Privacy Policy
TL;DR: We collect what we need to run voice agents for you. We encrypt it, scope it to your tenant, and let you delete it. We never sell your data. We never train foundation models on your calls.
1. Who we are
This service is provided by Metis Gold (“Callora”, “we”, “us”), operator of the platform at call.metis.gold. For privacy questions: privacy@call.metis.gold. GDPR representative and data-protection queries: dpo@call.metis.gold.
2. What we collect
2.1 Account data
- Email address, hashed password (bcrypt/pbkdf2), Google account ID if you sign in with Google.
- Billing details (handled by Stripe — we store only the last-4, brand, and subscription state).
2.2 Voice-agent data
- Agent configurations (name, voice, instructions, tools). Yours; treated as your intellectual property.
- Call audio — streamed in real time to OpenAI Realtime API for speech understanding and to Twilio for telephony. Optionally recorded (only if you enable it and callers are notified).
- Call transcripts generated from the audio.
- Extracted fields post-call (e.g. caller name, phone, appointment slot) per your speech-analysis prompt.
- Phone numbers of callers you contact (outbound) or who contact you (inbound).
2.3 Technical data
- IP addresses, user-agent, session cookies.
- Server logs (request path, timestamps, status codes) — kept 30 days.
- Sentry error breadcrumbs with PII redacted.
3. Legal bases for processing (GDPR Article 6)
- Contract (Art 6(1)(b)) — delivering the service you signed up for.
- Legitimate interest (Art 6(1)(f)) — fraud prevention, security, rate limiting, audit logging.
- Consent (Art 6(1)(a)) — optional call recording, marketing emails.
- Legal obligation (Art 6(1)(c)) — tax records, subpoenas.
Voice recordings and voiceprints are biometric data under GDPR Art 9. We process them only under explicit consent (from you at signup and from the caller through your opening message / recording notification).
4. How long we keep it
- Free tier: transcripts and recordings retained 30 days from the call.
- Pro tier: 1 year.
- Business tier: 7 years (HIPAA-aligned, or shorter per your retention setting).
- Audit log entries: 7 years (regulatory requirement).
- Backups: rotated within 35 days.
You can delete any individual call, agent, or your entire account at any time from Dashboard → Settings → Privacy → Delete data. Server-side deletion completes within 30 days; backups purge within 35 days.
5. Who we share it with (subprocessors)
- OpenAI (US) — real-time speech-to-speech (Realtime API), transcript generation (Whisper), LLM reasoning (GPT-4o). Zero-retention configured; OpenAI does not train on API data.
- Twilio (US) — telephony (voice, SMS, recording storage). BAA available on Business tier.
- Stripe (US, Ireland) — payments. PCI DSS Level 1.
- Google Workspace (US) — Calendar / Gmail integrations you explicitly authorize.
- Cloudflare (US) — WAF, DDoS protection, DNS.
- MongoDB Atlas (US) — primary database, encryption at rest.
- Emergent (US) — hosting infrastructure.
Current subprocessor list is at /trust. We give 30 days’ advance notice of new subprocessors; email dpo@call.metis.gold to subscribe.
6. International transfers
Data may be processed in the United States. For EU/UK data subjects we rely on Standard Contractual Clauses (2021/914) with all subprocessors and, where applicable, the EU-US Data Privacy Framework.
7. Your rights
Under GDPR / UK GDPR / CCPA you have the right to:
- Access the personal data we hold (self-serve export in Dashboard → Privacy).
- Rectify inaccurate data.
- Erase your data (self-serve delete or email us).
- Restrict or object to processing.
- Data portability — JSON export of everything.
- Withdraw consent at any time.
- Lodge a complaint with a supervisory authority (ICO in the UK, your local DPA in the EU, the California AG in California).
California residents have additional rights under CCPA/CPRA: know, delete, correct, opt-out of “sale”/“share” (we do neither), limit use of sensitive personal information. Contact privacy@call.metis.gold.
8. Security
- TLS 1.3 in transit, AES-256-GCM per-field for sensitive fields at rest.
- Google OAuth refresh tokens encrypted with rotating master key.
- Immutable, cryptographically hash-chained audit log.
- Strict CSP + HSTS + Permissions-Policy on every response.
- MFA available for admins; passkeys planned for all users.
- Web Application Firewall + rate limiting on every endpoint.
Full posture at /trust. Vulnerabilities: security@call.metis.gold.
9. Breach notification
If we suffer a personal-data breach affecting you, we will notify you and (where required) the relevant supervisory authority within 72 hours of becoming aware, per GDPR Art 33/34.
10. Children
Callora is not intended for users under 16. We do not knowingly collect data from children. If you believe we have, email privacy@call.metis.gold and we’ll delete it.
11. Changes
We may update this policy. Material changes will be emailed to registered users at least 14 days before taking effect.