Privacy Policy
This page describes what Neo Dialer actually does with data — what we collect, where it lives, who else touches it, and how long we keep it.
Last updated: 20 August 2026
Who we are
Neo Dialer is a multi-tenant calling platform operated by NeoMD Health. When you sign up, your organisation becomes a tenant: a separate account whose data is scoped to your organisation and not visible to any other tenant.
For the calls you make, you are the data controller and we are the processor. You decide who is called, what is said, and whether calls are recorded. We process that data to run the service on your behalf.
What we collect
Account and user data
- Name, email address and password hash for each user in your organisation
- Organisation name, role assignment, and multi-factor authentication enrolment
- Sign-in timestamps, IP address and user agent, kept in the audit log
Call data
- Call metadata: numbers dialled, caller ID presented, direction, start and answer times, talk duration, outcome, and which agent or campaign handled the call
- Call recordings, when your organisation enables recording. WebRTC recordings are stereo — the agent on the left channel, the contact on the right
- Transcripts and AI-generated summaries, when transcription or call analysis is enabled on your plan
- Contact lists you upload to campaigns, and any notes or dispositions agents add
Operational data
- SIP signalling and registration events, used for call routing and abuse detection
- Usage counters — minutes, AI minutes, TTS characters, storage — used for billing
- Application error logs
Marketing site
If you submit the contact form or subscribe to the newsletter, we store what you typed along with the hostname you submitted from and a one-way hash of your IP address. We do not store your raw IP address for these forms. See our Cookie Policy for what the site sets in your browser.
Where data is stored
Application data sits in a managed PostgreSQL database (Supabase) hosted on AWS in the United States (us-east-1). Recordings and other media are stored in per-tenant private object-storage buckets in the same region; they are never served from a public URL, only through short-lived signed links issued to authenticated users in the owning tenant.
Voice media (RTP) is handled by media servers running Asterisk. Where an AI voice agent is on the call, the AI runtime is co-located with Asterisk on that server so audio stays on the loopback interface rather than crossing a network.
If your deployment requires a specific region or a dedicated media server, that is arranged as part of an Enterprise or white-label engagement — talk to us.
Sub-processors
These are the third parties that can process customer data, and what each one is used for. Which AI vendors apply to you depends on your plan and your tenant's AI configuration; a tenant with AI features disabled uses none of them.
| Provider | Purpose |
|---|---|
| Supabase (AWS, US) | Database, authentication, object storage |
| Hetzner | Application and media server hosting |
| Telnyx | SIP trunking and phone numbers, where you use platform-provided telephony |
| Deepgram, Groq | Speech-to-text for transcription and live AI conversation |
| OpenAI, Groq | Language models for AI voice agents, call summaries and analysis |
| ElevenLabs, Cartesia | Text-to-speech voices for AI agents |
Piper, a self-hosted text-to-speech engine, runs on our own infrastructure and sends no audio to a third party. If you bring your own SIP trunk, your telephony provider is your own contractual relationship, not a Neo Dialer sub-processor.
How long we keep it
- Call recordings — retention is set by your organisation and capped by plan: 30 days on Starter, 90 days on Growth, up to 365 days on Enterprise. If your tenant reaches its storage limit, the configured overflow policy applies (by default, the oldest recordings are deleted first).
- Call metadata and transcripts — kept for the life of the account so reporting stays accurate, unless you ask us to purge them.
- Audit logs — retained as a security record; these are deliberately not user-deletable.
- Marketing form submissions — kept until you ask us to remove them.
When an account is closed, tenant data is deleted on request. Tell us and we will confirm when it is done.
Who can see your data
Access inside your tenant follows the role you assign: agent, supervisor, org admin, billing admin, tenant admin, owner. Platform staff hold a separate platform role and can access a tenant for support only through an impersonation flow that is written to the audit log every time it is used.
Your rights
You can access, correct, export or delete personal data we hold. Most of it is directly reachable in the application — call history, recordings, contacts and users are all exportable by a tenant admin. For anything else, or for a request made on behalf of a person you called, contact us and we will action it. See GDPR for how this maps onto EU/UK data subject rights.
Changes to this policy
We will update the date at the top of this page when the text changes. Material changes affecting how customer data is handled are communicated to tenant admins directly.
Note
This page is a plain-language description of how the platform works. It is not a substitute for a signed Data Processing Agreement — if you need one, ask and we will provide it.
Questions about this page, or need it in a form your legal team can sign? Contact us.