Privacy Policy
Last updated: 19 August 2026
This Privacy Policy describes how CITT («we», «us» or «CITT») collects, uses and protects your personal data when you use our AI voice assistant platform, in accordance with Regulation (EU) 2016/679 (GDPR).
1. Data Controller
The controller of your data is SALIMOV Monoprosopi I.K.E. (SALIMOV Single-Member Private Company), which operates the CITT platform:
- Legal representative: Wladimir Neuberger (CEO)
- Registered office: Katehaki Metochi 1, 71500 Ano Kalessa, Heraklion, Crete, Greece
- General Commercial Registry (GEMI) no.: 172274527000 · Greek tax number (AFM): EL802214800
- Phone: +30 698 5822367 · Website: www.salimov.de
- Email: office@salimov.de
For any matter relating to the protection of your personal data, contact us at: info@citt.gr or office@salimov.de
2. Data We Collect
We collect the following categories of data:
- Account data: Name, business email, business name, phone number, industry sector
- Call data: Caller number, conversation transcript, summary, duration, call outcome, recording URL (where you have given consent)
- Appointments: Names and phone numbers of your customers who book appointments through your AI assistant
- Calendar data (optional Google connection): If you connect your Google Calendar, we store the email address of the Google account, the identifier of the selected calendar and an encrypted refresh token. From the calendar we read the events within a 180-day window from today, so that the AI assistant knows your availability. In addition, when the AI assistant books, changes or cancels an appointment, we create, update or delete the corresponding event in your Google Calendar — but only events the platform itself created; all your other events are only read (see section 6 for the access scope).
- Technical data: IP address, user agent, session cookies
- Payment data: We do not process card details. Payments are made by bank transfer; we retain only the invoicing details (company name, tax number (AFM), competent tax office (DOY), address) and the payment reference of the transfer
3. Legal Basis for Processing (Article 6 GDPR)
- Performance of a contract (Art. 6(1)(b)): We process your data to provide the CITT services you have signed up for
- Consent (Art. 6(1)(a)): Call recording and the sending of marketing emails take place only with your prior consent
- Legitimate interest (Art. 6(1)(f)): For the security of the platform and the prevention of abuse
4. How We Use Data
- Providing, maintaining and improving the AI voice assistant services
- Call analysis to produce insights and reports
- Invoicing and subscription management
- Technical support and service notifications
- Marketing communications (only with your consent)
5. Data Recipients
We do not sell your data. We share it only with the recipients below, and only as far as running the service requires:
- ElevenLabs (USA): Voice AI (processor) — the live call audio, the transcripts, the caller's number, the knowledge documents you upload and the recordings sent for transcription. The transfer rests on the Standard Contractual Clauses in their DPA and on the EU-US Data Privacy Framework.
- Telnyx (USA): VoIP telephony infrastructure and storage of the call recordings (processor) — the audio of recorded calls stays on Telnyx infrastructure; SMS is routed via Telnyx only as a fallback
- seven.io (seven communications GmbH & Co. KG, Germany): SMS delivery (processor) — the recipient's number and the message text
- OpenAI (OpenAI Ireland Ltd.): AI text processing (processor) — call transcripts are sent for task extraction, translation, summarisation and improvement suggestions, as are the messages you send to support. The data is not used for model training.
- Resend (Resend Inc., USA): Email delivery (processor) — the recipient address and the message content, which includes the caller's name, number and email address as well as the call summary
- DigitalOcean (USA): Application and database hosting (processor) — all platform data is stored in a Frankfurt (EU) data centre
- Sentry (Functional Software Inc.): Technical error tracking for the application and for your browser (processor) — technical error data; EU region (Frankfurt), no personal data sent by default
- Google (Google Ireland Ltd.): Google Calendar API — only if you voluntarily connect your calendar (processor). See section 6 for the Limited Use commitment.
- Systems you connect yourself (CRM, calendars, webhooks, partner platforms): If you connect your own system (Zoho Bigin, HubSpot, Airtable, Mews), connect your assistant to a partner platform (an order-intake platform, for example) or configure your own webhook, we transmit data there on your instruction — where the connection calls for it, that includes the full call transcript and the contact details the caller confirmed. Each such connection is switched on per account and bound per assistant. For those systems you are the controller.
- Viva.com (Viva Payments Single Member S.A., Greece): Card acceptance for topping up your credit (independent controller) — your e-mail address and name, the amount, and our order reference. No caller data and no call transcripts. Card details are entered on Viva's own payment page and never reach us.
Transfers outside the EEA take place on the basis of Standard Contractual Clauses (Article 46 GDPR) or, where the recipient is certified, of the EU-US Data Privacy Framework (Article 45 GDPR).
6. Google API — Limited Use
Our platform's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
We request exactly one calendar permission, beyond identification:
calendar.events— reading and writing events. This single permission covers both of the things your assistant needs, which is why we do not ask for a second one:- Read: your assistant reads your existing events so that it knows when you are busy and does not offer a time slot that is already taken.
- Write: when the assistant books an appointment on the phone, it records it in your calendar; when the customer cancels, it removes it or marks it as cancelled. We write exclusively to events created by the platform itself — we do not modify and do not delete events created by you or by third parties.
The openid and email permissions serve solely to identify which account was connected. We do not request access to your calendar list; synchronisation always targets the connected account's primary calendar.
We expressly commit that your Google Calendar data:
- is used exclusively so that your own AI assistant knows when you are available and can offer or book appointments — and to sync to your calendar only the appointments created by the platform
- is not used for advertising and is not transferred to advertising networks or data brokers
- is not sold to third parties
- is not used to develop, improve or train non-personalized artificial-intelligence or machine-learning models — Google Workspace APIs data is not used to develop, improve or train non-personalized AI and/or ML models
- is accessible only to the account that made the connection; human access takes place only with your explicit permission, for security purposes, or where required by law
You can revoke the connection at any time from the platform settings or directly at myaccount.google.com/permissions. Upon revocation we delete the stored refresh token and the cached events of your calendar.
7. Retention Period
- Call data: Automatically deleted after 90 days (configurable)
- Account data: Retained until you delete your account
- Audit logs: Retained for 1 year for compliance purposes
- Invoicing data: Retained for 7 years as required by tax law
8. Your Rights (Articles 15-22 GDPR)
You have the following rights regarding your personal data:
- Right of access (Art. 15): Obtain a copy of all your data — available from Settings → GDPR → Data Export
- Right to rectification (Art. 16): Edit your details from Settings → Profile
- Right to erasure (Art. 17): Delete your account and all your data — from Settings → GDPR → Delete Account
- Right to data portability (Art. 20): Receive your data in JSON format
- Right to object (Art. 21): Withdraw your consent to marketing at any time
To exercise your rights, contact us at info@citt.gr. We respond within 30 days.
9. Data Security (Article 32 GDPR)
- Encryption of data in transit (TLS 1.3) and at rest (AES-256)
- Encrypted storage of API keys
- Role-based access control (RBAC)
- Automatic data deletion under the retention policy
- Audit logging of all actions
10. Cookies
We use only cookies that are necessary for the operation of the service (authentication). We do not use tracking or advertising cookies. The option to accept or decline cookies is shown on your first visit.
11. Data Protection Authority
You have the right to lodge a complaint with the Hellenic Data Protection Authority (HDPA) if you believe that the processing of your data does not comply with the GDPR.
12. Changes to this Policy
We may update this Privacy Policy. We will notify you by email or in-app notification of material changes at least 30 days before they take effect.