Privacy Policy
Last updated: June 15, 2026 · v3.2
1. Data we collect
We collect account information you provide (name, work email, company), configuration data (connected integrations, guardrail settings), and — on behalf of our customers — the customer-support conversations Dessa processes. Website analytics are collected in aggregate, without cross-site tracking.
2. How we use it
Conversation data is processed solely to deliver the service: resolving conversations, routing handoffs, and producing the analytics visible in your workspace. We act as a processor under your instructions; the data controller is the business you interact with.
3. AI & model training
Your data never trains models used by other customers. Personally identifiable information is redacted before any model call. Optional per-workspace learning (e.g. tone tuning) stays inside your workspace and can be disabled at any time.
4. Retention & deletion
Default retention is 24 months, configurable down to 30 days per data category. On termination, all customer data is deleted within 30 days, with certification available on request.
5. Your rights
Depending on your location, you may have rights to access, correct, export or delete your personal data (GDPR, CCPA). Requests via privacy@heydessa.ai are answered within 30 days; end-user requests are routed to the responsible controller.
6. Contact
Dessa · a product of Trengo B.V. · Stadsplateau 30, 3521 AZ Utrecht, Netherlands · privacy@heydessa.ai. Our Data Protection Officer can be reached at the same address, attention DPO.