Privacy Policy
Last updated: August 26, 2026
1. Data Controller
ARIM Technologies S.R.L. (“ARIM”, “we”, “our”, or “us”), registered in Romania, is the data controller responsible for personal data processed in connection with the ARIM Call Center service (“Service”) available at arimcallcenter.com and app.arimcallcenter.com.
Contact: [email protected] — bd. Iuliu Maniu, nr. 17, bl. C1, sc. A, et. 4, ap. 20, Deva, Hunedoara, România.
2. Data We Collect
Account data
- Name and email address provided when you register, plus time zone or locale preferences that you provide or that we infer for workspace configuration.
- Hashed one-time passwords (OTPs) used for email-based authentication — these are deleted after verification.
- Session tokens, stored server-side and used to maintain your authenticated session.
Workspace configuration
- AI agent settings: name, greeting message, system prompt, and knowledge base documents you upload.
- Phone number configuration used to connect inbound calls to your agent, including any free Romanian national number allocated by ARIM, bring-your-own Telnyx/SIP settings, and allowed notification or redirect destinations.
- Knowledge base documents (PDFs) uploaded by you, stored in our secure object storage.
- OAuth tokens for connected Google and Microsoft accounts (access tokens, refresh tokens, granted scopes, account email). These tokens are encrypted at rest using AES-256-GCM.
- Provider API credentials (such as your Telnyx API key) when you choose to connect your own SIP number. These credentials are encrypted at rest using AES-256-GCM and are used only to configure inbound SIP routing and permitted signaling IPs on your behalf.
Calendar integration data
When you connect Google Calendar or Microsoft Outlook, the agent can read calendar availability and manage events (create, modify, delete) on your behalf. We access:
- Calendar list (names and IDs) — to show you which calendars are available for selection.
- Event data in selected calendars — to check free/busy status and create bookings.
- We do not read event titles, descriptions, or attendee lists unless necessary to create or update a booking.
Spreadsheet integration data
When you connect Google Sheets or Microsoft Excel, the agent can read and manage rows (add, update, delete) with call data. We access:
- Spreadsheet / workbook list (names and IDs) — to show you which files are available for selection.
- Selected spreadsheets / workbooks — to read and manage rows containing call metadata (date, caller number, duration, agent name).
- We do not read existing sheet contents beyond what is necessary to manage rows.
Call data
- Call metadata: agent involved, caller and callee numbers, start time, duration, and language.
- Call recordings (audio) of conversations handled by your agents, stored in our secure object storage.
- Transcripts of those recordings, used for review and analytics.
- Actions the agent performed during the call, such as calendar look-ups, appointment bookings, email notifications, spreadsheet updates, and call redirects where enabled.
- Browser voice demo data, including selected language, temporary session identifiers, microphone audio while the demo is active, and diagnostic connection events. The demo is intended for product testing only and should not be used to submit sensitive personal data.
Billing data
- Subscription identifiers, plan status, and renewal date received from our payment provider (Polar).
- Usage counters: number of agents, monthly call volume, call duration, and billable seconds or minutes for usage-based plans.
- Referral source or affiliate code provided during signup, and Affonso referral identifiers when marketing cookies are accepted.
Technical data
- Server-side request logs (IP address, user agent, response status) retained for security and abuse prevention.
- Diagnostic logs from the voice processing system and browser voice demo — these do not contain stored call audio unless explicitly shown as a recording in your dashboard.
AI and voice processing
Agent prompts, call context, transcripts, knowledge-base excerpts, and tool results may be sent to OpenAI's GPT-4o mini model to generate agent replies and decide which configured business actions to perform. For Romanian, English, Spanish, and other local voice configurations, speech-to-text and text-to-speech run on ARIM-managed infrastructure using local models. For Filipino/Tagalog, available only on eligible pay-as-you-go configurations, microphone or call audio and generated text are sent to Google Cloud Speech-to-Text and Google Cloud Text-to-Speech to provide recognition and synthetic voice output. For Albanian, available only on eligible pay-as-you-go configurations, microphone or call audio is sent to Google Cloud Speech-to-Text and generated text is sent to OpenAI text-to-speech for synthetic voice output. Audio snippets are processed only as needed to provide the voice session and are not retained longer than the associated call recording, unless a shorter transient processing period applies to browser demos.
3. How We Use Your Data
- To create and manage your workspace and authenticate users.
- To run your AI phone agent: routing calls, answering questions from your knowledge base, booking appointments, and producing recordings and transcripts.
- To read availability and manage events in connected Google or Microsoft calendars when a caller requests an appointment.
- To read and manage rows containing call metadata in connected Google Sheets or Microsoft Excel files for your record-keeping.
- To send email notifications and perform live call redirects to destinations you configure, where those features are supported for your number setup.
- To operate the browser voice demo and create temporary LiveKit voice-test sessions.
- To enforce subscription limits and to bill the correct fixed or usage-based plan.
- To attribute partner referrals and administer our affiliate program.
- To send transactional emails such as OTP codes and subscription notifications.
- To display call activity, recordings, transcripts, and usage metrics in your dashboard.
- To detect, investigate, and prevent fraudulent or abusive use of the Service.
- To comply with legal obligations applicable to ARIM.
4. AI Training & Anonymised Data
By default, we do not use your data for AI training. Your call recordings, transcripts, and knowledge base documents are never used by ARIM to train or improve AI models unless you explicitly opt in. OpenAI API data is not used by OpenAI to train its models unless the API customer explicitly opts in, and Google Cloud Speech-to-Text data is not used by Google to improve its services unless data logging is explicitly enabled.
If you enable AI training consent in your account settings:
- We may use anonymised call data — stripped of personal identifiers such as names, phone numbers, and precise timestamps — to improve ARIM-operated speech recognition, text-to-speech, routing, and conversation-quality systems.
- Anonymisation is performed before any data is used for training purposes.
- You can withdraw your consent at any time from your account settings. We will cease using your data for training within 30 days of withdrawal.
- Withdrawing consent does not affect the lawfulness of processing that occurred before the withdrawal.
5. Legal Basis for Processing (GDPR)
We process your personal data on the following legal bases under the General Data Protection Regulation (EU) 2016/679 (“GDPR”):
- Performance of a contract (Art. 6(1)(b)): processing necessary to provide the Service you have registered for, including agent operation, call handling, and account management.
- Legitimate interests (Art. 6(1)(f)): maintaining service security, preventing abuse, and aggregated internal analytics to improve the Service.
- Legal obligation (Art. 6(1)(c)): retaining certain records where required by Romanian or EU law.
- Consent (Art. 6(1)(a)): where we explicitly ask for your consent (for example, AI training consent, marketing/tracking cookies, or when you connect a Google or Microsoft integration via OAuth).
6. Role Regarding Call Participants
When your agents handle calls with third parties (for example, your customers), the personal data of those third parties (voice audio, transcripts, names, phone numbers, and any information they share during the call) is processed by ARIM as a data processor on your behalf. You are the controller for that data and are responsible for the lawful basis and for informing call participants that the call may be recorded and that they are speaking with an AI agent.
By using the Service you instruct ARIM to process this data solely to provide the Service, in accordance with these terms and our Terms of Use.
A Data Processing Agreement (DPA) is available upon request at [email protected].
7. Data Retention
- Account data (name, email, time zone): retained for the lifetime of your account. Deleted within 30 days after account deletion.
- Session tokens: deleted upon logout or expiry.
- OTP codes: deleted immediately after successful verification or upon expiry (typically 10 minutes).
- Agent configuration and knowledge base documents: retained for as long as the workspace is active. Deleted within 30 days after workspace deletion.
- Free ARIM-provided phone numbers: released immediately when the subscription ends or is cancelled; associated records are deleted within 30 days of release.
- OAuth tokens for Google/Microsoft calendars: retained while the integration is connected. Revoked and deleted when you disconnect the integration or delete your workspace.
- Provider API credentials (for example, Telnyx API keys): retained only while the connection is active. Deleted immediately when you disconnect the provider or remove the API key, and within 30 days after account deletion.
- Call recordings and transcripts: retained for up to 90 days by default, then permanently deleted unless a longer retention is contractually agreed.
- Browser voice demo session data: processed transiently to provide the demo and retained only in diagnostic logs needed for security, abuse prevention, and troubleshooting.
- Call metadata (logs): retained for up to 12 months for billing verification and dispute resolution, then permanently deleted.
- Server access logs: retained for up to 90 days for security purposes.
- Referral source and affiliate attribution records: retained while your account or subscription exists, and for the period needed for commission reconciliation and dispute resolution.
- Billing identifiers from Polar: retained for the duration required by applicable accounting and tax law (typically 5–10 years in Romania).
8. Third-Party Service Providers
We share data with the following categories of third-party processors where necessary to deliver the Service:
Polar (Polar Software Inc.)
Our payment, subscription, and usage-billing provider. When you subscribe to a paid plan or choose usage-based billing, Polar processes your payment card data and billing information as an independent data controller. Polar is subject to its own Privacy Policy. We receive subscription status identifiers and a customer ID from Polar, and we may send metered usage events such as billable call seconds for invoicing.
AI and voice providers
To produce agent responses we send relevant prompts, conversation context, transcript text, knowledge-base excerpts, and tool results to OpenAI's GPT-4o mini model. For most voice configurations, speech-to-text and text-to-speech are processed on ARIM-managed infrastructure using local models. For Filipino/Tagalog, we send audio and generated text to Google Cloud Speech-to-Text and Google Cloud Text-to-Speech. For Albanian, we send audio to Google Cloud Speech-to-Text and generated text to OpenAI text-to-speech. These providers act as processors or sub-processors under their applicable business, cloud, service, and data processing terms.
Google & Microsoft (calendar and spreadsheet integrations)
When you connect a Google or Microsoft account, we exchange OAuth tokens with that provider and perform operations strictly within the scopes you granted. Tokens are stored encrypted at rest using AES-256-GCM and are revoked when you disconnect the integration or delete your workspace.
Google Calendar scopes: https://www.googleapis.com/auth/calendar.readonly (list calendars), https://www.googleapis.com/auth/calendar.events (manage events), openid, email, profile.
Google Sheets scopes: https://www.googleapis.com/auth/drive.file (access spreadsheets you select via Google Drive Picker), openid, email, profile.
Microsoft Outlook scopes: Calendars.ReadWrite, offline_access, openid, email, profile.
Microsoft Excel scopes: Files.ReadWrite, Sites.Read.All, offline_access, openid, email, profile.
We do not use Google or Microsoft user data for advertising, sale, or training AI models. We access only the minimum data necessary to provide the calendar and spreadsheet features you activate.
Phone carriers and number providers
The voice connection between callers and your agent is carried by the phone service you configure.
Bring your own Telnyx number. If you connect a number from your own Telnyx account, you provide your Telnyx API key so the Service can configure the SIP connection, whitelist ARIM’s signaling IPs, assign outbound voice profile credentials for call transfer and redirection, and assign the number to that connection. Your API key is encrypted at rest using AES-256-GCM and is only used to manage that connection. Telnyx remains an independent controller for the call signaling and media that traverse its network.
Free ARIM-provided Romanian number. If ARIM allocates a free Romanian national number to your workspace, the number is provisioned through ARIM’s Telnyx account and remains under ARIM’s contractual relationship with Telnyx; ARIM acts as the data controller for the configuration data associated with that number.
Email delivery provider
A transactional email provider is used to deliver OTP codes and account notifications. Your email address is transmitted to this provider solely for delivery purposes. The provider acts as a data processor under a data processing agreement with ARIM.
Meta Platforms Technologies, LLC (Meta Conversions API)
When you consent to marketing cookies, we send conversion event data to Meta using the Conversions API. The data includes SHA-256 hashed identifiers (email, internal user ID) and may include first-party click/browser identifiers. No raw personal data is transmitted. Meta acts as an independent data controller for the data it receives and is subject to its own Privacy Policy.
Affonso (ZASolution)
Our affiliate and referral tracking provider. Affonso is loaded in consent mode. Before marketing consent, it must not set the full referral cookie and may use URL-based continuity parameters for privacy-preserving attribution. When you consent to marketing cookies, Affonso may set a first-party referral cookie and process referral identifiers, click metadata, signup or checkout attribution, and subscription attribution data to calculate partner commissions and prevent affiliate fraud. Affonso acts as our processor for this tracking data and is subject to its own Privacy Policy.
Cloud infrastructure provider
The Service is hosted on cloud infrastructure. Your data — including the database, recordings, transcripts, and knowledge base documents — is stored on servers located within the European Economic Area (EEA), or in countries that provide an adequate level of data protection as recognised by the European Commission. When OpenAI or Google Cloud is used to provide AI, speech recognition, or text-to-speech processing, relevant inputs and outputs may be processed in regions made available by those providers under their applicable service terms.
We do not sell, rent, or share your personal data with third parties for their own marketing purposes.
9. Google API Services User Data Policy
ARIM's use and transfer of information received from Google APIs for Google Calendar, Google Sheets, and Google Cloud Speech/Text-to-Speech adheres to the Google API Services User Data Policy, including the Limited Use requirements where they apply. Specifically:
- We use Google user data only to provide and maintain the calendar, spreadsheet, Filipino/Tagalog speech recognition, Filipino/Tagalog text-to-speech, and Albanian speech recognition features you request.
- We do not sell Google user data to third parties.
- We do not use Google user data for advertising purposes.
- We do not transfer Google user data to third parties except as necessary to provide the Service (for example, storing encrypted tokens in our database or routing Filipino/Tagalog or Albanian speech requests through Google Cloud).
- Human reviewers do not access Google user data unless required for technical support with your explicit consent.
10. International Data Transfers
Where personal data is transferred outside the EEA (for example, to Polar, OpenAI, Google, Microsoft, or another infrastructure or AI provider), we ensure appropriate safeguards are in place, such as Standard Contractual Clauses (SCCs) approved by the European Commission, or we rely on an adequacy decision where applicable.
11. Security
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, accidental loss, destruction, or disclosure. These include:
- All data in transit is encrypted using TLS.
- Database access is restricted to authorised systems and workspaces are logically isolated.
- Knowledge base files and call recordings are stored in object storage with access restricted to the workspace that owns them.
- OAuth tokens are stored encrypted and revoked on disconnect.
- Provider API credentials (such as Telnyx API keys) are encrypted at rest using AES-256-GCM.
No method of transmission or storage is 100% secure. If you become aware of a security vulnerability affecting the Service, please disclose it responsibly at [email protected].
12. Your Rights Under GDPR
As a data subject under the GDPR, you have the following rights regarding your personal data:
- Right of access (Art. 15): request a copy of the personal data we hold about you.
- Right to rectification (Art. 16): request correction of inaccurate or incomplete data.
- Right to erasure (Art. 17): request deletion of your personal data (“right to be forgotten”), subject to legal retention obligations.
- Right to restriction of processing (Art. 18): request that we restrict processing of your data in certain circumstances.
- Right to data portability (Art. 20): receive your personal data in a structured, machine-readable format.
- Right to object (Art. 21): object to processing based on legitimate interests.
- Right to withdraw consent: where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.
If you are a call participant (not a registered user), the controller for your data is the workspace that operated the agent you spoke with — please direct rights requests to that workspace owner. We will assist them with fulfilling your request.
To exercise any of these rights as a registered user, contact us at [email protected]. We will respond within 30 days. You may also delete your account directly from the account settings page, which permanently removes all your data.
You have the right to lodge a complaint with the Romanian data protection supervisory authority:
ANSPDCP — Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal
www.dataprotection.ro
13. Cookies & Local Storage
The Service uses cookies and local storage to provide core functionality, improve the Service, and measure the effectiveness of our marketing. You can manage your preferences at any time through the cookie banner or by clearing your browser cookies.
Essential cookies
- Session cookie: strictly necessary to maintain your authenticated session. Deleted when you log out or your session expires.
- Cookie consent preference: stores your choices about non-essential cookies. Retained for one year so we do not ask you on every visit.
- UI preferences: limited use of localStorage to remember sidebar state and similar interface settings.
Analytics cookies
- Google Analytics 4: used to understand how visitors interact with the Service, which pages they visit, and how they navigate the site.
- These cookies are placed only when you consent to analytics cookies.
- Google Analytics 4 does not store full IP addresses by default.
- We use Google Consent Mode v2 to communicate your choices to Google services and to enable cookieless measurement when consent is not granted.
Marketing cookies and server-side measurement
- Meta Conversions API: used to measure the effectiveness of advertising campaigns. When you consent to marketing cookies, we send event data (such as signup and subscription events) directly from our server to Meta.
- The data sent to Meta includes a SHA-256 hashed version of your email address and your internal user ID. We do not send raw email addresses or other personal identifiers.
- We may also send a first-party click identifier (fbc) and browser identifier (fbp) if they are available, to help Meta attribute conversions to ad interactions. These identifiers are stored in first-party cookies named
_fbcand_fbponly when you consent to marketing cookies. - This tracking is performed server-side; no Meta pixel script is loaded in your browser.
- These events are sent only when you consent to marketing cookies.
- Affonso affiliate tracking: Affonso runs in consent mode. When you consent to marketing cookies, Affonso may set
affonso_referralandaffonso_datacookies for up to 30 days to attribute signups, subscriptions, and any referral incentives to partners. If you do not consent, these cookies are removed; you may still voluntarily provide a referral source during signup.
Managing and withdrawing consent
- You can accept, reject, or manage individual cookie categories through the cookie banner displayed on your first visit.
- You can reopen your cookie preferences at any time by clicking the Cookie settings link in the footer of any page.
- Registered users can also manage cookie preferences from the Privacy section of their account settings.
- Withdrawing or changing consent updates your cookie preference immediately and stops the corresponding tracking scripts from loading on the next page load.
- You can also manage or delete cookies through your browser settings.
14. Health-Related Data
The Service is not designed to process Protected Health Information (PHI) as defined by HIPAA. If you are a covered entity or business associate under HIPAA and need to process PHI through the Service, you must contact us to execute a Business Associate Agreement (BAA) before transmitting any health data. Without an executed BAA, you must not upload, transmit, or store PHI using the Service.
15. Children's Privacy
The Service is not directed at children under the age of 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.
16. B2B outreach (direct marketing)
We collect publicly available professional contact details (such as the clinic or business name, email address, phone number, and role) from public websites, Google Maps, and public directories, in order to contact businesses directly with offers about our B2B services.
The legal basis is our legitimate interest (Art. 6(1)(f) GDPR) in promoting our services to professionals and businesses for whom they are relevant. We have carried out and documented a legitimate interest assessment (LIA). Data is kept only until you object, or for a limited period without a response from you, after which it is deleted.
Every such communication includes our identity, the source from which we obtained your data, and a simple, free way to unsubscribe. You may object at any time to processing for direct marketing purposes (Art. 21 GDPR) at [email protected] or via the unsubscribe link in the email; objections are honored immediately, and your address is added to our suppression list so you are not contacted again.
We do not sell or share this data with third parties for marketing purposes.
17. Changes to This Policy
We may update this Privacy Policy periodically to reflect changes in our practices or legal requirements. We will update the “Last updated” date and, for material changes, notify you by email at least fourteen (14) days before the changes take effect. We encourage you to review this page regularly.
18. Contact
For any privacy-related questions, requests, or concerns:
ARIM Technologies S.R.L.
bd. Iuliu Maniu, nr. 17, bl. C1, sc. A, et. 4, ap. 20
Deva, Hunedoara, România
[email protected]