Privacy Policy
This policy explains how CallSmarter processes the personal data of visitors to callsmarter.ai and of those who request a pilot through the website form, in accordance with Regulation (EU) 2016/679 (GDPR) and Spanish Organic Law 3/2018 on the Protection of Personal Data and Guarantee of Digital Rights (LOPDGDD). Data that CallSmarter processes on behalf of its customers when providing the service is governed by the Data Processing Agreement.
Data controller
- Controller: Atiempo.Me SL (trade name: CallSmarter)
- Tax ID (NIF): B56542111
- Address: Calle Timón 58, Centro Comercial Torrequebrada, Oficina 17, 29631 Torrequebrada, España
- Data protection contact: [email protected]
You may send any query about the processing of your data or the exercise of your rights to this address.
Data we process
“Request a pilot” form. When you submit a request, we process:
- your name, business email address and company name;
- the approximate size of your contact database (as a range);
- your telephone number, only if you choose to provide it (optional);
- the language of the page from which you submit the request;
- the tick in the acceptance box and the version of this policy in force at that time (identified by the date of its wording);
- the date and time of receipt, recorded by our server;
- any UTM parameters present in the page address, if the link you followed included them (utm_source, utm_medium, utm_campaign, utm_term, utm_content);
- your browser identifier (user-agent).
The form also includes a hidden anti-spam control field (honeypot) that people do not fill in and that contains no personal data.
IP address. When you submit the form, your IP address is used transiently, in the server’s memory, to limit the submission rate and prevent spam, within a window of up to one hour. The IP address is not stored with the request.
Server technical logs. Like any web server, ours generates technical logs (date and time, requested path, IP address and response code), which are used for security and diagnostic purposes.
What we do not do
The callsmarter.ai website does not use its own cookies, analytics tools or advertising pixels, and does not store form data in your browser (neither in localStorage nor in sessionStorage). Details are set out in the Cookie Policy.
We do not sell or disclose your data for commercial purposes, and we do not send you marketing communications or newsletters.
Purposes and legal bases
| Purpose | Data | Legal basis |
|---|---|---|
| Handling your pilot request and communicating with you about it (assessment, proposal and organisation of the pilot) | Form data | Steps taken at the request of the data subject prior to entering into a contract (Art. 6(1)(b) GDPR); as regards the contact details of persons acting on behalf of a company, legitimate interest (Art. 6(1)(f) GDPR and Art. 19 LOPDGDD) |
| Recording acceptance of this policy | Box tick, policy version, date and time | Consent (Art. 6(1)(a) GDPR) and the duty to be able to demonstrate it (Art. 7(1) GDPR) |
| Knowing the channel through which the request arrived and detecting automated submissions | UTM parameters, user-agent | Legitimate interest (Art. 6(1)(f) GDPR) |
| Ensuring website security, preventing spam and diagnosing incidents | IP address (transient use), server technical logs | Legitimate interest (Art. 6(1)(f) GDPR) |
By ticking the box in the form, you confirm that you have read this policy and consent to the processing of your data in order to respond to your request. You may withdraw your consent at any time, without affecting the lawfulness of processing carried out before its withdrawal.
Where we rely on legitimate interest, we have assessed that the processing is limited, is to be expected in a business-to-business relationship and is not overridden by your interests or rights; you may object at any time and request information about that assessment.
We do not use form data to send marketing communications. Should we wish to do so in the future, we would ask for your specific and separate consent, in accordance with Article 21 of the LSSI-CE.
Retention periods
- Pilot requests: 12 months from receipt, if no contract is concluded. If a contract is concluded, the data will be kept for the duration of the contractual relationship and thereafter for the limitation periods of any claims that may arise from it.
- Server technical logs: [period — e.g. 30 days, to be confirmed].
- IP address for rate limiting: in memory only, within a window of up to one hour.
Once these periods have expired, the data is deleted or anonymised. Where applicable, data will be kept blocked in accordance with Article 32 LOPDGDD, available solely to judges and courts, the Public Prosecutor and the competent authorities, for the limitation period of any potential liabilities.
Recipients and processors
To operate the website and handle requests, we use the following providers, which act as processors or provide technical services:
- Hosting (virtual private server): [hosting provider — to be provided], [server location — to be provided]. Hosts the server and the database in which requests are stored.
- Cloudflare, Inc.: content delivery network (CDN), DNS, attack protection and TLS encryption. Processes the IP address and technical data of requests to the website.
- Telegram: internal notifications to our team about new requests. The notification contains only the company name, database size range, language and request number; it does not include your name, email address or telephone number.
To provide the platform service to our customers — not in relation to website visitors — we also use OpenAI (voice model, transcription and call analysis), Octella (telephony and SIP; region: [region — to be provided]) and NOWPayments (cryptocurrency balance top-ups). Details are available in the Data Processing Agreement.
We do not sell your data. We will only disclose it to public authorities, judges or courts where there is a legal obligation to do so.
International transfers
Some providers (Cloudflare, OpenAI, Telegram and NOWPayments) may process data outside the European Economic Area (EEA). In such cases, the transfer is based on the safeguards of Chapter V GDPR (Arts. 44 to 49): an adequacy decision of the European Commission, where applicable (including the EU-U.S. Data Privacy Framework for entities participating in it), or, failing that, the standard contractual clauses approved by the European Commission (Art. 46(2)(c) GDPR), together with any appropriate supplementary measures.
You may request information about the applicable safeguards and obtain a copy of them by writing to [email protected].
Your rights
You may at any time exercise your rights of access, rectification, erasure, restriction of processing, data portability and objection, and withdraw your consent, without affecting the lawfulness of processing prior to its withdrawal.
To exercise them, write to [email protected] stating the right you wish to exercise and details that allow us to identify you (for example, the email address with which you submitted the request). We will only ask for additional information to confirm your identity where we have reasonable doubts about it.
We will respond within one month of receipt of your request. That period may be extended by two further months where necessary, taking into account the complexity and number of requests, in which case we will inform you within the first month (Art. 12(3) GDPR).
If you consider that the processing of your data does not comply with the law, you may lodge a complaint with the Spanish Data Protection Agency (www.aepd.es).
Automated decision-making
We do not take decisions based solely on automated processing, including profiling, that produce legal effects concerning website visitors or similarly significantly affect them (Art. 22 GDPR).
Mandatory data
The fields marked as mandatory in the form are necessary to handle your request; if they are not provided, we will not be able to respond. The telephone number is optional.
Security
Data is transmitted encrypted via HTTPS/TLS. Only authorised staff can access requests, through a dashboard protected by two-factor authentication and role-based permissions; actions performed in the dashboard are recorded in an activity log.
Minors
The service is aimed at businesses and professionals and is not intended for persons under 14 years of age (Art. 7 LOPDGDD). We do not knowingly process data of persons under that age.
Changes to this policy
We may update this policy to reflect changes in the law or in our processing. Each new version is published on this page with its date. The version accepted when submitting the form is stored with each request.
