LEGAL REVIEW DRAFT ยท UPDATED 2026-08-11
Privacy Notice
This Privacy Notice explains how Ring2 handles personal data when you visit the Ring2 website, submit a partner inquiry, communicate with us, or use a contracted Ring2 VoiceAgent service.
1. Scope and responsible organization
This notice applies to website visitors, prospective and current partners, customer and supplier representatives, authorized service users, and other people who communicate with Ring2. The Ring2 legal entity responsible for the website and Ring2's own commercial records will be the entity identified in Section 18.
For a contracted VoiceAgent deployment, the partner or end customer will ordinarily determine the purpose of the calls, the intended audience, the permitted data fields, and whether recording or transcription is enabled. That organization will ordinarily act as the controller or business, and Ring2 will ordinarily act as its processor or service provider. Ring2 may separately act as a controller for its own account administration, security, billing, legal compliance, and business relationship records. The signed agreement, Order Form, and Data Processing Addendum define the roles for each deployment.
2. Data collected through the website
Partner inquiry data
The public partner inquiry form requires four fields:
- work email address;
- company name;
- country or region; and
- partner type.
If a submission is accepted, Ring2 also creates a unique Request ID and records the submission time. The form does not ask you to upload recordings, contact lists, credentials, identity documents, payment details, or sensitive personal data.
Attribution and interaction data
The current website may send limited first-party events to Ring2's own event endpoint. Depending on the action, an event may include the event name, time, a generated event ID, country or region, partner type, Request ID, CTA location, demo type, booking source, UTM source, medium, campaign, term and content, referrer, and landing path.
The implemented event names are partner CTA click, demo play, form start, form-step completion, form submission, and confirmed booking. A booking event is recorded only when a connected scheduling flow sends a booking confirmation; clicking a scheduling link alone is not treated as a completed booking.
Technical request data
Hosting, content-delivery, security, and network providers necessarily process technical request data such as IP address, browser or device information, requested URL, timestamps, and diagnostic logs when they deliver a page or API response. Based on the current application code, Ring2 does not deliberately add an IP address, persistent cookie identifier, advertising identifier, or device fingerprint to its partner-inquiry or first-party event record.
3. Data collected in business communications
If you email Ring2, attend a briefing, request a proposal, negotiate an agreement, or ask for support, Ring2 may process your name, role, business contact details, correspondence, meeting notes, qualification information, proposed market and workflow, technical requirements, and commercial or contractual records. Please do not provide customer-confidential material, call data, or sensitive personal data before an appropriate written agreement and secure transfer method are in place.
4. Data processed in VoiceAgent services
A contracted deployment may process the following categories only to the extent specified in the Order Form, DPA, approved workflow, and service configuration:
- partner, customer, and authorized-user account details, roles, settings, support requests, and billing records;
- caller or recipient telephone numbers and other approved identifiers;
- call time, duration, routing, status, disposition, transfer, and related telephony metadata;
- approved prompts, scripts, knowledge sources, workflow fields, structured outcomes, and integration payloads;
- call audio, recordings, transcripts, summaries, or extracted fields when the relevant function is expressly enabled;
- CRM, scheduling, messaging, or other business-system actions initiated by the approved workflow; and
- operational, diagnostic, fraud-prevention, security, and support logs.
Partners and end customers must not configure a workflow to collect passwords, payment credentials, government identifiers, health information, biometric data, precise location, children's data, or other sensitive data unless the collection is necessary, lawful, expressly approved in writing, and protected by appropriate contractual and technical controls.
5. Sources of data
Ring2 obtains personal data directly from website visitors, business contacts, partners, customers, and authorized users; from URL parameters and referring pages; from interactions with the partner inquiry and demonstration; from connected telecommunications, CRM, scheduling, messaging, and other business systems; and from service providers supporting the requested service.
If you provide personal data about another person, you are responsible for having authority to provide it and for giving any notice, obtaining any consent, or establishing any other lawful basis required by applicable law and the signed agreement.
6. Purposes of processing
Ring2 uses personal data as reasonably necessary to:
- receive, validate, store, review, and respond to partner inquiries;
- assess partner, customer, workflow, market, and integration fit;
- arrange briefings, prepare requested materials or proposals, and manage pre-contract discussions;
- create, configure, provide, secure, support, and bill for contracted services and integrations;
- route calls, produce approved structured outcomes, support human transfer, and perform approved business-system actions;
- understand which pages, demonstrations, and outreach sources lead to commercial conversations and improve the website funnel;
- authenticate administrators and authorized users, diagnose failures, prevent abuse or fraud, and protect Ring2, its users, and its systems;
- manage supplier, finance, corporate, audit, insurance, and legal records; and
- comply with law, respond to lawful requests, and establish, exercise, or defend legal claims.
7. Legal grounds
Where applicable law requires a legal basis, Ring2 relies on one or more of the following: steps requested before entering into a contract; performance of a contract; compliance with legal obligations; legitimate interests in operating a secure B2B website, evaluating partner opportunities, communicating with business contacts, providing and improving services, and protecting legal rights; and consent where consent is required.
The partner or end customer is responsible for establishing and documenting the legal basis for its calling audience, call purpose, use of contact data, recording or transcription, automated follow-up, and any marketing communication. A partner inquiry is not treated as blanket consent to unrelated or indefinite marketing.
8. Business communications and preferences
When you request a briefing or contact Ring2, Ring2 may reply, arrange the requested discussion, provide relevant materials, and send closely related follow-up. Ring2 may send other relevant B2B information only where permitted by applicable law. You may ask Ring2 to stop non-essential promotional communications using the contact method in the message or the privacy contact identified in Section 18. Ring2 may continue to send service, security, billing, contractual, or legal messages needed for an active relationship.
9. Cookies, local storage, and external resources
The current public website does not deliberately install third-party advertising pixels, session replay, or a general-purpose third-party analytics tag. The first-party events described above are sent directly to Ring2's event endpoint and depend on the production event store being configured and available.
The website loads fonts from Google-hosted font services. A browser request for those font resources may disclose technical request data to Google under Google's own terms and privacy practices. The protected partner inbox stores an administrator's Basic authorization value in the current browser tab's session storage after sign-in and removes it on sign-out or when the tab session ends. The separate Tracking Notice describes the current implementation and must be updated before materially different analytics, advertising, or cross-site tracking technology is deployed.
10. Disclosure of personal data
Ring2 does not sell personal data through the current website. Ring2 may disclose personal data only as reasonably necessary to:
- authorized Ring2 personnel and contractors responsible for commercial follow-up, service delivery, finance, legal, security, or support;
- providers supporting website hosting, persistent storage, content delivery, telecommunications and numbers, speech processing, model inference, cloud infrastructure, security, email, scheduling, support, billing, and business-system integrations;
- the relevant partner, end customer, or authorized users where the data relates to their deployment or Ring2 acts on their instructions;
- professional advisers, auditors, insurers, investors, lenders, and transaction counterparties subject to appropriate confidentiality obligations; and
- courts, regulators, law-enforcement bodies, and other recipients when disclosure is required by law or reasonably necessary to protect rights, safety, or service integrity.
The named production subprocessor list, purposes, and processing regions must be completed before paid production processing and reflected in the applicable DPA or subprocessor schedule.
11. International transfers
Ring2's website, business operations, and service supply chain may involve providers or authorized teams in more than one country. Before production launch, the parties must document the approved service data region and cross-border flows in the Order Form, DPA, or subprocessor schedule. Where applicable law requires a transfer safeguard, the parties will use the mechanism stated in the signed DPA, such as applicable standard contractual clauses, an approved addendum, an adequacy mechanism, or another legally recognized safeguard.
12. Security and access
Ring2 applies measures appropriate to the data and the deployed implementation. The current website validates required form fields and field lengths, rejects oversized submissions, keeps production storage and administrator secrets on the server side, returns an error instead of a false success when persistence is unavailable, and protects the lead inbox with configured administrator credentials. Accepted inquiry records and first-party events can be viewed through the protected inbox API; accepted inquiry records can also be exported as CSV.
The current lead inbox does not yet provide per-user roles, access logs, lead assignment, correction or deletion controls, automated notification, CRM synchronization, CAPTCHA, rate limiting, or duplicate suppression. Those capabilities must not be represented as available until implemented and verified.
Security measures for contracted VoiceAgent services, including access control, encryption, logging, vulnerability management, backup, recovery, isolation, and incident response, must be stated in the signed DPA or security schedule and must match the deployed architecture. No certification or absolute security guarantee is made in this notice.
13. Retention, return, and deletion
Ring2 retains website inquiry data, related first-party events, business correspondence, and preference or suppression records only for as long as reasonably necessary for the purposes described in this notice, including evaluating the inquiry, managing the relationship, protecting the service, and meeting legal or recordkeeping requirements. The default periods for inquiry records, event records, suppression records, logs, and backups must be approved before publication.
VoiceAgent data is retained according to the signed Order Form, DPA, and configured service settings. Recording and transcript retention must be expressly approved for each deployment. At the end of the service or following a valid instruction, Ring2 will return or delete data as required by the signed agreement, subject to documented backup cycles, security records, legal holds, and legal retention duties. Deletion from active systems may not immediately remove restricted copies from protected backups; those copies will remain isolated and expire or be overwritten under the approved backup schedule.
14. Individual rights and requests
Depending on the applicable law and your location, you may have rights to request access, correction, deletion, restriction, objection, portability, withdrawal of consent, or information about certain automated processing. You may also have the right to complain to a competent data-protection authority. These rights may be subject to legal conditions and exceptions.
Requests about Ring2's website or Ring2's own business-contact records should be sent to the privacy contact identified in Section 18. Ring2 may request information needed to verify identity, authority, and the scope of the request. Where Ring2 processes VoiceAgent data for a partner or end customer, call participants should ordinarily direct the request to that organization; Ring2 will assist it as required by the DPA and applicable law.
15. Voice communications, AI disclosure, and recording
Ring2 does not determine that a proposed call is lawful merely because the technology can place or answer it. Before launch, the partner or end customer must review the target country's rules for telemarketing, business calling, do-not-call or suppression lists, calling hours, caller identity, AI disclosure, recording, transcription, number registration, and cross-border data handling.
Where required by law or the approved workflow, callers must be told the identity of the responsible organization, that they are interacting with an AI system, whether the call is recorded or transcribed, and how to reach a human or exercise an opt-out. The Acceptable Use and Voice Compliance page summarizes operational boundaries but does not replace market-specific legal review.
16. Children's data
The website and partner inquiry are intended for adult business representatives and are not directed to children. A VoiceAgent workflow must not intentionally target or collect personal data from children unless the responsible partner or end customer has completed the required legal review, obtained any required authorization, and entered a written service scope accepted by Ring2.
17. Changes and contract precedence
Ring2 may update this notice when the website, service, provider set, or legal requirements change. The page will state the updated date. If a change materially affects an active contracted service, notice will be provided as required by the signed agreement or applicable law.
For paid VoiceAgent services, the signed Partner Agreement or MSA, Order Form, DPA, Acceptable Use Policy, and service schedules control where they address the same processing in greater detail or state an agreed order of precedence.
18. Completion block before publication
Ring2 entity: legal name; registration jurisdiction and number; registered address.
Privacy contacts: monitored privacy email; legal-notice email; any required DPO or regional representative.
Retention schedule: approved periods for inquiries, events, suppression records, service data, recordings, transcripts, logs, and backups.
Service data map: launch regions; named production subprocessors and purposes; processing locations; approved transfer mechanism.