Privacy should be clear before a conversation begins.
Ask Bennett is an artificial intelligence voice and website information service. This policy describes the personal information handled by Ask Bennett and the choices available to individuals. It does not replace a customer business's own privacy notice when Bennett is installed on that business's website or phone system.
Overview and Scope
This Privacy Policy applies when you visit Ask-Bennett.com, communicate with Ask Bennett, create or manage an account, purchase or use the service, contact support, submit a form, or interact with an Ask Bennett voice or chat experience that identifies Ask Bennett as the service provider.
It applies to personal information collected online and, where relevant, through telephone, voice, email, account, billing, and customer-support interactions. It does not govern an unrelated third-party website, platform, or business that has its own privacy policy.
When a business installs Bennett, that business generally decides why Bennett is used, what business content is provided, what questions Bennett should address, and how the business will follow up. That business may be the controller or business responsible for end-user information, while Ask Bennett processes that information on the business's behalf.
Who We Are and Our Privacy Roles
Ask Bennett operates in the United States. In this policy, “Ask Bennett,” “we,” “us,” and “our” refer to Ask Bennett and the Ask Bennett service.
When Ask Bennett acts as a controller or business
We determine the purposes and means of processing for our own website visitors, prospective customers, account holders, billing contacts, administrative users, support contacts, marketing preferences, security logs, and business operations.
When Ask Bennett acts as a processor or service provider
For voice, chat, transcript, website-question, lead, and other end-user information processed through a customer deployment, Ask Bennett generally acts on the customer's documented instructions as a processor, service provider, or contractor. The applicable customer agreement and Data Processing Addendum control that processing.
Business customers are responsible for providing any required privacy notices, AI notices, recording disclosures, and consent mechanisms to their visitors, callers, employees, and other individuals, unless Ask Bennett has expressly agreed in writing to provide a specific notice or mechanism.
Personal Information We Collect
The information we collect depends on how you interact with us, the features a customer enables, and the information you choose to provide.
| Category | Examples | Primary Sources |
|---|---|---|
| Identifiers and contact information | Name, business name, title, email address, phone number, account identifiers, and contact details. | You, your employer, a customer business, forms, communications, and account setup. |
| Account and commercial information | Plan, subscription status, location, purchase history, invoices, service configuration, and customer relationship records. | You, account administrators, our billing system, and service providers. |
| Payment and transaction information | Billing address, payment status, transaction identifiers, payment method type, and limited card or bank details supplied by the payment processor. | You and our payment processor. We do not intentionally store full payment card or bank account numbers. |
| Voice, chat, and interaction information | Questions, responses, chat messages, transcripts, call metadata, audio when recording is enabled, language, interaction time, and conversation context. | You, website visitors, callers, customer businesses, and the Ask Bennett service. |
| Customer content and business information | Website pages, product and service information, hours, locations, policies, pricing, FAQs, documents, instructions, and approved knowledge sources. | Customer businesses, public websites, connected sources, and authorized administrators. |
| Device, internet, and usage information | IP address, browser, device type, operating system, pages viewed, referring URL, timestamps, approximate location derived from IP, and diagnostic logs. | Your browser, device, cookies, logs, analytics, hosting, and security services. |
| Communications and support information | Emails, support requests, feedback, complaint records, call notes, attachments, and other communications. | You, customer administrators, support channels, and service providers. |
| Preferences and inferences | Language preference, communication preference, likely business interests, and service-use patterns inferred from interactions. | Your choices, account activity, and service usage. |
| Sensitive personal information | Information that may be sensitive under applicable law if voluntarily included in a conversation, document, or support request. | You, a caller, a website visitor, or a customer business. The service is not designed to collect unnecessary sensitive information. |
We may also receive information from publicly available sources, authorized integrations, customer-selected systems, fraud and security providers, payment providers, and business partners.
Do not submit passwords, complete payment card or bank account numbers, Social Security numbers, government identification numbers, medical details, precise location, or other sensitive information unless the feature clearly requires it and you are authorized to provide it.
How We Use Personal Information
We use personal information to:
- Provide, operate, configure, maintain, and improve Ask Bennett.
- Respond to voice, chat, website, account, sales, billing, support, and privacy requests.
- Prepare Bennett using customer-approved website and business information.
- Authenticate users, manage accounts, administer subscriptions, process payments, and maintain transaction records.
- Generate, route, summarize, transcribe, and support interactions when those features are enabled.
- Detect fraud, abuse, security threats, service failures, prohibited use, and technical problems.
- Measure performance, troubleshoot issues, conduct quality assurance, and improve reliability.
- Comply with law, enforce agreements, establish or defend legal claims, and protect rights, safety, property, and the service.
- Send service notices and, where permitted, business communications. You may opt out of promotional email at any time.
- Complete a merger, financing, acquisition, reorganization, sale, or other business transaction, subject to appropriate safeguards.
Legal bases for EU, EEA, Irish, and UK processing
Where the GDPR or UK GDPR applies, we rely on one or more of the following legal bases: performance of a contract, steps taken at your request before entering a contract, legitimate interests, compliance with legal obligations, protection of vital interests where applicable, and consent when consent is required. Our legitimate interests include operating and securing the service, supporting customers, improving reliability, preventing fraud, and managing our business, provided those interests are not overridden by your rights and interests.
Artificial Intelligence, Voice, Chat, and Transcripts
Ask Bennett uses artificial intelligence to understand questions and generate spoken or written responses. Individuals should be informed that they are interacting with an AI system. The service is intended to provide business information and conversational assistance, not human judgment or professional advice.
What Bennett knows
Bennett is prepared from information made available through the customer website, connected sources, and other content supplied or approved by the customer. If information is not included in those sources, Bennett may not know it and may be unable to answer. Customer businesses are responsible for keeping their website and approved content accurate, current, lawful, and complete.
AI output can contain errors
AI-generated responses can be inaccurate, incomplete, delayed, misunderstood, or unexpected, even when the underlying business content is accurate. Users should confirm important information directly with the applicable business before relying on it.
Voice data and recording
When voice functionality is used, the service processes audio long enough to recognize speech and generate a response. Audio may be recorded or retained only when recording is enabled, disclosed, and permitted. A transcript, summary, metadata, or diagnostic record may be created to provide the service, maintain quality, investigate problems, or follow customer instructions.
We do not use voice data to create a biometric voiceprint or to identify a person by the unique characteristics of their voice unless that use is separately disclosed and legally authorized.
No significant automated decisions
Ask Bennett is not intended to use personal information to make a solely automated decision that produces legal effects or a similarly significant effect on an individual. Bennett may help provide information, collect a request, route a conversation, or help a user reach a next step. A customer business remains responsible for its decisions, services, sales, employment, eligibility, pricing, contracts, and human follow-through.
A customer that enables voice recording, transcription, analytics, call transfer, lead capture, or another data feature must provide required notices and obtain required consent under the laws of every relevant jurisdiction. This includes laws governing call recording, electronic communications, consumer privacy, employment privacy, and AI transparency.
Cookies, Analytics, and Opt-Out Preference Signals
We and our service providers may use cookies, pixels, local storage, software development kits, and similar technologies to operate the website, remember preferences, maintain security, understand usage, diagnose problems, and measure performance. More detail will be provided in the Ask Bennett Cookie Policy.
Where legally required, non-essential technologies will not be activated until consent is obtained. You can manage cookies through the available consent controls and your browser settings. Blocking some technologies may affect website functionality.
Where applicable law requires recognition of a browser-based universal opt-out mechanism, including Global Privacy Control or another recognized opt-out preference signal, we will process the signal as a request to opt out of covered sale, sharing, or targeted advertising for the browser or device that sends it.
Because there is no uniform legal standard for “Do Not Track,” the website may not respond to a traditional Do Not Track signal unless required by law.
Retention and Deletion
We retain personal information only for as long as reasonably necessary for the purposes described in this policy, to follow customer instructions, provide the service, maintain security, resolve disputes, enforce agreements, and satisfy legal, accounting, tax, insurance, and regulatory obligations.
Our retention decisions consider:
- The type, amount, sensitivity, and context of the information.
- The purpose for which the information was collected and whether that purpose can be achieved another way.
- Customer configuration, instructions, subscription status, and contractual requirements.
- Security, fraud, abuse, backup, litigation-hold, and dispute-resolution needs.
- Legal and regulatory retention requirements in the applicable country or state.
Typical retention framework
- Account, contract, invoice, and transaction records may be retained for the relationship and up to seven years afterward when needed for tax, accounting, legal, or dispute purposes.
- Voice, chat, transcript, and end-user interaction data is retained according to customer configuration, customer instructions, the applicable agreement, and operational need. It may be deleted or returned after the service ends, subject to legal holds, fraud prevention, and limited backup cycles.
- Support and complaint records may be retained for up to three years after closure, or longer when needed for a legal or regulatory matter.
- Security and diagnostic logs are generally retained for up to twenty-four months, unless a longer period is needed to investigate abuse, maintain security, or meet a legal obligation.
Deletion from active systems may not immediately remove data from encrypted backups. Backup copies are isolated, protected, and deleted or overwritten through normal retention cycles.
Security
We use administrative, technical, and physical safeguards designed to protect personal information against unauthorized access, use, alteration, loss, destruction, or disclosure. The safeguards may include access controls, authentication, encryption in transit, logging, vendor controls, backups, security monitoring, least-privilege access, and incident response procedures.
No transmission, storage system, website, AI service, or security program can be guaranteed to be completely secure. You are responsible for maintaining the confidentiality of account credentials and for notifying us promptly of suspected unauthorized access.
If a security incident affects personal information, we will investigate and provide notice to affected individuals, customers, regulators, or authorities when required by applicable law or contract.
International Data Transfers
Ask Bennett is based in the United States and uses service providers that may process information in the United States and other countries. Those countries may have privacy laws that are different from the laws where you live.
Where required for restricted transfers from the European Economic Area, Ireland, or the United Kingdom, we use an approved transfer mechanism, such as an adequacy decision, European Commission Standard Contractual Clauses, the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or another lawful safeguard. We may also conduct transfer assessments and apply additional contractual, organizational, or technical measures where appropriate.
Canadian, Australian, and New Zealand information may also be processed outside the country of origin. We remain responsible for using appropriate contractual and operational measures when applicable law requires them.
Your Privacy Rights and Choices
Depending on where you live and subject to legal exceptions, you may have some or all of the following rights:
Confirm whether we process your information and request access to it.
Request correction of inaccurate or incomplete personal information.
Request deletion, subject to legal, security, contractual, and operational exceptions.
Receive certain information in a portable format where required.
Restrict or object to certain processing, including direct marketing.
Withdraw consent for future processing when consent is the legal basis.
Opt out of covered sale, sharing, targeted advertising, profiling, or certain sensitive-data uses.
Appeal a denied request or complain to us and an applicable regulator.
How to submit a request
Email [email protected] with the subject “Privacy Request,” or use the contact page. Tell us the right you wish to exercise and the country and state or province where you live.
We may need to verify your identity and authority before acting. Verification may include confirming control of an email address, requesting account information, or asking for information that reasonably matches our records. We will use verification information only to process the request. An authorized agent may submit a request where permitted, but we may require proof of authorization and direct identity confirmation from the individual.
We will not discriminate against you for exercising a legally protected privacy right. A request may be denied or limited when an exception applies, when identity cannot be verified, or when the request is manifestly unfounded, excessive, technically infeasible, or conflicts with another person's rights. We will explain the reason when required.
United States State Privacy Notice
Residents of states with comprehensive consumer privacy laws may have rights to access, correct, delete, and obtain a copy of personal data, and to opt out of certain sale, targeted advertising, profiling, or sensitive-data processing. Rights, definitions, exceptions, appeal procedures, and response periods vary by state.
California Notice at Collection and Privacy Disclosure
The table below summarizes the categories of personal information we may have collected, used, and disclosed for a business purpose during the preceding twelve months. Our actual practices depend on your relationship with us and the features used.
| California Category | Purposes and Recipients | Sold or Shared |
|---|---|---|
| IdentifiersName, email, phone, IP address, account ID, business contact details. | Service delivery, accounts, support, security, billing; disclosed to customers and service providers as described above. | No sale for money. No cross-context behavioral advertising sharing unless separately disclosed. |
| Customer records informationContact, billing, account, and transaction information. | Contract administration, billing, customer service, legal and accounting needs. | No sale for money. |
| Commercial informationSubscriptions, plans, purchases, and service history. | Service delivery, billing, support, analytics, and business operations. | No sale for money. |
| Internet or network activityUsage, browser, device, pages, logs, and interactions. | Website operation, security, troubleshooting, analytics, and performance. | No sale for money. Covered opt-out signals are honored where required. |
| Audio and electronic informationVoice audio when enabled, chat, transcript, and communication records. | Voice and chat service, support, quality, security, customer instructions, and legal compliance. | No sale for money. |
| Professional or employment-related informationBusiness title, employer, role, and administrative authority. | Business accounts, access control, communications, and support. | No sale for money. |
| InferencesLanguage, service preference, or likely business interest inferred from activity. | Personalization, support, service improvement, and account management. | No sale for money. |
| Sensitive personal informationOnly if voluntarily submitted or required for a legally authorized feature. | Provide the requested service, security, compliance, or customer instruction. We do not use sensitive information to infer characteristics where restricted. | No sale for money. |
California residents may request to know, access, correct, or delete covered personal information, and may request information about categories collected, sources, purposes, and recipients. Where applicable, residents may opt out of sale or sharing and limit certain uses of sensitive personal information. We do not offer a financial incentive for personal information unless a separate notice describing the program is provided.
We retain each California category using the criteria and framework stated in the Retention section. We do not retain a category longer than reasonably necessary and proportionate for the disclosed purposes, subject to legal and contractual needs.
Appeals
If your state provides a right to appeal and we deny your request, you may appeal by replying to our decision or emailing [email protected] with the subject “Privacy Appeal.” We will provide appeal instructions and any available regulator contact information required by your state.
European Union, European Economic Area, and Ireland
If the GDPR applies, you may have rights of access, rectification, erasure, restriction, portability, objection, withdrawal of consent, and complaint. You also have the right not to be subject to a solely automated decision that produces legal or similarly significant effects, subject to statutory exceptions.
You may object at any time to processing for direct marketing. You may also object to processing based on legitimate interests, and we will stop unless we demonstrate compelling legitimate grounds or the processing is needed for legal claims.
You may complain to the supervisory authority in the EU or EEA country where you live, work, or believe an infringement occurred. In Ireland, the supervisory authority is the Data Protection Commission.
Ask Bennett does not intend to use voice or chat interaction data to make significant automated decisions about individuals. We disclose that users are interacting with an AI system and will maintain that disclosure in line with applicable AI transparency requirements.
United Kingdom
If UK data protection law applies, you may have rights to be informed, access, rectification, erasure, restriction, portability, objection, and protection concerning automated decision-making. You may withdraw consent where consent is the legal basis.
You may submit a data protection complaint to us at [email protected]. We will acknowledge a UK data protection complaint within 30 days, keep you informed of progress where appropriate, and provide an outcome without undue delay, as required by applicable UK law.
You may also complain to the UK Information Commissioner's Office. International transfers from the UK will use an approved safeguard where required, including the UK IDTA or UK Addendum.
Canada
Where Canadian private-sector privacy law applies, we collect, use, and disclose personal information for identified and appropriate purposes, with meaningful consent where consent is required. The form of consent may vary based on the sensitivity of the information and the reasonable expectations of the individual.
You may request access to and correction of personal information we hold about you. You may withdraw consent for future processing where processing is based on consent, subject to legal or contractual restrictions and reasonable notice. Withdrawal may affect our ability to provide a requested feature.
Personal information may be processed outside Canada and may be accessible to courts, law enforcement, or national-security authorities under the laws of the country where it is processed. We use contractual and operational safeguards appropriate to the processing.
You may complain to the Office of the Privacy Commissioner of Canada or an applicable provincial privacy regulator after first giving us an opportunity to address the concern.
Australia
Where the Australian Privacy Act 1988 and Australian Privacy Principles apply, this policy is intended to explain the kinds of personal information we collect and hold, how we collect and use it, the circumstances in which we disclose it, how you may access and correct it, and how you may complain.
We collect only personal information reasonably necessary for our functions and activities. Sensitive information is collected only with consent or as otherwise permitted by law. Information may be disclosed to overseas recipients, including recipients in the United States and locations used by our service providers.
Ask Bennett does not currently use personal information in an automated system to make decisions that could reasonably be expected to significantly affect an individual's rights or interests. If that changes, we will update this policy with the information required by Australian law.
To make an Australian privacy complaint, contact us using the details below. We will investigate and respond within a reasonable period. You may then complain to the Office of the Australian Information Commissioner if you are not satisfied.
New Zealand
Where the New Zealand Privacy Act 2020 applies, we collect personal information only for a lawful purpose connected with our functions and only when collection is necessary for that purpose. We provide notice about collection, use, recipients, access, and correction as required.
If we collect personal information indirectly and New Zealand's indirect-collection notification requirements apply, we will provide the required notice unless a statutory exception applies.
You may request access to and correction of your personal information. You may complain to the New Zealand Office of the Privacy Commissioner after first contacting us so we have an opportunity to resolve the issue.
Children and Young People
Ask Bennett is designed for businesses and general audiences. It is not directed to children under 13 in the United States, and we do not knowingly collect personal information from a child under 13 without verifiable parental consent when consent is required by law.
Voice recordings and audio that contain a child's voice may be personal information. A customer that deploys Bennett in a service likely to be used by children must obtain appropriate legal review, provide age-appropriate notices, minimize collection, and obtain parental or guardian authorization when required.
If you believe a child provided personal information contrary to applicable law, contact us and we will investigate and take appropriate action.
Changes, Contact, and Data Protection Complaints
Changes to this policy
We may update this policy to reflect changes in the service, technology, vendors, business practices, or law. The revised policy will display a new “Last Updated” date. If a change is material, we may provide additional notice through the website, account, email, or another appropriate method before the change takes effect when required.
Contact Ask Bennett
Questions, privacy requests, complaints, and appeals may be sent to:
Ask Bennett
United States
Email: [email protected]
Phone: (888) 515-8088
Use the subject “Privacy Request,” “Privacy Complaint,” or “Privacy Appeal” so the request can be routed correctly. Please do not send complete payment card numbers, bank account numbers, passwords, or government identification by email.
We will investigate privacy complaints in good faith and provide an outcome within the period required by applicable law. You may also have the right to complain to a privacy, data protection, consumer protection, or supervisory authority in your country, state, or province.