Legal

Privacy Policy

How StateSet collects, uses, shares, retains, and protects information when providing ResponseCX.

Effective and last updated: August 26, 2026

1. Scope and roles

This Privacy Policy explains how StateSet, Inc. handles personal information in connection with ResponseCX websites, accounts, trials, support, and platform services. It does not govern a customer’s own privacy practices.

For customer content processed to provide the service, the customer generally acts as controller or business and StateSet acts as processor or service provider. An applicable data processing agreement controls that processing.

2. Information we collect

  • Account and business information, including names, work email addresses, organization, role, and authentication identifiers.
  • Billing and transaction information, including plan, invoices, outcome records, disputes, and payment-method metadata. Full card details are processed by Stripe and do not pass through our application servers.
  • Customer content, including messages, tickets, knowledge, policies, order and subscription context, agent configuration, and records returned by connected systems.
  • Usage, device, log, diagnostic, audit, and security information, including IP address, browser, request identifiers, actions, errors, and service performance.
  • Marketing and communications information, including campaign parameters, demo requests, preferences, and correspondence.

3. How we use information

  • Provide, secure, support, and improve ResponseCX and its integrations.
  • Authenticate users, enforce organization access, prevent abuse, and investigate security incidents.
  • Execute configured workflows, produce responses, maintain audit history, meter outcomes, invoice customers, and resolve billing disputes.
  • Communicate about the service, support requests, security, billing, product updates, and—where permitted—relevant offers.
  • Comply with law, enforce agreements, and protect customers, end users, StateSet, and the public.

4. AI and automated processing

ResponseCX uses AI service providers and configured models to process prompts, knowledge, conversation context, and tool results. Customers control which data and systems are connected and should avoid submitting data that is unnecessary for the selected workflow.

Operational decisions may be automated within customer-configured guardrails or routed for human approval. Customers can review audit records and configure escalation and approval thresholds.

5. How information is shared

  • With infrastructure, authentication, payment, analytics, communications, AI, observability, and support providers acting under contractual restrictions.
  • With integrations and destinations selected or authorized by the customer.
  • With professional advisers, auditors, insurers, and transaction counterparties where reasonably necessary.
  • To comply with law, legal process, or valid government requests, or to protect rights, safety, and service integrity.
  • We do not sell personal information for money. Where advertising or analytics laws treat certain disclosures as “sharing,” available browser or contact-based choices apply.

6. Retention and deletion

We retain information for the period needed to provide the service, meet contractual commitments, maintain security and audit history, resolve disputes, and comply with law. Retention may vary by data category and customer configuration. Customers may request deletion or export subject to legal, security, backup, and contractual limitations.

7. Security

We use administrative, technical, and organizational safeguards designed to protect information, including access controls, encryption in transit, audit logging, and incident-management procedures. No system is completely secure, and customers must also protect credentials and configure least-privilege integration access.

8. International transfers

StateSet and its providers may process information in the United States and other countries. Where required, we use contractual and organizational measures intended to support lawful cross-border transfers.

9. Privacy rights and choices

Depending on location, individuals may have rights to access, correct, delete, restrict, object to, or obtain a copy of personal information, and to withdraw consent. Requests concerning data controlled by a ResponseCX customer should first be directed to that customer. We will not discriminate for exercising applicable privacy rights.

You may opt out of marketing email using the unsubscribe link. Browser settings can limit cookies; some essential storage is required for authentication, security, attribution continuity, and user preferences.

10. Children

ResponseCX is a business service and is not directed to children under 13. Customers are responsible for ensuring that their use of the service and collection of end-user information is appropriate for their audience and permitted by law.

11. Changes to this policy

We may update this policy to reflect changes in the service, providers, or law. We will post the updated version and change the effective date, and will provide additional notice when required.