Privacy Policy
This policy explains what personal data Creston Connect LLC collects, why we collect it, how long we keep it, and the rights you have over it. It covers our website, our platform, and calls placed or answered by our AI voice agents.
Last updated: August 8, 2026 · Applies to Creston Connect LLC
1. Who we are
Creston Connect LLC ("Creston Connect", "we", "us") is a company registered in Florida, United States, with its registered office at 999 Ponce De Leon Blvd, Suite 1110, Coral Gables, FL 33134, United States. We provide AI-powered inbound and outbound calling services to businesses.
For personal data relating to visitors of this website, we act as the data controller. For personal data processed on behalf of a business customer during calls — for example the contact details of that customer's own customers — we act as a data processor, and the business customer is the controller. In that case, our processing is governed by the data processing agreement signed with that customer.
For any privacy question, contact us at jajuanrandle071@gmail.com.
2. Personal data we collect
Website visitors
- Contact form submissions: your name, email address, and optionally your company name and phone number, plus the content of your message.
- Technical data: IP address, browser type, device type, referring page and pages viewed, collected in server logs for security and troubleshooting.
Call participants
- Call metadata: the phone numbers involved, the date, time and duration of the call, its outcome, and the campaign or workflow it belonged to.
- Call content: an audio recording and/or a written transcript of the conversation, where recording is enabled by the business on whose behalf the call is made and permitted by the laws applicable to the call.
- Consent and suppression records: evidence of the lawful basis for contacting you, and any opt-out request you make.
- Business context: information supplied by our customer to handle your enquiry, such as an order number, subscription status or appointment.
What we do not collect
We do not knowingly collect payment card numbers, government identification numbers, health information or biometric identifiers through our voice agents. Our agents are configured to decline and redact such information if it is volunteered. We do not sell personal data, and we do not use call content to build advertising profiles.
3. How we use personal data, and our lawful basis
| Purpose | Lawful basis (GDPR Art. 6) |
|---|---|
| Responding to enquiries submitted through this website | Legitimate interests; steps prior to entering a contract |
| Providing the calling service to our business customers | Performance of a contract (as processor, on the controller's basis) |
| Recording and transcribing calls for quality and dispute resolution | Legitimate interests; consent where required by local law |
| Maintaining consent and do-not-call suppression records | Legal obligation |
| Security monitoring, fraud prevention and abuse detection | Legitimate interests |
| Billing and financial record-keeping | Legal obligation |
4. Automated processing and AI
Calls are handled by an automated voice agent. The agent uses speech recognition, a large language model and speech synthesis to understand and respond to what is said. Every call begins with a disclosure that the caller is an AI system acting on behalf of a named business — see our AI Disclosure Statement.
Our agents do not make decisions producing legal or similarly significant effects about you without human involvement. Where a request falls outside the agent's scope — including any request to speak with a person — the call is escalated to a human at the business you are dealing with.
5. Who we share data with
We share personal data only with the following categories of recipient:
- The business customer on whose behalf a call was made or received.
- Sub-processors that we rely on to deliver the service: cloud hosting and application infrastructure, telephony carriers and voice transport providers, speech recognition and language model providers, and transactional email delivery. A current list of sub-processors is available on request.
- Professional advisers (legal, accounting, audit) under a duty of confidentiality.
- Authorities where we are legally required to disclose, or to establish, exercise or defend legal claims. We notify the affected customer unless legally prohibited.
We do not sell personal data, and we do not share it with data brokers, advertisers or list vendors. No sale or sharing of personal information occurs as those terms are defined under the California Consumer Privacy Act.
6. International transfers
Our infrastructure is operated in the United States. Where personal data originating in the European Economic Area or the United Kingdom is transferred to us, the transfer is made under the European Commission's Standard Contractual Clauses together with the UK International Data Transfer Addendum, supported by technical measures including encryption in transit and at rest.
7. How long we keep data
- Call recordings and transcripts: retained for 90 days by default, then deleted. Business customers may configure a shorter window, or disable recording entirely.
- Call metadata: retained for the life of the customer account plus twelve months, for billing and dispute resolution.
- Consent and opt-out records: retained for at least five years, as evidence of compliance with telemarketing rules. Opt-out records are retained indefinitely, because deleting them would risk contacting you again.
- Website enquiries: retained for twenty-four months from your last contact with us.
8. Your rights
Depending on where you live, you may have the right to:
- access the personal data we hold about you, and receive a copy;
- correct data that is inaccurate or incomplete;
- have your data deleted;
- restrict or object to processing, including profiling;
- receive your data in a portable, machine-readable format;
- withdraw consent at any time, without affecting past processing;
- opt out of future calls — you can do this on any call simply by saying so, or by writing to us; and
- lodge a complaint with your data protection authority.
To exercise any of these rights, email jajuanrandle071@gmail.com. We respond within thirty days, and we will not discriminate against you for exercising a right. If your request concerns data we process on behalf of a business customer, we will forward it to that customer and assist them in responding.
9. Security
We encrypt data in transit using TLS and at rest using AES-256. Access to production systems is limited to named personnel, requires multi-factor authentication, and is logged. We run least-privilege access reviews, maintain an incident response process, and notify affected customers without undue delay — and within seventy-two hours where the law requires it — following a personal data breach.
10. Cookies
This website uses only cookies that are strictly necessary for the site to function and remain secure. We do not use advertising cookies, cross-site trackers or third-party analytics that profile you across websites. If we introduce optional analytics in future, we will ask for your consent first.
11. Children
Our services are sold to businesses and are not directed at children. We do not knowingly collect personal data from anyone under sixteen. If you believe a child has provided us with personal data, contact us and we will delete it.
12. Changes to this policy
We will update this page when our practices change and revise the "last updated" date above. Where a change is material, we will notify business customers by email at least thirty days before it takes effect.
13. How to contact us
Creston Connect LLC
999 Ponce De Leon Blvd, Suite 1110, Coral Gables, FL 33134, United States
Email: jajuanrandle071@gmail.com
Questions about this page?
Write to jajuanrandle071@gmail.com. Postal enquiries can be sent to Creston Connect LLC, 999 Ponce De Leon Blvd, Suite 1110, Coral Gables, FL 33134.