OneDo.me ยท Data processing

Data processing agreement

Version of 28 July 2026 ยท Terms of Service ยท Privacy statement

When your page has an AI assistant, your callers tell it things โ€” their name, their phone number, what they need. That is personal data, and under the GDPR you decide what happens with it: you are the controller. We only handle it to deliver the service to you, which makes us your processor. This agreement sets out the terms of that, as Article 28 of the GDPR requires. It applies automatically as part of the Terms of Service from the moment your assistant is switched on; no signature needed.

1. Parties

Controller: you โ€” the owner of the OneDo.me page, whether a business, an association or a private person.
Processor: Confianta EOOD, UIC 207288781, registered office Detelina 49A, 9101 Byala, Varna, Bulgaria, support@confianta.com.

2. What is processed, and why

SubjectPersonal data that people who call your page give to your AI assistant, and the transcript of that conversation.
PurposeAnswering your callers, taking their message, and passing it to you โ€” plus, where you switch it on, booking an appointment for them.
NatureLive speech recognition, generating an answer, transcribing, transmitting to you by email and in your owner panel, and short-term storage.
Data subjectsAnyone who calls your page and speaks or types to the assistant.
Categories of dataWhatever the caller says: usually a name and a phone number or email address, the reason for calling, and any appointment details. Plus technical connection data.
DurationAs long as your assistant is active. Transcripts are deleted from our systems 30 days after the conversation.

3. We act only on your instructions

We process this data only to deliver the service and only as you instruct us. Your instructions are: these documents, the settings and assistant instructions you configure on your page, and anything else you ask us in writing. We do not use your callers' data for our own purposes, we do not sell it, and we do not use it to train our own models. If we ever believe an instruction breaks data protection law, we will tell you and may pause it until it is sorted out.

4. Confidentiality

Everyone on our side who can reach this data is bound to keep it confidential. Access is limited to what is needed to run and support the service.

5. Security

We take appropriate technical and organisational measures, including:

  • encryption in transit โ€” HTTPS for the site, encrypted media for calls;
  • calls between two people running directly between browsers, so their content never reaches us at all;
  • access to the server restricted to the people who operate it;
  • automatic deletion of transcripts after 30 days, so the amount of data held stays small by design;
  • an administration of minutes and cost that holds no conversation content.

6. Sub-processors

You give us general permission to use the sub-processors below. Each is bound by obligations no weaker than these.

WhoWhat for
Google (Gemini Live)Speech and conversation for the assistant in some languages
DeepgramSpeech recognition and speech for the assistant in other languages
OpenAIThe language model used inside the Deepgram pipeline to form answers
ResendDelivering transcripts and summaries to you by email
TwilioSMS alerts
Cal.comAppointment booking, if you switch it on
StripeYour own payment data (not your callers')
Hostinger International LtdThe server the service runs on, in Frankfurt, Germany

If we want to add or replace one, we will tell you at least 30 days in advance by email or in the owner panel. If you object on reasonable data protection grounds, tell us within those 30 days; if we cannot find a workable alternative, you may cancel the assistant subscription with effect from the change, and we will refund any unused prepaid minutes in that specific case.

7. Transfers outside the EEA

Some of the providers above process data in the United States. Those transfers rest on the European Commission's standard contractual clauses or on an adequacy decision, together with the safeguards those providers apply.

8. Helping you meet your own obligations

  • Requests from your callers. If someone asks us directly for access to or deletion of their data, we do not answer for you โ€” we pass the request on and help you deal with it.
  • Data breaches. If a breach affects your callers' data, we tell you without undue delay and in any case within 48 hours of becoming aware of it, with what we know and what we are doing about it.
  • Assessments. We give you the information you reasonably need for a data protection impact assessment or a consultation with a supervisory authority.

9. Deletion

Transcripts are deleted from our systems 30 days after the conversation, automatically. If you stop using the assistant or delete your page, anything still within that window is removed on the same schedule, and you can ask us to delete it sooner. Note that the transcripts already emailed to you are in your own mailbox and outside our control โ€” keeping or deleting those is your responsibility.

10. Showing that we comply

On request we give you the information you need to verify that we meet these obligations. A full on-site audit is not proportionate for a service of this size, so we answer questions in writing and, if you have a genuine reason, we will work out something reasonable with you.

11. What we need from you

You are the controller, so these are yours to get right:

  • Have a lawful basis for the data your assistant collects, and a privacy policy of your own that mentions it.
  • Tell your callers that they are speaking with an AI assistant and that the conversation is written down and sent to you. By default we do that for you โ€” the assistant introduces itself as a digital assistant and the page carries a notice โ€” but if you change the greeting or the instructions, it stays your responsibility. In some countries it is legally required.
  • Do not configure your assistant to ask for special categories of data โ€” health details, religion, political views, biometric data โ€” or for payment card numbers. The service is not built for it. If a caller volunteers such a thing anyway, it ends up in the transcript and follows the same 30-day deletion.
  • Keep the transcripts you receive safe, and delete them when you no longer need them.

12. Liability

The liability limits in clause 13 of the Terms of Service apply to this agreement too, except where the GDPR itself sets the liability of a processor towards data subjects.

13. Changes

If we change this agreement in a way that matters, we announce it at least 30 days in advance and you can cancel before it takes effect. The version date is at the top.

OneDo.me is a website of Confianta EOOD · www.confianta.com · support@confianta.com
Terms · Privacy · Data processing