Privacy Policy
Effective as of: August 20, 2026
Your privacy matters to us. This Privacy Policy explains how Veillant ("Veillant", "we", "us") collects, uses, shares, and protects information when you use our website and our platform for building and deploying AI voice phone assistants (collectively, the "Service"). If you do not agree with this policy, please do not use the Service.
1. Scope
This policy covers information processed through the Service. Capitalized terms not defined here have the meaning given in our Terms of Service. Our use of subprocessors is described on our Subprocessors page, and our use of cookies in our Cookies Policy.
Who we are. The Service is operated by Veillant (enkeltmandsvirksomhed, CVR 46669207, Rødovre Port 52, 5. 1., 2610 Rødovre, Denmark). Contact for anything in this policy: the address in Section 12.
Our two roles. For the account you create with us, your name, email, configuration, and billing, Veillant is the data controller. For the people who call the phone assistants you deploy, you (our customer) are the controller of your callers' personal data and Veillant acts as your processor, handling that data only on your instructions and under our Data Processing Agreement (GDPR Art. 28). If you are a caller, the business you phoned, not Veillant, is responsible for your data; see "Callers' rights" below.
2. What information we collect
- Account data: your name, email address, and profile image provided through Google sign-in.
- Configuration data: the companies, agents, products, services, and knowledge documents you create in the Service.
- Billing data: subscription status and payment metadata processed by our payment provider (Stripe). We do not store full card numbers.
- Call metadata: for each call your agent handles, we store data such as duration, timestamps, token usage, estimated cost, and status, used for operating the Service and billing. No caller identifier is part of this record.
- Derived call analytics: at the end of each call, an AI step reads the live transcript in memory and derives only aggregate, content-free counters: the hour of day, a coarse country, whether the call was handled or escalated, whether it was resolved, the call length in six coarse ranges, and the reason of the call chosen from a fixed, closed list (your own catalog items, stored by internal identifier, or one of eight generic categories such as "opening hours"). Free text written by the AI is never stored, reason counters carry no dates, and no per-call analytics record linked to your account exists (the only per-call trace is the account-less system signal described below). The raw transcript is discarded.
- System signals: for each call we keep one technical signal row with no link to any account, company or caller: a generic business category, a coarse region, the hour, the resolution outcome, and a technical quality indicator from a fixed list. It cannot be traced to you or to a caller; to the extent it were ever considered personal data, Veillant processes it as controller under legitimate interest, to improve the Service and understand demand.
- Technical and log data: device, browser, IP address, and usage information generated automatically when you use the Service.
What we never store from a call: we do not store call audio, we do not store the raw transcript, and we do not retain the caller's phone number. A caller's number is used only in the moment, to email you an escalation (with the caller's name if given and a short AI-written reason and note) so you can call them back, and to derive a coarse region, and is never written to our database, logs, or analytics.
3. Calls are not recorded, and are analyzed privately
Veillant does not record or store the audio of phone calls. Call audio is streamed and processed in real time through our AI and telephony providers (OpenAI and Twilio) so your agent can listen and respond, and is not persisted by us. The transcript exists only transiently, in memory, so the AI can respond during the call. It is never saved to our database.
The in-memory transcript is read once, at the end of the call, by an AI step that outputs only the aggregate counters described in Section 2 and then discards the transcript. Those counters are stored decoupled: each dimension is counted on its own row and the combination is never written together, so no stored record describes an individual call or can be traced back to an individual caller. Call-reason counters additionally carry no dates at all and reach your dashboard as a snapshot refreshed at most weekly, once your account has answered a minimum number of calls, and a visible counter never advances by fewer than five calls. Every caller is told at the start of the call that they are speaking with an artificial intelligence assistant and that the call is not recorded, and can ask for a person at any time.
4. How we use information
- To provide, operate, secure, and improve the Service.
- To process subscriptions and payments.
- To display usage, cost, and aggregated call analytics in your dashboard.
- To improve the Service and understand demand using anonymous, aggregated signals that are not linked to any account or caller.
- To communicate with you about your account, security, and service updates.
- To detect, prevent, and address fraud, abuse, or technical issues.
We do not sell your personal data, and we do not use your Customer Content to train AI models.
5. Legal bases (GDPR)
Where the GDPR applies, we rely on the following bases for the data we process as controller:
- Performance of a contract: account, configuration, and billing data, to provide the Service you signed up for.
- Legitimate interests: technical and log data, the aggregated call analytics described in Sections 2 and 3, and anonymous aggregated signals, to secure, operate, and improve the Service; balanced against the rights of those concerned and paired with the safeguards described here (no identifiers, no content, no per-call record).
- Consent: any optional processing you opt into (such as marketing communications), which may be withdrawn at any time.
- Legal obligation: where we must retain or disclose data to comply with the law.
For your callers' data, you are the controller and set the legal basis; we process it as your processor under our Data Processing Agreement.
6. How we share information
We share data only with trusted subprocessors strictly to deliver the Service, including OpenAI (AI, real-time voice, and the end-of-call analysis that derives analytics), Twilio (telephony), Resend (delivery of escalation emails, which may carry a caller's number and name to reach you), Stripe (payments), and our hosting, database and authentication providers. We require them to protect your data and use it only to provide their services to us. We may also disclose information where required by law, to enforce our Terms, to protect rights and safety, or in connection with a merger or acquisition (subject to this policy). See the full list on our Subprocessors page.
7. Data retention
We keep each kind of data for a stated period and no longer. A daily automated job enforces the periods below and records what it deleted.
- Account & configuration data: kept while your account is active. When you close your account it is erased 30 days later (see Section 9).
- Call metadata and derived analytics counters: kept for the life of your account to power your dashboard and billing, and erased with it. Analytics rows that carry a date are additionally deleted after 24 months; the counters that carry no date are lifetime totals and are erased with the account.
- Administrative log (who changed what in your account): 12 months, except the entries recording a deletion being requested, cancelled or carried out, which follow the account and are covered below.
- System signals: as these carry no link to any account or caller, they may be retained indefinitely.
- What survives account deletion: the record that you accepted a given version of our legal documents, and the records of the deletion being requested, cancelled or carried out, are deliberately kept for five years after the end of the calendar year in which your account closed. They hold your email address and our internal account identifier, and nothing else: the IP address they were created from is erased when the account is. We keep them to establish, exercise or defend legal claims (GDPR Art. 17(3)(e)), for the same period Danish bookkeeping rules require the invoices they relate to to be kept.
Because we never store call audio, raw transcripts, or caller numbers, there is nothing about an individual caller to retain in the first place. After anything is deleted, copies remain for up to seven days in our database provider's point-in-time backups before rotating out. Backups are used only to restore the Service after a failure; if a restore takes place, deletions that fell inside the recovered window are applied again.
What else outlives your account, and where. Beyond those records, nothing about you stays in Veillant's own systems except the account-less system signals described above and, for up to twelve months from the day each entry was written, the administrative log. Your invoices are held by our payment provider under its own retention rules, because Danish bookkeeping law requires them to be kept for five years, and our email provider retains what it needs to deliver messages we sent you. Both are named on our Subprocessors page.
8. International transfers
Our providers may process data in the United States and other countries whose data-protection laws may differ from yours. Where required, we rely on appropriate safeguards (such as the EU Standard Contractual Clauses) for international transfers.
9. Your rights
Depending on your location, you may have the right to:
- Access the personal data we hold about you.
- Correct inaccurate data.
- Export / port your data to another provider.
- Erase your data, and object to or restrict certain processing.
- Withdraw consent at any time, and opt out of marketing communications.
EU/EEA residents have these rights under the GDPR; California residents have rights under the CCPA/CPRA, including the right not to be discriminated against for exercising them (and we do not sell personal information). To exercise any right, contact us below.
Closing your account. You can delete your account yourself, from your account settings, at any time. The moment you confirm, your subscription stops renewing, your assistant stops answering calls, and you are signed out on every device. Your data is then held for 30 days before it is erased. That window exists so a deletion made by mistake, or by someone who reached your account without your permission, can be undone: we email you a link that cancels it, and signing in again brings you to a page with a button that cancels it. You can still export your data throughout those 30 days. Once they pass, the erasure runs on our next daily deletion run and cannot be reversed. What survives it, and for how long, is listed in Section 7.
If you want it erased immediately rather than after 30 days, write to us and we will carry it out without the waiting period.
Callers' rights. If you are a person who called a Veillant-powered assistant, the business you phoned is the controller of your data, not Veillant. Direct any access or deletion request to that business; our assistants are instructed to pass such requests to a human. Veillant itself holds no audio, transcript, or phone number tied to you, and its analytics are decoupled and aggregated so that no record identifies you, so on our side there is nothing to look up or erase.
10. Children
The Service is not directed to individuals under 16, and we do not knowingly collect their personal data.
11. Security
We use technical and organizational measures to protect your information, including scoping each account's data to that account so it is never shared across users. No method of transmission or storage is completely secure, but we work to protect your data and respond to incidents appropriately.
12. Changes & contact
We may revise this policy from time to time; we will notify you of material changes by email or through the Service. For privacy questions or requests, contact us at privacy@veillant.eu.