Privacy policy
Last updated: 24 August 2026
This is a translation. In case of any discrepancy the Italian version prevails.
This policy is for people who open an Idra account and for visitors to this site. If you called a business that uses Idra, the notice for you is this one. No numbered clauses: every number you read is the one the system actually applies. The Italian version is the authoritative one.
Who we are
Idra is a service that answers the phone for you, run by Francesco Vitale, sole trader, Via della Repubblica 51, 95040 Ramacca (CT), Italy — VAT IT06178100878. For anything to do with personal data write to privacy@ciaoidra.com.
We wear two hats. For your account data we are the controller: we decide why and how it is processed. For the data of the people who call your business the controller is you, and we are the processor (art. 28 GDPR): we process it only to make the service work for you, on your instructions.
The rules of that second relationship are in the data processing agreement, which you accept when you sign up; the commercial conditions are in the terms.
What we collect
Account and business. Email and password (hashed by Supabase, our database provider: we never see it), first and last name, business name, business phone and email, address, city, timezone, working hours, service radius, the rules you write for the agent, your Telegram chat id and, if you turn that channel on, your WhatsApp number with the date you opted in.
Billing. All we keep is your Stripe customer and subscription ids. Billing address, VAT number and card details are never stored on our side: they live only at Stripe.
The data of the people who call your business, which we process on your behalf: name, phone number (the key we use to recognise someone), email if given, address and city, the full call transcript, every single turn, the AI-written summary, a link to the audio recording, the job type with its description, urgency and estimated value, appointments with their notes, the reason for an escalation, and the raw data the model writes when it takes a note.
We do not store the audio ourselves. The recording stays on the infrastructure of Vapi, the telephony provider: we keep only the link, and when you play it back it is your browser that streams it from Vapi.
Site visits. The site runs on Vercel, which handles request traffic and function logs. For cookies, see the cookie policy. We count page views with Vercel Analytics, which writes nothing to your device and gives you no permanent identifier. The detail is in the cookie policy.
Why we process it, and on what legal basis
- To make the service work for you — the account, configuring the agent, answering the phone, calls and jobs in the dashboard, notifications, the subscription, support. Legal basis: performance of the contract (art. 6.1.b GDPR).
- To keep the service running and safe — security, abuse prevention, diagnosing faults, defending a legal claim. Legal basis: our legitimate interest (art. 6.1.f).
- To comply with the law, in particular keeping accounting records. Legal basis: legal obligation (art. 6.1.c).
- Caller data is not processed on a legal basis of ours: you choose that basis, because you are its controller. We process it because you instructed us to, under the DPA.
Who we share it with
We do not sell personal data and we do not hand it to anyone for marketing. The only ones who see it are the providers that make Idra work:
| Provider | What it does | What data it receives |
|---|---|---|
| Supabase | database and authentication | everything listed above |
| Vapi | telephony, recording, call artifacts | caller number, live audio, transcript, recording |
| Deepgram (behind Vapi) | speech-to-text | the caller's audio |
| ElevenLabs (behind Vapi) | text-to-speech | the text the agent speaks |
| OpenAI | the model that runs the conversation | instructions including the caller's name, phone, address and history, the whole conversation, tool results |
| Stripe | subscriptions and payments | account holder's name and email, billing address, VAT number, card |
| Resend | emails to the account holder | your email; in the body, the caller's name, phone, city, job type and value |
| Twilio | SMS to callers, WhatsApp to the owner | recipient numbers and message bodies |
| Meta / WhatsApp | reached only through Twilio | the content of the owner's notifications |
| Vercel | site hosting | request traffic and function logs |
| Vercel Analytics | site visit statistics | page viewed, referrer, approximate country and device type — no permanent identifiers, no cookies |
Deepgram and ElevenLabs sit behind Vapi: we never contact them directly, but we are the ones who choose them in the assistant configuration, and stopping at Vapi would tell you half the chain.
Telegram, said plainly. If you receive notifications on Telegram, the caller's phone number and problem description reach Telegram. We do not have an ordinary processor arrangement with Telegram under art. 28: we tell you in the open, so you can decide whether to use that channel.
Outside the European Union. Supabase keeps the database in the EU. The others — Vapi with Deepgram and ElevenLabs, OpenAI, Stripe, Resend, Twilio, Meta/WhatsApp and Vercel — also process data outside the European Economic Area: those transfers rest on the EU standard contractual clauses or on an adequacy decision, depending on the provider. We are not promising you more than that.
Where the data lives
The database and authentication are on Supabase, in the eu-central-1 (Frankfurt, Germany) region; the site's functions on Vercel are pinned to the fra1 (Frankfurt) region. The rest of the chain — telephony, transcription, voice, model, payments, email and SMS — processes data outside the European Economic Area. If that changes, this page changes with it.
How long we keep it
No “for as long as necessary”. These are the windows, and the system applies them on its own:
| Data | How long |
|---|---|
| Call audio recording (at Vapi, and the link we hold) | 30 days from the call |
| Transcript, AI summary, individual conversation turns | 12 months from the call |
| Call data with no content (time, duration, outcome, value) | 24 months, then deleted |
| Customer record, jobs, appointments, escalations | until you delete them, or 24 months after the last contact |
| Closed account | 30-day grace period, then we delete the business and all data attached to it |
| Invoices and accounting records (at Stripe) | 10 years |
The ten years on invoices are not our choice: art. 2220 of the Italian civil code requires them, and they override a deletion request. Even when you close the account and we delete the rest, the accounting records stay — and we do not use them for anything else.
Artificial intelligence
Idra is a conversational agent: it answers with a synthetic voice, understands what the person is saying and takes notes. The model is OpenAI's, the transcription Deepgram's, the voice ElevenLabs'.
It always declares itself. Before anything else the agent says: «Ciao, sono l'assistente automatico di {Nome Attività}: non sono una persona, ma prendo i tuoi dati e ti faccio richiamare dal titolare.» — “Hi, I'm the automated assistant of {Business Name}: I'm not a person, but I'll take your details and have the owner call you back.” If recording is on, it adds: «La chiamata è registrata.» — “This call is being recorded.” That declaration is written into the code at two independent points and cannot be switched off from the dashboard: it is what art. 50 of the EU AI Act requires.
No decision taken by a machine alone produces legal or similarly significant effects on anyone (art. 22 GDPR). In the default configuration the agent is in “assist” mode: the booking and messaging tools are not even made available to it, so it collects the details and asks the caller to wait for your call. It never agrees a binding price.
Two things it does on its own, and you should know about them: it books an appointment by itself, but only if you raise the autonomy level in the settings, and it puts the call through to your phone when it recognises an emergency.
Voice and biometric data
A call recording is a person's voice, so let us say it plainly: recordings exist only so that you can listen back to the call and so that the system can transcribe it. We do not use them to recognise anyone by their voice, we do not create voiceprints, we do not compare one call with another. We do not process biometric data for the purpose of identifying a person and we do not intend to process special categories of data (art. 9 GDPR): if someone on the phone mentions a health problem it ends up in the transcript because they said it, not because we are looking for it, and it disappears with the windows above.
How we protect it
We hold audio and transcripts of people who are not our customers, so here is the precise list:
- All fourteen database tables have row-level access control, through a single central function: one business's data is reachable only by that business.
- The service key, the one that bypasses those checks, is confined to six automated routes that all verify who is calling them: Vapi with a constant-time comparison, Stripe and Twilio with signature verification, Telegram with a secret token, the scheduled job with a bearer token.
- Credentials are scrubbed from error messages, no personal data goes into the application logs, and traffic always travels over TLS.
- Encryption at rest is the providers' — Supabase and Vapi — on the terms set out in their documentation: it is not an extra layer of encryption written by us.
Two things that are not in place today, so you do not find out later: signing in uses email and password with no second factor, and we have not yet configured browser security headers (HSTS, CSP). In the meantime, use a password you use nowhere else.
Your rights
Over your data you have the rights in articles 15–22 GDPR: to know what data we hold and get a copy of it (access), to correct it if it is wrong (rectification), to have it deleted (erasure), to freeze its use while something is being sorted out (restriction), to take it elsewhere in a machine-readable format (portability) and to object to processing we carry out on our legitimate interest (objection).
To exercise one, write to privacy@ciaoidra.com. We reply within one month (art. 12 GDPR); if the request is complicated we may take up to two months more, but we will tell you within the first. There is not yet a button in the dashboard to close your account: for now we do it ourselves, at your request by email, with the 30-day window in the table above.
If the request comes from someone who called your business, you are the controller: that person has to come to you, and we give you the help set out in the DPA so you can answer in time.
If you think we are getting it wrong and we have not given you a satisfactory answer, you can complain to the Italian data protection authority, the Garante per la protezione dei dati personali: Piazza Venezia 11, 00187 Rome, phone +39 06 696771, email garante@gpdp.it, certified mail protocollo@pec.gpdp.it, garanteprivacy.it. You can also go to the ordinary courts.
Changes to this policy
We will update this page when the product changes: one more provider, a different window. The last-updated date at the top changes with the text. If a change is substantial, we will email you before it takes effect.