Subject matter and duration
Rinqo processes your customers' data, name, phone number, email, conversation content, appointment details, for the duration of your contract. After termination we delete all personal data within 30 days, unless a statutory retention obligation applies.
Categories of data + data subjects
Categories: contact data, content data (calls, emails, chats), usage data. Data subjects: your customers, prospects, employees interacting with Rinqo. Sensitive data (GDPR Art. 9, e.g. health) only if you explicitly configure that and have a legal basis for it.
Technical and organisational measures
AES-256-GCM encryption for content data at rest, TLS 1.3 in transit, role-based access control, audit log on every write, two-factor authentication for all Rinqo staff, annual penetration tests at minimum. Full TOMs attached to the DPA.
Sub-processors
We use providers with a DPA per GDPR Art. 28 and Standard Contractual Clauses, with processing located in the EU: Hetzner (hosting, DE), Twilio Ireland (telephony), Microsoft Ireland Operations Ltd. (Azure OpenAI Service as primary LLM provider — Sweden Central, Microsoft EU Data Boundary, no training on customer data), KugelAudio GmbH, Hannover, Germany (TTS, EU hosting), Deepgram (STT, EU region), Brevo (email, FR). OVHcloud Roubaix stands by as an opt-in Pure-EU failover provider and only becomes a sub-processor after activation. Note: Deepgram is a US corporation with its own EU region — processing stays in the EU. You receive 30 days' notice before a new sub-processor is added, with right of objection. The full list with legal entities and data types is available in the TIA documentation in the dashboard.
Data subject rights + deletion
We assist you with access, rectification, deletion and portability requests (GDPR Art. 15-20). Via dashboard self-service you can export or delete individual records. On email request we respond within 48 hours.
Incident notification
We notify you of any data protection incidents without undue delay, within 24 hours of becoming aware. Incident reports include: nature of the incident, affected data, actions taken, recommendations for your own Art. 33 GDPR notification to the supervisory authority.
Audit rights
You may audit us once a year, and at any time on concrete cause. On request we provide reports (ISO 27001 in preparation, SOC-2 equivalent). On-site audits with two weeks' notice.