Legal
Privacy Policy
Last updated May 2026
Data controller
Scope
This Privacy Policy applies to visitors of callilio.com, trial and paying business customers, and end callers whose data is processed on behalf of our customers (where Callilio acts as a processor). It is drafted to comply with the EU General Data Protection Regulation (GDPR / DSGVO) and Austrian implementation law (DSG).
Data we collect
- Account & billing
- Name, business email, company name, billing address, subscription status, and payment metadata processed by Stripe (we do not store full card numbers).
- Product usage
- Call metadata, transcripts, booking records, configuration settings, audit logs, and support tickets you submit.
- Website & marketing
- IP address, device/browser type, pages viewed, referral source, and — with consent — analytics and marketing cookies.
- Communications
- Content of messages you send via our contact form or email, plus delivery metadata.
Legal bases (Art. 6 DSGVO)
| Processing | Legal basis |
|---|---|
| Providing the Callilio service under contract | Art. 6(1)(b) — performance of a contract |
| Security, fraud prevention, service integrity | Art. 6(1)(f) — legitimate interests |
| Optional analytics & marketing cookies | Art. 6(1)(a) — consent |
| Legal retention & tax obligations | Art. 6(1)(c) — legal obligation |
Purposes
- Operate AI phone reception, booking, and related automation features.
- Authenticate users, enforce access control, and maintain platform security.
- Invoice subscriptions, manage trials, and communicate billing events.
- Improve reliability, support customers, and develop new features.
- Comply with applicable law and respond to lawful requests.
Recipients & processors
We use carefully selected subprocessors bound by data processing agreements, including application delivery (Vercel), database and storage hosting (Supabase, EU region), telephony (Twilio), email (Resend), payments (Stripe), and AI/voice providers configured per account. A current subprocessor list is available on request.
International transfers
Primary customer data is stored in our provider's West EU (London) region, in the United Kingdom. Speech and language sub-processors we rely on operate from the United States. Where a subprocessor processes data outside the EEA, we rely on appropriate safeguards such as EU Standard Contractual Clauses and supplementary measures as required by Schrems II.
Retention
We retain personal data only as long as necessary for the purposes above. Account data is kept for the subscription term plus statutory limitation periods. Call logs and transcripts follow configurable retention per business account. Marketing consents are refreshed when the consent version changes.
Your rights
Under Articles 15–22 GDPR you have the right to access, rectify, erase, restrict, port, and object to certain processing, and to withdraw consent at any time without affecting prior lawful processing.
Access & portability: Request a copy of personal data we hold about you in a structured, commonly used format.
Erasure: Ask us to delete data where there is no overriding legal ground to retain it.
Objection: Object to processing based on legitimate interests; we will assess and respond per Art. 21.
Complaint: You may lodge a complaint with your supervisory authority. In Austria this is the Datenschutzbehörde (dsb.gv.at).
Austria-specific notes
As an Austrian controller we apply the Datenschutzgesetz (DSG) alongside GDPR. Where processing is likely to result in a high risk, we conduct data protection impact assessments. For sensitive use cases involving systematic monitoring of publicly accessible areas, prior consultation with the Datenschutzbehörde may be required — Callilio's standard SaaS deployment does not involve such monitoring.
Cookies
We use cookies as described in our Cookie Policy. Optional cookies require your consent before activation.