DataCall, Inc. ("DataCall", "we", "us", "our") builds a private-AI workflow platform for regulated industries. Open-source language models (such as Llama and Mistral) run on infrastructure that the customer owns or controls, so the operational data a customer processes through our software — patient records, electronic protected health information (ePHI), privileged matter files, client portfolios, transactions, and similar — stays inside the customer's own environment. In the ordinary course of providing the Service, that data is not sent to DataCall or to any external AI provider. This Privacy Policy explains the limited personal data DataCall itself collects and controls through our public marketing site (datacall.ai) and our tenant-facing Platform App (platform.datacall.ai), the reasons we process it, and your rights under the GDPR, UK GDPR, and CCPA/CPRA and other US state privacy laws.
Last updated. The effective and "Last updated" dates for this Policy appear at the top of this page. Section 19 explains how we signal changes.
1. Overview & Scope
This Policy applies to personal data that DataCall collects and controls about:
- Website visitors and prospects who use our public marketing site at datacall.ai; and
- Platform-account users — the administrators and operators of customer tenants who sign in to the Platform App at platform.datacall.ai.
In this Policy, the "Service" means the DataCall private-AI workflow platform software, the Platform App at platform.datacall.ai, and the marketing site at datacall.ai, collectively. "Platform Account Data" means the account identity, workflow-request prompts, and access/request logs DataCall collects and controls, as described in Section 4. Capitalized terms used but not defined in this Policy — including Customer Data and Outputs — have the meaning given in our Terms of Service.
This Policy does not apply to Customer Workflow Data. Our software is designed so that open-source models run on infrastructure the customer controls, and Customer Workflow Data is created, received, maintained, processed, and stored inside the customer's own environment. In the ordinary course, that data is not transmitted to DataCall and is not routed to any external AI provider (for example, no Anthropic or OpenAI). If you are a patient, client, or other individual whose information a DataCall customer processes through the Service, please direct your privacy requests to that customer, which is the controller of that data; see Section 14.
2. Controller / Processor Roles of the Parties
The privacy obligations for a given set of data depend on who determines the purposes and means of processing it:
- Customer Workflow Data. The customer is the data controller (GDPR / UK GDPR), the covered entity or business associate (HIPAA), and the responsible party (CCPA/CPRA). The customer determines the purposes and means of processing. The customer's own privacy notice — not this Policy — governs its collection and use of that data from its own data subjects, patients, or clients.
- Processing on a customer's behalf. Where DataCall processes personal data on a customer's behalf, DataCall acts as a processor / service provider, and a separate DPA governs that processing.
- ePHI. Where any DataCall-operated component creates, receives, maintains, or transmits ePHI, DataCall acts as a Business Associate under an executed BAA. Absent a signed BAA, the customer must not route ePHI through DataCall-operated components (see Section 16).
- Website & account data. For the Platform Account Data DataCall collects about website visitors and Platform-account holders for its own business purposes — account identity, the prompts a signed-in user submits, access logs, and marketing analytics — DataCall is the controller. This is the data the rest of this Policy describes.
In the ordinary course DataCall has no access to Customer Workflow Data and therefore cannot identify, retrieve, correct, or delete it on an individual's behalf; such requests must be directed to the customer (see Section 14).
Requesting a DPA. Customers in regulated industries that require a Data Processing Agreement to satisfy GDPR Article 28 should contact legal@datacall.ai (or privacy@datacall.ai); DataCall makes a standard Data Processing Agreement, incorporating the Standard Contractual Clauses where applicable, available on request.
3. Who We Are & How to Contact Us
The controller of the personal data described in this Policy is DataCall, Inc., a Delaware corporation, with a registered postal address at 5431 N. East River Rd., Chicago, IL 60656, USA.
For all data-protection inquiries and to exercise your privacy rights, contact us at privacy@datacall.ai. You may also reach us at:
- hello@datacall.ai — general inquiries
- security@datacall.ai — security and incident matters, and BAA requests
- legal@datacall.ai — legal matters and DPA requests
EU and UK representatives; Data Protection Officer.
- EU Representative (GDPR Art. 27): DataCall does not currently offer the Service to, or monitor, individuals in the EEA, and has not appointed an Article 27 representative. We will appoint one before offering the Service in the EEA where Article 27 requires it.
- UK Representative (UK GDPR Art. 27): DataCall does not currently offer the Service to, or monitor, individuals in the UK, and has not appointed a UK representative. We will appoint one before offering the Service in the UK where Article 27 requires it.
- Data Protection Officer (GDPR Art. 37): DataCall has not appointed a statutory Data Protection Officer. For any data-protection question or to exercise your rights, contact privacy@datacall.ai.
4. Personal Data We Collect & Its Sources
We collect only the limited personal data we actually need to run our website and the Platform App (the "Platform Account Data"). Today, that is:
| Category | What it is | Source |
|---|---|---|
| Account identity | Your email address, name, and profile picture, obtained when you sign in with Google OAuth. We receive only the email, name, and profile picture you authorize. | Google (third-party sign-in), at your direction. Your use of Google sign-in is also subject to Google's privacy policy. |
| Session & authentication cookies | dc_sess (a signed, httpOnly session token) and dc_name (your display name). | Set by the Platform App when you sign in. |
| Workflow-request prompts | The text of workflow-request prompts you submit through the Platform App while signed in, stored server-side in a SQLite database. | Directly from you. |
| Request / access logs | IP address, browser user agent, and timestamps of requests. | Automatically collected by the Platform App and our hosting/edge infrastructure (including the ingress edge). |
| Marketing-site data | Your cookie-consent choice (stored in browser localStorage as dc_cookies_v1) and analytics data, collected subject to consent. | Your browser, on the marketing site. |
| Sales / scheduling data | If you book a meeting with us, the contact details you provide. | You, via a HubSpot meeting link (processed by HubSpot). |
What we do not collect through these channels. In the ordinary course, DataCall does not collect or receive Customer Workflow Data — ePHI, patient or client records, privileged files, portfolios, or transaction data — through the website or the Platform App. The workflow-request prompt field is intended for configuration and instructions, not for regulated operational data. Do not paste ePHI, nonpublic personal financial information, privileged matter content, or other regulated operational data into prompt fields, support messages, or other Platform App inputs. Because these inputs are stored on DataCall-operated systems outside your perimeter, BAA-covered ePHI and other regulated operational data should flow only through the in-perimeter workflow path on the customer's own infrastructure — not through the control-plane prompt store — even where a BAA or DPA is in place.
Free-text prompts. Because the workflow-request prompt field is free text, you must not include other people's personal data in it. DataCall handles any personal data that nonetheless appears in prompts under this Policy and, where it acts on a customer's behalf, under the applicable DPA.
Sensitive personal information. DataCall does not collect or use sensitive personal information (as defined by the CPRA) about website visitors or Platform-account holders for any purpose that triggers the right to limit its use; the limit-use right in Section 13 is offered for completeness.
5. Why We Process Data & Our Legal Bases
We process the personal data above only for the purposes below. For individuals protected by the GDPR or UK GDPR, the corresponding Article 6 legal basis is shown.
| Purpose | Data used | GDPR / UK GDPR legal basis |
|---|---|---|
| Provide and secure your Platform account (authenticate you, maintain your session) | Account identity; session cookies | Performance of a contract, Art. 6(1)(b); legitimate interests in security, Art. 6(1)(f) |
| Deliver requested functionality (process and store the prompts you submit) | Workflow-request prompts | Performance of a contract, Art. 6(1)(b) |
| Operate, debug, secure, and protect the Service; prevent fraud and abuse (such handling is not solely automated with legal or similarly significant effects) | Access / request logs | Legitimate interests, Art. 6(1)(f) |
| Measure and improve our marketing site | Analytics and non-essential cookies | Consent, Art. 6(1)(a) |
| Respond to sales inquiries, schedule meetings, and send related B2B communications | Sales / scheduling data | Legitimate interests in B2B outreach, Art. 6(1)(f), or consent where required |
| Bill and settle fees | Account and billing data (handled by Stripe) | Performance of a contract, Art. 6(1)(b); legal obligation, Art. 6(1)(c) |
| Comply with legal obligations (tax, audit, lawful requests) | As applicable | Legal obligation, Art. 6(1)(c) |
Where we rely on legitimate interests, we have weighed those interests against your rights and freedoms. You may object to that processing at any time (see Section 13).
6. How We Disclose Personal Data
We do not sell or share your personal information (see Section 8). We disclose the Platform Account Data we control only as follows:
- To sub-processors and service providers that help us run the website and control plane, each under contract and solely to provide the Service on our behalf for a business purpose (see Section 9).
- To comply with law or valid legal process — for example, in response to a lawful government or regulatory request, subpoena, or court order — where we reasonably believe disclosure is required.
- To establish, exercise, or defend legal claims, to enforce our Terms of Service, and to protect the rights, property, or safety of DataCall, our customers, or others.
- In a business transfer — in connection with a merger, acquisition, financing, reorganization, or sale of assets — in which case the successor will be bound by this Policy or a policy at least as protective.
8. No Sale, No Share, No Model Training
We do not sell or share your personal information. DataCall does not sell personal information, and does not share it for cross-context behavioral advertising, as those terms are defined under the CCPA/CPRA. To the best of our knowledge, DataCall has not sold or shared personal information in the 12 months preceding the "Last updated" date of this Policy. When we disclose data to the sub-processors listed in Section 9, they act under contract solely to provide the Service on our behalf for a business purpose; that disclosure is not a "sale" or "share."
No model training. DataCall does not use Customer Data, including the workflow-request prompts you submit, to train or fine-tune foundation models.
"Data never leaves your perimeter." This statement describes the intended architecture for Customer Workflow Data — open-source models run on infrastructure the customer controls, and in the ordinary course no Customer Workflow Data is transmitted to DataCall or any external AI provider. It describes that design, which depends on the customer's own configuration and use; it is not an unconditional guarantee, and it does not refer to the limited account, prompt, and log data that the Platform App necessarily collects, which is described in this Policy.
9. Sub-Processors & Service Providers
We rely on a small set of service providers to operate our website and control plane. Each processes only the limited control-plane data described in this Policy — not Customer Workflow Data processed inside the customer's perimeter. We require each sub-processor to be bound by a DPA or equivalent processor terms to process data only as instructed and to maintain appropriate safeguards.
| Provider | Role / purpose |
|---|---|
| Google (OAuth / Identity) | Authentication of Platform-account users |
| Google Cloud (Cloud Run) | Hosting and compute for the DataCall-operated control plane |
| ngrok | Ingress / edge tunneling for the Platform App; transits request metadata (IP, user agent) and authenticated traffic |
| Stripe | Billing, payment, and settlement processing |
| HubSpot | Sales-meeting scheduling, CRM, and related B2B communications for prospect outreach |
| Google Workspace (Gmail) | Operational and transactional email (for example, account and security notices) |
We use HashiCorp Vault internally to manage secrets; it is not a recipient of personal data in the ordinary course. Payment-card data is handled by Stripe under its own terms and is not stored by DataCall. We maintain a current list of sub-processors and will provide at least 30 days' advance notice of a new sub-processor that processes Platform Account Data, where an applicable DPA requires it.
10. International Data Transfers
DataCall and its sub-processors (for example, Google Cloud, Stripe, and HubSpot) may process personal data in the United States and other countries. Where we transfer personal data of individuals in the EEA, the UK, or Switzerland to a country without an adequacy determination, and where such safeguards are required, we rely on appropriate safeguards, which may include the European Commission's Standard Contractual Clauses (SCCs) and, for UK data, the UK International Data Transfer Addendum (IDTA) to the SCCs. Where required, we put these mechanisms in place with the relevant sub-processors. Where applicable, we apply supplementary measures such as encryption in transit and at rest and access controls to transferred data.
DataCall does not currently rely on the EU–US Data Privacy Framework; where a cross-border transfer requires safeguards, we rely on the mechanisms described above. You may request a copy of the relevant transfer safeguards by emailing privacy@datacall.ai.
11. Data Retention
We keep personal data only as long as we need it for the purposes described in this Policy or to meet a legal obligation, then delete or anonymize it.
- Account identity (email, name, picture) — retained while your account is active and for up to ninety (90) days after closure, unless a longer period is required by law.
- Session cookies (
dc_sess,dc_name) — retained for the session / cookie lifetime, then expire. - Workflow-request prompts (SQLite) — retained for as long as needed to provide the Service, then deleted; the customer controls retention where applicable.
- Access / request logs (IP, user agent) — retained for a limited security and operations window, typically up to ninety (90) days.
- Billing records — retained as required for tax, audit, and legal obligations, typically up to seven (7) years.
You may request export or deletion of the limited Platform Account Data on termination, subject to legal-retention requirements and routine backups, as further described in our Terms of Service. Because Customer Workflow Data resides in the customer's environment, the customer controls its export, retention, and deletion.
12. Security of Processing
We use technical and organizational measures designed to protect the personal data we control, including:
- Encryption in transit and at rest for data DataCall controls;
- Secrets managed in HashiCorp Vault, and signed httpOnly session cookies to protect authentication tokens;
- Role-based, least-privilege access to systems holding personal data; and
- Access and request logging on the DataCall-operated control plane to support monitoring and incident response.
Separately, each workflow keeps an encrypted audit trail that operates within the customer's own environment under the customer's control; it is part of the customer-side software and is not data that DataCall holds or operates as part of its control plane.
No system is perfectly secure, and we cannot guarantee absolute security. Our architecture is designed to support a customer's security obligations and can be configured to help a customer meet them; we do not assert, as an absolute, that the Service is SOC 2 certified or that it makes any customer HIPAA-, FINRA-, or otherwise compliant. The customer is responsible for securing the infrastructure where its Customer Workflow Data is processed.
13. Your Privacy Rights
Depending on where you live, you may have some or all of the following rights over the personal data DataCall controls about you.
GDPR & UK GDPR
- Access, rectification, and erasure of your personal data;
- Restriction of, and objection to, processing — including objecting to processing based on legitimate interests and to direct marketing;
- Data portability;
- Withdrawal of consent at any time, without affecting prior lawful processing; and
- The right to lodge a complaint with your supervisory authority (your EU Data Protection Authority or the UK ICO). This right is in addition to contacting us, and you do not have to exhaust our process first.
For the website and Platform Account Data DataCall controls, we do not use solely-automated processing that produces legal or similarly significant effects about you. Outputs generated within a customer's workflow run within the customer's environment under the customer's control and require human review by the customer, which is responsible for any decision-making.
CCPA / CPRA (California)
- Right to know and access the personal information we have collected;
- Right to delete and to correct your personal information;
- Right to opt out of the sale or sharing of personal information — note that we do not sell or share it;
- Right to limit the use of sensitive personal information; and
- Right not to be discriminated against for exercising your rights.
Other US state privacy laws
We honor analogous rights, where applicable, under other US state privacy laws, including the Virginia VCDPA, Colorado CPA, Connecticut CTDPA, Utah UCPA, and Texas TDPSA, and we will respond to verified requests as those laws require.
How to exercise your rights
Email privacy@datacall.ai. We may need to verify your identity before acting. An authorized agent may submit a request on your behalf; for agent requests, we may require proof of the agent's authority (for example, written, signed permission) and may verify your identity directly. We aim to respond within the time limits set by applicable law, and where the law permits an extension for complex or numerous requests, we may take it and will tell you. Some rights may be limited by law. For Customer Workflow Data, please contact the relevant customer, which is the controller (see Section 14).
14. Individuals Whose Data a Customer Processes
If you are a patient, client, or other individual whose information a DataCall customer processes through the Service, the customer — not DataCall — is the controller / covered entity / responsible party for that Customer Workflow Data. Please direct any request to access, correct, delete, or otherwise exercise rights over that data to the relevant customer.
In the ordinary course DataCall has no access to Customer Workflow Data and therefore cannot identify, retrieve, correct, or delete it on an individual's behalf. Where DataCall acts as a processor or Business Associate, it assists the customer in responding to such requests as required by the applicable DPA or BAA.
15. Global Privacy Control & Do-Not-Track
DataCall does not sell or share personal information or use it for cross-context behavioral advertising, so an opt-out preference signal such as the Global Privacy Control (GPC) has no "sale" or "share" to suppress. Where we deploy non-essential analytics on our marketing site, those cookies are set only after you consent, and you can withdraw consent at any time (see Section 7); where technically feasible, we also treat a recognized GPC signal as a request not to set non-essential cookies. There is no industry-standard response to the browser "Do Not Track" (DNT) signal, and we do not currently respond to DNT signals.
16. Healthcare Data & ePHI — Governed by a BAA
ePHI is processed within the customer's perimeter. Where any DataCall-operated component creates, receives, maintains, or transmits ePHI on a customer's behalf, it does so only under an executed Business Associate Agreement (BAA). The BAA — not this Privacy Policy — governs DataCall's handling of ePHI, and it controls over any conflicting terms as to that ePHI.
Absent a signed BAA, customers must not route ePHI through DataCall-operated components, including workflow-request prompts to the Platform App and support channels. We sign BAAs; contact security@datacall.ai to arrange one. The Service is designed to support, and can be configured to help, covered entities and business associates meet their HIPAA and HITECH obligations; we make no representation that the Service alone makes a customer HIPAA-compliant. Determinations and consents under 42 CFR Part 2 and obligations under HITECH remain the customer's responsibility. Patients and individuals seeking to exercise rights over their health information should contact the covered-entity customer; DataCall assists as Business Associate.
17. Children's Privacy
The Service and website are intended for business and organizational use and are not directed to, and we do not knowingly collect personal data from, anyone under 18. If we learn that we have collected such data, we will delete it. A parent or guardian with concerns may contact privacy@datacall.ai.
18. Personal-Data Breach Notification
Where DataCall acts as a controller and a personal-data breach occurs, we will notify the relevant supervisory authority and affected individuals as and when required by applicable law, including the GDPR/UK GDPR (generally within 72 hours of becoming aware, where feasible) and applicable US state data-breach-notification laws.
Where DataCall acts as a processor or Business Associate, we will notify the affected customer without undue delay in accordance with the applicable DPA or BAA, and the customer — as controller or covered entity — leads regulatory and individual notifications. For ePHI, the BAA's HIPAA breach-notification terms control. Report a suspected security incident to security@datacall.ai.
19. Changes to This Policy
We may update this Policy from time to time by posting the revised version with a new "Last updated" date at the top of this page. Where required, we will communicate material changes by reasonable means, such as an in-product notice or an email to account holders. Your continued use of the website or Platform App after the effective date constitutes acknowledgment of the updated Policy, subject to any consent that applicable law requires for new processing.