Data Processing Agreement

Last updated 14 August 2026

Roles

For the personal data inside your account — contacts, recordings, transcripts, messages and everything derived from them — you are the controller and we are the processor. We act on your documented instructions, and using the platform as intended is one of those instructions.

For data about your own account holders, meaning the people at your company who log in, we are the controller. The privacy policy describes what we do with it.

What we process, and why

  • Categories of data: contact identifiers, call audio, transcripts, message content and metadata, and the scores and playbook signals derived from them.
  • Categories of people: your customers and prospects, and your own staff who use the platform.
  • Purpose: providing the service, and nothing else. We do not process your data for our own purposes.
  • Duration: for as long as your agreement runs, plus the deletion window set out below.

Sub-processors

We use a small number of sub-processors: cloud infrastructure, carriers and messaging providers, and the tooling that keeps the service running. The current list, with what each one receives and where it sits, is attached to the signed agreement. We notify customers before adding one, and you can object.

Security measures

  • Encryption in transit and at rest, with keys managed by us or by you on enterprise plans.
  • Access by role, scoped per campaign, with SSO and SCIM available.
  • No standing staff access to customer recordings. Support access is kept to a fixed time, approved by you, and appears in your audit log.
  • Payment card data detected and redacted before recordings are written to storage.
  • Independent penetration testing, with the summary available under NDA.
  • An audit log of every access, export and approval, with an actor and a timestamp.

Transfers and residency

Residency is chosen at account setup and does not move afterwards. Where a transfer out of a region is necessary, it is made under the appropriate mechanism — the standard contractual clauses for EU data — and named in the signed agreement rather than left implicit.

How we assist you

  • We help you respond to data subject requests, including access, correction and deletion.
  • We notify you of a personal data breach affecting your data within the window the agreement specifies, with what we know at the time rather than after the investigation closes.
  • We help with data protection impact assessments where our processing is what is being assessed.

Deletion and return

You can export your data at any time. On termination, and on request during the agreement, data is deleted within the window the agreement specifies. Deletion removes the audio, the transcript, the derived scores and the CRM mirror — it is a real deletion rather than a hidden flag.

Audit

You can audit our compliance with this agreement once a year, and more often where a regulator requires it. In practice most customers are satisfied by the penetration test summary, the security overview and a completed questionnaire, all of which we would rather hand over early than defend late.

This page is a summary, written to be readable. The executable agreement is the document that binds either of us, and it is issued during procurement — ask through the contact page and we will send it.

Frequestly Asked Questions About Hyperdial

Voice, chat, SMS, email and social on one intelligence layer, trained on your own calls and verified by your own managers. No fragmentation, no lock in.

Talk to us →
How is HyperDial different from an AI voice agent?

Every other AI voice product ships a model trained on someone else's conversations and asks you to prompt it into sounding like you. Hyperdial starts from your own recordings: it isolates what your closers do differently, how they handle the price objection, when they slow down, what they say before they ask. A manager approves the pattern, and only then does it speak to a customer.

Will HyperDial sound like our team?

It sounds like the reps it learned from, in the languages they sell in, even when they switch language mid sentence. You hear every voice and every learned pattern before it goes live.

What happens when HyperDial’s AI can’t handle a call?

It hands off to a human with the full context attached: transcript, intent, sentiment and the reason it escalated. The customer never repeats themselves.

How does HyperDial handle DPDPA and TSR compliance?

India data residency, consent capture, PII redaction, DNC scrubbing and a full audit trail on every call. On every plan, not as an upgrade.

How much call data does HyperDial need to learn your team’s communication style?

Around 500 recorded calls is enough for a first playbook. It keeps refining as new calls come in, and each refinement goes back through manager approval.

Can we keep our existing phone numbers with HyperDial?

Yes. Porting is free from any provider, with live status through the switch. Most teams see no service interruption at all.

Is building an AI voice agent in-house cheaper than using HyperDial?

In year one it looks cheaper. Then Indian language speech models, latency under 100 ms at concurrency, and QA for thousands of live calls each need a team you'd rather point at revenue work.

Your best rep already knows how to close. Let everyone else in on it.

14 day trial · No credit card · Live in days

SECURITY & COMPLIANCE
GDPR COMPLIANT
Encrypted in transit and at rest, stored in region