1.Introduction
This Privacy Policy explains how Calleem, established in Malaysia (“Calleem”, “we”, “us”), handles personal data when you visit calleem.tech, use the Calleem dashboard, or call a business that uses Calleem as its AI receptionist.
We do not sell personal data, and we only use it for the purposes described in this policy.
2.Our role: controller and processor
- Account and website data. For data about our customers and website visitors (for example your account details and messages you send us), Calleem is the controller.
- Caller data. When someone calls a business that uses Calleem, that business is the controller of the caller’s personal data and Calleem is its processor. We process caller data only on the business’s instructions and to provide the Service to it. If you called a business and have a question about your data, please contact that business directly; if you contact us, we will pass your request on to it.
3.Data we collect
Account data
Your name, email address, phone number, business name, login credentials and account settings, and records of your plan, minute balance and usage.
Business configuration
The information you give your assistant, such as opening hours, services, prices, staff names, frequently asked questions, greeting messages, booking settings and the phone numbers connected to the Service.
Caller data (processed on behalf of the business)
Caller phone numbers, call recordings, transcripts, AI-generated call summaries, details the caller gives during the call (such as their name and reason for calling), booked appointments, SMS confirmations sent to callers, and call metadata such as date, time and duration.
Website, contact form and chatbot data
Information you submit through our contact form (such as your name, email, business name, phone number and message), messages you send to the chatbot on our website, and basic technical data such as IP address, browser type, device information and server logs.
Payment data
Payments made through our checkout are processed by Stripe. Stripe collects your card details directly. We never see or store your full card number. We receive limited information from Stripe, such as your name, email, billing country, the plan or top-up purchased, amounts and payment status.
Support communications
The content of emails and other messages you send us, and our replies.
4.How we use data
We use personal data to:
- provide the Service: answer calls, book appointments, send SMS confirmations, and show calls, transcripts, summaries and appointments in your dashboard (performance of our contract with you);
- manage your account, minutes, subscriptions and billing (contract, and our legal obligations for tax and accounting);
- answer contact form, chatbot and support requests (our legitimate interest in responding);
- keep the Service secure, prevent fraud and abuse, and fix problems (our legitimate interests);
- improve the Service using usage statistics and feedback (our legitimate interests);
- send you service messages, and product news where you have agreed or where the law allows it. You can unsubscribe from marketing emails at any time;
- comply with legal obligations and respond to lawful requests from authorities.
Caller data is used only to provide and support the Service for the business the call belongs to.
5.Sub-processors and sharing
We use the following service providers (sub-processors) to run Calleem. They process personal data only to provide their services to us and under contracts that protect the data.
- Vapi — Voice AI platform that runs the AI receptionist and processes call audio, recordings and transcripts.
- Twilio — Telephony: phone numbers, call routing and SMS confirmations.
- OpenAI (via Vapi) — Language model that understands callers and generates the assistant’s replies.
- Deepgram (via Vapi) — Speech-to-text transcription of calls.
- ElevenLabs (via Vapi) — Text-to-speech for the assistant’s voice.
- Amazon Web Services — Application hosting, and Amazon Bedrock for the chatbot on our website.
- MongoDB Atlas — Database that stores account data, business settings, call records and appointments.
- Vercel — Hosting of our website and dashboard.
- Stripe — Checkout, card payments, subscriptions and receipts.
We may also share personal data:
- with the business you called, which can see your call details in its dashboard;
- when required by law, or to protect the rights, safety and security of our users, callers, us or others;
- with a buyer or successor if we are involved in a merger, acquisition or sale of assets, who must keep protecting the data in line with this policy.
6.International transfers
We are based in Malaysia, and several of our sub-processors are located in, or process data in, the United States and other countries. These countries may not have the same data protection laws as yours. When we transfer personal data from the European Economic Area, the United Kingdom or Switzerland to other countries, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses, the UK addendum to them, or the EU-US Data Privacy Framework where a provider is certified under it.
7.How long we keep data
- Call recordings, transcripts, summaries and appointments are kept while the business’s account is active and deleted within 90 days after the account is closed, unless the business deletes them earlier.
- Account data is kept while your account is active and deleted within 90 days after it is closed, except for records we must keep longer by law, such as invoices and tax records.
- Contact form, chatbot and support messages are kept for as long as needed to answer and follow up on your request, and then deleted or anonymized.
- Technical logs are kept for a limited period for security and troubleshooting.
8.Security
We protect personal data with technical and organizational measures, including encryption in transit (HTTPS/TLS), authentication for the dashboard, access controls that limit access to people and systems that need it, and choosing providers with strong security practices. No system is completely secure, but if a personal data breach affects you, we will notify you and the relevant authorities as required by law.
9.Your privacy rights
EU, EEA and UK (GDPR)
You have the right to access your personal data, correct it, have it deleted, restrict or object to its processing, receive it in a portable format, and withdraw consent at any time where we rely on consent. You also have the right to complain to your local data protection authority.
California (CCPA/CPRA)
California residents have the right to know what personal information we collect and how we use and disclose it, to request deletion and correction, and not to be discriminated against for exercising these rights. We do not sell personal information or share it for cross-context behavioral advertising. You can use an authorized agent to make a request for you.
How to exercise your rights
Send us a message through our contact form. We may need to verify your identity before acting on a request, and we will reply within the time the law requires (usually within one month under the GDPR and 45 days under the CCPA). If you are a caller, your request is usually best sent to the business you called, as it controls your data; if you contact us, we will forward it.
11.Children
Calleem is a business service and is not directed at children. Accounts are only for people aged 18 or older, and we do not knowingly collect personal data from children for our own purposes. If you believe a child has given us personal data, contact us and we will delete it.
12.Changes to this policy
We may update this Privacy Policy from time to time. We will post the new version on this page and update the “Last updated” date. If the changes are significant, we will also notify customers by email or in the dashboard.
13.Contact
For privacy questions or requests, write to us through our contact form. You can also read our Terms of Service and Refund Policy.