Privacy and data
Call recordings contain personal data about your customers and your agents. This page explains what Caller does with that data and what controls you have. The full legal text is in the Privacy Policy, the Terms of Service and the Data Processing Agreement.
What is stored for a call
Section titled “What is stored for a call”- The recording, as you uploaded it.
- The transcript, with who speaks and at what minute of the call.
- The analysis: title, summary, topic, outcome, customer sentiment, and the score for each criterion with its explanation.
- The data the call is filed under: agent, campaign, date, direction and, if you sent them or they were in the file name, the customer’s name and phone number.
Where the data is processed, and who is involved
Section titled “Where the data is processed, and who is involved”Everything is stored and processed in the European Union. Caller does not do all of it with its own means: the server, the storage of the recordings, the transcription and the AI models that analyze each call are provided by European suppliers, which act on our instructions under a data processing contract.
What is worth knowing:
- Transcription is done by an outside provider, which receives the whole recording. As soon as it returns the transcript, its copy is deleted.
- The analysis is done by AI models from another provider, which receives the transcript, your template and the passages of your knowledge base that apply. It keeps neither the requests nor the answers.
- Nothing is used to train models, ours or the providers’.
The list of providers, with what each one receives and where it processes it, is in the Privacy Policy and in the annex of the Data Processing Agreement. If the list is going to change, we give 30 days’ notice.
Who can listen to a recording
Section titled “Who can listen to a recording”Recordings have no public address. To play one, the app requests a temporary permission that expires after 10 minutes. It is granted only to someone who is signed in and can see that call: the people who work with the account, the agent who took it if you have given them access and, if you have given it, the people of the client it belongs to. Who sees what is in Users and permissions. A link to a call (https://app.caller.ee/calls/…) does not let anyone who cannot sign in to that account see or hear anything.
Hide personal data in transcripts
Section titled “Hide personal data in transcripts”In Settings → Security, turn on PII redaction. From then on, in every new transcript these kinds of data are replaced with a tag before the transcript is stored and before the AI reads it:
| Data | Replaced with |
|---|---|
| Email addresses | [EMAIL] |
| Phone numbers | [PHONE] |
| DNI | [DNI] |
| NIE | [NIE] |
| IBAN | [IBAN] |
| Card numbers | [CREDIT_CARD] |
A sentence such as “my DNI is 12345678Z and my email is marta@example.com” is stored as “my DNI is [DNI] and my email is [EMAIL].”
It is off by default. Before you turn it on, keep in mind that a criterion such as “the agent asks for the DNI” can still be evaluated, because the request stays in the text, but a criterion that needs to read the number itself cannot.
Sentiment: only the customer’s
Section titled “Sentiment: only the customer’s”Caller estimates how the customer feels during the call. It does not estimate the agent’s emotions: the EU AI Act prohibits inferring a person’s emotions in the workplace (Article 5(1)(f)). The metrics that are calculated for the agent are objective: how much they talk, how fast, and how much silence there is.
Delete calls
Section titled “Delete calls”When you delete a call, from its page or in bulk from Calls, its recording, its transcript, its analysis and the values of its custom fields are erased at once, and the call disappears from the app: from lists, from search and from reports. This cannot be undone, and there is no trash.
All that remains of the call is a record with no content: its dates, its length and the minutes it used. It keeps no names, phone numbers, file name or anything that was said or scored.
On the free plan, deleting a call does not give storage back: its allowance counts everything uploaded. This is explained in Plan and limits.
Delete recordings after a set time
Section titled “Delete recordings after a set time”On the Business plan, an administrator can set, under Settings → Security → How long recordings are kept, a time of 30, 60, 90 or 180 days, or 1 or 2 years. Each call is deleted by itself once it is that old, counted from the day it was uploaded.
- It is deleted as it would be by hand: recording, transcript and analysis, for good. Its figures stop counting in the analytics.
- Setting a time deletes at that moment the calls that are already older. Before you confirm, the app says how many there are.
- A client can have a time of its own, different from the account’s. Its calls follow that one.
- Calls are checked several times a day, so one may take a few hours to go after reaching its time. A call that changes client may take up to a week to follow the new time.
Removing the time brings nothing back: it only stops deleting.
Export your data
Section titled “Export your data”- Calls and their results, as CSV, from Calls.
- The figures for a period, from Analytics.
- Your profile data, as JSON, from Settings → Advanced → Export JSON.
Delete the account
Section titled “Delete the account”Go to Settings → Advanced → Delete Account. The account and everything in it are permanently erased: recordings, transcripts, analyses, templates, documents, agents, campaigns and API keys. This cannot be undone, and we cannot recover anything afterward.
If you want to keep something, export it first.
The only thing that remains is a fingerprint of your email address together with what the account had used of its plan: the minutes of the current period and the storage. It is kept for 12 months and serves one purpose: that deleting an account and creating it again does not start the free allowances afresh. The fingerprint lets us recognize the same address if it signs up again, but it cannot be turned back into the address, and nothing else is kept with it. An account that had used nothing leaves nothing. You can object by writing to us.
Keys and secrets
Section titled “Keys and secrets”Caller does not store API keys in plain text: it keeps a fingerprint that lets it recognize a key, not read it. That is why a key is shown only when you create it. Slack and Teams webhook addresses, which work like passwords, are shown truncated once they are saved.
Questions about data protection
Section titled “Questions about data protection”The Data Processing Agreement is part of the terms you accept when you create the account; you do not need to ask for it. For questions about how data is processed or about exercising data protection rights, write to caller@sumgrey.com.