Skip to content
Cioplaz
Back to Home Pricing
Legal

Privacy Policy

Effective: October 1, 2026 · Last updated: September 24, 2026

Terms Privacy Refunds

Contents

  1. 1. Data controller
  2. 2. The short version
  3. 3. Data we process
  4. 4. Purposes & legal bases
  5. 5. Conversation partners
  6. 6. Retention
  7. 7. Processors & Whop
  8. 8. International transfers
  9. 9. Security
  10. 10. Your rights
  11. 11. Cookies
  12. 12. Changes

1. Data controller

This Privacy Policy explains how we process personal data under the EU General Data Protection Regulation 2016/679 (GDPR), the UK GDPR and other applicable data protection laws.

  • Controller: the operator of Cioplaz
  • Privacy contact: [email protected]

2. The short version

  • We don’t store raw audio. It’s transcribed in real time and deleted immediately.
  • You set how long transcripts and messages are kept (0 days, 7/30/90 days or custom).
  • We never use your conversations to train AI models, and we never sell your data.
  • Data is stored encrypted in EU data centers.
  • Payments are handled by Whop. We never see your full card details.
  • You can export or permanently delete all your data at any time.

3. Data we process

3.1 Account data

Name, email address, password (stored as a salted hash), company name, subscription plan and usage.

3.2 Billing data

Whop collects your payment details, billing address and tax information at checkout. We receive from Whop only what we need to manage your subscription: your name, email, country, plan, payment status and transaction IDs. We never receive your full card number.

3.3 Conversation data

  • Audio: call audio processed in real time. It is not stored unless you explicitly turn on the recording feature.
  • Transcripts and messages: text transcripts of calls, and the text of messages received and sent through Integrations.
  • Analysis data: mood, topic and intent estimates, summaries and generated reply suggestions.
  • Contact Profiles: contact names, platform identifiers and the instructions you write.
  • Knowledge base: documents you upload (e.g. CV, product sheets).

3.4 Integration data

Access tokens for connected platforms (encrypted), user IDs and the scopes of access. We never ask for or store your passwords for third-party platforms.

3.5 Technical data

IP address, device and operating system type, app version, error logs and usage statistics (e.g. Quota consumption, feature usage).

4. Purposes and legal bases

PurposeDataLegal basis (Art. 6 GDPR)
Creating your account and providing the ServiceAccount, conversation and integration dataPerformance of contract, Art. 6(1)(b)
Sending automatic messagesMessages, Contact ProfilesPerformance of contract, based on your explicit per-contact setting
Managing subscriptions and invoicesBilling data received from WhopPerformance of contract, Art. 6(1)(b); legal obligation, Art. 6(1)(c)
Security and abuse preventionTechnical data, logsLegitimate interest, Art. 6(1)(f)
Product improvement, anonymous statisticsAggregated, anonymized usage dataLegitimate interest, Art. 6(1)(f)
Marketing newsletterEmail, nameConsent, Art. 6(1)(a), withdrawable anytime

We do not use conversation content for advertising profiles, and we do not use it to train our own or third-party AI models.

5. Data about your conversation partners

Because of how the Service works, we also process personal data of people who take part in your calls and message threads: their voice, messages and names.

You use the Service for your own purposes, so you are responsible for making sure this processing is lawful. That includes informing the people concerned and, where required, obtaining their consent. For business customers, Cioplaz acts as a processor on your behalf, and we sign a data processing agreement (DPA).

If you believe your data has been processed by Cioplaz as someone’s conversation partner, you can request deletion at [email protected]. We will handle the request in coordination with the relevant User.

We do not extract or separately categorize special category data (e.g. health data) that comes up in a conversation. It is handled like the rest of the conversation, according to your retention settings.

6. Retention

DataRetention
Raw audioNot stored (held in memory only while being processed)
Transcripts, messages, analysesPer your settings. Default: Starter 7 days, Professional 90 days, Enterprise custom
Contact Profiles, knowledge baseUntil you delete them or close your account
Account data30 days after account closure
Billing recordsAs required by tax and accounting law (typically 8–10 years)
Security logs90 days

Deleted data is permanently removed from backups within 35 days.

7. Processors, and Whop

Whop. Payments are processed by Whop Inc., 300 Kent Ave #401, Brooklyn, NY 11249, USA ([email protected]). Whop is merchant of record for sales tax and VAT and processes your payment data as an independent controller under its own Privacy Policy.

We also use the following categories of processors, each bound by a contract under Art. 28 GDPR:

  • Cloud infrastructure and hosting: [provider name], EU region
  • Speech recognition and AI models: [provider name(s)], on terms that include zero data retention and no training
  • Email delivery: [provider name]
  • Error tracking and analytics: [provider name]

We will send the current list of processors on request, and we notify Enterprise customers of changes in advance.

8. International transfers

We store data primarily within the European Economic Area (EEA). When data is transferred outside the EEA (for example to Whop in the USA for payment processing), we rely on an adequacy decision (such as the EU–US Data Privacy Framework) or the European Commission’s Standard Contractual Clauses, with supplementary safeguards where needed.

9. Security

  • TLS 1.3 encryption in transit, AES-256 encryption at rest
  • Integration tokens encrypted in a separate key management system
  • Role-based access, two-factor authentication for staff, access logging
  • Regular security testing and vulnerability scanning

In the event of a personal data breach, we will notify the supervisory authority and, where required, affected individuals without undue delay, in line with Art. 33–34 GDPR.

10. Your rights

Under the GDPR you have the right to:

  • Access (Art. 15): find out what data we hold about you and get a copy.
  • Rectification (Art. 16): have inaccurate data corrected.
  • Erasure (Art. 17): have your data deleted. You can also do this directly in your account settings.
  • Restriction of processing (Art. 18).
  • Data portability (Art. 20): export your data in a machine-readable format (JSON).
  • Object (Art. 21) to processing based on legitimate interest.
  • Withdraw consent at any time, without affecting the lawfulness of prior processing.

Send requests to [email protected]. We respond within 30 days. For payment data held by Whop, you can also contact Whop directly.

You have the right to lodge a complaint with a supervisory authority, in particular in the EU member state of your habitual residence, place of work or the place of the alleged infringement. Our lead supervisory authority is the Hungarian National Authority for Data Protection and Freedom of Information (NAIH, naih.hu).

11. Cookies

Our website uses strictly necessary cookies (login, security, preferences). Analytics and marketing cookies are only set with your prior consent, which you can change at any time in the cookie settings. Whop’s checkout may set its own cookies, governed by Whop’s policies.

12. Changes to this policy

We may update this policy from time to time. For material changes we will notify you by email or in the app at least 30 days in advance. Previous versions are available on request.

Service provider: Cioplaz. Contact: [email protected].

Payments: Whop Inc., 300 Kent Ave #401, Brooklyn, NY 11249, USA. Merchant of record for sales tax and VAT only.

© 2026 Cioplaz. All rights reserved. Terms · Privacy · Refunds