When we process call data for you, the roles are straightforward: you are the controller of the data you submit, and we are your processor. We process it only to provide the service and on your instructions.
What the processing involves
- Purpose: automated analysis of call transcripts to produce scores, evidence excerpts, summaries, and recommendations.
- Types of personal data: identifiers (names, email addresses) and the content of conversations in transcripts; account email; usage metadata.
- Data subjects: your representatives/employees and the other participants on the analyzed calls (e.g. prospects, customers); your account users.
- Duration: for the term of your use of the service.
What we store (data minimization)
We do not store full transcripts. We retain derived analysis (scores, confidence, short verbatim evidence excerpts, summaries, recommendations) in a cache keyed to a one-way cryptographic hash of the transcript, kept indefinitely (no automatic expiry) and deleted on request; scorecard templates under your account; hashed-email usage counters; a scores-only rep-performance history (up to 24 months) if trends are on; and, if you turn on Report History (auto-save, off by default), the full derived report in Cloudflare storage (including customer/company names and short call excerpts) until you delete it. Logs contain no transcript content.
At a glance:
| Data | Stored? | How long |
|---|---|---|
| Full call transcript | No | In memory only |
| Derived analysis (scores + short excerpts) | Yes, keyed to a one-way hash | Indefinite (no auto-expiry); deleted on request |
| Saved reports (History / auto-save, off by default) | Yes, on Cloudflare (incl. customer names + excerpts) | Until you delete or close the account |
| Rep performance trends (scores only, per rep) | Yes, if trends are on (on by default for new accounts) | Up to 24 months |
| Scorecard templates | Yes | Until you delete them |
| Application logs | Yes (no call content) | Limited operational retention |
Sub-processors
| Sub-processor | Role | Location |
|---|---|---|
| Cloudflare, Inc. | Hosting, database, and storage | US / global edge |
| AI model provider (US) | AI scoring of transcripts | US |
| Cloudflare Email Routing | Lead notifications and report-copy emails | Recipient email, report content |
| Clerk (sign-in) | Sign-in / authentication | Account email, authentication state |
We hold a data-protection agreement with each sub-processor imposing obligations no less protective than those we offer you, and we'll give notice before adding or replacing one.
Security measures
- Encryption of data in transit (TLS) and at rest.
- Identity-based access control; least privilege.
- No storage of full transcripts; logs exclude transcript content and model output.
- Prompt-injection input filtering and output validation ("output gate").
- Rate limiting, daily quotas, and anomaly lockout.
- Reputable, SOC 2-audited sub-processors.
Assistance, breaches, deletion
- We reasonably assist you with data-subject requests and your security and impact-assessment obligations.
- We notify you without undue delay after becoming aware of a personal-data breach affecting your data.
- On termination or request, we delete or return your data. Full transcripts are never stored; the derived-analysis cache, any saved reports (History), and the rep-trend history are deleted on request or account closure.
International transfers
Where we transfer personal data across borders, we rely on a valid transfer mechanism (e.g. EU Standard Contractual Clauses), set out in the formal DPA.
Requesting the formal DPA
If your organization requires a signed DPA, contact support@studio-moneyball.io and we'll provide one for execution.