Vestibo
All legal documents

Legal

Privacy policy

Privacy Policy

Version: v1.0 β€” 2026-07-23 Effective date: 2026-07-23

This Privacy Policy explains how Vestibo ("Vestibo", "we", "us", "our") collects, uses, and shares personal information when you (a) visit our website at https://vestibo.com, (b) use the Vestibo dashboard as a customer, (c) interact with an AI agent built on the Vestibo platform as an end-user, or (d) communicate with us. It is written to satisfy our obligations under the EU GDPR, the UK GDPR, the Swiss FADP, the California Consumer Privacy Act ("CCPA") as amended by the CPRA, Canada's PIPEDA, and Australia's Privacy Act. Counsel must localise the language for every jurisdiction where the Service is offered.

If you are an end-user interacting with an AI agent built on Vestibo on behalf of one of our customers, the customer is the data controller for that interaction. Refer to that customer's privacy notice. We act as a processor on the customer's behalf β€” see the Data Processing Addendum.

1. Who we are

Vestibo is based in the United States and its infrastructure runs in the United States. Our full registered company details and postal address are available on request at legal@vestibo.com. For privacy questions, contact:

  • Privacy / data subject requests: privacy@vestibo.com
  • EU / UK representative (Art. 27 GDPR / UK GDPR): not currently appointed. We do not target the Service to individuals in the EEA or the UK; if and when Art. 27 applies to us, we will appoint representatives and update this notice.
  • Data Protection Officer: not appointed β€” our processing does not meet the Art. 37 GDPR thresholds that require one. Privacy questions go to privacy@vestibo.com.

2. What we collect, why, and on what legal basis

2.1 If you are a website visitor

CategoryExamplesWhyLegal basis (GDPR)Retention
Device & log dataIP address, user-agent, pages viewed, referring URLOperate the website, detect abuse, debugLegitimate interests (Art. 6(1)(f))90 days
CookiesStrictly-necessary cookies plus a consent-exempt language-preference cookie (see Cookie Policy); no analytics or advertising cookies β€” aggregate usage is measured server-sideRun the siteLegitimate interests (Art. 6(1)(f))per Cookie Policy
CommunicationsEmail content you send to us, support ticketsRespond to youLegitimate interests / contract3 years

2.2 If you are a customer (account holder)

CategoryExamplesWhyLegal basisRetention
IdentityName, email, password hash, time-zone, localeProvide the Service, account securityContract (Art. 6(1)(b))account life + 30 days
BillingStripe customer ID, last 4 digits of card, billing address, VAT/GST IDCharge for the ServiceContract / legal obligation7 years (tax)
ConfigurationAgent name, industry, persona, guardrails, knowledge base textRun your agentContractaccount life + 30 days
TelemetryLogin times and product-usage milestones (e.g. onboarding/funnel steps reached)Detect abuse, measure adoption, improveLegitimate interests12 months
SupportEmail + chat content with our teamHelp youContract3 years
OAuth tokensTokens for the integrations you choose to connect (e.g. Google, Acuity, HubSpot, Salesforce), stored encrypted at restIntegrations you turn onContract (your consent)until revoked

2.3 If you are an end-user reaching an agent built on Vestibo

For end-users (people who text, call, or email an agent built on Vestibo by one of our customers), the customer is the data controller, and Vestibo processes the data on the customer's behalf under the DPA. Categories we may process on the customer's behalf include:

  • Identity: name, phone number, email address, postal address (where the caller provides it).
  • Conversation content: transcripts of the call/text/email/chat, voicemail recordings (where a caller leaves a voicemail β€” full live call audio is not recorded by default, so the stored record of a live call is its text transcript), and the structured fields the agent extracts (appointment time, reason for contact, etc.).
  • Health information ("PHI"): only if the customer is on the HIPAA-eligible tier and has signed a BAA with us. Otherwise you must not transmit PHI to the agent.
  • Sensitive special-category data (Art. 9 GDPR): we do not intentionally process it unless the customer has lawful basis and has configured the agent to handle it (e.g. a healthcare customer with a BAA).

2.4 Cookies and tracking technologies

See the dedicated Cookie Policy.

2.5 We do not knowingly collect data about children under 16

If you are under sixteen (16), please do not use the Service. If we become aware that we have collected personal information from a child under sixteen without verifiable parental consent, we will delete it.

3. How we use personal information

We use personal information to:

  • provide, secure, and improve the Service;
  • authenticate accounts (including via magic link and TOTP);
  • communicate with you about your account (transactional);
  • send marketing communications to customers who have opted in (you can unsubscribe at any time via the link in every marketing email);
  • bill you for paid plans and recover unpaid invoices;
  • detect, investigate, and prevent fraud, security incidents, and abuse;
  • comply with legal obligations (tax, accounting, lawful requests);
  • produce aggregated, de-identified usage statistics for our own product analytics.

We do not:

  • sell personal information (and have not in the prior twelve months) within the meaning of CCPA / CPRA;
  • share personal information for cross-context behavioural advertising;
  • use Customer Data, conversation transcripts, or end-user voice recordings to train any third-party foundation model.

Where we use an AI sub-processor (such as Anthropic β€” our default model provider β€” and, where enabled for a tenant, OpenAI, Deepgram, or ElevenLabs) we have contracted for the same restrictions β€” see SUBPROCESSORS.md.

4. Who we share data with

We share personal information only with:

  • Sub-processors β€” the third-party service providers listed in SUBPROCESSORS.md, each under a written contract that satisfies Art. 28 GDPR / SCC obligations and prohibits use of the data outside the Service.
  • Our customers β€” when you interact with an agent built on Vestibo, we share the conversation with the customer that configured the agent. That customer is the controller of that conversation under their privacy notice.
  • Authorities β€” where required by law (subpoena, warrant, court order). We challenge over-broad requests where possible and aim to publish an annual transparency report.
  • Acquirers β€” in a merger, acquisition, financing, or asset sale, personal information may be transferred to the acquirer subject to this Privacy Policy (or a more protective successor). We will notify customers and end-user controllers in advance.

We do not share personal information with data brokers, advertisers, or any third party for targeted advertising.

5. International transfers

We are headquartered in the United States. Our primary infrastructure runs in us-east-1. Where personal data of EU/EEA, UK, or Swiss residents is transferred to a country that has not been deemed by the European Commission to provide an adequate level of protection, we rely on:

  • the EU Standard Contractual Clauses (Module 2 β€” Controller to Processor) as adopted in Commission Implementing Decision (EU) 2021/914 of 4 June 2021;
  • the UK International Data Transfer Addendum issued by the ICO on 21 March 2022, where the transfer is from the UK;
  • the Swiss FDPIC's addendum to the SCCs, where the transfer is from Switzerland.

We maintain a Transfer Impact Assessment (TIA) process for onward transfers to US-based sub-processors under the Schrems II framework, and make our current assessment available to customers on request.

EU/UK customers can also rely on the EU-US Data Privacy Framework ("DPF") or its UK extension where the sub-processor is DPF-certified; the Sub-processors list flags this for each.

6. Security

We implement administrative, technical, and physical safeguards designed to protect personal information against unauthorised access, disclosure, alteration, and destruction. These are described in the public Security Overview. No method of electronic transmission or storage is one-hundred-percent secure; we cannot guarantee absolute security.

In the event of a personal data breach affecting personal data processed on a customer's behalf, we notify the customer without undue delay and in any event within forty-eight (48) hours of becoming aware, in accordance with Art. 33 GDPR and the DPA.

7. Retention

We retain personal information only as long as needed to provide the Service and meet the legal, accounting, and reporting obligations in Β§ 2 above. See the Retention column there for the relevant period.

After the retention period:

  • account data is deleted within thirty (30) days of account closure;
  • the data is purged from rolling backups within ninety (90) days;
  • aggregated, de-identified statistics may be retained indefinitely for internal analytics.

Customers can request earlier deletion under Β§ 8 (Your rights).

8. Your rights

Depending on where you live, you have some or all of the following rights regarding the personal information we hold about you:

  • Access β€” receive a copy of the personal information we hold about you.
  • Rectification β€” correct inaccurate personal information.
  • Erasure ("right to be forgotten") β€” request deletion, subject to legal exceptions.
  • Restriction β€” restrict our processing pending verification.
  • Portability β€” receive your data in a structured, commonly used machine-readable format.
  • Objection β€” object to processing based on legitimate interests, including profiling and direct marketing.
  • Withdraw consent β€” where processing is based on consent, at any time without affecting prior lawful processing.
  • Not be subject to a decision based solely on automated processing β€” we do not make legally significant or similarly significant decisions about you solely by automated means.
  • Lodge a complaint with your local supervisory authority (in the EU/EEA), the ICO (UK), the FDPIC (Switzerland), the OPC (Canada), the OAIC (Australia), or the California Privacy Protection Agency (CPPA).

California residents have additional rights under the CCPA / CPRA (right to know, right to delete, right to correct, right to opt out of sale or sharing β€” N/A as we do not sell or share for behavioural advertising β€” right to limit use of sensitive personal information, and the right to non-discrimination for exercising these rights).

To exercise any right, email privacy@vestibo.com or use the dashboard's privacy centre. We respond within thirty (30) days of verifying your identity (extendable to sixty (60) days for complex requests, with notice).

If you are an end-user reaching a Vestibo-powered agent, please contact the relevant customer first; we will forward your request to them as a processor.

9. Marketing

We send marketing emails only to customers who have opted in. Every marketing email contains an unsubscribe link. We do not send marketing SMS or calls. The transactional emails our customers' agents send through the Service are governed by the customer's relationship with the recipient, not by this Privacy Policy.

10. Children

The Service is not directed to children under sixteen (16). See Β§ 2.5.

11. Changes to this Policy

We may update this Privacy Policy from time to time. We will post the updated version with a new "Effective date" and, for material changes, notify customers by email and an in-product banner at least thirty (30) days before the change takes effect.

12. How to contact us

TopicChannel
Privacy / data subject requestsprivacy@vestibo.com
Security disclosuressecurity@vestibo.com β€” see Vulnerability Disclosure
Legal noticeslegal@vestibo.com
General contacthello@vestibo.com

Postal address: available on request at legal@vestibo.com.


Changelog

  • v1.0 (2026-07-23) β€” first published version; rebranded to Vestibo and reconciled to the current product.
  • v0.1 (2026-05-16) β€” initial internal draft.

Questions? Email legal@vestibo.com.