# Privacy Policy

> How Deduxer S.R.L. handles personal data on the Onist website, the demo line, the app and the calls the receptionist answers.

_Deduxer S.R.L. · Onist · The short version_

- Customer data remains yours. We process it on your instructions using the configured providers and safeguards described in the Privacy Policy. Section 14 of the Terms is the processing agreement.
- Audio expires after 30 days by default; the business can choose 7–365 days. Expired audio cannot be played. Cleanup removes the stored object and records deletion, with recoverable retries during storage outages. Other business records remain subject to the controller’s retention instructions and legal duties; audio expiry does not delete bookings, transcripts or accounting records. Authentication email payloads expire within one hour, delivery metadata after 30 days. Ask the operator for deletion/export assistance and the production backup retention schedule.
- Essential session and preference cookies keep the account signed in and remember language or display choices. Optional product analytics is off until permission is given. It does not capture form contents, call audio, messages, or booking receipt tokens. Analytics permission can be changed on this page.

## 1. Who is responsible

Deduxer S.R.L., tax id RO50140604, registered office at București, România, makes and operates Onist. For everything in this policy where we decide why and how data is processed, we are the controller. Write to [legal@onist.ro](mailto:legal@onist.ro) for anything about your data.

This policy covers the Onist website, the demo line and callback requests, the accounts of the businesses that use Onist, the calls, messages and bookings the receptionist handles for them, and the booking page. It applies from 12 September 2026.

## 2. Two roles: when we decide, and when a business decides

We act in two roles, and your rights depend on which one applies.

- We are the controller for the website, the demo line, the callback form, the accounts and billing of our customers, our own marketing and support. Sections 3 to 12 apply in full.
- We are a processor when the receptionist answers a call to a business that uses Onist, books an appointment, sends an SMS or a WhatsApp message, or when someone books through that business's booking page. The business is the controller and decides what happens to the data. We process it on the business's instructions under the data processing agreement in our [Terms of Service](/terms#dpa).

If you called a business that uses Onist, here is what happened to your call. The receptionist told you that it is an AI and that the call was recorded, or asked your consent where the law requires it. The recording, a transcript and a short summary went to the business, together with your phone number and what you asked for, so that the business can call you back, book you in or answer your question. The business can delete the call at any time. We do not use your voice for anything else, we do not build a voice profile, and we do not contact you on our own behalf.

To exercise your rights over such a call, contact the business. If you cannot reach it or it does not answer, write to us and we will help.

## 3. What data we collect

Customer account data includes contact and business information, services, staff, availability and configuration. The enabled phone, booking and messaging features process customer contact details, service or vehicle details, appointments, messages, consent evidence and authorized call audio and transcripts. Paddle handles payment credentials; Onist receives billing status and transaction references. Temporary authentication messages contain a verification link and expire from the delivery queue.

## 4. Why we use it and on what legal basis

| Purpose | Data | Legal basis |
| --- | --- | --- |
| Run the receptionist, the app, the calendar, the messages and the booking page for a business | Account and business details, calls, messages, bookings | Performance of the contract with the business (Art. 6(1)(b) GDPR); for callers' data, the business's instructions as controller |
| Run the demo line and call you back when you ask | Demo audio, phone number, IP address | Our legitimate interest in showing the product to people who ask for it (Art. 6(1)(f)); you start the call or the request yourself |
| Assign and register phone numbers, verify forwarding | Business details, identity documents where required | Performance of the contract; legal obligation where the carrier's regulator requires identification (Art. 6(1)(c)) |
| Bill, invoice and keep accounts | Billing details, invoices, payment status | Performance of the contract; legal obligation under tax and accounting law |
| Keep the service secure and prevent abuse: rate limits, fraud checks, blocking spam | IP addresses, usage logs, call metadata | Legitimate interest in protecting the service, our numbers and our customers |
| Understand how the product is used and fix problems | Optional coarse navigation events, sanitized error reports | Consent for optional analytics; legitimate interest in diagnosing service failures. No caller content or advertising profiles |
| Answer support requests and disputes | Your messages, account details, the calls concerned | Performance of the contract; legitimate interest in defending claims |
| Comply with the law and requests from authorities | What the request requires | Legal obligation |

## 5. AI, recordings and your voice

The agent announces its AI identity and follows the configured recording notice and consent policy. Audio is processed by the enabled speech provider to understand the request and generate a response. Provider retention and regional controls must be configured before live calls. Onist does not use customer content to train its own models.

Romania and Italy: the business must choose a lawful recording policy for its own activity and notify callers. Country selection is not consent evidence. A refusal must stop recording. The exact AI disclosure used by the agent is reproduced below.

## 6. Who we share data with

Only providers for enabled features receive the data needed for their work. Intended infrastructure: Supabase in Frankfurt, Vercel functions in Frankfurt, Railway workers in Amsterdam, and EU projects for Sentry and PostHog. OpenAI, Telnyx, Kapso/Meta, Resend and Paddle handle the enabled AI, telephony, messaging, email and billing functions; LiveKit is used only in the configured alternate media mode. These regional settings, contracts and any international transfer mechanism must be verified before live activation. Provider inclusion here does not mean its account is already enabled.

## 7. Where data is stored

Only providers for enabled features receive the data needed for their work. Intended infrastructure: Supabase in Frankfurt, Vercel functions in Frankfurt, Railway workers in Amsterdam, and EU projects for Sentry and PostHog. OpenAI, Telnyx, Kapso/Meta, Resend and Paddle handle the enabled AI, telephony, messaging, email and billing functions; LiveKit is used only in the configured alternate media mode. These regional settings, contracts and any international transfer mechanism must be verified before live activation. Provider inclusion here does not mean its account is already enabled.

## 8. How long we keep it

Audio expires after 30 days by default; the business can choose 7–365 days. Expired audio cannot be played. Cleanup removes the stored object and records deletion, with recoverable retries during storage outages. Other business records remain subject to the controller’s retention instructions and legal duties; audio expiry does not delete bookings, transcripts or accounting records. Authentication email payloads expire within one hour, delivery metadata after 30 days. Ask the operator for deletion/export assistance and the production backup retention schedule.

## 9. Security

Security. Tenant access is enforced by database policies. Files are private and recording links expire after sixty seconds. Changes are audited and application logs omit caller content. Encryption, staff access and backup settings are verified as part of production deployment; regional storage alone does not eliminate international transfers.

## 10. Your rights

Under the GDPR you can ask us to:

- tell you what data we hold about you and give you a copy;
- correct it;
- delete it;
- restrict how we use it, or object to a use based on legitimate interest;
- give it to you, or to another provider, in a machine-readable form;
- withdraw a consent you gave; that does not affect what was done before.

Write to [legal@onist.ro](mailto:legal@onist.ro). We may ask you to confirm who you are. We answer within one month; if a request is complex we may take up to two more months and we tell you. Exercising your rights is free.

If you called a business that uses Onist, send your request to that business, which is the controller. If you cannot reach it, write to us and we pass the request on and help.

You can complain to a supervisory authority. In Romania that is the Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP), B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, București, [dataprotection.ro](https://www.dataprotection.ro). In Italy it is the Garante per la protezione dei dati personali, [garanteprivacy.it](https://www.garanteprivacy.it). You can also complain to the authority of the country where you live.

## 11. Cookies

Essential session and preference cookies keep the account signed in and remember language or display choices. Optional product analytics is off until permission is given. It does not capture form contents, call audio, messages, or booking receipt tokens. Analytics permission can be changed on this page.

## 12. Children

The website, the demo and the app are for adults acting for a business. We do not knowingly collect data from anyone under 18. A minor may still call a business that uses Onist; in that case the business is the controller and the call is handled like any other. If you think we hold data about a child without a valid basis, tell us and we delete it.

## 13. Changes to this policy

We update this policy when the service or the law changes. The date at the top tells you which version you are reading. For changes that matter, we email our customers before they take effect.

## 14. Contact

Deduxer S.R.L., București, România. Tax id RO50140604, trade register J2024003862236. Email [legal@onist.ro](mailto:legal@onist.ro). Phone [+40 745 077 209](tel:+40745077209).

---

[HTML](https://onist.ro/en/privacy) · [https://onist.ro](https://onist.ro/en)
