How REENG collects, uses, shares, secures and retains personal data — including call recordings, transcripts and voice profiles — across the REENG voice AI platform.
Version 1.0 · Effective August 2026
The short version
For most call data, REENG is not the decision-maker. A business deploys an AI agent on REENG; that business decides what is collected and why. We process it on their instructions. If you were a caller and want your data deleted, the business you called is the first place to ask — see section 17.
We do not train AI models on your data — not on recordings, transcripts, knowledge bases, or voice profiles — and we do not release them to third-party AI providers for that purpose. Section 10 covers this in full.
This Policy applies to personal data processed in connection with the REENG platform, our website, APIs, voice services and support channels. It addresses four groups of people whose data we handle differently:
This Policy does not cover the privacy practices of our customers. When a business uses REENG to run its own calls, that business determines what is collected, why, and for how long — its own privacy notice governs that relationship, not this one.
We aim to implement appropriate technical and organisational measures to support compliance with applicable data protection law, including the Nigeria Data Protection Act 2023, and — where relevant to a customer's use — the UK GDPR and EU GDPR.
REENG is a voice AI platform operated by REENG. We're headquartered and operate primarily out of Nigeria. For any privacy question, the fastest way to reach us is the contact page.
Our role changes depending on the data, and it determines who decides and who you should approach:
Where we act as processor, we process personal data only on the customer's instructions. We don't decide what an AI agent asks, what it records, or how long a customer chooses to retain it within the options we make available.
We collect only what's necessary for the purposes in section 9. We don't require end callers to give us data directly, and we don't enrich, append to, or purchase personal data about end callers from third parties. The platform isn't designed as a repository for sensitive personal data (payment card numbers, government IDs, health records, etc.) — but because calls are unscripted, such data may occasionally be spoken by a caller and captured incidentally in a recording or transcript. Customers are responsible for configuring redaction and retention controls appropriate to that risk.
When an end caller speaks to an AI agent, REENG receives the call through a telephony provider, converts speech to text, passes the text to a language model for interpretation and response, converts the response back to speech, and may execute business functions the customer has configured.
Whether calls are recorded is a customer configuration setting, not a REENG default. Where recording is enabled, audio is stored in the customer's workspace. Notice and consent obligations for recording rest with the customer — requirements differ materially between Nigeria, the UK, the EU and individual US states.
Transcripts are produced by automated speech recognition and may contain errors, particularly across accents, dialects, code-switching and background noise. AI-generated summaries are derived from transcripts and inherit those limitations — neither should be treated as a verbatim or authoritative record of what was said.
Call data is held within the customer's logically segregated workspace. Access controls are designed so that one customer cannot access another customer's call data.
A person's voice is treated in three distinct layers:
REENG does not claim ownership of any person's voice, likeness or vocal identity. Our rights are limited to processing voice material to operate the voice profile at the customer's instruction. Responsibility for obtaining consent from the person whose voice is captured rests with the customer — customers must obtain express, informed, documented and revocable consent, and must not submit the voice of a person under eighteen, or any third party's voice, without documented authorisation.
We can't independently verify that consent exists. If you believe your voice has been submitted to REENG without your authorisation, contact us via the contact page— this is one of the few cases where we'll act directly, and may suspend, quarantine or delete a voice profile in response to a credible complaint without waiting for the customer's instruction.
A customer may delete a voice sample or voice profile at any time through the dashboard.
Customers may upload business information — documents, product data, pricing, policies, FAQs — so an AI agent can retrieve it during a conversation. This content is processed into embeddings and stored in a vector database within the customer's workspace. Where a customer uploads material containing personal data, that data is processed on the customer's instructions; customers are responsible for having a lawful basis to upload it.
REENG routes conversation content to third-party providers for speech recognition, language understanding, response generation and speech synthesis (see section 12). AI output is generated rather than retrieved from a verified source, and may be inaccurate, incomplete or fabricated — where an AI-generated summary about you is inaccurate, you have a right to seek correction under section 16.
Where we act as controller, we process personal data to:
We do not sell personal data. We do not share personal data with third parties for their own marketing purposes. We do not use call data, transcripts or voice material to build profiles of end callers for our own commercial purposes.
REENG does not use customer data, call data, transcripts, voice samples or voice profiles to train general-purpose or foundation AI models, and does not make customer data available to third-party AI providers for their own model training. We use aggregated, de-identified operational metrics — call volumes, latency, error rates — for monitoring and capacity planning only; these never identify a customer, an end caller, or the content of a conversation.
We will not begin using customer data for model training without amending this Policy and notifying affected customers in advance.
REENG does not make automated decisions producing legal or similarly significant effects about end callers on its own initiative. The platform generates responses, classifications and summaries, and executes functions a customer has configured. A customer may configure a workflow in which an AI agent decides an outcome without human involvement — where that happens, the customer is the controller responsible for compliance with the law governing automated decision-making. Customers are required to maintain meaningful human review, confirmation steps or escalation paths for consequential workflows (medical, financial, legal, employment, insurance and emergency contexts). REENG must not be used as, or in place of, an emergency service.
Delivering voice AI at production quality currently requires services that aren't all hosted within Nigeria — speech recognition, language models, speech synthesis, cloud hosting and monitoring may each be performed outside the country. This means personal data in a call — including the caller's words and voice — may be transmitted across borders during the call itself. We state this plainly because it's material; a customer operating in a regulated sector should assess it before deployment. Where a customer requires call data or voice material to remain within a specified jurisdiction, this can be discussed directly with us.
We keep personal data only as long as necessary for the purpose it was collected for, or as required by law. Retention for data held in a customer workspace (recordings, transcripts, call metadata, voice samples and profiles) is configured by the customer within the options we make available, and voice samples/profiles are deleted on withdrawal of consent. Account data is kept for the duration of the account; billing and financial records are kept as required by applicable law. When data is deleted, it's removed from production systems promptly; copies may persist in encrypted backups until overwritten in the ordinary backup cycle, during which time they aren't accessible for operational use.
We implement technical and organisational measures appropriate to the risk, including encryption in transit and at rest, role-based access control, tenant isolation between customer workspaces, authentication controls, secure management of API credentials, logging and monitoring, and backups. REENG does not currently hold formal third-party security certifications — if that changes, this Policy will say so explicitly.
No system is completely secure, and we can't guarantee that unauthorised access, disclosure, alteration or destruction will never occur. Where a personal data breach occurs, we'll notify the Nigeria Data Protection Commission within the period required by the Nigeria Data Protection Act 2023, and notify affected customers without undue delay so they can meet their own obligations. Account holders are responsible for protecting their own credentials and API keys, and for promptly deactivating access for individuals no longer entitled to it.
Subject to applicable law, you have the right to:
To exercise any of these, reach us via the contact page. We may need to verify your identity before acting. We may be unable to fulfil a request in full — for example where data is subject to a legal retention obligation, or where disclosure would reveal another person's data — and if we decline, we'll explain why. If you're dissatisfied with how we've handled a request, you can also complain to the Nigeria Data Protection Commission, or, if you're in the UK or EEA, your national supervisory authority.
If you spoke to an AI agent and want your data handled, contact the business you called first — they decide what is recorded, why, and for how long; we only run the infrastructure on their instructions, and they're best placed to locate your call and act on your request. If you can't identify or reach that business, contact us and we'll make reasonable efforts to identify the customer concerned and pass your request to them.
The exception is unauthorised use of your voice: if you believe your voice was cloned or used on REENG without your authorisation, contact us directly and we'll investigate without waiting for the customer's instruction. Customers are also required to honour a caller's request to be transferred to a human representative where escalation is available — if that didn't happen, raise it with the business you called.
REENG accounts may only be created by individuals aged eighteen or over (or the age of legal majority in their jurisdiction) acting for a business. Customers must not submit the voice of a person under eighteen as a voice sample under any circumstances. Where a customer operates a service that children may call, that customer is responsible for the additional protections applicable law requires. We don't knowingly process a child's personal data as controller — if you believe we have, contact us and we'll investigate and delete it where appropriate.
We may update this Policy to reflect changes in our services, subprocessors, infrastructure, or legal requirements. Where a change materially affects how we process personal data — including the model-training position in section 10, the transfer position in section 13, or retention in section 14 — we'll give advance notice by email to account administrators and by notice in the dashboard before the change takes effect. Minor editorial corrections may be made without notice.
For anything in this Policy — data protection questions, rights requests, or a report of unauthorised voice use — the fastest way to reach us is the contact page.
REENG · Privacy Policy · Version 1.0 · reeng-ai.dev