Skip to content

Privacy policy

Last updated Feb 10, 2026

Copilot CX, Inc. (“Copilot,” “we,” “us,” or “our”) respects your privacy and is committed to protecting it through this Privacy Policy. This policy explains how we collect, use, disclose, retain, and safeguard personal information when you visit or use our websites, applications, products, and services (collectively, the “Services”).

1. Scope

This Privacy Policy applies to:

  • Visitors to our websites

  • Customers and users of our Services

  • Business contacts, partners, and prospects

It does not apply to information processed on behalf of customers under a separate Data Processing Agreement (DPA), where Copilot acts as a data processor.

2. Definitions

  • Personal Data / Personal Information: Information that identifies, relates to, or can reasonably be linked to an individual.

  • Sensitive Personal Data: Data such as precise location, government identifiers, or credentials, where applicable.

  • Processing: Any operation performed on personal data (collection, storage, use, disclosure).

  • Controller / Processor: As defined under GDPR.

3. Information We Collect

3.1 Information You Provide Directly

  • Name, email address, phone number

  • Company name, role, and contact details

  • Account credentials

  • Support communications

  • Marketing preferences

  • Contractual and billing information

3.2 Information Collected Automatically

  • IP address and approximate location

  • Device and browser information

  • Log files and usage analytics

  • Cookies and similar tracking technologies

3.3 Information from Third Parties

  • CRM and sales platforms

  • Marketing and analytics providers

  • Business partners and integrations

4. How We Use Personal Information

We process personal information for the following purposes:

PurposeLegal Basis
Provide and operate the ServicesPerformance of a contract
Account creation and authenticationPerformance of a contract
Customer supportLegitimate interests
Product improvement and analyticsLegitimate interests
Marketing communicationsConsent or legitimate interests
Legal complianceLegal obligation
Security and fraud preventionLegitimate interests

5. Cookies and Tracking Technologies

We use cookies and similar technologies to operate and improve our Services.

Cookie Categories

  • Strictly Necessary: Required for site functionality

  • Performance & Analytics: Measure usage and performance

  • Functional: Remember preferences

  • Marketing: Advertising and attribution

You can manage cookie preferences through your browser settings or our cookie website settings.

6. Data Sharing and Disclosure

We may share personal information with:

  • Service Providers: Hosting, analytics, support, payment processing

  • Business Partners: Integrations requested by you

  • Legal Authorities: When required by law

  • Corporate Transactions: Mergers, acquisitions, or asset sales

All service providers are contractually required to protect personal information and use it only for authorized purposes.

7. International Data Transfers

Personal information may be transferred to and processed in the United States or other jurisdictions.

Where required, we rely on:

  • Standard Contractual Clauses (SCCs)

  • Adequacy decisions

  • Other lawful transfer mechanisms

8. Data Retention

We retain personal information only as long as necessary for the purposes described:

Data TypeTypical Retention
Account dataDuration of account + up to 24 months
Support recordsUp to 36 months
Marketing dataUntil opt-out or 24 months of inactivity
Analytics dataAggregated or anonymized where possible

Retention may be extended where legally required.

9. Your Privacy Rights

Depending on your location, you may have the right to:

  • Access your personal information

  • Correct inaccurate data

  • Delete personal information

  • Restrict or object to processing

  • Data portability

  • Withdraw consent

  • Opt out of marketing communications

How to Exercise Your Rights

Submit a request via:

We respond to verified requests within 30 days, as required by law.

10. U.S. State Privacy Rights

Residents of California and other U.S. states may have additional rights under laws such as CPRA, VCDPA, and CPA, including:

  • Right to know

  • Right to delete

  • Right to correct

  • Right to opt out of sale or sharing (if applicable)

Copilot does not sell personal information.

11. Children’s Privacy

Our Services are not directed to children under 13 (or 16 where applicable). We do not knowingly collect personal information from children. If such information is discovered, it will be deleted promptly.

12. Security Measures

We implement appropriate technical and organizational safeguards, including:

  • Encryption in transit and at rest (where applicable)

  • Access controls and authentication

  • Monitoring and logging

  • Incident response procedures

No system is completely secure; however, we continuously improve our security posture.

13. Data Breach Notification

In the event of a data breach involving personal information, we will notify affected individuals and regulators as required by applicable law.

14. Do Not Track & Global Privacy Control

Our Services do not currently respond to browser “Do Not Track” signals. We recognize Global Privacy Control (GPC) signals where legally required.

15. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via our website or email. The “Last Updated” date reflects the latest revision.

16. Contact Us

For questions or concerns about this Privacy Policy or our privacy practices:

Copilot CX, Inc.
Email: privacy@copilot.cx



If you have questions or comments about this policy, you may contact our Data Protection Officer (DPO), Elad Levi, by email at elad@copilot.cx, or by post to:

Co-pilot CX Inc.

Elad Levi

122 Grand St.

New York, NY 11222

United States

Safari requires user permission to enable video autoplay