our", "us") is committed to protecting your privacy and safeguarding your personal data. This Privacy Policy explains how we collect, use, store, and protect information when you visit our website, interact with our AI voice or chat agents, or engage with our services. This policy has been prepared in accordance with the EU General Data Protection Regulation (GDPR) and the Irish Data Protection Act 2018.
Who We Are
Ninova AI is a company based in Ireland providing AI Voice Agents and AI Customer Support solutions for businesses. We act as a data controller for the personal data we collect through our website and as a data processor when handling data on behalf of our business customers.
Information We Collect
We may collect and process the following categories of information:
- Name — provided when you fill in a form or contact us.
- Email Address — used for communication and account-related messages.
- Phone Number — used to contact you regarding your enquiry or service.
- Company Name — provided during sign-up or enquiries.
- Contact Form Information — messages, requests, and details submitted via our forms.
- AI Chat Messages — text you exchange with our AI chat agents.
- AI Voice Conversations — where applicable, audio interactions with our AI voice agents.
- Website Usage Information — pages visited, time on site, referring URLs, and interactions.
- IP Address — collected for security, fraud prevention, and basic analytics.
AI Conversations
When visitors interact with our AI voice or chat agents, conversations may be processed and, where applicable, recorded or transcribed to provide our services, improve AI performance, and maintain service quality. We only retain this information for as long as necessary and handle it in accordance with applicable data protection laws.
How We Use Your Information
We use the information we collect to:
- Provide, operate, and maintain our AI voice and chat services.
- Respond to enquiries, quotes, demo requests, and support tickets.
- Process sign-ups, subscriptions, and payments.
- Improve the accuracy, quality, and performance of our AI models and platform.
- Send service updates, technical notices, and account-related communications.
- Detect, prevent, and address technical issues, misuse, or security incidents.
- Comply with our legal and regulatory obligations.
Legal Basis for Processing (GDPR)
Under GDPR, we rely on the following legal bases to process your personal data:
- Consent — where you have given clear consent for a specific purpose.
- Contract — where processing is necessary to provide the services you have requested.
- Legal Obligation — where we are required to process data to comply with the law.
- Legitimate Interests — where processing is necessary for our legitimate business interests, such as improving our services or preventing fraud, and does not override your rights.
Third-Party Services
To operate our services, we may share limited personal data with trusted third-party providers who act as our data processors. These may include:
- Base44 — application platform and hosting infrastructure.
- Retell AI — real-time AI voice agent infrastructure.
- Google Workspace — business communications and productivity.
- Google Analytics — website analytics (if enabled in the future).
- Calendar integrations — for appointment booking features.
- CRM integrations — for lead and customer relationship management.
All third-party providers are required to process personal data in accordance with GDPR and appropriate contractual safeguards.
Data Storage
Your personal data is stored on secure servers operated by us or our trusted third-party providers. Where data is transferred outside of the European Economic Area (EEA), we ensure appropriate safeguards are in place, such as Standard Contractual Clauses approved by the European Commission.
Data Security
We implement appropriate technical and organisational measures to protect your personal data from unauthorised access, disclosure, alteration, or destruction. These measures include encryption in transit, access controls, secure authentication, and regular review of our systems and processes.
Data Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including satisfying any legal, accounting, or reporting requirements. When personal data is no longer needed, it is securely deleted or anonymised.
Your GDPR Rights
Under GDPR, you have the following rights regarding your personal data:
Right of Access
You have the right to request a copy of the personal data we hold about you.
Right to Rectification
You have the right to request correction of inaccurate or incomplete data.
Right to Erasure
You may request the deletion of your personal data where there is no legal reason for us to continue processing it.
Right to Restriction
You have the right to request that we restrict the processing of your personal data in certain circumstances.
Right to Portability
You may request to receive your personal data in a structured, commonly used, machine-readable format.
Right to Object
You have the right to object to processing based on legitimate interests or direct marketing.
You also have the right to lodge a complaint with the Irish Data Protection Commission (DPC) if you believe your data has been handled unlawfully.
Contact Information
If you have any questions about this Privacy Policy or would like to exercise any of your GDPR rights, please contact us via the contact form on our website. We aim to respond to all privacy-related requests within 30 days.
Updates to This Policy
This Privacy Policy may be updated from time to time.
