1. Who this policy covers
This policy explains how Thosjod ("Thosjod", "we", "us") handles personal data in two different roles.
As a controller: for our own customers and prospects - people who visit thosjod.com, book a demo, create an account or contact us.
As a processor: for the visitors to our customers' websites. When a customer installs Thosjod on their site, the customer decides why and how visitor data is processed, and we process it on their behalf under our agreement with them. Visitors of a customer's website should read that customer's privacy policy and contact them first.
2. Information we collect
- Account information: name, work email, company name, role, password (stored hashed) and billing details for the people who use Thosjod.
- Website-visitor data (processed for customers): pages viewed, referrer, session timing, device and browser information, approximate location derived from IP address, and - where identification is enabled by the customer - company and contact details matched through enrichment.
- Conversation data: messages exchanged with Thosjod's AI agents, and any details a visitor chooses to share in a conversation, such as name, email or requirements.
- Voice data: audio and transcripts, only when a customer enables the voice agent.
- Enquiry and form data: information submitted through our demo, contact, newsletter and audit-tool forms.
- Usage data: how customers use the Thosjod application, for security, support and product improvement.
3. How we use information
- To provide the Thosjod service: engaging, identifying and qualifying visitors, routing leads, booking meetings and syncing records to the CRM a customer connects.
- To ground AI responses in the knowledge sources a customer approves, and to hand conversations to a human when no grounded answer exists.
- To run AI-visibility tracking and GEO/AEO audits that a customer configures.
- To operate, secure, support and improve the service, including detecting abuse.
- To respond to enquiries, run free audit tools and send the follow-up the requester asked for.
- To bill customers and meet our legal obligations.
We do not sell personal data.
4. Legal basis for processing
For website-visitor data, the customer is the controller and determines the legal basis, such as consent or legitimate interests, and is responsible for any notices and consent their visitors require. Thosjod's identification runs within a configurable, consent-aware framework designed to support those obligations.
For our own customers and prospects, we rely on performance of our contract, our legitimate interests in running and marketing a B2B service, compliance with legal obligations and, where required, consent.
7. Data retention
We keep personal data only as long as needed for the purposes above, then delete or anonymise it. Customers can delete visitor and conversation data from their workspace at any time.
8. Your rights
Depending on where you live - including under India's DPDP Act 2023, the GDPR and US state laws such as the CCPA - you may have the right to access, correct, delete or port your personal data, to object to or restrict processing, to withdraw consent, and to nominate someone to exercise your rights. You may also complain to your data protection authority.
If your data was processed by Thosjod on behalf of one of our customers, please contact that customer first; we will help them respond.
9. Security
We use technical and organisational measures appropriate to the risk, including encryption in transit, access controls, single sign-on for Scale and Enterprise workspaces, and a full configuration audit trail.
10. International data transfers
Where personal data is transferred outside the country where it was collected, we use appropriate safeguards, such as Standard Contractual Clauses where applicable.
11. Children's privacy
Thosjod is a business service and is not directed at children. We do not knowingly collect personal data from children.
12. Changes to this policy
We may update this policy. When we make material changes we will update the date below and, where appropriate, notify customers.