Privacy Policy
This Privacy Policy describes how CallBotAgent, Inc. (the "Operator", "we", "us") collects, uses, discloses, and protects personal data, and how you can exercise your rights under applicable law (including GDPR, the UK GDPR, the California Consumer Privacy Act / CPRA, the Brazilian LGPD, and PIPEDA). For European customers and data subjects, we have designated an EU representative under Article 27 GDPR; full identity and contact details are in our Legal Notice.
1. Introduction & Scope
This Policy applies globally to all visitors of our marketing site, all users of the Platform (Customers and their Authorized Users), and to End-Customers whose personal data is processed by the Platform on a Customer's behalf.
This Policy is designed to satisfy the notice obligations under Article 13 GDPR, the analogous obligations under the UK GDPR, the CPRA's notice-at-collection requirement, the LGPD information-rights requirement, and similar laws. Where mandatory local law provides additional rights, we honor them to the minimum extent required.
This Policy is read together with our Terms of Service, our Data Processing Addendum, the Cookies Policy, and the Sub-Processors List.
2. Roles & Entities
2.1 Operator
CallBotAgent, Inc., a Delaware corporation (US), is the operator of the Platform globally. It owns the Platform, contracts with all Customers, issues invoices via Stripe, and runs marketing.
2.2 EU Representative
The Operator has designated an EU representative under Article 27 GDPR for the European Economic Area, the United Kingdom, and Switzerland. Data subjects in those territories may exercise their rights and address requests to either the Operator or the EU representative; both routes reach the same compliance team. The representative's full identity and corporate registration are published in our Legal Notice; for direct contact use [email protected].
2.3 Roles under the GDPR
The Operator's role depends on the data category:
| Data category | Operator's role | Controller (if not Operator) |
|---|---|---|
| Marketing-site visitor data (cookies, IP, page views, form submissions) | Controller | — |
| Customer account data (email, name, billing details, panel usage, support tickets) | Controller | — |
| End-Customer data processed during Calls placed by the Platform | Processor (acting on Customer's documented instructions per the DPA) | The Customer (the merchant) |
| Aggregated and de-identified usage statistics | Controller (data is no longer personal data) | — |
3. Personal Data We Collect
3.1 From marketing-site visitors
- Cookies and similar technologies (Section 5 and Cookies Policy)
- IP address (where required for security and abuse prevention)
- Browser/device metadata, referrer, pages visited, session duration
- Email addresses and any text submitted in contact forms, demo requests, or newsletter sign-ups
3.2 From Customers (account holders)
- Account: business name, contact name, email, phone, role/job title
- Billing: business address, VAT number (where applicable), invoicing email; full payment-card data is collected by Stripe directly and never stored by the Operator
- Authentication: hashed password, MFA secrets, login session metadata
- Platform usage: configuration choices, scripts, catalog mapping, panel actions, IP, browser, time-stamps
- Support communications: ticket content, screenshots, recordings of demo calls
- Marketing preferences: email subscription state, event attendance
3.3 From End-Customers (during Calls placed for Customers)
Processed as processor on the Customer's behalf — see DPA. Categories typically include name and phone number (provided by the Customer's e-commerce store), order metadata (order ID, items, value, payment method, delivery address summary), Call audio recording (where Customer has enabled recording), Call transcript and machine-generated metadata (intent classification, outcome, accept/decline of upsell, sentiment if Customer enables that feature), and information freely provided by the End-Customer during the Call.
Special categories of personal data within the meaning of Article 9 GDPR are not requested by the Platform by design. If End-Customers volunteer special-category information during a Call, the PII redaction layer will detect and redact it from transcripts where feasible; recordings are subject to retention controls. Customer must not configure scripts that solicit special-category data.
Voice audio is processed for communication, not biometric identification. The Platform processes voice audio (raw recordings and transcripts) solely to conduct, transcribe, and summarise voice conversations on Customer's behalf. The Platform does not apply any technical processing or analysis of voice audio for the purpose of uniquely identifying a natural person within the meaning of Article 4(14) GDPR (Biometric Data); voiceprint generation, speaker recognition, voice-based authentication, and similar identification techniques are not features of the Platform. Accordingly, voice audio processed by the Platform does not, by itself, constitute special-category data under Article 9 GDPR.
3.4 From third parties
- Shopify (Customer's connected store): order webhooks and catalog data, on Customer's instruction
- Telephony providers (Twilio, Telnyx, Vonage): call signalling data and disposition (answered, busy, no-answer)
- Payment processor (Stripe): subscription state and invoice metadata
- Identity-verification providers (Enterprise only, where applicable)
4. Purposes & Lawful Bases
4.1 Marketing-site visitors
| Purpose | Lawful basis (GDPR Art. 6) |
|---|---|
| Operate and secure the website | Legitimate interests (Art. 6(1)(f)) — security, abuse prevention |
| Analytics, attribution, and conversion measurement | Consent (Art. 6(1)(a)) where required by ePrivacy Directive |
| Respond to contact-form / demo requests | Pre-contractual measures at your request (Art. 6(1)(b)) |
| Send marketing emails (newsletter) | Consent (Art. 6(1)(a)); soft opt-in for existing customers under PECR / national law |
4.2 Customer accounts
| Purpose | Lawful basis |
|---|---|
| Provide the Service (account, panel, calls) | Performance of contract (Art. 6(1)(b)) |
| Billing and accounting | Performance of contract + legal obligation (Art. 6(1)(b), (c)) |
| Security, fraud prevention, KYC/KYB | Legitimate interests + legal obligation (Art. 6(1)(c), (f)) |
| Customer support | Performance of contract (Art. 6(1)(b)) |
| Service improvement based on aggregated data | Legitimate interests (Art. 6(1)(f)) — aggregated and de-identified |
| Service-update emails | Performance of contract (Art. 6(1)(b)) |
4.3 End-Customer data (processor capacity)
Processed only on the Customer's documented instructions per the DPA. The Customer is responsible for identifying its own lawful basis for the processing and for the consents and notices it provides to End-Customers.
5. Cookies & Analytics
We use cookies and similar technologies on the marketing site and (in a more limited way) inside the Platform admin panel. Strictly-necessary cookies are set by default; non-essential cookies (analytics, marketing/attribution) are set only with consent where required by law. You can manage your cookie preferences via the consent banner shown on first visit and at any time via the cookie-preferences link in the footer. For details on each cookie category, third-party providers, retention, and how to opt out, see the Cookies Policy.
6. AI & Automated Decisions
The Platform uses automated processing (large language models, intent classifiers, scoring) to generate AI Outputs during a Call. None of this processing constitutes a decision with legal or similarly-significant effect on a data subject within the meaning of Article 22 GDPR — the AI Outputs are advisory inputs into the Customer's own decisions (e.g., whether to ship an order). Material decisions about an End-Customer that are based on AI Output remain the Customer's responsibility and are subject to human review.
We do not use End-Customer recordings, transcripts, or other personal data to train, fine-tune, or evaluate AI models — neither our own nor those of our Sub-Processors. This restriction is contractual: each Sub-Processor that receives End-Customer data has signed a zero-retention addendum or equivalent commitment.
7. Sharing & Disclosures
7.1 Sub-Processors
We disclose personal data to vetted Sub-Processors that act on our instructions and under written data-processing agreements that include the technical and organisational measures, breach-notification, audit, and sub-processor-control obligations required by Article 28 GDPR. Categories include:
- Voice-AI orchestrator (provider name not disclosed publicly per our hidden-vendor policy)
- LLM providers (e.g., OpenAI, Anthropic, Google) — zero-retention
- Text-to-speech providers (e.g., ElevenLabs, Cartesia, OpenAI voices) — zero-retention
- Telephony providers (Twilio, Telnyx, Vonage) — call signalling and PSTN delivery
- Cloud infrastructure (Google Cloud, EU regions) — hosting, storage, database
- Billing (Stripe) — subscription billing as merchant of record where applicable; PCI DSS Level 1
- Storefront integration (Shopify) — OAuth and webhook source; Shopify is the Customer's data controller for the underlying store data
- Email and transactional messaging, Error monitoring, Product analytics (subject to consent where applicable)
The current Sub-Processors List with provider names where disclosable, regions, and DPA status is published at /sub-processors. Customers receive at least 30 days' prior notice of any change.
7.2 Other recipients
- Professional advisors (lawyers, accountants, auditors) under confidentiality
- Law-enforcement and regulators where required by valid legal process and after our review of legality
- Acquirer in a corporate transaction (sale, merger, restructuring) under confidentiality and continuity of this Policy
7.3 No sale of personal information
We do not sell personal information for monetary or other valuable consideration as defined under the CPRA and similar US state laws. We do not engage in cross-context behavioural advertising as defined under the CPRA without consent and an applicable opt-out.
8. International Transfers
Personal data collected in the EU/EEA, UK, or Switzerland may be transferred to the United States (where the Operator is incorporated) and to other regions in which Sub-Processors operate. Where the destination country has not been recognised as adequate, we rely on:
- The Standard Contractual Clauses (Module 1 controller-to-controller, Module 2 controller-to-processor, or Module 3 processor-to-sub-processor as applicable);
- The UK Addendum to the SCCs (where UK personal data is involved);
- The Swiss adaptations and the FDPIC's recognition of the EU SCCs;
- Supplementary technical measures (encryption in transit and at rest, access control, key management) and contractual measures (zero-retention addenda, data-minimisation by Sub-Processors).
A Transfer Impact Assessment ("TIA") summary is maintained as an internal compliance record and informs the Operator's safeguard design.
9. Retention
| Category | Default retention | Notes |
|---|---|---|
| Marketing-site cookies and analytics | Up to 13 months | Per ePrivacy guidelines (CNIL standard); shorter on consent withdrawal |
| Newsletter subscription | Until unsubscribed; opt-out events kept 5 years for proof of consent | |
| Customer account data | For the duration of the subscription + period required by applicable law (typically 5–10 years for invoice-related records) | Driven by tax, accounting, and bookkeeping retention laws |
| Customer-support tickets | 3 years | |
| End-Customer Call recordings | Customer-configurable: 7 days minimum, 90 days default, 24 months maximum | Customer instructs, processor executes |
| End-Customer Call transcripts | Up to 24 months (default 12) | PII-redacted in storage; full transcript only for authorised Customer staff |
| Audit logs (account access, admin actions) | 12 months minimum | |
| Anonymised / aggregated usage statistics | Indefinitely | Not personal data after anonymisation |
10. Security
We implement technical and organisational measures appropriate to the risk, including:
- Encryption in transit (TLS 1.3) and at rest (AES-256);
- Encryption-key rotation every 90 days via managed KMS (Google Cloud KMS, EU region);
- Backups encrypted with a separate key set from production data;
- Multi-factor authentication mandatory for admin accounts; SSO for Enterprise on request;
- Access control on a need-to-know basis with role-based permissions and quarterly access reviews;
- Audit logging of access to End-Customer data, retained for at least 12 months;
- Automated PII redaction on transcripts before write to long-term storage;
- Vulnerability scanning, dependency monitoring, and security patching on production infrastructure.
Detailed measures are described in the DPA Annex on Technical and Organisational Measures and in the public Security One-pager.
No system is perfectly secure. You are responsible for securing your own devices and credentials. Notify us at [email protected] as soon as you suspect a breach of your account.
11. Your Rights
Subject to applicable law you may have the following rights with respect to your personal data:
- Access: a copy of the personal data we hold about you;
- Rectification: correction of inaccurate or incomplete personal data;
- Erasure (right to be forgotten): deletion subject to legal-obligation retention;
- Restriction: temporarily limit processing while a dispute is resolved;
- Portability: receive personal data you provided in a structured, machine-readable format;
- Objection: object to processing based on legitimate interests, including for direct marketing;
- Withdraw consent: where processing is based on consent, you may withdraw it at any time;
- No automated decision-making: as described in Section 6, we do not make Article 22 decisions;
- Lodge a complaint: with the supervisory authority of your habitual residence, place of work, or alleged infringement (e.g., the data-protection authority of your EU/EEA Member State, the Information Commissioner's Office in the United Kingdom, the Federal Data Protection and Information Commissioner in Switzerland, or the California Privacy Protection Agency in California). The Operator's designated EU representative (see Legal Notice) is also a valid contact for European data subjects.
To exercise any right, contact us at [email protected] (Operator) or [email protected] (EU Representative). We respond within 30 days for GDPR/UK GDPR requests and within 45 days for CPRA requests, with a possible extension where the request is complex.
For requests involving End-Customer data: please contact the merchant whose store you ordered from first; we forward all such requests to the merchant in accordance with the DPA.
13. Do Not Track / Global Privacy Control
Where applicable law requires us to honor opt-out preference signals (such as the Global Privacy Control / GPC), we do so. There is no industry consensus on responding to "Do Not Track" (DNT) browser signals; we do not currently respond to DNT outside the legal scope of GPC. Where required, our cookie banner provides parity-equivalent controls.
14. California / US States Disclosures
This section provides additional disclosures required by the CPRA and similar US state laws (Virginia VCDPA, Colorado CPA, Connecticut CTDPA, Utah UCPA, Texas, Florida, Oregon, Iowa, Indiana, Tennessee, Montana, Delaware, Maryland, and others).
14.1 Categories of personal information collected
Identifiers; commercial information; internet/network activity; geolocation (approximate, derived from IP); inferences drawn from the foregoing. We do not collect "sensitive personal information" within the meaning of CPRA other than account credentials.
14.2 Sources, business purposes, and recipients
As described in Sections 3, 4, and 7.
14.3 Right to know, delete, correct, opt-out of sale/sharing, limit sensitive PI
You have those rights as described in Section 11. To submit a request, contact [email protected]. Authorized agents may submit on your behalf with verifiable consent.
14.4 Right to non-discrimination
We do not discriminate against you for exercising your privacy rights.
14.5 Notice of financial incentives
We do not offer financial incentives in exchange for personal information.
14.6 Shine the Light
California residents may request information about disclosure of personal information to third parties for direct-marketing purposes during the prior calendar year. We do not disclose for this purpose.
15. Changes to this Policy
We may update this Policy to reflect changes in our services, legal requirements, or practices. We will post the updated Policy with a new "Last Updated" date and, for material changes, give notice by email or in-app notice at least 30 days in advance. Continued use of the Service after the new Policy takes effect constitutes acknowledgment.
16. Contact
CallBotAgent, Inc.
1111B S Governors Ave STE 39750
Dover, DE 19904, USA
Telephone: +1 (719) 624-4435
Privacy: [email protected]
Security incidents: [email protected]
Designated EU representative
For data subjects in the EU/EEA, the United Kingdom, and Switzerland.
EU contact: [email protected]
Full corporate identity and registered office: Legal Notice.