Effective Date: January 1, 2026
Last Updated: June 21, 2026
Poniq, Inc. (“Poniq,” “we,” “us,” or “our”) is an independent California corporation founded in 2025. We provide the Poniq AI sales agent platform and related services (the “Service”). This Privacy Policy describes how we collect, use, disclose, retain, and protect personal information when you:
- Visit our websites (including poniq.ai and any subdomains or successor sites, the “Site”);
- Join our waitlist or request early access;
- Create or use a Poniq account or dashboard;
- Use or configure the Service on your website(s); or
- Otherwise interact with us.
By using the Site or Service, you acknowledge this Policy.
1. Key Distinctions: Controller vs. Processor Roles
We process personal information in two primary capacities. This distinction is important for your rights and our obligations.
1.1 Poniq as a Business/Controller (our direct relationship with you)
When you visit the Site, join the waitlist, register for an account, subscribe, contact support, or provide information to us directly, we act as a “business” under the California Consumer Privacy Act (CCPA/CPRA) and as a “controller” under laws such as the GDPR. This Policy primarily addresses that activity.
1.2 Poniq as a Service Provider/Processor (your website visitors)
When you deploy the Poniq agent on your website, we process personal information of your visitors (end-users who chat with the AI sales agent) as a service provider or processor solely on your behalf and at your direction, pursuant to our Terms of Service and any Data Processing Addendum (“DPA”) we make available. In this capacity:
- You (or your organization) are the controller/business with respect to that data.
- You are responsible for providing any required notices to your visitors at or before collection, obtaining any necessary consents (including for voice conversations, recording, or automated processing), and ensuring your use of the Service and resulting conversations comply with all applicable laws.
- We do not use visitor conversation data to train or improve general-purpose AI models except as expressly authorized by you in writing or as aggregated/anonymized in a manner that does not identify you or your visitors.
- Requests from your visitors regarding their data in the Service should generally be directed to you as the controller. We will assist you in responding as required by our DPA and applicable law.
If you are a customer and require a DPA, contact legal@poniq.ai or privacy@poniq.ai.
We collect personal information from the sources and for the purposes described below. “Personal information” has the meaning given under applicable law (including CCPA “personal information” and GDPR “personal data”).
- Identifiers and Contact Data: Name, email address, phone number (if provided), company or organization name, job title/role, website URL(s), and billing contact information.
- Account and Business Data: Information provided during registration, onboarding, waitlist signup, or in communications (e.g., use case, team size, vertical/industry, preferred integrations).
- Payment and Transaction Data: Billing address, invoice details, and payment method information. Full payment card details are processed and stored by our payment processor (Stripe); we receive limited tokens or confirmation data.
- Communications and Support: Content of emails, support tickets, feedback, survey responses, and other correspondence with us.
- User-Generated Content (Account Level): Playbooks, coaching notes, configuration settings, and other materials you upload or create in the Service.
- Device, Browser, and Usage Data: IP address, device type, operating system, browser type and version, referring/exit pages, pages viewed, time spent, clickstream data, and other log information when you use the Site or logged-in dashboard.
- Cookies and Similar Technologies: See Section 7 and our standalone Cookie Policy.
- Location Information: Approximate location derived from IP address (we do not collect precise GPS data without consent).
- Inferences: We may draw inferences about your preferences or business needs based on the above (e.g., interest in specific vertical playbooks).
2.3 Conversation and Visitor Data Processed on Your Behalf (Processor Role)
When the Service is active on your website(s), we process (on your instructions):
- Conversation Content (“Conversation Data”): All messages, transcripts, audio (for voice-enabled sessions), video context (for escalated meetings), and any personal information visitors voluntarily provide during interactions with the AI agent (e.g., name, email, phone, address, company, budget details, health or wellness information in medical/wellness contexts, or other details relevant to qualification, objections, or closing).
- Derived Data: Real-time and post-conversation intent scores, qualification summaries, objection tags, sentiment indicators, gap/competitor mentions, recommended actions, and structured data generated by our systems or AI models to power the Service.
- Integration and Action Data: Information necessary to execute actions you configure, such as creating or updating CRM records (deals, contacts, notes in Pipedrive or GoHighLevel), calendar events (Google Calendar), payment links or confirmations (Stripe), support tickets/logs (HelpScout), or payloads sent via webhooks, Zapier, n8n, or our API.
- Technical and Session Metadata: Visitor user agent, page URL and referrer, session identifiers, timestamps, engagement metrics, and other data needed to deliver, secure, and analyze conversations.
Sensitive Personal Information: Visitors may share sensitive categories of information (e.g., health-related details in medical/wellness verticals). You are solely responsible for configuring the Service appropriately, providing any required notices or consents, and complying with laws governing sensitive data (including HIPAA where applicable). Our medical/wellness playbooks are described as “HIPAA-aware” for workflow design purposes only; deploying the Service in regulated healthcare contexts requires you to confirm all compliance obligations (including potential need for a Business Associate Agreement) with qualified counsel. We process such data only as instructed by you.
3.1 As Controller (Our Direct Relationship)
- Operate, maintain, secure, and improve the Site, waitlist, accounts, and Service.
- Process waitlist and early-access requests and send related communications.
- Provide customer support, respond to inquiries, and manage our relationship with you.
- Personalize content and experiences (e.g., recommended playbooks).
- Analyze usage and performance to develop new features and improve reliability.
- Detect, prevent, and respond to fraud, abuse, security incidents, and violations of our Terms.
- Comply with legal obligations, enforce agreements, and protect our rights and the rights of others.
- Send service, transactional, and (with your consent or as permitted by law) marketing communications. You may opt out of marketing at any time.
3.2 As Processor (on Behalf of Customers)
We process Conversation Data and related visitor information solely to:
- Deliver the core functionality of the AI sales agent (qualification, objection handling, booking, payments, escalation, logging).
- Execute the integrations and actions you configure.
- Generate analytics, insights, gaps reports, and playbook improvement suggestions for your account.
- Provide coaching tools (backchannel, takeover, live video) and related features.
- Maintain security, debug, and improve the specific Service instance for you.
We do not use this data for our own marketing or to build profiles of your visitors for purposes unrelated to providing the Service to you.
3.3 AI and Automated Processing
The Service uses artificial intelligence, including large language models and other automated systems, to:
- Conduct and respond to real-time conversations.
- Score intent and qualify leads.
- Extract structured insights (objections, gaps, competitors, sentiment).
- Propose playbook improvements.
- Generate summaries and recommended actions.
AI outputs can be inaccurate or incomplete. You are responsible for reviewing playbooks before deployment, monitoring agent performance, and ensuring all communications and resulting business practices comply with applicable law. We disclose the use of automated processing as required. Under emerging rules (including certain 2026 CCPA/CPRA provisions regarding automated decisionmaking technology), additional notices or rights may apply depending on your use case and jurisdiction; you are responsible for any obligations arising from your deployment of the Service.
We do not “sell” personal information as defined under the CCPA/CPRA, nor do we “share” it for cross-context behavioral advertising purposes in the manner that would trigger an opt-out right under current interpretations for our direct controller activities.
We disclose personal information only as described in this Policy:
4.1 Service Providers and Subprocessors (Processor and Controller Contexts)
We engage third-party companies and individuals to perform services on our behalf (hosting, infrastructure, CDN and edge delivery, real-time communications/video, AI model inference, payment processing, email/transactional messaging, analytics, customer support tooling, security, and professional services). These parties are contractually required to:
- Process personal information only for the purposes we specify and as permitted by law.
- Implement appropriate technical and organizational security measures.
- Assist with consumer rights requests and security incident response.
- Not use the data for their own purposes (including, for AI providers, training foundation models on your data without authorization).
Material categories of service providers/subprocessors include (this list is not exhaustive and may change; see our current Subprocessor List):
- Cloudflare, Inc. — CDN, DNS, Pages hosting, Workers (consent management), D1 (waitlist), Turnstile, widget CDN (cdn.poniq.ai), and RealtimeKit for live escalation when enabled (United States).
- Hetzner Online GmbH — Dedicated server hosting for the operator application, including storage of account and Conversation Data at rest (United States).
- xAI Corp. — Large language model inference for AI agent responses, summaries, and related features (United States; contracts restrict training on Customer Data).
- Google LLC / Google Cloud Platform — Google Tag Manager and Google Analytics on the Site (with consent); analytics workloads and encrypted backup storage for production Service data (United States).
- Stripe, Inc. — Subscription billing and (when enabled) in-chat payment links. Stripe acts as a controller for certain payment data.
- Communications — Transactional email and notification providers for account and security messages.
- Analytics and operations — Limited internal analytics, error monitoring, and team tooling (access minimized and logged).
- Other — Professional advisors and parties necessary for legal compliance or business operations.
We maintain contracts with these parties consistent with CCPA service provider requirements and GDPR processor obligations.
4.2 Integrations You Enable
When you connect Pipedrive, Google Calendar / Workspace, Stripe, HelpScout, GoHighLevel, Zapier, n8n, webhooks, or other tools, we transmit the data you instruct us to transmit to those services. Those third parties are independent controllers (or additional processors) subject to their own privacy policies and your agreements with them. We are not responsible for their data practices.
4.3 Legal, Safety, and Business Transfers
We may disclose information:
- To comply with applicable law, legal process (subpoenas, court orders), or governmental requests.
- To enforce our Terms, protect our rights, property, or safety or that of our users, visitors, or the public.
- In connection with a merger, acquisition, corporate reorganization, financing, sale of assets, or bankruptcy, in which personal information is among the transferred assets (we will notify affected parties where required or practicable).
4.4 Aggregated or De-Identified Data
We may use and disclose aggregated, anonymized, or de-identified data that does not identify you or any individual for any purpose (e.g., industry benchmarks, product improvement, research).
5. Data Retention
We retain personal information only as long as necessary for the purposes described in this Policy, to provide the Service, to comply with legal obligations, to resolve disputes, to enforce agreements, and for legitimate business purposes (including backup, audit, and safety).
- Account and business data (controller context): Retained for the duration of the relationship plus a reasonable period thereafter (typically several years) to address legal claims, audits, and re-engagement where permitted.
- Conversation Data and derived insights (processor context): Retention periods are configurable in your account settings where available. By default, we retain data for a period sufficient to deliver the Service, support coaching/insights, and allow you to export data. Upon account termination or deletion request (subject to the DPA), we delete or anonymize Conversation Data in accordance with our retention schedule and the DPA, unless we are legally required or permitted to retain it longer (e.g., for fraud prevention or legal holds).
- Payment records: Retained as required by tax, accounting, and financial regulations (often 7+ years).
You may request deletion of your controller-context personal information (subject to exceptions such as legal obligations or ongoing contracts). Requests related to visitor data you control should be handled under your own policies and our DPA.
6. Security
We implement and maintain reasonable administrative, technical, and organizational measures designed to protect personal information against unauthorized access, destruction, use, modification, or disclosure. These include encryption in transit (TLS) and at rest where appropriate, access controls, logging and monitoring, vendor due diligence, and regular review of our practices.
No method of transmission or storage is 100% secure. We cannot guarantee absolute security. You are responsible for:
- Maintaining the confidentiality of your account credentials and API keys.
- Configuring appropriate access controls and permissions for your team within the Service.
- Ensuring the security of your own systems and websites on which the Poniq embed is deployed.
- Promptly notifying us of any suspected security incident or unauthorized access.
If we become aware of a security incident affecting your personal information, we will notify you in accordance with applicable law and our agreements.
7. Cookies and Tracking Technologies
For a detailed table of cookies, providers, durations, and your choices, see our Cookie Policy. Summary:
We and our service providers use cookies, local storage, pixels, and similar technologies on the Site and, to a limited extent, in connection with the Service widget for the following purposes:
- Strictly Necessary / Essential: Authentication, session management, security (e.g., CSRF protection), and basic functionality of the Site and logged-in areas. These cannot be disabled without breaking core features.
- Preferences / Functional: Remembering choices such as theme or certain settings.
- Analytics and Performance: Understanding how visitors use the Site to improve design and performance (we use privacy-respecting analytics where possible and minimize identifiers).
- Service Delivery (Widget): The embed script and agent may use cookies or browser storage for conversation continuity, session state, or to respect user preferences within a visitor’s interaction with your site. These are set in the context of your domain and are under your control as the site operator.
Cookie consent on poniq.ai: When you visit the Site, we show a cookie banner and store your choices in a first-party cookie (poniq_consent). You can accept all cookies, reject non-essential cookies, or manage preferences by category:
- Necessary — required to remember your cookie choices and operate core site features.
- Analytics — Google Tag Manager may load its container script; Google Analytics (GA4) and other analytics tags fire only when you consent, enforced via Google Consent Mode (
analytics_storage).
- Marketing — conversion and advertising tags configured in Google Tag Manager fire only when you consent, enforced via Google Consent Mode (
ad_storage and related signals).
You can reopen the preferences modal anytime via Cookie preferences in the site footer.
You can control cookies through your browser settings (most browsers allow blocking or deleting cookies). Disabling certain cookies may affect Site functionality or the visitor experience of the agent on your site. We do not currently respond to the Global Privacy Control (GPC) or similar signals on the Site for our controller activities beyond what is described here; we will update this Policy as practices or legal requirements evolve. For more information on cookies used, contact us or review your browser tools.
8. Your Rights and Choices
Your rights depend on your location and our role (controller vs. processor).
8.1 Rights When We Act as Controller (CCPA/CPRA, GDPR, and Similar Laws)
Subject to applicable law and verification requirements, you may have the right to:
- Know / Access: Receive information about the categories and specific pieces of personal information we have collected about you, the sources, purposes, and categories of third parties with whom we shared it.
- Delete: Request deletion of personal information we hold about you (subject to exceptions).
- Correct: Request correction of inaccurate personal information.
- Opt-Out of Sale/Share: We do not sell or share personal information for cross-context behavioral advertising. If our practices change, we will provide a clear “Do Not Sell or Share My Personal Information” link and honor opt-out signals (including browser signals where required).
- Limit Use of Sensitive Personal Information: We do not use or disclose sensitive personal information for purposes other than those permitted under CCPA without providing the right to limit (to the extent we collect it directly in a controller capacity).
- Non-Discrimination: We will not discriminate against you for exercising your rights.
- Portability: Receive a copy of certain personal information in a portable format (where technically feasible).
- Withdraw Consent / Object: Where processing is based on consent or legitimate interests (GDPR), you may withdraw consent or object (subject to our legitimate interests).
How to Exercise Rights (Controller Context): Submit requests by emailing privacy@poniq.ai or using any web form we may provide. We will verify your identity (e.g., via email confirmation or other reasonable methods) before responding. You may use an authorized agent; we may require proof of authorization and direct verification. We will respond within the timeframes required by law (generally 45 days for CCPA, extendable once by 45 days with notice; one month for GDPR, extendable by two months).
California Residents: You may also request information about our disclosure of personal information for a business purpose in the prior 12 months (categories of information and categories of recipients). The above rights apply.
For personal information of your website visitors that we process as a processor, please refer to your own privacy policy and notices. Direct any access, deletion, or other rights requests from those individuals to you. We will cooperate with you to the extent required by our DPA and applicable law.
8.3 Marketing Communications
You may opt out of marketing emails by using the unsubscribe link in those emails or by contacting us. We may still send you transactional or service-related communications.
8.4 Do Not Track
Some browsers have “Do Not Track” features. There is no uniform standard for how to respond to these signals. We currently do not respond to DNT signals on the Site but honor legally required opt-out mechanisms (such as GPC where applicable).
9. International Data Transfers and Data Residency
Poniq is based in the United States. We configure Subprocessors listed in our Subprocessor List to use United States regions for storage and processing of personal information, unless otherwise required by a specific customer agreement.
Personal information we collect as a controller is processed in the United States. If you access the Site or Service from outside the United States, you understand that your information will be transferred to and processed in the United States, which may have different data protection laws than your jurisdiction.
When we transfer personal information from the EEA, UK, Switzerland, or other jurisdictions with data transfer restrictions, we rely on appropriate safeguards such as Standard Contractual Clauses (SCCs) approved by the European Commission (or UK Addendum / Swiss version), adequacy decisions where available, or other lawful mechanisms.
10. Children’s Privacy
The Site and Service are not directed to children under 13 (or the applicable age of digital consent in your jurisdiction, such as 16 in some EEA countries). We do not knowingly collect personal information from children. If you believe we have collected information from a child in violation of applicable law, contact us immediately at privacy@poniq.ai so we can take appropriate action.
11. Links to Third-Party Sites and Services
The Site and Service may contain links to or integrate with third-party websites, applications, and services (including the CRMs, calendars, and payment processors you connect). This Policy does not apply to those third parties. We encourage you to review their privacy policies.
12. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons. We will post the revised Policy on this page with a new “Last Updated” date. For material changes, we may provide additional notice (e.g., email to account holders or a prominent banner). Your continued use of the Site or Service after the effective date of the revised Policy constitutes acceptance of the changes to the extent permitted by law.
Poniq, Inc.
Attn: Privacy
California, United States
Email: privacy@poniq.ai (for privacy and data rights requests)
Email: legal@poniq.ai (for legal and DPA inquiries)
For general inquiries: Use the contact methods on the Site or the waitlist form.