Privacy Policy

Last Updated: September 25, 2026

Whiteworth Inc. (“Whiteworth,” “we,” “us,” or “our”) respects privacy and is committed to handling personal information responsibly. Whiteworth owns and operates AgentNode, its AI-enabled platform for real-estate businesses to manage lead communications, configure messaging automations, place and receive calls, coordinate bookings, and connect customer-selected services.

This Privacy Policy describes how we collect, use, disclose, retain, and protect personal information in connection with the AgentNode website, platform, related services, marketing, support, and other interactions that link to or reference this Privacy Policy (collectively, the “Services”).

Your access to and use of AgentNode are governed by the AgentNode Terms of Service Addendum and the Common Paper Cloud Service Agreement Standard Terms Version 2.1 incorporated into that addendum (collectively, the “Terms”). This Privacy Policy describes our privacy practices. It does not amend the Terms governing a customer’s use of AgentNode; we will handle personal information as described here, subject to applicable law.

1. Scope of This Privacy Policy

This Privacy Policy applies to personal information we collect or process when you:

  • visit or interact with our website or the Services;
  • create, administer, or use an AgentNode account;
  • connect a customer relationship management system, calendar, communications service, artificial-intelligence feature, or another third-party service to AgentNode;
  • communicate with us by email, text message, telephone, chat, support request, sales inquiry, or another channel;
  • receive marketing communications from us or interact with our advertising; or
  • otherwise provide personal information to us.

This Privacy Policy does not apply to a website, application, product, or service operated by a third party that does not link to this Privacy Policy. We may provide additional notices for particular features, activities, or jurisdictions.

AgentNode does not sell or license lead lists or other personal information to customers. Instead, AgentNode enables customers to connect and use their own CRM data, contacts, leads, communications, and business information through the Services.

2. Customer Data and Customer Responsibility

AgentNode customers may use the Services to import, connect, synchronize, or otherwise process information about their leads, contacts, clients, prospective clients, agents, employees, contractors, and other individuals (“Customer Data”). Customer Data may include names, telephone numbers, email addresses, property-related information, conversation history, booking information, CRM records, calendar information, messaging preferences, and consent records. Calls placed or received through AgentNode may generate call metadata whether or not recording is enabled. If a customer enables recording, Customer Data may also include call audio, recordings and transcripts, recording settings and announcement records, and AI-assisted summaries, CRM updates, and follow-up drafts.

The AgentNode customer that provides or connects Customer Data generally controls that data and is responsible for providing any required privacy notices, obtaining required permissions or consents, responding to requests from its contacts or leads, and ensuring that its use of the Services complies with applicable law. We process Customer Data to provide, secure, support, maintain, and improve the Services; to carry out the applicable customer’s instructions; and for the other purposes described in this Privacy Policy and the Terms.

Customers may use AgentNode to place and receive calls. Recording is off by default and may be enabled by the customer. When recording is enabled, AgentNode supplies a recording announcement with default wording that the customer may customize. The customer is responsible for using appropriate notices on every recorded call, determining applicable recording and transcription requirements, obtaining and documenting all required participant consents, and addressing objections or withdrawals. The availability or playback of an announcement does not by itself establish that consent has been obtained. We process call information to deliver the services configured by the customer, as described below.

If you are a lead, contact, or other individual whose information was submitted to AgentNode by one of our customers, you should direct requests about that customer’s communications, services, relationship with you, or use of your data to the applicable customer first. We may assist the customer with verified requests where appropriate and as required by applicable law.

3. Personal Information We Collect

The personal information we collect depends on how you interact with the Services and the features you or an AgentNode customer enable.

A. Account, Contact, and Business Information

We may collect your name, business name, trade name, business address, email address, telephone number, username, account credentials, role, professional or real-estate business information, tax or business-identification information, authorized-representative information, and other information you provide when creating, administering, or using an account.

B. Billing and Transaction Information

We may collect or receive billing address, payment-method information, payment status, subscription information, credit balances, usage, overage information, invoices, refunds, chargebacks, transaction history, and related records. Stripe processes payment-card information for the Services. We do not intentionally store full payment-card numbers.

C. Customer Data, Communications, and Booking Information

When an AgentNode customer uses the Services, we may process Customer Data, including contact information; lead and CRM records; message content; call, text, and other communication metadata; message preferences; opt-in, opt-out, revocation, and recording-consent information; booking, calendar, scheduling, routing, callback, and appointment information; property-related information; and conversation history. Customers may place outbound calls and receive inbound calls using the Services. If a customer enables call recording, we may process call audio, recordings, transcripts, call timing and routing information, recording settings, announcement wording and change records, available announcement-status information, and related objections or requests. We may also process AI-assisted call summaries, CRM updates, and follow-up drafts generated from transcripts. Section 3.G separately addresses communications with Whiteworth itself.

D. AI Inputs, Outputs, and Customer-Provided Materials

We may process prompts, scripts, templates, CRM fields, knowledge-base content, customer-service directions, uploaded documents, property descriptions, images, links, listing information, pricing, availability, agent information, calendar data, qualification criteria, routing instructions, follow-up rules, and AI-generated or AI-assisted content used through the Services.

E. Integration Data

When you authorize an integration, we may receive information from and transmit information to the connected service to enable the integration. Depending on the integration, this may include contact, lead, message, activity, event, availability, scheduling, calendar, CRM, account, and other data selected or made available through the connection.

F. Device, Usage, and Technical Information

We and our service providers may automatically collect IP address, browser type, operating system, device identifiers, device settings, language, internet-service-provider information, general geographic location derived from IP address, log information, error reports, dates and times of access, pages or features used, clicks, session information, referring pages, and interactions with our communications.

G. Communications and Support Information

This subsection concerns communications directly with Whiteworth, such as sales, account, and support interactions, not customer calls with leads or contacts through AgentNode. We may collect information you provide in those interactions, including emails, messages, support requests, feedback, attachments, call or meeting information, and other communications. To the extent permitted by applicable law, we may monitor or record our own communications for support, personnel training, quality assurance, security, dispute-resolution, service-improvement, and business-administration purposes.

H. Marketing and Advertising Information

We may collect information about your interaction with our marketing, advertising, website, emails, events, or promotional communications, including cookie, pixel, web-beacon, advertising, analytics, and campaign-performance information.

I. Information We Ask Customers Not to Provide

Unless we expressly authorize a particular workflow in writing, customers must not upload, transmit, store, or otherwise make available through the Services protected health information, payment-card data, bank-account information, Social Security numbers, government-issued identification numbers, biometric information, authentication credentials, or sensitive financial, credit, mortgage-prequalification, or veteran-status information.

4. How We Collect Personal Information

We collect personal information:

  • directly from you or an AgentNode customer when you create an account, complete onboarding, connect an integration, configure a campaign or automation, submit Customer Data, enable calling or recording, make a payment, contact us, or otherwise use the Services;
  • through customer-directed calls and, where enabled, recordings made using the Services;
  • automatically through cookies, pixels, web beacons, log files, local storage, device identifiers, and similar technologies when you use our website or Services;
  • from connected services and integrations that you or an AgentNode customer authorize, including customer relationship management, calendar, communications, billing, workplace-collaboration, and artificial-intelligence services;
  • from Stripe, our payment processor, and from hosting and cloud-infrastructure providers, communications providers, security and fraud-prevention providers, analytics providers, advertising providers, customer-support providers, and professional advisors; and
  • from publicly available sources, business partners, or other sources where permitted by applicable law.

5. How We Use Personal Information

We may use personal information to:

  • provide, operate, maintain, secure, troubleshoot, and support the Services;
  • create and administer accounts, authenticate users, manage access, process payments, administer subscriptions and prepaid credits, and communicate about accounts, transactions, changes, and support requests;
  • process Customer Data and the applicable customer’s instructions, including enabling CRM, calendar, communications, booking, scheduling, and other authorized integrations;
  • enable customer-directed calls and, where recording is enabled, process call audio and transcripts to provide transcription, AI-assisted summaries, CRM updates, and follow-up drafts, including through communications and AI service providers;
  • generate, route, classify, or otherwise assist with other AI-enabled features, automations, communications, bookings, and workflows;
  • respond to inquiries, provide customer support, train personnel, conduct quality assurance, and improve our support operations;
  • monitor service performance, analyze usage, diagnose technical problems, detect and prevent fraud, abuse, security incidents, and unlawful activity, and enforce our agreements;
  • develop, maintain, measure, improve, and enhance the Services, including through aggregated or de-identified information and as otherwise permitted by the Terms;
  • market the Services, measure advertising effectiveness, communicate about products, features, offers, events, and other business-development activities, subject to applicable law and available choices;
  • comply with legal, regulatory, tax, accounting, recordkeeping, and other requirements; establish, exercise, or defend legal claims; and protect the rights, safety, and security of Whiteworth, our customers, users, and others;
  • evaluate, negotiate, complete, or administer an actual or potential financing, merger, acquisition, restructuring, sale of assets, bankruptcy, or other corporate transaction; and
  • fulfill another purpose disclosed when information is collected or with your consent where required by law.

6. AI Features

AgentNode may use AI functionality to generate, revise, classify, route, or otherwise assist with customer communications, templates, automations, bookings, and business workflows. Where a customer has enabled call recording and has provided the required notices and obtained required consents, AI features may process call transcripts to prepare summaries, CRM updates, and follow-up drafts for that customer. AI features may also process Customer Data, customer-provided prompts, scripts, templates, knowledge-base content, message content, CRM information, calendar information, and other inputs needed to provide an enabled feature. These AI features assist with call-related outputs rather than placing or conducting calls.

AI-generated or AI-assisted content may be inaccurate, incomplete, inappropriate, or unsuitable for a particular recipient or circumstance. AgentNode customers are responsible for configuring, supervising, reviewing, and validating AI-assisted features and outputs before using them where appropriate to their business, legal obligations, and risk profile.

Third-Party AI Providers

We may use third-party artificial-intelligence, machine-learning, cloud, communications, and other technology providers to support AI-enabled features. Communications and transcription providers may process call audio and metadata to provide calling and transcription, and AI providers may process transcripts and resulting outputs to deliver customer-enabled summaries, CRM updates, and follow-up drafts. The providers we use may change over time. Information processed by a provider, and the provider’s access to and retention of that information, depend on the feature used and the provider’s applicable arrangements and settings. Our use of Customer Data and information about the provision, use, and performance of the Services for artificial-intelligence or machine-learning development, training, or enhancement is governed by the Terms. Our commitments concerning mobile telephone numbers, text-message opt-in data, and SMS consent are described in Section 8.

7. How We Disclose Personal Information

We may disclose personal information to:

  • Authorized customer users. An AgentNode customer’s authorized users may access Customer Data, messages, booking information, CRM-synchronized records, and other information made available through that customer’s account.
  • Service providers and subprocessors. We may disclose information to providers that support hosting, cloud infrastructure, application hosting, SMS and telephony, payment processing, business email and productivity, property data, error monitoring, AI-enabled functionality, security, customer support, and other business operations. Providers identified for customer or lead data include Amazon Web Services (AWS) for hosting and infrastructure; Vercel for application hosting; SignalHouse for SMS and telephony; Stripe for payments; Google for business email and productivity; Anthropic and OpenRouter for AI model services; RentCast and Realie for property data; and Sentry for error monitoring. Which providers receive information depends on the features used and the services performed. AI and other providers may change over time. Website analytics and advertising recipients are described in Section 9.
  • Connected services and integrations. We may receive information from and disclose information to a connected CRM, calendar, communications service, payment processor, workplace-collaboration service, AI service, or other integration when you or an AgentNode customer authorizes the connection and as necessary to enable the requested functionality.
  • Carriers, aggregators, campaign registries, and telecommunications providers. We may disclose information needed to register, provision, transmit, monitor, support, secure, or enforce messaging campaigns, sender identities, telephone numbers, and related communications functionality.
  • Affiliates and professional advisors. We may disclose information to our affiliates and to our lawyers, accountants, insurers, auditors, consultants, and other professional advisors as needed for legitimate business purposes.
  • Legal and safety purposes. We may disclose information to courts, government authorities, regulators, law enforcement, carriers, aggregators, or other parties when required by law, legal process, or governmental request, or when we reasonably believe disclosure is necessary to protect rights, safety, security, property, or the integrity of the Services; investigate fraud, abuse, or unlawful activity; or enforce our agreements.
  • Corporate transactions. We may disclose information to buyers, investors, lenders, insurers, advisors, successors, and other participants in an actual or potential corporate transaction. Such a disclosure does not, by itself, transfer SMS consent to a different brand, customer, program, or campaign; the restrictions in Section 8 continue to apply.
  • With consent or at your direction. We may disclose information for another purpose with your consent or at your direction.

AgentNode customers may use the Services to manage SMS communications to contacts and leads. This Section describes our processing and handling of mobile messaging information in connection with the Services. It does not change the applicable customer’s responsibilities under the Terms for its messages, campaigns, recipients, consent practices, or compliance with applicable law and messaging-industry requirements.

A. Information We Process for SMS Features

In connection with SMS and related messaging features, we may process mobile telephone numbers; message content; message status; sending, delivery, and error information; consent records; consent source and timestamp; message preferences; opt-out, revocation, and suppression records; sender identities; telephone-number and campaign-registration information; and related campaign, automation, configuration, compliance, and support information. We may process this information when an AgentNode customer configures a campaign or automation, connects a CRM or other authorized integration, communicates with a recipient through the Services, or requests support for a messaging feature.

B. Use of Mobile Messaging Information

We may use mobile messaging information to provide, operate, secure, support, maintain, troubleshoot, and improve the Services and their messaging features. This includes enabling customer-configured campaigns and automations; transmitting, routing, tracking, and supporting messages; registering, provisioning, and administering campaigns, sender identities, and telephone numbers; processing opt-out, revocation, HELP, and other compliance keywords; applying suppression controls; responding to support requests; detecting and preventing fraud, abuse, security incidents, unlawful activity, and violations of our agreements; and complying with applicable legal, carrier, aggregator, campaign-registry, and telecommunications requirements.

We do not sell, rent, share, or transfer mobile telephone numbers, text-message opt-in data, or SMS consent to third parties, affiliates, or lead generators for their own marketing, promotional, lead-generation, or other unrelated commercial purposes. We also do not permit third parties, affiliates, or lead generators to use mobile telephone numbers, text-message opt-in data, or SMS consent obtained through the Services for their own marketing, promotional, lead-generation, or unrelated commercial purposes.

SMS consent is not transferable to another brand, customer, program, or campaign. An opt-in, consent record, opt-out, revocation, or other messaging preference associated with one AgentNode customer, sender identity, telephone number, campaign, or messaging program does not, solely because it is processed through the Services, authorize use by another customer, brand, sender identity, telephone number, campaign, or messaging program.

The restrictions in this Section do not prevent us from disclosing or processing mobile messaging information with service providers, carriers, aggregators, campaign registries, telecommunications providers, or third-party components solely as necessary to provide, secure, support, maintain, improve, or enforce the Services; comply with applicable law or messaging-industry requirements; register, provision, transmit, monitor, or support messages and campaigns; or protect the rights, safety, security, property, or integrity of Whiteworth, the Services, our customers, recipients, or others. Any such disclosure or processing is subject to the Terms and applicable law.

D. Message Frequency, Rates, STOP, and HELP

Message frequency may vary based on the applicable customer’s campaign, automation, settings, recipient interaction, and other factors. Message and data rates may apply. Recipients may reply STOP, or use another reasonable method permitted by applicable law, to request that applicable messages stop. Depending on the messaging program and applicable requirements, we or the applicable customer may send a confirmation or other operational response to process or confirm an opt-out request.

Recipients may reply HELP or use available customer-care contact information for assistance. An opt-out from marketing messages does not prevent Whiteworth or the applicable customer from sending transactional, account, security, legal, or other non-marketing messages where permitted by applicable law.

E. Customer Responsibility and Operational Controls

AgentNode customers are responsible for obtaining and maintaining all notices, permissions, disclosures, consents, and other authorizations required for their messages and campaigns. Customers are also responsible for configuring, supervising, and using messaging features, campaigns, automations, sender identities, opt-out language, quiet-hour settings, and other messaging settings in compliance with the Terms, applicable law, and applicable carrier, aggregator, campaign-registry, and telecommunications requirements.

We may process opt-out, revocation, HELP, and other compliance keywords; send confirmation or operational responses; apply suppression controls; and take other measures described in the Terms or reasonably necessary to comply with applicable law or messaging-industry requirements, protect recipients, or protect Whiteworth and the Services. Customers must not disable, bypass, delay, override, or interfere with available opt-out, revocation, or suppression functionality.

9. Cookies, Analytics, Advertising, and Communications

We and our service providers may use cookies, pixels, web beacons, local storage, log files, SDKs, and similar technologies to operate the Services, remember preferences, keep accounts secure, understand usage, diagnose problems, measure marketing, and advertise our Services. At launch, our website will use Google Analytics to measure visits and interactions. If we enable a Meta pixel for paid advertising, it may collect information about interactions with our website to help us measure and deliver advertising, subject to applicable law and available choices. Such tools may receive browser and device information and information about website interactions, depending on their configuration. We do not intentionally provide customer SMS opt-in data or call recordings to advertising partners for their own advertising purposes.

You may be able to control certain cookies and similar technologies through your browser or device settings. Disabling cookies may affect the availability or functionality of parts of the Services. Where required by applicable law, we will process a valid Global Privacy Control or other legally recognized opt-out preference signal as an opt-out of applicable sale, sharing, or targeted-advertising processing associated with the browser or device that transmits the signal.

We may send marketing and promotional communications by email, text message, telephone, or other lawful channels. You may opt out of marketing emails by using the unsubscribe mechanism in the message or contacting us as described below. Opting out of marketing communications does not prevent us from sending transactional, account, security, legal, or other non-marketing communications.

10. Retention

We retain personal information for as long as reasonably necessary to provide, support, maintain, secure, and improve the Services; administer accounts, subscriptions, payments, prepaid credits, campaigns, and integrations; comply with legal, tax, accounting, security, and recordkeeping obligations; process privacy requests; resolve disputes; enforce our agreements; and protect our rights and the rights of others.

Retention periods vary based on the information’s nature, sensitivity, source, purpose, legal requirements, and the risks associated with retaining or deleting it. For example, we may retain:

  • account, authentication, and business-contact information while an account is active and afterward as reasonably necessary for account administration, security, legal compliance, dispute resolution, fraud prevention, and enforcement;
  • billing, payment, subscription, credit, refund, chargeback, and transaction records as reasonably necessary for accounting, tax, audit, payment-dispute, fraud-prevention, and legal purposes;
  • messages, campaign records, consent records, opt-out and suppression information, communications metadata, and complaint-related records as reasonably necessary for service administration, compliance, carrier and registry obligations, dispute resolution, and legal claims;
  • where recording is enabled, call audio, recordings, transcripts, call metadata, announcement wording and setting records, consent and objection records, and AI-assisted summaries, CRM updates, and follow-up drafts as reasonably necessary to provide the requested feature, maintain security, address complaints or disputes, comply with law, and preserve relevant evidence;
  • Customer Data during the subscription and after termination as provided in the Terms, subject to applicable backup, legal-hold, security, and recordkeeping practices;
  • website, device, cookie, analytics, advertising, and usage information as reasonably necessary to operate, secure, analyze, improve, market, and measure the Services, subject to applicable opt-out choices; and
  • privacy-request, verification, security, incident-response, audit, and compliance records as reasonably necessary to process and document requests, protect security, comply with law, and establish, exercise, or defend legal claims.

When we no longer need personal information, we will delete, destroy, de-identify, or aggregate it in accordance with our practices and applicable law. Backup and archival records may be retained for a limited period under our business-continuity and disaster-recovery practices.

11. U.S. Privacy Rights and Choices

Depending on your state of residence and the nature of our processing, you may have rights to request access to, correction of, deletion of, or information about personal information we maintain about you. You may also have the right to opt out of certain processing, including the sale or sharing of personal information, targeted advertising, or certain profiling, where applicable.

To submit a privacy request, email legal@goagentnode.com with the subject line “Privacy Request.” Please provide sufficient information for us to verify your request and identify the information at issue. We may request additional information to verify your identity or authority to act for another person. You may use an authorized agent where permitted by applicable law; we may request signed authorization and verify your identity directly.

If you are entitled to appeal a decision regarding a privacy request, email legal@goagentnode.com with the subject line “Privacy Request Appeal.” We will respond to verified requests and appeals within the period required by applicable law. We will not discriminate against you for exercising privacy rights available under applicable law.

California Notice at Collection

If the California Consumer Privacy Act, as amended, applies to our processing, this section supplements the disclosures above with a notice at collection. Descriptions of features planned for launch or tools that may be enabled later do not mean those practices occurred during any preceding 12-month period.

We may collect the following categories of personal information: identifiers; personal information described in California Civil Code section 1798.80(e), such as contact and billing information; commercial information; internet or other electronic network activity information; general geolocation information derived from IP address; professional or employment-related information; communications and support information; and inferences drawn from usage or interaction information. We may also process limited sensitive personal information, such as account credentials or information a customer submits through the Services, but do not use or disclose sensitive personal information to infer characteristics about an individual.

We collect these categories directly from individuals and customers, including through customer-directed calls and recordings where enabled, automatically through the Services and our website, from authorized integrations, and from service providers and other sources described in this Privacy Policy. We use them for the purposes described in Sections 5 and 6 and disclose them for business purposes to the recipient categories described in Section 7. Section 9 describes website analytics and potential advertising tools separately from customer mobile opt-in information.

We do not sell mobile opt-in data processed through the Services or share it for cross-context behavioral advertising. If we sell or share personal information as those terms are defined by California law, we will provide any required notice and opt-out method. We honor legally recognized opt-out preference signals where required by applicable law.

California residents may have rights to know, access, correct, delete, opt out of sale or sharing, limit certain uses or disclosures of sensitive personal information, and receive equal service and pricing. The availability and scope of these rights are subject to applicable law and exceptions.

12. Security

We use reasonable administrative, technical, and physical safeguards designed to protect personal information from unauthorized or unlawful access, use, destruction, loss, alteration, or disclosure. Our safeguards may include access controls, authentication measures, least-privilege practices, encryption or other protections for information in transit and at rest where appropriate, logging and monitoring, security updates, vendor oversight, incident-response procedures, and personnel confidentiality or training requirements.

No system, website, transmission, or storage method is completely secure. You should use caution when transmitting information to us through email, text message, or other communications channels.

13. Children’s Information

The Services are intended for businesses and adult users and are not directed to children. We do not knowingly collect personal information from children under 13 years of age. If you believe we have collected personal information from a child in error, please contact us at legal@goagentnode.com.

14. International Access

The Services are intended for use in the United States. If you access the Services from outside the United States, you do so only with our prior written approval and understand that your information may be processed in the United States or another location where we or our service providers operate, subject to applicable law.

15. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will post the updated version through the Services and revise the “Last Updated” date. If we make a material change, we will provide additional notice when required by applicable law.

16. Contact Us

If you have questions about this Privacy Policy or our privacy practices, or if you wish to submit a privacy request, contact us at:

Whiteworth Inc.
2810 N Church St, STE 88617
Wilmington, DE 19802
legal@goagentnode.com