Security & data protection

How we protect your data and your customers' data.

Security and data protection are built into Leadcaller, not bolted on afterwards. This page describes how we protect your data and your customers' data, from infrastructure to your rights under the GDPR.

Infrastructure and encryption

Leadcaller runs on AWS in the EU (Stockholm). All traffic to and from the service is encrypted over HTTPS/TLS. Access tokens are encrypted with keys in AWS KMS, and our operational databases and uploaded files are encrypted at rest.

Access and data isolation

Each customer's data is logically isolated per account. Internal views and APIs require login and the right permissions. Access is governed by roles, and a logged-in user can only reach their own company's data. Sensitive administrative actions are logged for traceability.

GDPR and your rights

As a data processor, we help you comply with the GDPR:

  • Access and portability: export leads and data whenever you want.
  • Erasure: if you delete a customer, the associated personal data is removed.
  • Data location: data is stored in AWS data centres in Stockholm. Some sub-processors, such as AI providers, may process data outside the EU, under standard contractual clauses (see the privacy policy).

Some data is kept for as long as the law requires, for example invoicing records under the Swedish Accounting Act.

AI transparency

Where AI is used towards end users, in chat and in voice agents, we say so clearly, in line with the EU AI Act (Article 50). Nobody is led to believe they are talking to a human.

Security work

Security is an ongoing process, not a one-off effort:

  • Threat modelling: we model and review the attack surface as we build.
  • Monitoring: errors and anomalies are captured in real time.
  • Backups: the database is backed up regularly and automatically, with protection against accidental deletion.
  • Reviewed codebase: automated security checks run in our CI pipeline on every change.