Privacy Policy
Contents
- 1. Data controller
- 2. Data protection officer
- 3. Data collected
- 4. Purposes and legal bases
- 5. B2B prospecting
- 6. Automated decisions and profiling
- 7. Retention periods
- 8. Sub-processors and transfers
- 9. Your rights
- 10. Data security
- 11. AI transparency (EU AI Act)
- 12. Cookies and trackers
- 13. Data of minors
- 14. Changes to this policy
The purpose of this privacy policy is to inform you in a clear, complete and transparent manner about how Softcallia collects, uses, stores and protects your personal data when you use our website www.softcallia.com(the “Site”) and our application app.softcallia.com (the “Application”), together the “Service”. It also describes how we use the business contact details of the companies we contact to present Softcallia: see section 5.
This policy is established in accordance with Regulation (EU) 2016/679 of 27 April 2016 (GDPR), French Law No. 78-17 of 6 January 1978 as amended (Data Protection Act), Law No. 2004-575 of 21 June 2004 (LCEN) and Regulation (EU) 2024/1689 (EU AI Act).
1. Identity and contact details of the data controller
The data controller is the entity that determines the purposes and means of processing your personal data:
| Name | Softcallia — Côme Bruchet, sole trader |
| Address | 24 rue David, 51100 Reims, France |
| SIRET | 102 453 487 00013 |
| Data controller | Côme Bruchet |
| Contact email | contact@softcallia.com |
| Phone | +33 9 39 24 23 46 |
2. Data protection officer (DPO)
Softcallia has fewer than 250 employees and does not carry out large-scale processing of special categories of data within the meaning of Article 37 of the GDPR. The designation of a DPO is therefore not mandatory. Nevertheless, we have designated an internal personal data protection contact.
For any question relating to the protection of your personal data:
- Email: dpo@softcallia.com
- Postal address: Softcallia — Côme Bruchet — 24 rue David, 51100 Reims
3. Personal data collected
We collect only data that is adequate, relevant and limited to what is necessary in relation to the purposes for which it is processed (data minimization principle, Article 5.1.c of the GDPR). Here is the detail by category:
3.1. Identification and account data
| Data | Purpose | Legal basis |
|---|---|---|
| First and last name | Creation and management of the user account | Performance of the contract (Art. 6.1.b GDPR) |
| Email address | Authentication, communications, notifications | Performance of the contract (Art. 6.1.b GDPR) |
| Phone number | Call-forwarding configuration, urgent alerts by SMS | Performance of the contract (Art. 6.1.b GDPR) |
| Company name, SIRET, business address | Billing, personalization of the AI agent, tax compliance | Performance of the contract (Art. 6.1.b) + legal obligation (Art. 6.1.c GDPR) |
| Password (hashed with bcrypt and individual salting) | Secure authentication | Performance of the contract (Art. 6.1.b GDPR) |
| Role (administrator, agent, viewer) | Management of access rights within the team | Performance of the contract (Art. 6.1.b GDPR) |
3.2. Telephone call data
| Data | Purpose | Legal basis |
|---|---|---|
| Caller's number | Customer identification, callback, call history | Legitimate interest (Art. 6.1.f GDPR) — management of the customer relationship |
| Call audio stream (processed in real time, not recorded by default) | AI transcription during the call. Without the recording option, no audio is retained: only the text transcription is stored. | Legitimate interest (Art. 6.1.f GDPR) — the caller is informed at the start of the call in accordance with Art. L.34-1 of the CPCE |
| Audio recording of the call (option off by default, turned on by Softcallia at the customer business's request) | Allow the business to listen back to a request to check what was said. The voice agent announces the recording at the start of the call; if the caller objects, the recording is stopped and deleted. | Legitimate interest of the customer business, as data controller (Art. 6.1.f GDPR), with prior notice and a right to object |
| Text transcription of the call | Consultation, search, AI summary, urgency detection | Performance of the contract (Art. 6.1.b GDPR) |
| AI-generated summary | Facilitate quick decision-making by the user | Performance of the contract (Art. 6.1.b GDPR) |
| Call duration | Usage statistics, consumption tracking | Performance of the contract (Art. 6.1.b GDPR) |
| Urgency level (classified by AI) | Automatic sorting of calls, triggering of priority alerts | Performance of the contract (Art. 6.1.b GDPR) |
| Call status (new, in progress, handled, archived) | Workflow management | Performance of the contract (Art. 6.1.b GDPR) |
| Type of issue detected by the AI | Categorization, statistics | Performance of the contract (Art. 6.1.b GDPR) |
3.3. Appointment data
| Data | Purpose | Legal basis |
|---|---|---|
| Customer name and contact details | Automatic appointment booking | Performance of the contract (Art. 6.1.b GDPR) |
| Date, time, reason for the appointment | Calendar management | Performance of the contract (Art. 6.1.b GDPR) |
3.4. Payment data
| Data | Purpose | Legal basis |
|---|---|---|
| Stripe customer ID | Management of subscriptions and invoices | Performance of the contract (Art. 6.1.b GDPR) |
| Stripe subscription ID | Tracking of subscription status | Performance of the contract (Art. 6.1.b GDPR) |
| History of invoices and payments | Accounting, tax obligations | Legal obligation (Art. 6.1.c GDPR) — Art. L.123-22 of the French Commercial Code |
Important: Softcallia never collects or stores your banking data (card number, expiry date, security code). All payments are processed directly by Stripe Inc., certified PCI DSS Level 1. Only technical Stripe identifiers (with no banking data) are retained in our system.
3.5. Browsing data and technical data
| Data | Purpose | Legal basis |
|---|---|---|
| IP address | Security, abuse prevention, rate limiting, technical logging | Legal obligation (Art. 6.1.c GDPR — Art. 6-II LCEN) + legitimate interest (Art. 6.1.f GDPR) |
| User-agent (browser type, OS) | Technical compatibility, bug resolution | Legitimate interest (Art. 6.1.f GDPR) |
| Pages visited, dates and times of visits | Audience analysis of the showcase site (only if a cookie is consented to) | Consent (Art. 6.1.a GDPR) |
| Application error logs | Detection and correction of malfunctions (via Sentry) | Legitimate interest (Art. 6.1.f GDPR) |
| Cookies and trackers | See our Cookie Policy | Consent or exemption (depending on category) |
3.6. Data collected from callers (third parties)
When a third party (the User's customer) calls the number configured in the Service, certain data concerning them is collected: phone number, voice content of the call, transcription and summary. The caller is informed at the start of the call that the conversation is processed by an automated assistant. If the business called has requested the audio recording option, the voice agent also announces that the call is recorded and that the caller can object; if they do, the recording is stopped and deleted. For the data of their own customers, the User is the data controller and Softcallia the processor. The User undertakes to comply with their information obligations under Articles 13 and 14 of the GDPR.
3.7. Google Calendar data (optional)
If the User connects their Google Calendar (optional, under Settings then Integrations), Softcallia accesses, with the Google permission “See and edit events on all your calendars” (calendar.events), the events of their calendars: start and end times, status, availability (busy or free), invitation responses, and event titles.
- Read: before offering a time slot to a caller, Softcallia checks that the User is not already busy. The voice assistant only receives busy time ranges, never the title or content of events. Titles are shown only to the User, in their own Softcallia schedule.
- Write: Softcallia creates, updates and deletes in their calendar the appointments booked through the Service.
- Retention: no copy of Google events is kept. They are read when needed; only the identifier of the appointments created by Softcallia and the (encrypted) authorization token are stored.
- What Softcallia never does: sell this data, use it for advertising, use it to train artificial intelligence models, or let a person read it, except with the User's explicit consent, for security purposes or to comply with the law.
- Revocation: the User can disconnect their calendar at any time under Settings then Integrations, or at myaccount.google.com/permissions; the token is then deleted.
Softcallia's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
4. Purposes and legal bases of processing
Your data is processed for the following purposes:
| Purpose | Legal basis (Art. 6 GDPR) | Legitimate interest pursued (where applicable) |
|---|---|---|
| Provision and operation of the Softcallia service | Performance of the contract (Art. 6.1.b) | — |
| Management of your user account | Performance of the contract (Art. 6.1.b) | — |
| AI processing, transcription and summary of telephone calls | Performance of the contract (Art. 6.1.b) | — |
| Real-time processing of the audio stream for transcription purposes (without recording) | Legitimate interest (Art. 6.1.f) | Ensuring the quality of the transcription service; the caller is informed |
| Optional audio recording of calls, at the customer business's request | Legitimate interest of the customer business (Art. 6.1.f) | Listening back to a request to check what was said; the caller is informed at the start of the call and can object |
| Automatic urgency detection by AI | Performance of the contract (Art. 6.1.b) + legitimate interest (Art. 6.1.f) | Enabling a rapid response in urgent situations |
| Management of automatic appointments | Performance of the contract (Art. 6.1.b) | — |
| Billing, subscription management | Performance of the contract (Art. 6.1.b) + legal obligation (Art. 6.1.c) | — |
| Sending of transactional notifications (alerts, reminders) | Performance of the contract (Art. 6.1.b) | — |
| Marketing communications based on consent: newsletter, emails sent after a request made on our site, and any marketing message sent to a consumer | Consent (Art. 6.1.a) | — |
| B2B prospecting: emails and calls to businesses, using the business contact details they publish (section 5) | Legitimate interest (Art. 6.1.f) | Presenting Softcallia to businesses whose trade the service is relevant to. You can object at any time, without giving a reason |
| Customer support | Performance of the contract (Art. 6.1.b) | — |
| Service improvement and aggregated/anonymized statistics | Legitimate interest (Art. 6.1.f) | Improving features and the relevance of the AI |
| Security, fraud prevention, rate limiting | Legitimate interest (Art. 6.1.f) + legal obligation (Art. 6.1.c) | Protecting the Service and its users against unauthorized access |
| Retention of connection logs | Legal obligation (Art. 6.1.c) — Art. 6-II LCEN | — |
| Audience analysis of the showcase site | Consent (Art. 6.1.a) | — |
5. B2B prospecting
Softcallia contacts businesses that are not yet customers, by email and by phone, to present its service. This section is for the professionals we contact this way. The controller for this processing is Softcallia, Côme Bruchet, sole trader, 24 rue David, 51100 Reims, France, as identified in section 1.
5.1. Who and what data
We contact trade and service businesses that Softcallia can help: plumbers, roofers, electricians, heating and air-conditioning (HVAC) contractors, landscapers and related trades, in France and in the United States, in particular in California. The data we use relates to the business and the people who represent it:
- trade name, legal name, trade, activity and size of the business;
- name and role of the owner or manager, when published;
- business email and phone number, website;
- business address;
- public information: French SIREN or SIRET number, contractor license number, RGE certification, reviews and ratings published online;
- a priority score we compute from this information, to decide which businesses to contact first;
- the history of our exchanges: contact dates, replies, notes and, where applicable, your objection.
5.2. Where the data comes from
We do not ask you for this data: it comes from information that businesses publish themselves or that appears in public registries.
- the business's own website;
- its public listings in directories and map services, such as Google Business Profile, which feeds Google Maps;
- in France, the INSEE Sirene business register and the ADEME list of RGE-certified professionals;
- in the United States, the contractor license registries kept by each state, such as the Contractors State License Board (CSLB) in California;
- professional directories.
On request, we will tell you the exact source of your contact details.
5.3. Purpose and legal basis
We use this data to present Softcallia to you: an AI receptionist with full management software for businesses in your trade, covering call answering day and night, urgent-call triage, appointment booking, scheduling and invoicing. We also use it to keep track of our exchanges.
This processing is based on our legitimate interest (Art. 6.1.f GDPR): making our service known to the businesses whose trade it serves. In France, the CNIL, the French data protection authority, allows email prospecting of professionals without prior consent, provided the message relates to the recipient's profession and the recipient can easily object in every message (Art. L.34-5 of the French Postal and Electronic Communications Code). Phone prospecting of professionals rests on the same basis and gives the same right to object.
5.4. Retention period
We keep this data for 3 years from collection or, if you replied to us, from our last exchange, as the CNIL recommends. It is then deleted. If you object to prospecting, the rule in section 5.6 applies.
5.5. Recipients and transfers
Your data is never sold, rented or passed on to third parties. Only Softcallia has access to it, with four sub-processors:
- Google, which provides our Google Workspace business email;
- Supabase, which hosts our prospect database;
- Vercel, which hosts the administration interface through which we view that database;
- Anthropic, whose AI assistant Claude we use to research the public sources listed in 5.2 and to prepare our messages.
These companies are based in the United States: transfers of data to the United States are governed by the European Commission's Standard Contractual Clauses and the measures described in section 8.
5.6. Your right to object
You can object at any time, free of charge and without giving a reason, to Softcallia contacting you for prospecting purposes.
Simply reply “stop” or “no” to any of our emails, tell us during a call, or write to contact@softcallia.com or dpo@softcallia.com. Your request is applied as soon as we receive it: we stop contacting you and your record is marked as objected in our prospect database.
So that your objection keeps being respected, that record is kept with the date of your request for as long as Softcallia carries out prospecting, and is never used to contact you again. If you also ask for your data to be erased, we erase the rest of your record and keep only the business name, the email or phone number concerned and the date of your request, in an opposition list.
5.7. Your other rights
You also have the rights of access, rectification, erasure and restriction, and the right to lodge a complaint with the CNIL, as described in section 9.
6. Automated decisions and profiling
In accordance with Article 22 of the GDPR, we inform you that the Service uses automated processing involving artificial intelligence. This processing constitutes profiling within the meaning of Article 4(4) of the GDPR because it automatically analyzes the content of calls to infer information (urgency, type of issue, summary).
6.1. Automated processing carried out
| Processing | Description | Potential impact |
|---|---|---|
| Urgency classification | The AI analyzes the content of the call and assigns an urgency level (low, medium, high, critical) | Determines the order of priority in which calls are presented to the User and whether or not immediate alerts are triggered |
| Categorization of the type of issue | The AI identifies the nature of the caller's request | Helps organize the User's work |
| Summary generation | The AI produces a concise summary of each call | Facilitates quick review without re-listening to the entire call |
| Appointment proposal | The AI proposes available slots to the caller | May create an appointment in the User's calendar |
6.2. Safeguards
- None of these automated decisions produces a legal effect or a similarly significant effect on the persons concerned within the meaning of Article 22.1 of the GDPR. These are decision-support tools: it is always the human User who decides on the final action (call back, ignore, confirm an appointment, etc.).
- Transcriptions and summaries are automatic interpretations that may contain errors. Unless the business has turned on the audio recording option, the call is not recorded and cannot be listened to again to verify a transcription: the transcription may be contested and corrected through human intervention (see below).
- You have the right to contest a classification, express your point of view and obtain human intervention by contacting dpo@softcallia.com.
7. Data retention periods
We retain your data only for as long as necessary for the purposes for which it was collected, in accordance with the storage limitation principle (Article 5.1.e of the GDPR):
| Data category | Retention period | Justification |
|---|---|---|
| Call audio stream (without the recording option) | No retention | By default, calls are not recorded. The audio stream is processed in real time solely for transcription purposes, then discarded. Data minimization (Art. 5.1.c GDPR) |
| Audio recordings of calls (option turned on at the business's request) | 90 days, then automatic deletion | Listening back to a request by the business. Deleted immediately if the business deletes the call, if the caller objects, or when the account is deleted |
| Call transcriptions (text, summary, classification) | 365 days (configurable by the company, min. 30 days) | Customer history — user setting + minimization |
| Profile data (user account) | Duration of the contract + 30 days | Performance of the contract (Art. 6.1.b GDPR) |
| Billing data (invoices, proof of payment) | 10 years | Legal obligation (Art. L.123-22 of the French Commercial Code, Art. 289 of the CGI) |
| Internal messages (dashboard) | Duration of the contract | Collaboration — performance of the contract |
| Appointments | Duration of the contract + 90 days | Customer follow-up — performance of the contract |
| GDPR audit logs | 3 years | Accountability (Art. 5.2 GDPR) |
| Proof of consent to cookies | 13 months (stored locally in your browser) | Proof of consent (Art. 7.1 GDPR). Your choice is stored in your browser's local storage, not on our servers: we keep no copy of it. |
| Analytics cookies | 13 months | CNIL recommendation (deliberation 2020-091) |
| Connection logs (IP address, timestamp) | 12 months | Art. 6-II of the LCEN + Decree No. 2011-219 |
| Prospect data (contact form) | 3 years after the last contact | CNIL recommendation |
| B2B prospecting data (businesses we contact) | 3 years from collection or, if the business replied to us, from our last exchange, then deleted | CNIL recommendation. See section 5 |
| Prospect record after an objection, marked as objected. After an erasure request, only one line of the opposition list remains: business name, email or phone number concerned, date of the request | For as long as Softcallia carries out prospecting | Ensuring that a business that has objected is no longer contacted (Art. 21.3 GDPR) |
| Error logs (Sentry) | 90 days | Legitimate interest (bug fixing) |
Upon expiry of these periods, the data is permanently deleted or irreversibly anonymized for statistical purposes.
8. Sub-processors and international data transfers
To provide the Service, we use technical sub-processors (Articles 28 et seq. of the GDPR). These sub-processors act solely on our documented instructions and are contractually bound to protect your data in accordance with the GDPR. Data Processing Agreements (DPAs) have been concluded with each of them.
8.1. List of sub-processors
| Sub-processor | Country / Region | Data concerned | Transfer safeguards |
|---|---|---|---|
| Supabase Inc. | USA (AWS EU infrastructure) | Database (accounts, calls, transcriptions, appointments, B2B prospect database), uploaded files (photos, documents), audio recordings from the option (encrypted storage in the EU, Paris region) | SCCs (European Commission, decision 2021/914) + DPA. AES-256 encryption at rest. Row Level Security (RLS). |
| Stripe Inc. | USA (Irish entity for the EU) | Payment data (card processed by Stripe, only the customer ID is stored with us) | EU-US Data Privacy Framework (DPF). PCI DSS Level 1. SCCs. |
| Twilio Inc. | USA | Telephony (caller number, real-time routing of the audio stream), SMS. When the recording option is on, Twilio produces the audio file and keeps it only while it is transferred (a few seconds), then deletes it. | SCCs + DPA. SOC 2 Type II, ISO 27001. |
| OpenAI Inc. | USA | Audio (transcription), text (analysis, summary, classification) | Specific DPA. No data is used to train the models (zero-retention API policy). SCCs. |
| Google LLC (Google Workspace) | USA | Softcallia's business email: emails exchanged with our customers and prospects, including B2B prospecting emails | SCCs + DPA. |
| Anthropic PBC | USA | B2B prospecting: research of public information about the businesses we contact and preparation of our messages, with the AI assistant Claude | SCCs + DPA. |
| Vercel Inc. | USA (global CDN, EU Edge functions) | Hosting of the application and of our administration interface, through which we view the B2B prospect database (HTTP requests, headers, IP) | SCCs + DPA. SOC 2 Type II. |
| Upstash Inc. | EU (Frankfurt, Germany) | Ephemeral application cache (rate limiting, sessions) | GDPR-native. Data processed and stored exclusively in the EU. |
| Brevo (Sendinblue) | France | Transactional emails (alerts, confirmations, reminders) | GDPR-native. ISO 27001. Data hosted in the EU. |
| n8n GmbH | Germany | Automation workflows (call orchestration, notifications) | GDPR-native. Self-hosted on a VPS in the EU. |
| Functional Software Inc. (Sentry) | USA | Technical error logs (stack traces, anonymized IPs, user-agent) | SCCs + DPA. SOC 2 Type II. Minimized data (no business data). |
| Cal.com Inc. | USA | Demo booking on our site (name, email, chosen slot). Concerns our prospects, not the data of your customers. | SCCs + DPA. Loaded only after an explicit action on your part. |
8.2. Transfers outside the European Economic Area (EEA)
Some of our sub-processors are located in the United States. Transfers of data to the United States are governed by the following mechanisms, in accordance with Chapter V of the GDPR:
- Standard Contractual Clauses (SCCs) approved by the European Commission (implementing decision 2021/914 of 4 June 2021), incorporated into the DPA of each sub-processor;
- EU-US Data Privacy Framework (adequacy decision of 10 July 2023) for certified sub-processors (Stripe);
- Additional measures: encryption in transit (TLS 1.3) and at rest (AES-256), minimization of transferred data, regular risk assessment.
We never sell your data to third parties. Your data is shared only with the sub-processors listed above, strictly to the extent necessary to provide the Service.
9. Your rights
In accordance with Articles 15 to 22 of the GDPR and Articles 48 to 56 of the French Data Protection Act, you have the following rights over your personal data:
| Right | Content | Basis |
|---|---|---|
| Right of access | Obtain confirmation that data concerning you is being processed, access it and obtain a copy. | Art. 15 GDPR |
| Right to rectification | Request the correction of inaccurate or incomplete data. | Art. 16 GDPR |
| Right to erasure | Request the deletion of your data when it is no longer necessary, when you withdraw your consent, or when the processing is unlawful. | Art. 17 GDPR |
| Right to restriction of processing | Request the restriction of processing in certain cases (e.g. contesting the accuracy, objection under examination). | Art. 18 GDPR |
| Right to portability | Receive your data in a structured, commonly used and machine-readable format (JSON, CSV). You can exercise this right from the GDPR tab of your dashboard. | Art. 20 GDPR |
| Right to object | Object to processing based on legitimate interest (Art. 6.1.f), including profiling related to that processing. We will cease processing unless there are compelling legitimate grounds. A caller can object to the audio recording of their call as soon as the voice agent announces it: the recording is stopped and deleted. They can also exercise this right with the business they called, which is the data controller for this processing. For prospecting, an objection always takes effect, without exception (Art. 21.3 GDPR): see section 5.6. | Art. 21 GDPR |
| Rights related to automated decisions | Not be subject to a decision based solely on automated processing producing legal effects. AI classification is a support tool; the User decides. | Art. 22 GDPR |
| Right to withdraw consent | For processing based on consent (analytics cookies, marketing communications sent with your agreement), you may withdraw your consent at any time without affecting the lawfulness of prior processing. | Art. 7.3 GDPR |
| Post-mortem directives | Define directives relating to the retention, erasure and communication of your data after your death. | Art. 85 of the French Data Protection Act |
9.1. How to exercise your rights
- By email: dpo@softcallia.com, specifying your identity (first name, last name, account email) and the right you wish to exercise.
- Via your dashboard:the “GDPR” tab of the Settings page lets you export your data (portability) and request the deletion of your account (erasure).
- By post:Softcallia — Côme Bruchet — 24 rue David, 51100 Reims.
We will respond to your request within a maximum of 30 days from receipt. This period may be extended by two additional months in the event of complexity or a large number of requests, in which case you will be informed within the initial one-month period (Art. 12.3 GDPR).
9.2. Complaint to the CNIL
If you believe that the processing of your personal data constitutes a breach of the GDPR, you have the right to lodge a complaint with the French Data Protection Authority (CNIL), the competent supervisory authority in France:
- Website: www.cnil.fr
- Address: CNIL — 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07
- Phone: +33 1 53 73 22 22
10. Data security
In accordance with Article 32 of the GDPR, we implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk:
10.1. Technical measures
- Encryption in transit: TLS 1.3 for all communications between your browser, our servers and our sub-processors.
- Encryption at rest: AES-256 for the database (Supabase/AWS) and uploaded files.
- Data isolation: Row Level Security (RLS) on Supabase ensures that no company can access another's data (multi-tenant isolation at the database level).
- Access control: role-based access control (RBAC) with three levels (administrator, agent, viewer).
- Audio recordings (option): listening limited to the owner and admins of the customer business, from its application. Every playback is logged; none is served from a public address or cached.
- Rate limiting: protection against brute-force attacks via Upstash Redis (sliding window).
- Passwords: hashed with bcrypt (cost factor 10), individual salting. No password is stored in plain text.
- Authentication: JWT tokens with automatic rotation and secure refresh.
- HTTP security headers: Content-Security-Policy (CSP), HTTP Strict Transport Security (HSTS), X-Frame-Options, X-Content-Type-Options, Referrer-Policy.
- Webhook validation: HMAC signature for Stripe, secret key for n8n.
10.2. Organizational measures
- Principle of least privilege: each component of the system has access only to the data strictly necessary for its function.
- Logging: sensitive access and operations are traced in an audit log (GDPR audit log).
- Monitoring: monitoring of errors and anomalies via Sentry, with automatic alerts.
- Breach notification: in the event of a data breach, the CNIL is notified within 72 hours and the persons concerned are informed as soon as possible in accordance with Articles 33 and 34 of the GDPR.
11. Transparency on the use of artificial intelligence
In accordance with Regulation (EU) 2024/1689 of 13 June 2024 on artificial intelligence (EU AI Act) and the CNIL's recommendations on the use of AI in the processing of personal data:
11.1. AI systems used
- Provider: OpenAI Inc. (GPT and Whisper models via API)
- Functions: voice transcription (speech-to-text), summary generation, urgency classification, categorization of issues, conversational voice responses to callers
- Risk classification (EU AI Act):limited risk — the system interacts directly with natural persons (callers) and generates synthetic content (voice)
11.2. Transparency obligations
- The caller is informed at the start of the call that they are interacting with an automated assistant using artificial intelligence (transparency obligation, Art. 50 EU AI Act).
- The AI is a decision-support tool, not an autonomous decision-making system. It is always the human User who decides on the action to take.
- No data transmitted via the OpenAI API is used to train or improve OpenAI's AI models(in accordance with OpenAI's API data policy — zero data retention for API customers).
- Transcriptions and summaries are automatic interpretations that may contain errors, omissions or inaccuracies. They do not constitute a guaranteed faithful reproduction.
12. Cookies and trackers
The Site and the Application use cookies and similar technologies. For detailed information about the cookies used, their purposes, retention periods and the ways to manage your preferences, please consult our dedicated Cookie Policy.
13. Data of minors
The Service is intended for professionals (B2B). It is not designed to be used by persons under the age of 18. We do not knowingly collect personal data of minors. If we find that data of minors has been collected inadvertently, we will delete it as soon as possible.
14. Changes to this policy
We may modify this policy at any time to reflect regulatory, case-law or technical developments. Any substantial change will be notified:
- by email to the address associated with your account;
- by a notification in the Application;
- by updating the date shown at the top of this page.
For changes affecting processing based on consent, your consent will be requested again.
Contact — Data protection
For any question relating to the protection of your personal data:
- Data contact email: dpo@softcallia.com
- Address: Softcallia — Côme Bruchet — 24 rue David, 51100 Reims
- CNIL: www.cnil.fr — 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07
Questions?
contact@softcallia.comSIRET 102 453 487 00013