Privacy Policy

Last updated: May 13, 2026

1. Data Controller

The data controller for personal data processed through this Service is Andrea Magni, operating under the trade name Closly, based in Italy. For any privacy-related inquiries, you can reach us at privacy@closly.app.

2. Personal Data We Collect

We collect the following categories of personal data:

2.1 Account Information

When you create an account, we collect your name, email address, and password. If you sign in via a third-party provider (Google), we receive your name, email address, and profile identifier from that provider. We do not receive or store your third-party account password.

2.2 Voice and Call Data

Our Service provides AI-powered simulated voice calls for sales training purposes. When you participate in a training call, we collect:

  • Audio recordings of the simulated call
  • Transcripts generated from those recordings
  • AI-generated feedback, evaluation scores, and performance summaries
  • Call duration and technical metadata

2.3 Chat and Messaging Data

When you interact with AI-simulated leads via our text chat feature, we store the messages exchanged during those training sessions.

2.4 Usage and Performance Data

We collect data about how you use the Service, including appointment scheduling activity, performance audit results, and general interaction patterns within the platform.

2.5 Technical Data

We automatically collect certain technical information, including browser type, device type, IP address, and pages visited. We also receive aggregated usage and performance metrics via our hosting provider's tools (Vercel Web Analytics and Vercel Speed Insights), as described in Section 7. We also store your audio device preferences (microphone and speaker selection) locally on your device.

3. How We Use Your Data

We process your personal data for the following purposes:

  • Providing the Service: to create and manage your account, deliver AI-powered voice training, generate feedback and performance analytics, and facilitate team management features.
  • Improving the Service: to analyze usage patterns (including aggregated site and performance metrics from our hosting tools), diagnose technical issues, and develop new features.
  • Communication: to send you essential service-related notifications (e.g., account verification, security alerts, material changes to our terms).
  • Legal compliance: to comply with applicable laws, regulations, and legal processes.

4. Legal Bases for Processing (GDPR Art. 6)

We rely on the following legal bases to process your personal data:

  • Performance of a contract (Art. 6(1)(b)): processing is necessary to provide the Service you have signed up for, including account management, AI training calls, and performance analytics.
  • Legitimate interest (Art. 6(1)(f)): processing is necessary for our legitimate interests in improving the Service, ensuring security, and preventing abuse, provided these interests are not overridden by your rights. This includes measuring aggregated website traffic and real-user page performance using Vercel Web Analytics and Vercel Speed Insights, which load on all pages of the Service (see Section 7). You may object to this processing under Art. 21 as described in Section 9.
  • Consent (Art. 6(1)(a)): where we expressly ask for and obtain your consent for a specific processing activity, you may withdraw it at any time without affecting the lawfulness of prior processing. We do not rely on consent as the legal basis for Vercel Web Analytics or Vercel Speed Insights as described in Section 7.
  • Legal obligation (Art. 6(1)(c)): where we are required by law to process certain data.

5. Third-Party Service Providers

We share your data with the following categories of third-party processors, each of which processes data on our behalf and under our instructions:

  • Supabase, Inc. (United States) — authentication services and database hosting. Processes your account credentials and session data.
  • Vapi, Inc. (United States) — AI voice call infrastructure. Processes your voice audio during simulated training calls.
  • OpenAI, Inc. (United States) — AI language model services. Processes call transcripts and chat messages to generate training feedback, evaluations, and performance audits.
  • Vercel, Inc. (United States) — hosting, content delivery, Vercel Web Analytics (aggregated usage), and Vercel Speed Insights (real-user performance metrics such as Core Web Vitals).
  • Discord, Inc. (United States) — when our optional internal notification integration for the public "try" experience is enabled, we may send limited event metadata to Discord (which may include your email address and links related to demo calls). We configure this to minimise personal data where feasible.

Where required by applicable law, we put in place Data Processing Agreements (DPAs) under GDPR Art. 28 with our third-party processors, including Supabase, Vercel, Vapi, and OpenAI, using the contractual terms made available for the applicable service and plan.

We do not sell your personal data to any third party, nor do we share it for advertising purposes.

6. International Data Transfers

Some of our third-party service providers are based in the United States. When your personal data is transferred outside the European Economic Area (EEA), we ensure appropriate safeguards are in place, including:

  • The EU-U.S. Data Privacy Framework, where the recipient is certified
  • EU Standard Contractual Clauses (SCCs) approved by the European Commission

You may request a copy of the relevant safeguards by contacting us at privacy@closly.app.

7. Cookies and Local Storage

We use strictly necessary cookies to manage your authenticated session. These cookies (prefixed with sb-) are set by our authentication provider (Supabase) and are essential for the Service to function. They cannot be disabled.

We load Vercel Web Analytics and Vercel Speed Insights on every page of the Service by default. There is no separate consent banner for these tools. They help us measure aggregated traffic and diagnose technical performance (for example Core Web Vitals). Vercel Web Analytics is designed to collect anonymized, aggregated usage data without using cookies. Vercel Speed Insights collects real-user performance signals to understand how quickly pages load for visitors. The legal basis for this processing is legitimate interests (Art. 6(1)(f) GDPR) as described in Section 4. You may exercise your right to object under Art. 21 by contacting us (Section 9).

We store your audio device preferences (microphone and speaker selection) in your browser's local storage. This data never leaves your device.

We do not use any marketing, advertising, or third-party tracking cookies.

8. Data Retention

We retain your personal data for as long as your account is active and as needed to provide the Service. When you or your organization's administrator deletes your account, we will delete or anonymize your personal data within 30 days, unless we are legally required to retain certain data for a longer period (e.g., for tax or legal compliance purposes).

Call recordings, transcripts, scorecards, and AI-generated feedback and evaluation outputs are retained for the lifetime of your account to enable ongoing performance tracking and training analytics.

9. Your Rights Under GDPR

If you are located in the EEA, you have the following rights regarding your personal data:

  • Right of access (Art. 15): you may request a copy of the personal data we hold about you.
  • Right to rectification (Art. 16): you may request correction of inaccurate or incomplete data.
  • Right to erasure (Art. 17): you may request deletion of your personal data, subject to legal retention obligations.
  • Right to restriction (Art. 18): you may request that we restrict processing of your data in certain circumstances.
  • Right to data portability (Art. 20): you may request to receive your data in a structured, commonly used, machine-readable format.
  • Right to object (Art. 21): you may object to processing based on legitimate interest at any time.
  • Right to withdraw consent (Art. 7(3)): where processing is based on consent, you may withdraw it at any time.

To exercise any of these rights, please contact us at privacy@closly.app. We will respond within 30 days.

You also have the right to lodge a complaint with a supervisory authority in your EU Member State of residence, place of work, or place of the alleged infringement.

10. Automated Decision-Making and AI Act Transparency

Our Service uses artificial intelligence to generate training feedback, performance scores, and coaching suggestions. These AI-generated outputs are provided solely for educational and training purposes. They do not constitute automated decision-making that produces legal effects or similarly significantly affects you within the meaning of GDPR Art. 22.

Certain features of the Service are also subject to the EU Artificial Intelligence Act (Regulation (EU) 2024/1689, the "AI Act"). For the AI-powered simulation and coaching use case we offer, we assess the relevant AI functionality as falling within the AI Act's limited-risk category, which includes transparency obligations for persons interacting with an AI system.

We inform users that they are interacting with an AI system (for example simulated voice or chat training with a non-human counterpart), in line with AI Act transparency requirements including Art. 50 where applicable.

AI-generated feedback, scorecards, and evaluations are tools to support learning and performance improvement. They are not intended to replace employment-related assessments, disciplinary measures, hiring decisions, or other significant decisions about individuals that should be taken by qualified human decision makers at your organization.

11. Data Security

We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. These measures include encryption in transit (TLS/HTTPS), secure authentication mechanisms, and access controls limited to authorized personnel.

While we strive to protect your data, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security.

12. Age Requirement

The Service is intended for business professionals and is not directed at individuals under the age of 18. We do not knowingly collect personal data from anyone under 18. If we become aware that we have collected data from a person under 18, we will delete it promptly.

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you by posting a prominent notice on our Service or by sending you an email at least 30 days before the changes take effect. Your continued use of the Service after the effective date constitutes acceptance of the updated policy.

14. Contact Us

If you have any questions about this Privacy Policy or wish to exercise your data protection rights, please contact us at:

Email: privacy@closly.app