Privacy Policy

Last updated: July 2026

This Privacy Policy explains how Depla (“Depla,” “we,” “us”) collects, uses, shares, and protects information when you visit our website, run a demo, or use the Depla AI phone-agent service (the “Service”). It also explains how we handle the personal information of people who call a restaurant that uses Depla.

Information We Collect

  • Information you provide. Contact details (name, business name, email, phone number), the website URL you submit for a demo, billing details, and anything you send us through forms or support.
  • Demo and conversation content. The content of demo chat sessions, and for live customers, call recordings, transcripts, and order details processed by the agent.
  • Caller information.When someone calls a restaurant served by Depla, we process the caller's phone number and the details they provide (such as name and order) to fulfill the call, on behalf of that restaurant.
  • Automatically collected. Standard technical data such as IP address, browser/device type, and usage and diagnostic logs collected to operate and secure the Service.

How We Use Information

  • To provide, operate, and maintain the Service and your voice agent.
  • To respond to demo requests, follow up with you, and provide support.
  • To process payments and manage your account.
  • To secure, troubleshoot, and improve the Service, including model quality.
  • To comply with legal obligations and enforce our terms.

We do not sellyour personal information. We do not use the content of a customer's calls to train models in a way that identifies that customer or its callers; any model improvement uses de-identified or aggregated data.

Call Recording and Consent

Calls to a live Depla phone number may be recorded and transcribed for order accuracy, quality, and training of staff and the agent. Customers (restaurants) are responsible for providing any legally required notice to their callers. Recordings and transcripts are retained on a limited schedule and then purged. Sample or representative recordings shown on our website are produced by us for demonstration and do not contain real customer calls.

How We Share Information

We share information only as needed to run the Service:

  • Service providers. Vendors that power telephony, speech-to-text and text-to-speech, AI models, hosting, and analytics, under contracts that limit their use of the data.
  • Restaurant customers. Caller and order information is shared with the restaurant the caller contacted, as the controller of that data.
  • Legal and safety. Where required by law, to protect rights and safety, or in connection with a business transfer.

Service Providers & Sub-processors

We rely on a small set of trusted providers to run the Service. They process data on our behalf under contracts that limit their use of it. The main categories and providers are:

  • Telephony & call transport: Twilio (and additional carriers we may add) to receive and route phone calls.
  • Speech-to-text: Deepgram, to transcribe caller speech into text.
  • Text-to-speech:ElevenLabs, to generate the agent's spoken voice.
  • AI language models:OpenAI (and Anthropic for onboarding features), to understand requests and generate the agent's replies.
  • Point of sale: Clover, when a restaurant connects it, to sync menus and push orders.
  • Hosting, CDN & bot protection: Cloudflare, for delivery, security, and Turnstile bot protection.
  • Email: Google Workspace, for transactional email such as password resets and verification.
  • Website analytics: Plausible, a privacy-friendly analytics tool that uses no cookies and does not track you across sites.

This list may change as the Service evolves; we'll keep it current here. If you need a data processing agreement (DPA) or a formal sub-processor list for your records, contact us.

Cookies & Analytics

Our website uses only essential cookies needed to operate it and, where enabled, Cloudflare Turnstile to tell humans from bots on our demo and contact forms. For traffic measurement we use Plausible, which is cookieless and collects only aggregated, non-identifying usage data — so we do not show a tracking-cookie banner because we do not set tracking cookies.

International Data Transfers

We operate in the United States, and our providers may process data in the United States and other countries. Where personal data is transferred from the EEA, UK, or other regions, we rely on appropriate safeguards (such as Standard Contractual Clauses) where required.

Data Retention

We keep information only as long as needed for the purposes described here, to comply with legal obligations, resolve disputes, and enforce agreements. Demo agents and demo data are temporary and removed after a short period. Call recordings are purged on a limited retention schedule.

Security

We use administrative, technical, and physical safeguards designed to protect personal information, including encryption of sensitive fields in transit and at rest. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.

Your Choices and Rights

Depending on where you live, you may have rights to access, correct, delete, or port your personal information, or to object to certain processing. To make a request, or to ask that a restaurant (as the controller) handle caller data, contact us using the details below. You can opt out of marketing emails at any time via the unsubscribe link. We will not discriminate against you for exercising these rights.

California (CCPA/CPRA)

California residents may request access to or deletion of their personal information and may opt out of any “sale” or “sharing” of personal information. We do not sell personal information and do not share it for cross-context behavioral advertising.

EEA / UK (GDPR)

If you are in the EEA or UK, our legal bases for processing are performance of a contract, our legitimate interests in operating and securing the Service, your consent (where applicable), and compliance with legal obligations. For caller and order data, the restaurant you called is the controller and Depla acts as its processor; you may direct requests to that restaurant or to us. You also have the right to lodge a complaint with your local data protection authority.

Children's Privacy

The Service is intended for businesses and is not directed to children under 13, and we do not knowingly collect their personal information.

Changes to This Policy

We may update this Privacy Policy from time to time. We will post the updated version with a new “Last updated” date and, for material changes, provide additional notice where appropriate.

Contact

Questions or privacy requests? Email hello@depla.ai.

Try the demo