Legal
Privacy Policy
This policy explains how Tuolen Technologies handles personal data when you visit our websites, use Tuolen AI, create an account, or communicate with us.
- Effective date
- 25 September 2026
- Company
- Tuolen Technologies
Our role
Tuolen Technologies is registered in Nigeria and is responsible for personal data used to operate our websites, accounts, sales, support, security, and business administration.
When an organisation uses Tuolen AI to communicate with its customers, employees, or users, that organisation normally decides why and how conversation data is used. In that case, the organisation is the controller and Tuolen Technologies processes the data on its instructions. Requests about that data should normally be directed to the organisation that deployed the Tuolen agent.
Data we collect
Depending on how you use Tuolen AI, we may collect:
- Account data, such as your name, work email, telephone number, organisation, role, credentials, preferences, and team membership.
- Transaction data, such as subscription, invoice, payment status, and limited payment metadata.
- Communications, including sales enquiries, support requests, surveys, and calls or meetings where appropriate notice is given.
- Service and device data, including IP address, browser information, timestamps, pages and features used, diagnostic events, and security logs.
- Configuration and integration data, including agent settings, encrypted integration credentials, connected-channel metadata, and integration identifiers.
- Customer Content, including prompts, messages, files, knowledge documents, tool outputs, audio, and transcripts submitted to the service.
- Usage, reliability, fraud-prevention, and security information derived from use of the service.
Please do not submit sensitive data unless it is necessary, lawful, authorised, and supported by an appropriate Tuolen plan or written agreement.
Where data comes from
- Directly from you when you create an account, configure the service, or contact us.
- From the organisation that provides your account or deploys a Tuolen agent.
- From customer-authorised communication channels and integrations.
- Automatically from devices, browsers, and service activity.
- From service providers, partners, and public sources where lawful.
How we use data
We use personal data to provide, authenticate, secure, maintain, and support Tuolen AI; administer accounts and commercial relationships; operate customer-selected features; answer enquiries; prevent fraud and abuse; improve reliability and accessibility; comply with law; enforce agreements; and establish or defend legal claims.
Depending on the circumstances and applicable law, we rely on contract, steps requested before entering a contract, legal obligations, legitimate interests, consent, or a customer's documented instructions. Where we rely on consent, it may be withdrawn without affecting earlier lawful processing.
AI and automated processing
Tuolen AI can generate replies, summaries, classifications, recommendations, and transcriptions. AI output may be inaccurate, incomplete, or biased and should be reviewed appropriately.
Tuolen AI is not intended to make solely automated decisions that produce legal or similarly significant effects unless expressly approved in writing and supported by appropriate safeguards. Customers decide how their agents are configured and deployed.
International transfers
Data may be processed outside your country. Where required, we use recognised transfer mechanisms and supplementary safeguards, which may include adequacy decisions, approved contractual clauses, transfer assessments, encryption, and access controls.
Retention
We retain personal data only as long as reasonably necessary for the purposes described in this policy, contractual commitments, security, dispute resolution, and legal requirements. Customer Content is retained according to the applicable customer agreement, service configuration, and valid deletion instructions.
Security
We use technical and organisational safeguards designed to protect personal data, including access controls, tenant-scoped authorisation, encryption of stored integration credentials, logging, rate limiting, and security controls for outbound requests. No system can be guaranteed completely secure.
Your rights
Subject to applicable law, you may have rights to be informed, access data, correct data, delete data, restrict processing, object, withdraw consent, obtain portable data, complain to a regulator, and request review of certain automated decisions. We may verify identity and may lawfully limit or refuse a request.
For data controlled by a Tuolen customer, contact that customer first. For data controlled by Tuolen Technologies, contact hello@tuolen.com. Nigerian data subjects may also complain to the Nigeria Data Protection Commission.
Children
Tuolen's direct account services are intended for people aged 18 or older. Customers must not knowingly deploy Tuolen AI to collect children's data without an appropriate lawful basis, notices, consents, age controls, and written approval where required.
Changes and contact
We may update this policy and will post the revised version with a new effective date. Material changes will receive additional notice where required.
See our Cookie and Storage Policy for details about browser storage and similar technologies.
Questions, privacy requests, and security reports may be sent to hello@tuolen.com.
