Skip to content
Legal

Data processing agreement

Last updated: 24 August 2026

This is a translation. In case of any discrepancy the Italian version prevails.

When Idra answers the phone for you, it collects personal data about people who never signed up for anything and never saw our website: your own customers. This document is the data processing agreement required by article 28 GDPR, and it sets out what we may and may not do with that data. It forms part of the Terms and is accepted when you create your account: you do not need to request a countersigned copy. The Italian text is the authoritative one; if this translation differs from it, the Italian prevails.

Roles: who decides and who carries it out

The GDPR draws a line between two roles. The controller is whoever decides why and how personal data is used. The processor is whoever handles that data on the controller's behalf, doing only what the controller says.

For the data of people who call your number, you are the controller: they are your customers, the relationship is with you, and you decide what the assistant asks them. We are the processor: Francesco Vitale, sole trader trading as Idra, Via della Repubblica 51, 95040 Ramacca (CT), Italy, VAT IT06178100878, info@ciaoidra.com.

There are two hats here and they should not be confused. For your own account data — your email, your business name, your subscription — we are the controller, and the privacy policy governs that. This agreement is only about your callers' data.

This document forms part of the Terms and becomes binding between us the moment you create your account. If the Terms ever said something different about how we handle callers' data, what is written here wins. If we update it we email the account address, with at least 30 days' notice when the change is substantial.

Subject matter, duration, nature and purpose

What we actually do. We answer inbound calls on the number you connect; we speak to the caller with a synthetic voice; we transcribe the conversation; we pull out the details you need (who called, from where, what the problem is, how urgent it is); we create or update the customer record and the job; we notify you on the channels you have switched on; if you have enabled it, we send the caller a confirmation SMS; and if you have enabled recording, the call is recorded.

Why we do it. Only to provide you with the service. We do not use your callers' data for our own purposes, we do not sell it, we do not pass it to third parties for their purposes, and we do not use it to train any AI model of ours.

For how long. For as long as your subscription lasts, plus the retention windows below. These are the outer limits: after them, the data is gone from the service.

DataHow long we keep it
Call audio recording (held at Vapi, and the link we hold)30 days from the call
Transcript, AI-generated summary, individual turns of the conversation12 months from the call
Call data with no content: date, time, duration, outcome, value24 months, then deleted
Customer record, jobs, appointments, escalationsuntil you delete them, or 24 months from the last contact
Closed account30-day grace period, then the whole account is deleted
Invoices and accounting records (held at Stripe)10 years — art. 2220 of the Italian Civil Code, a legal obligation

These windows are not an intention: a nightly automated job applies them to the database and, for the audio, asks Vapi to delete the recording — because that one is not in our house, and blanking the link would not be erasure. If Vapi does not answer, the request stays queued and is retried the following night until it is confirmed.

What data we handle, and whose

The data subjects — the people the data is about — are your customers and anyone else who calls the number connected to Idra: someone who asks for a quote and then disappears, a relative calling on someone else's behalf, a building manager, a supplier, a wrong number. It also covers anyone mentioned during the call.

The data the assistant collects and puts in your dashboard:

  • The caller's name and phone number. The number is the key we use to recognise the same person across calls.
  • Email, address and town, when they give them.
  • The problem they describe, with a job title, description, urgency and estimated value.
  • The date, time and notes of any appointment booked.
  • The full transcript of the call and every individual turn, theirs and the assistant's.
  • The AI-generated summary of the call.
  • The link to the audio recording, when recording is on.
  • The reason a call was handed over to you (escalation) and the text content of the tools the model used during the call.

We do not store the audio ourselves. The recording stays on Vapi's infrastructure: we keep only the link, and when you play it back from the dashboard it is your browser that streams it straight from Vapi.

Idra is not built to collect special categories of data — health, religious beliefs, political opinions, sexual orientation, criminal records. Do not tell the assistant to collect them: see “What you have to do”.

Your instructions

We process your callers' data only on your documented instructions. Those instructions are: this document, the Terms, the configuration you set in the dashboard, and anything you send us in writing to info@ciaoidra.com.

Your configuration is an instruction. The greeting, your business details, the list of services, the rules you write for the assistant, the autonomy level, recording on or off, the channels you want notifications on: each of those choices is an order you give us about what to collect and what to do with it. If you tell the assistant to ask for a piece of data, we are collecting it on your behalf, and it is on you to be allowed to collect it.

How autonomous the assistant is. By default it works in assist mode: it takes the details and asks you to call back. It does not book appointments on its own and it never gives a binding quote. If you raise the autonomy level, the assistant can book appointments and send messages by itself. On top of that, a call classified as an emergency can be transferred live to your phone. These are automated actions that happen because you instructed them.

Two things we always do, and they cannot be switched off. At the start of every call the assistant says it is an automated assistant and not a person; when recording is on, it also says the call is being recorded. This is required by article 50 of the EU AI Act, it is written into the code at two independent points, and there is no switch in the dashboard to turn it off.

If an instruction looks unlawful, we say so. If what you ask us to do appears to us to breach the GDPR or another data protection rule, we write to you and may suspend that single instruction until we have sorted it out together. This is not legal advice: it is a duty article 28 places on us.

Outside your instructions we do only what it takes to keep the service running (technical maintenance, security, aggregate statistics that identify nobody) and what the law requires of us. If a law forces us to handle the data differently from what you told us, we tell you first, unless that same law forbids it.

Our obligations as processor

These are the obligations article 28(3) GDPR requires to be in writing. We undertake to:

  • Process your callers' data only on your documented instructions, including for transfers outside the European Union, unless a law requires otherwise — in which case we tell you first where we are allowed to.
  • Make sure anyone with access to the data is bound by confidentiality. Today the only person with administrative access is the sole trader behind Idra; if anyone else joins, they will be contractually bound before they get access.
  • Apply appropriate technical and organisational measures under article 32: the ones we actually have are listed under “Security”.
  • Engage another provider (a sub-processor) only on the conditions set out under “The providers we use”, imposing on them by contract the same obligations we owe you, and remaining answerable to you for what they do.
  • Help you respond to requests from your own customers exercising their rights, with measures appropriate to the nature of the processing.
  • Assist you with the obligations in articles 32 to 36 — security, breach notification, impact assessments, prior consultation with the supervisory authority — taking into account what we know and what is available to us.
  • Delete or return the data at the end of the relationship, whichever you choose, and delete remaining copies unless a law requires us to keep them.
  • Make available the information needed to show we meet these obligations, and allow the checks described under “Checks and audits”.

The providers we use

We rely on other providers to run the service. In GDPR language they are sub-processors: they process your callers' data on our behalf, while we process it on yours. By accepting this document you authorise all of them (this is the general written authorisation article 28(2) allows). Here is the complete, current list:

ProviderWhat it does and what it receivesWhere it processes the data
SupabaseDatabase and authentication: everything listed above lives hereEuropean Union — Frankfurt (eu-central-1)
VapiTelephony, recording and call artefacts: caller's number, live audio, transcript, recordingOutside the EEA — standard contractual clauses
Deepgram (behind Vapi)Turning speech into text: receives the caller's audioOutside the EEA — standard contractual clauses
ElevenLabs (behind Vapi)The assistant's synthetic voice: receives the text of its repliesOutside the EEA — standard contractual clauses
OpenAIThe model that runs the conversation: receives the system instructions containing the caller's name, phone, address and history, the whole conversation, and the results of the toolsOutside the EEA — standard contractual clauses
StripeSubscription and billing: the account holder's name, email, billing address, VAT number and card — not the callers'Outside the EEA — standard contractual clauses
ResendThe emails we send you: your address and, in the body, the caller's name, phone, town, job and estimated valueOutside the EEA — standard contractual clauses
TwilioSMS to callers and WhatsApp messages to you: recipients' numbers and message bodiesOutside the EEA — standard contractual clauses
Meta / WhatsAppReached only through Twilio: delivers the notification content to your phoneOutside the EEA — standard contractual clauses
TelegramNotifications to you on the Telegram channel, only if you connect it: receives the caller's phone number and problem descriptionOutside the EEA — no ordinary article 28 arrangement: read the note below
VercelApplication hosting: all request traffic and function logsFunctions run in Frankfurt (fra1); provider outside the EEA — standard contractual clauses

Deepgram and ElevenLabs are named even though we never call them directly: we configure them inside the Vapi assistant ourselves, and naming only Vapi would hide part of the chain.

Telegram: read this before switching it on. If you connect the Telegram channel, the caller's phone number and problem description pass through Telegram's servers to reach your phone. With Telegram we do not have a data processing agreement like the one we have with every other provider in this table: we use the service on its public terms. We are not hiding it, because the choice is yours: the Telegram channel is optional and stays off until you connect it, and you can receive notifications by email, SMS or WhatsApp instead. If you never connect it, none of your callers' data goes through Telegram.

If we change a provider. We email the account address at least 30 days before adding a new one or replacing an existing one, telling you who they are, what they will do and what data they will receive. You have 30 days to object, by writing to info@ciaoidra.com with your reason, if it is a reasonable data protection reason. If you object we look for a way out — keeping your account on the previous provider, or switching that feature off for you. If neither is technically possible, you may cancel your subscription without penalty before the change takes effect. If we have to replace a provider urgently, because of a security problem or because they stop operating, we act immediately and tell you as soon as we can.

Transfers outside the European Union

The database is in Europe: the Supabase project sits in Frankfurt, and the application's functions run on Vercel in the Frankfurt region.

Every other provider in the table processes data outside the European Economic Area. Those transfers rely on the safeguards in Chapter V GDPR: the European Commission's standard contractual clauses contained in each provider's own contract or, where it applies, an adequacy decision.

We say what is true and no more: we have not negotiated bespoke clauses with these providers. Their standard agreements apply, they are public on their websites, and you can read them. If your own client or your adviser asks you for a copy of those clauses, write to us and we will point you to them.

The exception, again, is Telegram: if you switch that channel on, the data travels outside the EEA on the basis of Telegram's public terms alone, with no agreement negotiated by us. It is the only point in the chain where this happens.

Security

The measures that are genuinely in place today:

  • Every table in the database has row-level access rules, and they all run through a single check: “does this user own this business?” If the check fails, the row does not even exist as far as the requester is concerned. One account cannot see another account's data.
  • The technical key that bypasses those rules is used by six system routes only (provider webhooks and scheduled jobs), never by the application you use.
  • Every webhook is authenticated before it runs: Vapi with a constant-time comparison, Stripe with its cryptographic signature, Twilio with its own request validation, Telegram with a secret token, scheduled jobs with a dedicated token.
  • Credentials are stripped out of error messages, and no personal data goes into the application logs.
  • All connections are encrypted in transit (TLS).
  • Encryption at rest is provided by the vendors that host the data, Supabase and Vapi: their documentation is what counts here, not our code.

What is not there yet, so you can factor it into your own risk assessment rather than discover it later: sign-in is email and password, and two-factor authentication is not available yet; browser security headers (HSTS, CSP) are not configured yet; and there is no button to delete your account yourself, the request goes through us. In the meantime: pick a long password, do not reuse it anywhere else, and do not share the account.

What you have to do

You are the controller, so there are a few things we cannot do in your place. They are few, and these are they.

  • Tell the people who call you. People need to know that an automated assistant may answer the phone, that the conversation is transcribed and, if you have enabled recording, recorded. We have already written the page they can read: notice for people who call. Link it from your website, from wherever you publish the number and from your email signature, so the notice is there before anyone picks up the phone. The assistant also says it out loud at the start of every call, but the spoken line on its own does not cover everything articles 13 and 14 GDPR require of you.
  • Make sure you are allowed to collect that data. You need a lawful basis for the data you have us collect: normally that is performing a contract, or the pre-contractual steps the person themselves asked for, which is the quote or the callout they are ringing about. If you configure the assistant to ask for anything beyond that, the lawful basis for it is yours to have.
  • Do not have it collect special-category data. Do not configure the assistant to ask about health, religious or philosophical beliefs, political opinions, trade union membership, sex life, biometric data or criminal convictions. Idra is not built for that data, and this agreement does not cover it.
  • Do not use the numbers for marketing without consent. Numbers that come from an enquiry call are there to answer that enquiry. Sending promotions requires specific consent, which you have to collect yourself.
  • Keep your own record of processing. Even as a sole trader you are a controller and you need the record required by article 30. This document gives you nearly everything you need to fill it in: purposes, categories of data, categories of data subjects, providers, retention periods, transfers.
  • Answer your own customers. If one of your customers asks to see their data or to have it deleted, the answer has to come from the controller, which is you. We help: see “Your customers' rights”.
  • Keep your credentials safe and tell us straight away if you suspect someone has got into your account.

If you do not do these things, we cannot do them for you: the controller's position is yours, and the consequences of a missing notice land on you.

If there is a data breach

A personal data breach is any incident leading to the destruction, loss, alteration, disclosure of or unauthorised access to data: a successful attack, a mistake that exposes data to someone who should not see it, a record deleted by accident and unrecoverable.

If it happens to us or to one of the providers on the list, we tell you without undue delay after becoming aware of it, by email to the account address and, if it is urgent, on another channel you have switched on as well.

The notice contains:

  • What happened and when, as far as we know at that point.
  • Which categories of data are involved and, approximately, how many people and how many records.
  • The likely consequences for the people involved.
  • What we have already done and what we propose to do to limit the damage.
  • A direct contact for everything else: info@ciaoidra.com.

If we do not know everything at first, we send what we have and keep you updated as we learn more. The 72-hour notification to the supervisory authority, where one is needed, is made by the controller — you. We cannot make it for you, but we give you in writing everything you need to make it in time. The same goes for telling the affected people, where that is required.

Your customers' rights

The people who call have the right to know what data you hold about them, to have it corrected, to have it deleted, to object to the processing and to receive a copy of it. Those requests go to you, the controller. If one reaches us by mistake, we do not answer it on the merits: we forward it to the account address without delay, so the legal clock runs for whoever has to answer.

How we help, in practice:

  • Deletion. You do it yourself, from the customer's record in the dashboard: you confirm by typing their phone number and the erasure runs. Conversations and individual turns are removed; transcripts, summaries, recording links and the number are stripped out of the calls; missed-call recoveries are deleted; the content of the tools the model used is blanked; the customer record is deleted. Jobs and appointments stay, but detached from the person, because you need them for your accounts.
  • Correction. You edit the data directly in the customer record.
  • Access and portability. There is no export button in the dashboard yet: write to info@ciaoidra.com with the person's phone number and we will prepare a readable copy of their data, in time for you to answer within the month the GDPR gives you.

An honest note about the audio. The recording is not with us: it is at Vapi, and we hold only the link. When you erase a customer we do not just drop the link: we immediately ask Vapi to delete the recording. If Vapi does not answer at that moment, the request stays queued and is retried every night until it goes through. Either way, and regardless of any erasure, every recording is deleted at Vapi within 30 days of the call.

When the relationship ends

When the subscription ends, whether you cancel or payment fails, the data stays for 30 days. That is a grace period: it is there so a cancellation made by mistake, or a change of heart, does not cost you your customer history. After the 30 days we delete the whole account in one go: business, customers, calls, transcripts, summaries, jobs, appointments.

Within that window you have a choice: if you want a copy of the data before it goes, ask at info@ciaoidra.com and we will prepare it; if instead you want everything deleted immediately, without waiting the 30 days, ask and we will do it. There is no button in the dashboard to delete the account yourself yet: the request goes through us.

What survives anyway. The invoices and accounting records for the subscription sit at Stripe and have to be kept for 10 years, as article 2220 of the Italian Civil Code requires. They concern you as our customer, not your callers, and that obligation overrides an erasure request: it is one of the cases where the right to be forgotten gives way to a legal duty.

The retention windows in the table at the top apply regardless, including while the subscription is live: a transcript from fourteen months ago is gone, whether or not you close the account.

Checks and audits

You are entitled to check that we are doing what this document says. On written request to info@ciaoidra.com, and normally no more than once a year, we give you: the current version of this document, the current list of providers with their purposes and locations, a description of the security measures in place, the public references to our providers' documentation and certifications, and written answers to a reasonable data protection questionnaire. If there has been a breach affecting you, or if an authority asks, the once-a-year limit does not apply.

We are a sole trader and the infrastructure belongs to our providers: we cannot grant a physical inspection of their data centres, because it is not ours to grant. If your organisation needs a higher level of assurance than what is described here, let us talk about it before you subscribe, not after.

For anything to do with this agreement — an audit request, an objection to a new provider, a request from one of your customers, a suspected breach — the address is info@ciaoidra.com. We answer in Italian and in English.