Diallo

Privacy policy

Last updated: 8 October 2026

This policy explains what personal data Diallo collects, why, how long it is kept, who it is shared with and what rights you have. It applies to our website, to the Diallo dashboard and to the calls our AI agents answer for our customers in the browser, on their websites and apps.

Diallo is operated by Individual Entrepreneur Aleksandra Ilina (identification code 345855906), referred to below as “we”.

1. Who is responsible for your data

We are the data controller for the data of visitors to our website and of the people who use the Diallo dashboard.

When a business (our customer) uses Diallo to answer its calls, that business decides why and how its callers’ data is processed and is the controller of that data. We process it on the business’s behalf, as a processor, under our agreement with it and only on its instructions. If you called a business that uses Diallo, contact that business first about your data; we will help it respond.

2. What data we collect

From visitors to our website:

  • what you enter in the contact form: your name, phone number or Telegram, type of business and language;
  • if you try a demo call: your voice and the conversation with the demo agent, as for any call (see below);
  • technical data needed to serve the site: IP address, browser type, the pages requested and the time, in server logs.

From users of the dashboard:

  • account data: name, email address, language and workspace;
  • a password, stored only as a secure hash, never in readable form;
  • session and security data: sign-in times, IP address and failed sign-in attempts;
  • billing details the business provides for invoices.

From people who call a business that uses Diallo (processed on the business’s behalf):

  • the audio recording of the call and its written transcript;
  • the details the agent is set up to ask for, such as your name, the service you need or a preferred time;
  • appointments made during the call, and a short summary and mood of the call produced automatically after it;
  • technical call data: date, duration, language and how the call ended.

We do not ask for, and ask our customers not to have the agent collect, special categories of data (such as health, beliefs or biometric data used for identification) unless the business has a lawful basis for it and has told its callers.

3. Why we use it, and on what legal basis

  • To answer and handle calls for our customers, and to give them the transcripts, requests and appointments that result — to perform our contract with the business, on its instructions.
  • To create and run your account, sign you in and keep it secure — to perform our contract with you and for our legitimate interest in protecting the service.
  • To reply to a request you send through the website — to take the steps you asked for before a contract, or with your consent.
  • To keep the service working, find and fix faults, prevent abuse and measure call quality — our legitimate interest.
  • To issue invoices and meet accounting and tax obligations — a legal obligation.

We do not sell personal data and do not use it for advertising. We do not use the contents of our customers’ calls to train AI models.

The summary, mood and captured details of a call are produced automatically by an AI model to help the business follow up. They do not produce decisions with legal or similarly significant effects on callers; the business decides what to do with a request.

4. Call recording and AI

Calls answered by Diallo are handled by an AI voice agent, not a person, and are recorded and transcribed. Our customers are responsible for telling their callers this at the start of the call — the agent’s greeting is set up for it — and for having a lawful basis to record. If you do not want to talk to an AI agent or be recorded, you can end the call and contact the business another way.

5. Who we share data with

Only as needed to provide the service, with providers bound by contract to protect the data and use it only on our instructions:

  • hosting of the service and the database — OVHcloud, data centre in Poland (EU);
  • computing for speech recognition and speech synthesis — GPU servers rented through Vast.ai (USA);
  • audio connection for calls in the browser — Daily (USA);
  • language models that generate the agent’s replies and the call summaries — Anthropic and/or Groq (USA);
  • file storage and backups — Cloudflare R2 (EU jurisdiction where available);
  • Google — sign-in with a Google account, and the business’s Google Calendar when it connects one, to put appointments in it.

We may also disclose data where the law requires it, for example at the lawful request of a court or public authority, or to protect our rights. If Individual Entrepreneur Aleksandra Ilina is reorganised or sold, data may pass to the successor under this policy.

6. Transfers outside Georgia

Our servers are in the European Union. Some providers listed above process data in other countries, including the United States. We transfer data abroad only where the destination ensures an adequate level of protection or where appropriate safeguards are in place, such as standard contractual clauses, as required by the Law of Georgia “On Personal Data Protection” and, where it applies, the GDPR.

7. How long we keep data

  • Call recordings — 90 days, then deleted automatically.
  • Transcripts, summaries, requests and appointments — for as long as the business keeps its account, or until the business deletes them.
  • Account data — while the account exists; deleted within 30 days after the account is closed, except what we must keep by law.
  • Website contact requests — up to 12 months, unless they lead to a contract.
  • Invoices and accounting records — for the period required by Georgian tax law.
  • Database backups — 30 days.
  • Server logs — up to 90 days.

8. How we protect data

Connections are encrypted (HTTPS/TLS). Passwords are stored only as hashes. Access to data is limited to people who need it for their work, each business sees only its own workspace, and the servers are protected against unauthorised access and backed up daily. No system is perfectly secure; if a breach affects your data, we will notify the Personal Data Protection Service of Georgia and, where required, you.

9. Your rights

Under the Law of Georgia “On Personal Data Protection” (and the GDPR where it applies), you have the right to:

  • know whether we process your data and get a copy of it;
  • have inaccurate or incomplete data corrected;
  • have your data deleted or its processing restricted;
  • receive your data in a structured, machine-readable form and have it passed to another controller;
  • object to processing based on our legitimate interests;
  • withdraw your consent at any time, where processing is based on consent;
  • not be subject to a decision based solely on automated processing that significantly affects you.

To use these rights, write to envmotion@gmail.com. We may need to confirm your identity. We reply within the time the law sets. If your data was collected during a call to one of our customers, we will pass your request to that business and help it respond.

You can also complain to the Personal Data Protection Service of Georgia (personaldata.ge) or, in the EU, to your local supervisory authority.

10. Cookies

We use only the cookies needed for the service to work: a session cookie that keeps you signed in to the dashboard, and your language choice. We do not use advertising or tracking cookies. If we add analytics, we will update this section first.

11. Children

Diallo is a service for businesses and is not directed at children. We do not knowingly collect data of children under 16. If you believe a child has given us personal data, contact us and we will delete it.

12. Changes to this policy

We may update this policy as the service or the law changes. The date at the top shows the latest version. We will tell dashboard users about significant changes by email or in the dashboard before they take effect.

13. Contact

  • Individual Entrepreneur Aleksandra Ilina, identification code 345855906
  • Email: envmotion@gmail.com
  • Person responsible for personal data protection: Aleksandra Ilina, envmotion@gmail.com