Data Retention Policy
This policy describes how long we keep each category of personal data and what the basis/reason for that period is. The policy implements the principles of storage limitation and data minimization set out in Art. 5(1) of Regulation (EU) 2016/679 (GDPR).
1. Vocalyy's roles — controller vs. processor
D.O.D.O. OFFICE OUTLET S.R.L. acts in two distinct legal capacities, depending on the category of data, and the retention periods below must be read with this in mind:
- Controller for our client's own data (contact person, legal representative, billing data, account/authentication data, business communications). For this data, Vocalyy alone determines the purposes and means of processing.
- Processor for the data of our client's callers (the customers, patients, or prospective customers of the business who call or are called through the Vocalyy voice agent). For this data, the Vocalyy client is the controller, and we process it exclusively based on the client's documented instructions, in accordance with Art. 28 GDPR.
Vocalyy does not determine the purposes or legal basis on which our client collects data about its callers. The client, as controller, is responsible for identifying the applicable legal basis (for example, consent, legitimate interest, or performance of a contract), for informing the data subjects (callers), and for obtaining any necessary consent, including for special category data under Art. 9 GDPR or personal numeric code (CNP) data under Law No. 190/2018.
2. Retention periods table
The table below is the single reference for the retention periods used by Vocalyy.
Retention periods are fixed and identical for all clients: 30 days for the audio recording, 12 months for the transcript, the phone number, and the call metadata. The audio recording can be fully disabled, per agent, from the agent's configuration.
| Category | Period | Legal basis / reason |
|---|---|---|
| Caller's phone number | 12 months | Legitimate interest of the client (controller) in the history of the relationship with the caller; Vocalyy's operational necessity as processor |
| Call metadata (date, time, duration) | 12 months | Same as above |
| Full conversation transcript | 12 months | May contain special category data (for example, health data) — requires limited retention and enhanced security under Art. 9 GDPR and Law No. 190/2018 |
| Call audio recording (Supabase Storage, EU/Frankfurt) | 30 days from the date of the call, automatic deletion | Legitimate interest of the client (controller) in quality verification and evidence of the conversation; short period in application of the storage limitation principle, Art. 5(1)(e) GDPR |
| Billing data (Vocalyy client) | 5 years, calculated from 1 July of the year following the end of the financial year in which they were prepared | Art. 25 of Accounting Law No. 82/1991, as amended by Law No. 36/2023 |
| Audit logs | 24 months | Accountability under Art. 5(2) GDPR and investigation of security incidents (Art. 32 GDPR). The period is longer than the retention of caller data (12 months) precisely so we can later demonstrate what happened to that data and when it was deleted. |
| Website/demo data (not client caller data) | 12 months from the last interaction | Data from website forms (demo requests, contact, sign-up). Vocalyy's legitimate interest (Art. 6(1)(f) GDPR) in managing and following up on commercial enquiries. The period restarts on each new contact; if the person becomes a client, the data falls under the “Account data” regime. |
| Cookies | Maximum 13 months (non-essential cookies); for the duration of the session (strictly necessary cookies) | Consent, Art. 6(1)(a) GDPR (for non-essential cookies). The 13-month term is the maximum period recommended at European level for analytics cookies, after which consent must be requested again. |
| Account data (Vocalyy client: name, phone, business, authentication) | For the duration of the contract + 3 years after termination | Performance of the contract, Art. 6(1)(b) GDPR, plus the general 3-year statute of limitations for potential claims (Art. 2517 Civil Code). Accounting documents and invoices are retained separately, per the billing period already indicated above. |
3. Audio recording
The audio recording of every call is stored by Vocalyy, in Supabase Storage, European Union (Frankfurt, Germany), for 30 days from the date of the call. Once that period expires, our copy is automatically and permanently deleted, through a daily cleanup process.
During those 30 days, the client can listen to and download any recording from the Call History section of the dashboard. The downloaded copy remains in the client's possession, on their own device, indefinitely — from the moment of download, the client becomes the sole controller of that copy and is solely responsible for its security, storage, and any further processing.
The audio recording can be fully disabled, per agent, directly from the agent's configuration. Vocalyy does not keep audio beyond the 30 days and does not use it to train any AI model.
4. Automatic deletion
We have automated mechanisms that run periodically to delete data that has exceeded the applicable retention period set out in the table in Section 2. These mechanisms are periodically monitored to confirm correct operation.
5. Deletion at your request (Art. 17 GDPR)
You have the right to request the deletion of your personal data ("the right to be forgotten," Art. 17 GDPR) at any time, through:
- Email to privacy@vocalyy.ro or dpo@vocalyy.ro
- The "Delete account" button in the dashboard (where available)
- Written request to the registered office of D.O.D.O. OFFICE OUTLET S.R.L.
We commit to responding within a maximum of 30 days of receiving the request, in accordance with Art. 12 GDPR.
6. Exceptions to deletion
Under Art. 17(3) GDPR, the right to erasure is not absolute. We cannot delete certain data when there is a legal obligation to retain it, including:
- Billing data — kept for 5 years under Art. 25 of Accounting Law No. 82/1991 (as amended by Law No. 36/2023)
- Data necessary for the establishment, exercise, or defense of a legal claim — until the expiry of the applicable limitation period
- Audit logs — necessary to fulfill security obligations under Art. 32 GDPR
In these cases, we restrict access to the relevant data to authorized personnel only and do not use it for any purpose other than the one that justifies its retention.
7. Physical deletion — the technical cascade
Once triggered, the deletion of a data category propagates through all systems in which it is stored:
- Primary database — deletion from the active system
- Cache and operational logs — removal as soon as reasonably possible
- Backups — removal at the next backup cycle rotation
- Sub-processors — we request corresponding deletion in accordance with the contractual obligations assumed under the Data Processing Agreement (DPA) signed with each sub-processor
8. Audit and verification
The retention policy is reviewed periodically to confirm that the stated periods correspond to actual practice and to the legal obligations in force.
9. Changes to the policy
Any change to this policy will be:
- Published on this page, with the date of the new version
- Communicated to our clients with sufficient advance notice before taking effect, for significant changes
10. Contact
For questions about retention or to request deletion of your data:
- Privacy contact channel: dpo@vocalyy.ro
- Data subject access requests (DSAR): privacy@vocalyy.ro
The address dpo@vocalyy.ro is a privacy contact channel and does not, in itself, imply the formal designation of a Data Protection Officer (DPO) within the meaning of Art. 37 GDPR.
Related pages: Privacy Policy · Sub-processors · About the AI System · Data Processing Agreement (DPA)