Privacy Policy
This notice explains how Iterait, Inc. handles personal information across our website, business relationships, and AI OS: the operating layer connecting employees, agents, and applications. It also explains which organization to contact about your information.
Iterait acquired Welth Technologies, SAS Sociedad de Beneficio e Interes Colectivo, an Ecuadorian company. This acquisition explains the relationship between the Iterait brand and Welth Technologies.
1. Who is responsible for your information
When you visit our website, contact us, book a demo, or administer an Iterait account, Iterait determines the purposes of processing information for those activities. This includes relationship management, account administration, billing, fraud prevention, and security.
When an organization uses AI OS to process employee or customer information, that organization generally determines why and how the information is used. Iterait processes it on the organization's instructions as its processor, or subprocessor where applicable. The organization's privacy notice, agreement with Iterait, and applicable data-processing terms govern that relationship.
An employer or other organization may administer your access, configure agents, connect systems, and access records within its permissions. Ask that organization about its monitoring, retention, and use of your information. A connected app, messaging channel, or payment provider may also act independently under its own privacy notice.
2. Information we process and where it comes from
The information depends on the features and integrations your organization uses:
- Business and account information: name, work email, contact details, organization, account role, authentication records, and communications with our team. You or your organization's administrator provide these.
- Connected business information: documents, knowledge sources, CRM records, calendars, files, tool responses, and other information made available through the systems your organization connects. A connection does not make every source appropriate for every agent; your organization is responsible for its configuration and authorized use.
- Conversations and AI interactions: prompts, messages, contact identifiers, attachments, agent configurations, and generated responses. These come from users, messaging channels, and connected applications.
- Operational records: access and activity records, timestamps, technical errors, delivery receipts, usage measurements, and security events generated while the service runs.
- Commercial information: plan selections, billing contacts, payment status, and transaction references. Payment providers handle payment processing under their own terms.
- Website information: IP address, browser and device information, pages visited, referrer, campaign identifiers, and interactions with our website, collected through requests and tracking technologies.
If information is supplied by your employer, a customer organization, or a connected source rather than by you, that organization is responsible for having authority to provide it and giving you the relevant notice.
3. Why we use information
We use information to provide and administer accounts; connect authorized systems; operate agents and requested workflows; return responses; support users; measure usage and bill for services; detect misuse; investigate errors; and maintain service reliability.
We also use business contact information to answer inquiries, arrange demonstrations, manage contracts, and communicate about our services. Website measurement helps us understand visits, product interest, and campaign performance.
Where a law requires a legal basis, the appropriate basis depends on the activity: performance of a contract or steps you request before a contract; applicable legal obligations; consent for activities that require it; or legitimate interests where permitted, such as protecting our services and managing business relationships, subject to the required assessment and your rights. The customer organization determines the legal basis for information it instructs AI OS to process.
You do not have to supply optional information. Without information required for an account, a requested workflow, or billing, we may be unable to provide that function. Inaccurate information may affect access, results, and communications.
4. AI processing, connected apps, and human oversight
AI OS can send relevant prompts, conversation context, and tool results to the model providers used for a configured service. Providers and connected services process information according to the applicable configuration and contractual arrangements; their retention and processing terms can differ.
Under our 2026 Terms of Service, we do not use Customer Data to train or fine-tune foundation models. Those terms also require model-provider offerings that restrict training on Customer Data. This is not a claim that no provider processes or retains information.
AI-generated responses can be inaccurate or incomplete. Customer organizations must maintain meaningful human review for consequential decisions, including decisions concerning healthcare, employment, credit, or legal rights. If you want to understand or challenge a decision made by an organization using an agent, contact that organization and request human review.
Connecting a tool may allow an agent to retrieve information or carry out actions within its configured permissions. Administrators should review those permissions and avoid connecting information that is not needed for the intended task.
5. Who may receive information
Information may be processed by infrastructure and hosting providers, AI model providers, messaging services, payment processors, analytics providers, and service providers supporting the operation of Iterait.
The existing platform and website use Google Cloud infrastructure; the website integrates Google Analytics, Meta Pixel, and PostHog. Demo booking links take you to Cal.com. Model providers and other connected apps depend on the services enabled for your organization. Contact us for the provider and processing details applicable to your account.
Authorized Iterait personnel may access information for support, implementation, troubleshooting, or security when needed for their work. Your organization's administrators and other authorized users may also have access according to their roles.
We may disclose information where required by law, to respond to valid legal requests, or as necessary to protect rights and service security. Information may also be involved in a corporate transaction, subject to applicable confidentiality and data-protection requirements.
Website advertising and measurement disclosures are described separately below. They must not be confused with permission to use AI OS customer conversations for advertising.
6. Website cookies, analytics, and advertising
Our website uses browser storage to remember language preferences. Its current analytics integration loads Google Analytics, Meta Pixel, and PostHog to measure page views, interactions, and campaign attribution. These services may receive device or browser identifiers, IP addresses, page and referrer information, and campaign parameters. PostHog is configured with a US endpoint and may use cookies across joiniterait.com subdomains.
Meta Pixel supports advertising measurement and may connect website activity with information Meta holds. The characterization of advertising disclosures, and the choices required, depends on the applicable law. This notice does not treat simply visiting the website as consent.
Browser controls can limit cookies and storage, although blocking storage may affect remembered preferences. Those controls are not a substitute for any consent or opt-out mechanism required by law. Contact us with a tracking-related request. External booking and application sites have their own notices and settings.
7. Retention and deletion
We retain information for the purposes for which it was collected, taking account of the service agreement, the nature of the information, account activity, support and security needs, and applicable legal requirements. Different records need different retention periods; deleting an account does not necessarily delete every billing, legal, or security record immediately.
For Customer Data governed by our 2026 Terms of Service, those terms provide for requested export during the term or within 30 days after termination, and deletion or de-identification within 90 days after termination. Exceptions include encrypted backup copies removed on rolling schedules and records required for legal, tax, or security purposes. A free account inactive for more than 12 months may be deleted on 30 days' notice. The applicable agreement governs.
For information controlled by a customer organization, send a deletion or retention request to that organization. We assist it under the applicable agreement. Contact Iterait for the retention details relevant to website, account, billing, or support information.
8. International processing
Cloud infrastructure, model providers, analytics services, and connected applications may process information outside the country where you or your organization are located. Processing locations depend on the selected services and providers; this notice does not promise that all information remains in Ecuador, Latin America, or any single region.
Where applicable law restricts an international transfer, the required lawful mechanism and safeguards must be established for that transfer. Contact us for the locations, recipients, and safeguards applicable to your account, including how to obtain relevant information about those safeguards.
9. Security and sensitive information
Our Terms describe measures including encryption in transit and at rest, role-based access, secret management, and security logging. Security depends on the service configuration and on customers protecting credentials, selecting appropriate permissions, and supervising agents. No system can guarantee absolute security.
Do not submit passwords, full payment-card details, or other information prohibited by the Terms or the relevant messaging channel. Protected health information requires the specific authorization, agreements, and approved configuration described in the Terms. Organizations remain responsible for safeguards required for sensitive information.
Report a suspected security issue to security@joiniterait.com. Do not include passwords or unnecessary sensitive information in a report.
10. Your rights and choices
Depending on your location and the applicable law, you may have rights to access, correct, update, delete, restrict, object to processing, obtain a portable copy of your information, withdraw consent, or seek review of solely automated decisions. Rights may be subject to lawful exceptions. Withdrawing consent does not change the lawfulness of processing before withdrawal.
For information Iterait controls, write to hello@joiniterait.com with the subject “Privacy request.” Describe your request and your relationship with Iterait. We may need proportionate verification to protect your information; please do not send identity documents unless requested through an appropriate channel. We handle requests within the time limits required by applicable law.
For information processed on behalf of an organization, contact that organization first. If you contact Iterait, we can help identify the appropriate route and assist the organization under our agreement.
You may unsubscribe from promotional email through the instructions in the message or contact us. Necessary service and account notices are separate. You may also complain to the competent data-protection authority, including the Superintendencia de Protección de Datos Personales in Ecuador, or the authority competent for your location.
11. Children and organization-managed services
Iterait's business account services are intended for organizations, not for children to register independently. If an organization uses agents in a context involving minors, it is responsible for the lawful basis, required notices and permissions, appropriate configuration, and safeguards for that use. Contact us if you believe a child's information has been handled improperly.
12. Changes and contact
We may revise this notice to reflect changes in our services, processing, or legal requirements. Material changes require appropriate notice under applicable law. A website notice does not override the applicable customer agreement or remove individual rights.
Iterait, Inc.
A Delaware corporation.
390 NE 191st St, Miami, FL 33179, United States.
Telephone: +1 (732) 804-3199
Privacy inquiries: hello@joiniterait.com
Security reports: security@joiniterait.com
Related information: Terms of Service · AI OS.