Privacy Policy
Last updated: 2026-07-16
Last updated: 16 July 2026
Who we are
The AI Fortis Voice AI Platform (app.aifortis.com) is operated by AI Fortis Ltd. („ЕЙ АЙ Фортис“ ООД), a company registered in Bulgaria, EIK 208238799, VAT BG208238799, 1 Gen. Stefan Toshev St, 1618 Sofia, Bulgaria ("AI Fortis", "we", "us"). Privacy contact: office@aifortis.com.
Scope
This policy explains how we process personal data when operating the platform — a business-to-business (B2B) service through which our clients operate AI voice agents that make and receive phone and web calls. It covers visitors to the platform, our clients' account users, and — to the extent we act as a processor — the people our clients call or who call them ("end customers").
Controller and processor roles
- For account, usage and billing data of our business clients and their users, AI Fortis is the data controller.
- For personal data processed in the course of our clients' calls (end-customer phone numbers, names, CRM variables, call audio, recordings, transcripts and call analysis), the client is the data controller and AI Fortis acts as a data processor on the client's documented instructions under a Data Processing Agreement (DPA).
- End customers who wish to exercise rights over call data should contact the business that called them (or that they called); we will assist that client in responding.
Categories of data we process
- Account data: name, email address, role, language preference, authentication data and security logs.
- Client-provided contact data: end-customer phone numbers, names and custom CRM variables supplied by the client to place or route calls.
- Call data: call audio, recordings, transcripts, AI-generated summaries and analysis, timestamps, duration, outcome and cost.
- Usage and billing data: per-call and per-minute usage metering, plan, invoicing and payment records.
- Technical data: connection information (such as IP address and browser details) recorded in the standard server logs of our hosting providers, and the strictly necessary cookies described in the Cookie Policy.
Purposes and legal bases
- Providing and operating the platform — performance of a contract (GDPR Art. 6(1)(b)); for end-customer call data we process on the client's documented instructions as processor.
- Security, fraud prevention and service integrity — our legitimate interests (Art. 6(1)(f)).
- Billing, accounting and tax — compliance with legal obligations (Art. 6(1)(c)).
- Service communications and support — performance of a contract and our legitimate interests.
- Call recording: calls handled by the platform are recorded to provide transcripts, quality control and the client's business records. The client, as controller, is responsible for the legal basis and for any consent or notice required to record calls; the required AI and recording disclosures are configured by the client in each agent's greeting and script.
Sub-processors
We use the following providers to deliver the service (see the Sub-processors page for the current list and details):
- LiveKit — real-time voice infrastructure (call media, WebRTC/SIP).
- Google — AI language models (Gemini) powering agent conversations, and Google Workspace for service email and calendar scheduling.
- ElevenLabs — speech synthesis (text-to-speech).
- Deepgram — speech recognition (speech-to-text).
- OpenAI — speech recognition and, on agents configured for it, real-time speech-to-speech conversation.
- Microsoft (Azure Speech) — speech recognition on agents configured for it.
- Twilio, Telnyx and other telephony carriers — phone numbers and call carriage.
- Supabase — application database and authentication (hosted in the EU).
- Vercel — application hosting.
- Cloudflare R2 — call recording storage.
- Upstash — queues and rate limiting.
- Anthropic — the built-in assistant used by our staff; platform metadata only, no recordings, transcripts or end-customer phone numbers.
- Sentry — application error monitoring; diagnostic data only.
Which speech providers apply to a given agent depends on that agent's configuration.
We do not sell personal data.
EU data residency and international transfers
Our primary application database (Supabase) is hosted in the European Union. Some sub-processors (for example AI model, voice and telephony providers) may process data outside the EEA; where that happens we rely on appropriate safeguards, in particular the EU Standard Contractual Clauses, together with transfer impact assessments where required.
Retention
- Call recordings and transcripts are retained for the duration of the client relationship unless a different period is agreed with the client; they are deleted when the account is closed and on verified erasure requests. Data from website demo calls is automatically deleted after 12 months.
- Account, usage and billing data are kept for the life of the account plus statutory retention periods (e.g. under Bulgarian accounting law).
- We delete or anonymise personal data once it is no longer needed for the purposes above, unless a longer period is legally required.
Security
- Encryption in transit: all traffic uses TLS (HTTPS).
- Encryption at rest: provider keys, SIP and integration secrets are encrypted with AES-256-GCM; databases and storage are encrypted at rest by our hosting providers.
- Multi-tenant isolation: every record is scoped to its client and enforced with row-level security (RLS) in the database.
- Access control: role-based access, optional multi-factor authentication (TOTP), least-privilege service access and audit logging.
- Data lifecycle: data is deleted on account closure and on verified erasure requests; website demo data is purged automatically.
Your rights
Under the GDPR you may request access, rectification, erasure, restriction of processing and data portability, object to processing, and withdraw consent where processing is based on consent. To exercise your rights, contact office@aifortis.com. Where we act as processor for the data concerned, we will refer your request to the relevant client (controller) and assist them in responding.
Complaints
You may lodge a complaint with the Bulgarian Commission for Personal Data Protection (CPDP, www.cpdp.bg) or the supervisory authority in your EU member state.
Changes
We will update this policy as the service evolves and indicate the date of the latest revision at the top.