Privacy Policy

Privacy Policy

This Privacy Policy explains how Raisi, Inc. (“Raisi,” “we,” “us,” or “our”) collects, uses, discloses, and retains personal information in connection with its small-business AI-agent product, related websites that link to this Policy, and associated support and implementation services.

It applies to website visitors, prospective customers, account holders, authorized users, and individuals whose information is processed through these Services.

Other Raisi products may have separate notices. This Policy does not automatically apply to an independent fundraising, investment, acquisition, or business-sale engagement.

1. Our role

For information used to manage our website, customer relationships, accounts, billing, security, and our own business communications, Raisi generally determines the purposes and means of processing.

When a business customer provides personal information for a workflow and we process it solely on that customer’s instructions, we act on its behalf as a processor or service provider, where those terms apply.

For example, a customer may authorize Raisi to organize business contacts, prepare customer messages, or coordinate onboarding tasks. The customer determines the intended use and is responsible for its own privacy notices and lawful instructions.

If your information was provided by a business using Raisi, that business’s privacy policy also applies. Requests concerning information we process solely on its behalf may need to be directed to that business.

A customer agreement does not remove responsibilities that independently apply to Raisi.

2. Information we collect

The information collected depends on how you interact with the Services, which features you use, and which systems you connect.

Account and contact information

We collect information provided when you request a demo, contact us, create an account, or purchase Services. This may include your name, business email, telephone number, company name, role, billing address, and account preferences.

Business information

You may provide your website, industry, services, service area, target customers, goals, marketing materials, and descriptions of how your business operates.

Business information may also contain personal information, particularly for sole proprietors or documents identifying employees and customers.

Customer Content

We process materials you submit or authorize us to access. Depending on the workflow, these may include customer records, contact lists, emails, attachments, estimates, proposals, meeting notes, documents, task records, and other business materials.

We also process your instructions, generated outputs, edits, approvals, and feedback.

Connected-account information

When you enable a supported connection, we receive the information needed for that connection and the permissions you grant. This can include account identifiers, authorization tokens, relevant records, and connection-status information.

The information accessible through a connection depends on its permissions. Connecting a tool does not mean that every record available in that tool is necessary for every workflow.

Usage and technical information

We collect information about access to and use of the Services, such as IP address, browser and device information, approximate location inferred from IP address, pages visited, feature interactions, timestamps, diagnostic records, and security logs.

Where enabled and lawfully configured, communication workflows may process delivery, response, opening, or clicking information. The availability and accuracy of those signals can vary.

Billing information

Payment information is processed through the payment provider identified at checkout. We receive information needed to manage the transaction, such as payment status, subscription details, billing contact information, and relevant transaction identifiers.

Information from other sources

Where a requested feature involves research, we may obtain relevant business or professional information from public websites, customer-authorized sources, or licensed data providers.

We may also receive information from another authorized user in your organization or from someone who refers you to Raisi.

3. Why we use information

We use personal information to provide the features you request, operate accounts, maintain business context, generate outputs, carry out authorized workflows, and provide support.

For our own operations, we use relevant account and usage information to manage billing, understand product use, troubleshoot errors, detect misuse, protect systems, and meet legal obligations.

We may contact you about your account, requested services, product changes, and relevant Raisi offerings, subject to applicable marketing requirements and your choices.

We do not treat permission to connect an account as unrestricted permission to use its contents for unrelated research, advertising, or other products.

Where we process Customer Content on behalf of a business, our use is subject to that customer’s instructions and the applicable agreement.

4. AI processing and personalization

The Services use AI systems to interpret instructions, retrieve relevant information, generate recommendations, prepare materials, and support configured workflows.

Depending on the feature, relevant prompts, documents, messages, or portions of connected records may be transmitted to AI-model providers or supporting infrastructure providers.

Personalization may involve storing a business profile, prior instructions, workflow history, summaries, or searchable representations of business information. Using that information to produce a response for your account is different from using it to train a general-purpose AI model.

AI-model training and evaluation:
[INSERT THE VERIFIED PRACTICE: state whether Raisi or any provider uses Customer Content, connected-account data, outputs, logs, or derived information for general-model training or evaluation. Explain any separate permission, exclusions, and controls. Do not publish a “no training” promise without verifying provider terms and production settings.]

AI providers and processing locations:
[INSERT THE CURRENT AI-PROVIDER/SUBPROCESSOR LIST OR A LINK TO A MAINTAINED NOTICE, INCLUDING RELEVANT RETENTION AND PROCESSING-LOCATION INFORMATION.]

Authorized personnel may access relevant information to provide requested support, investigate an error, address security incidents, or meet legal obligations. Access must be limited to the relevant purpose and applicable contractual requirements.

5. Connected tools and your instructions

We use connected-account information to provide the features you enable and actions you authorize.

For example, a follow-up workflow may require relevant message history and customer information. An onboarding workflow may require specified documents, task records, and appointment information.

You may revoke a connection using available account controls or the connected provider’s permissions settings. Revoking access prevents future access through that connection once effective.

Revocation is separate from deletion. Information already imported, outputs already created, or records retained for permitted purposes may remain until deleted under the applicable retention process.

Actions already completed in another system, including messages sent or records updated, may remain in that system under its own retention practices.

6. Who receives information

We disclose personal information only for the purposes described in this Policy and subject to applicable agreements and law.

Service providers. Providers may process information to support hosting, storage, authentication, AI inference, integrations, communications, payments, analytics, security, and customer support. The information shared must be appropriate to the service being provided.

Your organization. Authorized users and administrators may access information within your business account according to the workspace’s permissions and the organization’s instructions.

Recipients and tools you authorize. When you approve a message, share a document, or enable a workflow, information may be delivered to the intended recipient or connected service.

Advisers and legal authorities. We may disclose information where reasonably necessary for professional advice, compliance with law, response to valid legal process, prevention of fraud, or protection of legal rights and safety.

Business transactions involving Raisi. Information may be disclosed in connection with a proposed or completed financing, merger, acquisition, or transfer of Raisi’s business, subject to appropriate confidentiality protections and applicable privacy requirements.

Other disclosures. We may share information when you separately direct or authorize us to do so.

7. Customer contacts and confidential business information

Uploading a customer list does not make that list available to other Raisi customers or authorize us to independently market to the people on it.

We use customer-provided contact information for the customer’s authorized Services and applicable contractual purposes. We do not use one customer’s confidential contact list to supplement another customer’s database.

Raisi may separately hold information about the same contact from a genuinely independent, lawful source. A source is not independent merely because customer-provided information was used as a lead or starting point to obtain the same contact elsewhere.

Any Customer Contact Data Protection Addendum agreed with your business applies to the information it covers.

Using the small-business AI-agent product does not authorize us to list your business for sale or share your nonpublic business materials with investors, acquisition buyers, community members, or unrelated customers. Such activities require a separately described service and appropriate authorization.

8. Cookies, analytics, and advertising

Our websites and applications use cookies and similar technologies for functions such as maintaining sessions, remembering preferences, supporting security, and measuring use.

Current analytics and advertising technologies:
[INSERT THE ACTUAL TOOLS AND PURPOSES USED ON THIS PRODUCT’S WEBSITE AND APPLICATION. IDENTIFY ANY ADVERTISING PIXELS, AUDIENCE-MATCHING TOOLS, SESSION RECORDING, OR CROSS-SITE TRACKING. REMOVE CATEGORIES THAT ARE NOT USED.]

Where required by law, nonessential technologies are used only after the required consent. Browser controls can limit some cookies, although disabling essential cookies may affect functionality.

Cookie and advertising choices:
[INSERT THE WORKING COOKIE-PREFERENCES OR PRIVACY-CHOICES LINK AND DESCRIBE THE CONTROLS ACTUALLY AVAILABLE.]

Some analytics or advertising disclosures may qualify as a “sale,” “sharing,” or processing for targeted advertising under applicable privacy laws, even when no money changes hands.

Sale, sharing, and targeted-advertising disclosure:
[STATE THE VERIFIED PRACTICE, INCLUDING WHETHER SUCH DISCLOSURES OCCURRED DURING THE PRECEDING 12 MONTHS; THE INFORMATION AND RECIPIENT CATEGORIES INVOLVED; AND THE AVAILABLE OPT-OUT METHOD. IF NONE OCCURRED, STATE THAT ACCURATELY.]

Browser privacy signals:
[STATE HOW THIS WEBSITE HANDLES GLOBAL PRIVACY CONTROL AND OTHER APPLICABLE OPT-OUT SIGNALS, AND ITS RESPONSE TO DO NOT TRACK. CONFIRM THAT THE TECHNICAL IMPLEMENTATION MATCHES THE STATEMENT.]

9. Retention and deletion

We retain personal information only for as long as reasonably necessary for the purpose for which it was collected, subject to applicable contracts and legal requirements.

Account and business-profile information is retained while needed to maintain the account and provide requested Services. Billing records are retained according to applicable accounting and tax requirements. Security and diagnostic records are retained according to their sensitivity and the time reasonably needed to investigate incidents and protect systems.

Following termination and a written request, we will return or delete customer-provided information within 30 days, subject to applicable legal requirements and any governing data-processing agreement.

Deletion must address relevant stored copies and derived account information, such as summaries and search indexes, rather than only removing the original upload.

Backup and provider deletion:
[CONFIRM HOW THE 30-DAY COMMITMENT IS IMPLEMENTED ACROSS ACTIVE SYSTEMS, BACKUPS, LOGS, SEARCH INDEXES, AND PROVIDERS. INSERT ANY NECESSARY, ACCURATE RETENTION DETAILS WITHOUT WEAKENING EXISTING CUSTOMER COMMITMENTS.]

We may retain limited information where needed to comply with law, resolve a dispute, prevent fraud, or honor an opt-out. Retained records remain subject to appropriate restrictions.

Information that has been genuinely de-identified may be retained for permitted analytics purposes, provided it cannot reasonably identify an individual and does not disclose a customer’s confidential business information. We do not attempt to re-identify such information.

10. Security

We use administrative, technical, and organizational safeguards appropriate to the information and processing involved.

Access to personal information is limited to authorized persons and service providers with a relevant need. Security requirements may also be specified in a customer agreement.

No system can guarantee absolute security. If a personal-information incident requires notification, we will provide notice to the affected customer or individuals as required by applicable law and contract.

Specific certifications, hosting arrangements, or security features apply only where expressly documented for the relevant Services.

11. Your rights and choices

Depending on your location and applicable law, you may have rights to access, correct, delete, or obtain a copy of your personal information; restrict or object to processing; withdraw consent; or opt out of certain advertising, sale, sharing, or profiling activities.

Some laws also provide rights concerning sensitive information and automated decisions with significant effects. The availability of these rights depends on the processing involved and whether the applicable law covers it.

To submit a request, contact privacy@raisi.ai. You may also contact info@raisi.ai if you need assistance reaching the appropriate team.

We may request information reasonably necessary to verify your identity or an authorized representative’s authority. We do not require unnecessary information to process a request.

We will respond within applicable legal deadlines and explain any permitted exception. Where applicable, you may appeal a denied request by replying to the decision or emailing privacy@raisi.ai with the subject “Privacy appeal.”

We will not unlawfully discriminate against you for exercising a privacy right.

Marketing messages. Use the unsubscribe mechanism in a marketing email or contact us to stop receiving those messages. Necessary account, billing, and security communications may continue.

Information submitted by a customer. If we process your information solely for a business customer, we may direct your request to that business and assist it as required.

Complaints. You may contact the privacy regulator or other competent authority in your jurisdiction.

12. Additional information for California residents

Where the California Consumer Privacy Act applies, the relevant information categories may include identifiers, account and customer-record information, commercial information, internet activity, approximate geolocation, professional information, correspondence, and inferences.

Some connected-account credentials or contents of private communications may qualify as sensitive personal information.

The collection sources, purposes, and recipient categories are described above. Sale, sharing, and targeted-advertising practices must be identified in Section 8.

We use sensitive information only for disclosed, necessary purposes or with the authorization required by law. Where additional rights to limit its use apply, we will provide the required mechanism.

Historical disclosure check:
[CONFIRM WHICH CATEGORIES WERE ACTUALLY COLLECTED AND DISCLOSED IN THE PRECEDING 12 MONTHS, AND ADD ANY REQUIRED CATEGORY-SPECIFIC DISCLOSURES OR ADDITIONAL REQUEST METHODS.]

California residents may exercise applicable rights through the contact methods in Section 11 and the relevant privacy controls.

13. International users

Personal information may be processed in the United States and other countries where Raisi or its service providers operate.

Where European, UK, Swiss, or other applicable law requires a transfer safeguard, we use the mechanism appropriate to that transfer. Contact privacy@raisi.ai for information about the safeguard applicable to your data.

International transfer details:
[CONFIRM RELEVANT PROCESSING COUNTRIES, TRANSFER MECHANISMS, AND ANY REQUIRED LOCAL REPRESENTATIVE BEFORE PUBLISHING.]

Where a legal basis is required, we rely on the basis appropriate to the purpose: providing a requested contract, meeting a legal obligation, pursuing legitimate interests in operating and securing the Services where those interests are not overridden, or obtaining consent where required.

Consent to optional processing may be withdrawn without affecting the lawfulness of processing that occurred before withdrawal. Use of the Services is not blanket consent to every form of processing or international transfer.

14. Children

The Services are intended for business users aged 18 or older and are not directed to children.

We do not knowingly solicit personal information from children through account registration. Customers should not submit children’s personal information unless the processing has been expressly agreed and all required safeguards and permissions are in place.

Contact privacy@raisi.ai if you believe a child’s information has been provided improperly so we can investigate and take appropriate action.

15. Changes to this Policy

We may update this Policy to reflect changes in the Services, our practices, or applicable requirements.

We will update the date above and provide additional notice when required. If a new use requires consent or other authorization, we will obtain it before beginning that use.

Publishing a revised Policy does not retroactively authorize uses inconsistent with earlier commitments.

16. Contact

Raisi, Inc.
995 Market St
San Francisco, CA 94103
United States

Privacy requests: privacy@raisi.ai
General inquiries: info@raisi.ai