REENG / Legal

Privacy Policy

How REENG collects, uses, shares, secures and retains personal data — including call recordings, transcripts and voice profiles — across the REENG voice AI platform.

Version 1.0 · Effective August 2026

The short version

For most call data, REENG is not the decision-maker. A business deploys an AI agent on REENG; that business decides what is collected and why. We process it on their instructions. If you were a caller and want your data deleted, the business you called is the first place to ask — see section 17.

We do not train AI models on your data — not on recordings, transcripts, knowledge bases, or voice profiles — and we do not release them to third-party AI providers for that purpose. Section 10 covers this in full.

1. Scope and Who This Covers

This Policy applies to personal data processed in connection with the REENG platform, our website, APIs, voice services and support channels. It addresses four groups of people whose data we handle differently:

  • Customer personnel — administrators, developers, billing contacts and other authorised users at a business that holds a REENG account.
  • End callers — individuals who call, or are called by, an AI agent that a customer has deployed.
  • Voice contributors — individuals whose voice is submitted to create a voice profile.
  • Website visitors and prospects — people who visit reeng-ai.dev, request a demo, or contact us.

This Policy does not cover the privacy practices of our customers. When a business uses REENG to run its own calls, that business determines what is collected, why, and for how long — its own privacy notice governs that relationship, not this one.

We aim to implement appropriate technical and organisational measures to support compliance with applicable data protection law, including the Nigeria Data Protection Act 2023, and — where relevant to a customer's use — the UK GDPR and EU GDPR.

2. Who We Are

REENG is a voice AI platform operated by REENG. We're headquartered and operate primarily out of Nigeria. For any privacy question, the fastest way to reach us is the contact page.

3. Controller and Processor Roles

Our role changes depending on the data, and it determines who decides and who you should approach:

  • We act as processor for call data, recordings, transcripts, summaries, knowledge base content, voice samples and voice profiles submitted by a customer. The customer is the controller.
  • We act as controller for account and authorised-user data, billing records, support correspondence, platform security logs, and website/marketing/prospect data.

Where we act as processor, we process personal data only on the customer's instructions. We don't decide what an AI agent asks, what it records, or how long a customer chooses to retain it within the options we make available.

4. Categories of Personal Data

  • Account data — name, business email, phone number, organisation, job title, credentials.
  • Billing data — subscription and plan details, usage volumes, invoices, payment status.
  • Customer business data — company/product information, documents and records uploaded to a workspace.
  • Call data — phone numbers, call metadata, timestamps, duration, recordings, transcripts, AI-generated summaries.
  • Voice data — voice samples, voice profiles and generated speech.
  • Technical data — IP address, device/browser information, logs, API activity, security events.
  • Support data — correspondence and diagnostic information you choose to share.

We collect only what's necessary for the purposes in section 9. We don't require end callers to give us data directly, and we don't enrich, append to, or purchase personal data about end callers from third parties. The platform isn't designed as a repository for sensitive personal data (payment card numbers, government IDs, health records, etc.) — but because calls are unscripted, such data may occasionally be spoken by a caller and captured incidentally in a recording or transcript. Customers are responsible for configuring redaction and retention controls appropriate to that risk.

5. Call Data, Recordings and Transcripts

When an end caller speaks to an AI agent, REENG receives the call through a telephony provider, converts speech to text, passes the text to a language model for interpretation and response, converts the response back to speech, and may execute business functions the customer has configured.

Whether calls are recorded is a customer configuration setting, not a REENG default. Where recording is enabled, audio is stored in the customer's workspace. Notice and consent obligations for recording rest with the customer — requirements differ materially between Nigeria, the UK, the EU and individual US states.

Transcripts are produced by automated speech recognition and may contain errors, particularly across accents, dialects, code-switching and background noise. AI-generated summaries are derived from transcripts and inherit those limitations — neither should be treated as a verbatim or authoritative record of what was said.

Call data is held within the customer's logically segregated workspace. Access controls are designed so that one customer cannot access another customer's call data.

6. Voice Samples and Voice Profiles

A person's voice is treated in three distinct layers:

  • Voice sample — audio submitted to create or configure a custom voice, stored in the customer's workspace and used only to build and maintain the voice profile.
  • Voice profile — the configuration derived from voice samples. Never shared across workspaces, never used for another customer, never used for general model training.
  • Generated speech — audio produced using the voice profile, treated as call data and retained accordingly.

REENG does not claim ownership of any person's voice, likeness or vocal identity. Our rights are limited to processing voice material to operate the voice profile at the customer's instruction. Responsibility for obtaining consent from the person whose voice is captured rests with the customer — customers must obtain express, informed, documented and revocable consent, and must not submit the voice of a person under eighteen, or any third party's voice, without documented authorisation.

We can't independently verify that consent exists. If you believe your voice has been submitted to REENG without your authorisation, contact us via the contact page— this is one of the few cases where we'll act directly, and may suspend, quarantine or delete a voice profile in response to a credible complaint without waiting for the customer's instruction.

A customer may delete a voice sample or voice profile at any time through the dashboard.

7. Knowledge Base Content and AI Processing

Customers may upload business information — documents, product data, pricing, policies, FAQs — so an AI agent can retrieve it during a conversation. This content is processed into embeddings and stored in a vector database within the customer's workspace. Where a customer uploads material containing personal data, that data is processed on the customer's instructions; customers are responsible for having a lawful basis to upload it.

REENG routes conversation content to third-party providers for speech recognition, language understanding, response generation and speech synthesis (see section 12). AI output is generated rather than retrieved from a verified source, and may be inaccurate, incomplete or fabricated — where an AI-generated summary about you is inaccurate, you have a right to seek correction under section 16.

8. Website Data and Cookies

The REENG dashboard and marketing site primarily use browser local storage — not cookies — to keep you signed in and remember your theme preference. If we add analytics or marketing cookies in the future, this section will be updated before they're deployed, and non-essential cookies will only be set with your consent.

Telephone interactions between an end caller and an AI agent don't involve cookies or web device identifiers of any kind — this section applies to our website and dashboard only.

9. Why We Process Data

Where we act as controller, we process personal data to:

  • Provide the service — create and administer accounts, authenticate users, provision workspaces, route calls, operate AI agents.
  • Bill and administer accounts — meter usage, issue invoices, collect payment, maintain financial records.
  • Provide support — respond to enquiries, diagnose faults, restore service.
  • Prevent security incidents and abuse — monitor for unauthorised access, detect fraud, investigate credible reports of unauthorised voice cloning.
  • Maintain service reliability — using aggregated, de-identified operational metrics only.
  • Meet legal and regulatory obligations.
  • Send business communications — service notices, contractual notices, security advisories.
  • Market our services to business contacts who haven't opted out.

We do not sell personal data. We do not share personal data with third parties for their own marketing purposes. We do not use call data, transcripts or voice material to build profiles of end callers for our own commercial purposes.

10. Model Training

REENG does not use customer data, call data, transcripts, voice samples or voice profiles to train general-purpose or foundation AI models, and does not make customer data available to third-party AI providers for their own model training. We use aggregated, de-identified operational metrics — call volumes, latency, error rates — for monitoring and capacity planning only; these never identify a customer, an end caller, or the content of a conversation.

We will not begin using customer data for model training without amending this Policy and notifying affected customers in advance.

11. Automated Decision-Making

REENG does not make automated decisions producing legal or similarly significant effects about end callers on its own initiative. The platform generates responses, classifications and summaries, and executes functions a customer has configured. A customer may configure a workflow in which an AI agent decides an outcome without human involvement — where that happens, the customer is the controller responsible for compliance with the law governing automated decision-making. Customers are required to maintain meaningful human review, confirmation steps or escalation paths for consequential workflows (medical, financial, legal, employment, insurance and emergency contexts). REENG must not be used as, or in place of, an emergency service.

12. Disclosure, Sharing and Subprocessors

We disclose personal data only:

  • To subprocessors who provide infrastructure, telephony, AI, storage, payment and support services on our behalf, under written contract.
  • To the customer whose workspace the data belongs to, and their authorised users.
  • To professional advisers bound by duties of confidentiality.
  • To public authorities where required by valid legal process.
  • In a corporate transaction (merger, acquisition, sale of assets), subject to equivalent protections continuing to apply.
  • With your consent, or at your direction.

We do not sell personal data, and don't disclose it to third parties for their own independent purposes.

The categories of subprocessors we currently use, based on our actual infrastructure:

  • Cloud hosting — Railway (application hosting) and Supabase (database).
  • Telephony — Twilio.
  • Speech recognition — Deepgram.
  • Language model inference — Groq.
  • Speech synthesis and voice cloning — ElevenLabs.
  • Vector search / embeddings — Qdrant.
  • Transactional email — Resend, for account and waitlist notifications.
  • Payments — Flutterwave.

Each is engaged under terms restricting use of REENG customer data to providing the contracted service. We'll update this list as our infrastructure evolves.

13. International Transfers

Delivering voice AI at production quality currently requires services that aren't all hosted within Nigeria — speech recognition, language models, speech synthesis, cloud hosting and monitoring may each be performed outside the country. This means personal data in a call — including the caller's words and voice — may be transmitted across borders during the call itself. We state this plainly because it's material; a customer operating in a regulated sector should assess it before deployment. Where a customer requires call data or voice material to remain within a specified jurisdiction, this can be discussed directly with us.

14. Data Retention

We keep personal data only as long as necessary for the purpose it was collected for, or as required by law. Retention for data held in a customer workspace (recordings, transcripts, call metadata, voice samples and profiles) is configured by the customer within the options we make available, and voice samples/profiles are deleted on withdrawal of consent. Account data is kept for the duration of the account; billing and financial records are kept as required by applicable law. When data is deleted, it's removed from production systems promptly; copies may persist in encrypted backups until overwritten in the ordinary backup cycle, during which time they aren't accessible for operational use.

15. Security

We implement technical and organisational measures appropriate to the risk, including encryption in transit and at rest, role-based access control, tenant isolation between customer workspaces, authentication controls, secure management of API credentials, logging and monitoring, and backups. REENG does not currently hold formal third-party security certifications — if that changes, this Policy will say so explicitly.

No system is completely secure, and we can't guarantee that unauthorised access, disclosure, alteration or destruction will never occur. Where a personal data breach occurs, we'll notify the Nigeria Data Protection Commission within the period required by the Nigeria Data Protection Act 2023, and notify affected customers without undue delay so they can meet their own obligations. Account holders are responsible for protecting their own credentials and API keys, and for promptly deactivating access for individuals no longer entitled to it.

16. Your Rights

Subject to applicable law, you have the right to:

  • Access — confirmation of whether we process your data, and a copy of it.
  • Rectification — correction of inaccurate data, including inaccurate AI-generated summaries about you.
  • Erasure — deletion where data is no longer necessary, consent is withdrawn, or processing is unlawful.
  • Restriction — limiting processing while a dispute about accuracy or lawfulness is resolved.
  • Portability — a copy in a structured, machine-readable format.
  • Objection — including an unconditional stop to direct marketing.
  • Withdraw consent — at any time, without affecting processing before withdrawal.
  • Complain — to a supervisory authority (see below).

To exercise any of these, reach us via the contact page. We may need to verify your identity before acting. We may be unable to fulfil a request in full — for example where data is subject to a legal retention obligation, or where disclosure would reveal another person's data — and if we decline, we'll explain why. If you're dissatisfied with how we've handled a request, you can also complain to the Nigeria Data Protection Commission, or, if you're in the UK or EEA, your national supervisory authority.

17. If You Were an End Caller

If you spoke to an AI agent and want your data handled, contact the business you called first — they decide what is recorded, why, and for how long; we only run the infrastructure on their instructions, and they're best placed to locate your call and act on your request. If you can't identify or reach that business, contact us and we'll make reasonable efforts to identify the customer concerned and pass your request to them.

The exception is unauthorised use of your voice: if you believe your voice was cloned or used on REENG without your authorisation, contact us directly and we'll investigate without waiting for the customer's instruction. Customers are also required to honour a caller's request to be transferred to a human representative where escalation is available — if that didn't happen, raise it with the business you called.

18. Children's Data

REENG accounts may only be created by individuals aged eighteen or over (or the age of legal majority in their jurisdiction) acting for a business. Customers must not submit the voice of a person under eighteen as a voice sample under any circumstances. Where a customer operates a service that children may call, that customer is responsible for the additional protections applicable law requires. We don't knowingly process a child's personal data as controller — if you believe we have, contact us and we'll investigate and delete it where appropriate.

19. Changes and Contact

We may update this Policy to reflect changes in our services, subprocessors, infrastructure, or legal requirements. Where a change materially affects how we process personal data — including the model-training position in section 10, the transfer position in section 13, or retention in section 14 — we'll give advance notice by email to account administrators and by notice in the dashboard before the change takes effect. Minor editorial corrections may be made without notice.

For anything in this Policy — data protection questions, rights requests, or a report of unauthorised voice use — the fastest way to reach us is the contact page.

REENG · Privacy Policy · Version 1.0 · reeng-ai.dev