Przejrzyste zasady dla strony, panelu i danych.
Ta strona porządkuje informacje o formularzu kontaktowym, korzystaniu z platformy oraz umowie powierzenia przetwarzania danych.
Operatorem serwisu jest podmiot prowadzący markę Callchestra. Kontakt w sprawach prywatności i umów: hello@callchestra.pl. Dane rejestrowe operatora są wskazywane w ofercie i umowie zawieranej z klientem.
Jak przetwarzamy dane
Zakres
Informacja obejmuje publiczną stronę Callchestra, formularz prezentacji i logowanie do panelu. Dane przetwarzane w usłudze na zlecenie klienta podlegają jego umowie i DPA.
Jakie dane zbieramy
- z formularza: imię i nazwisko, firma, służbowy e-mail, opcjonalny telefon i opis zastosowania;
- informacje techniczne: domena źródłowa, czas zgłoszenia oraz jednokierunkowy skrót adresu IP używany do ochrony formularza;
- w panelu: identyfikator konta, role, zdarzenia bezpieczeństwa i ślad działań wymagany do obsługi i audytu.
Cele, podstawy i retencja
Dane formularza służą odpowiedzi na prośbę o prezentację i przygotowaniu oferty — na podstawie zgody, działań przed zawarciem umowy oraz uzasadnionego interesu polegającego na obsłudze zapytania. Rekord formularza, razem ze skrótem IP, jest automatycznie przeznaczony do usunięcia po 90 dniach. Logi bezpieczeństwa i dane umowne mogą być przechowywane dłużej, gdy wymaga tego ochrona usługi, dochodzenie roszczeń albo prawo.
Odbiorcy i dostawcy
Dane mogą być obsługiwane przez dostawców hostingu i poczty OVHcloud, mechanizm tożsamości Keycloak utrzymywany przez Callchestra oraz — wyłącznie w zakresie uruchomionych funkcji AI — OpenAI. Integracje wybrane przez klienta mogą przekazywać dane do wskazanych przez niego systemów. Transfer poza EOG następuje tylko przy zastosowaniu odpowiedniej podstawy i zabezpieczeń umownych.
Twoje prawa
Możesz zażądać dostępu, sprostowania, usunięcia, ograniczenia, przeniesienia danych lub wnieść sprzeciw; zgodę można wycofać bez wpływu na wcześniejsze przetwarzanie. Przysługuje również skarga do Prezesa UODO. Napisz na adres wskazany powyżej.
Pliki cookie i pamięć przeglądarki
Publiczna strona zapamiętuje wyłącznie wybór języka w pamięci przeglądarki. Panel i Keycloak używają niezbędnych mechanizmów sesji i bezpieczeństwa; nie używamy ich do reklamy behawioralnej.
Podstawa zakresu informacji: materiały UODO i RODO.
Strona i panel Callchestra
Publiczna strona ma charakter informacyjny. Zakres, cena, SLA, odpowiedzialność i warunki komercyjne są określane w indywidualnej ofercie lub umowie B2B; treść tej strony ich nie zastępuje.
- konto panelu jest osobiste; użytkownik chroni hasło i drugi składnik logowania;
- nie wolno obchodzić zabezpieczeń, zakłócać usługi, testować cudzych tenantów ani wprowadzać treści bez odpowiedniej podstawy;
- funkcje telefonii, nagrywania i AI należy skonfigurować zgodnie z prawem, obowiązkiem informacyjnym i polityką klienta;
- operacje administracyjne są rejestrowane, a dostęp może zostać ograniczony przy incydencie bezpieczeństwa;
- zapowiedzi funkcji i status „pilot” nie stanowią gwarancji dostępności poza podpisaną umową.
Prawa do marki, interfejsu i oprogramowania Callchestra pozostają przy operatorze lub właściwych licencjodawcach.
Powierzenie danych dla klientów
Gdy Callchestra przetwarza dane rozmów i klientów na polecenie organizacji korzystającej z platformy, działa jako podmiot przetwarzający. DPA określa przedmiot i czas przetwarzania, kategorie danych i osób, instrukcje klienta, poufność, bezpieczeństwo, podprocesorów, obsługę praw osób, naruszenia, zwrot lub usunięcie danych i audyt.
Aktualne środki obejmują izolację tenantów, OIDC z MFA, szyfrowanie sekretów, ograniczenie sieci, kontrolę ról, audyt działań, kopie zapasowe i test odtworzenia. Konkretna lista podprocesorów i lokalizacji zależy od wybranego wariantu oraz integracji.
Poproś o DPA i listę podprocesorów →Clear rules for the website, console and data.
This page explains the demo form, use of the platform and the data processing agreement available to customers.
The service is operated by the entity trading under the Callchestra brand. Privacy and contract contact: hello@callchestra.com. The operator's registered details are provided in the commercial proposal and customer agreement.
How we process data
Scope
This notice covers the public Callchestra website, demo request form and console authentication. Customer data processed on a customer's behalf is governed by the customer agreement and DPA.
Data we collect
- form data: name, company, work email, optional phone and use-case description;
- technical data: source domain, submission time and a one-way IP hash used to protect the form;
- console data: account identifier, roles, security events and the audit trail required to operate the service.
Purposes, grounds and retention
Form data is used to answer the demo request and prepare an offer, based on consent, pre-contractual steps and the legitimate interest in handling the enquiry. The form record and IP hash are scheduled for automatic deletion after 90 days. Security logs and contractual records may be retained longer where needed to protect the service, establish claims or comply with law.
Recipients and providers
Data may be handled by OVHcloud hosting and email services, self-hosted Keycloak identity services and — only where an AI feature is enabled — OpenAI. Customer-selected integrations may send data to systems chosen by that customer. Any transfer outside the EEA requires an appropriate transfer mechanism and contractual safeguards.
Your rights
You may request access, correction, erasure, restriction, portability or object to processing. Consent may be withdrawn without affecting prior processing. You may also complain to the competent supervisory authority.
Cookies and browser storage
The public site only stores the language choice in browser storage. The console and Keycloak use essential session and security mechanisms; they are not used for behavioural advertising.
Reference: EU GDPR.
Callchestra website and console
The public site is informational. Scope, pricing, SLA, liability and commercial terms are set out in an individual B2B proposal or agreement; this page does not replace them.
- console accounts are personal; users must protect passwords and MFA;
- users must not bypass safeguards, disrupt the service, test another tenant or submit content without a proper basis;
- telephony, recording and AI features must be configured in accordance with applicable law and the customer's policies;
- administrative operations are logged and access may be restricted during a security incident;
- roadmap items and pilot status are not availability warranties outside a signed agreement.
Data processing for customers
When Callchestra processes call or customer data on an organisation's instructions, it acts as a processor. The DPA covers the subject and duration, categories of data and people, customer instructions, confidentiality, security, subprocessors, data-subject rights, incidents, return or deletion, and audits.
Current measures include tenant isolation, OIDC with MFA, encrypted secrets, network restrictions, role controls, action auditing, backups and restoration tests. The exact subprocessors and locations depend on the selected deployment and integrations.
Request the DPA and subprocessor list →