Ijadi LLC (“Ijadi,” “we,” “us,” or “our”) operates the Ijadi.io AI voice agent platform (the “Platform”) and the ijadi.io website (the “Website”).
This Privacy Policy describes how we collect, use, share, and protect personal information in connection with the Website and the Platform. It applies to:
– Visitors to ijadi.io;
– Customers who hold accounts with Ijadi (each, a “Customer”);
– End users who use the Platform on behalf of a Customer;
– Consumers whose telephone numbers, names, or other personal information appear in data Customers load onto the Platform (“Called Parties”).
Our roles differ depending on the context (see Section 3). For business contracts and processor-specific terms, see our Data Processing Addendum, available on request.
2.1 Information You Provide
Account and billing information. When you create a Customer account, we collect: name, email address, business name, billing address, payment method (processed by our payment processor, Stripe — we do not store full payment card details), and authentication credentials.
Customer support communications. When you contact us for support, we collect your messages, attachments, and the metadata of the communication.
2.2 Information Customers Provide About Other People
Customers upload contact records to the Platform that contain personal information about Called Parties (e.g., name, telephone number, email address, brokerage affiliation, or other fields the Customer chooses to upload). For this category, Ijadi acts as a Processor on the Customer’s behalf (see Section 3). The Customer is the Controller and is responsible for obtaining all consents and notices required by applicable law before providing this data to Ijadi.
2.3 Information Generated by Use of the Platform
Call audio and transcripts. When the Platform makes or receives calls on behalf of a Customer, we may process the audio of the call and generate transcripts. Whether the Customer enables call recording, recording retention period, and transcript handling are controlled by the Customer in the Platform settings.
Call metadata. Date, time, duration, originating and destination numbers, disposition, opt-out events, and AI-voice disclosure events.
-Compliance artifacts. DNC scrub results, TCPA litigator scrub results, per-campaign attestation records, caller-ID configuration.
2.4 Information Collected Automatically
When you visit the Website or use the Platform, we automatically collect:
– IP address, device identifiers, browser type and version, operating system, referring URL, pages viewed, and timestamps;
– Cookies and similar technologies (see Section 10);
– Performance and error data for the Platform.
2.5 Information from Third Parties
We may receive information from: payment processors (transaction status), analytics providers, fraud-prevention services, and service providers we use to operate the Platform (each listed in our subprocessor list at https://ijadi.io/legal/subprocessors/).
Ijadi acts in different capacities depending on the personal information involved:
Ijadi as Controller. With respect to the Website, Customer account and billing information, support communications, automatically-collected information about visitors, and personal information about Ijadi’s own personnel, Ijadi determines the purposes and means of processing and acts as a Controller (or “Business” under the CCPA).
Ijadi as Processor. With respect to Customer Data uploaded by Customers (including personal information about Called Parties), Ijadi processes the data only on the Customer’s documented instructions and acts as a Processor (or “Service Provider” under the CCPA). The Customer is the Controller and is responsible for the lawful basis of processing, including obtaining required consents and providing required notices to Called Parties.
A Customer that requires a written Data Processing Addendum (“DPA”) incorporating GDPR Article 28 / UK GDPR / CCPA Service Provider terms can request execution at [email protected] .
We use the information described in Section 2 to:
– Provide, operate, secure, and improve the Platform and the Website;
– Process payments and manage Customer accounts;
– Communicate with Customers about the Platform, including service announcements, support responses, and security notices;
– Comply with legal obligations, respond to lawful requests, and enforce our agreements;
– Detect, investigate, and prevent fraud, abuse, and security incidents;
– Conduct internal analytics, research, and development to improve the Platform;
– For Customer Data, only on the Customer’s documented instructions and as necessary to provide the Platform.
We will not use Customer Data to train artificial intelligence models for third parties without the Customer’s separate written authorization.
For individuals located in the European Union, United Kingdom, or European Economic Area, our legal bases for processing personal information include:
– Contract: processing necessary to perform a contract with the Customer or take steps before entering one;
– Legitimate interests: operating, securing, and improving the Platform, fraud prevention, and direct communications with Customers, balanced against the rights of data subjects;
– Legal obligation: compliance with applicable laws, including telemarketing, consumer protection, tax, and accounting law;
– Consent: where required (e.g., certain cookies, marketing communications), with the right to withdraw consent at any time.
For Customer Data where Ijadi acts as Processor, the legal basis is established by the Customer as Controller.
We share personal information only in these circumstances:
Service providers and subprocessors. We share with vendors that help us operate the Platform and Website, under written agreements imposing confidentiality and data-protection obligations. Current subprocessors are listed at https://ijadi.io/legal/subprocessors/ and include providers of cloud hosting, telephony, payments, customer support, error monitoring, and analytics.
Legal and regulatory. We may disclose information to comply with a subpoena, court order, regulatory demand, or other legal process; to enforce our agreements; or to protect the rights, property, or safety of Ijadi, our Customers, Called Parties, or others.
Business transfers. In the event of a merger, acquisition, financing, reorganization, or sale of all or part of our assets, personal information may be transferred as part of the transaction, subject to standard confidentiality protections.
With Customer authorization. For Customer Data, we share only as the Customer instructs.
Aggregated or de-identified information. We may share information that has been aggregated or de-identified in a manner that cannot reasonably be used to identify an individual.
We do not sell personal information. We do not sell personal information for monetary consideration. For California “sale” and “share” definitions, see Section 9.
Ijadi is based in the United States. Personal information we collect or process is stored and processed in the United States and other jurisdictions where our service providers operate.
Where we transfer personal information of EU, UK, or EEA residents outside those jurisdictions, we rely on:
– The European Commission’s Standard Contractual Clauses (“SCCs”) and the UK International Data Transfer Addendum (“IDTA”) for international transfers;
– Adequacy decisions where applicable; or
– Other lawful transfer mechanisms permitted under applicable law.
Customers requiring SCCs or IDTA in a Data Processing Addendum can request execution at [email protected] .
We retain personal information only as long as necessary for the purposes described in this Policy or as required by law.
– Customer account and billing data: for the duration of the account plus the period required for tax, accounting, and legal-defense purposes (typically seven (7) years).
– Customer Data: as instructed by the Customer through Platform settings, subject to applicable legal-hold and audit-log requirements.
– Call recordings and transcripts: as configured by the Customer; Ijadi retains compliance-related audit logs of call metadata for not less than four (4) years.
– Compliance artifacts (DNC and litigator scrub receipts, attestations, opt-out events): not less than five (5) years.
– Website analytics and logs: typically up to twenty-four (24) months unless a shorter or longer period is required for security or compliance.
After the applicable retention period, we delete, anonymize, or aggregate personal information.
9.1 EU/UK/EEA Rights (GDPR)
Subject to applicable conditions and exceptions, individuals located in the EU, UK, or EEA have the right to:
– Access the personal information we hold about them;
– Request correction of inaccurate or incomplete information;
– Request erasure (“right to be forgotten”);
– Request restriction of processing;
– Object to processing based on legitimate interests;
– Request data portability;
– Withdraw consent where processing is based on consent.
To exercise these rights, contact [email protected] . We will respond within thirty (30) days. Individuals also have the right to lodge a complaint with their local supervisory authority.
For Customer Data where Ijadi is the Processor, requests should be directed to the Customer; Ijadi will assist the Customer in responding as required by the DPA.
9.2 California Rights (CCPA / CPRA)
California residents have the right to:
– Know what personal information we collect, use, disclose, and (if applicable) sell or share;
– Access the specific pieces of personal information we hold;
– Delete personal information (subject to exceptions, including transactions, fraud prevention, and legal compliance);
– Correct inaccurate personal information;
– Opt out of the sale or sharing of personal information (we do not sell personal information; see Section 6);
– Limit the use of sensitive personal information;
– Non-discrimination for exercising these rights.
We honor the Global Privacy Control (“GPC”) signal as an opt-out of sale and sharing. We do not knowingly process the personal information of California consumers under sixteen (16) without affirmative consent.
To exercise California rights, contact [email protected] . We will respond within forty-five (45) days, with one extension where permitted. We may request information to verify the requester’s identity.
Authorized agents may submit requests on a consumer’s behalf with appropriate authorization documentation.
9.3 Other U.S. State Rights
Residents of Colorado, Connecticut, Virginia, Utah, Texas, and other states with comprehensive privacy laws may have similar rights of access, deletion, correction, and opt-out. To exercise these rights, contact [email protected] .
9.4 California “Shine the Light”
California residents may request information about our disclosures of personal information to third parties for those third parties’ direct marketing purposes. We do not disclose personal information to third parties for their direct marketing purposes.
We use cookies and similar technologies to operate the Website, remember preferences, analyze usage, and (where consent is given) deliver tailored content. Categories include:
– Strictly necessary: required for the Website to function.
– Functional: remember settings and preferences.
– Analytics: measure usage and improve performance.
– Marketing: (only with consent) used for advertising and remarketing.
You can manage cookie preferences through your browser settings and, where available, our cookie consent banner. We honor the Global Privacy Control signal where applicable.
We maintain administrative, technical, and physical safeguards designed to protect personal information against unauthorized access, disclosure, alteration, or destruction. These include encryption in transit and at rest, access controls based on least privilege, network segmentation, logging and monitoring, and regular security assessments. Detailed information about our security posture is available at ijadi.io/legal/ or on request.
No system is completely secure. We encourage you to use strong, unique passwords, enable available authentication features, and report suspected security issues to [email protected] .
If we become aware of a personal-data breach affecting your personal information, we will notify you and applicable regulators as required by applicable law. For Customer Data where Ijadi is the Processor, we will notify the Customer without undue delay (and in any event within seventy-two (72) hours of becoming aware), in accordance with the DPA and applicable law.
The Platform and Website are not directed to individuals under the age of sixteen (16). We do not knowingly collect personal information from children under sixteen (16). If we learn that we have collected such information without verifiable parental consent, we will delete it. Parents or guardians who believe their child has provided us with personal information should contact [email protected] .
The Platform uses AI-generated voice technology to place outbound calls on behalf of Customers. Customers are responsible for ensuring that AI-voice disclosure is provided to Called Parties at the start of each call, as required by applicable law, and for obtaining any required consent to record calls in two-party-consent jurisdictions. Ijadi processes call audio and transcripts only on the Customer’s instructions.
We may use de-identified, aggregated call data to improve Platform performance, accuracy, and safety. We do not use Customer call recordings or transcripts to train artificial intelligence models for third parties without the Customer’s separate written authorization.
Our Website does not respond to “Do Not Track” browser signals at this time, due to the absence of an industry-standard mechanism. We do honor the Global Privacy Control signal as described in Section 9.2.
The Website may contain links to third-party websites or integrate with third-party services. This Policy does not apply to those websites or services. We encourage you to review the privacy policies of any third party before providing information.
We may update this Policy from time to time. The “Effective Date” at the top reflects the latest version. Material changes will be announced through the Website or by email to Customers. Continued use of the Website or Platform after the effective date of an update constitutes acceptance.
For questions about this Policy, to exercise your rights, or to report a privacy concern:
Ijadi LLC
Attn: Privacy
30 N Gould St #21395, Sheridan, WY 82801
Email: [email protected]
EU/UK representatives: we are not currently required to designate an Article 27 GDPR representative or a UK GDPR representative. If this changes, the representative’s details will be added here.