Skip to content
Adoptiv

Privacy Policy

How Adoptiv Inc collects, uses, shares and protects personal data across telephony, CRM, connected mailboxes and AI, and the rights you can exercise.

Adoptiv Inc · Updated 2026-08-03

01Who we are

Adoptiv is a communications and CRM platform operated by Adoptiv Inc, a Delaware corporation with its registered office at 2810 N Church St STE 88783, Wilmington, DE 19802, United States. Adoptiv Inc is the only contracting entity. It holds the customer contracts, the carrier relationships and the data protection commitments described in this policy. There is no parent company and no other group entity involved in processing your data.

The platform combines programmable telephony, a dialer, a CRM with contacts, accounts, deals and pipelines, connected email and calendar, and AI features such as transcription, call analysis and email drafting.

Adoptiv is not a lead generation service, a list broker, a data reseller or a marketing agency. We do not sell personal data.

You can reach us at privacy@adoptiv.com, or by post at the Wilmington address above. Our phone number is +1 (636) 556 0022.

02When we are the controller and when we are the processor

This distinction decides who you should ask about a given record, so it is worth being precise.

We are the controller for the data we collect in our own right: visitors to our website, people who ask for a demo, and the named users who hold an Adoptiv login. We decide why and how that data is processed, and this policy governs it.

We are the processor for the data our customers put into the platform: their contact records, their deals, their call recordings, the messages in their connected mailboxes, and everything derived from those. The customer is the controller. We process it on their documented instructions under the terms at /legal/dpa.

If your details are in an Adoptiv workspace because a business you dealt with put them there, that business is the controller. Send your request to them. If you send it to us, we will pass it on to the customer and support them in answering it, but we cannot decide the outcome on their behalf.

03Personal data we collect

What we hold depends on your relationship with us and on which features your workspace has switched on.

Account and registration data. Name, job title, company, business email, phone number. Hashed passwords, multi-factor secrets, single sign-on identifiers, and OAuth tokens for the accounts you connect. Billing address and tax registration number.

Telephony and communications data. This is a communications platform, so by its nature it processes both metadata and content.

  • Call metadata: source and destination numbers, direction, date, time, duration, outcome, and routing information.
  • Call content: recordings where recording is switched on, voicemail audio, and transcripts.
  • Email content: message headers, bodies and attachments from the mailboxes a user connects, along with folder and read state.
  • Calendar data: events, times, attendees and meeting links from connected calendars.
  • Customer Proprietary Network Information, described in its own section below.

CRM data. Contact and account records, deal names and values, pipeline stages, notes, tasks, meetings, activity history, and any custom fields a workspace configures.

AI generated data. Transcripts, summaries, sentiment and topic labels, suggested next actions, lead and deal scores, and drafted email text. These are derived from the content above and inherit its sensitivity.

Technical and usage data. IP address, browser and operating system, device identifiers, access timestamps, features used, API request logs and error logs.

Payment data. We do not receive or store card numbers. Card details are entered directly with Stripe, which is a PCI-DSS Level 1 service provider. We receive the customer name, email, billing address and the result of the charge.

04How we collect it

  • Directly from you, through sign-up, profile settings, manual CRM entry, support tickets and sales conversations.
  • Automatically from platform activity. Calls, emails and meetings that run through Adoptiv are logged as they happen.
  • From accounts you connect, such as a Gmail or Microsoft mailbox, a calendar, a video conferencing account or another CRM.
  • From cookies and similar technologies on our marketing website. The authenticated product sets only the cookies it needs to keep you signed in and safe. See /legal/cookies.
  • From AI inference over content already in the platform.
  • From licensed business data providers, used to fill in company level detail such as industry, size or registered address. We do not scrape.

06Connected mailboxes and calendars

A user can connect a Google or Microsoft mailbox so that Adoptiv shows their email beside the CRM record it belongs to. This section sets out exactly what that access covers, because it is the most sensitive permission the product asks for.

The connection is made by an individual user for their own mailbox, through the provider's own consent screen. An administrator cannot connect a mailbox on someone else's behalf, and the consent screen shows the permissions before anything is granted.

Google: one scope, and why. Adoptiv requests a single restricted scope, https://www.googleapis.com/auth/gmail.modify. We request one scope rather than several because modify is a superset of the narrower Gmail scopes. It authorises everything the integration does, so asking for readonly, send and labels alongside it would add prompts without adding capability. The connected address is read from the Gmail profile endpoint, which modify already covers, so we do not request a separate profile or userinfo scope. This is the complete Google scope set for the product.

What we read from Gmail. Message headers, bodies and attachments, thread structure, and the labels and folders the mailbox uses. We list and fetch messages, and we use the Gmail history feed to pick up changes incrementally rather than re-reading the mailbox. We register a watch on the mailbox so Google can notify us through Google Cloud Pub/Sub when something changes. That notification carries a change marker, not message content.

What we write back to Gmail. Two things, both of them actions a user takes in Adoptiv. We send the messages a user sends from Adoptiv, and we update read state and labels when a user reads or files a message in the Adoptiv interface. Adoptiv has no ability to delete or trash a message in your Gmail mailbox. The product does not call the Gmail delete, trash or batch delete endpoints at all.

Microsoft Graph. For a Microsoft mailbox we request Mail.Read, Mail.ReadWrite, Mail.Send, Calendars.ReadWrite, Contacts.Read and offline_access. Mail.ReadWrite covers read state and folder moves, Mail.Send sends the messages a user sends from Adoptiv, Calendars.ReadWrite reads the calendar and writes the meetings a user books from Adoptiv, Contacts.Read matches senders to people the user already knows, and offline_access is what returns the refresh token so the connection survives without asking the user to sign in repeatedly. We subscribe to Graph change notifications for the same reason we use Pub/Sub on the Google side.

What is stored on Adoptiv servers. The messages, their headers and bodies, attachments, folder structure, read state, calendar events, and the drafts a user composes in Adoptiv. Drafts are held on our servers and are not written into the provider's drafts folder. We also store the connected email address and the OAuth tokens.

What is not stored. We do not copy your entire mailbox history without limit, we do not read mailboxes that no user has connected, and we do not use mailbox content to build any profile of you outside the workspace that connected it. Your mailbox content is never used to train generalised or non-personalised AI or machine learning models.

Tokens. Access and refresh tokens are encrypted at rest with AES-256-GCM. They are decrypted in memory only to make a call to the provider on the workspace's behalf.

What happens when a mailbox is disconnected. Disconnecting is available to the user who connected the mailbox, from the integrations screen. The steps are these.

  • For Google, the push notification watch is cancelled and the token is revoked with Google. Once revoked, the token cannot be used again, and the grant disappears from the user's Google account permissions page.
  • For Microsoft, the Graph change notification subscriptions are deleted at Microsoft so the mailbox stops sending us notifications.
  • Messages that are not attached to any contact or deal are deleted from Adoptiv, along with the folder structure and the drafts held for that mailbox.
  • Messages that are already attached to a contact or a deal are kept. They are detached from the mailbox connection and remain as part of the customer's CRM record, because the customer's account history would otherwise lose the correspondence behind a deal.
  • Those retained messages can be deleted on request. Ask the workspace administrator, or write to privacy@adoptiv.com and we will action it with the customer.

You can also revoke Adoptiv's access without going through the product, from the Google account permissions page or the Microsoft account app permissions page. If you do, we lose access immediately and the sync stops.

Adoptiv's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements. The full statement is at /legal/google-user-data.

07Call recording

Call recording is off by default. It is switched on by an administrator, either for the workspace or for a particular campaign.

When it is on, Adoptiv provides tools to help the customer meet notice and consent obligations: a configurable announcement played before the call connects, periodic beep tones during the call, and scripting for agents to disclose recording verbally.

The customer is responsible for lawful recording. Recording law depends on where each party is. Some jurisdictions accept one party consent and others require every party to agree. We provide the technical controls; the legal obligation sits with the account holder, who is the controller of those recordings.

Recordings are encrypted at rest with AES-256-GCM. Call media is carried over SRTP and API traffic over TLS. Access follows the workspace's role permissions, so a recording is visible only to users whose role allows it.

An administrator sets the retention period for recordings, and recordings are deleted automatically when it expires. Individual recordings can be deleted at any time from the platform, and deletion is permanent.

Where AI analysis is switched on, recordings and their transcripts are processed to produce transcripts, summaries and scores. Recordings are never used to train generalised AI models, and never leave the workspace that owns them except to the sub-processors listed at /legal/sub-processors.

08Customer Proprietary Network Information

Because Adoptiv provides voice services, some of the data we hold is Customer Proprietary Network Information, or CPNI, regulated in the United States under 47 U.S.C. 222 and the FCC rules made under it.

CPNI is the information we learn simply by carrying your calls: how many calls you make, where to, when, for how long, and how your service is configured. It does not include your name, your billing address or what was said on the call.

Without your affirmative consent we use CPNI only to deliver, route, bill and maintain your service, to prevent fraud and unauthorised use, and to answer a lawful government request. With your consent we may also use it to tell you about Adoptiv services that suit how you use the platform.

You can deny, restrict or withdraw our use of your CPNI for marketing at any time, and doing so does not affect the service you receive. Email privacy@adoptiv.com with the subject CPNI Opt-Out. A restriction stands until you tell us otherwise.

09AI and automated systems

AI features are opt-in for each workspace, and every switch starts off. Nothing is transcribed, analysed or sent to an AI provider until an administrator turns the feature on.

FeatureWhat it readsWhat it producesHuman involvement
Call transcriptionCall audioTime stamped textReviewable in the platform
Call analysisTranscriptsSummaries, sentiment, topicsInformational only
Email drafting and rewritingThread content the user has openSuggested textThe user edits and sends
Lead and deal scoringActivity history and CRM fieldsA score and a suggested next actionAdvisory, a person decides
Voice agentsLive call audio and the matching CRM recordSpoken replies and routingEscalation to a person, configured by the administrator

We do not use customer content to train or improve generalised AI models, and we do not let our AI providers do so either. Model providers that receive Adoptiv data are engaged under terms that prohibit training on it.

Automated decisions. The platform makes some operational decisions automatically, such as answering machine detection, call routing and screening numbers against do-not-call lists. None of these produce a legal or similarly significant effect on an individual within the meaning of Article 22 of the GDPR. Where an AI score or suggestion bears on a sales outcome, a person remains in the loop. If we ever ship a feature that makes a fully automated decision with significant effect, we will notify affected users and update this policy before it goes live.

AI agents that speak on a call identify themselves as AI, and synthetic voice is disclosed. This follows Article 50 of the EU AI Act, the FCC ruling of February 2024 treating AI generated voice calls as robocalls, and state disclosure rules such as California AB 2905.

Administrators can see which AI features are enabled, switch any of them off, and override any AI generated output.

The AI providers who may receive this content are named at /legal/sub-processors.

10How we share personal data

We share personal data only in the situations below. We do not sell it, and we do not share it for cross-context behavioural advertising.

RecipientWhat they receiveWhy
Telecommunications carriersPhone numbers and routing dataTo connect calls over the public network
StripeName, email, billing addressTo take payment. Stripe is a PCI-DSS Level 1 service provider and card details go to it directly
Cloud infrastructure providersPlatform data at rest and in transitHosting, storage and backup
AI and speech providersCall audio, transcripts, email bodies, CRM field valuesTranscription, analysis and generation, where the workspace has switched the feature on
Services you connectWhatever the integration is configured to syncTo deliver the integration you set up
Compliance and screening providersPhone numbers, company domains, postal addressesDo-not-call screening and record verification
Professional advisersOnly what the matter requiresLegal, audit and accounting advice, under a duty of confidence
Legal authoritiesWhat a valid order compelsCompliance with law. We tell the affected customer where we are legally allowed to, and we push back on overbroad requests
An acquirerBusiness data, in a merger or asset saleCorporate transaction. Affected customers are notified and the acquirer is bound by this policy or its equivalent

The full, named list of sub-processors, with what each one receives and whether it is on by default, is at /legal/sub-processors. We give 30 days' notice before adding one.

11International data transfers

Adoptiv Inc is established in the United States and serves customers worldwide, so personal data crosses borders. These are the mechanisms we rely on.

TransferMechanismStatus
EEA to the United States and other third countriesEU Standard Contractual Clauses, Decision (EU) 2021/914, with a transfer impact assessmentIn use
United Kingdom to third countriesUK International Data Transfer Agreement, or the UK Addendum to the EU SCCsIn use
Switzerland to third countriesSwiss addendum to the EU SCCs, under the revised FADPIn use
EU-US Data Privacy FrameworkRegistration by Adoptiv Inc with the US Department of CommerceApplication in progress. It will supplement the SCCs, not replace them
UK Extension to the EU-US DPFSought alongside the EU-US DPFApplication in progress
Swiss-US DPFSought alongside the EU-US DPFApplication in progress

We do not claim active Data Privacy Framework participation. Until the listing is live, transfers rest on the Standard Contractual Clauses and the UK IDTA, which stand on their own.

Every sub-processor that receives personal data from the EEA, the UK or Switzerland is bound by the same clauses through our contract with it.

Primary hosting is in Germany, with the United States available. A customer can ask us where its workspace sits and we will tell it.

12Security

  • Encryption. AES-256-GCM at rest, covering databases, backups, recordings and stored credentials. TLS in transit. SRTP for call media.
  • Credentials and tokens. OAuth tokens, mail passwords and provider API keys are encrypted at rest and are never returned by an API once stored.
  • Access control. Role based permissions, multi-factor authentication, single sign-on through SAML 2.0 and OAuth 2.0, IP allow lists, and per-endpoint rate limiting.
  • Tenant isolation. Each customer's data sits in its own database schema.
  • Internal access. Engineers do not browse customer data. Access to production is limited, tied to a named person, and logged.
  • Testing. Third-party penetration testing and continuous vulnerability scanning. Report a vulnerability through /legal/vulnerability-disclosure.
  • Backups. Automated daily backups with point-in-time recovery, encrypted, held separately from the primary systems.
  • Breach response. If a personal data breach affects your data, we notify affected customers and the relevant supervisory authority without undue delay and within 72 hours of becoming aware, as Article 33 of the GDPR requires.

A SOC 2 Type II examination is in progress. We make no other assurance claim, and we will not describe a control as audited before it has been. The controls themselves are documented at /legal/security-practices.

13How long we keep data

This is our retention policy. Where a customer sets a shorter period, the shorter period wins.

DataRetention periodWhat triggers deletion
Account and profile dataFor the life of the subscription, then 30 daysAccount closure or a deletion request
CRM records: contacts, accounts, dealsFor the life of the subscription, then 30 days for exportAccount closure or an erasure request
Call recordingsAs the administrator configures, 90 days by defaultConfigured expiry, manual deletion or a request
Transcripts and AI analysisDeleted with the recording they came fromDeletion of the parent recording
Call metadata and logs12 months from the callAutomated purge
Email and calendar content from connected accountsFor as long as the mailbox is connected. On disconnect, see the mailbox section aboveDisconnect, erasure request or account closure
Support conversations3 years from the last messageAutomated purge
Security and access logs12 monthsAutomated purge
Marketing consent records3 years from the last consent actionWithdrawal of consent
Billing and financial records7 yearsExpiry of the statutory period
Backups35 days, then overwrittenRolling expiry

A deletion request removes data from live systems straight away. Backups age out on the rolling schedule above, and we do not restore a backup to reinstate deleted data.

Once a period expires we delete the data or irreversibly anonymise it. Aggregated statistics that cannot identify anyone may be kept indefinitely. The operational detail sits at /legal/retention.

14Your rights in the EEA, the UK and Switzerland

If you are in the European Economic Area, the United Kingdom or Switzerland, you have these rights over personal data we hold as a controller.

  • Access, Article 15. A copy of your data and an explanation of how we process it.
  • Rectification, Article 16. Correction of anything inaccurate or incomplete.
  • Erasure, Article 17. Deletion, subject to any legal obligation we have to keep a record.
  • Restriction, Article 18. A pause on processing while a dispute is resolved.
  • Portability, Article 20. Your data in a structured, machine readable format, or sent to another controller.
  • Objection, Article 21. To processing based on legitimate interest, and to direct marketing at any time.
  • Automated decisions, Article 22. Not to be subject to a solely automated decision with significant effect, and to ask for human review.
  • Withdrawal of consent, Article 7(3). At any time, without affecting what was lawful before.
  • Complaint, Article 77. To your local supervisory authority, at any time.

Write to privacy@adoptiv.com. We answer within one month and will tell you if we need the two-month extension the GDPR allows for a complex request. We do not charge for this.

Where the data belongs to one of our customers rather than to us, we are the processor. We will pass your request to them and help them answer it.

15California rights

California residents have these rights under the CCPA as amended by the CPRA.

  • Know. The categories and specific pieces of personal information we collected in the preceding 12 months.
  • Delete. Deletion of personal information we collected about you, subject to the statutory exceptions.
  • Correct. Correction of inaccurate personal information.
  • Opt out. Of any sale or sharing for cross-context behavioural advertising. We do not sell or share personal information in that sense, and we honour the Global Privacy Control signal on our website.
  • Limit sensitive personal information. We use it only for the purposes the statute permits without a separate right to limit.
  • Non-discrimination. We will not treat you differently for exercising a right.

Categories collected in the last 12 months: identifiers such as name, email, phone number, IP address and account identifier; commercial information such as plan and purchase history; communications content such as recordings, transcripts and email where those features are in use; internet and network activity such as usage and access logs; inferences such as AI generated scores and sentiment; and professional information such as job title and employer.

Email privacy@adoptiv.com with the right you are exercising in the subject line. We verify your identity against the account, and we respond within 45 days, extendable by a further 45 with notice. An authorised agent may act for you with written permission.

16Other US state privacy rights

Residents of the states below have comparable rights under their own laws: access, correction, deletion, portability, and an opt-out of sale, targeted advertising and certain profiling. Most also give a right to appeal a refusal.

  • Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, New Jersey, Delaware, Iowa, Tennessee, Indiana, Minnesota, Maryland, Nebraska, New Hampshire, Kentucky and Rhode Island.

We respond within 45 days, extendable by 45 days with notice. If we refuse a request you may appeal by replying to our decision, and we will answer the appeal within 45 days and tell you how to contact your state Attorney General.

Email privacy@adoptiv.com with the subject State Privacy Rights Request and name your state.

17Cookies

Our marketing website uses strictly necessary, functional, analytics and advertising cookies, and asks for consent before setting anything beyond the strictly necessary ones.

The authenticated product is different. It sets only the cookies needed for sign-in, session security and cross-site request forgery protection. There are no advertising cookies inside the product.

You can change your choices at any time through the cookie preferences link in the website footer. The full list, with names and lifetimes, is at /legal/cookies.

18Children

Adoptiv is business software sold to businesses. It is not directed at children and we do not knowingly collect their personal data. We do not permit anyone under 16 to hold an Adoptiv account, and under 13 in the United States we are additionally bound by COPPA.

If you believe a child has created an account or that a child's data has reached us, email privacy@adoptiv.com with the subject Minor Account Report and we will delete it.

19Changes to this policy

We update this policy when our practices, our product or the law change. For a material change we give at least 30 days' notice: a banner in the product, an email to the administrator on file, and a new date at the top of this page.

If you do not accept a material change, you may terminate under the Terms at /legal/terms. Continuing to use the platform after the change takes effect means you accept it.

20How to contact us

ReasonAddress
Privacy questions, rights requests, opt-outsprivacy@adoptiv.com
Security reports and suspected breachessecurity@adoptiv.com
Legal notices and law enforcement requestslegal@adoptiv.com
PostAdoptiv Inc, 2810 N Church St STE 88783, Wilmington, DE 19802, United States
Phone+1 (636) 556 0022

We acknowledge a privacy enquiry within 2 business days and aim to resolve it within 30 days. If you are not satisfied with our answer, you can complain to your supervisory authority or state regulator, and we would rather you did that than stay unhappy with us.

Adoptiv Inc, 2810 N Church St STE 88783, Wilmington, DE 19802, United States. Questions about this document go to legal@adoptiv.com. Privacy requests go to privacy@adoptiv.com.