This Privacy Policy explains how Capex USA, Inc. ("Suzanoh," "we," "us," "our") collects, uses, discloses, and protects personal information in connection with our website at suzanoh.ai (the "Site") and our AI chat and voice platform, widgets, dashboards, and related services (together, the "Services"). Capex USA, Inc. is a Delaware corporation and a subsidiary of a Japan-based parent company.
This Policy is incorporated into our Terms of Service (https://www.suzanoh.ai/terms-conditions).
1. Scope — Please Read First: Our Two Roles
Suzanoh handles personal information in two very different roles, and this Policy applies differently depending on which one is involved.
(A) When we act as a controller (this Policy governs). For personal information about:
visitors to our Site,
people who create a Suzanoh account or use the Services ("Customers"), and
people who contact us, apply for jobs, or receive our communications,
we determine why and how the information is used, and this Policy applies.
(B) When we act as a processor / service provider (our Customer's policy governs). When a Customer deploys our chat widget, voice agent, or messaging features on their own website or channels, and an end user interacts with it ("End User"), we process that End-User data on behalf of and under the instructions of the Customer. In that case the Customer is the controller (or "business"), Suzanoh is the processor (or "service provider"), and the Customer's own privacy policy governs how that data is collected and used. If you are an End User with questions about your data, please contact the business whose website or service you were using. Section 11 describes this role in more detail.
2. Personal Information We Collect (as Controller)
We collect the following categories of personal information. Under the California Consumer Privacy Act (as amended, "CCPA/CPRA"), we map them to statutory categories where relevant.
We generally do not seek to collect sensitive personal information (as defined under CPRA) about our Customers or Site visitors. Some information may be collected incidentally through support or voice features (see Sections 10 and 11).
3. Sources of Personal Information
We collect personal information: (a) directly from you (when you sign up, subscribe, or contact us); (b) automatically as you use the Site and Services (cookies, analytics, server logs); and (c) from service providers such as our payment processor and analytics providers.
4. How We Use Personal Information
We use personal information for the following business purposes:
provide, operate, secure, maintain, and support the Services and your account;
process subscriptions, payments, renewals, and invoices;
communicate with you about your account, transactions, security, and support;
send product updates and marketing where permitted (you can opt out at any time);
understand and improve the Services, and develop new features;
detect, prevent, and investigate fraud, abuse, security incidents, and violations of our Terms;
comply with legal obligations and enforce our agreements.
We rely on the following legal bases where required (e.g., in the EU/UK): performance of a contract, our legitimate interests (operating and improving the Services), your consent (e.g., marketing and non-essential cookies), and compliance with legal obligations.
5. AI and Your Data
The Services use artificial intelligence provided by us and by third-party model providers. We use Customer Content and conversation data to provide, operate, secure, and improve the Services. We also use aggregated, anonymized, or de-identified conversation data — which cannot reasonably be used to identify you or an End User — to develop, train, and improve our artificial-intelligence and machine-learning models and features, including features made available to other customers. We take reasonable measures designed to prevent such aggregated or de-identified data from being used to identify you or an End User, and we do not attempt to re-identify it except where permitted by law for security or compliance. We do not use identifiable End-User personal information to train models made available to other customers except in aggregated or de-identified form or with the consent required by law. Our third-party AI model providers do not use data sent through the Services to train their own models. You can opt out of, or limit, certain uses by submitting a request through our contact form at https://www.suzanoh.ai/contact-us (or by emailing info@capex.ai). See Section 8 of our Terms of Service for the corresponding contractual terms.
6. Cookies and Tracking Technologies
We and our providers use cookies and similar technologies on the Site to keep it functioning, remember your preferences, measure performance, and understand usage. We currently use Google Analytics 4 and Google Tag Manager for analytics; we do not use cookies for advertising or cross-context behavioral advertising. You can control or block cookies through your browser settings; disabling some cookies may affect how the Site works.
7. When and With Whom We Disclose Personal Information
We disclose personal information to:
Service providers / sub-processors that perform functions on our behalf under contract, including cloud hosting and infrastructure, AI model providers, a payment processor, transactional email, and analytics. We contractually require these providers to protect personal information and to use it only to provide services to us.
Professional advisors (lawyers, accountants, auditors);
Authorities or third parties where required by law, to protect our rights or safety, or in connection with legal process;
A successor entity in a merger, acquisition, financing, or sale of assets.
A current list of our sub-processors is available on request at info@capex.ai.
8. "Selling" and "Sharing" of Personal Information
We do not sell your personal information, and we do not share it for cross-context behavioral advertising, as those terms are defined under the CCPA/CPRA and comparable U.S. state privacy laws. We use analytics (Section 6) to understand and improve the Site and Services, not to sell your data.
If we introduce advertising or retargeting technologies in the future (for example, to promote Suzanoh), we will update this Policy, provide a "Do Not Sell or Share My Personal Information" opt-out, and honor opt-out preference signals such as GPC for the browser and device on which they are enabled.
We do not knowingly sell or share the personal information of anyone we know to be under 16.
9. Your U.S. State Privacy Rights
Depending on your state of residence (including California, and states with comparable laws such as Colorado, Connecticut, Virginia, Utah, Texas, and others), you may have the right to:
Know / access the personal information we hold about you and how we use and disclose it;
Delete personal information we hold about you;
Correct inaccurate personal information;
Opt out of the sale or sharing of your personal information and of targeted advertising (see Section 8);
Limit the use of sensitive personal information (we do not use sensitive personal information for purposes requiring this right);
Not be discriminated against for exercising your rights.
How to exercise your rights. Submit a request through our contact form at https://www.suzanoh.ai/contact-us (or by emailing info@capex.ai). We will verify your identity before responding, generally by confirming information associated with your account. You may use an authorized agent to submit a request on your behalf with proof of authorization. We will not discriminate against you for exercising these rights.
Appeals. If we deny your request, you may appeal by contacting us at info@capex.ai; some states require this.
California "Shine the Light." California residents may request information about disclosures of personal information to third parties for their direct-marketing purposes. We do not make such disclosures; you may confirm this at the contact below.
End-User requests. If your request concerns data we processed on behalf of a business Customer (Section 11), we will refer you to, or assist, that Customer, who is the controller of that data.
10. Voice Data and Recordings
Where voice features are used, we and our infrastructure providers process audio and, where enabled, call recordings and transcripts, in order to provide the voice Services. We do not create voiceprints or perform biometric identification unless a Customer expressly configures and is contractually responsible for such use. Recording, disclosure, and consent obligations for calls with End Users are the responsibility of the Customer that operates the voice agent (see our Terms of Service, Section 7, and Section 11 below). Some U.S. states require all-party consent to record.
11. Data We Process on Behalf of Our Customers (Processor Role)
When End Users interact with a Suzanoh-powered chat widget, voice agent, or messaging channel deployed by one of our Customers, we process the resulting data (such as messages, voice content, contact details, and metadata) as a processor / service provider on behalf of that Customer. In that role:
the Customer decides what data is collected and why, and is generally the controller or business;
the Customer's privacy policy governs that data as to its own collection and use;
we process identifiable End-User personal data to provide, operate, secure, maintain, support, and improve the Services in accordance with our agreement with the Customer and applicable law;
we do not sell identifiable End-User personal data or use it for cross-context behavioral advertising;
we do not use identifiable End-User personal data to provide services on behalf of an unrelated Customer except as permitted by applicable law;
we may create and use aggregated or de-identified data as described in Section 5, including to develop, train, evaluate, and improve our AI and machine-learning models and features;
within the Services we do not use third-party advertising or analytics tracking tools on End-User data, and we do not persistently store End-User IP addresses (any IP address is held only briefly — on the order of seconds — for security and rate-limiting); and
requests to access, delete, or correct identifiable End-User data should be directed to the Customer, which we will support as required. Deletion of an individual End User's conversation, message, and usage records is technically supported.
12. Data Location and International Transfers
Where your data is stored. Customer Content and conversation data are stored primarily on servers located in Japan. Certain account and authentication data, and some of the service providers that support the Services, are located in the United States.
AI processing. Depending on the deployment model, an individual AI request may be processed temporarily in data centers outside Japan; in that case the data is used only to generate the response and is not stored there. For abuse-monitoring purposes, a provider may retain a flagged item for a limited period. Voice features being introduced may process data in the United States or other regions of the applicable provider.
Transfers. Because we operate from the United States, have a parent company in Japan, and use service providers located in other countries, personal information may be transferred to, stored in, and processed in countries other than the one where you are located — including Japan and the United States — whose data-protection laws may differ from yours. These transfers are made under appropriate safeguards, including data processing terms with our providers and, where required, standard contractual clauses or your consent.
13. Data Retention
We retain personal information for as long as needed to provide the Services, maintain your account, comply with legal obligations, resolve disputes, and enforce our agreements. Account and billing records are kept for the life of the account and for the period required by tax and accounting law.
For data processed through the Services, our current default retention periods are:
Conversation, message, and usage logs — 180 days, after which they are automatically deleted by a daily process (this period is configurable);
Voice data — where stored, handled the same way as conversation logs (voice recordings are not stored by default at this time);
Session data — automatically expires after 24 hours;
Database backups — retained for 35 days.
When no longer needed, we delete or de-identify personal information. For data processed on behalf of Customers, retention follows the Customer's instructions and our agreement (Section 11), and we can delete an individual End User's records on request.
The retention periods above apply to identifiable Customer Content and Conversation Data. We may retain aggregated or de-identified data — and statistical information, evaluation results, and model improvements derived from it — for longer periods, including after the underlying identifiable data has been deleted, where that data can no longer reasonably be associated with you or an End User and does not permit reconstruction of identifiable personal information or a Customer's confidential information.
14. Security
We maintain administrative, technical, and physical safeguards designed to protect personal information appropriate to its sensitivity. No system is perfectly secure, and we cannot guarantee absolute security. You are responsible for keeping your account credentials confidential.
15. Children's Privacy
The Services are intended for business use and are not directed to children. We do not knowingly collect personal information from anyone under 16 (or the applicable age in your jurisdiction). If you believe a child has provided us personal information, contact us and we will delete it.
16. Third-Party Links and Services
The Site and Services may link to or integrate third-party websites and services with their own privacy practices. We are not responsible for those practices; please review their policies.
17. Changes to This Policy
We may update this Policy from time to time. We will post the updated Policy with a new "Last updated" date and, for material changes, provide additional notice where required. Your continued use of the Services after the effective date constitutes acceptance of the updated Policy.
If we make a change that materially expands how we use personal information — for example, using it for a new purpose that is materially different from what we described when it was collected — we will provide prominent notice before that change takes effect and will obtain consent or other authorization where required by law. Unless permitted by applicable law, we will not apply a materially expanded use retroactively to personal information previously collected under a materially different commitment without appropriate notice or authorization.
18. How to Contact Us
For privacy questions or to exercise your rights, contact:
Capex USA, Inc. US Bank Tower, 633 West Fifth Street, 26th Floor Los Angeles, CA 90071, USA Email: info@capex.ai Web: https://www.suzanoh.ai
If you are an End User who interacted with a business that uses Suzanoh, please contact that business directly regarding your personal data (see Section 11).
