How responsibilities are structured
Under the General Data Protection Regulation (GDPR), there are two distinct roles in data processing:- Data controller - the entity that decides why and how personal data is processed
- Data processor - the entity that processes personal data on the controller’s behalf
Responsibility split
Data Processing Agreement
A Data Processing Agreement between you and ALEPI Organization OÜ, the company behind RapidCall, is incorporated into the platform’s Terms & Conditions under Section 7. It covers:- the scope of processing,
- the categories of data involved,
- your obligations as data controller,
- our obligations as data processor,
- and the use of authorised sub-processors.
Sub-processors
RapidCall uses third-party providers to deliver different parts of the platform. These providers act as sub-processors for specific technical functions.
The current sub-processor list is maintained in the platform’s Privacy Policy. It may be updated from time to time as providers are added, removed, or changed.
International data transfers
ALEPI Organization OÜ is registered in Estonia, within the EU/EEA. Primary platform operations are structured to support GDPR-compliant processing. However, some sub-processors, including AI model providers and cloud services, may process data outside the EEA, including in the United States. Where personal data is transferred outside the EEA, appropriate transfer mechanisms such as Standard Contractual Clauses (SCCs) and other lawful safeguards under Chapter V of the GDPR are used. If your organisation processes data relating to EU or EEA residents, you should be aware that some call-related data may be processed outside the EEA as part of speech generation, transcription, or language-model inference.What you need to do
If you operate in the EU/EEA or process personal data relating to EU/EEA residents, the practical responsibilities remain yours as the data controller.1. Establish a lawful basis
Before using RapidCall to process personal data, determine the lawful basis that applies to your use case. Depending on the context, this may include:- consent,
- legitimate interest,
- or another lawful basis available under Article 6 of the GDPR.
- calls to existing customers about an active account may often rely on legitimate interest,
- cold outreach or marketing-related calls may require prior consent, depending on the jurisdiction and use case.
2. Disclose AI use where required
If the applicable law or regulatory framework requires it, you must inform the recipient that they are speaking with an AI system. The most reliable way to do this is to include a short disclosure in the opening lines of the agent’s script. Even where not yet strictly required, this is increasingly becoming best practice.3. Disclose recording where required
If call recording is enabled, you are responsible for informing the recipient where required by law. This can be handled through:- an opening disclosure in the script,
- or an automated pre-call announcement.
4. Honour data subject rights
If a contact asks to:- access their data,
- delete their data,
- stop further processing,
- or receive a copy of their data,
5. Maintain consent records where required
If your use case depends on consent, you should retain a clear record of:- how consent was obtained,
- when it was obtained,
- and what the individual consented to.
Practical takeaway
RapidCall provides the infrastructure to run AI phone operations securely, but GDPR compliance depends primarily on how you use the platform. In practical terms, you are responsible for:- choosing the lawful basis,
- making the required disclosures,
- managing consent where needed,
- and handling the rights of the individuals you contact.
- processing data only on your instructions,
- securing the platform,
- and maintaining the processor-side safeguards needed to support compliant use.
