Privacy
What we hold,
and what we never do with it.
Bylda processes sales conversations, which is among the most sensitive data a company owns. This page says plainly what happens to it.
LAST UPDATED · 5 AUGUST 2026
Who we are
Bylda ("we", "us") provides an AI Sales Operating System that captures and analyses customer conversations and writes structured records into a customer's CRM. This policy covers usebylda.com and the Bylda product.
For personal data processed on behalf of a business customer, that customer is the data controller and Bylda is the processor, governed by our Data Processing Agreement. For this website and our own marketing, Bylda is the controller.
What we collect
- Account data — name, work email, company, and role for the people who use Bylda.
- Conversation data — audio, transcripts, and derived analysis from calls and meetings a customer connects, plus email and calendar metadata where enabled.
- CRM data — the records, fields, and schema Bylda reads in order to write back accurately.
- Usage data — product events, device and browser information, and IP address, used to operate and improve the service.
- Website data — pages viewed and referrer. We use privacy-respecting analytics and do not run advertising trackers.
How we use it
To deliver the service: transcribe and analyse conversations, extract structured fields, write to a customer's connected systems, draft follow-ups, and produce briefs and forecasts.
To support and secure the service: diagnose faults, prevent abuse, and meet legal obligations. We do not sell personal data, and we do not share it with advertisers.
Model training — the commitment
Your conversations are never used to train shared or third-party models. This is contractual, not merely a policy statement.
Where we use third-party model providers to process a request, they operate under zero-retention agreements: they process the request and retain nothing afterwards. Our current subprocessor list is published and versioned, and enterprise customers receive 30 days' notice before any addition.
We do not perform human review of customer transcripts without written, per-incident consent from that customer.
Recording and consent
Bylda enforces consent rules by region and meeting type. In two-party consent jurisdictions, recording does not begin until consent is captured. Administrators configure this once and it applies to every user on the account automatically.
Participants may request that a recording be excluded or deleted; customers can action this from the product, and we honour it in our systems within 30 days.
Where data is processed
Customers choose a processing region: United States, European Union, or United Kingdom. Data stays in the selected region, including transcripts, embeddings, and backups. International transfers, where they occur, rely on Standard Contractual Clauses.
Security
Data is encrypted with AES-256 at rest and TLS 1.3 in transit. Keys are managed in an HSM-backed service with routine rotation. Each customer occupies a logically isolated tenant with its own encryption context, and no embeddings are shared across tenants.
We hold SOC 2 Type II, run annual third-party penetration tests, and maintain an audit log of every read, write, and export, exportable to a customer's SIEM. Our full posture is at /security.
Retention and deletion
Conversation data is retained for the period a customer configures. On termination, customers can export everything — transcripts, summaries, extracted fields, and audit logs — in open formats. We then delete the tenant within 30 days, backups included, and confirm in writing.
Your rights
Depending on where you live, you may have rights to access, correct, delete, port, or restrict processing of your personal data, and to object to it. Where Bylda acts as a processor, we route requests to the relevant customer and support them in responding.
To exercise a right, write to privacy@usebylda.com. We respond within 30 days. You may also complain to your local supervisory authority.
Cookies
We use strictly necessary cookies for authentication and session integrity, and privacy-respecting analytics to understand aggregate site usage. We do not use advertising or cross-site tracking cookies.
Changes
We will post material changes to this policy on this page and, for changes that affect processing, notify account administrators by email before they take effect.
Write to privacy@usebylda.com and a person will answer.