DialedIn, LLC ("DialedIn," "Company," "we," "our," or "us") is committed to responsible data management, security, privacy, and compliance. This Data Handling Policy describes how data is collected, processed, stored, transmitted, retained, and disposed of when using the DialedIn platform and related services.
This policy applies to all employees, contractors, vendors, customers, and authorized users of DialedIn services.
1. Purpose
The purpose of this policy is to:
- Protect customer and caller information
- Establish data management standards
- Define security responsibilities
- Promote compliance with applicable laws
- Reduce operational and cybersecurity risks
- Ensure consistent handling of business data
2. Data Categories
DialedIn may process the following categories of information.
Customer Account Data
Information provided by customers, including:
- Business name
- Contact information
- Account credentials
- Billing information
- Service configurations
- Calendar integrations
- Notification preferences
Caller Data
Information collected during inbound communications, including:
- Caller name
- Phone number
- Email address
- Service requests
- Appointment requests
- Job descriptions
- Location information
- Notes collected during calls
Call Data
Information generated during communications, including:
- Call recordings
- Voice recordings
- Call metadata
- Call duration
- Timestamps
- Transcripts
- AI-generated summaries
- Lead qualification outcomes
- Scheduling outcomes
System Data
Technical information generated through use of the Services, including:
- Login activity
- Device information
- IP addresses
- Browser information
- Audit logs
- Error logs
- Usage metrics
SMS Notification Data
When a customer enables SMS call notifications, DialedIn may process:
- Recipient mobile phone number
- SMS notification enabled or disabled status
- Consent timestamp, source, and authorizing user
- Phone verification status and timestamp
- Opt-out status, timestamp, and method
- Related call identifier
- Message content or rendered call summary
- Telecommunications provider message or chat identifier
- Delivery status, delivery attempts, and error information
3. Data Collection Principles
DialedIn follows the principle of data minimization.
We collect only the information reasonably necessary to:
- Provide services
- Operate the platform
- Improve system performance
- Maintain security
- Comply with legal obligations
DialedIn does not intentionally collect information unrelated to service delivery.
4. Authorized Use of Data
Data may be used solely for legitimate business purposes, including:
- Providing contracted services
- Processing inbound calls
- Lead qualification
- Appointment scheduling
- Customer support
- Product improvement
- Security monitoring
- Legal compliance
- Billing and account management
Employees and contractors may access information only when necessary to perform authorized duties.
5. AI Data Processing
DialedIn utilizes artificial intelligence systems to facilitate certain services.
Data may be processed by:
- Speech recognition systems
- Voice AI systems
- Language processing systems
- Appointment scheduling systems
- Classification systems
- Automation platforms
AI systems may analyze:
- Call recordings
- Voice interactions
- Caller responses
- Transcripts
- Scheduling requests
- Service inquiries
AI-generated outputs are reviewed and maintained in accordance with applicable operational requirements.
6. Data Access Controls
Access to information is restricted using the principle of least privilege.
Authorized personnel may access data only when:
- Required to perform job responsibilities
- Required to support customers
- Required to investigate incidents
- Required to maintain system operations
Access permissions shall be reviewed periodically and revoked when no longer necessary.
7. Data Storage
Information may be stored using secure cloud-based infrastructure and third-party service providers.
Storage systems may include:
- Database platforms
- Cloud hosting environments
- Telecommunication providers
- AI service providers
- Backup systems
- Analytics systems
Reasonable efforts shall be made to ensure information is protected from unauthorized access.
8. Data Transmission
Data transmitted between systems should be protected using industry-standard encryption and secure communication protocols whenever reasonably available.
Sensitive information shall not be intentionally transmitted through unsecured channels unless specifically authorized and necessary for service delivery.
9. SMS Notification Handling
DialedIn limits SMS call notifications to information reasonably necessary to alert the authorized customer recipient about a completed call and the potential need for follow-up. Notifications may include caller details, a concise call summary, caller sentiment, urgency or recommended follow-up timing, and a secure link to the applicable call record.
Full call recordings and transcripts are not intended to be included directly in SMS notifications and remain accessible through authenticated DialedIn services when available.
Mobile phone numbers, SMS opt-in data, and messaging consent are not sold, rented, or shared with third parties or affiliates for their marketing or promotional purposes. DialedIn may provide this information to telecommunications and technology providers solely as necessary to deliver and support the messaging service, maintain security, prevent fraud, troubleshoot delivery, or comply with law.
DialedIn may retain consent and opt-out records as reasonably necessary to demonstrate compliance, honor recipient preferences, resolve delivery issues, and prevent accidental or unauthorized re-enrollment. SMS delivery failures must not prevent the underlying call record from being stored or interfere with other independently enabled notification channels.
10. Data Retention
DialedIn retains information only as long as reasonably necessary to:
- Deliver services
- Maintain operational records
- Resolve disputes
- Enforce agreements
- Meet legal requirements
Retention periods may be adjusted based on operational, legal, or contractual requirements.
| Data Type | Typical Retention Period |
|---|---|
| Call Recordings | Up to 24 Months |
| Call Transcripts | Up to 24 Months |
| Lead Records | Up to 36 Months |
| Customer Account Data | Duration of Service Relationship |
| Billing Records | 7 Years |
| Security Logs | Up to 24 Months |
11. Data Deletion
When information is no longer required, DialedIn may:
- Permanently delete records
- Remove identifying information
- Anonymize data
- Archive information as required by law
Deletion requests may be subject to legal, operational, or contractual limitations.
12. Aggregated and Anonymized Data
DialedIn may create aggregated, anonymized, or de-identified datasets derived from customer usage.
Such data may be used for:
- Analytics
- Reporting
- Product improvement
- Research
- Benchmarking
- Machine learning optimization
Aggregated data shall not intentionally identify individual customers or callers.
13. Third-Party Service Providers
DialedIn may engage third-party providers to support service delivery.
Examples include:
- Cloud infrastructure providers
- AI providers
- Telecommunication providers
- Scheduling providers
- Payment processors
- Customer support vendors
Third-party providers are expected to maintain reasonable safeguards appropriate to the services they provide.
14. Incident Response
In the event of a suspected security incident, DialedIn may:
- Investigate the incident
- Restrict system access
- Preserve evidence
- Notify affected parties when appropriate
- Engage legal, security, or technical professionals
- Implement corrective actions
Incident response activities will be conducted in a manner consistent with applicable legal obligations.
15. Security Safeguards
DialedIn maintains reasonable administrative, technical, and organizational safeguards, including where appropriate:
- Access controls
- Authentication requirements
- Role-based permissions
- Security monitoring
- Audit logging
- Encryption technologies
- Vendor risk management
No security system can guarantee complete protection against all threats.
16. Customer Responsibilities
Customers remain responsible for:
- Protecting account credentials
- Configuring user permissions appropriately
- Obtaining required caller consents
- Complying with applicable privacy laws
- Maintaining security of connected third-party systems
Customer actions that compromise security may increase risk and are outside DialedIn's control.
17. Regulatory Compliance
DialedIn seeks to operate in compliance with applicable laws and regulations, including those related to:
- Privacy
- Telecommunications
- Consumer protection
- Data security
- Record retention
Customers remain responsible for determining whether the Services meet their own regulatory obligations.
18. Employee and Contractor Obligations
Employees and contractors with access to information must:
- Access only authorized information
- Protect confidential information
- Follow company security policies
- Report suspected incidents promptly
- Maintain confidentiality after termination of engagement
Unauthorized access, disclosure, or misuse of information may result in disciplinary action or termination.
19. Policy Changes
DialedIn may modify this Data Handling Policy at any time.
Updated versions shall become effective upon publication or distribution.
Continued use of the Services constitutes acceptance of the revised policy.
