Privacy Policy
How we collect, use, and protect your information
1. Introduction & Overview
This Privacy Policy describes how NovoAIGen LLC ("Company," "we," "us," or "our"), a limited liability company incorporated in the State of Georgia, USA, and located in Suwanee, Georgia, collects, uses, discloses, and protects information through the Sappi platform (accessible at https://sappiai.com) and related services.
Sappi is a multi-channel, AI-powered customer communication SaaS platform that centralizes communications across WhatsApp, email, phone calls, and social media platforms. It provides sentiment analysis, CRM integration, lead management, and intelligent data processing.
Throughout this Privacy Policy, the following terms apply:
- "User" refers to Sappi's client — the business or individual subscribing to and using the Sappi platform.
- "Contact" refers to a User's client — the end-consumer or customer who interacts with the User through communication channels managed via Sappi (e.g., WhatsApp, email, phone, Facebook Messenger, Instagram).
By accessing or using Sappi, you agree to the collection and use of information in accordance with this Privacy Policy. If you do not agree with this policy, please do not use our services.
2. Information We Collect
2.1 Information from Users (Our Clients)
- Account registration data: Name, email address, company name, and billing information provided during sign-up and account management.
- Payment and billing information: Payment details processed via third-party payment processors (e.g., Stripe). We do not store full credit card numbers on our servers.
- Usage data and analytics: Information about how you use the Sappi platform, including features accessed, actions performed, and usage patterns.
- Integration credentials: API keys, access tokens, and authentication credentials for third-party services you connect (e.g., Meta/WhatsApp Business API, Facebook, Instagram, CRM systems). These tokens are encrypted at rest using AES-256-GCM encryption.
- Business configuration data: Business profile information, AI tone preferences, knowledge base documents, and other configuration settings you provide.
2.2 Information from Contacts (Users' Clients)
We process the following data on behalf of our Users in connection with communications managed through the Sappi platform:
- Communication data: Messages, call recordings and transcripts, and email content processed through the platform on behalf of Users.
- Contact information: Name, phone number, email address, and other identifiers provided by Users or collected through integrated channels.
- Sentiment analysis data: Insights and classifications derived from communications through AI processing.
- Metadata: Timestamps, message delivery status, channel source identifiers, and other technical metadata associated with communications.
2.3 Automatically Collected Information
- Device and browser information: IP address, browser type and version, operating system, and device identifiers.
- Cookies and similar technologies: Information collected through cookies, web beacons, and similar tracking technologies (see Section 12).
- Log data: Server logs, error reports, and usage patterns collected automatically when you access the platform.
3. How We Use Information
We use the information we collect for the following purposes:
- Providing and maintaining services: To operate, deliver, and improve the Sappi platform and its features.
- Processing communications: To facilitate and manage multi-channel communications (WhatsApp, email, phone, social media) on behalf of Users.
- AI-powered analysis: To perform sentiment analysis, reply to messages and answer phone calls on Users' behalf, automate workflows, and provide lead scoring as part of the Sappi service.
- Payment processing: To process payments, manage subscriptions, and handle billing-related communications.
- Account communications: To send Users service-related notices, updates, security alerts, and support messages.
- Advertising measurement: To measure how well our own advertising on Meta platforms works (see Section 12).
- Legal compliance: To comply with applicable laws, regulations, legal processes, or governmental requests.
- Security and fraud prevention: To detect, investigate, and prevent fraudulent activities, unauthorized access, and other harmful actions.
4. Data Processing Role Clarification
Understanding how data responsibilities are divided is important for transparency:
- NovoAIGen as Data Processor: With respect to Contact data (communications, contact information, sentiment data), NovoAIGen acts as a data processor on behalf of Users. We process this data solely according to Users' instructions and to provide the Sappi service.
- Users as Data Controllers: Users are the data controllers for their Contacts' data. Users are responsible for determining the purposes and means of processing Contact data and for obtaining appropriate consents from their Contacts.
- NovoAIGen as Data Controller: With respect to User account data (registration information, billing, usage analytics), NovoAIGen acts as the data controller.
Users are responsible for ensuring they have the appropriate legal basis (including consent where required) to collect and share Contact data through the Sappi platform.
5. AI and Automated Processing
Sappi uses artificial intelligence and machine learning technologies to provide its core features. This includes:
- Sentiment analysis: AI models analyze communication content to determine sentiment and emotional tone.
- Automated replies: AI replies to Contacts' messages on the channels a User connects, using the business information the User provides, and can book appointments.
- AI phone calls: An AI voice agent answers inbound calls to a User's Sappi phone number, and can answer questions and book appointments.
- Automated workflows: AI-powered automation for routing, categorizing, and prioritizing communications.
- Lead scoring: AI-based analysis to help Users prioritize leads and opportunities.
Important: AI processing is performed solely to deliver the Sappi service features requested by Users. We do not use Contact data to train general-purpose AI models without explicit consent.
Automated responses. Replies and calls are handled automatically; no person reviews each AI response before it is sent. Users control whether the AI responds: they can turn it off for a channel or for all channels, pause it on an individual conversation, and pause a phone agent. The AI also pauses a conversation by itself in some cases, for example when a Contact asks to speak with a person.
Call recording and transcription. Calls answered by Sappi's AI are recorded and transcribed, and a summary and analysis of each call are generated. Our voice provider, Retell AI, stores the recordings and transcripts; Sappi stores the transcript, the summary and analysis, and a link to the recording, which the User can open in the Sappi dashboard. No automatic deletion period is currently set for recordings and transcripts, so they are kept until deleted (see Sections 7 and 11).
Sappi's default call greeting does not tell callers that the call is recorded. The User, as data controller, is responsible for giving callers any notice, and obtaining any consent, that applicable law requires for call recording and for speaking with an AI, for example in the agent's greeting, which the User can edit. If a caller asks, the agent confirms that it is a virtual assistant.
6. Third-Party Services & Data Sharing
We may share information with the following categories of third-party service providers to operate and improve Sappi:
- Meta Platforms: WhatsApp Business API, Facebook Messenger, and Instagram integrations for processing communications on behalf of Users.
- Voice providers: Retell AI, which runs the AI voice agent (speech recognition, voice, and call analysis) and stores call recordings and transcripts; and Twilio, which provides phone numbers and connects calls, and receives the business address a User provides for number registration and emergency calling.
- Advertising: Meta Platforms, through the Meta Pixel and the Meta Conversions API, to measure our own advertising (see Section 12).
- Payment processors: Third-party payment services (e.g., Stripe) for processing subscription payments and billing.
- Cloud infrastructure providers: Hosting, database, and storage services that power the Sappi platform.
- AI/ML service providers: Third-party AI services (e.g., OpenAI) used to power sentiment analysis, response generation, and other AI features.
- Analytics providers: Services that help us understand platform usage and improve performance.
We do not sell personal data to third parties. We share data with third parties only as necessary to provide the Sappi service, comply with legal obligations, or protect our rights.
7. Data Retention
We retain data according to the following principles:
- Communication data: Retained while the User's account exists. No automatic deletion period currently applies, including to call recordings and transcripts. Data is deleted when the User requests it (see Section 11).
- Account data: Retained while the User's account exists, including after a subscription ends, until the User requests deletion (see Section 11).
- Usage and analytics data: Retained in anonymized or aggregated form for service improvement purposes.
- Payment records: Retained as required by applicable tax and accounting laws.
- Integration tokens: Deleted upon disconnection of the respective third-party integration or account closure.
- Disconnected channels: Disconnecting a channel stops new messages from arriving through it and deletes its access token and connection details. Contacts and conversations already received stay in the account. The same happens to every channel when a subscription ends, and the account's Sappi phone numbers are released.
Sappi does not currently offer retention settings or automatic deletion periods within the platform. To have data deleted, follow the process in Section 11.
8. Data Security
We implement appropriate technical and organizational measures to protect the information we process:
- Encryption in transit: All data transmitted between your browser and our servers is encrypted using TLS/SSL protocols.
- Encryption at rest: Sensitive data, including integration tokens and credentials, is encrypted at rest using AES-256-GCM encryption.
- Access controls: Role-based access controls and authentication mechanisms restrict access to data on a need-to-know basis.
- Security assessments: Regular security reviews and vulnerability assessments to identify and address potential risks.
- Incident response: Established procedures for detecting, responding to, and recovering from security incidents, including notification procedures as required by law.
While we strive to use commercially reasonable means to protect your information, no method of transmission over the Internet or method of electronic storage is 100% secure. We cannot guarantee absolute security.
9. International Data Transfers
Sappi is operated from the United States. If you access Sappi from outside the United States, please be aware that your information may be transferred to, stored, and processed in the United States and other countries where our service providers operate.
We take appropriate safeguards to ensure that international data transfers comply with applicable laws, including:
- Implementing standard contractual clauses or equivalent mechanisms where required.
- Ensuring our sub-processors maintain appropriate data protection standards.
- Complying with applicable cross-border data transfer requirements under U.S. federal and state laws, as well as Mexico's LFPDPPP where applicable.
10. Your Rights
10.1 Rights for All Users and Contacts
Regardless of your location, you may have the right to:
- Access: Request a copy of the personal data we hold about you.
- Correction: Request correction of inaccurate or incomplete data.
- Deletion: Request deletion of your personal data (see Section 11).
- Data portability: Request your data in a structured, commonly used format.
10.2 CCPA/CPRA Rights (California Residents)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA):
- Right to know: The categories and specific pieces of personal information we collect about you.
- Right to delete: Request deletion of personal information we have collected.
- Right to opt-out: Opt out of the "sale" or "sharing" of personal information. Note: We do not sell personal information.
- Right to non-discrimination: We will not discriminate against you for exercising your privacy rights.
10.3 ARCO Rights (Mexico — LFPDPPP)
If you are located in Mexico, you have ARCO rights under the Federal Law on Protection of Personal Data Held by Private Parties (LFPDPPP):
- Access (Acceso): Right to access your personal data held by us.
- Rectification (Rectificación): Right to correct inaccurate or incomplete data.
- Cancellation (Cancelación): Right to request deletion of your data.
- Opposition (Oposición): Right to oppose the processing of your personal data for specific purposes.
To exercise any of these rights, please contact us using the information provided in Section 16.
11. Data Deletion
We provide multiple ways to request deletion of personal data:
11.1 For Users (Sappi Clients)
Users may request deletion of their account and all associated data by emailing us at privacy@sappiai.com from the email address associated with their account. Account deletion is not currently available as a self-service option in the platform; our team processes each request. What deletion covers, and what may be retained, is described on our Data Deletion Instructions page.
11.2 For Contacts (Users' Clients)
Contacts should first reach out to the User (business) they communicated with to request data deletion. If unable to reach the User, Contacts may contact us directly at privacy@sappiai.com, and we will facilitate the deletion request.
11.3 Meta Platform Data
If you interacted with a service via Facebook, Instagram, or WhatsApp that uses Sappi, you may also request deletion of data obtained through these Meta integrations. Please refer to our dedicated Data Deletion Instructions page for detailed steps and timelines.
11.4 Deletion Timeline
We will acknowledge deletion requests within 5 business days and complete deletion within 30 days. Certain data may be retained as required by law (see Section 7).
13. Children's Privacy
Sappi is not intended for use by individuals under 18 years of age. We do not knowingly collect personal information from children under 18. If we become aware that we have collected personal information from a child under 18, we will take steps to promptly delete such information. If you believe we have inadvertently collected data from a child, please contact us at privacy@sappiai.com.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify Users by email and/or by posting a prominent notice on the Sappi platform. The "Last Updated" date at the bottom of this page indicates when this policy was most recently revised.
Your continued use of Sappi after the effective date of any changes constitutes your acceptance of the revised Privacy Policy.
15. Google User Data & Limited Use
When you connect Google Calendar, Sappi accesses certain Google user data through Google APIs to provide features you explicitly enable. This section describes that access and our commitment to Google's Limited Use requirements.
Google data we access:
- Google Calendar: we read your calendars and create, update, and cancel events to keep your appointments in sync (scope:
calendar). - Account email: we read your Google account email address to identify the connected account (scope:
userinfo.email).
We use Google user data solely to provide and improve the user-facing features you request: managing calendar appointments. Tokens are stored encrypted at rest and are deleted when you disconnect the integration.
Limited Use commitment. Sappi's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- We only use Google user data to provide or improve user-facing features that are prominent in the Sappi interface.
- We only transfer Google user data as necessary to provide or improve those features, to comply with applicable law, or as part of a merger or acquisition with prior notice to users.
- We do not use Google user data for serving advertisements.
- We do not allow humans to read Google user data unless (a) you give explicit consent for specific messages, (b) it is necessary for security purposes or to comply with applicable law, or (c) the data has been aggregated and anonymized.
- We do not use Google user data to develop, improve, or train generalized or non-personalized artificial intelligence or machine learning models. AI features process your data only to generate the specific output you requested, for your account.
16. Contact Information
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
- Company: NovoAIGen LLC
- Location: Suwanee, Georgia, USA
- Privacy inquiries: privacy@sappiai.com
- General inquiries: contact@novoaigen.com
- Website: https://novoaigen.com
Last updated: