1. Data controller
The data controller for the processing of your personal data is:
Communication One i Göteborg AB
Reg. no.: 556779-4135
Spinnerivägen 1, 448 50 Tollered, Sweden
Email: info@leadcaller.com
For questions about the processing of personal data or to exercise your rights, contact us at info@leadcaller.com.
2. Personal data we collect
2.1 Data you provide to us
- Contact details: name, email address, phone number, company name, registration number
- Account data: username, password (encrypted), role and permissions
- Payment details: billing address (payment data is handled by Stripe and never reaches our servers)
- Communication: emails, support tickets and other correspondence with us
- Form data: information you enter in contact, demo or registration forms
2.2 Data we collect automatically
- Technical data: IP address, browser type, operating system, device information, screen resolution
- Usage data: pages visited, clicks, scroll depth, session length, referrer URL
- Cookie data: consent status, session identifiers (see our cookie declaration)
- Geographic data: approximate location based on IP address (country, region)
- Marketing data: UTM parameters, campaign IDs, click IDs from ad platforms (gclid, fbclid etc.)
2.3 Data from the service (for customers)
- Call data: time, duration, phone numbers, call status
- Call content: audio recordings and AI-generated transcriptions (if enabled by the customer)
- CRM data: leads, contacts, deals, activities, notes
- Widget interactions: chat messages, callback requests, form submissions
- Campaign data: outreach, delivery status, open and click statistics
3. Purposes and legal basis
| Purpose | Legal basis | Retention |
|---|---|---|
| Providing and administering the service | Performance of a contract (Art. 6.1b) | Contract term + 12 months |
| Customer communication and support | Performance of a contract (Art. 6.1b) | Contract term + 12 months |
| Invoicing and accounting | Legal obligation (Art. 6.1c) | 7 years (Swedish Accounting Act) |
| Website analytics and improvement | Consent (Art. 6.1a) | 26 months or until consent is withdrawn |
| Marketing and newsletters | Consent (Art. 6.1a) | Until consent is withdrawn |
| Security and misuse protection | Legitimate interest (Art. 6.1f) | 12 months |
| AI services (voice AI, chatbot) | Performance of a contract (Art. 6.1b) | According to the customer's settings |
4. AI and automated decision-making
LeadCaller uses AI technology to provide services such as voice AI, chat assistants and lead scoring. The chat assistant is built on RAG technology (Retrieval-Augmented Generation), where the answers are grounded in the knowledge base and instructions that each customer configures themselves.
- AI-generated calls and answers are based on the customer's configured instructions, knowledge base and scripts.
- Lead scoring and prioritisation are supportive and do not result in decisions with legal effect for individuals.
- Call data and chat transcripts are not used to train the underlying AI models. Data is processed in real time and stored in databases and file storage that are encrypted at rest.
- The AI services are provided by third-party providers (see section 6 on sub-processors).
4.1 Transparency under the EU AI Act (Art. 50)
In accordance with the EU AI Act (Regulation 2024/1689), Article 50, every end user is informed at first interaction that they are communicating with an AI system. In the chat widget this is shown partly through a clear "AI assistant" label on every AI response, and partly through our terms of use, which are accepted before the conversation starts and which state explicitly that the chat is answered by an AI and not by a human.
LeadCaller's AI services are classified under the AI Act as systems with limited risk. The services are not used for biometric identification, emotion recognition, credit scoring or other uses covered by the high-risk provisions (Annex III).
4.2 Automated decision-making (GDPR Art. 22)
In accordance with Article 22 of the GDPR, we do not make decisions that are based solely on automated processing and that produce legal effects or similarly significantly affect you. You always have the right to request human review.
5. Cookies and tracking technologies
We use cookies and similar technologies. Analytics and marketing cookies are activated only after your consent via our cookie banner.
The following third-party services may be activated with your consent:
- Google Tag Manager & Google Analytics — website analytics and conversion measurement
- Google Ads — measures which ads lead to a demo booking or sign-up. We use Google's enhanced conversions: if you enter an email address or phone number in a form, it is sent to Google in hashed form (SHA-256) to link the conversion to the ad. Legal basis: consent to marketing (Art. 6.1a). Recipient: Google, which may process the data in the US (see sections 6 and 7).
- LinkedIn Insight Tag — measures the effect of our ads on LinkedIn. Legal basis: consent to marketing (Art. 6.1a). Recipient: LinkedIn, which may process the data in the US (see sections 6 and 7).
- Meta Pixel (Facebook/Instagram) — conversion measurement and retargeting for ad campaigns
You can change or withdraw your consent at any time via our cookie declaration.
6. Sub-processors and third-party providers
We share personal data with the following categories of recipients, all bound by data processing agreements (DPA):
| Sub-processor | Purpose | Data storage |
|---|---|---|
| Amazon Web Services (AWS) | Infrastructure, servers, databases, storage | EU (Stockholm, eu-north-1) |
| Twilio | Telephony, SMS, call handling | EU/US (DPA + SCC) |
| Stripe | Payment processing | EU/US (DPA + SCC) |
| SendGrid (Twilio) | Email delivery, transactional email | US (DPA + SCC) |
| Anthropic | AI language model (Claude) for voice and chat services | US (DPA + SCC) |
| OpenAI | AI language model, embeddings | US (DPA + SCC) |
| Deepgram | Speech-to-text (voice transcription) | US (DPA + SCC) |
| Sentry | Error monitoring and diagnostics | EU (Germany) |
| Google (GTM/GA) | Website analytics (with consent) | EU/US (DPA + SCC) |
| Google (Google Ads) | Ad measurement and enhanced conversions (with consent) | EU/US (DPA + SCC) |
| Ad measurement via the LinkedIn Insight Tag (with consent) | EU/US (DPA + SCC) | |
| Meta Platforms, Inc. | Conversion tracking and retargeting (with consent) | US (DPA + SCC) |
SCC = the EU Standard Contractual Clauses for transfers to third countries. Where sub-processors process data outside the EU/EEA, we ensure protection through the European Commission's Standard Contractual Clauses (Art. 46.2c GDPR) together with supplementary technical and organisational measures.
7. Transfers to third countries
Primary data storage takes place within the EU (AWS Stockholm). Some sub-processors process data in the US. For transfers outside the EU/EEA we use:
- The EU Standard Contractual Clauses (SCC)
- Technical safeguards (encryption at rest and in transit)
- Assessment of the level of protection in the recipient country (Transfer Impact Assessment)
8. Security measures
We take appropriate technical and organisational measures to protect your data:
- Encryption at rest for our operational databases and file storage
- TLS for all traffic to and from the service
- Role-based access control (RBAC) following the principle of least privilege
- Continuous security monitoring and automatic threat detection
- Automated daily backups within the EU
- Regular security reviews
Read more on our security page.
9. Your rights
Under the GDPR you have the following rights regarding your personal data:
-
Right of access (Art. 15)
You have the right to request a copy of the personal data we process about you.
-
Right to rectification (Art. 16)
You have the right to have inaccurate data corrected without undue delay.
-
Right to erasure (Art. 17)
You have the right to request deletion of your data. When logged in, you can delete your account directly.
-
Right to restriction (Art. 18)
You have the right to request that processing be restricted under certain conditions.
-
Right to data portability (Art. 20)
You have the right to receive your data in a machine-readable format. An export function is available in the account settings.
-
Right to object (Art. 21)
You have the right to object to processing based on legitimate interest or for direct marketing.
-
Right to withdraw consent
You can withdraw your consent at any time. Withdrawal does not affect the lawfulness of earlier processing.
To exercise your rights, contact us at info@leadcaller.com. We will respond to your request within 30 days.
10. Complaints to a supervisory authority
If you believe that our processing of your personal data violates the GDPR, you have the right to lodge a complaint with the Swedish Authority for Privacy Protection (IMY):
Swedish Authority for Privacy Protection (IMY)
Box 8114, 104 20 Stockholm
Phone: +46 8 657 61 00
Website: www.imy.se
11. Data Processing Agreement (DPA)
When you as a customer use the LeadCaller service, we act as a data processor for the personal data processed in the service (e.g. your customers' contact details, call data). We provide a data processing agreement (DPA) to all customers at no additional cost.
Contact us at info@leadcaller.com to request a data processing agreement.
12. Changes to this policy
We may update this privacy policy. For material changes, we will inform you by email or through a notice on our website. The latest version is always available on this page.
Contact us
Questions about how we handle your personal data?