top of page

Privacy Policy

 

 

 

 

Last Updated: 8th August, 2026


At TOWP AI LABS (“Company,” “we,” “us,” or “our”), we are committed to protecting your privacy and handling personal information responsibly.


We provide AI-powered voice agents and conversational automation services that enable businesses to communicate with their customers, manage calls, qualify leads, book appointments, provide support, and automate customer interactions.


This Privacy Policy explains how we collect, use, disclose, store, and protect personal information when you visit our website, use our services, communicate with us, or interact with an AI voice agent powered by our platform.


This Privacy Policy is intended to address applicable data protection requirements, including the EU General Data Protection Regulation (GDPR), applicable Cyprus data protection legislation, and the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), where applicable.


Who We Are


TOWP AI LABS
Address: Tinou, 18 OROKLINI HILLS 11, Flat/Office A22 Oroklini, 7040, Larnaca, Cyprus
Email: towpailabs@gmail.com
Website: https://www.towpailabs.com


For purposes of applicable data protection laws, TOWP AI LABS may act as a data controller when determining how and why personal information is processed.


When we process personal information on behalf of a business customer through our AI voice-agent platform, we generally act as a data processor/service provider, while the relevant business customer remains responsible for determining the purposes and means of processing.


Information We Collect


Depending on how you interact with our services, we may collect the following categories of information.


Account and Business Information


This may include:

 

  • Name

  • Business or company name

  • Email address

  • Telephone number

  • Business address

  • Login credentials

  • Billing and subscription information

  • Information provided when configuring an AI agent

Customer and Call Information


When an AI voice agent makes or receives a call, we may process:

  • Caller or recipient name

  • Telephone number

  • Voice recordings

  • Call transcripts

  • Conversation history

  • Call duration and timestamps

  • Call outcome

  • Information provided during the conversation

  • Appointment or booking information

  • Lead qualification information

  • Customer preferences

  • Other information necessary to complete the requested interaction


AI Agent Configuration Data


Customers may provide information used to configure their agents, including:

Business information
FAQs
Knowledge bases
Scripts and instructions
Brand voice and tone
Conversation workflows
Products and services
Pricing or business rules
Customer-service procedures


Technical and Usage Information


We may automatically collect:

 

  • IP address

  • Browser type

  • Device information

  • Operating system

  • Approximate location

  • Website activity

  • Log information

  • Usage and performance data

  • Cookies and similar technologies

How We Use Personal Information


We may use personal information to:

 

  • Provide and operate our AI voice-agent platform

  • Make and receive calls on behalf of our customers

  • Understand spoken language and conversation context

  • Generate AI responses

  • Complete tasks requested during conversations

  • Qualify leads and identify customer intent

  • Schedule appointments

  • Provide customer support

  • Improve agent performance and reliability

  • Provide analytics and reporting

  • Maintain conversation context and memory where enabled

  • Detect and prevent fraud, abuse, and security threats

  • Maintain and secure our platform

  • Process payments and manage subscriptions

  • Communicate with customers about our services

  • Comply with legal and regulatory obligations

We apply data-minimisation and purpose-limitation principles and seek to process only information that is reasonably necessary for the relevant purpose. GDPR principles include purpose limitation, data minimisation, storage limitation, and security.


AI Voice Conversations


Our services enable businesses to deploy AI voice agents that communicate with individuals by telephone.
Depending on how an AI agent is configured, conversations may be:

 

  • Recorded

  • Transcribed

  • Analysed

  • Stored

  • Used to maintain conversation context

  • Used to complete actions requested during a call

Businesses using our platform are responsible for configuring their agents and call practices in accordance with applicable laws.


Where required by applicable law, callers should be informed that they are interacting with an AI system and/or that the call is being recorded.


Voice Recordings and Transcripts


Voice recordings and transcripts may contain personal information and may include sensitive information depending on what a caller chooses to disclose.


We process such information only for legitimate and disclosed purposes and apply appropriate safeguards.


We do not require callers to provide sensitive personal information unless it is necessary for the specific service being provided.


Customer Data Processed on Behalf of Businesses


Our business customers may use our platform to process information about their customers, leads, employees, prospects, or other individuals.


In these circumstances, the business customer generally determines:

 

  • What information is collected

  • Why it is collected

  • How it is used

  • How long it should be retained

We process this information on the customer's behalf and in accordance with our agreement with that customer.


Businesses using our platform are responsible for ensuring that they have an appropriate legal basis for processing personal information and for providing any required privacy notices to their customers.


Legal Bases for Processing Under GDPR


Where GDPR applies, we process personal information only where a valid legal basis exists.

 

Depending on the circumstances, this may include:

 

Performance of a Contract


Where processing is necessary to provide a service or fulfil an agreement.

 

Legitimate Interests


Where processing is necessary for legitimate business interests, provided those interests are not overridden by the individual's rights and interests.

Consent


Where we rely on consent, individuals may withdraw their consent at any time.


Legal Obligation


Where processing is necessary to comply with applicable law or a legal requirement.


Where required by GDPR, we will provide information about the applicable legal basis and other required processing information.


How We Share Personal Information


We may share personal information with:

Service Providers


Third-party providers that help us operate our platform, including providers of:

 

  • Cloud hosting

  • AI and machine-learning infrastructure

  • Telecommunications and voice services

  • Speech recognition and text-to-speech services

  • Analytics

  • Security

  • Customer support

  • Payment processing

  • Email and communications

  • Data storage

Business Customers


Where we process information on behalf of a business customer, information may be made available to that customer according to their instructions and applicable agreements.


Integrations


If a customer connects our platform to third-party systems such as CRMs, calendars, helpdesks, or communication platforms, information may be transferred to those systems as necessary to perform the requested functionality.


Legal and Regulatory Authorities


We may disclose information where required by law, regulation, court order, legal process, or governmental authority, or where reasonably necessary to protect our rights, users, security, or property.

 

International Data Transfers


Because we may use service providers located in different countries, personal information may be processed outside Cyprus, the European Economic Area, or California.

Where GDPR applies, and personal information is transferred outside the EEA, we will use an appropriate lawful transfer mechanism where required, such as an adequacy decision or appropriate contractual safeguards.

 

Data Retention
We retain personal information only for as long as reasonably necessary for the purposes described in this Privacy Policy.


Retention periods may depend on:

 

  • The type of information

  • The purpose for which it was collected

  • Contractual requirements

  • Customer configuration

  • Legal and regulatory requirements

  • Security and dispute-resolution requirements

Customers using our platform may have options to configure retention periods for call recordings, transcripts, and conversation data.

 

Data Security


We use appropriate technical and organisational measures designed to protect personal information against:

 

  • Unauthorised access

  • Accidental loss

  • Destruction

  • Alteration

  • Unauthorised disclosure

  • Misuse

Security measures may include access controls, authentication, encryption, monitoring, logging, and other safeguards appropriate to the nature of the information.


No internet-based system can be guaranteed to be completely secure.

 

Your GDPR Rights


Where GDPR applies, you may have the right to:

  • Access your personal information

  • Correct inaccurate information

  • Request deletion of your information

  • Restrict certain processing

  • Object to certain processing

  • Receive your information in a portable format

  • Withdraw consent where processing is based on consent

  • Object to certain direct marketing

  • Lodge a complaint with a relevant supervisory authority

 

These rights are subject to applicable legal exceptions and limitations. The European Commission identifies access, rectification, erasure, restriction, portability, and objection among GDPR data-subject rights.

 

Cyprus Supervisory Authority

 

If you are located in Cyprus, you may contact the:

 

Office of the Commissioner for Personal Data Protection
15 Kypranoros Street
1087 Nicosia, Cyprus
Email: commissioner@dataprotection.gov.cy

 

The Cyprus Commissioner is the national data protection authority responsible for data protection matters in Cyprus.

 

California Privacy Rights — CCPA / CPRA


This section applies to California residents to the extent that the California Consumer Privacy Act, as amended by the California Privacy Rights Act, applies to our processing of their personal information.

 

Categories of Personal Information


Depending on how you interact with us, we may collect categories of personal information including:

 

  • Identifiers such as name, email address, and telephone number

  • Commercial information

  • Internet or network activity

  • Geolocation information

  • Professional or business information

  • Audio or electronic information, including voice recordings and call transcripts

  • Inferences derived from information used to provide or personalise services

  • Other categories of information described in the CCPA

California Privacy Rights


Subject to applicable exceptions, California residents may have the right to:

 

  • Know what personal information we collect, use, disclose, or otherwise process

  • Access personal information

  • Delete personal information

  • Correct inaccurate personal information

  • Opt out of the sale or sharing of personal information

  • Limit certain uses and disclosures of sensitive personal information

  • Receive equal treatment when exercising applicable privacy rights

The CPPA confirms these rights under the CCPA as amended by the CPRA.


California Privacy Requests


To submit a privacy request, contact us at:


Email: towpailabs@gmail.com
Privacy Request Form: https://www.towpailabs.com/


We will verify requests as required by applicable law and respond within the legally required timeframe.


Sale or Sharing of Personal Information


We Do Not Sell or Share Personal Information

We do not sell personal information for monetary or other valuable consideration, and we do not share personal information for cross-context behavioural advertising as defined under the CCPA. Because we do not engage in these activities, the CCPA right to opt out of the sale or sharing of personal information does not apply to our practices.


Sensitive Personal Information


Depending on the nature of a conversation, an AI voice agent may receive information that qualifies as sensitive personal information under applicable law.


We do not intentionally request sensitive personal information through our AI agents unless it is necessary for the service being provided.


Where applicable law provides additional rights or restrictions regarding sensitive personal information, we will process such information in accordance with those requirements.


Automated Decision-Making and AI


Our platform uses artificial intelligence to understand conversations, generate responses, identify intent, and perform actions.


Depending on how a customer configures the platform, AI may assist with decisions such as:

 

  • Lead qualification

  • Customer intent classification

  • Appointment prioritisation

  • Conversation routing

  • Customer-service workflows

Our AI agents are designed to assist businesses and automate conversations. They do not independently establish the legal basis for processing personal information.


Where applicable law provides rights relating to automated decision-making or profiling, we will provide the information and rights required by that law.


Cookies and Tracking Technologies


We may use cookies and similar technologies for:

 

  • Essential website functionality

  • Authentication

  • Analytics

  • Security

  • Performance monitoring

  • Marketing, where applicable

 

Where required, we will request consent before using non-essential cookies or similar technologies.


Children's Privacy


Our services are intended for businesses and are not directed toward children.

 

We do not knowingly collect personal information from children in violation of applicable law.

 

Third-Party Websites

 

Our website or services may contain links to third-party websites or services.

 

We are not responsible for the privacy practices of third parties. We encourage you to review their privacy policies before providing personal information.

 

Changes to This Privacy Policy


We may update this Privacy Policy periodically to reflect changes to our services, technology, business practices, or legal requirements.

 

When we update this policy, we will change the Last Updated date at the top of the page.

 

Contact Us

For questions, privacy requests, or concerns about this Privacy Policy, contact:

 

TOWP AI LABS
Tinou, 18 OROKLINI HILLS 11, Flat/Office A22 Oroklini, 7040, Larnaca, Cyprus
Email: towpailabs@gmail.com
Website: https://www.towpailabs.com/

bottom of page