This policy covers three separate things, and the difference between them matters more than anything else on this page.
- This website, tel-agent.com. One functional cookie, server logs, a CDN, no analytics.
- Dpro Cloud — the number and prepaid-credit service at
console.dpro.at, sold and operated by Dpro GmbH. This is the part with an account, a balance, and a regulator. - The Tel-Agent software itself, which is self-hosted. When somebody installs it, they run it on their own machine with their own model keys, and no call, recording or transcript reaches Dpro GmbH. There is nothing for us to describe, which is the point of the project rather than a feature of it.
Most of this page is about (2), because that is where personal data actually accumulates. If you have only read the site and never opened an account, only Part A applies to you.
The short version
This site has no analytics, no tracking pixels, no advertising, no profiling and no consent banner — because there is nothing to consent to beyond what is strictly necessary to serve the page. It sets one cookie, and only when you pick a language yourself.
Dpro Cloud holds what an account and a phone number require and nothing more: who you are, what you paid, which number you hold, and how much of it you used. It never receives the content of your calls or messages. Identity documents required by a number's regulator are passed straight through to the carrier and never stored by us.
We do not sell personal information, we do not share it for advertising, and we do not profile you.
Controller
Dpro GmbH, Wipplingerstraße 20/18, 1010 Vienna, Austria. Email: info@dpro.at · Telephone: +43 676 905 4441
Full company details are in the Impressum. We have not appointed a data protection officer, as we are not required to under Article 37 GDPR.
Part A — This website
What is processed
Server logs
When you open a page, our hosting provider records the technical data any web server receives: IP address, the page requested, date and time, referrer, user agent, and the response status. This is what makes it possible to deliver a page at all and to notice an attack or a fault.
Legal basis: Article 6(1)(f) GDPR — our legitimate interest in operating the site securely and reliably. These logs are not combined with anything else and are not used to build a profile.
The language cookie
| Name | od-lang |
| Contains | one of en, de, ar — nothing else |
| Set when | you choose a language using the switcher; never on a first visit |
| Lifetime | one year |
| Attributes | path=/, samesite=lax |
It exists so that having chosen a language, you are not sent somewhere else by your browser's Accept-Language header on your next visit. It holds no identifier, and it cannot be used to recognise you.
Legal basis: Article 6(1)(a) GDPR — you set it by making a choice. It is also a functional cookie under § 165(3) of the Austrian Telecommunications Act, which is why no banner asks you about it. Deleting it in your browser removes it; the site continues to work.
Nothing is written to localStorage or sessionStorage.
Processors and where the data goes
| Recipient | What it receives | Why |
|---|---|---|
| Vercel Inc., USA | server log data as above | hosting and delivery of the site |
| Cloudflare, Inc., USA (R2) | IP address and user agent, when your browser loads a film frame or an audio file | the animation assets on the landing page are served from a CDN rather than from the application server |
Both are used under a data processing agreement in accordance with Article 28 GDPR. Both are US companies, so a transfer to a third country takes place; it is covered by the EU standard contractual clauses and the respective provider's certification under the EU-US Data Privacy Framework.
The GitHub API is queried for the repository's star count and milestone — but at build time, from our server, not from your browser. Opening a page here does not contact GitHub unless you click a link to it.
What this site does not do
- No Google Analytics, Plausible, Matomo, or any other analytics
- No Google Fonts at page load — typefaces are served from this domain
- No embedded videos, maps, social widgets or share buttons
- No advertising network, no retargeting, no fingerprinting
- No newsletter, no automated decision-making or profiling under Article 22 GDPR
If you write to the email addresses on this site, we process what you send in order to answer you, on the basis of Article 6(1)(b) or (f) GDPR, and we keep it as long as the correspondence and any statutory retention period require.
The "Get a number" and "Add credit" buttons open Dpro Cloud on a different domain. Following one of them takes you into Part B.
Part B — Dpro Cloud
Dpro Cloud sells a phone number and prepaid credit. Everything below applies once you create an account at console.dpro.at; the API it talks to is tel-api.dpro.at.
Where your data is held
Each workspace has a data region, fixed when the workspace is created and never moved afterwards. It decides where your account, ledger, number and usage records live.
| Region | Where the data is held | Who it is for |
|---|---|---|
| EU | European Union | customers served from our European entity |
| US | United States | customers served under the United States offering |
As this policy is published, Dpro Cloud creates every workspace in the EU region. The US region is described here because it is part of the service's design and this page is written before it is offered rather than after — the same rule this policy has always followed. When a US region is available, you choose it at sign-up, this page names its provider and location, and nothing already in the EU is moved into it.
Where the carrier holds what, since 8 September 2026. The number itself is provided by Twilio, and Twilio keeps its own records. We have split them deliberately:
- Your calls are processed and stored in the European Union. Every number we provide is configured so that incoming calls are handled in Twilio's Dublin region, which is where the record of the call, and the logs of the requests made while handling it, are then kept.
- The account around them is not. The pool of numbers itself, our billing and usage records, and the regulatory registration route are managed in Twilio's United States region, because that is the only place Twilio offers them. Setting up, changing or releasing your number therefore involves a transfer, and so does the compliance check when a country requires one.
We describe this in two parts rather than one because a single sentence would have to be either wrong or vague. The safeguards for the second part are under International transfers below.
Your region does not change which rights you have. Rights under the GDPR and rights under US state privacy law are both set out below, and we apply whichever gives you more.
What is processed, and why
Account and workspace
| Data | email address, password (stored only as an Argon2id hash, never in readable form), workspace name, region and currency, session records, and the times you signed in |
| Purpose | to give you an account, keep it yours, and keep one customer's workspace out of another's |
| Legal basis | Article 6(1)(b) GDPR — performance of the contract you asked for |
| Retention | for the life of the account, then deleted, except what accounting law requires us to keep |
Your email is verified before you can buy anything. A password reset produces a single-use token that expires within an hour and is stored only as a hash.
Payments and credit
| Data | the amount, the currency, the time, the state of the payment, an invoice, and a reference from the payment processor |
| Purpose | to take payment, hold your prepaid balance, and issue the invoice the law requires |
| Legal basis | Article 6(1)(b) GDPR for the payment; Article 6(1)(c) GDPR for the invoice and its retention |
| Retention | invoices and their ledger entries for seven years, as required by § 132 of the Austrian Federal Fiscal Code |
We never see your card. Payment is taken on the processor's own hosted page. Your card number, expiry and security code go to the processor and never reach Dpro Cloud; we receive only the outcome and a reference. Our ledger is append-only by design: entries are never edited or deleted, and a correction is made by a further entry, because that is what an auditable balance requires.
Regulatory compliance documents
Some countries will not issue a phone number until the person or company that will use it has been identified. Austria and Germany both do this. When that applies to the number you are buying, you will be asked for documents such as an identity document and a proof of address.
These documents are not stored by Dpro Cloud. They are transmitted directly to the carrier that performs the regulatory check, in a single request, and are never written to our database, our logs, or any storage of ours. We keep only what we need to show you the state of your registration:
- the kind of document submitted (for example, "proof of address")
- its size and file type
- the carrier's reference for it
- whether it was approved or rejected, and when
We hold no copy of the document itself, and no member of our staff can retrieve one.
| Legal basis | Article 6(1)(c) GDPR — a legal obligation on the provider of the number, arising from the telecommunications law of the country the number belongs to. This is not a Dpro choice, and a number cannot be issued without it |
| Special categories | an identity document is not a special category of data under Article 9 GDPR, but it is a national identifier under Article 87 and we treat it accordingly. It is also sensitive personal information under the California Privacy Rights Act; we use it for the single purpose above, which is one of the permitted purposes, and for nothing else |
| Retention | our metadata is deleted when the number is released or the registration is rejected. The document itself is retained by the carrier under its own regulatory obligation; a request about the document content is directed there |
Your number and how it is used
| Data | the number, its country and type, its lifecycle state, the destination you route it to (a SIP address or a phone number), and normalised usage events — when a call or message arrived, how long it lasted, and what it cost |
| Purpose | to give you the number, route it where you asked, meter what you used, and bill it against your credit |
| Legal basis | Article 6(1)(b) GDPR |
| Retention | usage events for as long as needed to bill and reconcile them, and then for the period the carrier's invoice must be reconcilable against — currently seven years where the usage appears on an invoice |
We do not receive the content of your calls or messages. Dpro Cloud meters usage from the carrier's usage records. It does not record audio, it does not transcribe anything, and it does not read message bodies. Where a call goes after it reaches your number is your own system, and what happens there is outside this service entirely — see Part C.
The identifier the carrier uses for your account is stored encrypted, in one place, and is never returned by any part of our API.
Security, logging and audit
| Data | request logs with a correlation identifier, and an audit record of privileged actions and state changes — who did what, and when |
| Purpose | to operate the service safely, investigate a fault or an attack, and be able to show what happened to a balance or a number |
| Legal basis | Article 6(1)(f) GDPR — our legitimate interest in a secure and accountable service, and Article 6(1)(c) where an audit trail is required of us |
Our logs are structured and redacted at the point of writing. Authorization headers, keys, payment data, identity documents and raw carrier payloads are excluded by design and this is enforced by automated tests, not by convention.
Recipients
| Recipient | What it receives | Role |
|---|---|---|
| Twilio Ireland Limited (EU) / Twilio Inc. (US) | the number, its configuration, usage records, and — passed through, not stored by us — your regulatory compliance documents | the carrier that provides the number and performs the regulatory check |
| The payment processor | the payment amount and what it needs to take payment, entered by you on its own page | taking payment and issuing the receipt |
| Our hosting provider | everything the service stores, as the operator of the machine it runs on | hosting |
| Our mail provider | your email address and the message, for verification, password reset and service notices | transactional email |
Each is engaged under a data processing agreement under Article 28 GDPR, or acts as an independent controller where the law makes it one — the payment processor does, for its own anti-money-laundering and record-keeping duties.
The specific payment processor and hosting provider are named here as soon as they are contracted. This page is updated before the service takes a real payment, not after.
International transfers
A transfer outside the European Economic Area takes place where a recipient above is established outside it, or processes outside it. Every such transfer is covered by the EU standard contractual clauses, and additionally by the recipient's certification under the EU-US Data Privacy Framework where it holds one. We assess each recipient before engaging it and we do not transfer to a country without one of these safeguards.
For a workspace in the US region, the data is held in the United States by design, and that is what choosing the region means. Where an EU or UK individual's data is in that region, the transfer rests on the same safeguards.
The carrier is a partial transfer, and the part that is transferred is not your calls. Since 8 September 2026 every number we provide has its incoming calls processed in Twilio's Dublin region, so the record of a call and the logs made while handling it are created and held in the European Union.
What remains in the United States is the account around them: the pool of numbers, its configuration, our billing and usage records, and the route by which a regulatory registration is submitted. Those are managed by Twilio Inc. in its United States region because Twilio offers them nowhere else. That transfer rests on the standard contractual clauses in our agreement with Twilio and on Twilio's certification under the EU-US Data Privacy Framework.
We should also say what we cannot promise. Twilio states that during the current phase of its regional rollout it does not guarantee that all data remains within a selected region. We rely on the safeguards above for that reason as well, rather than telling you the question does not arise.
How long it is kept
| What | Kept for |
|---|---|
| Account and workspace | while the account exists |
| Sessions | seven days, or until you sign out |
| Email verification token | 24 hours |
| Password reset token | one hour, single use |
| Invoices and ledger entries | seven years (§ 132 BAO) |
| Usage events | as long as they must remain reconcilable against the carrier's invoice |
| Compliance metadata | deleted on release of the number or rejection of the registration |
| Compliance document content | never held by us |
| Audit records | as long as needed to account for the action, and no longer |
Deleting your account removes what we are free to remove. What accounting and telecommunications law requires us to keep, we keep, and nothing more.
Part C — The Tel-Agent software
Tel-Agent is open-source software that you install and run yourself. Dpro GmbH does not operate it, does not host it, and receives nothing from it.
- Calls, recordings, transcripts and message content stay on your machine.
- The model keys are yours, and the model provider you choose is your own relationship, governed by that provider's terms and privacy policy — not by this page.
- We have no remote access, no telemetry and no update channel that reports anything back.
If you run Tel-Agent to handle other people's calls, you are the controller for that processing, and the obligations are yours. A Dpro Cloud number pointed at your installation does not change this: we are the provider of the number, you are the operator of what answers it.
Artificial intelligence
Tel-Agent is an AI product, so the question deserves a direct answer rather than a paragraph of reassurance.
Dpro Cloud contains no artificial intelligence. It sells numbers and holds a balance. It runs no model, performs no inference, generates nothing, and makes no automated decision about you. There is no AI system in it within the meaning of Article 3(1) of Regulation (EU) 2024/1689 (the AI Act), and consequently no provider or deployer obligation arises for us in respect of it.
The AI is in the software you host. When Tel-Agent answers a call, the model runs under your control, with your keys, against the provider you chose. In the AI Act's terms you are the deployer; if you put it in front of the public, the transparency duty in Article 50 — telling a person they are speaking with a machine — is yours to meet, and the software gives you the means to meet it.
Your data is not used to train anything. We do not train models. We do not send your data to a model provider. We have no arrangement, present or planned, under which Dpro Cloud data becomes training material for anyone.
If Dpro Cloud ever offers a hosted agent, speech synthesis, or any other service that performs inference on your behalf, that is a different service with a different legal basis, and this page will describe it before it is switched on.
What we never do
- We do not sell personal information, and we never have.
- We do not share it for cross-context behavioural advertising.
- We do not profile you, score you, or make any decision about you by automated means alone within the meaning of Article 22 GDPR.
- We do not record, transcribe or listen to your calls.
- We do not retain a copy of your identity documents.
- We do not use your data to train a model.
Your rights
Under the GDPR
You have the right to access (Art 15), rectification (Art 16), erasure (Art 17), restriction of processing (Art 18), data portability (Art 20) and to object (Art 21). Where processing rests on consent, you may withdraw it at any time with effect for the future.
Where we rely on legitimate interest, you may object, and we will stop unless we can show compelling grounds that override your interests.
If you are in the United States
Depending on where you live, US state privacy law may give you the right to know what personal information we hold and where it came from, to delete it, to correct it, to obtain a portable copy, to opt out of sale, sharing, or targeted advertising, to limit the use of sensitive personal information, and to appeal a decision we make on such a request. You have the right not to be discriminated against for exercising any of them.
- We do not sell or share personal information as those terms are defined in the California Consumer Privacy Act as amended, or in any other state statute, so there is nothing to opt out of. There is no "Do Not Sell or Share My Personal Information" link because there is no such processing.
- The only sensitive personal information we ever handle is a regulatory identity document, and we handle it by passing it to the carrier without keeping it. It is used solely to obtain the number you asked for, which is a purpose the statute permits without a right to limit.
- We do not knowingly process the personal information of anyone under 16, and we do not sell it in any case.
- Where we offer numbers in the United States, information about your use of the telecommunications service is customer proprietary network information under 47 U.S.C. § 222, and we use and disclose it only as that section allows.
An authorised agent may make a request on your behalf with proof of authority.
Making a request
Write to info@dpro.at. We answer within one month under the GDPR, and within the period the applicable US state law sets, and we may need to verify that the request is really yours before we act on it — for an account, that normally means asking from the address the account uses.
Complaints
You have the right to lodge a complaint with a supervisory authority. The competent authority for us is the Österreichische Datenschutzbehörde, Barichgasse 40-42, 1030 Vienna, dsb.gv.at. If you are in another EU or EEA country you may complain to your own authority instead.
Changes
This policy describes the site and the service as they stand on the date below. If either starts doing something it does not do today, this page changes before that ships, not after. That rule is why the US region and the payment processor are described here as pending rather than quietly added later.
Last updated: 7 September 2026
