Legal
Privacy policy
What data passes through the system, where it sits, for how long and who sees it.
A working draft, not a final text
The document below describes what the system does accurately, but it has not been through a lawyer. Do not use it as a published policy until somebody qualified has.
What passes through
A call produces call metadata (numbers, duration, state), events with millisecond offsets, the transcript, the messages exchanged with the model, latency metrics, costs and, if you turned it on, an audio recording.
Account data: name, email address, role, organization. Billing data: usage, credits, invoices. Payment methods do not pass through our system; the payment processor holds them.
Where it sits
The installation database and storage sit in the configured region, the European Union by default. Recordings and artefacts can be moved to your own bucket, in which case you choose the region.
The transcription, model and voice vendors process audio and text on their own infrastructure. Which vendors are used is your configuration, and the list is visible in the console on each assistant.
How long we keep it
Retention is a policy per organization, applied by a job that runs daily. Anything past the policy is deleted.
Personal-data redaction, if enabled, masks card numbers, email addresses, phone numbers, IBANs and national identifiers in transcripts and logs.
Who can see it
Members of your organization, by role and permission. Every access to a recording goes through a short-lived signed URL, and changes are written to the audit log.
Platform staff have operational access to the infrastructure. What that means concretely, and how it is limited, has to be written here before this document is published.
What you can ask for
Access, correction, erasure, portability and objection, to the extent the applicable law gives them to you.
What each of those means in practice differs, and this page used to overstate two of them. Deleting a recording works on demand. Erasing the rest of a call runs through the retention policy or a command and has no interface; the API endpoint that deletes a call is a soft delete. There is no per-data-subject export — the CSV on the billing page is usage, not personal data. The data-rights page gives the state of all five.
Who else touches the data
The providers you configure yourself: the telephony carrier, transcription, the model, speech synthesis. Plus the hosting infrastructure and the payment processor.
The complete list is published and is generated from the same registries the console reads, so it cannot describe a vendor that is no longer selectable or omit one that has just become selectable. It carries what each vendor processes and where it says it processes, and it is honest about what is missing: no legal entity names, and no signed onward agreement with any of them.
Questions this document does not answer
It is a working draft and it says so. If your data protection officer needs something more specific than it gives, ask — a compliance page with a gap in it is a bug.