Privacy Notice — EREG-Dialer
Working draft (2026-05-18).
What we collect
- Account data: name, email, role, MFA enrollment status.
- Tenant data: organization name, billing details, integration credentials (encrypted).
- Contact data: lead phone numbers, names, emails, notes uploaded by you.
- Call data: timestamps, durations, dispositions, recordings (if you opt in).
- Usage data: pages viewed, actions taken, audit log entries.
How we use it
- Provide the dialer service.
- Process billing via Stripe.
- Place calls via Twilio.
- Support and troubleshooting.
- Improve the product (aggregate, anonymized analytics only).
How we share it
- Stripe processes payments.
- Twilio carries the calls.
- Anthropic / OpenAI processes AI features. Zero data retention confirmed with both providers; tenant kill switch in Settings → AI.
- Resend / Postmark sends transactional email.
- Sentry receives error reports (no PII).
- We never sell or share your data for marketing.
Your rights
- Access: Settings → Data → Export everything.
- Delete: tenant offboarding removes data on schedule.
- Correct: contact us if anything is wrong.
- Opt-out of "sale/share" (CCPA): we don't do either, but the Do-Not-Sell/Share link is on the marketing site footer.
Retention
- Call records and recordings: tenant chooses 12 / 24 / 36 / 60 months (default 24).
- Audit log: 7 years.
- Account data: lifetime of account + 30 days after cancellation.
Sub-processors
See https://www.eregdialer.com/legal/sub-processors (30-day notice on changes).
Breach notification
72-hour SLA to notify affected tenants per GDPR. We follow state-level breach laws (CA, NY, etc.).
Contact
Working draft. Binding version at https://www.eregdialer.com/legal/privacy after counsel review.