1. Introduction
TheySaid, Inc. ("TheySaid") is committed to protecting and respecting your privacy. This Privacy Policy ("Policy") details our commitment to protecting the privacy of individuals who visit our Website and use our Services ("Subscribers" or "You"). This Policy describes how TheySaid collects, uses, shares and secures the personal information you provide. It also describes your choices regarding use, access and correction of personal information and how it can be accessed and updated.
In case of any questions or complaints regarding our Policy or practices, please contact us at: security@theysaid.io
2. Scope of This Policy
This Policy applies to the information that we obtain through your use of the "Services" or when you otherwise interact with TheySaid.
"Subprocessors" shall have the meaning ascribed to it in Regulation (EU) 2016/679 ("GDPR"). Subprocessors are listed at theysaid.io/digital-processing-agreement-dpa.
"Services" means the services provided by TheySaid through its messaging and productivity platform (the "Platform").
"Personal Information" means information relating to an identified or identifiable natural person, including but not limited to: name, email address, postal address, telephone numbers, date of birth, payment information, and any other information you choose to provide. The use of information collected through our Service shall be limited to the purpose of providing the Service for which you have engaged with us.
3. Privacy Point of Contact
TheySaid has not designated a formal Data Protection Officer. For all privacy-related enquiries, data subject rights requests, or complaints regarding this Policy, please contact our Security & Privacy Lead at: security@theysaid.io
4. TheySaid as a Data Processor / Service Provider
Data protection law differentiates between the "Data Controller" and "Data Processor" under GDPR, and a "service provider" under the California Consumer Privacy Act ("CCPA").
In general, TheySaid's customers determine how and why personal data submitted to the TheySaid Service is used. With respect to Personal Data, TheySaid customers are the "Data Controller" and TheySaid is the "Data Processor" under GDPR and a "service provider" under CCPA.
As Data Controllers, TheySaid's customers are responsible for disclosing the rights of individuals ("Data Subjects") with respect to their Personal Data, including information regarding the collection and use of that Personal Data, in accordance with GDPR, CCPA, and other applicable laws.
5. Personal Data Processed Under This Policy
TheySaid acts as a Data Processor / Service Provider with respect to any Personal Data comprised in Customer Data. "Customer Data" means the content or information which individuals authorized by a customer submit to the TheySaid Service.
6. Information We Collect
Registration and Contact Information
We collect personal information when you (a) register to use the Services and (b) otherwise provide contact information to us via email. This may include your username, first and last name, email address, mailing address, or phone number.
Voice and Video Data
Where you use voice or video features of the Services, we collect audio and video recordings of survey responses. These recordings are transcribed using AI speech-to-text technology and analyzed to generate insights. Recordings may contain personal information you choose to share during a survey. Voice and video data is processed only on behalf of our customers (controllers) and is not used by TheySaid for any purpose other than providing the Services, except where you have provided explicit consent to AI model training use as described in Section 7 below.
Payment Information
When you purchase the Services, we collect transaction information which may include your credit card information, billing and mailing address, and other payment-related information ("Payment Information").
Technical, Usage and Location Information
We automatically collect information on how you interact with the Service, such as the IP address from which you access the Service, email receipts and views, date and time, and browser information. We use cookies and similar technologies to collect some of this information.
Third-Party Platforms
We may collect information when you interact with our content on third-party sites or platforms integrated into the Services, such as email, chat, or social networking sites.
Analytics
We collect analytics information when you use the Services to help us improve them. We may share anonymous data about your actions on our website with third-party analytics service providers.
7. How We Use the Information We Collect
We use your information to administer your account, authenticate and provide access to Services, and to process payment. We also use your information to send you communications regarding the Services, including maintenance and customer support communications, as well as promotions and information about new products and services.
Legal Basis for Processing (EEA/UK)
If you are an individual from the European Economic Area (EEA) or United Kingdom (UK), our legal basis for collecting and using personal information will depend on the context. We will normally process personal information where: (a) we have your consent; (b) we need it to fulfill our contractual obligations; or (c) the processing is in our legitimate business interests. In some cases, we may have a legal obligation to collect personal information.
Where we rely on your consent to process personal information, you have the right to withdraw consent at any time. Withdrawal does not affect the lawfulness of processing based on consent before its withdrawal.
AI Model Training
TheySaid processes your organization's survey data to train and improve TheySaid's AI models on the basis of its legitimate interests in developing and improving its Services (Article 6(1)(f) GDPR). This processing helps TheySaid build more accurate, personalized and effective AI models that benefit all customers.
You have the right to object to this processing at any time via the Data & Privacy section in your account settings. Only organization owners and administrators can exercise this right on behalf of their organization. If you object, TheySaid will cease using your organization's data for model training from the date of objection. Objecting will not affect models already trained prior to your objection, and will not affect your access to or use of the Services in any way.
TheySaid has conducted a Legitimate Interests Assessment concluding that its interests in using organization data for model improvement are not overridden by the rights and interests of data subjects, taking into account the safeguards described in this policy and the right to object described above.
Data Retention
We retain your organization's data for as long as your organization account exists, including after your subscription lapses, so that you can access your insights and response data at any time. You may delete your organization and all associated data at any time using the self-service deletion tool in your account settings or by contacting security@theysaid.io.
On organization deletion, the following retention periods apply:
Where you have consented to AI model training use, data retained for that purpose will be held until you withdraw consent or delete your organization.
8. Usage of Google APIs
TheySaid Inc.'s use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
9. Sharing of Information Collected
We do not sell, trade, share or transfer your personal information to third parties, except in the following limited circumstances:
10. Payment Information
When you purchase the Services, any banking or credit card information you provide is collected and processed directly by our payment processor Stripe. We never receive or store your full credit card information.
11. International Transfers of Personal Data
Where we transfer personal data outside the European Economic Area (EEA) or United Kingdom (UK), we ensure appropriate safeguards are in place in accordance with applicable Data Protection Laws. For EU and UK data subjects, transfers to our US-based subprocessors are governed by Standard Contractual Clauses (SCCs) or the EU-US Data Privacy Framework (DPF) where applicable. Transfers to our UK-based subprocessors are governed by the EU-UK Adequacy Decision (June 2021).
A full list of our subprocessors and their applicable transfer mechanisms is available at: theysaid.io/digital-processing-agreement-dpa.
We shall at all times provide an adequate level of protection for personal data processed, in accordance with the requirements of applicable Data Protection Laws.
12. CCPA
Beginning January 1, 2020, in order for TheySaid and its Subscribers to comply with the California Consumer Privacy Act of 2018, as amended (Cal. Civ. Code §§ 1798.100 to 1798.199), and any related regulations or guidance (collectively the "CCPA"), we have established the CCPA Supplemental Privacy and Security Requirements Annex ("Annex"). The terms of the Annex are incorporated into all agreements under which you process personal information on behalf of TheySaid, effective January 1, 2020.
13. Cookies
TheySaid uses the following categories of cookies:
Strictly Necessary Cookies
These cookies are essential for the proper functioning of the website and Services. They cannot be disabled as the Services will not function without them. These include our consent management cookie (cc_cookie) which records your cookie preferences.
Analytics Cookies
Where you consent, we use PostHog to collect product analytics events and logged-in user identification data to understand how the Services are used and to improve product performance.
Session Recording Cookies
Where you consent, we use Sentry Replay to record masked session replays to help us identify and fix user experience issues. Input fields are masked and no sensitive content is recorded.
All cookies set by TheySaid are first-party only, retained for 182 days, and not shared with third parties except as necessary to provide the analytics and session recording services described above. Server access logs separately record IP addresses and timestamps for security purposes.
You can manage your cookie preferences at any time via the Data & Privacy section in your account settings. Withdrawing consent for analytics or session recording cookies will stop future data collection but will not affect data already collected prior to withdrawal.
14. Communications Preferences
We offer those who provide personal information a means to choose how we use the information provided. You may manage your receipt of marketing and non-transactional communications by clicking on the "unsubscribe" link in our marketing emails or by sending a request to security@theysaid.io.
15. How Long We Retain Your Personal Information
We retain your organization's data for as long as your organization account exists, including after your subscription lapses, so that you can continue to access your insights and response data at any time.
On organization deletion, the following retention periods apply:
Where you have consented to AI model training use, data retained for that purpose is held until you withdraw consent or delete your organization.
You may delete your organization and all associated data at any time via the self-service deletion tool in your account settings or by submitting a written request to security@theysaid.io. We will acknowledge deletion requests within 3 business days.
We may retain certain personal data for longer periods where required by applicable law, regulation, or legal process.
16. Accessing and Updating Your Personal Information
Where we have not obtained personal information from you directly, but from Subprocessors or other sources, you will be informed about the identity and contact details of the controller, purpose, and recipients of personal information within a reasonable time period.
To request access to, correction of, or removal of your personal information, please contact us at security@theysaid.io. Requests will be handled within thirty (30) days.
17. Your Rights
To ensure fair and transparent processing, you have the right to:
To exercise any of these rights, please contact us at security@theysaid.io.
Children's Personal Information
We do not knowingly collect any personal information from children under the age of 18. If you are under the age of 18, please do not submit any personal information through our Websites or Services. If you believe a child under the age of 18 has provided personal information to us, please contact us at security@theysaid.io and we will use commercially reasonable efforts to delete that information.
18. Security
The security of your personal information is important to us. We maintain appropriate technical and organizational safeguards to protect your personal information, including:
No method of transmission over the Internet or electronic storage is one hundred percent secure. While we strive to use commercially reasonable means to protect your personal information, we cannot guarantee its absolute security.
19. Vulnerability Reporting
If you believe you have found a security vulnerability or a problem that puts our users or their data at risk, please contact our security team at security@theysaid.io. We will respond within 72 business hours and work with you to address the issue responsibly.
20. Changes to This Policy
We reserve the right to change our Privacy Policy at any time. If we make material changes to this Policy, we will notify you by email or through a prominent notice on the website prior to the changes becoming effective. We encourage you to periodically review this page for the latest information on our privacy practices.
Your continued use of the Websites or Services following notification of material changes constitutes your agreement to be bound by such changes. You may choose to discontinue use of the Websites or Services if you do not accept the terms of this Policy or any modified version.
21. Contact Us
If you have questions or need to contact us about this Privacy Policy, your data rights, or any privacy-related matter, please contact us at: security@theysaid.io

