Trust & Compliance Center
GDPR Compliance
How Callwise AI protects your data, ensures voice processing integrity, and respects caller rights under the General Data Protection Regulation (GDPR).
01
Our Commitment to GDPR
The General Data Protection Regulation (GDPR) is a comprehensive privacy law that regulates the processing of personal data of individuals in the European Union (EU) and European Economic Area (EEA). At Callwise AI, we are committed to meeting the stringent requirements of the GDPR across all of our systems, ensuring that caller audio stream processing, intent transcript storage, and calendar integrations respect European data privacy standards.
Our architecture has been engineered with "privacy-by-design" principles, making compliance seamless for European businesses deploying Callwise receptionists on their telephone networks.
02
Data Controller & Processor
Under GDPR, it is critical to distinguish the roles and responsibilities in the processing of personal data:
• Callwise as Data Processor: When our AI answers calls, processes transcripts, qualifies leads, and logs schedule slots for your business, we act purely as a Data Processor. Your business is the Data Controller, dictating the instructions, CRM integrations, and training boundaries of the receptionist.
• Callwise as Data Controller: We act as a Controller only for the basic registration, configuration, and telemetry data collected directly from our clients (such as your account details, portal login logs, and direct subscription billing).
03
Lawful Basis for Processing
To legally process any caller data in European jurisdictions, we assist controllers in establishing the appropriate lawful bases:
• Consent: For voice recording and transcript storage, callers are notified explicitly at the start of each session. Continued interaction acts as consent, or alternative keypads can be configured.
• Contractual Necessity: Processing is necessary to complete a booking, check schedule calendars, or perform qualification tasks explicitly requested by the calling client.
• Legitimate Interest: Providing basic operational security, spam protection, and real-time fraud mitigation on inbound phone calls.
04
Your Rights Under GDPR
We provide the necessary technical utilities to ensure European callers can exercise their data subject rights easily:
Right to Access
Callers can request a full package of their voice WAV files, caller transcriptions, and logged CRM fields.
Right to Erasure
Commonly known as the "Right to be Forgotten." Clients can trigger complete, irreversible deletion of caller history logs.
Right to Portability
Export operational metrics and lead qualification history in standard, machine-readable JSON formats.
Right to Rectification
Enable callers or agents to correct mis-transcribed names, addresses, or phone details inside the portal dashboard.
Restriction of Processing
Temporarily pause AI model evaluation on specific caller items during auditing periods.
Right to Object
Callers retain the right to object to automatic call processing and request immediate manual routing to human personnel.
05
Data Protection Measures
Our technical and organizational security controls ensure robust protection for telephony pipelines and user profiles:
• AES-256 Encryption: All call metadata, audio records, and calendar credentials are encrypted at rest with AES-256 and in transit with TLS 1.3.
• Access Control & Auditing: Fine-grained access privileges ensure that only authenticated workspace personnel can query portal transcripts. All internal access events are securely audited.
• Regular Pen-Testing: Callwise engages external, accredited security firms annually to perform penetration tests against our voice proxy servers and REST endpoints.
06
International Data Transfers
When call data originating from the European Economic Area (EEA), the United Kingdom, or Switzerland is transferred outside these territories, we ensure a compliant and protected environment:
Callwise relies on the European Commission's Standard Contractual Clauses (SCCs) incorporated within our global Data Protection Addendum (DPA) to govern transfers to processing hubs. Additionally, we participate in and comply with the EU-U.S. Data Privacy Framework regarding the processing of caller telemetry.
07
Data Breach Notification
In the highly unlikely event of a security compromise impacting our telephony databases or transcript partitions, Callwise maintains a dedicated Incident Response Plan:
We commit to notifying affected clients and supervisory authorities within 72 hours of becoming aware of any confirmed personal data breach, in full compliance with Article 33 of the GDPR.
08
Approved Sub-Processors
We partner with select technical sub-processors to power telephony delivery and infrastructure:
Entity Name
Purpose
Location
Amazon Web Services (AWS)
Cloud hosting, server compute & secure transcript database storage
Frankfurt (EU)
Twilio Inc.
Telephony proxy, SIP trunks, and cellular signal routing
Ireland / US
Stripe, Inc.
Secure billing interface and monthly transaction processing
Global
09
Data Protection Officer
If you have any questions regarding this policy, our DPA agreement, or wish to invoke data subject rights, our appointed DPO can be reached directly:
Callwise AI Data Protection Operations
Email: dpo@callwise.ai
Address: 480 Telephony Way, Suite 800, San Francisco, CA 94107
Submit a Data Subject Request (DSR)
Need to retrieve your Callwise records, delete historical calling transcripts, or execute privacy rights? Click below to load our secure request portal.
Launch DSR Portal
Callwise AI
The smart, instant 24/7 AI answering receptionist that ensures service businesses never leak a single valuable lead.