Security · GDPR in practice

Security and GDPR, without badges we have not earned

An AI voice agent talks to people on behalf of your company, so their data matters. Here is what we can say concretely about who is responsible for what, where the data sits and which measures are in place today, worded as in the data processing agreement (DPA) (in Romanian).

Updated 2 October 2026

Who is responsible for the data in a call? Two parties, different roles

For the calls the agent makes or receives on behalf of your company, you are the controller: you decide whom to call, why, what the agent says and what happens with the outcome. CyberSkill S.R.L., the company behind AgentVocal AI, is the processor (Article 28 GDPR): we provide the technology and process data only on your instructions, meaning your configuration in the platform and the data processing agreement you accept when you sign up.

We have a second, separate role too: controller for the data of visitors to this website, of people who request registration, and for billing data. Both roles are explained in the Privacy Policy (in Romanian), and cookies are described in the Cookie Policy (in Romanian).

In practice, your call data stays yours. We do not use it for anything other than providing you with the service.

Where the data is and who can see it

Hosted in Romania

Calls, recordings, transcripts and contact lists are hosted on servers in Romania.

Each customer in its own space

Every call, list and campaign belongs to a single customer. Recordings have no public links: they can only be played from a signed-in session of the company that owns the call.

You see everything

Each call has a recording (if you have enabled it), a transcript and a summary in the portal. You can follow what was said, not just what was decided.

What happens with the recording and the person called?

Call recording is your choice. If you switch it on, the agent has to be configured to tell the person at the start of the call that the conversation is being recorded, before asking for or receiving any information. You approve the wording of the notice and you are responsible for it, as the DPA requires.

The agent introduces itself as your company's virtual assistant and does not pretend to be a person. We recommend this, and for the person called it is also the most honest way to start a conversation.

What data goes into lists You decide what a contact list contains: usually a name and phone number, perhaps an order or case number and other fields the call needs. Keep only what the agent really needs to know. Special category data (health data, for example) should not be requested by the agent or uploaded to the platform, unless we have agreed otherwise in writing after an assessment. The details are in the DPA (in Romanian).

"Do not call me again" really means no A person can say at any time, even to the agent, that they no longer want to be contacted. The number goes onto the restriction list, and the list is checked before every call, SMS or WhatsApp message sent automatically. You manage the list in the platform.

Data subject rights, in practice

The people you call have the rights set out in the GDPR: access, rectification, erasure, restriction, portability and objection. Because your company is the controller, they will normally contact you, and we help you reply on time.

In the portal you can review recordings and transcripts and restrict numbers. For operations you cannot do yourself, such as permanently deleting a recording or extracting all of one person's data, we do them at your written request. If a person writes to us directly at contact@agentvocalai.ro, we pass the request on to the company on whose behalf the agent spoke.

Account access and technical measures

These are the measures from Annex 2 of the DPA that are in place today.

Individual accounts

Access is only through a personal account. Passwords are stored as hashes, not in plain text, and repeated failed sign-in attempts are blocked.

Two-step verification

A one-time code by SMS, available for administrator accounts and, at your request, for all your colleagues. Trusted devices are remembered for 30 days at most.

Audit log

Sign-ins, changes made in the portal and access to recordings are logged. When our team enters your account for support, the actions are clearly marked as such.

Encrypted connections

All traffic to the platform uses HTTPS. The credentials for connecting to your systems (email, SMS, telephony) are stored encrypted.

How long is data kept and what happens at the end?

Recordings, transcripts and lists are kept for the period you set as controller, and no longer than the term of the contract. You can ask for specific data to be deleted at any time. When the service ends, we return your data in a structured format or delete it, in line with the DPA (in Romanian); the exact deadlines are set out there. The data needed for billing (the date, duration and cost of calls, without the content of the conversations) we keep as a controller, for tax obligations.

Technical providers (sub-processors) To work, the service uses technical providers in categories such as hosting, voice and artificial intelligence processing, messaging and email. The data is hosted in Romania; for some categories, processing may take place outside the European Economic Area, only with the safeguards the GDPR requires. You receive the named, up-to-date list on written request at contact@agentvocalai.ro, and we tell you about important changes in advance.

Who does what: how responsibilities are shared

Security is not only the platform's job. This is how we divide things up.

CriterionWhat the platform doesWhat you doWhat we do together
Access and accountsIndividual accounts, passwords stored as hashes, blocking of repeated attempts, two-step verification by SMS, audit logYou give access only to those who need it, keep passwords confidential and ask for two-step verification for colleaguesWe review active accounts together when your team changes
Informing the personThe agent can say at the start of the call that it is a virtual assistant and that the conversation is recordedYou approve the wording of the notice and decide whether calls are recordedWe settle the right wording for your sector during setup
Data in listsEach list belongs to a single customer; recordings have no public linksYou choose what data to upload and take care not to upload special categoriesWe check the fields the call needs before launch
Do not call me againChecks the restriction list before calls, SMS and WhatsAppYou maintain the list and add requests received through other channelsWe test together that a restricted number is no longer contacted
Requests from individualsA portal with recordings and transcripts, and number restrictionYou reply to the person, as controller, within the legal deadlinePermanent deletion or extraction of one person's data is done by us, at your written request
IncidentsWe tell you without undue delay if your data is affectedYou notify the authority and the individuals where requiredWe work together on the assessment and the fix

How to report a vulnerability

If you have found a security problem, write to us at contact@agentvocalai.ro with the steps to reproduce it. Our contact details are also published in the standard security.txt file. Please do not access other people's data, and please do not publish the issue before we have had a chance to fix it. For how everything fits together, see How it works; for what we connect to your systems, see Integrations.

Frequently asked questions

Is call data stored in Romania?

Yes, calls, recordings, transcripts and lists are hosted on servers in Romania. Some technical providers, in categories such as voice and artificial intelligence processing or messaging, may also process data outside the EEA, only with the safeguards the GDPR requires. You receive the named list on request at contact@agentvocalai.ro.

Who is the controller of the data of the people called?

Your company, on whose behalf the agent speaks. CyberSkill S.R.L. is the processor and handles the data on your instructions and under the data processing agreement (in Romanian). For the data of website visitors and of people requesting registration, CyberSkill is the controller.

Do I have to tell the person the call is being recorded?

Yes. If you switch recording on, the agent is configured to tell the person at the start of the call. You approve the wording, and we help you draft it during setup.

What happens if someone says "do not call me again"?

The number goes onto the restriction list. The list is checked before every automatic call, SMS or WhatsApp message, and you can manage it from the portal.

Do you have security certifications?

We do not claim any certification. Instead we show you the concrete measures in the data processing agreement: individual accounts, hashed passwords, two-step verification by SMS, an audit log, separation between customers and encrypted connections.

Hear it, then decide.

Sign up, see the estimated cost in the form and test the agent on your own phone before it calls anyone.