Roles
For the personal data inside your account — contacts, recordings, transcripts, messages and everything derived from them — you are the controller and we are the processor. We act on your documented instructions, and using the platform as intended is one of those instructions.
For data about your own account holders, meaning the people at your company who log in, we are the controller. The privacy policy describes what we do with it.
What we process, and why
- Categories of data: contact identifiers, call audio, transcripts, message content and metadata, and the scores and playbook signals derived from them.
- Categories of people: your customers and prospects, and your own staff who use the platform.
- Purpose: providing the service, and nothing else. We do not process your data for our own purposes.
- Duration: for as long as your agreement runs, plus the deletion window set out below.
Sub-processors
We use a small number of sub-processors: cloud infrastructure, carriers and messaging providers, and the tooling that keeps the service running. The current list, with what each one receives and where it sits, is attached to the signed agreement. We notify customers before adding one, and you can object.
Security measures
- Encryption in transit and at rest, with keys managed by us or by you on enterprise plans.
- Access by role, scoped per campaign, with SSO and SCIM available.
- No standing staff access to customer recordings. Support access is kept to a fixed time, approved by you, and appears in your audit log.
- Payment card data detected and redacted before recordings are written to storage.
- Independent penetration testing, with the summary available under NDA.
- An audit log of every access, export and approval, with an actor and a timestamp.
Transfers and residency
Residency is chosen at account setup and does not move afterwards. Where a transfer out of a region is necessary, it is made under the appropriate mechanism — the standard contractual clauses for EU data — and named in the signed agreement rather than left implicit.
How we assist you
- We help you respond to data subject requests, including access, correction and deletion.
- We notify you of a personal data breach affecting your data within the window the agreement specifies, with what we know at the time rather than after the investigation closes.
- We help with data protection impact assessments where our processing is what is being assessed.
Deletion and return
You can export your data at any time. On termination, and on request during the agreement, data is deleted within the window the agreement specifies. Deletion removes the audio, the transcript, the derived scores and the CRM mirror — it is a real deletion rather than a hidden flag.
Audit
You can audit our compliance with this agreement once a year, and more often where a regulator requires it. In practice most customers are satisfied by the penetration test summary, the security overview and a completed questionnaire, all of which we would rather hand over early than defend late.
This page is a summary, written to be readable. The executable agreement is the document that binds either of us, and it is issued during procurement — ask through the contact page and we will send it.