Privacy Policy

Last updated: 2026

CallAmplify ("we") provides an AI phone assistant for small businesses. This policy explains how we process personal data under the GDPR, the UK GDPR and the Swiss FADP (full legal texts linked).

Who is responsible

CallAmplify, 8450 Andelfingen (ZH), Switzerland. Our full company details and postal address are in the Impressum. For anything in this policy, write to privacy@callamplify.com.

Controller and processor

For our customers' account data (name, email, billing) we act as the data controller. For call data, recordings and messages of callers we act as a processor on behalf of the business using CallAmplify — that business is the controller of its callers' data.

Data we process

Cookies

We only use strictly necessary cookies: a session cookie for sign-in and a cookie for your language preference. No third-party advertising or tracking cookies.

Visiting our website

When you open our website, our hosting provider records standard server log data: the IP address of the requesting device, the date and time, the resource requested, the referring page, and the browser and operating system your device reports. These logs exist to keep the site available and secure, are used for nothing else, and are not used to identify you. The hosting provider holds them for a short period and then deletes them.

We also measure our own audience, using our own software on our own servers. No analytics company is involved and nothing about your visit is sent to a third party. Per visit we record: which page was opened, the domain a visitor arrived from, campaign tags in the link (utm_*), the browser language, the country our network provider reports, and a coarse device class (desktop, tablet, phone). We do not store the full address of the page you came from, and we store no free text.

Nothing is stored on your device for this — no analytics cookie, no local storage. To count a visitor once a day rather than once a page, we derive a short code from your IP address and browser, mixed with a secret and the date. The raw IP address is never written to our database, and because the date is part of the input the same visitor produces a different code tomorrow — so the count cannot follow anyone across days, and nothing can be joined back to a person. What remains is visit statistics that identify nobody. Legal basis: our legitimate interest in knowing how our own site performs (Art. 6(1)(f) GDPR, Art. 31(1) FADP). Because nothing is read from or written to your device, this needs no consent banner.

Call recording

Where recording is enabled, it starts only after the notice at the beginning of the call has played. The recording is captured and stored by our telecommunications provider; CallAmplify stores a reference to the recording, not the audio file itself, and retrieves it over secure, time-limited links when an authorised user plays it back in the app. Where AI features are enabled, recordings may be transcribed, summarised or analysed. Recordings and related transcripts follow the account's retention period and are deleted when it expires — including a deletion request to the telecommunications provider. Callers who object to being recorded can ask for the recording to be deleted.

Legal basis

Performance of a contract (Art. 6(1)(b) GDPR), consent for recordings (Art. 6(1)(a)), and legitimate interests (Art. 6(1)(f)). Call content can occasionally include special categories of personal data (Art. 9 GDPR), such as health details; the business using CallAmplify, as controller, is responsible for a lawful basis for those. Confidentiality of communications is additionally protected by Art. 5 of the ePrivacy Directive 2002/58/EC and, in Switzerland, by Articles 179bis, 179ter and 179quinquies of the Criminal Code and by the FADP.

Processors

We use the following providers; a data processing agreement is in place with each (see also our DPA):

Business customers can request the current list of providers in writing at any time.

Before transcripts leave us for AI analysis we automatically remove email addresses, IBANs, long number sequences (such as phone or card numbers) and names given in an explicit introduction. This reduces exposure but cannot catch every form of personal data. The same removal is applied to the AI text responder and to AI-drafted follow-up messages, with one deliberate exception: a follow-up we draft for you may contain your client's first name so the message can address them personally. No provider trains models on your data.

The AI services above are off unless we switch them on; while they are off, no conversation content leaves our systems towards these providers. Processing of your callers' data (recordings, transcripts, contacts) always requires this activation. The website sales assistant is the one exception in scope: it runs on our marketing site before you are a customer, and handles no caller data at all.

Transfers outside Switzerland/the EU

Processing takes place primarily in the EU (Frankfurt). Some of the providers above are based in the United States — payment processing, AI processing, speech synthesis, the telephony company itself, and calendar sync where you connect one — so personal data may be transferred to a country whose level of data protection is not recognised as equivalent by Switzerland or the EU. Such transfers rely on adequacy decisions (the Swiss–U.S. and EU–U.S. Data Privacy Framework, and the UK Extension) where the provider is certified, and otherwise on the European Commission's Standard Contractual Clauses, including the Swiss amendments issued by the FDPIC and the UK addendum. We will provide a copy of these safeguards on request at privacy@callamplify.com.

Automated evaluation (profiling)

When AI analysis is enabled, calls are evaluated automatically — for example a summary, a classification of the enquiry, and a score for how promising it is. This supports prioritisation by the business you called. It does not produce an automated decision with legal or similarly significant effect within the meaning of Art. 22 GDPR or Art. 21 revFADP: whether and how you are called back is always decided by a person. You may object to this evaluation and request review by a human at privacy@callamplify.com.

Anonymous industry benchmarks

We compute anonymised industry comparisons (for example the average recovery rate of missed calls): aggregated values only, always across at least ten businesses, with no way to identify an individual business or caller. You can leave these comparisons at any time in Settings (Privacy & marketing); opting out works in both directions — your data stops contributing and the comparison is no longer shown to you.

Marketing communications

You only receive marketing from CallAmplify (email, SMS or telephone) with your explicit opt-in consent, which you can give and withdraw at any time in Settings under Privacy & marketing. Legal basis: consent (Art. 6(1)(a) GDPR). We never send marketing without an opt-in and never share your data for third-party marketing.

Number registration

To activate a phone number we are legally required to pass your business details (company name, registration/UID number, business address, contact details) to our telecoms provider and the competent regulator (in Switzerland, BAKOM). Legal basis: legal obligation (Art. 6(1)(c) GDPR) and performance of a contract (Art. 6(1)(b)).

Retention

We keep data only as long as necessary. Conversation content (transcripts, summaries, message texts) is automatically deleted after 12 months by default; statistical metadata is retained for your reporting.

Security

We protect data with encryption in transit (TLS) and at rest, hashed passwords, need-to-know access controls and logging of security-relevant events.

Your rights

You have the right to access, rectification, erasure, restriction and portability. Account owners can export their data at /api/account/export and request erasure of individual contacts. Send requests to the address below.

You also have the right to lodge a complaint with a supervisory authority — the FDPIC in Switzerland, your national data-protection authority in the EU, or the ICO in the United Kingdom.

Children

CallAmplify is a business service. People under 18 may not create an account, and we do not knowingly collect data from children.

Changes to this policy

We may update this policy. We announce material changes to account owners by email or in the app; the date above shows the current version.

Languages

This policy is published in English, German, French and Italian. If the versions differ, the English version prevails, as under our Terms.

Contact

Privacy: privacy@callamplify.com

CallAmplify · Privacy · Terms · DPA · Impressum · Sign in