Legal
Privacy Policy
Last updated: 20 April 2026 • Version 4.0
This policy is available in Dutch and English. In the event of any discrepancy between the two versions, the Dutch version prevails.
Ajora is a call intelligence service operated by Ajora B.V., a Dutch besloten vennootschap (private limited company) registered in the Handelsregister under KvK number 42138300, with its registered office at Poortstraat 28, 3572 HJ Utrecht, the Netherlands. In this policy, "Ajora", "we", and "us" refer to Ajora B.V. We can be reached at [email protected].
About This Policy & Our Role
This policy explains how Ajora B.V. processes personal data in connection with the Ajora service. It covers three categories of data subjects:
- Account holders: customers who have registered for an Ajora account.
- Call participants: other parties on a telephone call recorded by an account holder.
- Website visitors: visitors to ajora.io, including those without an account. We process their IP address and browser data in order to display and secure the site, along with whatever you enter in the contact form. Legal basis: legitimate interest (Article 6(1)(f) GDPR) in a working and secure website; for the contact form, acting on your request. We keep contact form messages no longer than we need to handle your question.
Our role differs depending on the data:
As data controller, we determine the purposes and means of processing for account data, billing data, and usage logs. This policy applies directly to that processing.
As data processor, we act on behalf of the account holder (our customer) for the content of recorded calls, including audio, transcripts, and AI-generated summaries. The account holder is the data controller for call content and is responsible for establishing a valid legal basis for recording calls and for informing other parties to the call. Our Data Processing Agreement, available at ajora.io/dpa, governs this relationship.
Data Protection Officer: Ajora B.V. has not appointed a Data Protection Officer, as our processing activities do not meet the thresholds set out in GDPR Article 37. For all privacy-related matters, contact [email protected].
1. Data We Collect & Legal Basis
Account data
When you register, we collect your email address, name, and a hashed password. We also store your verified phone number after you complete phone verification. Legal basis: contract performance (Article 6(1)(b) GDPR).
Call metadata
For each recorded call, we store the date, time, duration, and the phone number that initiated the call. Legal basis: processed on behalf of the account holder under a Data Processing Agreement.
Call transcripts & summaries
We generate and store an encrypted written transcript of your recorded calls, along with an AI-generated summary, action points, key decisions, and sentiment assessment. These are stored for the lifetime of your account and encrypted with a key tied to your account. Legal basis: processed on behalf of the account holder under a Data Processing Agreement.
Call audio
Call audio is captured during the call and transmitted to our transcription service. Audio is deleted from Ajora's systems immediately after the transcript is generated. ElevenLabs may retain audio in backup systems for up to 30 days per their data retention policy, after which it is permanently deleted. Audio is never accessible through the Ajora application after transcription. Legal basis: processed on behalf of the account holder under a Data Processing Agreement.
Usage data
We collect technical logs including IP addresses, timestamps, and API response codes for security and operational purposes. Legal basis: legitimate interest (Article 6(1)(f) GDPR) in maintaining service security and reliability.
Automated decision-making
The AI-generated summaries, action points, and sentiment assessments are decision-support outputs intended for the account holder's reference. They do not constitute automated decision-making within the meaning of GDPR Article 22, and no automated decisions with legal or similarly significant effects are taken based on this output.
2. Third-Party Processors
We use the following third-party processors to deliver our service. Each has signed a Data Processing Agreement with us and is contractually bound to process your data only on our instructions.
Note on AI training: We have explicitly opted out of all data training features with our AI and transcription providers. Your data (audio, transcripts, metadata) is never used to train Large Language Models.
Twilio Inc. (United States)
Purpose: Routing and recording of phone calls. Phone numbers and call audio are processed by Twilio. Audio is deleted from Twilio's systems immediately after we retrieve it. Data transfer safeguard: EU-US Data Privacy Framework (DPF-certified). DPA: twilio.com/legal/data-protection-addendum
ElevenLabs (United States)
Purpose: Converting call audio to text using their speech-to-text transcription models (currently Scribe v2). Call audio is transmitted to ElevenLabs for transcription and deleted from their active systems immediately after the transcript is returned. ElevenLabs may retain audio in backup systems for up to 30 days per their data retention policy. ElevenLabs does not use your data to train their models. Data transfer safeguard: EU-US Data Privacy Framework (DPF), supplemented by Standard Contractual Clauses. DPA: elevenlabs.io/dpa
Amazon Web Services — Bedrock (Frankfurt, Germany)
Purpose: Generating call summaries, action points, key decisions, and sentiment analysis from transcripts using Claude AI. Transcript content is sent to AWS Bedrock for AI processing. AWS does not use this data to train AI models. Data is processed in the EU (Frankfurt region, eu-central-1). DPA: aws.amazon.com/agreement/data-processing-addendum
Amazon Web Services — KMS (Frankfurt, Germany)
Purpose: Managing per-account encryption keys via AWS Key Management Service. Data is processed in the EU (Frankfurt region, eu-central-1). DPA: aws.amazon.com/agreement/data-processing-addendum
Hetzner Online GmbH (Nuremberg, Germany)
Purpose: Hosting the Ajora application and database. Data is processed in the EU (Nuremberg, Germany). DPA: hetzner.com/legal/dpa
Mollie B.V. (The Netherlands)
Purpose: Processing subscription payments. Billing information including payment details is processed by Mollie. We never see or store your payment details. Data transfer safeguard: N/A: EU processing. DPA: mollie.com/en/privacy
Google Ireland Limited (Google Analytics 4)
Purpose: Analysing website traffic and user behaviour to improve our online presence. Google Analytics collects your IP address for geographic analysis; the IP is discarded after processing and is not stored in GA4's reporting systems. Analytics cookies are set on your device only if you explicitly consent via our cookie banner. No call content, transcripts, or account data is shared with Google Analytics. Data transfer safeguard: EU-US Data Privacy Framework. Data is stored in the EU where possible. Settings: privacy.google.com/businesses/processorterms
Cloudflare, Inc. (United States)
Purpose: Serving and protecting our website. Cloudflare processes visitors' IP addresses and browser data in order to display the site and to block abuse. No call content, transcripts, or account data is processed through Cloudflare. Data transfer safeguard: EU-US Data Privacy Framework, supplemented by Standard Contractual Clauses. DPA: cloudflare.com/cloudflare-customer-dpa
Resend (United States)
Purpose: Delivering the messages you send through the contact form on our website. Your name, email address, subject, and message are processed by Resend in order to deliver the email to us. Data transfer safeguard: EU-US Data Privacy Framework, supplemented by Standard Contractual Clauses. DPA: resend.com/legal/dpa
3. Data Location & International Transfers
Ajora's core infrastructure (application servers and database hosted at Hetzner Nuremberg, Germany, and encryption key management in AWS Frankfurt region, Germany) is located in the European Union. Call transcripts, summaries, metadata, and account data are stored exclusively on this EU infrastructure.
Certain functions of the service require transmission of data to sub-processors located outside the EU. All such transfers are covered by an adequate safeguard under GDPR Chapter V:
| Processor | Location | Safeguard |
|---|---|---|
| AWS (Bedrock, KMS) | EU (Frankfurt) | Data processed in EU |
| Hetzner (Hosting) | EU (Nuremberg) | Data processed in EU |
| Twilio | United States | EU-US Data Privacy Framework |
| ElevenLabs | United States | EU-US Data Privacy Framework |
| Mollie B.V. | The Netherlands | Data processed in EU |
| Google Analytics | EU storage | EU-US Data Privacy Framework |
| Cloudflare (website) | United States | EU-US Data Privacy Framework |
| Resend (contact form) | United States | EU-US Data Privacy Framework |
No personal data is transferred to a country without an adequate safeguard recognised under GDPR.
4. Data Retention
| Data category | Retention period |
|---|---|
| Transcripts and summaries | Lifetime of account. Deleted when account is deleted. |
| Call audio | Deleted from Ajora systems immediately after transcription. Deleted from ElevenLabs backup systems within 30 days. |
| Call metadata (date, duration, number) | Lifetime of account. Deleted when account is deleted. |
| Account data | Retained until account is deleted. |
| Usage logs | 90 days. |
When you delete your account, your encryption key is destroyed first, rendering your transcripts cryptographically inaccessible. All remaining data is permanently erased from our production systems within 30 days and from backup systems within 90 days.
5. Your Rights (GDPR)
As a data subject under GDPR, you have the following rights:
- Right of access — You can request a copy of all personal data we hold about you.
- Right to rectification — You can ask us to correct inaccurate data.
- Right to erasure — You can delete your account at any time from your dashboard. All data is permanently deleted as described in §4.
- Right to data portability — You can request your data in a machine-readable format.
- Right to object — You can object to processing based on legitimate interest (such as usage logs).
- Right to restrict processing — You can ask us to restrict processing while a dispute is resolved.
- Right to withdraw consent — Where processing is based on consent (such as analytics cookies), you can withdraw consent at any time without affecting the lawfulness of prior processing.
To exercise any of these rights, email [email protected]. We will respond within one month (extendable by two months for complex requests). You also have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) at autoriteitpersoonsgegevens.nl.
Note for call participants (non-account holders): If your voice was recorded in a call made using Ajora, the account holder (the person who initiated the recording) is the data controller for your personal data. Requests from call participants regarding access, rectification, or erasure should be directed to the account holder in the first instance. We will assist account holders in honouring such requests.
6. Recording Consent
Ajora records telephone calls initiated by the account holder for the purpose of generating call summaries and transcripts.
When a recording begins, Ajora emits an audible beep as a technical signal that recording has started. This beep signals the start of recording; it does not replace the account holder's obligation to obtain consent.
The account holder is contractually required, under our Terms of Service, to:
- Verbally inform all other parties before recording begins that the call will be recorded and transcribed by Ajora.
- Obtain the consent of all other parties where required by law.
- Comply with all applicable recording and wiretapping laws in the jurisdictions of all parties on the call. Recording laws vary significantly by country (for example, all-party consent requirements in some US states; Article 139a Wetboek van Strafrecht in the Netherlands; equivalent rules across the EU).
- Establish and document a valid legal basis under GDPR Article 6 for processing the personal data of other parties on the call.
- Honour requests from other parties to access, correct, or delete their personal data.
Ajora provides the technical means to record, transcribe, and summarise calls. Using the service without obtaining proper consent or a valid legal basis may expose the account holder to civil and criminal liability. By using Ajora, you confirm that you will comply with all applicable recording laws and will obtain any consent required.
7. Security
We implement the following technical and organisational measures to protect your data:
- All data is encrypted. Business accounts receive their own encryption key per organisation.
- The master keys protecting these data keys are stored in AWS Key Management Service under strict access controls and are never stored in plaintext in our application.
- Access to key material is limited to a small number of authorised personnel and fully logged via AWS CloudTrail.
- All data in transit is encrypted using TLS 1.2 or higher.
- Access to production systems is restricted to authorised personnel, protected by multi-factor authentication, and reviewed periodically.
- Database backups are encrypted at rest and stored in the same EU region.
- All personnel with access to personal data are bound by confidentiality obligations.
- Sub-processors are assessed for appropriate security and privacy controls before onboarding, and DPAs are reviewed on a regular basis.
- We maintain a documented incident response procedure covering detection, containment, forensic review, notification, and post-incident review.
8. Data Breach Notification
If we become aware of a personal data breach that is likely to result in a risk to the rights and freedoms of data subjects, we will notify the Autoriteit Persoonsgegevens within 72 hours in accordance with GDPR Article 33. Where the breach is likely to result in a high risk, we will also notify affected users without undue delay in accordance with Article 34, by email to the address associated with the account.
If you suspect a security incident involving your data, contact [email protected] immediately.
9. Changes to This Policy
We may update this policy to reflect changes in our service, sub-processor stack, or legal requirements. Material changes will be communicated by email to the address associated with your account at least 14 days before they take effect. The current version, effective date, and a summary of changes are always available at ajora.io/privacy.
Sub-processor changes: When we add or replace a sub-processor involved in processing call content, we will notify account holders at least 30 days in advance by email. If you object to a new sub-processor on reasonable grounds, you may terminate your account before the change takes effect.
10. Minimum Age
Ajora is a business tool intended for users aged 18 or older. We do not target minors and do not knowingly collect personal data from users under 18. If you believe a minor has provided personal data to us, contact [email protected] and we will delete it without undue delay.
11. Contact
- For privacy-related questions or to exercise your rights: [email protected]
- For general support: [email protected]
Postal address: Ajora B.V., Poortstraat 28, 3572 HJ Utrecht, the Netherlands.
Response time: within one month for privacy requests; within 2 business days for support.
Ready to upgrade your phone calls?
Your account first, then the app
You set up your account and subscription here on the site. Then you download the app from the App Store or Google Play and log in with the same details.