This policy explains what data Redialog processes, what we deliberately never keep, and the controls you and your organization have. It covers the Redialog application and this website. Redialog is operated by BOOTHIC SMPC, a single-member private company incorporated in Greece, VAT No. EL801264656 ("we", "us").
Our two roles
For most of the data in Redialog — your documents, Q&A, transcripts, captured fields, summaries, notes and drafts — your organization decides why and how it is processed. Under the GDPR it is the controller, and we are its processor: we handle that data only on its instructions, under our Data Processing Agreement. If you took part in a call transcribed by one of our customers and want to exercise rights over that data, the quickest route is that organization — and we help them respond.
For a smaller set of data — accounts, billing, support messages and this website — we decide how and why, and we are the controller. The rest of this policy covers both roles and says which is which where it matters.
What we process
- Account data — your name, email, organization, role and seat assignment, with sign-in handled through WorkOS.
- Content you bring — documents, Q&A, Guides and Smart Field definitions you add to your Agents.
- Call data — live transcripts (including what other participants say), captured Smart Field values, summaries, tasks, notes and follow-up drafts.
- Usage and log data — IP address, browser and device information, timestamps, security logs and feature-usage counters such as AI-allowance metering.
- Billing data — plan, seat count and payment status. Payments are handled by Polar as merchant of record; we never see full card numbers.
- Messages you send us — by email or through the contact form on this site.
What we never do
Call audio is never stored: it is captured on your side of the call, transcribed on the fly, and immediately discarded. No bot joins your meetings or announces itself to the other side. We do not sell personal data. We do not use your content or calls to train AI models — ours or anyone else's. And this website carries no advertising and no cross-site tracking.
Why we process it
As your organization's processor, we process content and call data on its documented instructions. Where we are the controller, we rely on: performance of a contract (Art. 6(1)(b) GDPR) to run accounts, seats and billing; legitimate interests (Art. 6(1)(f)) to secure the service, prevent abuse, measure aggregate usage and improve Redialog; legal obligations (Art. 6(1)(c)) for tax and accounting records; and consent (Art. 6(1)(a)) where the law requires it — which you can withdraw at any time.
Subprocessors and recipients
We share personal data only with the providers needed to run Redialog. Each is bound by a data processing agreement and processes data only to provide its service to us:
- WorkOS (US) — authentication and single sign-on.
- Convex (US) — database and backend infrastructure storing app content.
- Soniox (US) — real-time speech-to-text; receives live call audio solely to return the transcript.
- Google (US/EU) — AI models (Gemini) generating Live Answers, Smart Fields, summaries and drafts from your content and transcripts.
For this website only: Umami Cloud provides cookieless, aggregate analytics, and Web3Forms delivers contact-form messages to our inbox.
Two kinds of recipients act for themselves rather than for us. Polar, our merchant of record, is the seller at checkout and an independent controller of payment data under its own privacy policy. And the integrations you choose to connect — HubSpot, Salesforce, Notion, Asana, Slack and similar — receive data only at your direction, under their own terms.
We update this list on this page and notify your admins at least 30 days before adding a new subprocessor; organizations can object as our Data Processing Agreement sets out. We may also disclose data where the law requires it; and if we are ever part of a merger or acquisition, this policy continues to protect the data that transfers.
International transfers
Our subprocessors are mainly in the United States. When personal data leaves the EEA, we rely on the safeguards the GDPR provides for: the EU–US Data Privacy Framework where the provider is certified, and the European Commission's Standard Contractual Clauses otherwise, alongside measures such as encryption in transit and at rest.
Retention
Your organization controls the life of its call data: admins can set calls to auto-delete after a chosen number of days. When a member leaves, their private calls are removed, shared resources transfer to an admin, and organization records are kept anonymized. Account data is kept while the account is active and deleted afterwards, except what tax and accounting law requires us to keep. Contact and support messages are kept as long as needed to help you. Deleted data also disappears from backups on their rolling replacement cycle.
Visibility inside your organization
Default call visibility is set by your admin. Any call can be made private, and private notes are visible only to their owner — enforced everywhere, including search and integrations.
Security
Data is encrypted in transit and at rest across the entire pipeline. Integration credentials are encrypted with AES-256-GCM. Sign-in and MCP access are secured with OAuth via WorkOS, and the service runs on SOC 2 Type II certified infrastructure with multi-region backups. Access to production data is limited to the few people who need it to run the service. No system is perfectly secure — if a breach ever puts your rights at risk, we will notify you and the supervisory authority as the GDPR requires.
Cookies
The app sets only the strictly necessary cookies needed to keep you signed in. This website sets none: analytics are cookieless, and there are no advertising or cross-site tracking cookies anywhere — which is why you don't see a cookie banner.
Your rights
You can ask for access to your personal data, correction, deletion, restriction or portability, object to processing based on legitimate interests, and withdraw consent at any time. Write to [email protected]; we may need to verify your identity, and we respond within one month. If the data lives in a customer's workspace — for example a call you took part in — we may refer you to that organization, since it controls the data, and we will help it respond. You can also lodge a complaint with the Hellenic Data Protection Authority (dpa.gr) or your local EU supervisory authority. If you are in California or another jurisdiction with its own privacy law, we honor those rights too — and we do not "sell" or "share" personal information as the CCPA defines those terms.
Children
Redialog is a business tool. It is not directed to anyone under 18, and we do not knowingly process children's data.
Changes
If we make material changes to this policy, we will notify you — by email or in the app — before they take effect.
Contact
BOOTHIC SMPC — single-member private company incorporated in Greece
29 Tavoulari Str., Greece · GEMI No. 153029403000 · VAT No. EL801264656
Operating Redialog · [email protected]