
Privacy Policy
Effective date: 1 August 2026
Last updated: 1 August 2026
1. Who we are
This Privacy Policy explains how Fieldcoreai ("Fieldcoreai," "we," "us," or "our") collects, uses, shares, and protects personal data when you visit fieldcore.dev, use our services, or otherwise interact with us.
Fieldcoreai is an AI automation company based in France. We build AI voice callers and custom AI automations tailored to our customers' needs. Our users include businesses (customers, suppliers, partners) and individual consumers (including people who receive or place calls handled by our AI voice agents).
For the purposes of the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR"), Fieldcoreai is the data controller of the personal data described in this policy, except where we act as a processor on behalf of a business customer (see Section 12).
Business name: Fieldcoreai
Contact email: [email protected]
Website: https://fieldcore.dev
2. Scope
This policy applies to:
Visitors to fieldcore.dev
Customers who purchase or subscribe to our services
End users who interact with AI voice agents or other AI automations we operate directly
Business contacts (suppliers, partners, prospects)
Where a business customer uses our platform to deploy AI automations to their end users, that customer is the controller of end-user data and their own privacy policy applies. We process that data as a processor under a Data Processing Agreement.
3. Information we collect
3.1 Information you provide directly
Account and contact information: name, email address, phone number, business name, job title.
Billing information: billing name, billing address, VAT number where applicable. Payment card details are entered directly into our payment processor (Stripe) and are not stored on our systems.
Content you submit: documents, files, prompts, instructions, configuration data, and any other content you upload or enter to configure or use our AI automations.
Communications: messages you send us via email or other channels.
3.2 Information generated through use of our AI services
Conversation data: transcripts and, where applicable, audio recordings of calls handled by our AI voice agents; text inputs and outputs of our other AI automations.
Metadata: timestamps, call duration, phone numbers involved, session identifiers, error and performance logs.
3.3 Information collected automatically
Technical data: IP address, browser type and version, device information, operating system, referring URL, pages visited, and access times.
Cookies and similar technologies: we use cookies only where you have given consent via our cookie banner (see Section 11). Strictly necessary cookies do not require consent.
3.4 What we do not collect
We do not knowingly collect data from children under 16, biometric data, or health data. If you believe we have inadvertently collected such data, contact us and we will delete it.
4. How we use your information and legal bases
Under GDPR, we must have a lawful basis to process your personal data. We rely on the following:
PurposeLegal basis (GDPR Art. 6)Providing our services, including operating AI voice agents and automations for youPerformance of a contract (Art. 6(1)(b))Processing payments and issuing invoicesContract (Art. 6(1)(b)) and legal obligation (Art. 6(1)(c))Improving our services (debugging, quality assurance, service optimisation)Legitimate interests (Art. 6(1)(f)) — improving reliability and quality of the services you useCorresponding with you (support, service notices)Contract or legitimate interestsComplying with legal obligations (tax, accounting, responding to lawful requests)Legal obligation (Art. 6(1)(c))Setting non-essential cookiesConsent (Art. 6(1)(a))Recording and processing calls handled by AI voice agentsContract with the business customer deploying the agent; where you are the called party, our customer's legitimate interests, subject to the transparency notice described in Section 5
We do not use your data to train our own or third-party AI models. Content you submit and conversations processed by our AI agents are used only to deliver the requested service and, in aggregated or de-identified form, to monitor and improve service quality.
5. AI-specific disclosures
Because we are an AI automation company, we want to be explicit about how AI is involved.
AI systems we use. We rely on third-party AI models, including models provided by Anthropic (Claude) and OpenAI (GPT), to power our automations. When you interact with our services, your inputs and, where relevant, conversation content may be transmitted to these providers for processing. These providers act as our sub-processors and are contractually prohibited from using your data to train their models.
AI voice agents — transparency. In compliance with Article 50 of the EU AI Act (applicable from 2 August 2026), any person who interacts with one of our AI voice agents will be clearly informed at the start of the interaction that they are speaking with an AI system, unless it is obvious from the circumstances.
Automated decision-making. We do not make decisions producing legal or similarly significant effects on you based solely on automated processing (GDPR Art. 22). Outputs of our AI systems are reviewed and confirmed by humans where they inform business decisions, and our voice agents do not provide legal, medical, or financial advice.
Call recording. Where we record calls placed or received by our voice agents, the recording is disclosed at the start of the call. Recordings are retained only for the period described in Section 8.
6. Who we share your data with
We do not sell your personal data. We share personal data only with the following categories of recipients:
Hosting and infrastructure providers:Cloudflare, Inc. — website hosting, CDN, and security services.HighLevel, Inc. (GoHighLevel) — CRM and marketing platform used to manage customer relationships, appointments, and business communications.
AI model providers:Anthropic PBC (Claude models).OpenAI, LLC (GPT models).
Payment processor:Stripe, Inc. (and Stripe Payments Europe, Ltd.) — for processing payments.
Professional advisers: accountants, auditors, lawyers, and insurers, where necessary.
Public authorities: where we are required to disclose data to comply with a legal obligation, court order, or lawful request.
Business transfers: in the event of a merger, acquisition, or sale of assets, personal data may be transferred as part of the transaction, subject to equivalent protection.
Each of these providers is bound by a written data processing agreement (or equivalent) that requires them to process personal data only on our instructions and to implement appropriate security measures.
7. International data transfers
Some of the providers listed above are located outside the European Economic Area (EEA), primarily in the United States. When we transfer your personal data outside the EEA, we rely on one or more of the following safeguards required by GDPR Chapter V:
Standard Contractual Clauses (SCCs) adopted by the European Commission, incorporated into our contracts with these providers;
Adequacy decisions where they apply (for example, the EU–US Data Privacy Framework, where the recipient is certified);
Supplementary technical and organisational measures where required following a transfer impact assessment.
You may request a copy of the safeguards we rely on by emailing [email protected].
8. How long we keep your data
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including to meet legal, accounting, or reporting requirements.
CategoryRetention periodAccount and customer relationship dataDuration of the contract, plus up to 3 years after the end of the relationship (French commercial prescription period)Invoices, billing records, and accounting documents10 years from the end of the financial year (Art. L.123-22 French Commercial Code)AI conversation data, transcripts, uploaded documents, and call recordingsFor the duration required to deliver the service, and then for a maximum of [BRACKETED — insert your default, e.g. 90 days] unless you or the controlling customer instruct earlier deletionProspect and marketing dataUp to 3 years from last contact (CNIL guidance)Website logs and technical dataUp to 12 monthsCookie consent recordsUp to 6 months
After the applicable retention period, personal data is deleted or anonymised.
9. Your rights
Under GDPR (and, where applicable, the French Data Protection Act), you have the following rights in respect of your personal data:
Right of access (Art. 15) — obtain confirmation of, and a copy of, the data we hold about you.
Right to rectification (Art. 16) — correct inaccurate or incomplete data.
Right to erasure ("right to be forgotten," Art. 17) — request deletion of your data in certain circumstances.
Right to restriction of processing (Art. 18).
Right to data portability (Art. 20) — receive your data in a structured, commonly used, machine-readable format.
Right to object (Art. 21) — object to processing based on our legitimate interests, including for direct marketing.
Right to withdraw consent at any time, where processing is based on consent, without affecting the lawfulness of processing before withdrawal.
Right not to be subject to solely automated decision-making producing legal or similarly significant effects (Art. 22).
Right to lodge a complaint with a supervisory authority. In France, this is the Commission Nationale de l'Informatique et des Libertés (CNIL) — www.cnil.fr.
How to exercise your rights. Email us at [email protected] with your request. We will respond within one month, as required by GDPR (extendable by two further months for complex requests). We may need to verify your identity before acting on your request.
10. Security
We implement appropriate technical and organisational measures to protect personal data against unauthorised access, alteration, disclosure, or destruction. These include:
Encryption of data in transit (TLS) and, where applicable, at rest;
Access controls and authentication for our internal systems;
Segregation of production and non-production environments;
Vetted sub-processors with their own security certifications;
Regular review of our security practices.
No method of transmission or storage over the internet is 100% secure. In the event of a personal data breach likely to result in a risk to your rights and freedoms, we will notify the CNIL within 72 hours and, where required, notify affected individuals without undue delay, in accordance with GDPR Arts. 33–34.
11. Cookies
Our website uses cookies and similar technologies. When you first visit fieldcore.dev, our cookie banner allows you to accept or reject non-essential cookies.
Strictly necessary cookies — required for the website to function (e.g., security, load balancing via Cloudflare). No consent required.
Functional cookies — remember your preferences.
Analytics and marketing cookies — only set if you consent.
You can change your cookie preferences at any time via the cookie settings link on our website, or by clearing cookies in your browser. Rejecting non-essential cookies will not affect your ability to use the core features of our services.
12. When Fieldcoreai acts as a processor
Where a business customer uses Fieldcoreai to deploy AI automations to their own end users (for example, a business that uses our voice agents to handle its own inbound or outbound calls), that business is the controller of end-user personal data and Fieldcoreai acts as a processor under GDPR Art. 28.
In that case:
We process end-user data only on the documented instructions of our customer;
Our services are governed by a Data Processing Agreement (DPA) that we make available to customers on request or as part of the contract;
End users should refer to that business customer's own privacy policy for information about how their data is handled. Requests to exercise data subject rights should be addressed to the controller.
13. Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in our services, legal requirements, or business practices. When we make material changes, we will notify you by email or through a notice on our website before the changes take effect. The "Last updated" date at the top of this policy indicates when it was last revised.
14. Contact us
For any question, request, or complaint about this Privacy Policy or the way we handle your personal data:
Email: [email protected]
If you are not satisfied with our response, you have the right to lodge a complaint with the CNIL (France) or with the data protection authority of your EU country of residence.