Callper privacy policy

This policy explains what Callper SRL does with personal data when you use the Callper dashboard, visit callper.ai, talk to our voice demo, book a demo with us, or write to us, and when we write to or phone your business first. It is written to meet Articles 13 and 14 of the GDPR. Related documents: the terms of service, the data processing agreement that governs the data your business entrusts to us, the sub-processor register, the caller notice for people who phone a business that uses Callper, and the Zero Data Retention processing description.

1. Who we are

The controller for the processing described in this policy is:

Callper SRL, a company registered in Romania, VAT RO55481408, trade register number J2026050795000

Registered office: Aeroportului Street no. 1D, building III, 4th floor, apt. 38, 700384 Iași, Romania

Privacy contact: office@callper.ai

Write to the privacy contact for anything in this policy: questions, requests to exercise your rights, or a complaint you want us to look at first.

2. Who this policy is for, and who it is not for

Callper answers the phone for businesses. Three groups of people meet our processing, and this policy covers the first two:

3. What we collect and why

Each row below names the data, what we use it for, the legal basis under Article 6 of the GDPR, and how long we keep it. Retention is covered in more detail in section 6.

DataWhere it comes fromPurposeLegal basisKept
Sign-in identity: name, email address, sign-in method (email, Google, Facebook or Apple), organization membership and role. If you sign in with Google or Facebook, that provider passes us the name, email address and profile picture on your account there. If you sign in with Apple, Apple passes us your name the first time only, and no picture; the email address it passes is your own or, if you choose Apple's Hide My Email, an address Apple creates that forwards to yoursYou, at sign-up and when an owner invites you; or Google, Facebook or Apple, at your request, when you choose to sign in with it; held by ClerkSigning you in, keeping each business's data separate from every other business's, owner and staff permissionsContract (Art. 6(1)(b))Life of the account, then deleted immediately on account deletion (section 6)
Your business's contact number: the phone number you give us at sign-up so that we can reach your businessYou, at sign-up; you can change it on the Preferences pageReaching you about your account, your billing and service issues. We never give this number to your callers, our assistant never speaks it, and we do not pass it to anyone else except as section 4 says. One use is yours: when you place a test call from your dashboard and it books an appointment, that booking in your own calendar carries this number as the attendee's, because the attendee is your businessContract (Art. 6(1)(b))Life of the account; erased with it (section 6)
Business identity: company name, address, country, VAT numberYou, at checkout; read back from the Stripe customer recordInvoicing and EU VAT, the identity the telephony provider requires before it will sell a phone numberContract; legal obligation for tax and telecoms identity rules (Art. 6(1)(c))Life of the account; invoices for the statutory period (section 6)
Billing: invoices, payment status, plan, subscription stateStripe, and our own mirror of what Stripe tells usCharging for the service, showing you what you pay and until whenContract; legal obligation for accounting recordsStatutory retention for invoices, held at Stripe
Payment methodYou, entered on Stripe's hosted pages. Card details never reach Callper. No card is asked for at sign-up; you enter one when you buy somethingPaymentContractHeld by Stripe
Assistant configuration: greeting, instructions, business hours, knowledge base text, FAQ entriesYou; or, when you ask us to build your first assistant from your own website, read from up to six of its public pages by our software and Anthropic (section 4) and shown to you as guesses to confirmRunning the assistant you configuredContractLife of the account; erased with it
Uploaded knowledge filesYouThe text is extracted and kept; the file itself is discarded after extraction. We keep the file name, size and type so you can see what you uploadedContractText: life of the account. File bytes: not kept
Voice-clone sampleYou (a recording of a named person's voice)Building a custom voice for your assistant. The sample is streamed to Telnyx and is not stored by Callper; Telnyx keeps it until the clone is deletedContract. You are responsible for having the consent of the person whose voice it isAt Telnyx until you delete the voice or the account
Phone-number paperwork: identity documents, company certificates, addressesYou, when filing a requirement group for a numberMeeting the regulatory conditions under which the telephony provider sells numbers in your countryLegal obligation (telecoms know-your-customer rules); contractDocuments pass through Callper to Telnyx and are not stored by us; we keep only a label (a file name, a summary). Telnyx holds them until the requirement group is deleted
Calendar connection: a Cal.com API key or OAuth tokens you supply, and a mirror of your event typesYouChecking availability and booking appointments in your own calendarContractLife of the connection; encrypted at rest; deleted when you disconnect or delete the account
Call records: date, time, duration, direction, outcome, cost, the caller's number and country, the transcript and a summary (unless Zero Data Retention is on)Generated when your assistant handles a callShowing you what happened on your line, billing minutes, letting you follow upContract. For the caller's personal data in these records, your business is the controller and we act on your instructions under the DPALife of the account; erased with it
Contacts and appointmentsYou (typed or imported) and, for appointments, the booking itselfYour business records about your own customersYou are the controller; we process under the DPALife of the account, or until you erase a contact
Cancellation feedback: a reason code and an optional free-text line, with the business nameYou, optionally, when cancellingUnderstanding why customers leaveLegitimate interest (Art. 6(1)(f)): improving the service. Never compelledKept after the account is gone; the business name is a snapshot, not a link to your data
Trial record: a one-way code made from the account owner's email address, the trial minutes left on the account, and the date it closedGenerated when an account is deleted or erasedMaking the free trial once per person: a new account on the same address is given what was left of the earlier trial, not a new oneLegitimate interest: stopping the free trial from being claimed again by closing the account and signing up again (Art. 6(1)(f))Kept after erasure, with no end date. It holds no email address: the code is a keyed hash, which cannot be turned back into an address and can only be matched against an address that signs up again
Deletion request record: who asked, when, and what was removed at each providerGenerated when you delete the accountProving that the deletion happened and reached every providerLegal obligation (accountability, Art. 5(2)); legitimate interestKept after erasure
Provider event log: the events Stripe, Telnyx and Clerk send us, with their identifiersGeneratedProcessing each event once, and proving what we did and whenLegitimate interest: reliability and accountabilityFor as long as we run the service. A row is the provider's delivery identifier, the event type and what we did with it: no message content, and nothing that names you
Support and sales correspondenceYou, when you write to usAnswering youLegitimate interest; contract where you are a customerUnder our control in Google Workspace: while your account is open, and in any case no more than 24 months after the last message in a thread. Google enforces no rule for us, so we delete it by hand
Demo booking: your name, email address and timezone, and the booking itselfYou, on our booking page, which HubSpot hosts for us (section 4) and which opens in a tab of its ownHolding the demo you asked for, and following it upSteps you asked for before any contract (Art. 6(1)(b)); legitimate interest in following up a demoIn HubSpot (section 4) from the moment you book: 12 months after the last time we or you wrote or spoke, unless you become a customer. Nothing deletes it automatically yet, so we delete it by hand (section 6). A demo booked through our earlier booking page, at Cal.com, also stays in that account until we close it (section 4)
Contact details of a business we contact first: the business's name, email address, phone number, postal address and website, and the name of a person at the business where its website gives oneNot from you. We found them ourselves: on the business's own public website; on OpenStreetMap, a public map whose data is published under the Open Database Licence; and, for lists built from October 2026, on two public registers that list practices by name and address: for GP practices, the list of GPs holding a GMS contract that the HSE's Primary Care Reimbursement Service publishes, and, for veterinary practices, the Veterinary Council of Ireland's register of veterinary premises. A register tells us that a practice exists and where. The HSE's list of GMS contract holders gives neither an email address nor a phone number, so for a GP practice found there both come from the practice's own website. The HSE's public Find a GP service lists GP practices with a phone number and, for some, an email address and a website; from 5 October 2026 we may write to a GP practice at the email address that service publishes for it, or at one its own website publishes. The Veterinary Council's register also publishes an email address and a phone number for each premises, and from 5 October 2026 we may write to a veterinary practice at the email address the register publishes for its premises, whichever mail provider that address is at, because the register gives it as the contact address of that practice. Before we write we check that the address exists (section 4). Our first email says which register, if any, we found the practice on, and whether the email address came from itTelling businesses about Callper by email and by phone, and following up if they do not answer. Before the first email we check once that the address exists, through a verification service (section 4) that asks your mail server whether the mailbox is there without sending anything to it; an address that does not exist is never written to. Every email is addressed to one business alone and comes from a mailbox a person at Callper reads. It is our own text with your business's name in it, sent by our own software through that mailbox a few at a time across the working day, with a copy logged on our record of your business in HubSpot, and with open and click tracking switched off. If you reply, our answer may be written and sent by an AI model rather than a person: it signs itself "Callper's AI Assistant", in its name and at its foot, and it answers only from a fixed sheet of facts about Callper. A person at Callper reads every answer it sends. A question those facts do not answer, a complaint, anything about your data, and any conversation that has gone past a first answer are passed to a person at Callper instead, and once a person has written to you in a conversation, the AI does not write in it again. Every call is made by a person, never by our AI assistant; it may be placed through HubSpot's calling service, is not recorded, and the caller's notes of it are kept on the same recordLegitimate interest (Art. 6(1)(f)): offering our service to businesses that take bookings by phone, using the contact details they publish so that people can reach them. You can make us stop at any time, and we do (section 7)In HubSpot and in our Google Workspace mailboxes (section 4), in the list we built from those sources, on our own computer, and in our record of what we sent your business and what came back, in our own database (section 4): 12 months after the last time we or you wrote or spoke, unless your business becomes a customer. Nothing deletes it automatically yet, so we delete it by hand (section 6)
Voice demo calls: a written transcript of what you and our demo assistant said, the time and length of the call, and, if you phone the demo number, the number you call from and the country it belongs to (unless you withhold it). A call from the browser carries no phone number. For a call in English, from the card or to the demo number, also a recording of the call, your voice and the assistant's on separate tracks ("The voice demo", below)You, when you press Call in the demo on callper.ai or phone the demo number we publishLetting you hear what Callper does by talking to it; for a phone call, giving each number a fair share of the demo's daily talking time; afterwards, checking that the demo answers correctly and is not being abused, and learning what people ask it so that we can improve the demo and the product. The recording has one purpose: finding the fault when the assistant stops mid-call, which a transcript cannot showLegitimate interest (Art. 6(1)(f)): letting someone who chooses to try the product hear it, and keeping a free demo working. Nobody has to call, the demo asks you for nothing, and nothing from the call is used to contact you. You can object to the recording at any time (section 7, and "The voice demo" below)30 days from the call, then deleted, here and at Telnyx, the recording included. Nothing deletes them automatically yet, so we delete them by hand (section 6)
A website you ask us to build an assistant from: the address you type, the text of up to six public pages of that website, the business profile read from them (the business's name, address, phone number, email address, opening hours, services and common questions, and any person's name the pages give with them, such as a practitioner's), and the draft assistant built from that profileThe address from you, when you use the builder on callper.ai; everything else from the public pages of that website, which our own software reads at your requestBuilding a draft assistant from the website so that you can hear it answer before you decide anything, and, if you sign up and keep it, making it your first assistant so that you retype nothingLegitimate interest (Art. 6(1)(f)): letting someone who is considering Callper hear it work for their own business. Only public pages of the one website named are read, only what a phone assistant needs is kept, and nothing from it is used to contact anyone ("An assistant built from a website", below)7 days from the build, then deleted by a scheduled job, unless you sign up and keep it within those 7 days. A kept draft becomes your account's assistant configuration (the row above)
Calls to an assistant built from a website (the preview, up to three minutes): a transcript, the time and length of the call, and, for a call in English, a recording, as for a call to the voice demo from the browserYou, when you press Call on the draftAs for the voice demo: letting you hear the assistant, and afterwards checking that it answered correctly and is not being abused. The recording has the voice demo's one purpose: finding the fault when the assistant stops mid-callLegitimate interest, as for the voice demo30 days from the call, then deleted, here and at Telnyx. Nothing deletes them automatically yet, so we delete them by hand (section 6)
Your internet address, when you use the demo or the builder in the browserYour browser, automaticallyGiving each internet connection a fair share of the demo's daily talking time, and one call at a time; for the builder, three builds a day, one at a timeLegitimate interest: keeping a free demo available to everyone rather than to whoever calls the mostIn the server's working memory until midnight UTC the same day, and never written to our database. Our server log records a short code in its place, which changes every day and can only be matched to an address with a key we hold. The log is kept about a month (section 6). For the builder we store a code made from the address, never the address itself: it is keyed with a secret we hold and with the day, so it changes every day, and it is erased from the record of the build the day after. It is pseudonymous rather than anonymous, because with that secret we could match a known address to it. The record that a build happened (when, whether it finished and what it cost us) stays, and names nobody once the code is gone
Server logs: IP address, request path, timestamps, errorsYour browser, automaticallySecurity, fault-findingLegitimate interest: keeping the service secure and workingIn the system journal on our own server in Romania, which is bounded by the space it may take on disk rather than by a date — about a month in practice (section 6)
Language preferenceYou, from the language pickerShowing the site and dashboard in your languageLegitimate interest; strictly necessary for the service you asked forOne year, in a cookie on your device (section 8)
Transactional email: the address and the message content (for example a cancellation confirmation or a low-balance warning)YouConfirming the acts that matter on the accountContractSent through Scaleway, in France. Scaleway states no retention period for the log of messages we have sent, and its API offers us no way to delete an entry from it: on 22 September 2026 that log still held every message we had ever sent, the oldest from 12 August 2026
A founding customer's reference: the business's name and town, two sentences someone at the business wrote about Callper, and one figure, the number of calls Callper's assistant answered for the business out of hours in its first month. Where the business's name is a person's, as a sole trader's is, or a practice's named after its practitioner, all of it is information about that personYou, when you agree to it by email; the figure is counted by us from your own call records, on your written instruction ("A founding customer's reference", below)Showing on callper.ai, in every language of the site, and in our sales material what Callper has done for one of its first customersConsent (Art. 6(1)(a)), asked for in an email of its own and given by replying to it. The free months do not depend on it, and you can withdraw it at any time (section 7)While the reference is in use; taken off callper.ai and out of our sales material within seven days of a withdrawal. The emails in which you agreed or withdrew are kept as the record of it, on the rule for support and sales correspondence above

We do not process special categories of data about dashboard users. The content of your callers' conversations may contain anything a caller chooses to say; how that is handled is the subject of the caller notice and the DPA.

The voice demo

The demo on callper.ai, and the demo phone number we publish, put you through to Callper's own assistant. For those calls Callper is the controller, because no business that uses Callper is involved, so this policy applies to them rather than the caller notice.

An assistant built from a website

On callper.ai you can type the address of a business's website and hear, a minute or two later, an assistant built from what that website says. For this Callper is the controller. This section is the information the GDPR asks us to give both to the person who types the address and to the people whose details that website publishes.

A founding customer's reference

Callper's first ten customers are offered three months of the Basic plan free. Separately, we ask each of them whether we may name them as a customer. For this Callper is the controller, and it rests on your consent.

4. Who receives your data

We use a small number of service providers. Every one of them is listed, with its legal entity, country, role and transfer footing, in the sub-processor register. The ones you will meet as a dashboard user or visitor:

ProviderWhat it doesWhereRole
Clerk, Inc.Sign-in, sessions, organization membershipUnited StatesOur processor
Stripe Payments Europe, Ltd (with Stripe, Inc. and Stripe Technology Company, Ltd)Checkout, invoicing, tax, the billing portalIreland; United StatesSee below: joint controller for payment processing, our processor otherwise
Telnyx LLCPhone numbers, calls, the AI assistant (its speech-to-text, language model and voice all run on Telnyx's own systems, so no other company receives a call), voice clones, number paperwork, and since 22 September 2026 the nightly backup of our whole database, encrypted on our own server before it is sent and unreadable to Telnyx, which does not hold the passphrase (section 6)A United States company. A call is processed live at the Telnyx site nearest to it, which may be outside the European Union; what Telnyx keeps of a call is stored in Germany, and the backup copy is held in Telnyx's eu-central-1 region, in the European UnionOur sub-processor for your callers' data; our processor for your configuration and paperwork, and for calls to our own voice demo, including the recordings of its English calls (section 3)
Scaleway SASTransactional emailFranceOur processor
Google Cloud EMEA Limited (with Google LLC behind it)Our support and business mailboxesIreland for the contract; the mailboxes are not stored only in EuropeOur processor
TES EURO MEDIA SRL (Gazduire.Net)The server in Bucharest that runs the dashboard, the API and the database, and the host's own daily and weekly backups of that server. Everything Callper stores is stored hereRomania; the host's backups may also sit in Germany, encryptedOur processor
Infisical Inc. (EU instance)Configuration secrets for our own systems. Holds no personal data about youEuropean UnionInfrastructure
HubSpot, Inc.Our own customer-relationship system, and the page where you book a demo with us: who asked us about Callper and who booked a demo, which businesses we have contacted first and what they answered (and, for them, the emails we write, sent through our own mailbox with no open or click tracking, and the calls we place through it, which are not recorded), who signed up (and the contact number your business gave us, on the company record), and how this public site is used — and, if you accepted the analytics cookies and then signed up, which pages this browser read before you did (section 8). Holds nothing about your callersData stored in the European Union (Germany); HubSpot, Inc. is a US companyOur processor
Anthropic Ireland, Limited (with Anthropic, PBC behind it)Three jobs, the third under the Data Processing Agreement as our sub-processor for that one purpose: when you ask us, after signing up, to build your assistant from your own website, the AI model that reads the public pages of that website and returns the business profile your assistant is built from, which you confirm before it is used (section 3, "Assistant configuration"). And two jobs of our own. The AI model that reads a reply to an email we wrote to your business first, decides whether it asks us to stop, shows interest, asks a question, says "not now" or needs a person, and writes our answer when the answer is on our fixed sheet of facts about Callper (section 3). And, when someone uses the builder on callper.ai, the AI model that reads the public pages of the website they named and returns the business profile a draft assistant is built from (section 3, "An assistant built from a website"). It sees those three things and nothing else: nothing about your callers, and nothing else a business that uses Callper keeps with us. It deletes what we send it and what it writes within 30 days, unless its safety checks flag the exchange as breaking its usage policy, when it may keep it for up to two years, and its terms forbid it to train its models on any of itIreland for the contract; the model runs in the United StatesOur processor
Bouncer Sp. z o.o.The email verification service that checks, once and before our first email, that the address we found for your business exists. It receives the address alone, asks your mail server whether the mailbox is there without sending anything to it, and keeps the address for at most 60 days; our script deletes the batch as soon as it has read the result. It runs in the European Union (Frankfurt)PolandOur processor
Cal.com, Inc.Our earlier booking page for a demo with us, at cal.com/callper, which no Book a demo link opens any more. This is our own Cal.com account: it holds the demo bookings made there before the page moved to HubSpot, takes no new ones, and is kept only until we close itUnited StatesOur processor, for those earlier demo bookings only

Google, Meta and Apple are where sign-in data comes from, not where it goes. If you sign in with Google or with Facebook, that provider sends Clerk your name, email address and profile picture, once, when you ask it to. If you sign in with Apple, Apple sends Clerk your email address, and your name only the first time, with no picture. Nothing travels the other way: we do not post to your Google, Facebook or Apple account, read anything beyond that profile, or share your Callper data with any of the three, except in one case. If you chose Apple's Hide My Email, the email address we hold is one Apple created for you, so the emails we send you go through Apple's relay, which forwards them to your real address. Apple runs that relay for you, under your own agreement with Apple, not for us. What Google, Meta or Apple records about the sign-in itself (and, for Apple, about the emails its relay forwards) is governed by its own privacy policy, and none of them is on our sub-processor register because none of them processes data for us.

Stripe is not an ordinary processor. For the regulated part of payment processing (anti-money-laundering, know-your-customer, fraud prevention and card-scheme rules) Stripe Payments Europe, Ltd and Stripe Technology Company, Ltd act as joint controllers with us, under their own legal obligations, for purposes we do not set. For everything Stripe does on our instructions (invoicing, tax calculation, the billing portal) Stripe is our processor. Stripe's own privacy policy describes what it does as a controller.

Cal.com appears in one role now, and it is not ours. If you are a dashboard user who connects a calendar, you connect your own Cal.com account under your own contract with Cal.com, and we send booking data to it on your instruction. That account is not our provider and is not on our sub-processor register; what Cal.com does with the data it holds for you is governed by your agreement with Cal.com. The one Cal.com account that was ours is the page at cal.com/callper where demos were booked until the booking page moved to HubSpot: Cal.com is our processor for what was typed there, it stays on the register as such until we close that account, and no demo is booked through it any more. A demo you book with us today is made on a page HubSpot hosts and is held in HubSpot (above), where the person who takes the demo sees who asked for it.

We do not sell personal data, and we do not share it with advertisers.

Requests from public authorities. We disclose personal data to a court, a supervisory authority, the police or any other public body only where the law obliges us to. Every such request is reviewed for its legal basis before anything is disclosed, and a request that does not carry one is refused. We disclose only the data the request lawfully requires and nothing more. We keep a record of each request: what was asked, by whom, the review, what was disclosed, and who at Callper was involved. We tell you about a request for your data unless the law forbids it. No such request had been received at the date of this policy.

5. International transfers

Callper claims GDPR compliance. Callper does not claim EU data residency, and you should not read this policy as saying your data never leaves the European Union.

What stays in the EU: your business records, your callers' records, transcripts, contacts, appointments and billing mirror are stored in Romania. What Telnyx itself keeps of a call (its call records and, on ordinary plans, the conversation) is stored in Telnyx's Germany region. Transactional email is sent from France. Our own secrets live on an EU instance. The nightly backup of that database stays in the European Union too, but no longer on our own server: an encrypted copy goes to Telnyx's eu-central-1 object storage (section 6). The objects do not leave the Union; the company holding them is American, which is why Telnyx has a second row in the table below. The host of our server also keeps its own daily and weekly backups of it, in Bucharest as a rule and possibly at Impossible Cloud GmbH in Hamburg, encrypted before they leave its data centre; those stay in the European Union too (section 6).

What leaves the EU, and on what footing:

RecipientCountryFooting for the transfer
Clerk, Inc.United StatesEU-U.S. Data Privacy Framework certification, with Standard Contractual Clauses in its data processing addendum as the fallback
Stripe, Inc.United StatesEU-U.S. Data Privacy Framework certification, with Standard Contractual Clauses in Stripe's data transfers addendum
Telnyx LLC, for calls and the AI assistant. The speech, language and voice models all run on Telnyx's own systems; no other company receives a callUnited States, for the company and for any call Telnyx processes at a site outside the European Union. Processing follows the call to the nearest Telnyx site and is not guaranteed to stay in the UnionEU-U.S. Data Privacy Framework certification, with the Standard Contractual Clauses in Telnyx's data processing addendum as the fallback
Telnyx LLC, for the encrypted database backupUnited States (staff access to objects stored in an EU region)The same footing. What the bucket holds is ciphertext; the passphrase is not kept there
Infisical Inc.United States (staff access to an EU-hosted instance)Standard Contractual Clauses
Cal.com, Inc. (the demo bookings made before our booking page moved to HubSpot)United StatesStandard Contractual Clauses, in the data processing agreement we signed with Cal.com on 29 September 2026. Cal.com, Inc. is not on the Data Privacy Framework list
Anthropic, PBC (the AI model that reads and answers replies to the emails we write to businesses first, that reads the website pages the builder on callper.ai is given, and that reads the website pages a business asks us to build its own assistant from)United StatesStandard Contractual Clauses in Anthropic's data processing addendum. Anthropic is not Data Privacy Framework certified as far as we can establish
Google LLC (our own mailboxes)United StatesEU-U.S. Data Privacy Framework certification, with the Standard Contractual Clauses in Google's Cloud Data Processing Addendum as the fallback

Transfer impact assessments for the US recipients are kept alongside the sub-processor register. If the Data Privacy Framework were invalidated, the Standard Contractual Clauses already in place would carry these transfers.

6. How long we keep data

While the account is open, we keep what section 3 lists for as long as you need the service to work.

When you delete the account, two things happen at different times:

  1. Immediately. Subscriptions are cancelled at Stripe, phone numbers are released to the telephony provider (and generally cannot be recovered), voice clones are deleted at Telnyx, and the Clerk organization and its logins are deleted. Nobody can sign in again.
  2. After 30 days. Your organization's own records are held in an archive for 30 days, unreachable from the dashboard, so that an account deleted by mistake can be restored: the owner signs up again with the email address the account was deleted with, and the account is offered back before anything new is created. Signing up and creating a new business instead ends that offer. At the end of the 30 days a scheduled job erases them permanently: assistants, call records, transcripts, summaries, notes, knowledge base, contacts, appointments, numbers, orders and members. The dialog you confirm says this before you confirm. On the same day the copy in our own customer-relationship system (HubSpot, section 4) goes too: your contact record is permanently deleted, and your organization's company record is deleted — HubSpot keeps a deleted record restorable for 90 days and then removes it.

If you need erasure sooner than 30 days, because you are exercising your right to erasure rather than closing an account you no longer use, write to office@callper.ai and say so. There is no button for it in the dashboard: an operator runs the erasure by hand, and it is the same erasure the scheduled job would have run on day 30.

What survives account deletion, and why:

Trial accounts. A self-serve sign-up gets 60 minutes for 10 days, and no card is asked for. The trial is once per person: if an earlier account on the same email address was deleted or erased, the new account gets what that account had left of its trial (possibly nothing) for 10 days, not a new 60. An account that ever had a paid plan leaves nothing. When the trial ends the account stays open — you can still subscribe — but it has nothing left to spend. If it never subscribes, it is erased 90 days after the trial ended, by a scheduled job. Fifteen days before that date we email the owner of the account: the day it will be erased, what goes with it, and that taking a plan keeps it. The job records that the message was accepted for delivery, and it will not erase an account without that record — so if the warning is sent but not delivered, the account stays until it is. An account with no confirmed email address to write to is deleted on the same schedule, because there is nobody to send the notice to: once it has gone fifteen days with no confirmed address, and still has none on the day, it is erased without one. The clock is always 10 + 90, so an account that never becomes a customer lives 100 days from sign-up whether it spent its minutes on the second day or never called at all. That erasure is the same one account deletion ends in and reaches the same places, including the transcripts held by the telephony provider and the copy in our customer-relationship system. An account that has ever had a paid plan is never touched by it, even if the plan was later cancelled.

Businesses we contacted first. If we found your business's contact details ourselves and wrote to you or phoned (section 3), we keep them for 12 months after the last time we or you wrote or spoke, and then delete them from HubSpot, from our mailboxes, from the list we built and from our record of what we sent. If your business becomes a customer, the rules for dashboard users above apply instead. No scheduled job enforces the 12 months yet, so we delete by hand. If you tell us to stop, we stop at once (section 7): we mark your record so that nobody at Callper writes to you or phones you again, and it is deleted on the same 12-month clock.

Demo bookings, and visitors who never become customers. If you booked a demo with us, your booking is kept in HubSpot on the same clock as above: 12 months after the last time we or you wrote or spoke, then deleted by hand, unless you become a customer. A demo booked through our earlier booking page, at Cal.com, is in that account too, on the same clock, until we close it. If you accepted the analytics cookies (section 8) and never signed up, HubSpot holds the pages this browser read against the random code in its cookie, not against a name or an email address. HubSpot gives us no way to delete those records by age, so they stay in our HubSpot account until that account closes, when HubSpot deletes them under its data processing agreement. On your device the cookies expire after six months at most, and refusing them deletes them at once (section 8).

When rent on a phone number lapses. If the monthly charge for a number fails, the number keeps working for a week, is then blocked, and on day 30 is released to the provider. Your call records for that number are not affected; they stay with the account.

Calls to our voice demo. The transcript, the call record, for a call in English the recording, and, for a phone call, the caller's number and its entry in the demo's contact list are kept for 30 days from the call and then deleted, from our database and from Telnyx (section 3, "The voice demo"). No scheduled job enforces the 30 days yet, so we delete by hand. The internet address the browser demo uses is never stored at all: it is forgotten at midnight UTC.

Assistants built from a website. A draft that nobody keeps is deleted 7 days after it was built, together with the pages read for it and the profile, by a scheduled job. If the person who built it signs up within the 7 days and keeps it, it becomes the new account's first assistant and follows the rules for dashboard users above. Calls to a draft are kept like calls to the voice demo: 30 days, deleted by hand until a scheduled job does. The record that a build happened is kept for as long as we run the service; the day-keyed code made from the internet address that asked for it is erased from it the day after, and from then on it names nobody.

A founding customer's reference. Kept while it is in use. Within seven days of a withdrawal it is taken off callper.ai and out of our sales material (section 3, "A founding customer's reference").

Backups. A dump of the database is taken every night and again before every deployment, and kept on the same server in Romania that holds the database itself. Since 22 September 2026 a copy of each nightly dump also leaves that server, so that losing the machine does not lose the backups with it. It is encrypted on the machine before it goes — AES-256, with a passphrase kept in our secrets manager and never in the place the copy lands — and sent to Telnyx Cloud Storage in the eu-central-1 region (section 4), which keeps it in the European Union. Telnyx stores the file and does not hold the passphrase, so it cannot read what is inside it. Dumps are deleted after 30 days in both places — deliberately the same clock as the archive above, so that none of our own backups holds data we have told you was erased — with two exceptions, both of them there so that a backup failure nobody has noticed cannot leave us with no copy at all: the seven most recent are always kept on the server, and if copies stop reaching the off-site storage we stop deleting the ones already there until they start arriving again. If we ever restore from a dump, anything that had already been erased is erased again.

The host of our server, TES EURO MEDIA SRL, also takes its own daily and weekly backup copies of the whole server, separately from our dumps. They are kept in its Bucharest data centre and may also be stored, encrypted with keys only the host holds, at Impossible Cloud GmbH in Germany. They are overwritten on the host's own cycle, whose exact depth it has not told us; its agreement with us deletes backups within 31 days of a deletion, and we take that as the outer bound. So data we have erased can survive in one of the host's copies for up to 31 days more. We cannot read those copies, and they exist only to restore the server after a failure; if the host ever restored from one, anything already erased would be erased again.

Server logs. The API and the reverse proxy write to the system journal on the server in Romania. It records the address a request came from, the path, the time and the response, and never the body of a request on a path that carries personal data. The journal is bounded by the space it may take on disk rather than by a date, which in practice means the oldest entries are overwritten after about a month. The logs of our scheduled maintenance jobs are separate: they record identifiers and outcomes rather than content, and are kept for 90 days.

7. Your rights

Under the GDPR you can ask us to:

Write to office@callper.ai. We answer within one month; if a request is complex we may take up to two further months and will tell you. We may ask you to confirm who you are before acting, normally by writing from the address on the account.

Complaining. You can complain to the Romanian supervisory authority, the Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP), B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, 010336 Bucharest, Romania — www.dataprotection.ro, anspdcp@dataprotection.ro — or to the supervisory authority in the EU country where you live or work. We would rather hear from you first, but you do not have to come to us before going to an authority.

8. Cookies

Three cookies are needed for the site to work at all. Four more measure how the site is used, and those are set only if you agree. You are asked the first time you visit, refusing is one click and costs you nothing, and you can change your answer whenever you like from Cookie settings in the footer.

Strictly necessary — always set. These need no consent under the ePrivacy rules, because without them the thing you asked for does not work.

CookieSet byWhat it doesLifetime
Session cookiesClerk, on callper.aiKeep you signed in to the dashboard. HttpOnly, SecureThe session
callper_localeCallperRemembers the language you chose in the language picker. Holds a two-letter language code and nothing elseOne year
callper_consentCallperRemembers whether you accepted or refused the analytics cookies below, so that you are not asked again on every page. Holds your answer and nothing elseSix months

Analytics — only if you accept. These are set by HubSpot, which we use as our own customer-relationship system. For as long as you are a visitor they tell us how people find Callper and which pages they read, so we can write better ones, and they name nobody. If you then sign up, and only if you accepted these cookies, the two are joined: on the page where you create your organization, right after signing up, we tell HubSpot the email address and name of your new account, and HubSpot attaches the pages this browser read on callper.ai before that moment — including where it arrived from — to your contact record. That is how we learn which pages and which channels bring customers, rather than only visits. It happens once, on that one page, and never inside the dashboard. If you refused the cookies there is nothing to join, and HubSpot learns of your sign-up only what the table of providers above says. It holds nothing about your callers.

CookieSet byWhat it doesLifetime
__hstc, hubspotutkHubSpotRecognise your browser between visits, so that someone who returns is counted once rather than as a new person each timeSix months
__hsscHubSpotTracks the current visit, so that pages read in one sitting are grouped together30 minutes
__hssrcHubSpotRecords whether this is a new browser sessionThe session

Three promises about those four. They are not set unless you accept — the script that sets them is not loaded at all until then, rather than loaded and told to behave. They are deleted if you refuse after having accepted, because a withdrawal that left them in place would not be a withdrawal; a withdrawal also ends the joining described above, so HubSpot keeps what it was already told and learns nothing more from this browser. And they are never set inside the signed-in dashboard — only on this public site and on the one sign-up page named above, whose address carries nothing about you — so nothing about your own records or your callers reaches HubSpot.

We run no advertising tags and no tracking pixels, and nothing above is used to make decisions about you (section 9). No email we send contains open or click tracking: not our transactional email, and not the emails we write to businesses we contact first. The links in them are ours and are not rewritten, the unsubscribe link included: it carries a signed code for your address and nothing else, and opening it records only that you asked us to stop.

9. Automated decisions

We make no decisions about you by automated means that have legal effects on you or affect you similarly significantly. Your plan, your invoices and your account status follow from what you bought, not from profiling.

If you reply to an email we wrote to your business first, an AI model reads the reply to decide how we answer it (section 3). What it decides is which of our answers to send, or to pass your reply to a person; it decides nothing about you that has a legal or similarly significant effect. A reply asking us to stop is honoured at once, whoever reads it, and when the model is not sure what a reply means, a person reads it.

Your assistant is an AI that speaks to your callers. What it does for them, and the fact that it is an AI, is described in the caller notice.

10. Children

Callper is a service for businesses. We do not offer it to children and do not knowingly collect personal data from anyone under 16. If you believe a child has given us data, write to office@callper.ai and we will delete it.

11. Security

Data at rest lives on a server in Romania. The copies that leave it are the nightly database backup, encrypted before it goes and held as ciphertext where it lands, and the host's own backups of the server, which stay in the European Union (section 6). Customer credentials we hold for you (a calendar key or token) are encrypted at rest. Card data never touches our systems. Identity documents pass through to the telephony provider and are not written to our storage or our logs. Access to production systems is limited to the people who operate the service. If a breach affects your data we will tell you and, where required, the supervisory authority within 72 hours.

12. When you are a caller, not a user

If you phoned a business that uses Callper, the business you called is the controller of what you said and of any details you gave. Callper processes that data only on the business's instructions. The caller notice is written for you: it says what the assistant is, what is processed where, what the business keeps, and how to ask the business for access or erasure. Direct requests about a call to the business you spoke with; if you write to us instead we will pass your request to them.

A call to our own voice demo is the exception. There the business you called is Callper, and section 3 ("The voice demo") is written for you.

13. Changes to this policy

We will post changes here with a new date at the top. For a change that materially affects dashboard users we will also email the account owner before it takes effect. Changes to the list of providers are notified under the DPA with a 30-day objection window.