Privacy
EIIƎ is operated by IPGN Solutions (a trading name of Nirst Ltd, registered in Scotland under company number SC710095, with registered office at 4 Rubislaw Terrace, Aberdeen, AB10 1XE, United Kingdom) ("we", "us", or "our"). We are the controllers of any personal data collected and processed in relation to the EIIƎ platform and the services we provide. The privacy and security of your data is of utmost importance to us. Please review this Privacy Policy to understand how we handle your information. By using or accessing our Services, you acknowledge and accept the practices described below. You consent to our collection, use, and sharing of your information as described in this Privacy Policy.
Last updated: 2026-10-02
Collection of Information
We collect and process personal data in compliance with applicable data protection laws, including the UK General Data Protection Regulation (UK GDPR) and the EU GDPR.
Account and profile data
When you sign up for EIIƎ we collect:
- First name and last name
- Email address
- Profile information (name and profile picture, where supplied via your authentication provider)
- Password (stored only as a one-way hash) or, where you sign in with a third-party identity provider (Google or Microsoft), authentication tokens issued by that provider
- Contact information you provide
Your account is associated with an organisation. Your organisation administrator may also see your name and email address as part of user management.
Email Integration Data
When you connect your email account (Google Gmail or Microsoft) to EIIƎ, we access:
- Your email messages and settings (including filters and labels)
- Your primary email address
- Your profile information (name and profile picture)
- Additional profile data provided by the authentication provider (such as gender and language preferences, which we do not store or use)
CRM content
When you use EIIƎ you provide content, including:
- Customer, business, contact, and location records
- Enquiries, proposals, orders, requests, and reminders
- Survey templates (your custom forms, including questions, field types, and instructions)
- Survey responses captured during a session (text input, voice-derived text, photos, signatures, notes)
- News articles, internal notifications, and feedback
You retain ownership of this content. We process it solely to provide the platform and services to you.
Deleting a survey session
You can delete a survey session from its page in the platform. A session that isn't complete can be deleted by the person it's assigned to. A completed session can be deleted only by someone your organisation has given the Delete Completed Surveys role, who must type the survey's title to confirm. A deleted session disappears from the platform at once. A phone that already holds a copy can no longer save changes to it or send it back. We keep it for 30 days in case it was deleted by mistake; within that time you can ask us to restore it. After 30 days it's removed for good, with its photos, signatures, sheets, voice recordings, transcripts, findings and stored reports. It leaves our database backups 31 days after that.
Voice and audio data
When you choose to use the voice-driven survey mode, your speech is recorded in real-time and converted to text by a third-party speech-to-text service (Soniox). Real-time audio is streamed directly to the speech-to-text provider and is not stored by default. Soniox does not retain audio after processing and does not use your data to train its models.
If your organisation's administrator has enabled the optional voice audio log, the platform additionally stores per-utterance audio clips and transcripts for up to 14 days. The audio log is disabled by default and is only available where an organisation administrator opts in. When enabled, you are shown a consent disclosure before voice mode begins. You can withdraw consent at any time by declining the consent prompt or by switching to manual text entry.
Audio log recordings are stored on AWS S3 in the eu-central-1 region (Frankfurt, Germany) and are automatically deleted by S3 lifecycle rule after 14 days. Transcripts and AI extraction metadata associated with utterances are kept with the survey session. They are removed when the session is reset or deleted (see "Deleting a survey session"), and you can delete the stored audio for an individual session at any time from the session audit page within the platform.
When you record a voice note against a contact record, the audio file is uploaded to AWS S3 (eu-central-1, Frankfurt) and is automatically deleted after 30 days. The audio is transcribed using Mistral AI (Voxtral Mini), a third-party AI service based in the EU. Transcriptions derived from voice notes are kept as part of the contact record. Deleting the voice note removes its transcript and audio, and deleting the contact removes all of its voice notes. You can also ask us to erase them.
Voice features are entirely optional. You may always use manual text entry instead. Your voice data is not used to identify who you are, and never to log you in.
Telling voices apart during a survey
When the start-phrase feature is enabled, the app distinguishes your voice from other voices within earshot, so that speech from bystanders is not written into your survey as if you had said it. To do this the app keeps about 1.5 seconds of you saying the start phrase. That recording stays on your device and is never stored by us or by any third party. Each time the survey reconnects, it is played to the speech-to-text service together with your live speech, and the service does not retain it. It is deleted when the survey is completed, archived or reset — or after 7 days if the survey is abandoned. It is used only to match your voice within that one survey, and never to identify you as a person or to authenticate you. No voiceprint is created: the recording is ordinary audio, and the speech-to-text service simply groups it with your live speech under a temporary label that is discarded when the connection closes.
Photos and media
Where you capture photographs as part of a survey session, the image files are uploaded to AWS S3 in the eu-central-1 region (Frankfurt, Germany). Images are linked to the survey session, group instance, or field that they were captured against, and are kept with the survey session. Resetting a session removes its photos, and deleting a session removes them with it (see "Deleting a survey session").
Signatures
Where a survey field requests a signature, the signature is captured on-screen and stored as a small image embedded directly in the survey session record. Signatures evidence acceptance or sign-off of a completed report and are not used for biometric identification or authentication. Signatures are removed when the session is reset or deleted, or on request.
Generated reports (PDFs)
Survey reports and other PDF and Word outputs are generated from your data when you request them. The generated file is stored on AWS S3 in the eu-central-1 region (Frankfurt, Germany) so that it can be downloaded again and shared without regenerating it. Report previews are deleted automatically after 7 days. Stored reports are kept with their survey session and removed when it is deleted (see "Deleting a survey session"), or sooner if you ask us.
Usage data
We collect operational telemetry that helps us run and improve the service:
- Application logs (timestamps, route paths, user identifier, error messages)
- Authentication events (sign-in attempts, session creation)
- Service usage metrics (number of surveys started, messages exchanged with the voice assistant, sub-processor invocations for cost management)
- Device and browser information that you submit by virtue of using the application
Cookies
We use both session cookies, which expire after you close your browser, and persistent cookies, which remain on your device until they expire or you delete them. We use cookies to authenticate you, remember your preferences, and analyse your usage of our services. You can control the use of cookies through your browser settings. However, please note that disabling cookies may limit your ability to use certain features.
Use of Information
The information collected is used for the purpose of providing and improving the platform. We may use your personal data to:
- Provide the platform and its features
- Authenticate you and protect the security of your account
- Process voice input and other AI-assisted input you have consented to use
- Generate reports, exports, and customer-facing communications from your data
- Communicate with you about service availability, important changes, security notices, and (with your consent) product updates
- Analyse aggregated usage trends to improve the platform
- Enforce our Terms and comply with our legal obligations
Lawful Bases for Processing
| Processing activity | Lawful basis (UK GDPR Art. 6) |
|---|---|
| Account creation and authentication | (b) Performance of a contract |
| Storing and processing CRM content (contacts, enquiries, surveys) | (b) Performance of a contract |
| Email integration (Gmail / Microsoft connection) | (b) Performance of a contract |
| Voice recording and transcription (real-time) | (a) Consent — voice mode is optional |
| Voice audio log (when organisation has opted in) | (a) Consent — admin-enabled, per-user disclosure |
| Voice notes against contact records | (a) Consent — voice notes are optional |
| Telling your voice apart from others during a survey (start phrase) | (a) Consent — the feature is optional |
| Separating bystander speech so it is not recorded as yours | (f) Legitimate interest — to keep other people's words out of your survey |
| AI processing of survey input | (b) Performance of a contract |
| AI Template Builder processing of uploaded documents | (b) Performance of a contract |
| AI processing of email signatures (contact extraction) | (b) Performance of a contract |
| HAMI Help Assistant | (f) Legitimate interest |
| WhatsApp Business Platform integration | (b) Performance of a contract (Customer warrants opt-in) |
| Service emails (security, account, billing) | (b) Performance of a contract |
| Marketing communications | (a) Consent (opt-in, opt-out at any time) |
| Aggregated analytics and service improvement | (f) Legitimate interest |
Data Sharing and Disclosure
We are committed to safeguarding your personal data and ensuring transparency in our data practices.
Email Provider Data Handling
We do not share, transfer, or disclose email provider data (Google or Microsoft) to third parties for purposes other than providing our services to you. Your email account information (including messages, settings, profile information, and email address) is used solely within the EIIƎ application to provide email integration features.
Where a user-facing feature requires it, the minimum necessary email-derived content may be processed by an AI sub-processor acting on our behalf to deliver that feature — for example, the "Add as EIIƎ Contact" feature sends only the sender's parsed signature text (not the full message body) to an AI model to extract contact details (see "Email Contact Extraction" below). Such processing is solely to provide the feature, the data is not retained by the sub-processor after processing, and it is not used to train any AI or machine learning model.
The only exceptions are:
- Our infrastructure and service providers (listed in the "Third-Party Service Providers" section below) who process data solely as part of providing our services
- When required by law or legal process
- With your explicit consent
Voice and AI-Assisted Features
The platform includes AI-powered features that process your input using third-party AI services:
- Survey Voice Assistant — Your transcribed speech (not raw audio) is sent to an AI model to interpret your responses and populate survey fields. The model processes your input in real time. The default provider, xAI, keeps nothing after responding (zero data retention). Some alternate providers may keep inputs for up to 30 days for abuse monitoring; none use them for model training. The default AI provider is xAI Grok, called through its EU endpoint (eu-west-1); xAI is a US company (see "International Transfers"). Alternative providers (Google Cloud Vertex AI Gemini in Belgium, OpenAI, Mistral AI in Paris, AWS Bedrock Claude Haiku in eu-central-1) may be configured by us as alternates.
- AI Template Builder — When you upload a source document (PDF or image of a form) for conversion into an EIIƎ survey template, the document is sent to an AI model for analysis. The default provider for image-based forms is xAI Grok; the default provider for PDF analysis is Anthropic Claude Haiku, accessed via AWS Bedrock in the eu-central-1 region. Uploaded source documents are stored in our S3 bucket and deleted automatically 7 days after the template build completes or is abandoned, or 30 days after a build that was left in progress. Deleting a template does not remove its source documents sooner.
- HAMI Help Assistant — When you use the in-app help assistant, your text queries and the assistant's responses are processed by an AI model hosted on Google Cloud (Vertex AI, Belgium). Conversation history is stored in our database to provide continuity across sessions and is automatically deleted after 6 months. You can also delete your whole conversation history at any time from the HAMI assistant interface.
- Email Contact Extraction — When you use "Add as EIIƎ Contact" on an email, the sender's parsed signature text is sent to an AI model to extract structured contact details (such as name, business name, address, and phone number). We send only the parsed signature portion, not the full message body. The model processes the text in real-time and does not retain it after generating a response. The provider is Anthropic Claude Haiku, accessed via AWS Bedrock in the eu-central-1 region (Frankfurt, Germany).
We use AI-assisted features on the basis of contract performance (delivering the service you have signed up for) and, for voice and voice notes, consent. You are informed when interacting with an AI-powered feature.
We do not use customer data to train any AI models, and our AI sub-processors have committed not to use your data for their own model training.
Cloud Text-to-Speech
In speaker mode of the survey voice assistant, the AI assistant's text replies are converted to spoken audio using Amazon Polly Neural Text-to-Speech in the eu-central-1 region. Only the assistant's reply text is sent to Polly; your voice input is never sent to Polly. Headset mode uses on-device text-to-speech and does not call any cloud TTS service.
Third-Party Service Providers (Sub-Processors)
We use the following third-party services to deliver the platform. Each acts as a data processor on our behalf under appropriate data processing agreements.
| Provider | Purpose | Data processed | Data location |
|---|---|---|---|
| Vercel | Web application hosting | Application data, request logs | EU region; Vercel Inc. is a US company (see "International Transfers") |
| Neon | PostgreSQL database services | All stored personal data | EU region; Neon is part of Databricks, Inc., a US company (see "International Transfers") |
| AWS (S3) | File storage (voice notes, voice audio log, photos, uploads, AI Template Builder source documents) | Audio files, image files, document uploads | Frankfurt, Germany (eu-central-1) |
| AWS (Bedrock) | AI inference (survey assistant alternate, AI Template Builder PDF analysis, email contact extraction) | Text prompts, transcribed speech, uploaded PDF documents, email signature text | Frankfurt, Germany (eu-central-1) |
| AWS (Polly) | Text-to-speech synthesis (speaker mode of survey voice assistant) | AI assistant reply text | Frankfurt, Germany (eu-central-1) |
| Soniox | Real-time speech-to-text transcription | Audio streams (real-time, zero retention) | EU processing endpoint; Soniox is a US company (see "International Transfers") |
| Mistral AI | Voice note transcription (Voxtral Mini); AI inference (alternate provider) | Audio files, text prompts | EU (Paris, France) |
| Google Cloud (Vertex AI) | AI inference (HAMI Help Assistant; survey assistant alternate) | Text prompts, transcribed speech | Belgium (EU) |
| OpenAI | AI inference (alternate survey assistant provider) | Text prompts, transcribed speech | OpenAI OpCo, LLC (US) for UK customers; OpenAI Ireland Ltd for EEA customers (see "International Transfers") |
| xAI | AI inference (default survey assistant; AI Template Builder image analysis) | Text prompts, transcribed speech, image content of uploaded forms | EU endpoint (eu-west-1); xAI is a US company (see "International Transfers") |
| Resend | Transactional email delivery (account, password reset, service notices) | Email address, message content | United States (see "International Transfers") |
| Meta Platforms Ireland Ltd (WhatsApp Business Platform) | Sending and receiving WhatsApp messages with your customers, where your organisation has connected a WhatsApp Business account | Phone numbers, message content, contact names | Meta's global infrastructure (EU and United States), under Meta's WhatsApp Business data processing terms (see "International Transfers") |
These providers process your data solely for the purpose of delivering the relevant feature and do not use your data for their own purposes, including model training.
International Transfers
Several of the sub-processors listed above are US companies, even where they process your data on servers in the EU: Vercel, Neon (part of Databricks), Resend, Soniox, xAI and, where configured, OpenAI. Your stored data, audio and transcripts are processed in EU regions wherever the provider offers one; Resend stores email data in the United States. Meta's WhatsApp Business Platform runs on Meta's global infrastructure. These transfers take place under the EU-U.S. Data Privacy Framework and its UK Extension (Vercel, Neon, Resend), or under the EU Standard Contractual Clauses with the UK Addendum or UK International Data Transfer Agreement (Soniox, xAI, OpenAI), or an equivalent transfer mechanism (Meta). AWS, Google Cloud and Mistral AI contract with us through European companies. We do not transfer your personal data outside the UK or EEA without such a mechanism in place.
Security of Your Data
We implement comprehensive security measures to protect your personal data, including data from email providers (Google and Microsoft):
- All data transmissions between your device and our servers are encrypted using SSL/TLS
- Access to EIIƎ is restricted to users authenticated through trusted providers (Microsoft or Google) and authorised by your organisation administrator
- We follow industry best practices for securing web and mobile applications
- We conduct regular security audits of our systems
- Your data is stored in secure database infrastructure with encryption at rest
- We limit access to your email provider data and other personal data to authorised personnel who need it to provide and improve our services
- We use secure authentication tokens and never store your account passwords in cleartext
Data Retention
We retain different types of data for different periods:
| Data type | Retention period |
|---|---|
| Account and profile data | Duration of your account, plus any legal retention period |
| CRM content (contacts, enquiries, surveys) | Until deleted by your organisation |
| Survey photos | Kept with the session; removed when the session is reset or deleted, or on request |
| Signatures | Kept with the session; removed when the session is reset or deleted, or on request |
| Deleted survey sessions | Removed for good 30 days after the delete, with all their files; out of database backups 31 days after that |
| Voice note audio files | 30 days (automatically deleted) |
| Voice note transcriptions | Until the voice note or its contact is deleted, or on request |
| Voice audio log recordings (when organisation has opted in) | 14 days (auto-deleted by S3 lifecycle rule) |
| Voice audio log transcripts and AI extraction metadata | Kept with the session; removed when the session is reset or deleted, from the session audit page, or on request |
| Generated reports (PDF and Word) | Kept with the session; removed when the session is deleted, or on request; previews 7 days |
| AI Template Builder source documents | 7 days after the build completes or is abandoned; 30 days if left in progress |
| HAMI Help Assistant conversations | 6 months (automated cleanup); you can delete your whole history at any time |
| Application logs and telemetry | Up to 30 days (mobile app logs: 7–14 days) |
| Internal audit, change, and activity logs | 18 months (security and privileged-action audit logs: 2 years) |
| Database backups | 30 days |
| Files stored for your organisation (photos, reports, uploads) after its account closes | Deleted automatically when the closure is final (7 days after it closes, unless agreed otherwise) |
Your Rights
Under data protection law you have the following rights in respect of your personal data:
- Right of access — to obtain a copy of the personal data we hold about you
- Right of rectification — to correct inaccurate or incomplete data
- Right of erasure — to request deletion of your data, subject to any overriding legal obligations on us
- Right to restriction of processing — in certain circumstances
- Right to data portability — to receive your data in a structured, commonly used, machine-readable format
- Right to object — to processing carried out on the basis of legitimate interest, including direct marketing
- Right to withdraw consent — at any time, where processing is based on consent (this does not affect the lawfulness of processing carried out before withdrawal)
- Right to lodge a complaint with a supervisory authority — in the UK, the Information Commissioner's Office (ico.org.uk)
For voice audio log recordings specifically, you can exercise your right to erasure on a per-session basis directly from the session audit page in the platform; deletion removes the audio from S3 storage and marks the database record as deleted while retaining the survey session itself.
To request deletion of specific data without closing your account, email us at support@e2e-ipgn.com describing the data you would like removed (for example, a particular contact record, survey session, voice note, voice audio log recording, stored report, or uploaded template source document). We will action your request within 30 days, except where we have an overriding legal obligation to retain the data (for example, records required for tax, audit, or regulatory purposes).
In order to process any of these requests we may need to verify your identity for your security. If you choose to have specific account or contact data erased, you may no longer be able to use our services. To exercise any of these rights, contact us at support@e2e-ipgn.com.
Aggregated and Anonymised Data
We may compile usage statistics and other aggregated data based on platform activity. Such data is aggregated and anonymised so that it does not identify any User, Customer, or their confidential information.
Marketing Communications
We will only send you marketing communications about EIIƎ with your consent. You can withdraw consent at any time by clicking the unsubscribe link in any marketing email or by contacting us at support@e2e-ipgn.com. Withdrawing consent for marketing does not affect service emails (account notices, security alerts, billing).
Children's Use
EIIƎ is intended for use by professionals in a business context. The platform is not directed at children, and we do not knowingly collect personal data from anyone under the age of 16. If you believe we have inadvertently collected such data, please contact us so we can delete it.
Changes to this Privacy Statement
We reserve the right to update or change this Privacy Policy at any time. We will post any changes on this page with a revised "Last updated" date. Material changes will be communicated to existing users by email or in-app notice.
Contact Us
If you have any questions or concerns about this Privacy Policy or our data practices, please contact us at support@e2e-ipgn.com.
For postal correspondence:
IPGN Solutions (a trading name of Nirst Ltd) 4 Rubislaw Terrace Aberdeen, AB10 1XE United Kingdom