1. Who we are
The Coworkkit service is operated by S.M. Ebrahim Mirsafian (operated as a sole proprietorship pending entity registration) — referred to here as “Coworkkit”, “we”, or “us”. You can reach us about this policy at ebi@coworkkit.ai. Postal address available on request.
2. Our two roles: controller and processor
Coworkkit sits between a business and that business’s own end-users, so we act in two distinct roles:
- Controller — for the data of our direct customers: the account, authentication, contact, and usage/billing records of the people and organisations who sign up for the Coworkkit portal. We decide how that data is used to run the Service, and this policy governs it.
- Processor — for the voice-session data of the end-users inside a customer’s application. When one of our customers embeds Coworkkit in their product, that customer is the controller — they decide why their users talk to the agent and what it can do. We process that session data only on the customer’s instructions, to operate the runtime. If you are an end-user who spoke to an agent in someone else’s app, the operator of that app is your controller; please see their privacy notice.
3. What we process
As controller (our direct customers):
- account & identity: name, email, and the sign-in identity from your provider (Google or GitHub);
- tenant configuration: the settings you choose for your coworker (voice, persona, and the like);
- usage & billing: session counts, minutes used, and remaining minute balances, plus the plan, subscription status, and invoice records for your account. Payment is taken by Paddle, our Merchant of Record (section 5): card numbers and security codes are entered on Paddle’s own hosted payment form and never reach Coworkkit’s systems. We do receive and retain Paddle’s transaction notifications in a billing audit log — these include the payment-method type, the last four digits of the card, its expiry and the cardholder name, or for a PayPal payment the PayPal account email, together with billing and tax details — which we keep for accounting, invoice and dispute purposes.
As processor (end-user voice sessions):
- the live voice stream and its transcript, the catalogue of actions the customer’s app has declared, and the record of which actions were invoked during a session;
- structured operational logs about each session (see section 6). Speech is transcribed in real time to operate the conversation; we do not build a voiceprint or other biometric template.
4. What we do not touch — the closed loop
Coworkkit’s agent runtime holds zero credentials to a customer’s backend and never imports a customer’s database or application client. Every action the agent takes is a remote procedure call fired into the end-user’s own browser, where it runs inside that user’s already-authenticated session — the agent is never more powerful than the user in front of the screen. Because of this design, Coworkkit keeps no standing copy of a customer’s business data. The values an action reads or writes pass transiently through the browser session so the agent can act and respond, but they are not retained by us and never written to our logs as values (only privacy-preserving digests — see section 7). What persists on our side is the voice session and its transcript, the declared action catalogue, and the record of which actions ran.
5. Sub-processors
We keep the runtime as a managed closed loop, so this list is short and stable. We do not use analytics, advertising, or CRM sub-processors.
The first three entries are runtime sub-processors: they handle voice sessions and the control plane on our instructions. The last, Paddle, is different in kind — it is our Merchant of Record, so it acts as the seller for the transaction under its own terms. It receives the email address of anyone who starts a checkout, so that it can recognise them at payment, and the billing details of those who complete one. No entry in this table other than the runtime three ever touches voice-session data.
| Sub-processor | Purpose | Region | Data terms |
|---|---|---|---|
| Google Cloud Platform | Application hosting (Cloud Run), the control-plane database (Cloud SQL for PostgreSQL: tenant, account, and usage records), and secret storage (Secret Manager). | EU — europe-west4 (Netherlands) | DPA |
| Google Speech-to-Text, Text-to-Speech & Vertex AI (Gemini) | Real-time speech recognition and voice synthesis for the conversation, and the language model that powers the agent. | Speech-to-Text & Text-to-Speech: EU (europe-west4). Vertex AI (Gemini): Google's global region. | DPA |
| LiveKit | Real-time audio transport (WebRTC) carrying the voice session between the browser and the agent. | EU — LiveKit Cloud (EU) or Coworkkit's own self-hosted EU transport (eu1), depending on tenant configuration. | DPA |
| Paddle | Payment processing as Merchant of Record — our direct customers' billing data only; never voice-session data. Covers the hosted checkout, payment-method and billing details, invoicing, sales-tax and VAT collection and remittance, refunds and chargebacks. Card numbers and security codes are entered on Paddle's own hosted payment form and never reach Coworkkit's infrastructure. As Merchant of Record Paddle is the seller for the transaction and acts under its own terms, not solely on our instructions. | Outside the EU — Paddle's contracting entity depends on the buyer's location (Paddle.com Market Ltd is its United Kingdom entity), and payment processing is global. | Data Sharing Addendum |
6. Where data is processed, and international transfers
Our control plane and speech services default to the European Union (Google Cloud’s europe-west4 region), and voice transport runs on EU infrastructure. Two honest exceptions: within the voice runtime, the Gemini language model runs in Google’s global Vertex AI region rather than a pinned EU region; and separately, payment processing runs wherever Paddle, our Merchant of Record, operates — it is not an EU-pinned service, and it never receives voice-session data. We therefore do not claim a blanket EU-only data-residency guarantee today. Where data is processed outside the EU/EEA, it is covered by the safeguards in the sub-processors’ data-processing terms (such as Standard Contractual Clauses). Stronger data-residency commitments are something we can discuss for a specific engagement.
7. How long we keep it
We keep account and usage data for as long as you have an account and as needed for legal and accounting purposes, then delete or anonymise it. Operational session logs are designed to be privacy-preserving: they record digests, key names, counts, and byte sizes — never transcript content, prompt bodies, tool-argument values, or credentials — and are retained on a short rolling basis for debugging and abuse prevention. A customer’s instructions may set shorter retention for the session data we process on their behalf.
8. Your rights
Depending on where you are, you have rights over your personal data — including access, rectification, erasure, portability, restriction, and objection — and, where we rely on consent, the right to withdraw it. To exercise any of these, email ebi@coworkkit.ai. If your data was processed because you used an agent inside another company’s app, that company is your controller — contact them, and we will support them as their processor. You also have the right to complain to your local data-protection authority.
9. Cookies
The portal uses a single strictly-necessary cookie to keep you signed in, and sets no analytics, tracking, or marketing cookies. See our Cookie Policy for details.
10. Changes to this policy
We may update this policy as our practices evolve. Material changes are reflected in the “Last updated” date above.
11. Contact
For any privacy question, contact S.M. Ebrahim Mirsafian at ebi@coworkkit.ai.