Data Processing Agreement
Last updated: 30 June 2026
This page summarises how Dialed processes personal data on behalf of customers and the sub-processors we engage. It supplements our Privacy Policy and Terms of Service. Enterprise and Team customers may request a signed Data Processing Agreement (DPA) covering Article 28 GDPR requirements.
Roles: controller and processor
For individual and self-serve accounts, Dialed acts as the data controller for account, billing, and platform usage data. You act as the controller (or joint controller, depending on your jurisdiction and employment relationship) for call recordings and any personal data contained in uploaded calls — including prospect and customer voices.
For Team and enterprise deployments where Dialed processes call content solely on your documented instructions, Dialed may act as a data processor and you as the data controller. The specific role is defined in your order form or signed DPA.
Processing activities
When you use Dialed, we process personal data to:
- Store and retrieve call recordings you upload.
- Transcribe audio via Deepgram.
- Generate AI reviews and coaching via Anthropic models.
- Deliver results through the Dialed application hosted on Vercel.
- Persist data in Supabase-managed infrastructure.
- Process subscription payments through Stripe.
- Run background jobs (e.g. review pipeline, notifications) via Inngest.
- Sync Discord community access when you link your account.
- Monitor errors via Sentry and enforce rate limits via Upstash.
Sub-processors
We use the following sub-processors to deliver the Service. We impose data protection obligations on each through written agreements and review this list periodically. Material changes will be notified to enterprise customers in accordance with their DPA.
| Sub-processor | Purpose | Location | Data processed |
|---|---|---|---|
| Supabase | PostgreSQL database, authentication, and call recording storage | EU / US (region-dependent) | Account data, call recordings, transcripts, reviews |
| Deepgram | Speech-to-text transcription with speaker diarisation | United States | Call audio files |
| Anthropic | AI analysis, coaching, and transcript compression | United States | Call transcripts and derived coaching content |
| Stripe | Payment processing and subscription billing | EU / US | Billing name, email, payment method metadata |
| Discord | Community access and verified-role sync | United States | Discord user ID, linked account metadata |
| Resend | Transactional email delivery | United States | Email address, notification content |
| PostHog | Product analytics (where consented) | EU / US | Pseudonymous usage events and page views |
| Sentry | Error monitoring and application stability diagnostics | United States | Error reports, stack traces, request metadata |
| Upstash | Caching and rate limiting | EU / US | IP addresses, rate-limit counters |
| Inngest | Background job processing | United States | Job payloads (e.g. call IDs, user IDs for processing steps) |
| Vercel | Application hosting, serverless functions, CDN | Global edge network | Request logs, IP addresses, application payloads in transit |
Security measures
We implement measures appropriate to the risk, including encryption in transit (TLS), access controls, authenticated API access, and environment separation. Call recordings are stored in dedicated storage buckets with restricted access. Production access is limited to authorised personnel on a need-to-know basis.
International transfers
Where personal data is transferred outside the EEA or UK, we rely on Standard Contractual Clauses, adequacy decisions, or other lawful transfer mechanisms as required by GDPR and UK GDPR. Details are available in our signed DPA on request.
Data subject requests
End users may contact privacy@usedialed.io to exercise access, deletion, or other rights. Enterprise customers who act as controllers should direct us via their account representative; we will assist within the timelines required by applicable law and your DPA.
Request a DPA
Team and enterprise customers may request a Data Processing Agreement that includes sub-processor terms, audit provisions, and breach notification commitments. Email legal@usedialed.io with your company name, billing contact, and estimated seat count. We typically respond within five business days with our standard DPA or redline process.
Contact
Data protection: privacy@usedialed.io
Legal / DPA requests: legal@usedialed.io