Privacy Policy

What data we process, why, where it is stored and for how long — and your rights.

Last updated 20 July 2026

What data we process

Account data: the name, email address and sign-in details of whoever manages the account, and your business profile — opening hours, services and the information the receptionist answers from.

Call data: transcripts of the calls, and any audio recordings if recording is turned on. The transcript lets you read what was said and improve the receptionist.

Booking and message data: when the receptionist books an appointment or takes a message, the content is stored in the audit trail (the tool_calls log). This can include the name and phone number of the caller, because it is needed to carry out the booking or deliver the message.

Usage and billing data: the number of minutes and calls, and what is needed to bill for the usage.

Why we process it

We process the data to deliver the service: answer the phone, book appointments, take messages, show you the call log and bill for usage. We collect as little as possible — the receptionist does not ask for sensitive personal data, and a booking is created only when the caller asks for it themselves.

We do not sell personal data, and we do not use it for anything other than delivering and improving the service.

Where the data is stored

What we store ourselves — account data, call logs, bookings and messages — sits in the EU. The database runs in Frankfurt, and the servers that handle call and booking traffic also run in Frankfurt.

The call itself is handled by the voice AI of a US-based subprocessor. Full EU data storage requires an extended agreement with the provider, which we have not enabled. So we do not claim the voice data is processed in the EU — that data flow is governed by the data processing agreement (DPA).

Read the data processing agreement (DPA)

How long we keep it

Transcripts and any audio recordings held by the voice-AI provider are kept for 30 days and then deleted.

Account data and the call log in our own database are kept for as long as you have an active account, and deleted on cancellation or when you ask — subject to the exceptions required by law, for example accounting-record obligations for invoice data.

Your rights

Under the General Data Protection Regulation (GDPR) you have the right to access, rectification and erasure of personal data we process, and the right to request restriction of processing or to have your data ported to you.

For data about the people who call your business, you are the controller and we are the processor — we process it on your instructions. The terms for that are set out in the data processing agreement.

You can also complain to the Norwegian Data Protection Authority (Datatilsynet) if you believe the processing breaches the rules.

Contact

Questions about privacy, or want to exercise your rights? Write to us at support@phoneless.io and we'll help you.