Privacy Policy
Effective August 6, 2026
This Privacy Statement explains how d (“Within,” “Within,” “we,” “us,” or “our”) collects, uses, discloses, and protects Personal Data when you visit our websites, communicate with us, request a demonstration, create or use an account, or use products and services that link to this Privacy Statement (collectively, the “Services”). “Personal Data” means information that identifies, relates to, describes, or can reasonably be linked with an individual. Personal Data does not include information that is lawfully de-identified or aggregated so that it cannot reasonably be linked to an individual.
Scope and Our Role
This Privacy Statement applies to Within websites, applications, software development kits (SDKs), dashboards, communications, and Services that link to or reference it. A separate or more specific notice may apply to a particular interaction or feature. If a specific notice conflicts with this Privacy Statement, the specific notice controls for that interaction.
When Within acts as a controller. Within generally acts as a controller or business when we collect and use information for our own business purposes, such as website operation, account administration, sales, marketing, billing administration, security, support, legal compliance, and managing our relationship with customers and partners.
When Within acts for a customer. Business customers may submit or make data available through the Services, including agent-session telemetry and data from connected customer systems. In those circumstances, the customer generally determines the purposes and means of processing, and Within acts as a processor or service provider under the customer’s instructions and our agreement with that customer. If your request concerns data controlled by a Within customer, you should ordinarily contact that customer directly. We will assist the customer as required by applicable law and our agreement.
Business use. The Services are designed for business customers and business-related use.
Personal Data We Collect
The Personal Data we collect depends on how you interact with us, which Services you use, the features a customer enables, and the information a customer chooses to submit or connect.
Information You Provide Directly
-
Contact and business information, such as name, business email address, telephone number, employer, job title, and business address.
-
Account information, such as account identifiers, login information, user role, preferences, and authentication information.
-
Sales and relationship information, such as demonstration requests, correspondence, meeting details, customer-support requests, survey responses, and information maintained in our customer relationship management systems.
-
Transaction and billing information, such as subscription plan, invoice and payment status, billing contact, and related records, may involve payment-card or banking details collected directly by Within’s payment providers, which are likely Stripe or another processor that Within may designate. Additionally, payments may be made via wire transfer or ACH, at Within’s discretion, with relevant bank information provided on invoices.
-
Other information you choose to provide, including information submitted in free-text fields, support tickets, forms, emails, or meetings.
Sensitive Personal Data. Unless expressly agreed in writing, the Services are not intended for highly sensitive or specially regulated data, such as government identification numbers, consumer financial account credentials, payment-card data, protected health information, biometric identifiers, precise geolocation, authentication secrets, or Personal Data about children.
Information Collected Through the Services on Behalf of Customers
Depending on customer configuration and integrations, the Services may process:
-
Agent and MCP-session telemetry, such as session identifiers, timestamps, tool names, tool calls, tool-call sequences, tool arguments or parameters, retries, errors, latency, quota events, success or failure signals, and related technical metadata.
-
Account and user identifiers used to associate activity with a customer account, workspace, organization, or user.
-
Commercial and product outcomes from connected customer systems, such as renewal, churn, upgrade, plan, product-use, account-status, customer-success, or billing events.
-
CRM, billing, account, and product-system data that a customer authorizes Within to access or receive through an integration.
-
Scores, inferences, trends, alerts, and recommendations generated by the Services from the information above.
Customers control the information they submit, the systems they connect, and how they use the Services. Customers are responsible for providing any required notices and obtaining any required permissions before making Personal Data available to Within.
Information Collected Automatically
When you use our websites or Services, we and our service providers may automatically collect information such as:
-
Internet Protocol address, browser type, device type, operating system, language, approximate location derived from IP address, and device or online identifiers.
-
Website and Service activity, such as pages viewed, links clicked, referral URLs, session duration, feature use, error logs, and interactions with emails or communications.
-
Cookies, pixels, tags, local storage, SDKs, logs, and similar technologies, as described in the “Cookies and Similar Technologies” section.
Information from Third Parties
We may receive Personal Data from business customers, authorized integrations, service providers, business partners, public sources, event organizers, referral sources, and other third parties. We may combine this information with information collected directly from you or through the Services where permitted by law.
How We Use Personal Data
We may use Personal Data for the following purposes:
-
Provide, operate, configure, maintain, and support the Services.
-
Create and administer accounts, authenticate users, manage subscriptions, process transactions, and provide customer service.
-
Collect and analyze agent-session telemetry and connect it with customer-authorized commercial or product outcomes to generate account-health, churn, renewal, upgrade, and related business signals.
-
Develop, test, troubleshoot, secure, monitor, and improve our websites and Services, including evaluating performance and reliability.
-
Communicate with you about the Services, your account, security, support, events, updates, and administrative matters.
-
Send marketing communications and personalize business outreach, subject to applicable law and your choices.
-
Protect Within, our customers, users, and others; detect, investigate, and prevent fraud, abuse, security incidents, and violations of our terms.
-
Comply with law, respond to lawful requests, establish or defend legal claims, and enforce our agreements.
-
Create aggregated, statistical, or de-identified information for analytics, benchmarking, product planning, and other lawful business purposes.
-
Carry out another purpose disclosed at the time of collection or with your consent.
Legal bases for EEA, UK, and similar jurisdictions. Where required, our legal bases may include performing a contract, pursuing legitimate interests, complying with legal obligations, and consent. Our legitimate interests may include operating and securing our business, improving the Services, communicating with business contacts, and understanding use of our products.
Artificial Intelligence and Automated Analysis
Within uses machine learning, statistical techniques, and other automated methods to analyze agent-session activity and customer-authorized business outcomes. These methods may generate account-health scores, predictions, classifications, alerts, explanations, or recommended actions related to matters such as churn risk, renewal likelihood, expansion potential, product friction, or customer engagement.
Model inputs and outputs. Inputs may include the telemetry, identifiers, integration data, and outcomes described above. Outputs are probabilistic and may be incomplete or inaccurate. Customers should apply appropriate human judgment and should not treat a score or recommendation as the sole basis for an important decision about an individual.
Customer-specific and general model improvement. Within may use customer data to operate, evaluate, and improve the customer’s configured Services. CUSTOMER DATA IS NOT USED TO TRAIN SHARED OR GENERAL MODELS..
Third-party AI providers. Within may use third-party artificial intelligence, machine learning, or foundation model providers in connection with the Services. Within will ensure that any Customer Data provided to such providers is limited to what is reasonably necessary to provide the Services and is subject to contractual confidentiality, security, retention, and data protection obligations consistent with this Agreement.
High-impact decisions. The Services are not designed or authorized for use as the sole basis for decisions that produce legal or similarly significant effects concerning an individual, including decisions about employment, credit, housing, insurance, education, healthcare, or access to essential services.
How We Disclose Personal Data
We may disclose Personal Data in the following circumstances:
-
Service providers and subprocessors. We may disclose information to vendors that provide hosting, cloud infrastructure, analytics, customer support, communications, payment processing, security, professional services, and other functions for us. These providers are authorized to process Personal Data only for permitted purposes and subject to contractual obligations appropriate to their role.
-
Customers and account administrators. Information and Service outputs may be available to the business customer that provided or authorized the data and to its designated administrators and users.
-
Customer-authorized integrations. We may exchange information with third-party systems when a customer enables or directs an integration.
-
Professional advisers. We may disclose information to lawyers, auditors, insurers, financial advisers, and similar professional advisers where reasonably necessary.
-
Corporate transactions. We may disclose information in connection with an actual or proposed merger, acquisition, financing, reorganization, bankruptcy, sale of assets, or similar transaction.
-
Legal, safety, and rights. We may disclose information when we believe disclosure is required by law or reasonably necessary to respond to legal process, protect rights or safety, investigate wrongdoing, or enforce agreements.
-
With your direction or consent. We may disclose information where you or the relevant customer directs us to do so or provides consent.
-
Aggregated or de-identified information. We may disclose information that cannot reasonably be used to identify an individual.
Sale, sharing, and targeted advertising. Within does not sell personal data and does not share personal data for cross-contextual advertising.
Cookies and Similar Technologies
We and our service providers may use cookies, pixels, tags, SDKs, local storage, web beacons, and similar technologies to operate our websites and Services, remember settings, authenticate users, understand usage, improve performance, measure communications, prevent fraud, and, if applicable, support advertising.
These technologies may include:
-
Strictly necessary technologies required for security, authentication, network management, and core functionality.
-
Functional technologies that remember preferences and provide enhanced features.
-
Analytics technologies that help us understand use, diagnose issues, and improve our websites and Services.
-
Advertising or marketing technologies, if used, that measure campaigns or help deliver more relevant communications.
Cookie controls. You can manage certain cookie choices through the site’s cookie settings and/or through browser settings. Blocking some cookies may affect website or Service functionality.
Security
We use reasonable administrative, technical, and organizational safeguards designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. Depending on the system and risk, safeguards may include encryption in transit and at rest, access controls, least-privilege practices, authentication, logging and monitoring, vulnerability management, backups, incident-response procedures, personnel confidentiality obligations, and review of service providers.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for maintaining the confidentiality of your credentials and promptly notifying us if you suspect unauthorized access to your account.
Data Retention
We retain Personal Data for as long as reasonably necessary to provide the Services, maintain our business relationship, fulfill the purposes described in this Privacy Statement, comply with legal and contractual obligations, resolve disputes, protect our systems, and enforce our agreements. Retention periods vary based on the type of data, customer instructions, account status, legal requirements, and operational needs.
When Personal Data is no longer needed, we may delete, anonymize, or securely dispose of it. Data in backups may remain until overwritten or deleted through our ordinary backup cycle, subject to appropriate safeguards and restrictions on further use.
International Data Transfers
Within and its service providers may process Personal Data in the United States and other countries where we or our providers operate. Those countries may have data-protection laws that differ from the laws where you live.
Where required, we use recognized legal mechanisms and safeguards for international transfers, such as adequacy decisions, standard contractual clauses, contractual commitments, and supplementary security measures.
Privacy Rights and Requests
Depending on where you live and subject to applicable exceptions, you may have rights to request access to Personal Data, correction, deletion, portability, restriction of processing, or additional information about our practices. You may also have rights to object to certain processing, withdraw consent, opt out of certain sales, sharing, or targeted advertising, limit certain uses of sensitive Personal Data, and appeal a decision concerning a privacy request.
How to submit a request. Submit a request through hello@getwith.in. Please describe your relationship with Within and the request you are making. We may request information reasonably necessary to verify your identity, authority, and the Personal Data involved.
Requests involving customer-controlled data. If Within processes the relevant Personal Data on behalf of a business customer, we may direct your request to that customer or ask you to contact the customer directly. We will support the customer’s response as required by applicable law and our agreement.
We will not discriminate against you for exercising an applicable privacy right. We may decline or limit a request where permitted by law, and we will explain our decision where required.
Additional U.S. State Disclosures
During the preceding 12 months, Within may have collected the categories of Personal Data described in this Privacy Statement from the sources described above, used them for the stated business and commercial purposes, and disclosed them to the categories of recipients described above.
California categories. Depending on the interaction, these categories may include identifiers; customer-record information; commercial information; internet or electronic-network activity; professional or employment-related information; inferences; and account login information that may be treated as sensitive Personal Data.
Children’s Privacy
Our websites and Services are intended for businesses and are not directed to children. We do not knowingly collect Personal Data from children under 13. If you believe a child has provided Personal Data to us, please contact us so we can review and take appropriate action.
Third-Party Websites and Integrations
Our websites and Services may link to or integrate with third-party websites, applications, platforms, and services. Their privacy practices are governed by their own notices and agreements, not this Privacy Statement. We encourage you to review those notices before providing information or enabling an integration.
Changes to This Privacy Statement
We may update this Privacy Statement from time to time. We will post the revised version with an updated “Last Updated” date. If changes are material, we may provide additional notice, such as through the Services, by email, or through another appropriate method.
15. Contact Us
Questions, complaints, or privacy requests may be submitted using the following contact information: hello@getwith.in.