Legal

Privacy Policy

Legal operator: Demetris Demetriou, trading as DD Cyprus1Click. Parakalo.ai is a service and trading brand operated by DD Cyprus1Click; it is not a separate company or tax entity.

1. Who is responsible

For caller conversations, the business receiving the call normally determines why the data is used and acts as the data controller. DD Cyprus1Click processes that call data for the business under its instructions. Demetris Demetriou, trading as DD Cyprus1Click, acts as controller for account administration, setup requests, service security, support, billing records and website communications relating to Parakalo.ai.

2. Data we process

3. AI and telephone transparency

Every Parakalo call begins with a server-controlled notice that the caller is interacting with an AI receptionist and that the call is transcribed. The current production integration creates a transcript for handling the request, producing a summary and carrying out permitted actions. It does not create a replayable audio recording. A customer cannot remove the mandatory AI and transcription notice from a receptionist greeting.

4. Purposes and legal bases

We use account and service data to provide the contracted service, secure and operate the platform, respond to support, meet legal obligations and protect legitimate interests in preventing misuse and maintaining reliable services. Each customer business is responsible for identifying and documenting the appropriate legal basis for its handling of caller data, including any special-category data it chooses to collect.

5. Service providers and recipients

Data is available to authorised users of the relevant business and to Parakalo personnel who need it for support, security or service operation. Necessary data may be handled by voice/AI and transcription infrastructure, telecommunications carriers, hosting and backup infrastructure, and transactional email providers. Current core call processing uses OpenAI voice/AI services and Zadarma telecommunications routing. We may also disclose information where required by law or necessary to protect legal rights.

6. Google Calendar data

A venue administrator may choose to connect a Google account and select a writable Google Calendar. Parakalo requests the connected account email, calendar-list metadata and access level, and event access for the selected calendar. We use this access only to show the connected account and available calendars, create and maintain Parakalo appointment events, read busy times to prevent double booking, and reconcile supported time changes or cancellations made in Google Calendar.

Parakalo stores the connected account email; selected calendar identifier, name and timezone; encrypted OAuth access and refresh tokens; Google event identifiers linked to Parakalo appointments; and synchronization status and audit history. Events not created by Parakalo are checked transiently for time, status and availability conflicts and their content is not retained as an appointment or used for advertising. Google Calendar data is not sold, used for advertising, or used to train general-purpose or personalised AI models.

Access is limited to providing the visible calendar and appointment features requested by the connected venue. Our use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including its Limited Use requirements. Data is disclosed only to authorised users and infrastructure providers necessary to operate and secure these features, or where legally required.

A venue can disconnect under Workspace → Integrations. Parakalo then attempts to revoke the Google token and deletes its locally stored access and refresh tokens. Existing events already created in Google are left in that calendar so the venue does not unexpectedly lose its records. The venue may also revoke access from its Google Account. Internal appointments and audit records follow the ordinary retention and legal requirements described below. Requests concerning stored account data may be sent to privacy@parakalo.ai.

7. International processing

Some service providers may process data outside Cyprus or the European Economic Area. Where required, Parakalo and its customers must use an applicable transfer mechanism and appropriate safeguards. Deployment region does not by itself replace a transfer assessment.

8. Retention

Customer businesses select a call-content retention period from 7 to 365 days. At expiry, Parakalo removes transcripts, summaries, extracted content and translations while retaining limited operational totals needed for security, accounting and service reliability. Workflow, account, audit and legal records may follow separate retention periods based on their purpose. Backups expire under a controlled recovery schedule and are not used as ordinary production data.

9. Your rights

Depending on the circumstances, individuals may have rights of access, correction, erasure, restriction, objection, portability and withdrawal of consent. Callers should first contact the business they called, using its stated privacy contact. Account users may contact privacy@parakalo.ai. Individuals may also complain to the Cyprus Commissioner for Personal Data Protection or another competent supervisory authority.

10. Security

Controls include tenant isolation, role-based access, mandatory two-factor authentication for platform administrators, encrypted provider settings and OAuth tokens, signed webhooks, action allowlists, audit logs, retention jobs, verified backups and restricted recovery procedures. No online system can guarantee absolute security.

11. Contact and changes

Privacy enquiries: privacy@parakalo.ai. General enquiries: hello@parakalo.ai. Material changes will be posted here with a new effective date.

← Back to Parakalo.ai