Privacy Policy
This Policy explains how AEER Platform Inc. (“AEER”, “we”, “us”) handles personal data in connection with the FG real-time voice-AI platform and the website at fg-platform.com (the “Service”).
1. Who we are and our two roles
The Service lets business customers build a voice assistant and embed it on their own websites as a widget. Depending on whose data is involved, we act in one of two roles under the EU/UK General Data Protection Regulation (“GDPR”):
- Controller — for the personal data of our account holders (our customers) and visitors to fg-platform.com. This Policy governs that processing.
- Processor — for personal data that a business customer collects from its own end-users through the FG widget (for example, conversation transcripts and leads). There, the customer is the controller and decides the purposes; we process on their behalf under our Data Processing Addendum. If you are such an end-user, please refer to the privacy notice of the website you were using.
2. Personal data we process
Account holders (we are controller)
- Identity and contact: name and email address.
- Credentials: a salted, hashed password (we never store passwords in clear text).
- Service usage and billing metrics: request counts, conversation minutes, token and cost accounting, and API-key metadata.
- Technical logs necessary to run and secure the Service.
End-users of a customer’s website (we are processor)
- Voice and text of the conversation with the assistant, including audio that is transcribed to text.
- Lead details a visitor chooses to submit (typically name and email).
- Context of the session: the page/website where the widget runs, language, timestamps, and a randomly generated session/visitor identifier.
We do not intentionally collect special categories of data. Please do not provide payment-card numbers, government IDs, health information, or other sensitive data to the assistant.
3. How the voice assistant processes data
To answer in real time, a conversation is processed through a pipeline of specialist providers (our sub-processors): speech is transcribed to text, a large-language model generates a reply, and the reply is synthesized back to speech. Transcripts and messages are stored so that the business customer can review conversations and captured leads in their console.
4. Why we process data and our legal bases
- To provide the Service (create and run assistants, hold conversations, capture leads, meter usage) — performance of a contract (GDPR Art. 6(1)(b)), or our and our customers’ legitimate interests (Art. 6(1)(f)).
- To secure the Service and prevent abuse (rate limits, quotas, fraud prevention) — legitimate interests (Art. 6(1)(f)).
- To communicate with account holders (email verification, service notices) — contract and legitimate interests.
- Where we act as processor, the legal basis for processing end-user data is determined by the business customer (controller).
5. Sub-processors
We use the following sub-processors to run the Service. They process personal data only to provide their function to us and under contractual obligations consistent with this Policy and our DPA.
| Sub-processor | Function | Region |
|---|---|---|
| Supabase | Managed database (stores accounts, conversations, leads) | EU (Frankfurt) |
| Render | Application hosting | EU (Frankfurt) |
| Cloudflare | Content delivery and network security | Global edge |
| Groq | Speech-to-text transcription | United States |
| Anthropic | Large-language-model responses | United States |
| Cartesia | Text-to-speech synthesis | United States |
| Jina AI | Rendering a customer’s website during assistant setup | United States |
| Resend | Transactional email (e.g. email verification) | United States |
6. International data transfers
Our primary database and application hosting are located in the European Union (Frankfurt). Some sub-processors are located in the United States, so certain data is transferred outside the EEA/UK. Where required, such transfers are protected by appropriate safeguards, in particular the European Commission’s Standard Contractual Clauses (and the UK Addendum where applicable), together with supplementary technical measures such as encryption in transit.
7. Retention and deletion
We keep account data for as long as the account is active and for a limited period afterwards as needed for legal, security, and accounting purposes. Conversation and lead data are retained according to the retention period configured by the business customer (controller) or their instructions; where a retention period is enabled, older conversations are deleted automatically. The Service provides tools to delete an individual conversation on request. Aggregate, non-identifying usage and cost records may be retained for accounting.
8. Your rights
Subject to applicable law, you may request to access, correct, delete, restrict, or port your personal data, and to object to certain processing. You may also withdraw consent where processing relies on it. To exercise these rights, email privacy@fg-platform.com. If you are an end-user of a customer’s website, we will refer your request to that customer (the controller) or act on their instructions. You also have the right to lodge a complaint with your local data-protection supervisory authority.
9. Security
We apply technical and organizational measures appropriate to the risk, including encryption in transit (TLS), encryption at rest at our database provider, tenant isolation via row-level security, salted password hashing, hashed session and API-key storage, least-privilege service credentials, and access controls. No method of transmission or storage is completely secure, but we work to protect your data and to detect and respond to incidents.
10. Cookies
fg-platform.com uses a single strictly-necessary cookie to keep you signed in; we do not use advertising or cross-site tracking cookies. The embeddable widget uses your browser’s local storage to remember language and to hold a session identifier for the duration of a conversation.
11. Children
The Service is intended for businesses and is not directed to children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us data, contact us and we will delete it.
12. Changes to this Policy
We may update this Policy from time to time. We will change the “last updated” date below and, for material changes affecting account holders, provide additional notice where appropriate.
13. Contact
AEER Platform Inc.
8 The Green, STE A, Dover, DE 19901, United States
Email: privacy@fg-platform.com