Security and data protection

What we do with call data

A page about what we store, who has access and who processes the data. We write only what is implemented today.

Data protection and confidentiality
Encrypted data in transit
TLS 1.3DPA / CRM
Announcement at the start of the callConfigurable per agent
Data controlExport & deletion on request
Contractual commitmentData are not sold
Documented architecture

Active measures today

  • Recording notice

    From 9 September 2026, for all calls that pass through our telephony server, the customer hears that the call is being recorded, in Romanian, Russian or both, before audio capture starts. For each call we keep proof that the notice was spoken.

  • Deletion and export on request

    At the request of the data subject or the client, we delete or export the data of a contact — calls, transcriptions, recordings. The request is sent to the contact address and we carry it out.

  • Platform on servers managed by us

    The database, panel and telephony run on servers managed by us, rented from OVHcloud.

  • Server-started voice sessions

    The voice button on the site does not contain the agent key. The page requests a session from the Kallina server, which issues a temporary link.

  • Encrypted connections

    The dashboard, API and voice sessions use HTTPS/TLS.

  • Data Processing Agreement

    For clients who use Kallina for their calls, we sign a data processing agreement (DPA) with MEGA PROMOTING S.R.L. You can request it through the contact page.

Put plainly

  • No certifications we do not have

    We do not have SOC 2, ISO 27001 or HIPAA certifications. We do not display them and we do not promise them.

  • No unwritten SLA

    We do not provide an uptime percentage without a signed contract that sets it out.

  • We do not sell data

    We do not sell data and we do not use customers' conversations for advertising.

The data path of a call

  1. The call comes in

    On our telephony server (Asterisk).

  2. The announcement is played

    The client is informed that the call is being recorded.

  3. Speech and voice

    The voice is transcribed and synthesised via ElevenLabs; the response is generated by the language model configured on the agent.

  4. Saving

    The recording and transcript are saved in the Kallina database.

  5. The result

    It is sent to the client’s CRM if the integration is configured.

  6. Deletion

    We do it on request, to the contact address, or at the term set in the contract with the client. Automatic deletion at the term does not yet run.

Sub-processors

Providers that process data for the Kallina service. The list is updated when we change a provider.

ProviderWhat for
OVHcloudServers: database, dashboard, telephony.
ElevenLabsSpeech recognition, voice synthesis, conversation session.
Google (Gemini)Language model, post-call analysis.
InfobipSending SMS messages.
Microsoft 365E-mail.
TelegramThe internal notification of requests from the website forms.

The client’s CRM (amoCRM, Bitrix24, Zoho and others) receives the call result; its provider is chosen by the client and is the client’s responsibility.

Roles

  • For your agent’s calls

    You are the data controller; MEGA PROMOTING S.R.L. processes them on your behalf, under the DPA.

  • For this site and the Kallina account

    MEGA PROMOTING S.R.L. is the data controller.

  • Applicable law

    Regulation (EU) 2016/679 (GDPR) for people in the EU. As a controller registered in the Republic of Moldova, we also apply Law No. 195/2024 on the protection of personal data.

Frequently asked questions

Are the conversations used to train models?

We do not train models on customers’ conversations. External providers process the data under their own commercial terms.

How do I request data deletion?

Write to us at the address on the contact page, with the subject “Personal Data”. We respond within one month at most.

Is the recording notice mandatory?

Yes, on calls that go through our telephony. The notice must come before the recording starts.

Does the data go to suppliers in other countries?

Yes, to the suppliers in the table. For suppliers outside the EEA, we use the European Commission’s standard contractual clauses.

Can I receive the DPA before the contract?

Yes. Write to us and we will send it.

What should I do if I discover a vulnerability?

Write to us at the address on the contact page, with details. Do not test on other customers’ data.

Do you need documents for the legal team?

We send the DPA, the list of sub-processors, and a description of the data flow.