Legal

Privacy Policy

Last updated: June 13, 2026 · Effective date: June 13, 2026

This Privacy Policy explains how BroadNet Technologies Ltd ("DialerBee", "we", "our", "us") collects, uses, stores, shares, and protects personal data when you visit our website, use our platform, or interact with our services.

Contents

  1. 01 Who We Are
  2. 02 Data We Collect
  3. 03 How We Collect Data
  4. 04 How We Use Data
  5. 05 Legal Bases for Processing (GDPR)
  6. 06 Data Sharing & Third Parties
  7. 07 International Data Transfers
  8. 08 Data Storage & Security
  9. 09 Data Retention
  10. 10 AI & Automated Processing
  11. 11 Your Rights
  12. 12 Children's Privacy
  13. 13 Cookies & Tracking
  14. 14 Changes to This Policy
  15. 15 Contact Us

1. Who We Are

DialerBee is an AI-powered outbound dialing platform operated by BroadNet Technologies Ltd. We provide outbound dialing software, answering machine detection, campaign management, compliance-supporting controls, and related services to businesses worldwide.

Data Controller: BroadNet Technologies Ltd

Email: privacy@dialerbee.com

Website: www.dialerbee.com

2. Data We Collect

2.1 Data You Provide

  • Account registration: Name, email address, company name, job title, phone number, billing address, and payment information
  • Demo and contact forms: Name, email, company, team size, use case, region, and any additional information you provide
  • Support requests: Information included in support tickets, emails, or chat messages
  • Contractual data: Billing details, contract terms, and authorized user information

2.2 Data Generated Through Platform Use

  • Call records: Call detail records (CDRs) including caller ID, recipient number, call duration, disposition, and timestamps
  • Campaign data: Contact lists, campaign configuration, dialing schedules, and DNC lists uploaded by customers
  • Call recordings: Audio recordings of calls as configured by the customer according to their recording policy and applicable consent requirements
  • AMD classification data: Classification results (human/machine), confidence scores, model version, and agent override status
  • Agent activity data: Login times, call handling metrics, disposition activity, and supervisor coaching events
  • Compliance data: DNC check results, consent records, calling-hour enforcement logs, and audit trail entries

2.3 Data Collected Automatically

  • Technical data: IP address, browser type and version, device type, operating system, screen resolution, and timezone
  • Usage data: Pages visited, features used, session duration, click patterns, and referral sources
  • Cookies and similar technologies: Session cookies, authentication tokens, and analytics identifiers (see Section 13)

3. How We Collect Data

  • Directly from you: When you create an account, submit a form, contact support, or use our platform
  • Automatically: Through cookies, server logs, and platform instrumentation when you visit our website or use our services
  • From your employer or administrator: If your organization creates an account on your behalf
  • From third parties: We may receive business contact data from partners or publicly available business directories for B2B outreach

4. How We Use Data

We process personal data for the following purposes:

Purpose Data Used
Provide and operate the platform Account, call, campaign, agent, and technical data
Process AMD classification Short initial audio segment (first ~3 seconds of call)
Enforce compliance rules Call records, DNC lists, consent records, calling-hour rules
Generate reports and analytics Call records, agent metrics, campaign performance data
Improve platform quality Usage patterns, error logs, performance metrics (aggregated)
Provide customer support Account data, support ticket content, platform logs
Communicate product updates Name and email address
Process billing and payments Billing details and payment information
Comply with legal obligations As required by applicable law
Protect security and prevent fraud Technical data, access logs, authentication records

5. Legal Bases for Processing (GDPR)

For individuals in the European Economic Area (EEA), United Kingdom, or other jurisdictions that require a legal basis for processing, we rely on the following:

  • Contract performance: Processing necessary to provide our services under your subscription agreement
  • Legitimate interests: Improving our platform, preventing fraud, ensuring security, and conducting B2B marketing — where these interests are not overridden by your rights
  • Legal obligation: Processing required to comply with applicable laws, regulations, or court orders
  • Consent: Where we rely on consent (e.g., marketing emails, analytics cookies), you may withdraw consent at any time

6. Data Sharing & Third Parties

We do not sell personal data. We do not rent, trade, or otherwise make personal data available to third parties for their own marketing purposes.

We share data only in the following circumstances:

  • Subprocessors: Third-party service providers that process data on our behalf to operate the platform (see our Subprocessor List)
  • Legal requirements: When required by law, regulation, court order, or governmental authority
  • Business transfers: In connection with a merger, acquisition, or sale of assets — with prior notice to affected customers
  • With your consent: When you explicitly authorize sharing with a specific third party
  • Aggregated data: We may share anonymized, aggregated statistics that cannot identify any individual

7. International Data Transfers

DialerBee operates infrastructure in multiple regions. When personal data is transferred outside of the EEA, we ensure adequate safeguards are in place:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Adequacy decisions where applicable
  • Transfer impact assessments for high-risk transfers
  • Data Processing Agreements with all subprocessors

For details on our subprocessors and their locations, see our Subprocessor List.

8. Data Storage & Security

We implement technical and organizational measures designed to protect personal data:

  • Encryption: TLS 1.2+ for all data in transit. AES-256 encryption for data at rest
  • Access control: Role-based access control (RBAC) with 7 distinct roles. Principle of least privilege
  • Tenant isolation: PostgreSQL Row-Level Security enforced on every tenant table. Automated security testing validates isolation boundaries
  • Audit logging: Append-only audit trail with actor, timestamp, and context for administrative and security-relevant actions
  • Recording security: Signed URLs with 1-hour expiry. No raw path access to recordings
  • Backup: Automated database backups with point-in-time recovery and tested restore procedures
  • Monitoring: Real-time infrastructure monitoring, alerting, and incident response procedures

For full details, see our Trust Center.

9. Data Retention

We retain personal data only as long as necessary for the purposes described in this policy or as required by law.

Data Type Retention Period
Account data Duration of contract + 30 days, or as required by law
Call recordings Configurable per tenant: 30 days (Starter), 90 days (Professional), 1 year (Enterprise). Legal hold exempt from automatic deletion
Call detail records Duration of contract + 90 days
AMD classification results Duration of contract + 30 days
Audit logs Minimum 1 year, configurable up to 7 years
Consent records Duration of contract + period required by applicable regulation
Website analytics 26 months from collection
Support tickets Duration of contract + 1 year

Upon contract termination, customers may request data export or deletion. We will process deletion requests within 30 days, subject to legal retention obligations.

10. AI & Automated Processing

DialerBee uses AI for answering machine detection (AMD). This section explains how AI processes data and your controls:

  • What is processed: A short initial segment of call audio (typically 3 seconds) is transcribed and classified in real time
  • No long-term audio storage: Raw audio used for AMD classification is not stored long-term. Classification results are retained
  • Tenant-scoped tuning: AMD feedback (agent corrections) can be tenant-scoped and governed by customer retention and AI settings. No cross-tenant data sharing by default
  • Human override: Agents can override any AI classification at any time. AI assists; humans decide
  • Opt-out: AI features can be controlled by tenant-level feature flags. Tenants can disable all AI features with a single configuration change
  • No profiling: We do not use AI to make automated decisions that produce legal effects or similarly significant effects on individuals

For full details, see our AI Data Policy.

11. Your Rights

Depending on your jurisdiction, you may have some or all of the following rights:

Access
Request a copy of the personal data we hold about you
Rectification
Request correction of inaccurate or incomplete data
Erasure
Request deletion of your personal data ('right to be forgotten')
Restriction
Request that we restrict processing of your data
Portability
Receive your data in a structured, machine-readable format
Objection
Object to processing based on legitimate interests or direct marketing
Withdraw Consent
Withdraw previously given consent at any time
Lodge Complaint
File a complaint with your local data protection authority

To exercise any of these rights, contact privacy@dialerbee.com. We will respond within 30 days (or sooner where required by law). We may ask you to verify your identity before processing your request.

For UAE Residents (TDRA/PDPL)

If you are located in the United Arab Emirates, you have rights under the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021). Contact us at privacy@dialerbee.com to exercise your rights.

For California Residents (CCPA)

California residents have additional rights under the CCPA, including the right to know, delete, and opt out of the sale of personal information. We do not sell personal information. Contact us at privacy@dialerbee.com for CCPA-specific requests.

12. Children's Privacy

DialerBee is a B2B platform and is not intended for use by individuals under the age of 18. We do not knowingly collect personal data from children. If we learn that we have collected data from a child, we will delete it promptly.

13. Cookies & Tracking

Cookie Type Purpose Required?
Essential Authentication, session management, security Yes
Functional Language preference, UI state Yes
Analytics Usage patterns, page views, performance Consent-based
Marketing Not currently used N/A

You can control cookies through your browser settings. Disabling essential cookies may affect platform functionality.

14. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make material changes:

  • We will update the "Last updated" date at the top of this page
  • We will notify active customers via email at least 30 days before material changes take effect
  • We will provide a summary of changes in the notification

We encourage you to review this page periodically. Continued use of DialerBee after changes take effect constitutes acceptance of the updated policy.

15. Contact Us

For privacy-related inquiries, data subject requests, or questions about this policy:

Privacy inquiries: privacy@dialerbee.com

DPA requests: legal@dialerbee.com

Security issues: security@dialerbee.com

General: hello@dialerbee.com

Related policies & resources