Skip to content
Legal

Privacy policy

Last updated: 24 August 2026

This is a translation. In case of any discrepancy the Italian version prevails.

This policy is for people who open an Idra account and for visitors to this site. If you called a business that uses Idra, the notice for you is this one. No numbered clauses: every number you read is the one the system actually applies. The Italian version is the authoritative one.

Who we are

Idra is a service that answers the phone for you, run by Francesco Vitale, sole trader, Via della Repubblica 51, 95040 Ramacca (CT), Italy — VAT IT06178100878. For anything to do with personal data write to privacy@ciaoidra.com.

We wear two hats. For your account data we are the controller: we decide why and how it is processed. For the data of the people who call your business the controller is you, and we are the processor (art. 28 GDPR): we process it only to make the service work for you, on your instructions.

The rules of that second relationship are in the data processing agreement, which you accept when you sign up; the commercial conditions are in the terms.

What we collect

Account and business. Email and password (hashed by Supabase, our database provider: we never see it), first and last name, business name, business phone and email, address, city, timezone, working hours, service radius, the rules you write for the agent, your Telegram chat id and, if you turn that channel on, your WhatsApp number with the date you opted in.

Billing. All we keep is your Stripe customer and subscription ids. Billing address, VAT number and card details are never stored on our side: they live only at Stripe.

The data of the people who call your business, which we process on your behalf: name, phone number (the key we use to recognise someone), email if given, address and city, the full call transcript, every single turn, the AI-written summary, a link to the audio recording, the job type with its description, urgency and estimated value, appointments with their notes, the reason for an escalation, and the raw data the model writes when it takes a note.

We do not store the audio ourselves. The recording stays on the infrastructure of Vapi, the telephony provider: we keep only the link, and when you play it back it is your browser that streams it from Vapi.

Site visits. The site runs on Vercel, which handles request traffic and function logs. For cookies, see the cookie policy. We count page views with Vercel Analytics, which writes nothing to your device and gives you no permanent identifier. The detail is in the cookie policy.

Why we process it, and on what legal basis

  • To make the service work for you — the account, configuring the agent, answering the phone, calls and jobs in the dashboard, notifications, the subscription, support. Legal basis: performance of the contract (art. 6.1.b GDPR).
  • To keep the service running and safe — security, abuse prevention, diagnosing faults, defending a legal claim. Legal basis: our legitimate interest (art. 6.1.f).
  • To comply with the law, in particular keeping accounting records. Legal basis: legal obligation (art. 6.1.c).
  • Caller data is not processed on a legal basis of ours: you choose that basis, because you are its controller. We process it because you instructed us to, under the DPA.

Who we share it with

We do not sell personal data and we do not hand it to anyone for marketing. The only ones who see it are the providers that make Idra work:

ProviderWhat it doesWhat data it receives
Supabasedatabase and authenticationeverything listed above
Vapitelephony, recording, call artifactscaller number, live audio, transcript, recording
Deepgram (behind Vapi)speech-to-textthe caller's audio
ElevenLabs (behind Vapi)text-to-speechthe text the agent speaks
OpenAIthe model that runs the conversationinstructions including the caller's name, phone, address and history, the whole conversation, tool results
Stripesubscriptions and paymentsaccount holder's name and email, billing address, VAT number, card
Resendemails to the account holderyour email; in the body, the caller's name, phone, city, job type and value
TwilioSMS to callers, WhatsApp to the ownerrecipient numbers and message bodies
Meta / WhatsAppreached only through Twiliothe content of the owner's notifications
Vercelsite hostingrequest traffic and function logs
Vercel Analyticssite visit statisticspage viewed, referrer, approximate country and device type — no permanent identifiers, no cookies

Deepgram and ElevenLabs sit behind Vapi: we never contact them directly, but we are the ones who choose them in the assistant configuration, and stopping at Vapi would tell you half the chain.

Telegram, said plainly. If you receive notifications on Telegram, the caller's phone number and problem description reach Telegram. We do not have an ordinary processor arrangement with Telegram under art. 28: we tell you in the open, so you can decide whether to use that channel.

Outside the European Union. Supabase keeps the database in the EU. The others — Vapi with Deepgram and ElevenLabs, OpenAI, Stripe, Resend, Twilio, Meta/WhatsApp and Vercel — also process data outside the European Economic Area: those transfers rest on the EU standard contractual clauses or on an adequacy decision, depending on the provider. We are not promising you more than that.

Where the data lives

The database and authentication are on Supabase, in the eu-central-1 (Frankfurt, Germany) region; the site's functions on Vercel are pinned to the fra1 (Frankfurt) region. The rest of the chain — telephony, transcription, voice, model, payments, email and SMS — processes data outside the European Economic Area. If that changes, this page changes with it.

How long we keep it

No “for as long as necessary”. These are the windows, and the system applies them on its own:

DataHow long
Call audio recording (at Vapi, and the link we hold)30 days from the call
Transcript, AI summary, individual conversation turns12 months from the call
Call data with no content (time, duration, outcome, value)24 months, then deleted
Customer record, jobs, appointments, escalationsuntil you delete them, or 24 months after the last contact
Closed account30-day grace period, then we delete the business and all data attached to it
Invoices and accounting records (at Stripe)10 years

The ten years on invoices are not our choice: art. 2220 of the Italian civil code requires them, and they override a deletion request. Even when you close the account and we delete the rest, the accounting records stay — and we do not use them for anything else.

Artificial intelligence

Idra is a conversational agent: it answers with a synthetic voice, understands what the person is saying and takes notes. The model is OpenAI's, the transcription Deepgram's, the voice ElevenLabs'.

It always declares itself. Before anything else the agent says: «Ciao, sono l'assistente automatico di {Nome Attività}: non sono una persona, ma prendo i tuoi dati e ti faccio richiamare dal titolare.» — “Hi, I'm the automated assistant of {Business Name}: I'm not a person, but I'll take your details and have the owner call you back.” If recording is on, it adds: «La chiamata è registrata.» — “This call is being recorded.” That declaration is written into the code at two independent points and cannot be switched off from the dashboard: it is what art. 50 of the EU AI Act requires.

No decision taken by a machine alone produces legal or similarly significant effects on anyone (art. 22 GDPR). In the default configuration the agent is in “assist” mode: the booking and messaging tools are not even made available to it, so it collects the details and asks the caller to wait for your call. It never agrees a binding price.

Two things it does on its own, and you should know about them: it books an appointment by itself, but only if you raise the autonomy level in the settings, and it puts the call through to your phone when it recognises an emergency.

Voice and biometric data

A call recording is a person's voice, so let us say it plainly: recordings exist only so that you can listen back to the call and so that the system can transcribe it. We do not use them to recognise anyone by their voice, we do not create voiceprints, we do not compare one call with another. We do not process biometric data for the purpose of identifying a person and we do not intend to process special categories of data (art. 9 GDPR): if someone on the phone mentions a health problem it ends up in the transcript because they said it, not because we are looking for it, and it disappears with the windows above.

How we protect it

We hold audio and transcripts of people who are not our customers, so here is the precise list:

  • All fourteen database tables have row-level access control, through a single central function: one business's data is reachable only by that business.
  • The service key, the one that bypasses those checks, is confined to six automated routes that all verify who is calling them: Vapi with a constant-time comparison, Stripe and Twilio with signature verification, Telegram with a secret token, the scheduled job with a bearer token.
  • Credentials are scrubbed from error messages, no personal data goes into the application logs, and traffic always travels over TLS.
  • Encryption at rest is the providers' — Supabase and Vapi — on the terms set out in their documentation: it is not an extra layer of encryption written by us.

Two things that are not in place today, so you do not find out later: signing in uses email and password with no second factor, and we have not yet configured browser security headers (HSTS, CSP). In the meantime, use a password you use nowhere else.

Your rights

Over your data you have the rights in articles 15–22 GDPR: to know what data we hold and get a copy of it (access), to correct it if it is wrong (rectification), to have it deleted (erasure), to freeze its use while something is being sorted out (restriction), to take it elsewhere in a machine-readable format (portability) and to object to processing we carry out on our legitimate interest (objection).

To exercise one, write to privacy@ciaoidra.com. We reply within one month (art. 12 GDPR); if the request is complicated we may take up to two months more, but we will tell you within the first. There is not yet a button in the dashboard to close your account: for now we do it ourselves, at your request by email, with the 30-day window in the table above.

If the request comes from someone who called your business, you are the controller: that person has to come to you, and we give you the help set out in the DPA so you can answer in time.

If you think we are getting it wrong and we have not given you a satisfactory answer, you can complain to the Italian data protection authority, the Garante per la protezione dei dati personali: Piazza Venezia 11, 00187 Rome, phone +39 06 696771, email garante@gpdp.it, certified mail protocollo@pec.gpdp.it, garanteprivacy.it. You can also go to the ordinary courts.

Changes to this policy

We will update this page when the product changes: one more provider, a different window. The last-updated date at the top changes with the text. If a change is substantial, we will email you before it takes effect.