Security & Compliance
Public one-pagerThis is the public security and compliance one-pager for CallBotAgent.ai. The full DPA and security questionnaire responses are published on the public legal pages of callbotagent.ai. For binding contractual commitments see the Data Processing Addendum; for the live vendor list see the Sub-Processors List.
Introduction
CallBotAgent.ai is a voice AI platform for e-commerce. We process personal data of your customers (name, phone number, order details, call content) on behalf of your store as a data processor under GDPR. This document summarises what we do by default — no upcharge, no asterisks — to pass every GDPR audit and every CISO conversation. If a control your compliance team requires is missing, email us at [email protected].
For binding contractual commitments see the Data Processing Addendum; for the live list of vendors and processing regions see the Sub-Processors List.
1. Data ownership — your data stays yours
We never sell, share, or reuse your data for any purpose other than running your store. At any point you can export or delete everything from the admin panel — no request to us needed.
Aggregated and de-identified usage statistics may be computed for product improvement, capacity planning, and security purposes; that data does not identify you or your end-customers.
2. GDPR by default — DPA, audit logs, data-subject rights
DPA (Data Processing Addendum) accepted electronically at subscription signup — template based on EU Commission SCC (Standard Contractual Clauses) Modules 2 and 3 with the UK Addendum and Swiss adaptations as applicable.
Data subject rights implemented in the admin panel:
- Right to erasure — customer data deletion within ≤ 30 calendar days of request.
- Right to access — export of all recordings, transcripts, and metadata in JSON / CSV.
- Right to rectification — editing of customer attributes directly in the panel.
Audit logs — every access to customer data is logged (admin, IP, timestamp, action) and retrievable for 12 months.
Recording consent — every Call begins with a configurable announcement; Customer is responsible for the wording and adequacy in each market.
3. Automated PII redaction
Payment-card numbers, national IDs, e-mail addresses, surnames, and other PII are automatically detected in call transcripts and replaced with placeholder tokens before writing to the database. Detection uses regex + Named Entity Recognition.
Audio recordings are available in the admin panel only to authorised store operators. They never reach logs, analytics, or BI dashboards.
Recording retention is configurable: default 90 days, minimum 7 days for complaint handling, maximum 24 months. After the period, recordings are deleted automatically.
4. Your conversations do NOT train AI models
End-customer data (recordings, transcripts, metadata) is not used to train, fine-tune, or evaluate AI models — neither ours nor any of our providers'.
Each provider in the chain (LLM, TTS, voice-AI orchestrator) operates under a zero-retention contractual restriction: every Call is processed in request-response mode, nothing is retained after session end.
Our own internal models (intent classifiers, fraud detectors) are trained exclusively on synthetic data or on customer data with explicit research consent captured in the DPA (opt-in, default OFF).
5. Encryption at-rest + in-transit
At-rest: AES-256 for all data — recordings, transcripts, metadata, backups.
In-transit: TLS 1.3 for all communication between CallBotAgent.ai, Customer's store (Shopify), telephony providers, and the voice-AI orchestrator.
Encryption keys are rotated automatically every 90 days via managed KMS (Google Cloud KMS, EU region).
Backups encrypted with separate keys from production data (segregation of duties); retained 90 days, then automatically destroyed.
Admin panel infrastructure: MFA mandatory for admin accounts; SSO (Google Workspace / Microsoft 365) for Enterprise.
6. Transparent sub-processors list
The full, up-to-date list of all third-party processors handling end-customer data is published at /sub-processors. The list is categorised by function (voice-AI orchestrator, LLM, TTS, telephony, hosting, billing, storefront integration) and disclosed openly per CLAUDE.md governance.
Sub-processor changes: every change (addition / removal / region change) communicated with at least 30 days' advance notice via the Sub-Processors page changelog and via the change-notification mailing list. Customers have an objection right within 30 days.
Document availability
| Document | How to access |
|---|---|
| DPA (Data Processing Addendum) | Public legal page — accepted electronically at subscription signup |
| Sub-processors list | Public page (/sub-processors) — updated continuously |
| Security questionnaire response (CAIQ Lite) | Public legal page — PDF + JSON download |
| Incident response procedure (summary) | Public security page — full incident notification flow defined in the Master Subscription Agreement and DPA |
| Privacy policy (for store end-customers) | Public legal page (/privacy) |
What we do NOT have (explicitly)
In the spirit of stack transparency, we state upfront what is work-in-progress:
- ISO 27001 — we do not hold this certificate; working on it in the longer term.
- SOC 2 Type II — we do not hold this report; working on it in the longer term.
- HIPAA — we do not service the US healthcare market, nor do we plan to (e-commerce focus).
- PCI DSS Level 1 — we do not process end-customer payment-card data. Payments are handled by the store through its own Shopify Payments / Stripe / PayU. CallBotAgent.ai does not see, store, or process end-customer card numbers.
- FedRAMP / IL5 — not applicable (commercial market, not government).
What we offer instead today:
- DPA modelled on SCC with GDPR clauses
- Sub-processors list with full DPA chain
- Security questionnaire response in CAIQ Lite format
- Own incident response playbook (summary)
Contact
- General inquiries: [email protected]
- Security incident report: [email protected] (subject prefix
[SECURITY INCIDENT]) - DPA / compliance: [email protected] (subject prefix
[DPA REQUEST]) - Privacy / data subject rights: [email protected]
- EU representative: [email protected] (see Legal Notice)
- Phone: +1 (719) 624-4435
- Postal address: 1111B S Governors Ave STE 39750, Dover, DE 19904, USA
Response SLAs:
- Security incident report — acknowledgment within 4 business hours
- DPA / compliance inquiries — acknowledgment within 2 business days