Legal

Privacy policy

Last updated 8 September 2026

This policy explains how NordTell, operated from Denmark, handles personal data on this website and in the NordTell platform. It is written in plain words on purpose. If anything here is unclear, ask us through the contact page.

Two roles

For visitors of this website and for the people who create accounts, NordTell is the data controller. For the calls your agents handle, the callers' voices, transcripts and the details they share, you are the controller and NordTell is your processor, acting on your instructions and the settings you choose in the platform.

What we collect on this website

  • Server logs: IP address, time, page requested, browser type. Kept briefly for security and to keep the site running.
  • The contact form: the name, email, company and message you send. We use it only to answer you, and it lives in our mailbox.
  • A small browser storage flag that remembers you have seen the opening animation. No advertising cookies, no third-party trackers.

What we collect in the platform

  • Account data: name, email, password (stored hashed), optional two-factor secret, sign-in events.
  • Workspace data: agents, prompts, numbers, leads, campaigns, tools, knowledge documents, settings and the audit log of changes.
  • Call data on your behalf: audio recordings if you enable them, transcripts, summaries, phone numbers, the variables the agent collected, and technical call metadata.
  • Billing data: your package, minutes used and bought, invoices. Card details are handled by Stripe and never touch our servers.

Where it is stored

The platform, its database and its files run on servers within the European Union, hosted by DigitalOcean.

Who else processes data

A voice agent uses external AI models and telephone carriers. Which ones is your choice, per agent and per number, and each is named in the platform where you choose it. Depending on your settings, calls may be processed by OpenAI, Anthropic, Google, ElevenLabs, Cartesia, Deepgram, Gladia or Soniox (speech and language models), by Telnyx, Twilio or your own SIP provider (telephony), and by LiveKit (call media). Payments are processed by Stripe. Each acts under its own data processing terms; we list the provider next to the model so that choosing one is an informed decision.

How long we keep it

  • Calls, recordings and transcripts: for the retention period you set in your workspace, then deleted.
  • Audit log: for the period you set (90 days by default).
  • Account and billing data: while your account exists, and afterwards as long as bookkeeping law requires for invoices.
  • Contact-form messages: until answered and no longer needed.

Your rights

You can see, correct, export and delete your data. Most of it you can do yourself in the platform: delete a call, a lead, a document, or your whole account. For anything else, or if you are a caller who spoke to an agent run by one of our customers, contact us or the business you called and we will help. You can also complain to the Danish Data Protection Agency (Datatilsynet).

Security

Traffic is encrypted with HTTPS. Provider API keys are stored encrypted. Access is by role; two-factor sign-in is available for every account. Every change in a workspace is written to an audit log.

Changes

When this policy changes, the date at the top changes with it, and material changes are announced in the platform.