Skip to main content

How responsibilities are structured

Under the General Data Protection Regulation (GDPR), there are two distinct roles in data processing:
  • Data controller - the entity that decides why and how personal data is processed
  • Data processor - the entity that processes personal data on the controller’s behalf
When you use RapidCall to contact individuals, you are the data controller. You decide who to contact, what data to use, what the purpose of the call is, and which legal basis applies. RapidCall is the data processor. We provide the technical infrastructure that executes your instructions, but we do not decide who you contact, what you say, or why the data is being processed. This distinction matters because it defines who is responsible for what.

Responsibility split

Data Processing Agreement

A Data Processing Agreement between you and ALEPI Organization OÜ, the company behind RapidCall, is incorporated into the platform’s Terms & Conditions under Section 7. It covers:
  • the scope of processing,
  • the categories of data involved,
  • your obligations as data controller,
  • our obligations as data processor,
  • and the use of authorised sub-processors.
A separate DPA does not need to be signed separately if the Terms have been accepted.

Sub-processors

RapidCall uses third-party providers to deliver different parts of the platform. These providers act as sub-processors for specific technical functions. The current sub-processor list is maintained in the platform’s Privacy Policy. It may be updated from time to time as providers are added, removed, or changed.

International data transfers

ALEPI Organization OÜ is registered in Estonia, within the EU/EEA. Primary platform operations are structured to support GDPR-compliant processing. However, some sub-processors, including AI model providers and cloud services, may process data outside the EEA, including in the United States. Where personal data is transferred outside the EEA, appropriate transfer mechanisms such as Standard Contractual Clauses (SCCs) and other lawful safeguards under Chapter V of the GDPR are used. If your organisation processes data relating to EU or EEA residents, you should be aware that some call-related data may be processed outside the EEA as part of speech generation, transcription, or language-model inference.

What you need to do

If you operate in the EU/EEA or process personal data relating to EU/EEA residents, the practical responsibilities remain yours as the data controller.

1. Establish a lawful basis

Before using RapidCall to process personal data, determine the lawful basis that applies to your use case. Depending on the context, this may include:
  • consent,
  • legitimate interest,
  • or another lawful basis available under Article 6 of the GDPR.
For example:
  • calls to existing customers about an active account may often rely on legitimate interest,
  • cold outreach or marketing-related calls may require prior consent, depending on the jurisdiction and use case.
If you are unsure, take legal advice before launching the campaign.

2. Disclose AI use where required

If the applicable law or regulatory framework requires it, you must inform the recipient that they are speaking with an AI system. The most reliable way to do this is to include a short disclosure in the opening lines of the agent’s script. Even where not yet strictly required, this is increasingly becoming best practice.

3. Disclose recording where required

If call recording is enabled, you are responsible for informing the recipient where required by law. This can be handled through:
  • an opening disclosure in the script,
  • or an automated pre-call announcement.

4. Honour data subject rights

If a contact asks to:
  • access their data,
  • delete their data,
  • stop further processing,
  • or receive a copy of their data,
you are responsible for handling that request. RapidCall provides the tools to support this, including deletion of call records, removal of recordings, export options, and the ability to disable recording at the agent level. If your use case depends on consent, you should retain a clear record of:
  • how consent was obtained,
  • when it was obtained,
  • and what the individual consented to.
For regulated outreach use cases, maintaining a reliable audit trail is essential.

Practical takeaway

RapidCall provides the infrastructure to run AI phone operations securely, but GDPR compliance depends primarily on how you use the platform. In practical terms, you are responsible for:
  • choosing the lawful basis,
  • making the required disclosures,
  • managing consent where needed,
  • and handling the rights of the individuals you contact.
RapidCall is responsible for:
  • processing data only on your instructions,
  • securing the platform,
  • and maintaining the processor-side safeguards needed to support compliant use.