Privacy Policy
Contents
- 1. Data controller
- 2. Data protection officer
- 3. Data collected
- 4. Purposes and legal bases
- 5. Automated decisions and profiling
- 6. Retention periods
- 7. Sub-processors and transfers
- 8. Your rights
- 9. Data security
- 10. AI transparency (EU AI Act)
- 11. Cookies and trackers
- 12. Data of minors
- 13. Changes to this policy
The purpose of this privacy policy is to inform you in a clear, complete and transparent manner about how Softcallia collects, uses, stores and protects your personal data when you use our website www.softcallia.com(the “Site”) and our application app.softcallia.com (the “Application”), together the “Service”.
This policy is established in accordance with Regulation (EU) 2016/679 of 27 April 2016 (GDPR), French Law No. 78-17 of 6 January 1978 as amended (Data Protection Act), Law No. 2004-575 of 21 June 2004 (LCEN) and Regulation (EU) 2024/1689 (EU AI Act).
1. Identity and contact details of the data controller
The data controller is the entity that determines the purposes and means of processing your personal data:
| Name | Softcallia — Côme Bruchet, sole trader |
| Address | 24 rue David, 51100 Reims, France |
| SIRET | 102 453 487 00013 |
| Data controller | Côme Bruchet |
| Contact email | contact@softcallia.com |
| Phone | +33 6 62 58 90 17 |
2. Data protection officer (DPO)
Softcallia has fewer than 250 employees and does not carry out large-scale processing of special categories of data within the meaning of Article 37 of the GDPR. The designation of a DPO is therefore not mandatory. Nevertheless, we have designated an internal personal data protection contact.
For any question relating to the protection of your personal data:
- Email: dpo@softcallia.com
- Postal address: Softcallia — Côme Bruchet — 24 rue David, 51100 Reims
3. Personal data collected
We collect only data that is adequate, relevant and limited to what is necessary in relation to the purposes for which it is processed (data minimization principle, Article 5.1.c of the GDPR). Here is the detail by category:
3.1. Identification and account data
| Data | Purpose | Legal basis |
|---|---|---|
| First and last name | Creation and management of the user account | Performance of the contract (Art. 6.1.b GDPR) |
| Email address | Authentication, communications, notifications | Performance of the contract (Art. 6.1.b GDPR) |
| Phone number | Call-forwarding configuration, urgent alerts by SMS | Performance of the contract (Art. 6.1.b GDPR) |
| Company name, SIRET, business address | Billing, personalization of the AI agent, tax compliance | Performance of the contract (Art. 6.1.b) + legal obligation (Art. 6.1.c GDPR) |
| Password (hashed with bcrypt and individual salting) | Secure authentication | Performance of the contract (Art. 6.1.b GDPR) |
| Role (administrator, agent, viewer) | Management of access rights within the team | Performance of the contract (Art. 6.1.b GDPR) |
3.2. Telephone call data
| Data | Purpose | Legal basis |
|---|---|---|
| Caller's number | Customer identification, callback, call history | Legitimate interest (Art. 6.1.f GDPR) — management of the customer relationship |
| Call audio stream (processed in real time, not recorded) | AI transcription during the call. No audio recording is retained: only the text transcription is stored. | Legitimate interest (Art. 6.1.f GDPR) — the caller is informed at the start of the call in accordance with Art. L.34-1 of the CPCE |
| Text transcription of the call | Consultation, search, AI summary, urgency detection | Performance of the contract (Art. 6.1.b GDPR) |
| AI-generated summary | Facilitate quick decision-making by the user | Performance of the contract (Art. 6.1.b GDPR) |
| Call duration | Usage statistics, consumption tracking | Performance of the contract (Art. 6.1.b GDPR) |
| Urgency level (classified by AI) | Automatic sorting of calls, triggering of priority alerts | Performance of the contract (Art. 6.1.b GDPR) |
| Call status (new, in progress, handled, archived) | Workflow management | Performance of the contract (Art. 6.1.b GDPR) |
| Type of issue detected by the AI | Categorization, statistics | Performance of the contract (Art. 6.1.b GDPR) |
3.3. Appointment data
| Data | Purpose | Legal basis |
|---|---|---|
| Customer name and contact details | Automatic appointment booking | Performance of the contract (Art. 6.1.b GDPR) |
| Date, time, reason for the appointment | Calendar management | Performance of the contract (Art. 6.1.b GDPR) |
3.4. Payment data
| Data | Purpose | Legal basis |
|---|---|---|
| Stripe customer ID | Management of subscriptions and invoices | Performance of the contract (Art. 6.1.b GDPR) |
| Stripe subscription ID | Tracking of subscription status | Performance of the contract (Art. 6.1.b GDPR) |
| History of invoices and payments | Accounting, tax obligations | Legal obligation (Art. 6.1.c GDPR) — Art. L.123-22 of the French Commercial Code |
Important: Softcallia never collects or stores your banking data (card number, expiry date, security code). All payments are processed directly by Stripe Inc., certified PCI DSS Level 1. Only technical Stripe identifiers (with no banking data) are retained in our system.
3.5. Browsing data and technical data
| Data | Purpose | Legal basis |
|---|---|---|
| IP address | Security, abuse prevention, rate limiting, technical logging | Legal obligation (Art. 6.1.c GDPR — Art. 6-II LCEN) + legitimate interest (Art. 6.1.f GDPR) |
| User-agent (browser type, OS) | Technical compatibility, bug resolution | Legitimate interest (Art. 6.1.f GDPR) |
| Pages visited, dates and times of visits | Audience analysis of the showcase site (only if a cookie is consented to) | Consent (Art. 6.1.a GDPR) |
| Application error logs | Detection and correction of malfunctions (via Sentry) | Legitimate interest (Art. 6.1.f GDPR) |
| Cookies and trackers | See our Cookie Policy | Consent or exemption (depending on category) |
3.6. Data collected from callers (third parties)
When a third party (the User's customer) calls the number configured in the Service, certain data concerning them is collected: phone number, voice content of the call, transcription and summary. The caller is informed at the start of the call that the conversation is recorded and processed by an automated assistant. The User, as data controller for the data of their own customers, undertakes to comply with their information obligations under Articles 13 and 14 of the GDPR.
4. Purposes and legal bases of processing
Your data is processed for the following purposes:
| Purpose | Legal basis (Art. 6 GDPR) | Legitimate interest pursued (where applicable) |
|---|---|---|
| Provision and operation of the Softcallia service | Performance of the contract (Art. 6.1.b) | — |
| Management of your user account | Performance of the contract (Art. 6.1.b) | — |
| AI processing, transcription and summary of telephone calls | Performance of the contract (Art. 6.1.b) | — |
| Real-time processing of the audio stream for transcription purposes (without recording) | Legitimate interest (Art. 6.1.f) | Ensuring the quality of the transcription service; the caller is informed |
| Automatic urgency detection by AI | Performance of the contract (Art. 6.1.b) + legitimate interest (Art. 6.1.f) | Enabling a rapid response in urgent situations |
| Management of automatic appointments | Performance of the contract (Art. 6.1.b) | — |
| Billing, subscription management | Performance of the contract (Art. 6.1.b) + legal obligation (Art. 6.1.c) | — |
| Sending of transactional notifications (alerts, reminders) | Performance of the contract (Art. 6.1.b) | — |
| Sending of marketing communications | Consent (Art. 6.1.a) | — |
| Customer support | Performance of the contract (Art. 6.1.b) | — |
| Service improvement and aggregated/anonymized statistics | Legitimate interest (Art. 6.1.f) | Improving features and the relevance of the AI |
| Security, fraud prevention, rate limiting | Legitimate interest (Art. 6.1.f) + legal obligation (Art. 6.1.c) | Protecting the Service and its users against unauthorized access |
| Retention of connection logs | Legal obligation (Art. 6.1.c) — Art. 6-II LCEN | — |
| Audience analysis of the showcase site | Consent (Art. 6.1.a) | — |
5. Automated decisions and profiling
In accordance with Article 22 of the GDPR, we inform you that the Service uses automated processing involving artificial intelligence. This processing constitutes profiling within the meaning of Article 4(4) of the GDPR because it automatically analyzes the content of calls to infer information (urgency, type of issue, summary).
5.1. Automated processing carried out
| Processing | Description | Potential impact |
|---|---|---|
| Urgency classification | The AI analyzes the content of the call and assigns an urgency level (low, medium, high, critical) | Determines the order of priority in which calls are presented to the User and whether or not immediate alerts are triggered |
| Categorization of the type of issue | The AI identifies the nature of the caller's request | Helps organize the User's work |
| Summary generation | The AI produces a concise summary of each call | Facilitates quick review without re-listening to the entire call |
| Appointment proposal | The AI proposes available slots to the caller | May create an appointment in the User's calendar |
5.2. Safeguards
- None of these automated decisions produces a legal effect or a similarly significant effect on the persons concerned within the meaning of Article 22.1 of the GDPR. These are decision-support tools: it is always the human User who decides on the final action (call back, ignore, confirm an appointment, etc.).
- Transcriptions and summaries are automatic interpretations that may contain errors. As the call audio is not recorded, it cannot be re-listened to in order to verify a transcription: the transcription may be contested and corrected through human intervention (see below).
- You have the right to contest a classification, express your point of view and obtain human intervention by contacting dpo@softcallia.com.
6. Data retention periods
We retain your data only for as long as necessary for the purposes for which it was collected, in accordance with the storage limitation principle (Article 5.1.e of the GDPR):
| Data category | Retention period | Justification |
|---|---|---|
| Audio recordings of calls | No retention | Calls are not recorded. The audio stream is processed in real time solely for transcription purposes, then discarded — data minimization (Art. 5.1.c GDPR) |
| Call transcriptions (text, summary, classification) | 365 days (configurable by the company, min. 30 days) | Customer history — user setting + minimization |
| Profile data (user account) | Duration of the contract + 30 days | Performance of the contract (Art. 6.1.b GDPR) |
| Billing data (invoices, proof of payment) | 10 years | Legal obligation (Art. L.123-22 of the French Commercial Code, Art. 289 of the CGI) |
| Internal messages (dashboard) | Duration of the contract | Collaboration — performance of the contract |
| Appointments | Duration of the contract + 90 days | Customer follow-up — performance of the contract |
| GDPR audit logs | 3 years | Accountability (Art. 5.2 GDPR) |
| Proof of consent to cookies | 13 months (stored locally in your browser) | Proof of consent (Art. 7.1 GDPR). Your choice is stored in your browser's local storage, not on our servers: we keep no copy of it. |
| Analytics cookies | 13 months | CNIL recommendation (deliberation 2020-091) |
| Connection logs (IP address, timestamp) | 12 months | Art. 6-II of the LCEN + Decree No. 2011-219 |
| Prospect data (contact form) | 3 years after the last contact | CNIL recommendation |
| Error logs (Sentry) | 90 days | Legitimate interest (bug fixing) |
Upon expiry of these periods, the data is permanently deleted or irreversibly anonymized for statistical purposes.
7. Sub-processors and international data transfers
To provide the Service, we use technical sub-processors (Articles 28 et seq. of the GDPR). These sub-processors act solely on our documented instructions and are contractually bound to protect your data in accordance with the GDPR. Data Processing Agreements (DPAs) have been concluded with each of them.
7.1. List of sub-processors
| Sub-processor | Country / Region | Data concerned | Transfer safeguards |
|---|---|---|---|
| Supabase Inc. | USA (AWS EU infrastructure) | Database (accounts, calls, transcriptions, appointments), uploaded files (photos, documents) | SCCs (European Commission, decision 2021/914) + DPA. AES-256 encryption at rest. Row Level Security (RLS). |
| Stripe Inc. | USA (Irish entity for the EU) | Payment data (card processed by Stripe, only the customer ID is stored with us) | EU-US Data Privacy Framework (DPF). PCI DSS Level 1. SCCs. |
| Twilio Inc. | USA | Telephony (caller number, real-time routing of the audio stream), SMS | SCCs + DPA. SOC 2 Type II, ISO 27001. |
| OpenAI Inc. | USA | Audio (transcription), text (analysis, summary, classification) | Specific DPA. No data is used to train the models (zero-retention API policy). SCCs. |
| Vercel Inc. | USA (global CDN, EU Edge functions) | Application hosting (HTTP requests, headers, IP) | SCCs + DPA. SOC 2 Type II. |
| Upstash Inc. | EU (Frankfurt, Germany) | Ephemeral application cache (rate limiting, sessions) | GDPR-native. Data processed and stored exclusively in the EU. |
| Brevo (Sendinblue) | France | Transactional emails (alerts, confirmations, reminders) | GDPR-native. ISO 27001. Data hosted in the EU. |
| n8n GmbH | Germany | Automation workflows (call orchestration, notifications) | GDPR-native. Self-hosted on a VPS in the EU. |
| Functional Software Inc. (Sentry) | USA | Technical error logs (stack traces, anonymized IPs, user-agent) | SCCs + DPA. SOC 2 Type II. Minimized data (no business data). |
| Cal.com Inc. | USA | Demo booking on our site (name, email, chosen slot). Concerns our prospects, not the data of your customers. | SCCs + DPA. Loaded only after an explicit action on your part. |
7.2. Transfers outside the European Economic Area (EEA)
Some of our sub-processors are located in the United States. Transfers of data to the United States are governed by the following mechanisms, in accordance with Chapter V of the GDPR:
- Standard Contractual Clauses (SCCs) approved by the European Commission (implementing decision 2021/914 of 4 June 2021), incorporated into the DPA of each sub-processor;
- EU-US Data Privacy Framework (adequacy decision of 10 July 2023) for certified sub-processors (Stripe);
- Additional measures: encryption in transit (TLS 1.3) and at rest (AES-256), minimization of transferred data, regular risk assessment.
We never sell your data to third parties. Your data is shared only with the sub-processors listed above, strictly to the extent necessary to provide the Service.
8. Your rights
In accordance with Articles 15 to 22 of the GDPR and Articles 48 to 56 of the French Data Protection Act, you have the following rights over your personal data:
| Right | Content | Basis |
|---|---|---|
| Right of access | Obtain confirmation that data concerning you is being processed, access it and obtain a copy. | Art. 15 GDPR |
| Right to rectification | Request the correction of inaccurate or incomplete data. | Art. 16 GDPR |
| Right to erasure | Request the deletion of your data when it is no longer necessary, when you withdraw your consent, or when the processing is unlawful. | Art. 17 GDPR |
| Right to restriction of processing | Request the restriction of processing in certain cases (e.g. contesting the accuracy, objection under examination). | Art. 18 GDPR |
| Right to portability | Receive your data in a structured, commonly used and machine-readable format (JSON, CSV). You can exercise this right from the GDPR tab of your dashboard. | Art. 20 GDPR |
| Right to object | Object to processing based on legitimate interest (Art. 6.1.f), including profiling related to that processing. We will cease processing unless there are compelling legitimate grounds. | Art. 21 GDPR |
| Rights related to automated decisions | Not be subject to a decision based solely on automated processing producing legal effects. AI classification is a support tool; the User decides. | Art. 22 GDPR |
| Right to withdraw consent | For processing based on consent (analytics cookies, marketing emails), you may withdraw your consent at any time without affecting the lawfulness of prior processing. | Art. 7.3 GDPR |
| Post-mortem directives | Define directives relating to the retention, erasure and communication of your data after your death. | Art. 85 of the French Data Protection Act |
8.1. How to exercise your rights
- By email: dpo@softcallia.com, specifying your identity (first name, last name, account email) and the right you wish to exercise.
- Via your dashboard:the “GDPR” tab of the Settings page lets you export your data (portability) and request the deletion of your account (erasure).
- By post:Softcallia — Côme Bruchet — 24 rue David, 51100 Reims.
We will respond to your request within a maximum of 30 days from receipt. This period may be extended by two additional months in the event of complexity or a large number of requests, in which case you will be informed within the initial one-month period (Art. 12.3 GDPR).
8.2. Complaint to the CNIL
If you believe that the processing of your personal data constitutes a breach of the GDPR, you have the right to lodge a complaint with the French Data Protection Authority (CNIL), the competent supervisory authority in France:
- Website: www.cnil.fr
- Address: CNIL — 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07
- Phone: +33 1 53 73 22 22
9. Data security
In accordance with Article 32 of the GDPR, we implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk:
9.1. Technical measures
- Encryption in transit: TLS 1.3 for all communications between your browser, our servers and our sub-processors.
- Encryption at rest: AES-256 for the database (Supabase/AWS) and uploaded files.
- Data isolation: Row Level Security (RLS) on Supabase ensures that no company can access another's data (multi-tenant isolation at the database level).
- Access control: role-based access control (RBAC) with three levels (administrator, agent, viewer).
- Rate limiting: protection against brute-force attacks via Upstash Redis (sliding window).
- Passwords: hashed with bcrypt (cost factor 10), individual salting. No password is stored in plain text.
- Authentication: JWT tokens with automatic rotation and secure refresh.
- HTTP security headers: Content-Security-Policy (CSP), HTTP Strict Transport Security (HSTS), X-Frame-Options, X-Content-Type-Options, Referrer-Policy.
- Webhook validation: HMAC signature for Stripe, secret key for n8n.
9.2. Organizational measures
- Principle of least privilege: each component of the system has access only to the data strictly necessary for its function.
- Logging: sensitive access and operations are traced in an audit log (GDPR audit log).
- Monitoring: monitoring of errors and anomalies via Sentry, with automatic alerts.
- Breach notification: in the event of a data breach, the CNIL is notified within 72 hours and the persons concerned are informed as soon as possible in accordance with Articles 33 and 34 of the GDPR.
10. Transparency on the use of artificial intelligence
In accordance with Regulation (EU) 2024/1689 of 13 June 2024 on artificial intelligence (EU AI Act) and the CNIL's recommendations on the use of AI in the processing of personal data:
10.1. AI systems used
- Provider: OpenAI Inc. (GPT and Whisper models via API)
- Functions: voice transcription (speech-to-text), summary generation, urgency classification, categorization of issues, conversational voice responses to callers
- Risk classification (EU AI Act):limited risk — the system interacts directly with natural persons (callers) and generates synthetic content (voice)
10.2. Transparency obligations
- The caller is informed at the start of the call that they are interacting with an automated assistant using artificial intelligence (transparency obligation, Art. 50 EU AI Act).
- The AI is a decision-support tool, not an autonomous decision-making system. It is always the human User who decides on the action to take.
- No data transmitted via the OpenAI API is used to train or improve OpenAI's AI models(in accordance with OpenAI's API data policy — zero data retention for API customers).
- Transcriptions and summaries are automatic interpretations that may contain errors, omissions or inaccuracies. They do not constitute a guaranteed faithful reproduction.
11. Cookies and trackers
The Site and the Application use cookies and similar technologies. For detailed information about the cookies used, their purposes, retention periods and the ways to manage your preferences, please consult our dedicated Cookie Policy.
12. Data of minors
The Service is intended for professionals (B2B). It is not designed to be used by persons under the age of 18. We do not knowingly collect personal data of minors. If we find that data of minors has been collected inadvertently, we will delete it as soon as possible.
13. Changes to this policy
We may modify this policy at any time to reflect regulatory, case-law or technical developments. Any substantial change will be notified:
- by email to the address associated with your account;
- by a notification in the Application;
- by updating the date shown at the top of this page.
For changes affecting processing based on consent, your consent will be requested again.
Contact — Data protection
For any question relating to the protection of your personal data:
- Data contact email: dpo@softcallia.com
- Address: Softcallia — Côme Bruchet — 24 rue David, 51100 Reims
- CNIL: www.cnil.fr — 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07
Questions?
contact@softcallia.comSIRET 102 453 487 00013