Dialed

Data Processing Agreement

Last updated: 30 June 2026

This page summarises how Dialed processes personal data on behalf of customers and the sub-processors we engage. It supplements our Privacy Policy and Terms of Service. Enterprise and Team customers may request a signed Data Processing Agreement (DPA) covering Article 28 GDPR requirements.

Roles: controller and processor

For individual and self-serve accounts, Dialed acts as the data controller for account, billing, and platform usage data. You act as the controller (or joint controller, depending on your jurisdiction and employment relationship) for call recordings and any personal data contained in uploaded calls — including prospect and customer voices.

For Team and enterprise deployments where Dialed processes call content solely on your documented instructions, Dialed may act as a data processor and you as the data controller. The specific role is defined in your order form or signed DPA.

Processing activities

When you use Dialed, we process personal data to:

  • Store and retrieve call recordings you upload.
  • Transcribe audio via Deepgram.
  • Generate AI reviews and coaching via Anthropic models.
  • Deliver results through the Dialed application hosted on Vercel.
  • Persist data in Supabase-managed infrastructure.
  • Process subscription payments through Stripe.
  • Run background jobs (e.g. review pipeline, notifications) via Inngest.
  • Sync Discord community access when you link your account.
  • Monitor errors via Sentry and enforce rate limits via Upstash.

Sub-processors

We use the following sub-processors to deliver the Service. We impose data protection obligations on each through written agreements and review this list periodically. Material changes will be notified to enterprise customers in accordance with their DPA.

Sub-processorPurposeLocationData processed
SupabasePostgreSQL database, authentication, and call recording storageEU / US (region-dependent)Account data, call recordings, transcripts, reviews
DeepgramSpeech-to-text transcription with speaker diarisationUnited StatesCall audio files
AnthropicAI analysis, coaching, and transcript compressionUnited StatesCall transcripts and derived coaching content
StripePayment processing and subscription billingEU / USBilling name, email, payment method metadata
DiscordCommunity access and verified-role syncUnited StatesDiscord user ID, linked account metadata
ResendTransactional email deliveryUnited StatesEmail address, notification content
PostHogProduct analytics (where consented)EU / USPseudonymous usage events and page views
SentryError monitoring and application stability diagnosticsUnited StatesError reports, stack traces, request metadata
UpstashCaching and rate limitingEU / USIP addresses, rate-limit counters
InngestBackground job processingUnited StatesJob payloads (e.g. call IDs, user IDs for processing steps)
VercelApplication hosting, serverless functions, CDNGlobal edge networkRequest logs, IP addresses, application payloads in transit

Security measures

We implement measures appropriate to the risk, including encryption in transit (TLS), access controls, authenticated API access, and environment separation. Call recordings are stored in dedicated storage buckets with restricted access. Production access is limited to authorised personnel on a need-to-know basis.

International transfers

Where personal data is transferred outside the EEA or UK, we rely on Standard Contractual Clauses, adequacy decisions, or other lawful transfer mechanisms as required by GDPR and UK GDPR. Details are available in our signed DPA on request.

Data subject requests

End users may contact privacy@usedialed.io to exercise access, deletion, or other rights. Enterprise customers who act as controllers should direct us via their account representative; we will assist within the timelines required by applicable law and your DPA.

Request a DPA

Team and enterprise customers may request a Data Processing Agreement that includes sub-processor terms, audit provisions, and breach notification commitments. Email legal@usedialed.io with your company name, billing contact, and estimated seat count. We typically respond within five business days with our standard DPA or redline process.

Contact

Data protection: privacy@usedialed.io
Legal / DPA requests: legal@usedialed.io