You have the right to access, correct, delete, and export your personal data. Visit your Account Settings to exercise these rights.
1. Introduction
ControlTheRoom.ai™ ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you use our AI-powered sales meeting intelligence platform (the "Service").
This Privacy Policy complies with:
- General Data Protection Regulation (GDPR) — EU
- California Consumer Privacy Act (CCPA) — California, USA
- California Privacy Rights Act (CPRA) — California, USA
- Other applicable data protection laws
2. Information We Collect
2.1 Personal Information You Provide
- Account Information: Name, email address, and authentication credentials via secure OAuth
- Meeting Brief Data: Company names, industry information, attendee names and titles, LinkedIn profiles, meeting context, special factors, research requests
- Contact Form Data: Name, email, and message content when you contact us
- Chat Messages: Conversations with our AI sales coach
- Payment Information: Billing details processed by third-party payment processors (we do not store credit card numbers)
2.2 Automatically Collected Information
- Usage Data: Pages visited, features used, time spent on platform, clicks, interactions
- Device Information: Browser type, operating system, device type, IP address, user agent
- Cookies and Tracking: Session cookies for authentication, preference cookies, analytics cookies
- Log Data: Access times, error logs, performance metrics
2.3 Information from Third Parties
- OAuth Providers: Basic profile information from your sign-in provider (name, email, login method)
- Public Data Sources: Company information, news articles, financial data, social media profiles (LinkedIn) used to generate meeting intelligence
- AI Service Providers: Data processed by our AI infrastructure partners (see Section 6)
2A. User-Generated Content Disclaimer
⚠️ IMPORTANT: Your Responsibility for Uploaded Content
You are solely responsible for the content you upload to our Service, including meeting transcripts, company information, and attendee data. We do not review, verify, or validate user-uploaded content before processing.
2A.1 Prohibited Content
You must NOT upload content that:
- Is protected by non-disclosure agreements (NDAs) or confidentiality obligations
- Contains material non-public information (MNPI) as defined by securities law
- Is protected by attorney-client privilege or work product doctrine
- Contains trade secrets or confidential business information belonging to third parties
- Violates any legal or contractual restrictions on disclosure
2A.2 No Liability for User Content
We are not responsible for:
- Verifying that you have the legal right to share uploaded content
- Monitoring or detecting confidential or NDA-protected information in your uploads
- Claims, damages, or legal consequences arising from your upload of restricted content
- Third-party claims for breach of confidentiality or NDA violations
2A.3 Data Processing
Content you upload (including transcripts) may be:
- Processed by our AI systems to generate meeting intelligence
- Stored on our servers and third-party cloud infrastructure
- Transmitted to AI service providers (OpenAI, Anthropic, etc.) for processing
- Retained according to our data retention policies (see Section 9)
If you upload confidential content by mistake, immediately contact us at support@controltheroom.ai to request deletion. However, we cannot guarantee complete removal if the content has already been processed by third-party AI providers.
3. How We Use Your Information
3.1 Legal Basis for Processing (GDPR)
We process your personal data based on the following legal grounds:
- Contract Performance: To provide the Service you signed up for
- Legitimate Interests: To improve our Service, prevent fraud, ensure security
- Consent: For marketing communications and optional analytics
- Legal Obligation: To comply with applicable laws and regulations
3.2 Specific Uses
- Generating AI-powered meeting briefs and sales intelligence
- Providing and improving our Service
- Processing payments and managing subscriptions
- Sending service-related communications (account updates, security alerts)
- Responding to your inquiries and support requests
- Analyzing usage patterns to improve features
- Preventing fraud and ensuring platform security
- Complying with legal obligations
4. Data Sharing and Disclosure
We do not sell your personal information. We share data only in the following circumstances:
- AI Service Providers: OpenAI, Anthropic, and similar providers to generate meeting intelligence (data processed under their privacy policies)
- Payment Processors: Stripe or similar services to process payments
- Analytics Providers: Anonymized usage data for platform improvement
- Legal Requirements: When required by law, court order, or government authority
- Business Transfers: In connection with a merger, acquisition, or sale of assets
5. Your Rights
Depending on your location, you may have the following rights:
- Access: Request a copy of the personal data we hold about you
- Correction: Request correction of inaccurate or incomplete data
- Deletion: Request deletion of your personal data ("right to be forgotten")
- Portability: Receive your data in a structured, machine-readable format
- Objection: Object to processing based on legitimate interests
- Restriction: Request restriction of processing in certain circumstances
To exercise these rights, visit your Account Settings or contact us at privacy@controltheroom.ai.
6. Data Security
We implement industry-standard security measures including:
- Encryption in transit (TLS/HTTPS) and at rest
- Secure OAuth authentication (no passwords stored)
- Regular security audits and vulnerability assessments
- Access controls and employee training
- Incident response procedures
No system is 100% secure. In the event of a data breach affecting your rights, we will notify you as required by applicable law.
7. Cookies
We use the following types of cookies:
- Essential Cookies: Required for authentication and core functionality
- Preference Cookies: Remember your settings and preferences
- Analytics Cookies: Help us understand how you use the Service (opt-out available)
You can manage cookie preferences through your browser settings. Disabling essential cookies may affect Service functionality.
8. Data Retention
We retain your data for as long as your account is active or as needed to provide the Service. Specifically:
- Account Data: Retained until account deletion
- Meeting Briefs: Retained until you delete them or your account
- Usage Logs: Retained for 90 days for security and debugging
- Payment Records: Retained for 7 years as required by tax law
9. Contact Us
For privacy-related questions or to exercise your rights:
- Email: privacy@controltheroom.ai
- General: hello@controltheroom.ai
We will respond to all privacy requests within 30 days (or as required by applicable law).