This Privacy Policy explains how Issei, a company registered in Barcelona, Spain ("Issei", "we", "us"), collects, uses, stores, and protects personal data when you visit our website at issei.ai, contact us, book a demo, or interact with the AI agents Issei operates on behalf of its customers (together, the "Services").
Issei provides AI agents that carry out a company's repetitive operational work inside the tools the company already uses. The agents answer, quote and estimate, schedule, follow up, and invoice end to end, over channels such as WhatsApp, phone, and email, integrated with the customer's own systems (CRM, ERP, TMS, order and booking software, spreadsheets, and email). We serve customers in sectors including logistics, insurance, retail, services, finance, real estate, and agriculture.
Issei is established in the European Union and is directly subject to the General Data Protection Regulation (GDPR) (Regulation (EU) 2016/679) and Spanish data protection law (LOPDGDD). Where Issei processes personal data of individuals located outside the EU/EEA, we apply the same standards set out in this Policy, regardless of the jurisdiction of the data subject.
1. Who This Policy Covers
This Policy applies to three groups:
- Customers: businesses and their authorised representatives who engage Issei to deploy AI agents, and the individuals at those businesses who administer the service.
- End contacts: individuals whose personal data flows through an AI agent because they interact with a customer over a channel the agent operates (for example, a person who messages a customer's WhatsApp line or emails its support address), or whose data is contained in the customer's systems that the agent is connected to.
- Visitors: individuals who visit our public website (issei.ai), contact us, or book a demo without becoming a customer.
If you are an end contact, Issei processes your personal data as a data processor on behalf of the customer whose channel or systems you interacted with. That customer is the data controller and is your primary contact for exercising data rights. You may also contact Issei directly at hi@issei.ai.
2. Data Controller and Processor
Controller: Issei is the data controller for customer account data, website usage data, and data collected from Visitors, demo bookings, and contact requests on issei.ai.
Processor: For business data that flows through the AI agents on behalf of a customer, Issei acts as a data processor under the documented instructions of that customer, in accordance with GDPR Article 28 and the Data Processing Agreement (DPA) agreed with each customer and available to customers on request.
Controller for anonymised data: Issei may also process anonymised and aggregated data derived from the Services as an independent controller for the purpose of improving and operating the Services. This data cannot be used to identify any individual. See Section 3.4.
3. What Data We Collect and Why
3.1 Customer Data
- Contact and account: name, work email, job title, company name. Purpose: account creation, service configuration, and support.
- Authentication: email and hashed password. We never store plaintext passwords.
- Usage data: features accessed, actions performed, session timestamps, IP address, browser type. Purpose: service operation, security, and aggregate improvement analytics.
- Billing status: subscription tier and payment status. Payment card details are processed exclusively by our payment provider and never stored by Issei.
3.2 Business Data Processed by the AI Agents (processed on behalf of customers)
When an AI agent operates on a customer's behalf, it processes the data contained in the customer's channels and connected systems. Depending on the customer's configuration and sector, this may include:
- Identity and contact data of the customer's own contacts: name, email address, phone number, WhatsApp identifier.
- Interaction content: the content of messages, calls, and emails exchanged between the customer's contacts and the AI agent, including text transcripts of voice interactions where applicable.
- Operational records: quotes and estimates, orders and bookings, schedules and appointments, follow-up records, and invoices generated or handled by the agent within the customer's workflows.
- Business system data: records the agent reads from or writes to the customer's CRM, ERP, TMS, order or booking software, spreadsheets, and email.
- AI-generated outputs: draft replies, quotes, summaries, and other outputs produced by the agent while carrying out the customer's operational tasks.
We do not intentionally collect special categories of personal data (GDPR Article 9). If such data is present in a customer's channels or systems, it is processed solely because the customer's data contained it. Customers who instruct Issei to process special category data assume full responsibility for the lawfulness of that processing.
Customer data is hosted in the European Union and is not used to train AI models.
3.3 Visitor Data (issei.ai)
- Device and browser data: IP address, browser type, pages visited, and session duration, collected via essential and analytical cookies where consent is given.
- Contact and demo data: name, work email, company name, and any message content you provide when you contact us or book a demo. Demo scheduling is handled through Google Calendar.
3.4 Anonymised and Aggregated Data (Issei as Controller)
Issei may derive anonymised, aggregated data from the Services (for example, aggregate statistics on service usage or model performance metrics) for the purpose of improving and operating the Services. This processing is carried out by Issei as an independent controller on the basis of legitimate interests (GDPR Art. 6(1)(f)).
Issei applies a rigorous anonymisation standard: data is only treated as anonymised when re-identification of any individual is not reasonably possible, taking into account all means likely to be used. Anonymised data is never shared with customers or third parties in a form that could identify any individual.
4. Legal Basis for Processing
- Contractual necessity (Art. 6(1)(b)): processing customer account data to perform the service contract, and processing demo requests to respond to you.
- Consent (Art. 6(1)(a)): non-essential cookies on issei.ai (obtained via cookie banner), including analytics loaded only after consent.
- Legitimate interests (Art. 6(1)(f)): service security, fraud prevention, and processing anonymised data to improve the Services. We have assessed that these interests are not overridden by data subject rights.
- Legal obligation (Art. 6(1)(c)): retaining records required by applicable law.
For business data processed through the AI agents, the legal basis for the underlying processing is determined by the customer as data controller; Issei processes that data on the customer's documented instructions under the DPA.
5. AI Processing, Automated Decisions, and the EU AI Act
Issei is aware of and aligned with the EU AI Act. Our AI agents are designed to carry out operational tasks — answering, quoting and estimating, scheduling, following up, and invoicing — within the workflows the customer defines, and always under the customer's control.
- Human oversight: the customer configures the scope of what its agents may do and retains the ability to review, correct, and override agent actions. Issei does not use the agents to make decisions producing legal or similarly significant effects on individuals without a meaningful role for the customer.
- No prohibited practices: Issei does not design or permit the Services to be used for practices prohibited under the EU AI Act.
- Transparency: where an individual interacts with an AI agent, this is disclosed so that people are aware they are dealing with an automated system, in line with the EU AI Act's transparency obligations.
- Audit trail: a log is maintained of agent actions, recording relevant inputs and outputs, so that the customer can review what the agent did. This log supports accountability and compliance.
Issei acts as the provider of the AI system. The customer acts as the deployer. As provider, Issei is responsible for the design and documentation of the AI system. As deployer, the customer is responsible for its lawful use within its own operations. This allocation of responsibility is consistent with the EU AI Act and does not limit Issei's obligations as provider.
6. Your Right to Information About AI Processing
If an AI agent processed your personal data as part of your interaction with an Issei customer, you have the right to request meaningful information about the processing (GDPR Art. 15).
Issei will facilitate, upon request:
- A description of the type of AI processing applied to your data (for example, generating a reply, a quote, or a scheduling proposal).
- The categories of input data used to generate outputs relating to you (for example, message content, order details).
- A general explanation of how the AI agent produces its outputs, including the main factors considered.
- Confirmation of the customer's role in reviewing or controlling the agent's actions.
Issei will not disclose proprietary model weights, internal prompt architecture, or technical implementation details that constitute trade secrets, except where disclosure is required by applicable law. Where a conflict arises between transparency obligations and intellectual property protection, Issei will provide the maximum disclosure permitted by law.
Because Issei acts as a processor for business data handled by the agents, requests relating to a specific interaction may be routed to the relevant customer, who is the data controller and holds the relevant context. Requests may be submitted to hi@issei.ai. We will respond within 30 days.
7. How We Share Data
We share data only in the following circumstances:
- Sub-processors: we engage third-party service providers to operate the Services (infrastructure, communications delivery, AI processing, analytics). All sub-processors operate under GDPR-compliant data processing agreements. Our current sub-processors include:
- Amazon Web Services — hosting and infrastructure, in the EU region (Frankfurt).
- Google — Google Analytics (loaded only after cookie consent) and Google Calendar (demo scheduling).
- Customers: business data processed by an AI agent is accessible to the customer on whose behalf the agent operates.
- Legal requirements: where required by applicable law, court order, or regulatory authority, or to protect the rights and safety of Issei or others.
- Business transfers: in the event of a merger, acquisition, or asset sale, data may transfer to the successor entity under equivalent protections. We will notify affected customers in advance where practicable.
8. International Data Transfers
Issei is established in Spain (EU), and customer data is hosted in the European Union (AWS, Frankfurt). Where any sub-processor operates infrastructure outside the EEA, or where personal data is otherwise transferred outside the EEA, we ensure appropriate safeguards are in place: Standard Contractual Clauses (SCCs) approved by the European Commission (Decision 2021/914), or reliance on an adequacy decision where applicable.
Where Issei processes personal data of individuals located in countries with their own data protection laws, the customer is responsible for ensuring that such processing complies with applicable local law. Issei applies GDPR-equivalent standards as a baseline for all processing regardless of the data subject's location.
9. Data Retention
- Customer account data: retained for the duration of the active subscription, plus 30 days after closure for export. Then permanently deleted.
- Business data processed by the AI agents: retained for the period configured by the customer, or for as long as necessary to provide the Services, and deleted or returned in accordance with the DPA on termination. Customers may delete such data at any time through the service or on request.
- AI audit logs: retained for the period necessary for accountability and compliance, then deleted or anonymised.
- Visitor data: aggregated analytics retained for up to 12 months. Contact and demo submissions retained for up to 24 months.
10. Your Rights (GDPR and Equivalent)
If you are in the EU/EEA, you have the following rights under GDPR. Issei applies equivalent rights as a matter of policy to data subjects located outside the EU/EEA:
- Access (Art. 15): request a copy of your personal data, including information about AI processing where applicable (see Section 6).
- Rectification (Art. 16): request correction of inaccurate or incomplete data.
- Erasure (Art. 17): request deletion of your data, subject to legal retention obligations.
- Restriction (Art. 18): request we limit processing in certain circumstances.
- Portability (Art. 20): receive your data in a structured, machine-readable format.
- Object (Art. 21): object to processing based on legitimate interests.
- Withdraw consent (Art. 7(3)): withdraw cookie consent at any time, without affecting prior lawful processing.
- Not to be subject to solely automated decisions (Art. 22): where automated processing would produce legal or similarly significant effects, you have the right not to be subject to a decision based solely on it. If you believe such a decision was made about you, contact hi@issei.ai.
- Complaint: you may lodge a complaint with the Agencia Española de Protección de Datos (AEPD, aepd.es) or the supervisory authority in your country of residence.
Submit requests to hi@issei.ai. We will respond within 30 days. For requests relating to business data processed by an AI agent, we will route the request to the relevant customer where they are the appropriate respondent as data controller. If the customer cannot be reached or no longer exists, Issei will act directly to fulfil the request to the extent it is able.
11. Security
- All data is encrypted in transit (TLS 1.2+) and at rest.
- Access controls ensure that no customer can access data belonging to another customer.
- Administrative access to raw data is restricted, server-side only, and is never exposed to the browser.
- Customer data is hosted in the European Union and is not used to train AI models.
- In the event of a personal data breach affecting your rights and freedoms, we will notify the relevant supervisory authority within 72 hours and affected individuals without undue delay, in accordance with GDPR Articles 33-34.
12. Cookies
On the public website (issei.ai): we may use essential, functional, and analytical cookies. A consent banner is presented on first visit and your preferences are respected. Analytical cookies, including Google Analytics, are loaded only after you give consent. You may withdraw consent or manage cookies through your browser settings at any time.
We do not use advertising or cross-site tracking cookies on any Issei-operated domain.
13. Children
The Services are not directed to individuals under 16. We do not knowingly collect data from minors. If we become aware that a minor has provided data, we will delete it promptly. Contact hi@issei.ai if you believe this has occurred.
14. Changes to This Policy
We may update this Policy. Material changes will be notified to customers by email at least 14 days before taking effect. The date at the top of this document indicates the current revision. Continued use of the Services after a change takes effect constitutes acceptance.
15. Contact
- Privacy and general enquiries: hi@issei.ai
- Supervisory authority: Agencia Española de Protección de Datos (AEPD), aepd.es