Data Processing Agreement
This agreement is part of the NordTell terms of service, and you accept it with them when you sign up. It covers the personal data your agents handle for you: the voices and words of the people who call your agents or are called by them, their phone numbers, your leads, and anything else about other people that you put into NordTell. Plain words, as everywhere else: it is your data, we use it only to run the service you set up, we keep it safe, and we delete it when you ask or leave.
1. Who is who
- You, the business with the NordTell account, are the controller: you decide why and how the data is processed.
- NordTell, Interactive Made ApS, CVR 41133902, Denmark (hello@nordtell.com), is your processor.
- If you use NordTell to serve your own clients, for example on a white-label package, you may be their processor. We are then your sub-processor on these same terms, and you pass on to your clients what they need from this agreement.
- This agreement does not cover data about you and your team as our customers: your account, your sign-ins and your billing. We are the controller of that, as our privacy policy explains.
2. What we process, and why
- Purpose: to run the platform for you. That means answering and placing calls with your agents, understanding and answering callers, recording calls if you switch recording on, writing transcripts and summaries, running your campaigns, leads, knowledge bases, tools, webhooks, automations and text messages, and showing all of it to you.
- What we do with the data: receive it through calls and through what you upload, store it, turn speech into text and text into speech, send it to the AI models and services that run your agents, send it where you connect it, and delete it.
- Whose data: people who call your agents or are called by them; your leads and contacts; people named in your prompts, knowledge-base documents and tools; your team members and clients, as far as they appear in your workspaces; and people whose voice you upload to clone a voice.
- What data: phone numbers; call audio, and recordings if you switch them on; transcripts and summaries; whatever callers choose to say, which can include names, addresses, e-mail addresses, appointments and orders; the details your agents collect; lead details (name, phone, e-mail, notes and your own fields); text messages; what your tools look up or send; knowledge-base content; voice samples; and call details such as time, length and outcome.
- Sensitive data: callers may tell your agent sensitive things, for example about their health when they call a clinic. If your agents will handle such data, you must have a legal basis for it, and set up recording and deletion to match.
- How long: for as long as you use NordTell, and until the data is deleted as described in section 10.
3. Your instructions
- We process the data only on your documented instructions. They are the terms, this agreement, and what you set up in the platform: your agents and their models, voices and languages, your numbers, recording, deletion settings, tools, webhooks, automations and integrations. A request you send us in writing, for example to support, is an instruction too. Choosing a service in the platform includes the transfer that service needs (section 7).
- We process the data in any other way only if EU or Danish law requires us to. If so, we tell you first, unless that law forbids it.
- If we think an instruction breaks the GDPR or other data protection law, we tell you.
- You make sure that you may process the data and use NordTell for it: a legal basis, telling callers what they need to know (your agents say they are AI, and you decide whether calls are recorded), and anything else the law requires where you and your callers are.
4. Confidentiality
Everyone at NordTell who can reach your data is bound to keep it confidential, and looks at it only when that is needed to run the service, to help you, or to keep it secure. Our support team can enter your account only while you allow it (Settings → Account → Support access), for one hour at a time, and every visit is written to your audit log.
5. Security
We protect your data with the measures in the annex at the end of this page, and keep them in step with the risks, with what is technically possible and with what it costs.
6. Sub-processors
- You allow us to use other companies, our sub-processors, to run the service. All of them are on our sub-processor page, with what each one does, where it works and what covers any transfer.
- Before a new sub-processor starts processing your data, we add it to that page, with the date at the top and a line in its change log. We don't send e-mails about it, so look there.
- If you object to a new sub-processor, write to us at hello@nordtell.com. We look for a way forward with you, for example a setting that keeps that company away from your data. If there is none, you can stop using the part of the service that needs it, or close your account.
- Each sub-processor is bound by contract to the same data protection obligations that this agreement puts on us, and we remain fully responsible to you for its work.
- Services you connect yourself are not our sub-processors: your own phone provider or SIP account, webhooks, custom tools, MCP servers, your calendar booking account, and the apps your automation flows talk to. Data goes to them because you set it up, under your own agreement with them.
7. Data outside the EU
- We store your data in the EU: our servers and database are in Frankfurt, Germany, and our backups in Amsterdam, the Netherlands.
- To run a call, the AI and phone services you choose process its content, the audio and the text, and some of them do that outside the EU, mainly in the USA. Which ones depends on your choices per agent and per number. The sub-processor page shows where each one works.
- Those transfers rest on the EU-US Data Privacy Framework where the company is certified, with the EU Standard Contractual Clauses as the fallback, or on the Standard Contractual Clauses alone where it is not.
8. Helping you with people's rights
- Most requests from the people the data is about, to see it or delete it, you can handle yourself in the platform: find a call or a lead, export your calls, and delete calls, recordings, leads and documents.
- Where something can't be done in the platform, we help you as far as we reasonably can.
- If a person contacts us directly about data we process for you, we pass the request on to you without undue delay, and we don't answer it ourselves unless you ask us to.
9. Breaches, and other help
- If we become aware of a personal data breach that affects your data, we tell you without undue delay, at the account owner's e-mail address. We tell you what we know: what happened, which data and which people it concerns, the likely consequences, and what we have done and are doing about it. We add to it as we learn more.
- You decide whether to notify the data protection authority and the people affected. We help you with the information we have.
- We also help you, with the information we have, with your own security obligations, with data protection impact assessments, and with consulting the authority beforehand where that is required.
10. Deleting your data
- You can delete data at any time: calls, recordings, transcripts, leads and documents, one by one, or automatically after a number of days you choose (Settings → Audit log → Data retention).
- When you delete your account from Settings, we delete every workspace that only you own, with everything in it, cancel your subscription and release the numbers rented through us. A workspace that has another owner keeps going without you.
- Copies in our backups are gone within 14 days.
- Voices you cloned are kept at the voice provider (ElevenLabs or Cartesia), and only the workspace that cloned them can see or use them. You can delete one yourself in the voice picker, under My voices; deleting the workspace or your account deletes them at the provider too.
- We keep what the law makes us keep: invoices and accounting records, for five years from the end of the financial year they belong to (the Danish Bookkeeping Act, § 12). They are about you as our customer, not about your callers.
- Before you delete, you can take a copy of what you need: export your calls, or fetch your data through the API.
- Our sub-processors delete what they hold under their own terms. Some AI providers keep requests for a short time, for example to detect abuse.
11. Showing that we keep this agreement
- On request, we give you the information you need to see that we keep this agreement: for example this agreement, the security measures below, the sub-processor list, and answers to reasonable questions.
- If that is not enough, you, or an independent auditor you choose who is bound to confidentiality, may inspect how we process your data. Give us reasonable notice. An inspection is at your own cost and can happen at most once a year, unless it follows a personal data breach or a data protection authority requires it. It must not put other customers' data at risk.
12. Liability, and which text wins
- The limits of liability in the terms of service apply to this agreement too, as far as the law allows.
- If the terms of service and this agreement say different things about personal data, this agreement wins.
13. Changes, law and language
- This agreement runs for as long as we process personal data for you.
- When we change it, the version and the date at the top change, and material changes are announced in the platform.
- Danish law applies, and disputes go to the courts of Denmark. This agreement is written in English. The Danish, Swedish and Norwegian versions are translations for your convenience; if a translation differs from the English version, the English version applies.
Annex: security measures
- Location: our servers, database and files are at DigitalOcean in Frankfurt, Germany (EU).
- Traffic: everything to and from the platform and its API is encrypted with HTTPS.
- Secrets: the keys to our AI providers and the phone-carrier credentials you connect are stored encrypted. Passwords are stored only as hashes (Argon2). API keys are stored as hashes and carry scopes that limit what they can do.
- Signing in: two-factor sign-in with an authenticator app is available for every account. Our own admin accounts always need a second code to sign in.
- Access: every workspace has roles, so each person gets only the access they need. Our support team enters an account only while its owner allows it, for one hour, and the visit is logged.
- Audit log: changes in a workspace are written to its audit log.
- Recordings: reachable only through signed links that expire: after a few hours in the app, after a week in webhooks. They are deleted with their call, their workspace or their account, and by your retention setting.
- Limits: signing in, signing up, password resets and other sensitive requests are limited per address, so nobody can try them endlessly.
- Addresses you type in: requests to web addresses you enter in tools, webhooks, MCP servers and imports can't reach our internal network.
- Backups: made every night and restored once to prove they work; kept for three nights on the server and for 14 days in separate storage in Amsterdam, the Netherlands (EU).
- Monitoring: a watchdog checks the server every five minutes and e-mails our team when something breaks.