Privacy
Privacy Policy
What we collect across consultations, the Marketing by ScoChat product, Voice AI implementations and custom engagements — and the controls you keep over your own data. Client engagements are additionally governed by their own written data terms.
Last updated: August 27, 2026
1. Who we are
ScoChat is an AI consultancy and custom-development practice operated by ScoNet, working from Houston, Texas and Dubai, UAE. We design, build and support custom AI agents and workflows, Voice AI assistants, and the Marketing by ScoChat product.
This policy explains how we handle information across four distinct contexts: this website, the Marketing by ScoChat product, Voice AI implementations where we operate a portal for a client, and custom AI engagements. The applicable context determines which sections apply to you.
2. Website and consultation information
We use this information to respond to your enquiry, prepare a scoping conversation and, where relevant, produce a proposal. Consultation enquiries are sent by email to our team; we do not sell this information or use it for advertising.
- Contact details you submit: name, work email, company, role and phone number where provided.
- The information you choose to describe about your process, systems or objectives when requesting a consultation.
- Basic technical data such as request logs, needed to serve and secure the site.
3. Marketing by ScoChat workspace data
Platform access tokens are stored encrypted and can be revoked at any time, from the workspace or from the platform itself. What the product can read or publish is limited by the permissions each platform grants. We do not sell customer data and we do not use workspace content to train publicly available models.
- Account information: name, work email, company and role.
- Workspace content: brand information, drafts, captions, calendars, comments and messages you bring into the workspace.
- Social platform data accessible through the permissions you grant via each platform's official OAuth flow.
- Usage and diagnostic data used to operate, secure and improve the product.
- Billing data handled by our payment provider; we do not store full card details.
4. Voice AI data, where configured
Where we implement and operate a Voice AI assistant for a client, the assistant processes information needed to handle the calls in scope. What is captured is a configuration decision made with the client during implementation, not a fixed default.
Recording, transcription, disclosure wording and consent handling depend on the client's configuration and on the law applicable to the caller and the business. The client determines those settings; we implement what the client approves. For a specific assistant, the client's own privacy notice governs how its callers' information is used.
- Call metadata: time, duration, direction, assistant used, intent and outcome.
- Caller-provided details required to complete the scoped task, such as a name, contact detail or appointment request.
- Recordings, transcripts and call summaries only where the client has configured them and where lawful in the relevant jurisdictions.
- Portal access data for named client users who review calls and reporting.
5. Custom AI engagement data
In custom AI agent, workflow and application engagements, the client's data is processed only as described in the applicable proposal, statement of work and data-processing terms. Those documents define the approved data sources, the environments used, access controls, retention and any subprocessors involved.
Where those terms conflict with this website policy, the signed engagement documents govern. We work to least-privilege access: credentials are scoped to the specific systems and objects the agreed workflow requires.
6. Service providers
We use infrastructure, AI model, telephony and communication providers to deliver our services. Providers are bound by contractual confidentiality and data-protection obligations, and the set of providers used in an engagement is documented in that engagement. A current list relevant to your context is available on request at sales@sconet.com.
7. Security
We apply role-based access control, tenant separation, encryption in transit and at rest, least-privilege service credentials and audit history for significant actions. See the Security page for the architectural detail, including a clear statement of what is a design commitment rather than a third-party certification. We do not currently hold SOC 2 or ISO 27001 certification and do not claim to.
8. Retention and deletion
Marketing by ScoChat workspace content and analytics are retained while the workspace is active. Voice AI and custom engagement retention periods are set in the applicable engagement documents, because they depend on the client's own obligations.
You may request deletion of your information at any time. We remove or anonymise the relevant data within a commercially reasonable period after verifying the request, except where retention is required by law or by a contract still in force. We do not publish a fixed deletion window here, because a guaranteed timeframe should be committed in writing for the specific service rather than implied on a marketing page.
9. Your rights
Depending on your jurisdiction you may request access, correction, deletion, export or restriction of your personal data, and may object to certain processing. Contact sales@sconet.com and we will respond within the timeframes required by applicable law. Where we process data on behalf of a client, we will refer the request to that client as controller.
10. Cookies and analytics
This website does not include advertising cookies by default. If analytics, chat, scheduling or other third-party tools are added, this notice and any consent mechanism will be updated before deployment.
11. International processing
We serve clients in the United States and the Middle East, and information may be processed in a country different from your own, subject to the safeguards required by applicable law. Where an engagement requires data to remain in a specific region, that requirement is captured during discovery and reflected in the architecture and the engagement documents.
12. Preview functionality
Parts of this website include clearly labelled preview interfaces containing sample data. No real call, publication, account connection, payment or authentication occurs in a preview, and no personal data you enter into a preview is transmitted to a backend service.
13. Changes and contact
We will update this page when our practices change and revise the date below. Material changes affecting clients are also communicated directly. Privacy questions can be sent to sales@sconet.com.
Next step
Have a question about how your engagement is handled?
We will point you to the right agreement, data boundary or owner.