Privacy Policy
Last updated: 16 July 2026
This Privacy Policy explains how Vaese AI(“Vaese AI”, “we”, “us”, or “our”), operator of the Cersei platform (“Cersei” or the “Service”), collects, uses, stores, and protects personal data. It applies to our website, dashboard, and the customer-support channels Cersei powers on behalf of the businesses that use it, including website chat, WhatsApp, email, and the appointments it books into a connected calendar.
1. Who we are
Vaese AI provides AI-powered customer-support tools that let a business answer their own customers across chat, WhatsApp, and email from a single dashboard. You can contact us at agency@vaese.info.
[Add your registered legal entity name, company registration number, and registered address here.]
2. Two roles: our customers and their end-users
Cersei is a tool used by businesses (our customers) to talk to their own customers (end-users). For most personal data that flows through the Service — the content of support conversations, and the contact details of end-users — the business using Cersei is the data controller and Vaese AI acts as a data processor on their behalf. For our own account, billing, and website data, Vaese AI is the controller.
3. Data we collect
Depending on how you interact with Cersei, we may process:
- Account data — for business users of the dashboard: name, email address, organization, and authentication details.
- Conversation content— the messages exchanged between an end-user and a business’s AI or team across chat, WhatsApp, and email.
- Contact and lead information— an end-user’s name, email address, WhatsApp phone number, and details they share or that the AI infers from a conversation (such as their reason for reaching out, interests, or timeline).
- Appointment and booking data— when a business uses the AI receptionist, the appointments it books: the service requested, the date and time, and — for on-site services — the address the end-user provides. To offer available times, we also look up the free/busy periods of the business’s connected calendar (times only, not the contents of their existing events).
- Connected-account credentials — when a business connects a third-party account (such as WhatsApp, Gmail, or Google Calendar), the access tokens needed to operate that channel on their behalf. These are stored encrypted.
- Technical data — limited device, browser, and usage information (for example, referring page, locale, and timestamps) used to operate and secure the Service.
4. How we use data
- To provide and operate the Service, including generating AI replies.
- To route a message to the correct business and maintain the record of a conversation in that business’s inbox.
- To help a business understand and manage their leads (for example, status and captured details).
- To secure the Service, prevent abuse, and debug problems.
- To provide customer support and communicate about the Service.
- To comply with legal obligations.
5. Service providers we share data with
We use trusted third parties to operate the Service. They process data only as needed to provide their service to us:
- Meta Platforms — to send and receive messages over the WhatsApp Business Platform.
- Google — where a business connects Gmail (to read and send email on their behalf) or Google Calendar (to check their availability and add booked appointments). See the dedicated Google section below.
- OpenAI — to generate AI responses and analyse message content for the features above.
- Convex — our backend and database hosting.
- Clerk — authentication and account management.
- Vapi — where a business uses voice-agent features.
- Vercel — hosting of our web application.
We do not sell personal data. We may disclose data if required by law or to protect our rights, users, or the public.
6. WhatsApp and Meta
When a business connects a WhatsApp number, messages their customers send are delivered to Cersei through Meta’s WhatsApp Business Platform so the business’s AI can respond. That processing is also subject to WhatsApp’s Privacy Policy. We use these messages only to operate the connected business’s support conversations — not for advertising, and not to build profiles across unrelated businesses.
7. Google user data — Gmail and Google Calendar
A business can choose to connect its own Google account to Cersei. What we access depends on which connection they approve:
- Gmail— with the business’s permission, we read messages in the connected mailbox to show them in the Cersei inbox, send replies the business (or its AI, at the business’s request) writes, and add or remove labels to organise messages. Emails are fetched from Gmail when the inbox is opened or refreshed — we do not keep a standing copy of the mailbox. We store the connection tokens (encrypted) and limited per-conversation metadata such as an AI triage category or a saved draft.
- Google Calendar— with the business’s permission, we look up the free/busy times of their calendar (only whether a time is busy — never the title, attendees, or contents of existing events) so the AI receptionist can offer genuinely available slots, and we create a calendar event when an appointment is booked. We store the connection tokens (encrypted) and the appointments booked through Cersei.
We use Google user data onlyto provide these user-facing features to the business that connected the account. We do not use it for advertising, we do not sell it, we do not use it to train AI or machine-learning models, and no human at Vaese AI reads it except with the business’s explicit permission (for example, to give support they asked for), where required for security or debugging, or where required by law. Message content may be processed by our AI provider solely to deliver a feature the business invoked (such as drafting a reply), never to build profiles or train models.
Cersei’s use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements.
A business can disconnect Gmail or Google Calendar at any time from the Cersei dashboard — which also revokes Cersei’s access with Google — or remove Cersei’s access directly in their Google Account security settings. On disconnection the stored connection tokens are deleted.
8. How we protect data
Connected-account credentials and other secrets are encrypted before storage. Access is scoped so one business can never access another business’s data. We apply appropriate technical and organizational measures to protect personal data, though no method of transmission or storage is completely secure.
9. Data retention
We retain personal data for as long as needed to provide the Service and for legitimate business or legal purposes. Businesses can disconnect a channel or request deletion of data they control.
[Specify concrete retention periods here if you have them.]
10. Your rights
Depending on your location, you may have rights to access, correct, delete, or restrict the use of your personal data, and to object to certain processing. Because a business is usually the controller of end-user conversation data, requests about that data may be directed to the relevant business; we will assist them as their processor. To make a request to us directly, contact agency@vaese.info.
11. International transfers
Our service providers may process data in countries other than your own. Where required, we rely on appropriate safeguards for such transfers.
12. Children
The Service is not directed to children and we do not knowingly collect personal data from children.
13. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be reflected by updating the “Last updated” date above.
14. Contact us
Questions about this Privacy Policy or our data practices? Email agency@vaese.info.