Privacy Policy
This policy explains what we do with personal data: yours as a customer, and that of the people who call or message your business and reach Joe.
Last updated 30 August 2026
Who we are
[REGISTERED COMPANY NAME] ([COMPANY REGISTRATION NUMBER]), [REGISTERED ADDRESS], operates We love Joe (“we”, “us”). For the personal data described below, we act asdata controller for our own customers, and asdata processor for the conversations your customers have with Joe on your behalf.
Questions about this policy: [privacy@yourdomain]. Our Data Protection Officer is [DPO NAME AND CONTACT, or remove this line].
The two relationships
This distinction matters, because different rules apply to each.
- You, our customer. We decide why and how your account data is processed, so we are the controller. This section of the policy governs that.
- Your customers. When someone calls or messages your business and Joe answers, we process their data on your instructions. You are the controller; we are the processor. Our Data Processing Agreement governs that relationship, and it takes precedence over this policy where the two differ.
What we collect
From you, as a customer
- Account data — name, work email, company name, password hash.
- Billing data — plan, billing address, VAT number, and the payment token held by our payment processor. We never see or store full card numbers.
- Configuration data — everything you tell Joe about your business: services, prices, hours, policies, uploaded documents.
- Usage data — logins, feature use, credit consumption, and technical logs including IP address and browser.
From the people who contact you
- Conversation content — the message, email, chat or call, and Joe’s replies.
- Call audio and transcripts, where the channel is voice.
- Contact identifiers — phone number, email address or social handle, depending on the channel.
- Anything the caller volunteers during the conversation, which is why you should configure Joe not to ask for data you do not need.
Why we process it, and on what basis
- To provide the service — performance of our contract with you.
- To bill you — performance of contract, and legal obligation for tax records.
- To keep the service secure and working — our legitimate interest in preventing abuse and diagnosing faults.
- To improve the product — our legitimate interest, using aggregated and de-identified data. We do not train models on your conversation content.
- To send you service messages — performance of contract. Marketing email is sent only with your consent, and every message has an unsubscribe link.
Where data lives
Customer data and conversation content are stored on infrastructure inthe European Union. Some sub-processors listed below operate outside the EEA; where that is the case, transfers are covered by Standard Contractual Clauses or an adequacy decision.
Sub-processors
We use the following categories of sub-processor. We will give notice before adding a new one.
| Provider | Purpose | Region |
|---|---|---|
| [Cloud hosting provider] | Infrastructure and data storage | EU |
| [Model provider] | Language model inference | [REGION] |
| [Telephony provider] | Inbound and outbound calls, SMS | [REGION] |
| [Payment processor] | Subscription billing | [REGION] |
| [Email provider] | Transactional email | [REGION] |
| [Analytics provider] | Product and website analytics | [REGION] |
How long we keep it
- Account and configuration data — while your account is open, then 30 days after closure, after which it is deleted.
- Conversation content and transcripts — for the retention period you set in your workspace. You can shorten it, and you can delete individual conversations at any time.
- Call audio — deleted on the schedule you configure. If you have not set one, it is not retained beyond transcription.
- Billing records — as long as tax law requires, typically ten years.
- Security logs — twelve months.
Who we share it with
Only the sub-processors above, and only for the purposes listed. We do not sell personal data, and we do not share it for anyone else’s advertising. We may disclose data where legally compelled, and where we can lawfully tell you about it, we will.
Your rights
Under the GDPR you can request access, correction, erasure, restriction, portability, and object to processing based on legitimate interests. Write to[privacy@yourdomain] and we will respond within one month.
If the request concerns a conversation with a business that uses Joe, that business is the controller — we will pass the request to them and help them answer it.
You can also complain to your supervisory authority, [SUPERVISORY AUTHORITY, e.g. CNIL (France)].
Automated decision-making
Joe generates replies automatically, and routes conversations according to rules the business configures. He does not make decisions producing legal or similarly significant effects without a human in the loop, and any request crossing a configured threshold is escalated to a person rather than decided automatically.
Cookies
This website uses cookies that are strictly necessary for it to function. Any analytics or marketing cookies are set only after you consent, and you can change that choice at any time.
Security
Data is encrypted in transit and at rest. Access is limited to staff who need it, logged, and reviewed. We test the service regularly, and we will notify you and the relevant authority of a personal data breach within the deadlines the GDPR sets.
Changes
We will post material changes here and, for changes that affect you meaningfully, email you before they take effect.