Privacy and Personal Data Processing Policy
This Policy explains how Aspen Blue Capital LLC ("Aspen", "we") collects, uses, shares and protects personal data. It applies to the site aspenbluecapital.com, to our communications and to the AIBI platform, with the distinction of roles explained in section 1.
Read section 1 first. Aspen processes data in two very different capacities: as Controller (our own visitors and customers) and as Processor (the people a customer contacts using AIBI). Who you should approach to exercise your rights depends on it.
1. Two different roles: when we are Controller and when Processor
1.1 Aspen as Controller
We are the Controller — and this Policy applies directly — in relation to:
- Anyone who visits the Site or writes to us.
- Anyone who applies for a role, proposes a partnership or an investment.
- Our customers' users and administrative contacts (the account data).
- The Service Data (telemetry, metrics, security, billing) of the Platform.
1.2 Aspen as Processor
When a customer uses AIBI to call or serve people, that customer is the Controller and Aspen acts as Processor, processing data on their behalf and under their instructions. This covers the contacts the customer uploads and the recordings, transcripts and summaries of their conversations.
In that case, this Policy does not govern the processing: it is governed by the Data Processing Agreement and by the customer's own privacy notice. If an AI agent called you and you want to exercise your rights, you must approach the company that called you. If you do not know who it was, write to us and we will help you identify them (see Privacy Preferences).
2. Controller identification
- Legal name: Aspen Blue Capital LLC.
- Jurisdiction of incorporation: Wyoming, United States of America.
- Registered office: 30 N Gould St, Ste N, Sheridan, WY 82801, United States of America.
- Email for exercising rights:business@aspenbluecapital.com
- Phone:+57 313 8744681
3. Regulatory framework
Aspen is a US company with international operations. We apply, as corresponds to the data subject:
- United States: applicable federal and state regulations, including the CCPA/CPRA (California) and equivalent state laws, the TCPA for communications, and state regulations on biometric data.
- Colombia:Law 1581 of 2012, Decree 1074 of 2015 and other habeas data rules; Law 2300 of 2023 on commercial contact.
- The mandatory regulations of the data subject's place of residence, where applicable.
4. Data we collect
4.1 Through the Site and our communications
- Contact data you provide: name, email, phone, company and the message you send.
- Talent, partner and investment data: professional profile, company, proposal.
- Browsing data: IP address, device, browser, pages visited, date and time, via cookies (Cookie Policy).
4.2 As a Platform customer
- Account data: user identification, credentials (stored protected), role and administrative activity.
- Billing data: plan, consumption and transactions. Payments are processed by Stripe; we do not store full card details.
- Service Data: usage metrics, technical logs, latencies, errors and diagnostics.
4.3 Data processed on behalf of our customers (Processor)
When a customer operates agents on AIBI, the Platform processes on their behalf:
- Contacts: name, phone number and any fields the customer uploads.
- Audio recordings of calls, and video in video calls.
- Transcripts and AI-generated summaries of the conversation.
- Metadata: date, time, duration, numbers and call outcome.
- Voice samples uploaded for cloning, where the customer uses that feature.
A voice may constitute biometric data subject to heightened regulation. A customer processing it must meet the applicable requirements (see the Responsible AI Policy).
5. Purposes
- Handling enquiries, requests and partnership, investment or talent processes.
- Providing, operating, maintaining and securing the Platform, and supporting you.
- Billing and managing the commercial relationship.
- Measuring and improving the performance of the Site, the content and the Platform.
- Preventing fraud, abuse and attacks, and investigating breaches of the Acceptable Use Policy.
- Sending you institutional or commercial information, where you have authorised it.
- Complying with legal, accounting and regulatory obligations, and responding to requests from authorities.
6. Use of data for artificial intelligence
This section deserves total clarity, because our product is built on AI models.
6.1 What we do not do by default
- We do not sell or share identifiable personal data with third parties without the customer's prior, express authorisation.
- We do not commercialise the conversations, recordings or contacts we process on a customer's behalf without their authorisation: we would only do so if the customer decides to agree it with us (see 6.4).
- We do not train or fine-tune AI models with a customer's identifiable data. To improve our models and services we use only aggregated and de-identified data (see 6.2).
6.2 Aggregated and de-identified data
We do generate aggregated and de-identified data from Platform usage (for example, conversation patterns, success rates, audio or model quality metrics). This is always collective or segment-level information — for example, contact-hour patterns, response rates or frequent topics in a sector — never specific conversations, audio or messages, and never data that identifies a person. We may use, publish, share and even commercialise it with the companies in our group and with partners, and incorporate it into our systems and models, in order to improve service quality and our products, generate value and fund the development of the Platform. In doing so we undertake to:
- Apply reasonably irreversible de-identification and aggregation processes before any use.
- Not attempt to re-identify any person, and to require the same contractually from anyone receiving the data.
- Not include content identifying a customer, their brands, their counterparties or their end users.
Once irreversibly de-identified and aggregated, this data ceases to be personal data and rights cannot be exercised over it, precisely because it no longer relates to an identifiable person.
6.3 Third-party models
The Platform relies on third-party models (see Sub-processors), which process data under contract and limited to the purpose of providing the service.
6.4 Content review
In order to operate, secure and improve the Platform, we may review and monitor the content processed through AIBI — conversations, recordings and transcripts — solely for security, abuse prevention, quality, legal compliance and product improvement purposes. Access is limited to authorised personnel, under the principle of least privilege and a duty of confidentiality.
We never sell or share a customer's identifiable data without their prior, express authorisation. We only share it with our sub-processors and with the companies in our group, under contract and to provide the service. Any commercialisation is limited to the aggregated and de-identified data described in 6.2.
7. Legal basis and authorisation
We process your data with your prior, express and informed authorisation — which you may give by electronic means — or on the basis of the other applicable legal grounds: performance of a contract, compliance with a legal obligation, or our legitimate interest in operating, securing and improving the service, where that interest does not override your rights.
8. Who we share data with
- Sub-processors and providers: those listed in Sub-processors, under contract and limited to the stated purpose.
- Companies in our group: where necessary to operate and provide support, under the same obligations.
- Authorities: where required by law or a competent order.
- In corporate transactions: Aspen is a holding that develops, acquires and disposes of companies; in a reorganisation, merger, spin-off, acquisition or asset sale, data may be transferred to the resulting or acquiring entity, which will be subject to this Policy or an equivalent one. We will inform you by a reasonable means.
- Partners, solely in relation to aggregated and de-identified data (section 6.2).
9. International transfers
Aspen operates from infrastructure in the United States (Contabo and Amazon Web Services) and its providers are located mainly there. Your data may therefore be transferred and processed outside your country of residence, including countries whose legislation may offer a different level of protection.
For transfers from Colombia we rely on your authorisation and on the other grounds and safeguards of Law 1581 of 2012 and the decisions of the Superintendency of Industry and Commerce, and we undertake contractually to maintain the required level of protection.
10. Your rights
Depending on where you live, you may know about, access, update, rectify, erase, object to, restrict and port your data, withdraw your authorisation, request proof of it and be informed of the use made of your data.
- Colombia: enquiries within a maximum of ten (10) business days; complaints within a maximum of fifteen (15) business days from the day after receipt, extendable as provided by law. You may file complaints with the Superintendency of Industry and Commerce (SIC).
- California (CCPA/CPRA): the right to know, delete, correct, and to opt out of the sale or sharing of your information, without suffering discrimination for exercising it. See Privacy Preferences.
Exercise your rights by writing to business@aspenbluecapital.com, stating your name, a means of contact and your specific request. We may ask you for additional information to verify your identity.
11. Security
We apply reasonable technical, human and administrative measures: encryption in transit, authentication with signed tokens, role-based access control, strict separation between accounts, double verification for administrative functions with an audit log, secrets management outside the code and the principle of least privilege. The detail is in clause 7 of the DPA.
No system is infallible and we do not claim to hold, as at today's date, third-party certifications (such as SOC 2 or ISO 27001). We work continuously to preserve the confidentiality, integrity and availability of the information, and we receive security reports under our Responsible Disclosure Policy.
12. Retention
We retain data for as long as necessary to fulfil the purposes described and to meet legal, accounting or contractual obligations, and then delete or anonymise it. Data processed on a customer's behalf is retained for the duration of the contract and is governed by clause 10 of the DPA.
13. Minors
Neither the Site nor the Platform is directed at minors, and we do not knowingly collect their data. Our customers are prohibited from processing minors' data through the Platform without meeting the applicable heightened requirements. If we detect a minor's data processed without due authorisation, we will proceed to delete it.
14. Cookies
See the detail and management options in our Cookie Policy.
15. Effect and changes
This Policy applies from its publication and may be updated. We will publish changes on this page indicating the date of the last update; material changes will be communicated by a reasonable means.
Questions about your data? Write to us at business@aspenbluecapital.com and we will help you exercise your rights.