ClozoSome are Born Closers.Rest have Clozo.
Home Product Pricing About Privacy Terms
Get Started
Legal · Plain English

Privacy Policy

Last updated: 6 July 2026 · Questions? privacy@clozo.ai

The short version. Clozo runs your sales operations on infrastructure we control. We do not sell, rent, or trade your personal data with anyone. Every customer's data is isolated at the database-row level so one customer can never see another's. You own your data and can export it any time. For data your business loads into Clozo about your own contacts, you are the data controller and Clozo is your processor — you are responsible for having a lawful basis and any required consents for that data.
On this page
  1. Who we are & our role
  2. Information we collect
  3. How we use information
  4. Legal bases (GDPR)
  5. Controller vs. processor
  6. How AI processes data
  7. Communications, calls & recordings
  8. How we share (& never sell)
  9. Sub-processors
  10. Data retention
  11. Security
  12. Your privacy rights
  13. International transfers
  14. Cookies & analytics
  15. Children
  16. Changes
  17. Contact

1. Who we are & our role

"Clozo," "we," "our," and "us" refer to Clozo FZE LLC, a company registered in the United Arab Emirates (registered details in Section 17). Clozo operates the AI-powered revenue platform at clozo.ai, the academy at academy.clozo.ai, and the application at app.clozo.ai (together, the "Service").

We act as a controller for personal data about visitors to our marketing site, prospects, newsletter subscribers, and the individuals who administer customer accounts. We act as a processor for the "Customer Content" that our paying customers load into the Service about their own leads, contacts, and end users (see Section 5).

2. Information we collect

2.1 Information you provide

  • Account & billing: name, work email, company, role, plan, billing address, the last four digits and brand of your payment card, and your payment-processor customer ID. Full card numbers never touch our servers — our payment processor holds them.
  • Newsletter: email and any optional details you submit.
  • Customer Content: the leads, contacts, deals, calls, messages, files, recordings, transcripts, sequences, scripts, and notes you choose to store in the Service.
  • Support communications: anything you send to our support addresses or in-product chat.

2.2 Information collected automatically

  • Product & site telemetry: feature usage, error events, performance traces, page views, and heatmaps — via PostHog, Microsoft Clarity, Sentry, and Google Analytics 4.
  • Network metadata: IP address, browser, device, referrer, language, and timestamps — used for security, rate-limiting, abuse prevention, and audit logs.

2.3 Information from third parties

  • Integrations you connect (e.g. Google/Gmail, Microsoft/Outlook, social platforms, payment and telephony providers) send us only the data and scopes you authorise, used only to provide the features you enabled.

3. How we use information

  • To provide, secure, maintain, and improve the Service.
  • To process payments and prevent fraud (via our payment processor).
  • To send service communications (account, billing, security, legal, and material product changes). You cannot opt out of these while your account is active — they are necessary to operate the Service.
  • To send marketing you opted into; you may unsubscribe at any time via the link in each message.
  • To operate AI features within your account (see Section 6).
  • To comply with law, enforce our terms, and protect our rights, our users, and the public.

4. Legal bases (GDPR)

  • Contract (Art. 6(1)(b)) — to deliver the Service you signed up for.
  • Legitimate interests (Art. 6(1)(f)) — to secure and improve the Service and prevent abuse, balanced against your rights.
  • Consent (Art. 6(1)(a)) — for optional marketing and non-essential cookies; withdrawable at any time.
  • Legal obligation (Art. 6(1)(c)) — to meet legal, tax, and accounting requirements.

5. Controller vs. processor (your responsibilities)

When you upload or generate Customer Content about your contacts (leads, recipients, call/SMS targets), you are the controller and Clozo is the processor acting on your instructions. You are solely responsible for: (a) having a lawful basis and any required consent to collect and process that data; (b) providing your contacts with any legally required notices; (c) honouring their privacy requests; and (d) your use of communications features in compliance with applicable law (see Section 7). You will indemnify Clozo for claims arising from your handling of Customer Content, as set out in our Terms of Service. We process Customer Content only to provide the Service and per your instructions, and we make a data-processing addendum available on request.

6. How AI processes data

The Service uses AI models (self-hosted and/or third-party) to power features such as summaries, scoring, drafting, coaching, and transcription. When you use these features, the relevant content is sent to the model provider solely to generate the output you requested. We do not permit your Customer Content to be used to train third-party foundation models, and we do not use one customer's content to build models that serve another customer. AI output is generated statistically, may be inaccurate or incomplete, and is not professional advice; you are responsible for reviewing it before you rely on or act on it.

7. Communications, calls & recordings

Clozo provides tools that let you send email and SMS/WhatsApp and place and receive calls, and (where you enable it) record and transcribe calls. For every such communication, you are the sender/caller of record and are solely responsible for complying with all applicable laws — including consent, do-not-call, anti-spam, and call-recording/one- and two-party-consent laws (e.g. TCPA, CAN-SPAM, CASL, GDPR/ePrivacy, and local equivalents). You are responsible for obtaining any consent required before recording a call or messaging a contact. Clozo processes these communications on your behalf as your processor and is not responsible for your compliance decisions.

8. How we share (and never sell)

We never sell, rent, or trade personal data. We share data only with the sub-processors listed in Section 9, and only the minimum needed to run the Service. We may also disclose information where we have a good-faith belief it is necessary to comply with a lawful legal process, enforce our agreements, or protect the rights, safety, or property of Clozo, our users, or the public. We will push back on overbroad requests.

9. Sub-processors

We use the following categories of sub-processors. A current list is available on request; we give notice of material changes to active customers.

  • Fly.io — application hosting and compute (primary region: US East).
  • Supabase — managed PostgreSQL database and authentication.
  • Stripe — billing and payment processing.
  • Telephony & messaging providers (e.g. Twilio, Telnyx) — the calls, SMS, and WhatsApp messages you initiate.
  • Email providers (e.g. SendGrid and, where you connect them, Google/Microsoft) — transactional and marketing email you send.
  • AI/LLM providers (e.g. OpenRouter and self-hosted models) — AI feature processing (no third-party training on your data).
  • Analytics & monitoring — PostHog, Microsoft Clarity, Sentry, Google Analytics 4, LinkedIn Insight Tag, Postmark (deliverability/DMARC).

10. Data retention

Customer Content is retained while your account is active and, after termination, for a limited wind-down period so you can export it, after which it may be deleted or moved to secure long-term archival storage. You can request export at any time and request erasure at any time — on a verified erasure request we will delete or irreversibly anonymise the relevant data across our production systems within 30 days, except where we must retain limited records to meet legal, tax, accounting, or fraud-prevention obligations (typically up to 7 years). Account & billing records are retained as required by law. Server logs are retained up to 90 days, then aggregated to anonymous statistics.

11. Security

  • Tenant isolation by default. Every row carries a company_id; database Row-Level Security policies enforce at query time that one customer can never read another's rows.
  • Encryption. TLS in transit on every endpoint; encryption at rest for the database and stored files.
  • Secrets management. Credentials are held in a managed secret store, never in source code committed to version control.
  • Authentication. Managed auth with optional MFA, SSO/SAML for eligible plans, signed session cookies, and concurrent-session limits.
  • Audit logging. Sensitive operations are recorded to audit logs.

No system is perfectly secure. While we work hard to protect your data, we cannot guarantee absolute security. Report a vulnerability to security@clozo.ai.

12. Your privacy rights

Subject to applicable law, you may request to access, correct, delete, restrict, or object to the processing of your personal data, withdraw consent, and receive a copy of your data in a portable format. Where Clozo is a processor (Customer Content), we will refer your request to the relevant customer (the controller) or assist them in responding. To exercise your rights, email privacy@clozo.ai; we respond within the period required by applicable law (generally 30 days). You may also lodge a complaint with your local supervisory authority. California residents: we do not sell or "share" (as defined by the CPRA) personal information, and you have the right to non-discrimination for exercising your rights.

13. International transfers

Clozo operates from the UAE and uses sub-processors located in the United States and other regions. Where personal data is transferred internationally, we rely on appropriate safeguards such as Standard Contractual Clauses and our sub-processors' own transfer mechanisms. Contact privacy@clozo.ai if you require specific data-residency arrangements.

14. Cookies & analytics

Our marketing site uses strictly-necessary cookies (auth, CSRF, session) and analytics/measurement tags: Google Analytics 4 (G-55S3X1YSXL), Microsoft Clarity (w4oexhie7x), LinkedIn Insight Tag (9133604), PostHog, and Sentry. You can block non-essential cookies via your browser or device settings without losing access to content.

15. Children

Clozo is a business product intended for users aged 18 and over and is not directed to children. We do not knowingly collect data from minors. If you believe a minor has provided us data, email privacy@clozo.ai and we will delete it.

16. Changes to this policy

We may update this policy as our product or applicable law evolves. Material changes are posted here and, for active customers, announced by email before they take effect. The "Last updated" date above always reflects the current version. Your continued use of the Service after the effective date constitutes acceptance.

17. Contact

Clozo FZE LLC
Amber Gem Tower, Mezzanine Floor, Sheikh Khalifa Street
P.O. Box 4848, Ajman, United Arab Emirates

Privacy / Data Protection: privacy@clozo.ai
Security: security@clozo.ai
General: info@clozo.ai

This Privacy Policy should be read together with our Terms of Service.

ClozoSome are Born Closers.Rest have Clozo.

The AI-powered revenue platform that unifies CRM, intelligence, and engagement. Built for teams that close.

Product

CRM & Leads Hotline AI Intelligence Analytics Social & Tasks

Resources

All Features How It Works AI Engines Pricing

Company

About Privacy Policy Terms of Service Contact
© 2026 Clozo. All rights reserved.
Privacy Terms