Legal
Privacy Policy
Effective and last updated: 31 August 2026
Legal operator: Demetris Demetriou, trading as DD Cyprus1Click. Parakalo.ai is a service and trading brand operated by DD Cyprus1Click; it is not a separate company or tax entity.
This policy explains how DD Cyprus1Click, operating the Parakalo.ai service, handles personal data for its website, customer accounts and AI telephone-reception service. A business using Parakalo must also provide information about its own purposes and legal basis for handling caller data.
1. Who is responsible
For caller conversations, the business receiving the call normally determines why the data is used and acts as the data controller. DD Cyprus1Click processes that call data for the business under its instructions. Demetris Demetriou, trading as DD Cyprus1Click, acts as controller for account administration, setup requests, service security, support, billing records and website communications relating to Parakalo.ai.
2. Data we process
- Account and business details, including names, email addresses, telephone numbers, roles and configuration.
- Call information, including caller number when presented, destination, timestamps, duration, language, transcript, summary, stated contact details and requested actions.
- Structured workflow records such as callback messages, leads, contacts, appointments and notification delivery status.
- Technical and security information such as login records, IP address, webhook events, provider identifiers, audit history and operational errors.
- Support requests and communications sent to us.
3. AI and telephone transparency
Every Parakalo call begins with a server-controlled notice that the caller is interacting with an AI receptionist and that the call is transcribed. The current production integration creates a transcript for handling the request, producing a summary and carrying out permitted actions. It does not create a replayable audio recording. A customer cannot remove the mandatory AI and transcription notice from a receptionist greeting.
4. Purposes and legal bases
We use account and service data to provide the contracted service, secure and operate the platform, respond to support, meet legal obligations and protect legitimate interests in preventing misuse and maintaining reliable services. Each customer business is responsible for identifying and documenting the appropriate legal basis for its handling of caller data, including any special-category data it chooses to collect.
5. Service providers and recipients
Data is available to authorised users of the relevant business and to Parakalo personnel who need it for support, security or service operation. Necessary data may be handled by voice/AI and transcription infrastructure, telecommunications carriers, hosting and backup infrastructure, and transactional email providers. Current core call processing uses OpenAI voice/AI services and Zadarma telecommunications routing. We may also disclose information where required by law or necessary to protect legal rights.
6. Google Calendar data
A venue administrator may choose to connect a Google account and select a writable Google Calendar. Parakalo requests the connected account email, calendar-list metadata and access level, and event access for the selected calendar. We use this access only to show the connected account and available calendars, create and maintain Parakalo appointment events, read busy times to prevent double booking, and reconcile supported time changes or cancellations made in Google Calendar.
Parakalo stores the connected account email; selected calendar identifier, name and timezone; encrypted OAuth access and refresh tokens; Google event identifiers linked to Parakalo appointments; and synchronization status and audit history. Events not created by Parakalo are checked transiently for time, status and availability conflicts and their content is not retained as an appointment or used for advertising. Google Calendar data is not sold, used for advertising, or used to train general-purpose or personalised AI models.
Access is limited to providing the visible calendar and appointment features requested by the connected venue. Our use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including its Limited Use requirements. Data is disclosed only to authorised users and infrastructure providers necessary to operate and secure these features, or where legally required.
A venue can disconnect under Workspace → Integrations. Parakalo then attempts to revoke the Google token and deletes its locally stored access and refresh tokens. Existing events already created in Google are left in that calendar so the venue does not unexpectedly lose its records. The venue may also revoke access from its Google Account. Internal appointments and audit records follow the ordinary retention and legal requirements described below. Requests concerning stored account data may be sent to privacy@parakalo.ai.
7. International processing
Some service providers may process data outside Cyprus or the European Economic Area. Where required, Parakalo and its customers must use an applicable transfer mechanism and appropriate safeguards. Deployment region does not by itself replace a transfer assessment.
8. Retention
Customer businesses select a call-content retention period from 7 to 365 days. At expiry, Parakalo removes transcripts, summaries, extracted content and translations while retaining limited operational totals needed for security, accounting and service reliability. Workflow, account, audit and legal records may follow separate retention periods based on their purpose. Backups expire under a controlled recovery schedule and are not used as ordinary production data.
9. Your rights
Depending on the circumstances, individuals may have rights of access, correction, erasure, restriction, objection, portability and withdrawal of consent. Callers should first contact the business they called, using its stated privacy contact. Account users may contact privacy@parakalo.ai. Individuals may also complain to the Cyprus Commissioner for Personal Data Protection or another competent supervisory authority.
10. Security
Controls include tenant isolation, role-based access, mandatory two-factor authentication for platform administrators, encrypted provider settings and OAuth tokens, signed webhooks, action allowlists, audit logs, retention jobs, verified backups and restricted recovery procedures. No online system can guarantee absolute security.
11. Contact and changes
Privacy enquiries: privacy@parakalo.ai. General enquiries: hello@parakalo.ai. Material changes will be posted here with a new effective date.
← Back to Parakalo.ai