Skip to policy

Susan · Legal

Privacy Policy

How we handle information when your organization uses Susan to carry out business work.

Effective and last updated:

1. Who we are and scope

Susan (“we,” “us,” or “our”) provides managed AI agents for business operations. This policy applies to the Susan website, platform, agents, applications, Microsoft Teams apps and bots, connected messaging channels, and related support services.

For customer deployments, the service provider and any additional data protection commitments are identified in the customer agreement. This policy explains our information practices; the customer agreement and any applicable data processing agreement govern our processing on the customer’s behalf. Our Terms of Use describe use of the service.

Susan is intended for business use by adults. We do not knowingly collect personal information from children under 18 through accounts intended for their own use. Contact us if you believe a child has provided such information.

2. Your organization’s control

Your organization decides which workflows to enable, which applications to connect, who may use Susan, and which permissions and approvals apply. For personal information within customer messages, files, and business records, we process information on the organization’s instructions to provide the agreed service. The organization is responsible for the notices, permissions, and lawful basis required for that use.

We determine how to use information needed to administer our own business, such as account contacts, billing records, website inquiries, service communications, and security records. If you use Susan through an employer or another organization, its administrators may manage your access and review workspace information in accordance with their permissions and policies.

3. Information we process

  • Account and business information: names, work email addresses, organization details, user identifiers, roles, preferences, and information provided during setup or support.
  • Messages and work content: requests, conversation context, attachments, documents, records retrieved from authorized applications, generated responses, and work products. Depending on the workflow, records may contain contact, accounting, financial, employee, or customer information.
  • Connection information: connected account identifiers, granted permissions, authorization tokens, and credentials needed to operate approved integrations.
  • Activity and support records: task and run information, timestamps, recorded actions and changes, connection events, diagnostic logs, and support communications. Computer-based workflows may also process screen content, screenshots, and interaction records needed for execution, supervision, and troubleshooting.
  • Website and device information: IP address, browser and device information, pages visited, referral information, and performance or error data.
  • Billing information: billing contacts, plan and transaction details, and payment-provider references. Payment card details entered into our payment provider’s checkout are handled by that provider.

We receive information from you, your organization, authorized users, connected applications, and service providers involved in delivering Susan. The information processed depends on the features and workflows your organization enables.

4. How we use information

We use information to authenticate users, configure agents, carry out authorized tasks, deliver responses and work products, maintain workflow context, provide support, manage billing, and communicate about the service. We also use operational information to diagnose errors, maintain reliability, protect accounts, investigate misuse, and meet legal obligations.

Where applicable law requires a legal basis for processing that we control, we rely on performance of a contract, legitimate interests in operating and securing our business and responding to inquiries, compliance with legal obligations, or consent where required. You may withdraw consent for processing based on consent. Declining information needed to operate a feature may prevent us from providing that feature.

We do not sell personal information or share it for cross-context behavioral advertising.

5. Microsoft Teams and connected applications

When your organization enables a Susan Teams app or bot, Susan may receive messages and attachments delivered to the app, user and organization identifiers, conversation or channel identifiers, and the context needed to route requests and respond. Access depends on the app’s installation scope, its configured capabilities, and the permissions granted by users or administrators.

Access to Microsoft 365 resources such as files, email, calendars, or directory information depends on separately authorized integrations and permissions. Installing a Teams bot does not itself authorize unrestricted access to those resources. Other connected applications follow the permissions and account access your organization authorizes.

We use this information to perform the requested workflow and deliver results to the configured destination. Messages and results posted to a shared channel may be visible to its participants. Choose destinations and share information in accordance with your organization’s policies.

Administrators can manage app availability and revoke permissions through the relevant provider’s controls, and can contact Susan to disconnect a workflow. Removing an app or revoking access does not automatically delete previously processed records or copies held in Microsoft Teams or other connected systems. See the retention and deletion section below.

6. AI processing and human review

Susan uses AI models to interpret requests, reason about tasks, and generate responses or work products. Relevant messages, documents, retrieved records, and screen content may be sent to the model providers configured for your deployment. Model-provider processing and retention are governed by the applicable provider terms and deployment arrangements.

We do not use customer content to train AI models without the customer’s explicit authorization. Contact us for information about the providers and data-handling arrangements that apply to your deployment.

Authorized operational and support personnel may review information when needed to deliver, troubleshoot, or secure the service. AI outputs require review appropriate to the workflow. Susan is not intended to make decisions with legal or similarly significant effects on individuals without appropriate human oversight.

7. Sharing and service providers

We share information as needed with:

  • Your organization’s authorized users, administrators, and recipients selected through its workflows.
  • Providers of cloud hosting, databases and authentication, agent computers, AI inference, integration connectivity, messaging, diagnostics, support, and payment processing used to deliver the service.
  • Third-party applications your organization connects or directs Susan to use.
  • Professional advisers, authorities, or other parties when reasonably necessary to comply with law, protect rights and safety, or address fraud and security incidents.
  • Parties to a merger, acquisition, or transfer of the business, subject to applicable confidentiality and data protection requirements.

The providers involved vary by deployment and enabled features. Customers can request the relevant provider information and data processing terms using the contact below. Third-party services that your organization uses independently also operate under their own terms and privacy policies.

8. Security and client traceability

Susan uses technical and organizational controls designed to protect customer information, including authenticated access, workspace permissions, tenant-scoped agent environments, protected credential handling, encrypted web connections, and activity logging. Access to customer information is limited according to authorized roles and operational responsibilities.

Susan maintains operational records organized through Runs, Changes, Access, and Data lifecycle views in its Audit Center. These records cover recorded connection changes and activity on the agent computer, with timestamps, action details, outcomes, and actor information where captured. Access to audit views and exports is restricted to authorized roles.

Customers may contact Susan support to request information about recorded activity associated with their organization, subject to the applicable agreement, reporting scope, permissions, and retention period. Your organization can use available records alongside its connected applications’ own histories to review work and follow up on changes.

If we identify a personal data breach requiring notification, we will notify the relevant customer or individuals as required by applicable law and our agreement.

9. Storage, retention, and deletion

Information may be stored in Susan’s application databases, agent environments, file storage, and operational or recovery systems, as well as in the connected applications and service-provider systems used for the workflow.

We determine retention by the type of information, the purpose for which it was collected, the active customer relationship, configured retention settings, contractual requirements, and legal or security obligations:

  • Account and workspace information is kept while needed to administer the customer relationship and complete closure obligations.
  • Messages, files, workflow context, and work products are kept for the enabled workflow and applicable customer instructions or retention arrangements.
  • Operational, audit, and security records have retention appropriate to troubleshooting, accountability, abuse prevention, and applicable obligations. Different record categories may have different retention periods.
  • Billing, legal, and dispute records may be retained for applicable recordkeeping requirements and the establishment or defense of legal claims.

Authorized customer representatives can request return or deletion of customer data by contacting us. We verify the request, identify the relevant systems and any required retention, and coordinate completion under the customer agreement and applicable law. When information is no longer needed, we delete or de-identify it as appropriate.

Deletion from active systems may precede expiration of backup or recovery copies under their lifecycle. Legal holds and required records may affect deletion. Copies retained by your organization, channel participants, or independently operated third-party services are subject to those parties’ controls. Disconnecting an integration stops its authorized use but is a separate action from requesting deletion.

10. International processing

Susan and its service providers may process information in the United States and other countries where they operate. Processing locations depend on the deployment and providers used; any specific residency commitments must be stated in the customer agreement.

Where applicable law requires safeguards for international transfers, the relevant transfer mechanism and safeguards must apply to that processing. Contact us for information about the locations and transfer arrangements relevant to your service.

11. Cookies and website analytics

We use cookies and similar technologies needed for sign-in, session management, and service operation. We also use website performance and usage analytics to understand how the site performs and improve it. Browser settings can limit or remove cookies, although doing so may affect signed-in features. Where consent is legally required for optional technologies, that consent governs their use.

12. Your choices and privacy rights

Depending on your location and applicable law, you may have rights to access, correct, delete, or obtain a copy of personal information, restrict processing, or withdraw consent. You may also have the right to complain to your local data protection authority.

You may have the right to object to processing based on legitimate interests and to object to direct marketing. You can opt out of marketing messages using the instructions in the message or by contacting us. Necessary service and security communications may continue.

Send requests to hello@trysusan.com. We may need to verify your identity and authority, and will respond within the time required by applicable law. If the information belongs to a customer workspace, contact your organization first; we support the organization in responding to requests for data it controls. We do not discriminate against individuals for exercising applicable privacy rights.

13. Policy updates

We update this policy as our services and information practices change. The effective date above identifies the current version. For material changes, we provide notice through appropriate service communications or a prominent notice, and obtain consent where required.

September 28, 2026: This version describes Susan’s managed agents and connected apps, including Microsoft Teams, AI processing, client audit visibility, and data lifecycle practices.

14. Contact

For privacy questions, data requests, or information about your deployment’s data processing arrangements, contact Susan at hello@trysusan.com. Include your organization and the nature of your request. Please do not send passwords, access tokens, or sensitive customer records in an initial email.