Legal
Privacy
Last updated: September 29, 2026
Controller
ILO APPLICATIONS SL, Spain, is the controller for account, billing, product, and service operation data unless a separate data processing agreement says otherwise. Contact support@calltrin.com for privacy requests.
Personal data we process
We may process account details, authentication data, billing metadata, plan information, assistant settings, phone numbers, call metadata, outbound call objectives, transcripts or recordings where enabled, summaries, follow-ups, owner and sub-owner memories, business knowledge, uploaded file metadata, audit events, support messages, device and log data, and cookies needed to operate secure sessions.
Purposes and legal bases
We use personal data to provide the service, authenticate users, answer and summarize calls, create follow-ups, maintain assistant memory, place owner-authorized outbound calls, provide support, prevent misuse, secure the app, meet legal obligations, and improve reliability. The main GDPR legal bases are contract performance, legitimate interests, legal obligations, and consent where required.
Callers and assistant memory
Trin is designed to disclose that she is AI. Account owners are responsible for informing callers and obtaining any required consent for call forwarding, recording, transcription, or AI-assisted handling. Owner and sub-owner memories are designed to stay separate from public caller behavior and from each other.
Optional call location
For an owner web or mobile call, you can choose to share a one-time approximate location to ask about local weather or nearby places. We use it only for that active call and relevant weather or web-search requests. We do not save the device coordinates in the conversation record or account memory. You can call without location; spoken place names can still appear in the ordinary transcript. Location providers may process the approximate area under their own retention terms.
Processors and transfers
We may use trusted processors for hosting, storage, databases, payment processing, email, phone services, AI infrastructure, analytics, logging, and support. If personal data is transferred outside the European Economic Area, we use appropriate safeguards such as adequacy decisions, standard contractual clauses, or equivalent mechanisms.
Retention and deletion
We keep personal data for as long as needed to provide the service, meet legal obligations, resolve disputes, prevent abuse, and maintain security. Account data, memories, transcripts, summaries, and follow-ups can be deleted or exported where the product supports it or by contacting us, subject to legal and security retention requirements.
Your rights
Depending on the legal basis and circumstances, you may have rights to access, rectify, erase, restrict, port, or object to processing of your personal data, and to withdraw consent where processing is based on consent. You may also lodge a complaint with the Spanish Data Protection Agency or your local supervisory authority.
Security
The app is designed around HTTP-only cookie authentication, CSRF protection for unsafe requests, validated route input, role checks for administrative APIs, controlled error responses, and operational logging. No online service is risk-free, so users should avoid adding unnecessary sensitive data to assistant memory.
Contact
For privacy questions or data requests, contact support@calltrin.com.