1. Two roles
As a business (a “controller”), Enso decides how it handles information about our vendor customers and people who visit our website. That is what most of this policy describes.
As a service provider (a “processor”), Enso handles personal information about the people its agents talk to on a customer’s behalf — callers, technicians, property managers, tenants, and other contacts — only to run the desk for that customer. The customer directs that processing under its agreement with Enso. If you were contacted by an Enso agent and want to exercise a privacy right, contact the vendor whose line you called; we will help them respond.
2. Information we collect
From customers directly
- Account and contact details — name, work email, company name, phone number, role.
- Business details you enter during setup — trades, sites and asset names, crew and on-call contacts, intake scripts, dispatch rules.
- Billing details — processed by Stripe. We receive confirmation, plan, and the last four digits and card brand; we do not store full card numbers.
- Support and other communications you send us.
Automatically from the website
- Usage data — pages viewed, links clicked, session activity.
- Device and connection data — IP address, browser and operating system, device identifiers.
- Referral data — UTM parameters and referring URLs.
- Cookies — see Section 6. The site also loads web fonts from Google Fonts, which receives the request IP.
From operation of the Service (on the customer’s behalf)
- Call audio, and recordings only where a customer has enabled recording.
- Transcripts of calls, and the content of SMS and email the agents handle.
- Work-order data — site, unit, asset, access notes, urgency, status.
- Contact information and interaction history of the individuals the agents communicate with.
3. How we use information
- Provide, operate, secure, and improve the Service and the website.
- Configure and tune each customer’s agents to its sites, trades, and dispatch rules.
- Process payments, send service and transaction messages, and provide support.
- Detect and prevent fraud, abuse, and security incidents, and comply with law.
- Send marketing about Enso to business contacts, where permitted and subject to opt-out. We do not send marketing to the individuals the agents contact on a customer’s behalf.
We do not sell personal information, and we do not “share” it for cross-context behavioral advertising.
4. AI processing
Calls, messages, and email handled by the agents are processed by a third-party AI model provider under contract. That provider does not use content sent through its API to train its foundation models. We use content to operate and improve the customer’s own configuration, not to build products for other customers without de-identification.
5. How we share information
- Subprocessors and service providers — telephony and messaging, AI model hosting, payment processing, cloud hosting, and database providers, each bound to protect the information and use it only to provide their service. Categories are listed on the Security page.
- At the customer’s direction — for example when a completed work order is sent to the customer’s own system by email, webhook, or file export.
- Legal and safety — to comply with law, enforce our terms, or protect rights and safety.
- Business transfers — in connection with a merger, acquisition, or sale of assets, subject to this policy.
6. Cookies
The website uses cookies and similar technologies that are necessary for it to function, a support-chat widget that sets its own cookies when you open it, and — where enabled — privacy-preserving analytics to understand traffic. We do not use advertising cookies. You can control cookies through your browser settings.
7. Retention
We keep account and business information for as long as the account is active and for a limited period afterward for legal, tax, and audit purposes. Transcripts, recordings, and work-order data are retained for the period a customer configures, or our default retention window, and are then deleted or de-identified. We will delete or return Customer Data on request after an account closes, subject to law and backups that expire on a rolling basis.
8. Your choices and rights
Depending on where you live, you may have the right to access, correct, delete, or receive a copy of your personal information, and to object to or restrict certain processing. California residents have rights under the CCPA as amended by the CPRA, including the right to know, delete, and correct, and the right not to be discriminated against for exercising them; as noted above, we do not sell or share personal information. To exercise a right, contact privacy@ensofm.ai. We will verify your request and respond within the time the law allows. For information the agents processed on a customer’s behalf, we will route your request to that customer.
9. Security
We use administrative, technical, and physical safeguards appropriate to the information we handle, including encryption in transit and access controls on a need-to-know basis. No method of transmission or storage is completely secure. See Security for more detail.
10. Children
The Service is for businesses and is not directed to children. We do not knowingly collect personal information from children.
11. International
Enso operates in the United States and stores information there. If you access the Service from outside the United States, you understand the information is processed in the United States.
12. Changes
We may update this policy. Material changes will be announced by email or in the app before they take effect, and the “last updated” date above will change.
13. Contact
Privacy questions or requests: privacy@ensofm.ai.