Back to home

Privacy

Privacy Policy

How Chirps and Monzed process account information, Customer Content, website visitor data, voice interactions, and optional tracking.

Effective and last updated: August 13, 2026

This is the English reference version of the policy. Translations, where available, are provided for convenience; mandatory local consumer and privacy rights always remain unaffected.Read the Terms of Service.

1. Scope, operator, and contact

This Privacy Policy explains how Monzed, the operator of Chirps ("Chirps", "we", "us", or "our"), handles personal data when you use chirps.cc, the Chirps dashboard, embedded widgets, voice features, and related support or communications services (together, the "Service").

For our own website, account, billing, security, and commercial activities, Monzed is the data controller. Our contact details are Monzed, Tornimae tn 5, Kesklinna linnaosa, Tallinn, Harju maakond 10145, Estonia. For privacy questions or requests, contact [email protected].

When a business customer uses Chirps to interact with its visitors, customers, or prospects, that business is generally the controller of the conversation and lead data, and Monzed generally acts as its processor. Section 3 explains this distinction.

2. Personal data we collect

We collect data you provide, data generated through use of the Service, and limited technical data needed to operate it. The categories may include:

  • Account and workspace data: name, email address, profile image, authentication information, workspace membership, preferences, and communications with us.
  • Billing and commercial data: plan, invoices, payment status, tax information where required, and transaction identifiers. Payment card details are handled by our payment processor and are not stored by Chirps.
  • Customer Content: prompts, messages, uploaded files, URLs, knowledge sources, forms, bookings, feedback, leads, assistant configuration, and other material a customer submits to the Service.
  • End-user interaction data: chat messages, contact details voluntarily provided in a widget or form, session identifiers, device and browser details, IP-derived location, timestamps, referral URLs, and event/activity logs.
  • Voice data: telephone numbers, call metadata, call transcripts, recordings, and related voice interaction content when voice or call-recording features are enabled and used.
  • Support and security data: support requests, audit logs, diagnostic data, fraud-prevention signals, and information needed to investigate misuse or keep the Service secure.

Please do not submit special-category, highly sensitive, or regulated personal data through Chirps unless you have assessed that use, obtained every required authorization, and have an appropriate written agreement with us where law requires one.

3. Customer data and privacy roles

Our business customers decide why and how their assistants collect and use Customer Content and end-user interaction data. They are responsible for their own privacy notices, lawful basis, consent choices, retention rules, and responses to their end users.

We process that Customer Content on the customer’s documented instructions to provide, secure, support, and improve the Service. We may also process limited data as an independent controller where necessary for account administration, billing, abuse prevention, security, legal compliance, and service analytics.

If you are an end user of one of our customers’ assistants, please contact that customer first to exercise your privacy rights. We will assist our customer where applicable and as required by law.

4. How and why we use data

We use personal data to provide and administer the Service; authenticate users; process payments; configure and run assistants; respond to requests; provide support; maintain security; prevent fraud and abuse; measure product performance; send service communications; and comply with legal obligations.

Where the GDPR or similar law applies, we rely on performance of a contract, our legitimate interests in operating a secure and useful service, compliance with legal obligations, and consent where required. Where we rely on consent, you may withdraw it at any time; this does not affect processing already carried out before withdrawal.

5. AI, automation, and voice features

Chirps uses third-party and proprietary technical services to generate responses, summarize conversations, process knowledge sources, and provide voice and workflow features. AI-generated output may be inaccurate, incomplete, or unsuitable for a particular purpose. Customers remain responsible for reviewing outputs and for decisions made using them.

We process the inputs, configuration, and relevant context needed to deliver the requested AI feature. We do not intentionally use Customer Content to train generally available foundation models unless we have an explicit agreement or permission to do so. AI and infrastructure providers may process data as subprocessors under their applicable terms and data-processing commitments.

Customers using voice, calling, recordings, SMS, or email features must give all notices and obtain all consents required by applicable communications, recording, employment, privacy, and consumer-protection laws before using those features.

6. Cookies and similar technologies

We use necessary cookies and local storage to keep the website, dashboard, authentication, language, workspace, and security functions working. We ask for consent before enabling optional analytics or marketing technologies where consent is required.

Our public-site consent manager lets you accept, reject, or manage optional categories. Analytics may include product analytics and web analytics; marketing may include affiliate attribution. The Chirps widget may also present its own consent choices when a customer enables that feature. Necessary storage remains active because it is required for the service to function.

You can change browser settings or your available cookie preferences at any time. Blocking necessary storage can prevent parts of Chirps from working correctly.

7. Sharing, subprocessors, and connectors

We share data only as needed to operate the Service, comply with law, or with your direction. Recipients may include providers of hosting, database, authentication, payment, email delivery, optional analytics, AI processing, voice and telecommunications, customer support, and professional-advisory services. We may also use other service providers that support the Service.

Customers may connect third-party services and custom APIs to an assistant. Once enabled, the relevant data may be sent to or received from that provider under the customer’s instructions. The customer is responsible for reviewing the connector, its permissions, the data it receives, and the provider’s own terms and privacy policy.

We may disclose information when reasonably necessary to protect rights, safety, security, or property; investigate abuse; comply with a legal request; or complete a corporate transaction, subject to applicable law.

8. International transfers

Chirps and its providers may process data in the European Economic Area and in other countries where we or our providers operate. Where a transfer from the EEA, UK, or Switzerland requires a transfer mechanism, we use an appropriate safeguard, such as an adequacy decision, standard contractual clauses, or another valid mechanism, as applicable.

9. Security and retention

We use reasonable technical and organizational measures designed to protect personal data, including access controls, authentication, encryption in transit where supported, monitoring, and least-privilege practices. No system or transmission can be guaranteed to be perfectly secure; customers should use strong credentials, restrict workspace access, and protect their own connected systems.

We keep data for as long as necessary for the purposes described here, to meet contractual and legal obligations, resolve disputes, enforce agreements, and maintain security. Retention can vary by plan, configuration, legal requirement, and customer instruction. After account termination or a valid deletion request, data is deleted or anonymized within a reasonable period, subject to backups, legal retention duties, and security records.

10. Your rights and choices

Depending on your location and the circumstances, you may have rights to request access, correction, deletion, restriction, objection, portability, and withdrawal of consent. You may also have the right to complain to a competent data-protection authority.

To make a request about data for which Monzed is controller, email [email protected]. We may need to verify your identity and authority before responding. Rights are not absolute and may be limited by applicable law. We respond within the period required by applicable law.

For Customer Content processed on behalf of a Chirps customer, contact that customer first. We will direct the request appropriately or assist the customer as required by our agreement and applicable law.

11. Marketing and children

You can opt out of non-essential marketing emails through the unsubscribe link in the email or by contacting us. We may still send operational, security, billing, or account messages.

Chirps is not directed to children. Do not use the Service or configure it to knowingly collect personal data from children unless you have a lawful basis, appropriate safeguards, and all required parental or guardian consents. If you believe a child has provided data unlawfully, contact us so that we can investigate.

12. Changes to this policy

We may update this Privacy Policy to reflect changes in the Service, law, or our data practices. We will post the updated version with a new effective date and, where required, provide additional notice. Your continued use after the effective date is subject to the updated policy to the extent permitted by law.