GDPR Compliance

GDPR Compliance

Our commitment to European data protection regulations and individual privacy rights

Regulation (EU) 2016/679

GDPR Principles

The six core principles that guide all data processing activities under GDPR

Lawful Processing

Personal data must be processed lawfully, fairly and in a transparent manner.

Purpose Limitation

Data must be collected for specified, explicit and legitimate purposes.

Data Minimization

Only collect data that is adequate, relevant and limited to what is necessary.

Accuracy

Personal data must be accurate and kept up to date.

Storage Limitation

Data should not be kept longer than necessary for the purposes.

Integrity & Confidentiality

Data must be processed in a manner that ensures security and confidentiality.

Accountability

Organizations must demonstrate compliance with GDPR principles.

Individual Rights

Eight fundamental rights that individuals have under GDPR

Right to Access

Article 15

Individuals have the right to know what personal data is held about them.

Right to Rectification

Article 16

Individuals can have their personal data rectified or incomplete data completed.

Right to Erasure

Article 17

Individuals can request deletion of their personal data (right to be forgotten).

Right to Restriction

Article 18

Individuals can limit how their data is processed.

Right to Portability

Article 20

Individuals can receive their data in a structured, commonly used format.

Right to Object

Article 21

Individuals can object to processing based on legitimate interests or direct marketing.

Our Compliance Measures

Technical and organizational measures implemented to ensure GDPR compliance

Data Protection Officer

  • Dedicated DPO appointed and contact details published
  • Regular training and awareness programs for staff
  • Data protection impact assessments (DPIAs) conducted
  • Privacy by design principles implemented

Security Measures

  • AES-256 encryption for data at rest and in transit
  • Multi-factor authentication for all user accounts
  • Regular security audits and penetration testing
  • Incident response procedures and breach notification

Data Processing Records

  • Complete records of all data processing activities
  • Data processing agreements with all third parties
  • Regular reviews and updates of processing records
  • Transparent data flow mapping and documentation

Data Processing Information

How we collect, process, and protect personal data

Lawful Basis for Processing

We process personal data based on the following lawful bases under GDPR Article 6:

Performance of Contract

Processing necessary for providing our AI voice services

Legitimate Interest

Improving services and preventing fraud

Legal Obligation

Complying with applicable laws and regulations

Consent

Where required for specific processing activities

International Data Transfers

When personal data is transferred outside the European Economic Area (EEA), we implement appropriate safeguards:

  • • Standard Contractual Clauses (SCCs) approved by the European Commission
  • • Adequacy decisions for countries with appropriate protection levels
  • • Binding Corporate Rules (BCRs) for intra-group transfers
  • • Certification schemes providing adequate protection

Data Retention Periods

We retain personal data only as long as necessary for the purposes for which it was collected:

Account DataDuration of account + 6 years
Call Recordings30 days (configurable)
Analytics Data24 months (anonymized)
Consent Records7 years (legal requirement)

GDPR Inquiries

Contact our Data Protection Officer for GDPR-related questions or to exercise your rights

Email: [email protected]

Phone: +17196244435

Address: 1111B S Governors Ave STE 39750, Dover, DE 19904, USA

Response Time: Within 30 days of request