Privacy policy
How CloudDialer handles your data and your customers' data. Last updated 1 July 2026.
Data controller
Riot Tool ApS (CloudDialer) is the data controller for the personal data we process about visitors to our website and users of our service. Contact us at hello@clouddialer.net with questions or to exercise your rights. For the customer and lead data your organization enters into CloudDialer, your organization is the controller and we act as processor — see our data processing agreement.
What data we process
Account details (name, email, phone number, organization), payment and billing details, usage data (logins, in-product actions, technical logs), and enquiries via forms and email. If your organization uses the dialer, we also process call metadata and — where the feature is enabled — call recordings and transcriptions.
Purposes and legal bases
We process this data to deliver and invoice the service (contract, GDPR art. 6(1)(b)), to improve and secure the platform and prevent abuse (legitimate interest, art. 6(1)(f)), to comply with bookkeeping and tax law (legal obligation, art. 6(1)(c)), and for marketing where you have consented (art. 6(1)(a)).
Processors and disclosure
We use a limited number of sub-suppliers to run the service, e.g. hosting, payment processing (Stripe), SMS delivery and transcription. All are bound by data processing agreements. Where a supplier is located outside the EU/EEA, the transfer is safeguarded by the EU Commission's standard contractual clauses or an equivalent valid transfer mechanism. We never sell personal data.
Retention
Account data is kept while your account is active and deleted or anonymized no later than 12 months after the account is closed, unless legislation requires longer retention (e.g. 5 years for invoice data under the Danish Bookkeeping Act). Call recordings are retained according to your organization's settings.
Your rights
You have the right to access, rectification, erasure, restriction of processing, data portability and objection. Consent can be withdrawn at any time. Write to hello@clouddialer.net and we will respond within one month at the latest. You can also complain to the Danish Data Protection Agency (Datatilsynet), Carl Jacobsens Vej 35, 2500 Valby, www.datatilsynet.dk.
Security
All traffic is encrypted (TLS), data is encrypted at rest in EU-based data centres, access is role-based and logged, and each organization's data is logically separated from others. In case of a personal data breach we notify affected customers and the supervisory authority in accordance with the GDPR.