AI phone assistant
DownloadGitHub266ENDEARZH-HANSHIESFRPTRUIDJATRVIFAKOITPLUKNLROELCSSVHUBGSRDAFISKNBSQHRSL

Privacy policy

What Dpro GmbH does with personal data across three separate things: this website, the Dpro Cloud number service, and the self-hosted Tel-Agent software that sends us nothing at all.

This policy covers three separate things, and the difference between them matters more than anything else on this page.

  1. This website, tel-agent.com. One functional cookie, server logs, a CDN, no analytics.
  2. Dpro Cloud — the number and prepaid-credit service at console.dpro.at, sold and operated by Dpro GmbH. This is the part with an account, a balance, and a regulator.
  3. The Tel-Agent software itself, which is self-hosted. When somebody installs it, they run it on their own machine with their own model keys, and no call, recording or transcript reaches Dpro GmbH. There is nothing for us to describe, which is the point of the project rather than a feature of it.

Most of this page is about (2), because that is where personal data actually accumulates. If you have only read the site and never opened an account, only Part A applies to you.

The short version

This site has no analytics, no tracking pixels, no advertising, no profiling and no consent banner — because there is nothing to consent to beyond what is strictly necessary to serve the page. It sets one cookie, and only when you pick a language yourself.

Dpro Cloud holds what an account and a phone number require and nothing more: who you are, what you paid, which number you hold, and how much of it you used. It never receives the content of your calls or messages. Identity documents required by a number's regulator are passed straight through to the carrier and never stored by us.

We do not sell personal information, we do not share it for advertising, and we do not profile you.

Controller

Dpro GmbH, Wipplingerstraße 20/18, 1010 Vienna, Austria. Email: info@dpro.at · Telephone: +43 676 905 4441

Full company details are in the Impressum. We have not appointed a data protection officer, as we are not required to under Article 37 GDPR.


Part A — This website

What is processed

Server logs

When you open a page, our hosting provider records the technical data any web server receives: IP address, the page requested, date and time, referrer, user agent, and the response status. This is what makes it possible to deliver a page at all and to notice an attack or a fault.

Legal basis: Article 6(1)(f) GDPR — our legitimate interest in operating the site securely and reliably. These logs are not combined with anything else and are not used to build a profile.

Name od-lang
Contains one of en, de, ar — nothing else
Set when you choose a language using the switcher; never on a first visit
Lifetime one year
Attributes path=/, samesite=lax

It exists so that having chosen a language, you are not sent somewhere else by your browser's Accept-Language header on your next visit. It holds no identifier, and it cannot be used to recognise you.

Legal basis: Article 6(1)(a) GDPR — you set it by making a choice. It is also a functional cookie under § 165(3) of the Austrian Telecommunications Act, which is why no banner asks you about it. Deleting it in your browser removes it; the site continues to work.

Nothing is written to localStorage or sessionStorage.

Processors and where the data goes

Recipient What it receives Why
Vercel Inc., USA server log data as above hosting and delivery of the site
Cloudflare, Inc., USA (R2) IP address and user agent, when your browser loads a film frame or an audio file the animation assets on the landing page are served from a CDN rather than from the application server

Both are used under a data processing agreement in accordance with Article 28 GDPR. Both are US companies, so a transfer to a third country takes place; it is covered by the EU standard contractual clauses and the respective provider's certification under the EU-US Data Privacy Framework.

The GitHub API is queried for the repository's star count and milestone — but at build time, from our server, not from your browser. Opening a page here does not contact GitHub unless you click a link to it.

What this site does not do

If you write to the email addresses on this site, we process what you send in order to answer you, on the basis of Article 6(1)(b) or (f) GDPR, and we keep it as long as the correspondence and any statutory retention period require.

The "Get a number" and "Add credit" buttons open Dpro Cloud on a different domain. Following one of them takes you into Part B.


Part B — Dpro Cloud

Dpro Cloud sells a phone number and prepaid credit. Everything below applies once you create an account at console.dpro.at; the API it talks to is tel-api.dpro.at.

Where your data is held

Each workspace has a data region, fixed when the workspace is created and never moved afterwards. It decides where your account, ledger, number and usage records live.

Region Where the data is held Who it is for
EU European Union customers served from our European entity
US United States customers served under the United States offering

As this policy is published, Dpro Cloud creates every workspace in the EU region. The US region is described here because it is part of the service's design and this page is written before it is offered rather than after — the same rule this policy has always followed. When a US region is available, you choose it at sign-up, this page names its provider and location, and nothing already in the EU is moved into it.

Where the carrier holds what, since 8 September 2026. The number itself is provided by Twilio, and Twilio keeps its own records. We have split them deliberately:

We describe this in two parts rather than one because a single sentence would have to be either wrong or vague. The safeguards for the second part are under International transfers below.

Your region does not change which rights you have. Rights under the GDPR and rights under US state privacy law are both set out below, and we apply whichever gives you more.

What is processed, and why

Account and workspace

Data email address, password (stored only as an Argon2id hash, never in readable form), workspace name, region and currency, session records, and the times you signed in
Purpose to give you an account, keep it yours, and keep one customer's workspace out of another's
Legal basis Article 6(1)(b) GDPR — performance of the contract you asked for
Retention for the life of the account, then deleted, except what accounting law requires us to keep

Your email is verified before you can buy anything. A password reset produces a single-use token that expires within an hour and is stored only as a hash.

Payments and credit

Data the amount, the currency, the time, the state of the payment, an invoice, and a reference from the payment processor
Purpose to take payment, hold your prepaid balance, and issue the invoice the law requires
Legal basis Article 6(1)(b) GDPR for the payment; Article 6(1)(c) GDPR for the invoice and its retention
Retention invoices and their ledger entries for seven years, as required by § 132 of the Austrian Federal Fiscal Code

We never see your card. Payment is taken on the processor's own hosted page. Your card number, expiry and security code go to the processor and never reach Dpro Cloud; we receive only the outcome and a reference. Our ledger is append-only by design: entries are never edited or deleted, and a correction is made by a further entry, because that is what an auditable balance requires.

Regulatory compliance documents

Some countries will not issue a phone number until the person or company that will use it has been identified. Austria and Germany both do this. When that applies to the number you are buying, you will be asked for documents such as an identity document and a proof of address.

These documents are not stored by Dpro Cloud. They are transmitted directly to the carrier that performs the regulatory check, in a single request, and are never written to our database, our logs, or any storage of ours. We keep only what we need to show you the state of your registration:

We hold no copy of the document itself, and no member of our staff can retrieve one.

Legal basis Article 6(1)(c) GDPR — a legal obligation on the provider of the number, arising from the telecommunications law of the country the number belongs to. This is not a Dpro choice, and a number cannot be issued without it
Special categories an identity document is not a special category of data under Article 9 GDPR, but it is a national identifier under Article 87 and we treat it accordingly. It is also sensitive personal information under the California Privacy Rights Act; we use it for the single purpose above, which is one of the permitted purposes, and for nothing else
Retention our metadata is deleted when the number is released or the registration is rejected. The document itself is retained by the carrier under its own regulatory obligation; a request about the document content is directed there

Your number and how it is used

Data the number, its country and type, its lifecycle state, the destination you route it to (a SIP address or a phone number), and normalised usage events — when a call or message arrived, how long it lasted, and what it cost
Purpose to give you the number, route it where you asked, meter what you used, and bill it against your credit
Legal basis Article 6(1)(b) GDPR
Retention usage events for as long as needed to bill and reconcile them, and then for the period the carrier's invoice must be reconcilable against — currently seven years where the usage appears on an invoice

We do not receive the content of your calls or messages. Dpro Cloud meters usage from the carrier's usage records. It does not record audio, it does not transcribe anything, and it does not read message bodies. Where a call goes after it reaches your number is your own system, and what happens there is outside this service entirely — see Part C.

The identifier the carrier uses for your account is stored encrypted, in one place, and is never returned by any part of our API.

Security, logging and audit

Data request logs with a correlation identifier, and an audit record of privileged actions and state changes — who did what, and when
Purpose to operate the service safely, investigate a fault or an attack, and be able to show what happened to a balance or a number
Legal basis Article 6(1)(f) GDPR — our legitimate interest in a secure and accountable service, and Article 6(1)(c) where an audit trail is required of us

Our logs are structured and redacted at the point of writing. Authorization headers, keys, payment data, identity documents and raw carrier payloads are excluded by design and this is enforced by automated tests, not by convention.

Recipients

Recipient What it receives Role
Twilio Ireland Limited (EU) / Twilio Inc. (US) the number, its configuration, usage records, and — passed through, not stored by us — your regulatory compliance documents the carrier that provides the number and performs the regulatory check
The payment processor the payment amount and what it needs to take payment, entered by you on its own page taking payment and issuing the receipt
Our hosting provider everything the service stores, as the operator of the machine it runs on hosting
Our mail provider your email address and the message, for verification, password reset and service notices transactional email

Each is engaged under a data processing agreement under Article 28 GDPR, or acts as an independent controller where the law makes it one — the payment processor does, for its own anti-money-laundering and record-keeping duties.

The specific payment processor and hosting provider are named here as soon as they are contracted. This page is updated before the service takes a real payment, not after.

International transfers

A transfer outside the European Economic Area takes place where a recipient above is established outside it, or processes outside it. Every such transfer is covered by the EU standard contractual clauses, and additionally by the recipient's certification under the EU-US Data Privacy Framework where it holds one. We assess each recipient before engaging it and we do not transfer to a country without one of these safeguards.

For a workspace in the US region, the data is held in the United States by design, and that is what choosing the region means. Where an EU or UK individual's data is in that region, the transfer rests on the same safeguards.

The carrier is a partial transfer, and the part that is transferred is not your calls. Since 8 September 2026 every number we provide has its incoming calls processed in Twilio's Dublin region, so the record of a call and the logs made while handling it are created and held in the European Union.

What remains in the United States is the account around them: the pool of numbers, its configuration, our billing and usage records, and the route by which a regulatory registration is submitted. Those are managed by Twilio Inc. in its United States region because Twilio offers them nowhere else. That transfer rests on the standard contractual clauses in our agreement with Twilio and on Twilio's certification under the EU-US Data Privacy Framework.

We should also say what we cannot promise. Twilio states that during the current phase of its regional rollout it does not guarantee that all data remains within a selected region. We rely on the safeguards above for that reason as well, rather than telling you the question does not arise.

How long it is kept

What Kept for
Account and workspace while the account exists
Sessions seven days, or until you sign out
Email verification token 24 hours
Password reset token one hour, single use
Invoices and ledger entries seven years (§ 132 BAO)
Usage events as long as they must remain reconcilable against the carrier's invoice
Compliance metadata deleted on release of the number or rejection of the registration
Compliance document content never held by us
Audit records as long as needed to account for the action, and no longer

Deleting your account removes what we are free to remove. What accounting and telecommunications law requires us to keep, we keep, and nothing more.


Part C — The Tel-Agent software

Tel-Agent is open-source software that you install and run yourself. Dpro GmbH does not operate it, does not host it, and receives nothing from it.

If you run Tel-Agent to handle other people's calls, you are the controller for that processing, and the obligations are yours. A Dpro Cloud number pointed at your installation does not change this: we are the provider of the number, you are the operator of what answers it.


Artificial intelligence

Tel-Agent is an AI product, so the question deserves a direct answer rather than a paragraph of reassurance.

Dpro Cloud contains no artificial intelligence. It sells numbers and holds a balance. It runs no model, performs no inference, generates nothing, and makes no automated decision about you. There is no AI system in it within the meaning of Article 3(1) of Regulation (EU) 2024/1689 (the AI Act), and consequently no provider or deployer obligation arises for us in respect of it.

The AI is in the software you host. When Tel-Agent answers a call, the model runs under your control, with your keys, against the provider you chose. In the AI Act's terms you are the deployer; if you put it in front of the public, the transparency duty in Article 50 — telling a person they are speaking with a machine — is yours to meet, and the software gives you the means to meet it.

Your data is not used to train anything. We do not train models. We do not send your data to a model provider. We have no arrangement, present or planned, under which Dpro Cloud data becomes training material for anyone.

If Dpro Cloud ever offers a hosted agent, speech synthesis, or any other service that performs inference on your behalf, that is a different service with a different legal basis, and this page will describe it before it is switched on.


What we never do


Your rights

Under the GDPR

You have the right to access (Art 15), rectification (Art 16), erasure (Art 17), restriction of processing (Art 18), data portability (Art 20) and to object (Art 21). Where processing rests on consent, you may withdraw it at any time with effect for the future.

Where we rely on legitimate interest, you may object, and we will stop unless we can show compelling grounds that override your interests.

If you are in the United States

Depending on where you live, US state privacy law may give you the right to know what personal information we hold and where it came from, to delete it, to correct it, to obtain a portable copy, to opt out of sale, sharing, or targeted advertising, to limit the use of sensitive personal information, and to appeal a decision we make on such a request. You have the right not to be discriminated against for exercising any of them.

An authorised agent may make a request on your behalf with proof of authority.

Making a request

Write to info@dpro.at. We answer within one month under the GDPR, and within the period the applicable US state law sets, and we may need to verify that the request is really yours before we act on it — for an account, that normally means asking from the address the account uses.

Complaints

You have the right to lodge a complaint with a supervisory authority. The competent authority for us is the Österreichische Datenschutzbehörde, Barichgasse 40-42, 1030 Vienna, dsb.gv.at. If you are in another EU or EEA country you may complain to your own authority instead.

Changes

This policy describes the site and the service as they stand on the date below. If either starts doing something it does not do today, this page changes before that ships, not after. That rule is why the US region and the payment processor are described here as pending rather than quietly added later.

Last updated: 7 September 2026