Data & privacy
Your customer conversations are the most sensitive data you have. This page is the plain-English version of how Resonant IQ treats them — what it reads, how it's protected, and the controls you hold. The Privacy Policy and Security pages are the authoritative source.
Three commitments shape everything below. They're worth holding in mind as you read the specifics.
What Resonant IQ reads
Only what you connect, and only what the product uses. Through the read-only OAuth access you grant, Resonant IQ imports the two streams — conversation transcripts and their metadata, plus account activity like notes, tasks, calls, and meetings — along with the contact and company identifiers needed to associate a conversation with an account.
Whose data it is
For the conversation data you connect, your organization is the data controller — you own it, and Resonant IQ processes it only on your instructions to deliver the service, under a Data Processing Agreement. For your own account and billing data, Resonant IQ is the controller.
Each tenant's data is isolated from every other's — enforced at the application boundary and again by Postgres row-level security as an independent second layer, with a cross-tenant isolation test suite running in CI. One tenant cannot reach another's data.
AI and your data
Resonant IQ uses large language models to score conversations and detect signals. Two providers see conversation text as part of that work, both under enterprise data-handling terms, and neither retains your data for training:
- Anthropic — conversation scoring. Transcripts are sent to Anthropic's API to return scores and explanations. Anthropic retains API inputs for up to 30 days for trust and safety, then deletes them; details at trust.anthropic.com.
- Voyage AI — semantic search. Transcripts are sent to return vector embeddings used only for search and evidence retrieval.
Scores are advisory only. Your organization retains sole responsibility for any employment, coaching, or operational decisions made using them — Resonant IQ output is an input to human judgment, not a binding determination.
How it's protected
The controls below are built and running today — not planned. The full detail lives on the Security page.
On compliance: Resonant IQ is pre-launch and does not yet hold a SOC 2 report, but runs an internal controls program mapped to SOC 2 Trust Services Criteria, with a formal audit planned once there are production customers. GDPR data-subject obligations — export and deletion — are supported today.
Where it's processed
Resonant IQ runs on a small, deliberate set of US-based providers, each bound by a data processing agreement. The key ones that touch conversation data:
The full subprocessor list — and the EU-to-US transfer mechanisms (Standard Contractual Clauses) — is in Privacy Policy §7. You'll get at least 30 days' notice before a new subprocessor handling your data is added.
How long it's kept
Data is retained for as long as your account is active, with these windows after closure or deletion:
Disconnect an integration and its sourced data is purged within 60 days. Close your account or request deletion and Customer Data is deleted within 90 days, with confirmation; backups are purged on the same schedule after their normal cycle.
Controls you hold
- Disconnect any integration from Settings at any time — it revokes OAuth access immediately.
- Export your data in a structured, machine-readable format, or request deletion of specific records or your whole tenant.
- Data-subject rights (access, rectification, erasure, portability, and more) are available per the Privacy Policy. Requests from your end customers are administered by your organization as the controller; if you forward a valid one, Resonant IQ acts on it promptly.
Questions & requests
For the full legal detail, see the Privacy Policy, Security, and Terms. A copy of the Data Processing Agreement is available on request.