Privacy Policy
Last updated: July 28, 2026
Who we are
PhoneMyAgent is operated by CodeShant Technologies (UDYAM registration UDYAM-BR-26-0188408) ("we", "us"). We provide an AI phone-agent service for businesses, acting as the data controller for account information and as a data processor for the call content our customers (tenants) handle through the service. For any privacy question or to exercise your rights, contact [email protected].
Data we collect
- Account data: your email address and business (tenant) name. We use passwordless login, so we never store a password.
- Google sign-in data: only if you choose to sign in with Google. Google confirms your email address to us and gives us a stable identifier for your Google account, which we store so we recognise you next time. We receive nothing else from Google, and we cannot read or change anything in your Google account.
- Call data: the caller's phone number, call recordings where the tenant has enabled recording, transcripts, and AI-generated summaries.
- Call management data: names the business saves for its callers, tags it puts on calls, and internal notes its team writes about a call.
- Knowledge data: documents you upload and the content of URLs you ask us to index for your agent.
- Customer records: spreadsheets a business imports so its agent can answer one caller about their own order, booking or account. The business chooses what is in them; they usually hold a customer's name, phone number, a reference such as an order number, and the details of that order. Each row is only ever read back to the caller it belongs to, and the business can delete a whole table, and every row in it, at any time.
- Usage and billing records: call minutes, plan, and payment status.
- Technical logs: limited server logs used for security, debugging, and abuse prevention.
Lawful bases for processing
Where we decide why and how data is processed (account, billing, and security data), we rely on:
- Performance of a contract: to deliver the service you sign up for.
- Legitimate interests: to keep the service secure and prevent abuse.
Call content is different. For calls, recordings, and transcripts, the business you called is the controller: it decides whether to record, what its agent says, and how long to keep it. We process that content on its instructions as its processor, under our data processing agreement, and the lawful basis for it is that business's to choose and to state. If your call was recorded and you want it erased, the fastest route is the business you called; you can also contact us and we will pass it on and support them in acting on it.
Call recording and AI disclosure
Before the agent begins speaking, callers hear a spoken disclosure that they are talking to an AI assistant and that the call may be recorded. This is on by default for every agent. It is a setting the business that answers your call controls, and they may reword it or switch it off, so the exact wording you hear is theirs. Whether a call is recorded at all is also their choice, as is how long recordings are kept.
Recordings and transcripts are stored on our infrastructure and are deleted when the business closes its account.
Subprocessors
We rely on the following subprocessors to run the service. We update this list before adding a new one, and business customers are notified 30 days in advance under the data processing agreement.
| Subprocessor | Purpose | Region |
|---|
| OpenAI | Speech processing and AI responses | United States |
| Twilio | Phone numbers and call carriage, including caller numbers | United States / EU |
| SendGrid | Transactional email | United States |
| Stripe | Card payments and subscriptions | United States / EU |
| Contabo | Server hosting and data storage | Germany (EU) |
| Cloudflare | Website network, DNS, security, and cookieless page-view statistics | United States / EU edge |
Data retention
We keep account data for as long as the account is active. Call recordings and transcripts are kept for the retention window the business configures.
When a business closes its account, we erase its people and its callers straight away: the user accounts, sign-in tokens, calls, transcripts, caller numbers and saved caller names, tags and notes, the recordings on disk, uploaded documents, the customer records it imported from spreadsheets, and the credentials it had stored with us.
Two things deliberately survive. We keep the invoices and the usage totals they are based on, because tax law requires us to keep them, and those totals contain no caller and no call. We also keep the business name on the closed account, because an invoice has to say who it was issued to. Nothing else is retained.
Your rights under the GDPR
If you are in the EU/EEA or UK, you have the right to:
- Access the personal data we hold about you.
- Rectification of inaccurate or incomplete data.
- Erasure of your data ("right to be forgotten").
- Restriction of processing in certain circumstances.
- Portability of the data you provided, in a machine-readable format.
- Objection to processing based on legitimate interests.
To exercise any of these, email [email protected]. We respond within one month. You also have the right to lodge a complaint with your local data protection supervisory authority.
If you were a caller rather than a customer, these rights are real but the business you called holds them, not us: it decides what happens to its calls. Write to us anyway if that is easier and we will identify the business, pass your request on, and act on their instruction to erase it. We will not hand you their records ourselves, because they are not ours to give.
International transfers, cookies, analytics, and changes
International transfers. Your call is answered from servers in the European Union, but the speech itself is not processed there. Call audio and the resulting transcript are processed by OpenAI in the United States. We contract for that service with OpenAI Ireland Limited, so our own agreement sits inside the EEA, and the onward transfer to the United States takes place under OpenAI's data processing terms and transfer mechanisms. Where we engage a subprocessor outside the EEA directly, we put Standard Contractual Clauses or another Article 46 mechanism in place. Where a European processing option becomes available for these services, we will update this page.
Cookies. The public site sets one cookie, pma_lang, which remembers the language you picked. The dashboard stores a session token to keep you signed in. Each exists only to do something you asked for, so neither needs your consent. We use no advertising cookies and no third-party tracking cookies.
Analytics. We use Cloudflare Web Analytics to count page views and see which pages are worth keeping. It stores nothing in your browser, no cookie and no local storage, it does not fingerprint your device, and it cannot follow you to other websites. It holds no identifier for you at all: a "visit" is simply a page view that arrived from somewhere else. Because nothing is stored on or read from your device, there is no consent banner to click. Cloudflare already carries every request to this site as our network provider, so this adds no new recipient of your data.
Changes. We may update this policy; material changes will be reflected in the "Last updated" date above.