Data processing agreement
Last updated: 5 October 2026
This is a translation. In case of any discrepancy the Italian version prevails.
When Idra answers the phone for you, it collects personal data about people who never signed up for anything and never saw our website: your own customers. This document is the data processing agreement required by article 28 GDPR, and it sets out what we may and may not do with that data. It forms part of the Terms and is accepted when you create your account or when you pay for the subscription through a payment link: you do not need to request a countersigned copy. The Italian text is the authoritative one; if this translation differs from it, the Italian prevails.
Roles: who decides and who carries it out
The GDPR draws a line between two roles. The controller is whoever decides why and how personal data is used. The processor is whoever handles that data on the controller's behalf, doing only what the controller says.
For the data of people who call your number, you are the controller: they are your customers, the relationship is with you, and you decide what the assistant asks them. We are the processor: Francesco Vitale, sole trader trading as Idra, Via della Repubblica 51, 95040 Ramacca (CT), Italy, VAT IT06178100878, info@ciaoidra.com.
There are two hats here and they should not be confused. For your own account data — your email, your business name, your subscription — we are the controller, and the privacy policy governs that. This agreement is only about your callers' data.
This document forms part of the Terms and becomes binding between us the moment you create your account or pay for the subscription through a payment link. If the Terms ever said something different about how we handle callers' data, what is written here wins. If we update it we email the account address, with at least 30 days' notice when the change is substantial.
Subject matter, duration, nature and purpose
What we actually do. We answer inbound calls on the number you connect; we speak to the caller with a synthetic voice; we transcribe the conversation; we pull out the details you need (who called, from where, what the problem is, how urgent it is); we create or update the customer record and the job; we notify you on the channels you have switched on; if you have enabled it, we send the caller a confirmation SMS. On the current line the call audio is not recorded: it is listened to live and only the text remains.
Why we do it. Only to provide you with the service. We do not use your callers' data for our own purposes, we do not sell it, we do not pass it to third parties for their purposes, and we do not use it to train any AI model of ours.
For how long. For as long as your subscription lasts, plus the retention windows below. These are the outer limits: after them, the data is gone from the service.
| Data | How long we keep it |
|---|---|
| Call audio | Not recorded on the current line. Recordings made at Vapi up to 11 September 2026: 30 days from the call |
| Transcript, AI-generated summary, individual turns of the conversation | 12 months from the call |
| Call data with no content: date, time, duration, outcome, value | 24 months, then deleted |
| Customer record, jobs, appointments, escalations | until you delete them, or 24 months from the last contact |
| Closed account | 30-day grace period, then the whole account is deleted |
| Invoices and accounting records (held at Stripe) | 10 years — art. 2220 of the Italian Civil Code, a legal obligation |
These windows are not an intention: a nightly automated job applies them to the database. For the recordings still held at Vapi from the previous service it asks Vapi to delete them — because those are not in our house, and blanking the link would not be erasure; if Vapi does not answer, the request stays queued and is retried the following night until it is confirmed.
What data we handle, and whose
The data subjects — the people the data is about — are your customers and anyone else who calls the number connected to Idra: someone who asks for a quote and then disappears, a relative calling on someone else's behalf, a building manager, a supplier, a wrong number. It also covers anyone mentioned during the call.
The data the assistant collects and puts in your dashboard:
- The caller's name and phone number. The number is the key we use to recognise the same person across calls.
- Email, address and town, when they give them.
- The problem they describe, with a job title, description, urgency and estimated value.
- The date, time and notes of any appointment booked.
- The full transcript of the call and every individual turn, theirs and the assistant's.
- The AI-generated summary of the call.
- The reason a call was flagged to you as urgent (escalation) and the text content of the notes the model took during the call.
- For calls handled up to 11 September 2026 by the previous service, the link to the audio recording, when recording was on.
We do not keep the audio. On the current line the caller's voice reaches OpenAI through Telnyx, is listened to live to answer and transcribe, and is recorded neither by us nor by Telnyx. OpenAI does not use data received through its API to train models and may keep it for up to 30 days for abuse monitoring. Recordings from the previous service sit at Vapi, we hold only the link, and they are deleted 30 days after the call.
Idra is not built to collect special categories of data — health, religious beliefs, political opinions, sexual orientation, criminal records. Do not tell the assistant to collect them: see “What you have to do”.
Your instructions
We process your callers' data only on your documented instructions. Those instructions are: this document, the Terms, the configuration you set in the dashboard, and anything you send us in writing to info@ciaoidra.com.
Your configuration is an instruction. The greeting, your business details, the list of services, the rules you write for the assistant, the autonomy level, the channels you want notifications on, the calendar you may connect: each of those choices is an order you give us about what to collect and what to do with it. If you tell the assistant to ask for a piece of data, we are collecting it on your behalf, and it is on you to be allowed to collect it.
How autonomous the assistant is. By default it takes the details and tells the caller you will call back. It does not book appointments on its own and it never gives a binding quote. Urgent requests are flagged to you straight away as urgent; the assistant does not transfer the call to your phone. The exception is the numbers you ask us to put straight through to you (suppliers, family, colleagues): those calls ring your mobile without going through the assistant and, if you do not answer, the assistant takes them. If someone has called before, the assistant knows the name they gave and their earlier requests, so they do not have to repeat everything; it never reads saved addresses or other details aloud. Google Calendar is optional and you connect it yourself: by default the assistant only reads when you are free or busy, without what your events say, and does not book. Only if you choose the «Can book» mode can the assistant put an appointment in a free slot of your calendar, which you are told about straight away and can cancel. These are automated actions that happen because you instructed them.
Two things we always do, and they cannot be switched off. First: at the start of every call the assistant says it is an automated or virtual assistant: with the standard sentence “Hi, I'm the automated assistant for {Business Name}: I'm not a person, but I'll take your details and have the owner call you back.”, or with the greeting you chose, if it already says so. This is required by article 50 of the EU AI Act, the sentence is written into the code, and there is no switch in the dashboard to turn it off. Second: if the caller describes a danger to people — a smell of gas, smoke or fire, suspected carbon monoxide, water on sockets or the electrical panel — a check written into the code makes the assistant tell them, before any other question, how to get safe and to call 115 (gas, fire) or 112 (carbon monoxide). You receive the request marked urgent straight after.
If an instruction looks unlawful, we say so. If what you ask us to do appears to us to breach the GDPR or another data protection rule, we write to you and may suspend that single instruction until we have sorted it out together. This is not legal advice: it is a duty article 28 places on us.
Outside your instructions we do only what it takes to keep the service running (technical maintenance, security, aggregate statistics that identify nobody) and what the law requires of us. If a law forces us to handle the data differently from what you told us, we tell you first, unless that same law forbids it.
Our obligations as processor
These are the obligations article 28(3) GDPR requires to be in writing. We undertake to:
- Process your callers' data only on your documented instructions, including for transfers outside the European Union, unless a law requires otherwise — in which case we tell you first where we are allowed to.
- Make sure anyone with access to the data is bound by confidentiality. Today the only person with administrative access is the sole trader behind Idra; if anyone else joins, they will be contractually bound before they get access.
- Apply appropriate technical and organisational measures under article 32: the ones we actually have are listed under “Security”.
- Engage another provider (a sub-processor) only on the conditions set out under “The providers we use”, imposing on them by contract the same obligations we owe you, and remaining answerable to you for what they do.
- Help you respond to requests from your own customers exercising their rights, with measures appropriate to the nature of the processing.
- Assist you with the obligations in articles 32 to 36 — security, breach notification, impact assessments, prior consultation with the supervisory authority — taking into account what we know and what is available to us.
- Delete or return the data at the end of the relationship, whichever you choose, and delete remaining copies unless a law requires us to keep them.
- Make available the information needed to show we meet these obligations, and allow the checks described under “Checks and audits”.
The providers we use
We rely on other providers to run the service. In GDPR language they are sub-processors: they process your callers' data on our behalf, while we process it on yours. By accepting this document you authorise all of them (this is the general written authorisation article 28(2) allows). Here is the complete, current list:
| Provider | What it does and what it receives | Where it processes the data |
|---|---|---|
| Supabase | Database and authentication: everything listed above lives here | European Union — Frankfurt (eu-central-1) |
| Telnyx | Telephony: the Italian number you forward calls to and the routing to the assistant — or to your mobile, for the contacts you list — over an encrypted connection. Receives the caller's number, the number called and the call audio in transit, without recording it | Outside the EEA — standard contractual clauses |
| OpenAI | The real-time model that listens to the caller, answers with a synthetic voice and transcribes; then a second model writes the summary, problem, urgency and estimated value. Receives the live audio, the caller's number, the transcript and the details collected. Does not use them to train models and may keep them for up to 30 days for abuse monitoring | Outside the EEA — standard contractual clauses |
| Stripe | Subscription and billing: the account holder's name, email, billing address, VAT number and card — not the callers' | Outside the EEA — standard contractual clauses |
| Resend | The emails we send you: your address and, in the body, the caller's name, phone, town, job and estimated value | Outside the EEA — standard contractual clauses |
| Twilio | SMS to callers and WhatsApp messages to you: recipients' numbers and message bodies | Outside the EEA — standard contractual clauses |
| Meta / WhatsApp | Reached only through Twilio: delivers the notification content to your phone | Outside the EEA — standard contractual clauses |
| Telegram | Notifications to you on the Telegram channel, only if you connect it: receives the caller's phone number and problem description | Outside the EEA — no ordinary article 28 arrangement: read the note below |
| Only if you connect Google Calendar yourself (optional): by default it reads only when you are free or busy, without what your events say; only if you choose the «Can book» mode does it also write appointments with the customer's name, phone and address. We keep an encrypted access token and the Google account email; events are deleted when you erase the customer | Outside the EEA — standard contractual clauses or adequacy decision | |
| Vercel | Application hosting: all request traffic and function logs | Functions run in Frankfurt (fra1); provider outside the EEA — standard contractual clauses |
Former providers. Until 11 September 2026 telephony ran through Vapi, with Deepgram for transcription and ElevenLabs for the voice. Since that date they receive no new data. Only the recordings of earlier calls remain at Vapi, and the nightly job has each one deleted 30 days after its call.
Telegram: read this before switching it on. If you connect the Telegram channel, the caller's phone number and problem description pass through Telegram's servers to reach your phone. With Telegram we do not have a data processing agreement like the one we have with every other provider in this table: we use the service on its public terms. We are not hiding it, because the choice is yours: the Telegram channel is optional and stays off until you connect it, and you can receive notifications by email, SMS or WhatsApp instead. If you never connect it, none of your callers' data goes through Telegram.
If we change a provider. We email the account address at least 30 days before adding a new one or replacing an existing one, telling you who they are, what they will do and what data they will receive. You have 30 days to object, by writing to info@ciaoidra.com with your reason, if it is a reasonable data protection reason. If you object we look for a way out — keeping your account on the previous provider, or switching that feature off for you. If neither is technically possible, you may cancel your subscription without penalty before the change takes effect. If we have to replace a provider urgently, because of a security problem or because they stop operating, we act immediately and tell you as soon as we can.
Transfers outside the European Union
The database is in Europe: the Supabase project sits in Frankfurt, and the application's functions run on Vercel in the Frankfurt region.
Every other provider in the table processes data outside the European Economic Area. Those transfers rely on the safeguards in Chapter V GDPR: the European Commission's standard contractual clauses contained in each provider's own contract or, where it applies, an adequacy decision.
We say what is true and no more: we have not negotiated bespoke clauses with these providers. Their standard agreements apply, they are public on their websites, and you can read them. If your own client or your adviser asks you for a copy of those clauses, write to us and we will point you to them.
The exception, again, is Telegram: if you switch that channel on, the data travels outside the EEA on the basis of Telegram's public terms alone, with no agreement negotiated by us. It is the only point in the chain where this happens.
Security
The measures that are genuinely in place today:
- Every table in the database has row-level access rules, and they all run through a single check: “does this user own this business?” If the check fails, the row does not even exist as far as the requester is concerned. One account cannot see another account's data.
- The technical key that bypasses those rules is used only server-side, by system routes, and never reaches the browser or the application you use.
- Every webhook is authenticated before it runs: OpenAI, Stripe, Twilio and Resend with their cryptographic signatures, Telnyx by confirming the call with Telnyx's API, Telegram with a secret token, scheduled jobs with a dedicated token, Vapi (previous service) with a constant-time comparison.
- Credentials are stripped out of error messages, and no personal data goes into the application logs.
- All connections are encrypted in transit (TLS).
- Encryption at rest is provided by the vendors that host the data, starting with Supabase: their documentation is what counts here, not our code. The Google Calendar access token is additionally encrypted by us before it is stored.
What is not there yet, so you can factor it into your own risk assessment rather than discover it later: sign-in is email and password, and two-factor authentication is not available yet; browser security headers (HSTS, CSP) are not configured yet; and there is no button to delete your account yourself, the request goes through us. In the meantime: pick a long password, do not reuse it anywhere else, and do not share the account.
What you have to do
You are the controller, so there are a few things we cannot do in your place. They are few, and these are they.
- Tell the people who call you. People need to know that an automated assistant may answer the phone and that the conversation is transcribed. We have already written the page they can read: notice for people who call. Link it from your website, from wherever you publish the number and from your email signature, so the notice is there before anyone picks up the phone. The assistant also says it out loud at the start of every call, but the spoken line on its own does not cover everything articles 13 and 14 GDPR require of you.
- Make sure you are allowed to collect that data. You need a lawful basis for the data you have us collect: normally that is performing a contract, or the pre-contractual steps the person themselves asked for, which is the quote or the callout they are ringing about. If you configure the assistant to ask for anything beyond that, the lawful basis for it is yours to have.
- Do not have it collect special-category data. Do not configure the assistant to ask about health, religious or philosophical beliefs, political opinions, trade union membership, sex life, biometric data or criminal convictions. Idra is not built for that data, and this agreement does not cover it.
- Do not use the numbers for marketing without consent. Numbers that come from an enquiry call are there to answer that enquiry. Sending promotions requires specific consent, which you have to collect yourself.
- Keep your own record of processing. Even as a sole trader you are a controller and you need the record required by article 30. This document gives you nearly everything you need to fill it in: purposes, categories of data, categories of data subjects, providers, retention periods, transfers.
- Answer your own customers. If one of your customers asks to see their data or to have it deleted, the answer has to come from the controller, which is you. We help: see “Your customers' rights”.
- Keep your credentials safe and tell us straight away if you suspect someone has got into your account.
If you do not do these things, we cannot do them for you: the controller's position is yours, and the consequences of a missing notice land on you.
If there is a data breach
A personal data breach is any incident leading to the destruction, loss, alteration, disclosure of or unauthorised access to data: a successful attack, a mistake that exposes data to someone who should not see it, a record deleted by accident and unrecoverable.
If it happens to us or to one of the providers on the list, we tell you without undue delay after becoming aware of it, by email to the account address and, if it is urgent, on another channel you have switched on as well.
The notice contains:
- What happened and when, as far as we know at that point.
- Which categories of data are involved and, approximately, how many people and how many records.
- The likely consequences for the people involved.
- What we have already done and what we propose to do to limit the damage.
- A direct contact for everything else: info@ciaoidra.com.
If we do not know everything at first, we send what we have and keep you updated as we learn more. The 72-hour notification to the supervisory authority, where one is needed, is made by the controller — you. We cannot make it for you, but we give you in writing everything you need to make it in time. The same goes for telling the affected people, where that is required.
Your customers' rights
The people who call have the right to know what data you hold about them, to have it corrected, to have it deleted, to object to the processing and to receive a copy of it. Those requests go to you, the controller. If one reaches us by mistake, we do not answer it on the merits: we forward it to the account address without delay, so the legal clock runs for whoever has to answer.
How we help, in practice:
- Deletion. You do it yourself, from the customer's record in the dashboard: you confirm by typing their phone number and the erasure runs. Conversations and individual turns are removed; transcripts, summaries, any recording links and the number are stripped out of the calls; appointments written to Google Calendar are deleted; missed-call recoveries are deleted; the content of the notes the model took is blanked; the customer record is deleted. Jobs and appointments stay, but detached from the person, because you need them for your accounts.
- Correction. You edit the data directly in the customer record.
- Access and portability. There is no export button in the dashboard yet: write to info@ciaoidra.com with the person's phone number and we will prepare a readable copy of their data, in time for you to answer within the month the GDPR gives you.
An honest note about the audio. On the current line there is no audio to delete, because it is not recorded. For calls handled up to 11 September 2026 the recording may still be at Vapi: when you erase a customer we do not just drop the link, we immediately ask Vapi to delete it, and if Vapi does not answer the request stays queued and is retried every night. Either way every recording is deleted at Vapi within 30 days of the call. The same queue applies to appointments on Google Calendar.
When the relationship ends
When the subscription ends, whether you cancel or payment fails, the data stays for 30 days. That is a grace period: it is there so a cancellation made by mistake, or a change of heart, does not cost you your customer history. After the 30 days we delete the whole account in one go: business, customers, calls, transcripts, summaries, jobs, appointments.
Within that window you have a choice: if you want a copy of the data before it goes, ask at info@ciaoidra.com and we will prepare it; if instead you want everything deleted immediately, without waiting the 30 days, ask and we will do it. There is no button in the dashboard to delete the account yourself yet: the request goes through us.
What survives anyway. The invoices and accounting records for the subscription sit at Stripe and have to be kept for 10 years, as article 2220 of the Italian Civil Code requires. They concern you as our customer, not your callers, and that obligation overrides an erasure request: it is one of the cases where the right to be forgotten gives way to a legal duty.
The retention windows in the table at the top apply regardless, including while the subscription is live: a transcript from fourteen months ago is gone, whether or not you close the account.
Checks and audits
You are entitled to check that we are doing what this document says. On written request to info@ciaoidra.com, and normally no more than once a year, we give you: the current version of this document, the current list of providers with their purposes and locations, a description of the security measures in place, the public references to our providers' documentation and certifications, and written answers to a reasonable data protection questionnaire. If there has been a breach affecting you, or if an authority asks, the once-a-year limit does not apply.
We are a sole trader and the infrastructure belongs to our providers: we cannot grant a physical inspection of their data centres, because it is not ours to grant. If your organisation needs a higher level of assurance than what is described here, let us talk about it before you subscribe, not after.
For anything to do with this agreement — an audit request, an objection to a new provider, a request from one of your customers, a suspected breach — the address is info@ciaoidra.com. We answer in Italian and in English.