GDPR
Where Neo Dialer sits in the GDPR picture, which obligations fall to you, and what the platform gives you to meet them.
Last updated: 20 August 2026
Who is the controller
For the people you call, you are the controller and Neo Dialer is the processor. You decide the lawful basis, the purpose, and the contact list. We process that data only to deliver the service and only on your instructions.
For your own users' account data and for visitors to this website, we are the controller. That is covered in the Privacy Policy.
What that means in practice
The obligations that sit with you as controller — and that no platform can discharge on your behalf — include:
- Establishing a lawful basis before you call someone
- Providing privacy information to the people you call, including that the call may be recorded and, where applicable, that they are speaking to an automated voice agent
- Running a DPIA where your calling programme warrants one
- Honouring objections and erasure requests you receive directly
Data subject rights
Most rights can be exercised without involving us at all, because the data is in your tenant and you have direct access to it:
| Right | How it is served |
|---|---|
| Access / portability | Tenant admins can export call history, recordings, transcripts and contact records from the application. |
| Rectification | Contact records are editable directly in the platform. |
| Erasure | Delete the contact and its call records in-app. For a full purge across recordings, transcripts and backups, raise it with us and we will action and confirm it. |
| Objection / restriction | Add the number to your DNC list — the dialer will refuse to call it from any campaign in the tenant. |
If a data subject contacts us directly about a call you made, we will not act on the data ourselves — we will refer them to you as controller and tell you it happened.
Sub-processors and international transfers
Our sub-processors are listed in the Privacy Policy, along with what each is used for. The platform's primary infrastructure is hosted in the United States, so processing EU or UK personal data on it involves an international transfer, made under Standard Contractual Clauses.
Two things worth knowing when you assess this:
- AI features are optional. A tenant with transcription, analysis and AI voice agents disabled sends call content to none of the AI sub-processors.
- Self-hosted text-to-speech is available. Piper runs on our own infrastructure, so AI speech output need not involve a third-party vendor at all.
EU or UK data residency, and dedicated media servers in a region of your choosing, are available as part of an Enterprise or white-label engagement rather than on the standard plans. Ask us before assuming a region.
Security of processing
Article 32 measures — tenant isolation, encryption, access control, MFA, audit logging — are described on the Security page. Note the certification section there: our controls are real but not third-party audited.
Breach notification
If we become aware of a personal data breach affecting your tenant, we will notify you without undue delay with what we know, so you can meet your own 72-hour obligation to your supervisory authority.
Getting a DPA
We provide a Data Processing Agreement including Standard Contractual Clauses and the sub-processor list. Request one and we will send it for signature.
Note
This page explains how the platform supports your GDPR obligations. It is not a certification, and it is not legal advice about your calling programme.
Questions about this page, or need it in a form your legal team can sign? Contact us.