Privacy policy.
This policy explains what personal data Medra processes when our agents hold conversations on behalf of our clients, why we process it, how long we keep it and what rights you have. It is written to be read, not filed. Where a legal term is unavoidable, it is defined in section 2.
In plain language
- We process data for our clients, not for ourselves.
When an agent messages or calls you, it does so on behalf of a company you already have a relationship with. That company decides why. We process under its instructions.
- Conversations are the data.
Messages, call recordings and transcripts, the phone number or email they arrive from, and the account context the client shares with us to answer you correctly.
- We do not sell personal data.
We never sell, rent or trade personal data, and we do not use your conversations to advertise to you.
- You can ask, correct, delete and object.
In every conversation you can ask to stop. Requests are handled within the legal deadline of your country, and faster where we can.
1.Who we are and how to reach us
Medra is the trading name of MedraApp LLC, a conversational AI company headquartered in Buenos Aires, Argentina, and part of the CESI.AI group. We build and operate AI agents that hold commercial conversations, over WhatsApp, voice and email, on behalf of enterprise clients in Latin America and other regions.
Medra has appointed a Data Protection Officer. Questions about this policy or about your data can be sent to the DPO and our privacy team. Requests are acknowledged within five business days.
2.Definitions
| Term | Meaning in this policy |
|---|---|
| Client | The company that has engaged Medra to hold conversations with its customers or prospects. |
| End user, you | The person our agent messages or calls: a customer, prospect or contact of a Client. |
| Agent | The AI system Medra builds and operates, which reads, writes and speaks in a conversation. |
| Conversation data | Messages, audio, transcripts, metadata (timestamps, channel, delivery status) and the agent's internal notes about a conversation. |
| Account context | Information a Client shares with Medra so the agent can answer correctly: order status, balance, plan, previous interactions. |
| Controller / processor | The party that decides why and how data is processed (controller) and the party that processes it on that party's instructions (processor). Terminology from GDPR; Ley 25.326 and LGPD use equivalent concepts. |
3.Our role: processor and controller
For conversations we hold on behalf of a Client, the Client is the controller and Medra is the processor. The Client determines the purpose, the audience and the message; we process conversation data and account context only under its documented instructions, set out in a data processing agreement signed with every Client.
Medra is the controller for a narrower set of data: the personal data of our own Clients' staff who use the Medra Console, visitors to medra.app, applicants to our team, and the aggregated, anonymised statistics we derive from conversations to improve the platform. Sections 4 to 11 apply to both roles unless stated otherwise.
4.What data we process
| Category | Examples | Source |
|---|---|---|
| Identifiers | Phone number, email address, name as shown on the channel, Client account ID. | Client · the channel |
| Conversation data | Text messages, voice notes, call recordings and transcripts, attachments you send, timestamps, delivery and read status. | You · the agent |
| Account context | Order, invoice or balance status; plan or tier; prior tickets; eligibility signals the Client shares to qualify or assist you. | Client |
| Derived data | Intent and sentiment labels, lead tier, escalation flags, summaries the agent writes for the Client's team. | The agent |
| Console usage | Login, role, actions taken by Client staff in the Medra Console, device and IP for security logs. | Client staff |
| Website | Pages visited on medra.app, referrer, approximate location from IP, form submissions. | Visitors |
We do not intentionally collect special categories of data (health, religion, political opinion, biometric identification, and equivalents under local law). If you volunteer such information in a conversation, it is retained only as part of that conversation, under the Client's instructions, and is never used to derive labels or profiles.
medra.app sets no advertising or cross-site tracking cookies and runs no third-party analytics, so a browser's Do Not Track or Global Privacy Control signal is honoured by default. The booking page embeds Cal.com, which may set its own cookies under its own privacy policy when you book a meeting.
5.Why we process it and on what basis
- To hold the conversation the Client asked us to hold: answer, qualify, onboard, assist, remind or collect. Basis: the Client's contract with you, its legitimate interest, or your consent where the channel or the law requires it (for example, opt-in for marketing messages on WhatsApp).
- To route a conversation to a person when the agent cannot or should not decide. Basis: the same as 5.1.
- To measure whether the agent did its job, response rates, resolution, recovery, including holdout groups. Basis: the Client's legitimate interest in evaluating a service it pays for.
- To improve the platform, using aggregated and anonymised data that cannot be linked back to you. Basis: Medra's legitimate interest. Raw conversation data is not used to train general-purpose models.
- To secure the platform and comply with law, including record-keeping duties under telecommunications and consumer protection rules. Basis: legal obligation and legitimate interest.
6.Voice recordings and AI processing
When the agent places or receives a call, you are told at the start that you are speaking with an automated assistant on behalf of the Client, and that the call may be recorded. You may ask for a person at any point; the agent is required to comply.
Conversations are processed by large language models and speech models. Some of those models are operated by third-party providers described in section 8, under written agreements that bind them to the confidentiality of the data. The agent makes recommendations, a lead tier, a payment plan, a next step, but decisions with legal or similarly significant effect on you (for example, refusing a service or reporting a default) are taken by the Client, not by the agent, and you may request human review of any such decision.
7.Retention
- Conversation data, call recordings and account context: for as long as the Client's contract with Medra is in force, then deleted within 90 days of the contract ending. Clients may instruct earlier deletion.
- Console security and system logs: 1 year.
- Website visits and enquiries: only for as long as they have a business use, then deleted or de-identified.
- Aggregated, anonymised statistics: indefinitely, because they no longer identify anyone.
Data subject to a legal hold or a legal duty to retain is kept for as long as that duty requires. Otherwise, personal data is deleted on a verified request from the person it concerns. Retention periods are reviewed every year.
8.Sharing and sub-processors
We share personal data with: the Client on whose behalf the conversation is held; sub-processors that provide infrastructure, messaging, telephony and AI model capacity under written contracts; and authorities when the law requires it. No sub-processor receives personal data until it has passed a risk assessment and signed a written agreement setting out its security and confidentiality obligations, and each one is reviewed at least once a year. The current list of sub-processors, with their role and location, is available on request from security@medra.app.
We never sell personal data. We do not share conversation data between Clients.
9.International transfers
Our agents operate in more than nineteen countries and some sub-processors host data outside the country where you live. Where data leaves a jurisdiction, we rely on the mechanisms that jurisdiction recognises: adequacy decisions where they exist, standard contractual clauses (EU) or the model clauses approved by the Agencia de Acceso a la Información Pública (Argentina), and the equivalent instruments under LGPD. Clients may require regional hosting, and several do.
10.Your rights
Depending on where you live, you have some or all of the rights below. We honour them regardless of the legal basis on which they arise, and we do not ask why you are exercising them.
- AccessA copy of the personal data we hold about you, in a readable format.
- RectificationCorrection of data that is inaccurate or incomplete.
- ErasureDeletion of your data where no legal duty requires us to keep it.
- Objection and opt-outReply "stop" in any channel and the agent stops. This is honoured immediately and passed to the Client.
- Restriction and portabilityLimits on processing while a dispute is resolved; your data in a machine-readable format.
- Human reviewA person reviews any decision that affects you, on request.
Where Medra acts as processor, we forward your request to the Client within two business days and assist it in responding. Where the CCPA applies, California residents have the rights it grants, including the right not to be discriminated against for exercising them, and can exercise them at privacy@medra.app. Medra does not sell or share personal information as that law defines those terms. You may also complain to your supervisory authority: in California, the California Privacy Protection Agency; in Argentina, the Agencia de Acceso a la Información Pública; in the EU, the authority of your member state; in Brazil, the ANPD.
11.Security
Client data is encrypted at rest (AES-256), in transit over public networks, and in backups. Access follows least privilege and is role-based, protected by multi-factor authentication for privileged accounts, logged, and reviewed every quarter. It is removed within 24 business hours when someone leaves. Production is separated from development, and production customer data is not used for testing without management approval. The control set and the current certification status are published in our Trust Center; how every agent is attacked before release is shown on the home page. If a breach affects your data, we report it to the Client, to you and to the relevant authority without undue delay, as our contracts and the applicable law require.
12.Changes to this policy
We revise this policy when the law, our services or our sub-processors change. Each version carries a number and an effective date at the top of the page. Material changes are notified to Clients at least 30 days in advance and, where the agent has an open conversation with you, announced in that conversation.
Draft for legal review. Deadlines, retention periods and authority references must be confirmed by counsel in each operating jurisdiction before publication.