Privacy Policy

How Ciaomatic collects and uses personal data as a controller — for our account holders, website visitors, and usage data.

Version 1.0 (draft) · 11 July 2026

This Privacy Policy explains how [[ENTITY_LEGAL_NAME]] ("Ciaomatic", "we", "us"), with registered office at [[REGISTERED_ADDRESS]], collects and uses personal data for which we are the controller. This includes data about our account holders, their team members, prospective customers, and visitors to our website.

For personal data contained in the calls our customers' agents handle — call recordings, transcripts, and caller phone numbers — we act as a processor on behalf of our customer, who is the controller of that data. Our handling of that caller data is governed by our Data Processing Addendum and by the customer's own privacy notice, not by this Policy.

1. Data we collect

Account and contact data

When you sign up or contact us, we collect identifiers such as your name, email address, organization name, and authentication details (managed through our authentication provider), and your language preference.

Billing data

When you subscribe, our payment processor collects and processes your payment details. We receive billing metadata such as your plan, billing country, subscription status, and invoices; we do not store full card numbers.

Usage and configuration data

We collect data about how you use the Service, including your agent configurations, phone numbers, integration connections (with credentials stored encrypted), call and usage metadata (such as counts, durations, and outcomes), test-call and verification activity, and audit records of administrative actions.

Website and device data

When you visit our website or dashboard, we may collect technical data such as IP address, browser and device information, and a functional language-preference cookie (see Cookies below).

2. How and why we use data

We use personal data to provide, secure, and improve the Service; to authenticate users and manage accounts; to process payments and prevent fraud and abuse; to enforce our Terms and Acceptable Use Policy; to send transactional and service emails; to provide support; to comply with legal obligations; and to communicate about the Service. Our legal bases (where the GDPR applies) are performance of our contract with you, our legitimate interests in operating and securing the Service, compliance with legal obligations, and, where relevant, your consent.

3. Cookies

We use a small number of strictly functional cookies. In particular, the "ciaomatic_locale" cookie stores your chosen language so we can show the site in the right language. It is set only when you explicitly choose a language and is not used for advertising or cross-site tracking. Because it is strictly necessary for a feature you request, it does not require a consent banner, but we disclose it here for transparency. Our authentication and payment providers may set their own strictly necessary cookies to operate sign-in and checkout.

4. Subprocessors and service providers

We rely on the following providers to operate the Service. They process personal data on our behalf under appropriate agreements:

  • Twilio — telephony: phone numbers, call routing, and optional call recording.
  • OpenAI — AI voice models that power the agent's speech and understanding.
  • Cloudflare — hosting, application infrastructure, storage, and security.
  • Stripe — payment processing and subscription billing.
  • Clerk — user authentication and account management.
  • Resend — delivery of transactional and service emails.

This list may change as the Service evolves; we will keep it up to date. Some of these providers process data outside your country, including in the United States.

5. International transfers

Where we transfer personal data outside the European Economic Area or the United Kingdom, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses or an adequacy decision, as applicable.

6. Data retention

We keep account and billing data for as long as your account is active and thereafter as needed to comply with legal, tax, and accounting obligations and to resolve disputes. Usage and audit records are retained for operational and security purposes. Retention of caller call data (recordings and transcripts) is configurable per organization and is described in the DPA.

7. Your rights

Depending on your location, you may have rights to access, correct, delete, port, or restrict the processing of your personal data, to object to certain processing, and to withdraw consent. Where the GDPR applies, you may also lodge a complaint with your supervisory authority. To exercise your rights, contact us at [[PRIVACY_CONTACT_EMAIL]]. If your request concerns caller data our customer controls, we will direct you to, or coordinate with, that customer.

8. Security

We use technical and organizational measures to protect personal data, including encryption of integration secrets and access controls. No system is perfectly secure, but we work to protect your data and to respond appropriately to incidents.

9. Children

The Service is intended for businesses and is not directed to children. We do not knowingly collect personal data from children.

10. Changes and contact

We may update this Policy from time to time; each version is dated. For privacy questions or to exercise your rights, contact us at [[PRIVACY_CONTACT_EMAIL]] or by post at [[REGISTERED_ADDRESS]]. Our data protection contact is [[DPO_CONTACT]].