Privacy Policy
Updated: 28 September 2026
This is an English translation of the Ukrainian original. In case of any discrepancy, the Ukrainian version prevails.
1. About this document
This Policy explains what personal data the Peremovyny platform (the Platform) processes, for what purposes, on what legal basis, to whom it is disclosed, and what rights the people whose data is processed have.
The Platform is a corporate voice-based negotiation trainer. An employee holds a spoken conversation with a virtual counterpart and immediately receives a breakdown of that conversation with scores for individual skills. The Platform is sold to companies, not to private individuals.
This Policy covers the peremovyny.pro website, the Platform web application and related communications.
2. Who we are and in what role we process data
This Policy is issued by the operator of the Peremovyny platform (we, us). The operator's full company details are set out in the agreement with each Customer and are available on request using the contacts in section 16.
We act in different roles in different situations. This matters, because your role determines whom you should contact to exercise your rights.
2.1 We are the controller
We determine the purposes and means of processing ourselves when it comes to:
- website visitors and people who submit a request through the "Request access" form;
- contact persons at customer and prospective customer companies (negotiations, agreements, invoices);
- users who register for demo mode themselves;
- requests to our support team;
- keeping the Platform secure and meeting our legal obligations.
2.2 We are the processor
When a customer company (the Customer) uses the Platform, it decides which of its employees to add, which scenarios to create and which materials to upload. In this case the Customer, as the employer, is the controller, and we process the data on its behalf and within the scope of our agreement.
This covers: the accounts of the Customer's employees, the audio recordings and transcripts of their training conversations, evaluation results, statistics, and the content the Customer uploads.
2.3 What this means in practice
If you are an employee of a customer company, your employer decided to give you access to the Platform, and it is your employer who is responsible for the legal basis for processing your data, for informing you, and for retention periods within the chosen plan. Please contact your employer first with questions about your rights. We will help your employer handle your request, and if you contact us directly, we will forward your request to the Customer and let you know.
If you are a website visitor, a contact person or a demo user, contact us directly using the details in section 16.
3. What data we process
3.1 Account data
Nickname, first name, last name, email address (which is also the login), role in the system, job title, department or group. Phone number is an optional field; if provided, it is stored in the profile, but we do not send text messages.
Authentication data: a protected (hashed) password, two-factor authentication settings, sign-in session data.
3.2 Audio recordings and transcripts
Each training conversation is recorded in a two-channel format: the employee's voice on one channel and the synthesised voice of the virtual counterpart on the other. The recording can be played back in the session history.
A text transcript of both sides of the conversation is also stored.
Recordings of conversations shorter than 30 seconds, and of sessions interrupted by technical failures, may be retained for technical reasons, but they are not evaluated and are not included in statistics. The Customer may ask us to stop recording such sessions, or to switch off recording for its workspace entirely.
3.3 Evaluation results
Scores for eight negotiation skills (from 1 to 5 each), an overall score from 0 to 100, calculated conversation metrics (share of speaking time, word count, pace, filler words, number of questions, duration), quotes from the dialogue supporting each score, recommendations, and an indicator of whether the scenario goal was achieved.
3.4 Content uploaded by the Customer
Training scenarios, descriptions of virtual personas and products, and knowledge base documents (product descriptions, scripts, company policies and similar) that the Customer uploads so that the virtual counterpart and the evaluation system take them into account.
These materials may contain the Customer's commercial information. The Customer must not upload personal data of third parties without a legal basis — this is set out in the Terms of Use.
3.5 Technical data and logs
IP address, browser type and version, device type, interface language, timestamps of actions, security event logs and an audit trail (who did what and when within the Customer's workspace), and technical connection quality metrics.
3.6 Contract and payment data
The customer company's name and details, contact persons' details, the selected plan, invoices issued, payment confirmations, and promo codes applied. We do not accept or process payment cards — payment is made by bank transfer against an invoice, outside the Platform.
3.7 What we do not do
- We do not process payment cards — the Platform does not accept card payments.
- We do not send text messages. The phone field is kept for future use, but no messages are sent.
- We do not use your voice to identify you. Recordings are used for training and conversation review, not to recognise who is speaking. We do not create voiceprints and do not use voice as a biometric identifier.
- We do not place calls over the telephone network. Conversations take place in the browser.
- We do not intentionally collect special categories of data (health, religious or political beliefs and similar). Please do not enter such data in profiles, scenarios or knowledge base documents.
- We do not sell personal data or share it for other parties' advertising.
- We do not share recordings or transcripts with third-party providers for training their models. How we ourselves use training session materials to improve the Platform is described in section 7 — this happens only if the customer company has allowed it.
- We do not create voice clones of specific people and do not use recordings to synthesise anyone's voice.
4. Where we get data from
- From the Customer — when it creates employee accounts and sends invitations.
- From you — when you complete your profile, use the Platform, contact support, fill in a form on the website, or register for the demo yourself.
- Automatically — while you use the Platform (technical data, logs, session recordings and transcripts).
- From Google — if you register for demo mode with a Google account, we receive your name and email address.
5. Purposes and legal bases
5.1 Where the Customer is the controller (section 2.2)
The legal basis is determined by the Customer as the employer — typically the performance of employment duties, staff training, and the employer's legitimate interest in developing its employees' skills. We process this data solely on the Customer's documented instructions and do not use it for our own purposes.
5.2 Where we are the controller
| Purpose | Legal basis |
|---|---|
| Entering into and performing the agreement with the Customer, invoicing | Performance of a contract |
| Responding to a "Request access" form submission, pre-contract communication | Steps taken at the person's request before entering into a contract; legitimate interest |
| Providing access to demo mode | Performance of a contract (demo terms) |
| User support | Performance of a contract; legitimate interest |
| Security, abuse prevention, audit trail | Legitimate interest in protecting the Platform and Customers' data |
| Maintenance, backups, disaster recovery | Legitimate interest; performance of a contract |
| Anonymised statistics for product development | Legitimate interest (data is anonymised) |
| Improving the Platform using training session materials (section 7) | Legitimate interest — only if the Customer has enabled this option; subject to the right to object |
| Accounting and tax records | Compliance with a legal obligation |
| Product newsletters to people who are not our Customers | Consent (which can be withdrawn at any time) |
| Non-essential cookies | Consent |
6. Automated evaluation and artificial intelligence
The Platform automatically evaluates every training conversation. This is important to understand, so we explain it in detail.
How it works. Conversation metrics (pace, share of speaking time, number of questions and so on) are calculated algorithmically. Scores for the eight skills are assigned by a language model. The overall 0–100 score is calculated as a weighted average using published weights, so it is reproducible and verifiable.
An explanation is always given. For each skill, the Platform shows why that particular score was given — with specific quotes from your conversation, what you did well, what could be improved, and an example of a better phrasing.
This is a training tool, not an HR decision. Scores are produced for your development. The Terms of Use expressly prohibit the Customer from treating an automated score as the sole or decisive basis for HR decisions — about hiring, pay, promotion or dismissal. Such decisions must be made by a person, taking other circumstances into account.
Results may be inaccurate. Language models are probabilistic: a score, quote or conclusion may not reflect what was actually said in the conversation.
You can challenge a score. Contact your manager or the person responsible at your employer: they have access to the recording and transcript and can review the result.
7. Using training session materials to improve the Platform
We use training session materials to make the Platform better: to evaluate conversations more accurately, to make the dialogue more natural, and to find and fix errors faster. We describe this in detail, because this wording covers activities of very different sensitivity.
7.1 What exactly we do
(a) Anonymised statistics. Aggregated usage metrics — number and duration of sessions, score distribution, frequency of technical failures. They do not allow a person or company to be identified. Used at all times.
(b) Quality spot checks. A limited group of authorised staff may listen to individual recordings and read transcripts to check the accuracy of automated evaluation, investigate a complaint about a score, or look into a technical failure. Every such access is logged.
(c) Improving and fine-tuning models. Audio recordings, transcripts and evaluation results may be used to tune and fine-tune the models used in the Platform — in particular, to improve evaluation accuracy and the naturalness of the virtual counterpart's behaviour.
7.2 The customer company switches this on
Items (b) and (c) apply only if the customer company has expressly allowed this in its workspace. By default, this option is switched off.
The setting applies to the Customer's entire workspace, and the Customer can change it at any time. Switching it off takes effect going forward: new materials are no longer used.
An important limitation we want to be upfront about: data that has already been included in a training set and used to fine-tune a model cannot technically be removed from a model that has already been trained. We stop any further use and remove the relevant materials from the sets used for future iterations, but a model that has already been trained cannot "unlearn" them.
7.3 What we use and what we never touch
We use: audio recordings of training conversations, their transcripts, evaluation results and technical session metrics.
We do not use:
- the Customer's knowledge base documents — they may contain trade secrets and never enter training sets;
- the hidden part of scenarios or the Customer's product descriptions;
- data from other customers' demo workspaces, contract data or payment data.
We do not:
- create voice clones of specific people or use recordings to synthesise anyone's voice;
- share recordings with third-party providers for training their models (see 8.1);
- use these materials to evaluate, profile or compare specific employees beyond what the Platform already shows their employer.
7.4 How we reduce risk
- Before use, materials are pseudonymised: direct identifiers — first name, last name, email address, job title, company name — are separated from the content of the conversation.
- Access is limited to authorised staff bound by confidentiality, to the minimum extent necessary, and is logged.
- All processing stays within the EU.
- Training sets are stored separately with their own retention period (section 9) and are deleted when it expires.
7.5 Legal basis and your right to object
For this purpose we act as the controller — that is, we take responsibility for it rather than relying on the Customer's instructions. The legal basis is our legitimate interest in developing and improving the quality of the Platform, pursued only if the Customer has enabled this option and informed its employees.
You can object to your recordings being used in this way — through your employer or directly using the contacts in section 16. We stop such use going forward, subject to the limitation described in 7.2. This does not affect your ability to use the Platform.
7.6 Demo mode
In demo mode, audio recordings are not stored, so item (c) does not apply to audio. Transcripts and evaluation results of demo sessions may be used to improve the Platform — the demo is provided free of charge on exactly this condition, so please do not enter real personal data in it.
8. Who we share data with
8.1 Artificial intelligence service providers
To make the conversation possible, data is sent to external services:
| Service | What is sent |
|---|---|
| Speech recognition | Audio of your turn in the conversation |
| Language model (conversation) | Scenario settings and the course of the dialogue |
| Speech synthesis | Text of the virtual counterpart's turn |
| Language model (analysis) | Transcript of the completed conversation |
Processing takes place exclusively within the European Union. We do not engage providers that process data outside the EU. This rule has no exceptions — it also applies when the primary provider is unavailable and the system automatically switches to a backup provider.
Under our agreements with these providers, the data is not used to train their models.
The list of specific providers is provided to Customers as part of the Data Processing Agreement, and on request. We notify Customers in advance of any replacement or addition of a provider, within the period set out in the agreement.
8.2 The Customer's own keys
The Customer may connect its own provider credentials. In that case, processing takes place under the Customer's direct agreement with the relevant provider, and the terms of that agreement are determined by the Customer. The keys are stored encrypted, are never displayed in full, and are destroyed when the Customer's workspace is deleted.
8.3 Other sub-processors
Cloud infrastructure and storage providers, an email delivery service, monitoring and backup tools, and the support desk. All of them act under written data processing agreements, with processing restricted to the EU.
8.4 Other disclosures
- To the Customer (the employer) — managers and administrators see the results of employees in their team according to the permissions configured.
- To public authorities — only on the basis of a lawful request, to the extent required by law.
- In the event of a reorganisation — to the legal successor, with prior notice to Customers.
- To professional advisers — lawyers and auditors bound by confidentiality.
9. Retention periods
| Category | Retention period |
|---|---|
| Audio recordings of conversations | Depends on the Customer's plan: 1 month, 3 months, or a period agreed separately. No recording takes place in demo mode |
| Transcripts, scores, statistics | For the term of the agreement with the Customer |
| Account data | For the term of the agreement; after a user is deactivated — until the agreement ends |
| Data after the agreement ends | The Customer's workspace is archived; after deletion, a recovery period applies (30 days by default), after which the data is permanently destroyed |
| Audit trail records | 12 months, unless a longer period is agreed with the Customer |
| Security logs | 12 months |
| Contract and accounting documents | At least 3 years, and up to 7 years where required by tax law |
| Website form submissions where no agreement is concluded | 12 months |
| Demo accounts and their data | 14 days from registration, after which they are deleted |
| Training sets for improving the Platform (section 7) | 24 months from the date the material is added to the set |
| Anonymised statistics | Indefinitely (contains no personal data) |
The Customer may ask for data to be destroyed earlier. We also comply with justified deletion requests to the extent they do not conflict with our legal obligations.
10. How we protect data
- Mandatory two-factor authentication for all users.
- Encryption of data in transit and at rest.
- Workspace isolation: one customer company's data is not accessible to another — separation is enforced on the server, not just in the interface.
- Role-based access control: a user sees only their own results, a manager sees their team, the platform administrator has no access to financial data, and vice versa.
- An audit trail of significant actions.
- Encrypted storage of provider keys, including the Customer's own keys.
- Daily backups with a documented and tested recovery procedure.
- Staff access controls on a need-to-know basis, under confidentiality obligations.
If an incident poses a risk to people's rights, we notify the Customer without undue delay so that it can meet its obligations as the controller, and we notify the supervisory authority and the data subjects where that obligation rests with us.
11. Your rights
Regardless of who the controller is, you have the right to:
- access — know what data about you is processed and obtain a copy;
- rectification — correct inaccurate data or complete incomplete data;
- erasure — have your data deleted, in the cases provided for by law;
- restriction of processing — while your objection is being assessed;
- object to processing based on legitimate interest;
- data portability — receive your data in a portable format;
- withdraw consent at any time where processing is based on consent — this does not affect the lawfulness of processing before withdrawal;
- not be subject to a decision based solely on automated processing that significantly affects you. The Platform does not make such decisions, and the Terms of Use prohibit the Customer from using scores in this way;
- object to your recordings being used to improve the Platform — see section 7.5, which also describes the technical limitation regarding models that have already been trained;
- lodge a complaint with a supervisory authority.
How to exercise your rights. If you are an employee of a customer company, contact your employer; we are obliged to assist it. If you are a website visitor, contact person or demo user, contact us via the peremovyny.pro website. We respond within one month; in complex cases this period may be extended, and we will let you know.
We may ask you to confirm your identity so that we do not disclose your data to someone else.
12. Cookies
Essential cookies — signing in, keeping your session active, security, remembering your interface language. The Platform cannot work without them; they are used without consent.
Analytics and functional cookies — help us understand how the website is used and improve it. They are used only with your consent, which you give through the banner on the website and can withdraw at any time.
We do not use advertising cookies or trackers from third-party advertising networks.
13. Demo mode
Demo mode lets you try the Platform without an agreement. You register yourself — with an email address or a Google account.
- The demo workspace is isolated from Customers' production workspaces, their data and storage.
- Limits: 30 minutes of conversation and 14 days of access.
- Only pre-configured demo scenarios are available.
- Audio recordings of demo conversations are not stored.
- We send emails when you register and 24 hours before your access expires.
- Transcripts and results of demo sessions may be used to improve the Platform (section 7.6).
- When the demo period ends, the demo account and its associated data are deleted.
Do not enter real personal data or confidential information in demo mode.
14. Age of users
The Platform is intended for corporate use by adult employees. It is not directed at people under 18, and we do not knowingly collect their data. If you believe such data has reached us, let us know via the peremovyny.pro website and we will delete it.
15. Changes to this Policy
We may update this Policy. The current version is always available on the website. We notify Customers of material changes by email at least 30 days before they take effect, so that there is enough time to review them and ask questions if needed.
16. Contact us
You can contact us via the peremovyny.pro website.
Email: sales@smiddle.com