Legal

Privacy Policy

Last updated: September 9, 2026

1. Who We Are and What This Policy Covers

Mazed Labs, Inc. ("Mazed", "we", "us") is a Delaware corporation headquartered in San Francisco, California. We build a multimodal AI agent platform for voice and video interactions.

This Privacy Policy explains how we handle personal data when you visit mazed.ai and its subdomains (the "Site"), contact us, book a demo, or use the Mazed platform and APIs (the "Service"). It applies worldwide and includes the additional disclosures required by the EU and UK General Data Protection Regulations ("GDPR"), the Swiss Federal Act on Data Protection, and US state privacy laws such as the California Consumer Privacy Act as amended by the CPRA ("CCPA").

Where our customers use the Service to process data about their own end users (for example, callers who speak with an agent built on Mazed), we act as a processor or service provider on the customer's behalf. That processing is governed by our agreement with the customer, including a Data Processing Addendum ("DPA"), and the customer's own privacy notice. See the section "Customer Data Processed Through the Platform" below.

2. Personal Data We Collect

Information you provide to us directly:

  • Contact and account details such as your name, work email address, company name, job title, password and billing information when you create an account, request a demo, subscribe to updates or contact us.
  • Demo bookings made through our scheduling provider (Cal.com), including the date, time, time zone and any notes you add.
  • Communications you send us by email, in-product chat or through forms, including support requests and feedback.
  • Content you upload to the Service in order to configure agents, such as knowledge-base documents, prompts, integrations and voice samples (subject to the Voice Cloning Agreement).

Information collected automatically when you use the Site or Service:

  • Server logs including IP address, browser type and version, operating system, referring URL, pages viewed, timestamps and error diagnostics.
  • Approximate location derived from your IP address (country and, in the US, state). We use this to display pricing in your local currency and to show the cookie consent flow that applies in your jurisdiction. We do not store your IP address for this purpose.
  • Cookies and similar technologies described in our Cookie Policy, including your language preference and your cookie choices.
  • Aggregated, cookieless usage statistics collected by Vercel Analytics when you have allowed analytics.

Information from third parties: we may receive business contact data from our customers when they invite you to a workspace, from identity providers you choose to sign in with, and from publicly available professional sources for sales outreach in accordance with applicable law.

3. How We Use Personal Data and Our Legal Bases

We use personal data for the following purposes. Where GDPR applies, the legal basis for each purpose is indicated in brackets.

  • Providing, operating and securing the Site and Service, including authentication, billing and customer support [performance of a contract; legitimate interests].
  • Responding to demo requests, enquiries and support tickets [performance of a contract or steps prior to entering into one; legitimate interests].
  • Improving and developing our products, including debugging, analysing aggregated usage trends and testing new features [legitimate interests; consent for analytics cookies where required].
  • Sending service notices, security alerts and, where permitted, information about products and events. You can opt out of marketing emails at any time via the unsubscribe link [legitimate interests; consent where required by law].
  • Detecting, preventing and investigating fraud, abuse, security incidents and violations of our Terms of Service [legitimate interests; legal obligation].
  • Complying with legal obligations, responding to lawful requests from public authorities and enforcing our agreements [legal obligation; legitimate interests].
  • Displaying region-appropriate pricing and legal notices based on approximate location [legitimate interests].

We do not use personal data collected through the Site for automated decision-making that produces legal or similarly significant effects about you. We do not train foundation models on your account data or customer content without a separate agreement.

4. Cookies and Analytics

The Site uses a small number of first-party cookies that are strictly necessary (your language and your cookie choices) and, subject to your consent where required, Vercel Analytics for aggregated page-view statistics. Vercel Analytics does not set cookies, does not use persistent identifiers and does not track you across sites.

Visitors in the EEA, United Kingdom and Switzerland (and any location we cannot determine) are asked for consent before analytics runs. Visitors in the United States receive a notice and can opt out at any time; we also honor the Global Privacy Control browser signal as an opt-out. You can change your choice at any time via "Cookie Settings" in the footer. Full details are in our Cookie Policy.

5. How We Share Personal Data

We do not sell personal data and we do not share it for cross-context behavioral advertising. We share personal data only with:

  • Service providers (processors) that host and run our infrastructure and business tooling, such as Vercel Inc. (hosting and analytics), Cal.com, Inc. (demo scheduling), cloud, email, payment, customer-support and telephony providers, and the LLM and speech providers that power the Service. These providers may only process data on our documented instructions.
  • Our customers, when you interact with an agent or workspace they operate, as described in their own privacy notice.
  • Professional advisers such as lawyers, auditors and insurers under confidentiality obligations.
  • Public authorities, regulators or other third parties where required by law, to protect the rights, property or safety of Mazed, our users or others, or to enforce our agreements.
  • A successor entity in connection with a merger, acquisition, financing or sale of assets, subject to this policy.

A current list of the sub-processors used for the Service is available on request from [email protected] and is provided to customers as part of the DPA.

6. International Data Transfers

We are based in the United States and our providers may process data in the US and other countries. Where we transfer personal data from the EEA, the United Kingdom or Switzerland, we rely on the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum and the Swiss adaptations of those clauses, together with supplementary measures where appropriate. Copies of the relevant transfer mechanism can be requested at [email protected].

7. Data Retention

We keep personal data only for as long as needed for the purposes described above. In general: account data is kept for the life of the account and deleted or anonymized within 90 days after closure; demo and enquiry records are kept for up to 24 months; server logs are kept for up to 30 days unless needed for a security investigation; and billing records are kept as long as required by tax and accounting law. Customer content is retained according to the customer's configuration and the DPA.

8. Security

We apply technical and organizational measures appropriate to the risk, including encryption in transit and at rest, access controls and least-privilege principles, logging and monitoring, and vendor due diligence. No system is perfectly secure; if you believe your data has been compromised, please contact [email protected] immediately.

9. Your Rights in the EEA, United Kingdom and Switzerland

If you are located in the EEA, the United Kingdom or Switzerland, you have the right to:

  • Access the personal data we hold about you and receive a copy.
  • Rectify inaccurate or incomplete data.
  • Erase your data in certain circumstances ("right to be forgotten").
  • Restrict or object to processing, including processing based on legitimate interests and any direct marketing.
  • Receive your data in a portable, machine-readable format.
  • Withdraw consent at any time, without affecting processing that took place before withdrawal.
  • Lodge a complaint with your local supervisory authority. In the UK this is the Information Commissioner's Office (ico.org.uk); a list of EU authorities is available at edpb.europa.eu.

To exercise any of these rights, email [email protected]. We will respond within one month, extendable by two further months for complex requests as permitted by law. We may need to verify your identity before acting on a request.

10. Your Rights Under US State Privacy Laws

Residents of California and other US states with comprehensive privacy laws (including Virginia, Colorado, Connecticut, Utah, Texas and Oregon) have rights to know what personal information we collect and how it is used and shared, to access and delete it, to correct inaccurate information, to obtain a portable copy, and to opt out of the sale or sharing of personal information and of targeted advertising. You also have the right not to be discriminated against for exercising these rights.

In the preceding 12 months we collected the following categories of personal information as defined by the CCPA: identifiers (name, email, IP address); customer records (billing details); commercial information (subscriptions and demo requests); internet or network activity (log and usage data); approximate geolocation (country and state derived from IP); professional information (company and job title); and audio or visual information you choose to upload to the Service. We collect these from you directly, automatically from your device, and from our customers and partners, for the business purposes described above. We do not sell personal information, we do not share it for cross-context behavioral advertising, and we have no actual knowledge of selling or sharing the personal information of consumers under 16.

We honor Global Privacy Control signals as a valid request to opt out. You can also use the "Do Not Sell or Share My Personal Information" link in the footer to opt out of analytics, or email [email protected]. Authorized agents may submit requests on your behalf with written permission. We will verify requests by matching the information you provide against our records and respond within 45 days, extendable once by a further 45 days where permitted.

11. Customer Data Processed Through the Platform

When our customers deploy agents built on Mazed, the conversations, recordings, transcripts and other content of their end users ("Customer Data") are processed under the customer's instructions. The customer is the controller or business responsible for that data, and their privacy notice governs how it is collected and used. We process Customer Data only to provide the Service, prevent abuse and comply with law, as set out in our DPA and Terms of Service.

If you have interacted with a Mazed-powered agent and wish to exercise privacy rights over that data, please contact the organization that operates the agent. We will assist our customers in responding to such requests as required by law.

12. Children

The Site and Service are intended for business users and are not directed to children under 16 (or the higher age required by local law). We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact [email protected] and we will delete it.

13. Changes to This Policy

We may update this policy from time to time. The "Last updated" date above shows when the current version took effect. For material changes we will provide additional notice, such as an email to account holders or a banner on the Site. Continued use of the Site or Service after a change takes effect constitutes acceptance of the updated policy to the extent permitted by law.

14. Contact & Data Controller

Mazed Labs, Inc. is the controller responsible for the personal data described in this policy. For privacy questions or to exercise your rights, contact us at [email protected].

Legal name
Mazed Labs, Inc.
Entity type
Delaware C Corporation
Incorporation date
August 14, 2025
Delaware file number
10296100
Authorized representative
Muhlis Olcay
Phone
(415) 915-6003
Registered address
2261 Market Street STE 85852, San Francisco, CA 94114, USA
Privacy Policy | Mazed