This Privacy Policy ("Policy") describes how DoorCall AI, Inc., a Delaware corporation ("DoorCall AI," "we," "us," or "our"), collects, uses, discloses, retains, and protects Personal Information in connection with the DoorCall AI platform, the website located at doorcall.ai, and all related applications, application programming interfaces, and services (collectively, the "Services").
DoorCall AI operates an artificial-intelligence receptionist that answers inbound telephone calls forwarded by garage-door service businesses, converses with callers, classifies the nature and urgency of the caller's request, validates service coverage, schedules appointments, and delivers structured summaries and notifications to the business. This Policy is incorporated by reference into the DoorCall AI Terms of Service.
1. Scope and Application
1.1 Covered Activities. This Policy applies to Personal Information processed through the Services, the website, transactional communications, and support interactions.
1.2 Excluded Activities. This Policy does not apply to: (a) the independent privacy practices of any Customer; (b) third-party websites, products, or services that are not operated by DoorCall AI, including those reached through links or integrations; or (c) information that has been irreversibly de-identified or aggregated such that it cannot reasonably be used to infer information about, or otherwise be linked to, an identified or identifiable natural person or household.
1.3 Conflict with a Data Processing Addendum. Where DoorCall AI has executed a Data Processing Addendum ("DPA") with a Customer, and a conflict exists between this Policy and that DPA with respect to Caller Data, the DPA governs.
2. Definitions
For purposes of this Policy, capitalized terms have the meanings set forth below. Terms defined in the Terms of Service and not defined here have the meanings given in the Terms of Service.
2.1 "Account Data" means Personal Information relating to a Customer's personnel, including names, business email addresses, business telephone numbers, role assignments, authentication credentials, workspace configuration, and audit records of administrative actions.
2.2 "AI Output" means any transcript, summary, classification, extraction, sentiment indicator, urgency designation, or other content generated by automated means from a Communication.
2.3 "Caller" means a natural person who places or receives a telephone call, or exchanges a text message, that is handled by the Services on behalf of a Customer.
2.4 "Caller Data" means Personal Information relating to a Caller that is collected or generated in the course of a Communication, including the categories enumerated in Section 4.
2.5 "Communication" means any inbound or outbound telephone call, voicemail, short message service ("SMS") message, or equivalent electronic communication handled through the Services.
2.6 "Controller" means the entity that, alone or jointly with others, determines the purposes and means of the processing of Personal Information. "Processor" means the entity that processes Personal Information on behalf of, and under the documented instructions of, a Controller. Where applicable law uses different terminology (including "business," "service provider," and "third party" under California law), those terms are construed consistently with this Section.
2.7 "Customer" means the business entity that subscribes to the Services, being in the ordinary case a garage-door installation, repair, or maintenance company.
2.8 "Personal Information" means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular natural person or household, and includes "personal data" as defined under the GDPR.
2.9 "GDPR" means Regulation (EU) 2016/679, and, as applicable, the United Kingdom General Data Protection Regulation as incorporated by the European Union (Withdrawal) Act 2018 ("UK GDPR").
2.10 "Subprocessor" means a third party engaged by DoorCall AI to process Caller Data on behalf of a Customer.
3. Our Dual Role: Controller and Processor
The allocation of responsibility under this Policy depends on the category of Personal Information at issue. This distinction is operative and determines where a data subject must direct a rights request.
3.1 DoorCall AI as Processor. With respect to Caller Data, DoorCall AI acts as a Processor and, under California law, as a service provider. The Customer determines the purposes and means of processing, including whether Communications are recorded, what disclosures are delivered to Callers, the retention period applied, and whether appointments are booked automatically. DoorCall AI processes Caller Data solely to provide the Services, to comply with law, and as otherwise permitted by Section 6.
3.2 DoorCall AI as Controller. With respect to Account Data, billing information, website visitor data, support communications, security telemetry, and marketing communications, DoorCall AI acts as a Controller and determines the purposes and means of processing.
3.3 Routing of Requests. A Caller who wishes to exercise rights in respect of Caller Data should direct the request to the Customer whose telephone line the Caller contacted. Where a Caller submits such a request to DoorCall AI directly, DoorCall AI will, without undue delay and in any event within ten (10) business days, refer the request to the relevant Customer and, at that Customer's documented instruction, assist in fulfilling it. DoorCall AI does not independently grant or deny requests concerning Caller Data absent Customer instruction or a legal obligation to act.
4. Personal Information We Collect
4.1 Caller Data
In the course of a Communication, the Services collect and generate:
(a) Contact identifiers — the Caller's name, telephone number in E.164 format, and, where volunteered, electronic mail address;
(b) Service-location information — street address, municipality, and postal code of the premises at which service is requested, together with the derived determination of whether that location falls within the Customer's configured service area;
(c) Service-request content — the Caller's description of the equipment fault or request, responses to intake questions, stated scheduling preferences, and property classification (residential or commercial);
(d) Audio recordings — recorded audio of the Communication, but only where the Customer has enabled recording and the disclosure obligations described in Section 11 have been satisfied;
(e) Transcripts and AI Output — machine-generated transcripts with speaker attribution, structured extractions, narrative summaries, urgency classifications, safety flags, sentiment indicators where available, and confidence scores;
(f) Telephony metadata — call start and end times, duration, direction, call disposition, transfer outcome, carrier-supplied identifiers, and provider call identifiers;
(g) Messaging data — the content and delivery status of SMS confirmations and notifications, together with records of consent and of any opt-out instruction; and
(h) Appointment records — scheduled date and time, assigned dispatch calendar, service classification, internal notes entered by the Customer's personnel, and any recorded job value.
4.2 Account Data
We collect the Customer's business name, trading address, business telephone number and electronic mail address, website, operating timezone, service area configuration, service catalogue, hours of operation, receptionist configuration, notification recipients, and the names, business electronic mail addresses, business telephone numbers, and role assignments of authorized users. We also maintain authentication credentials in hashed and salted form and audit records of material administrative actions.
4.3 Billing Information
Subscription status, plan selection, billing period, usage counters, and payment status are processed by DoorCall AI. Payment card numbers, bank account numbers, and equivalent payment credentials are collected and processed directly by our payment processor and are not transmitted to, stored by, or accessible to DoorCall AI.
4.4 Website and Technical Data
We collect internet protocol address, browser type and version, operating system, device characteristics, referring uniform resource locator, pages accessed, timestamps, and interaction events. Cookie practices are described in Section 8 and, in greater detail, in the Cookie Policy.
4.5 Support and Correspondence
We collect the content of support requests, correspondence, and any information voluntarily submitted in connection with them.
4.6 Information We Do Not Intentionally Collect
The Services are not designed to collect payment card data, government-issued identifiers, financial account numbers, biometric identifiers, precise geolocation derived from device sensors, or information concerning racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, sexual orientation, or criminal convictions. A Caller may nonetheless volunteer such information spontaneously during an unstructured conversation, including information concerning health or disability where it bears on the urgency of a service request. Where such information is incidentally captured, DoorCall AI processes it solely as part of the Communication record, applies the same retention period applicable to that record, does not use it to build profiles, and does not use it to infer characteristics about the Caller.
5. Sources of Personal Information
We obtain Personal Information: (a) directly from Callers during Communications; (b) directly from Customers and their authorized users; (c) automatically through operation of the Services and the website; (d) from telephony carriers and our voice infrastructure provider in the form of call signalling and metadata; (e) from a Customer's connected calendar where the Customer has authorized that integration; and (f) from our payment processor in the form of subscription and payment status.
6. Purposes of Processing
6.1 Caller Data. We process Caller Data to answer and conduct Communications; to transcribe, summarize, classify, and extract structured information from them; to determine whether a service location falls within the Customer's configured service area; to compute appointment availability and create, reschedule, or cancel appointments; to deliver notifications and confirmations to the Customer and, where the Customer has enabled them and consent has been recorded, to the Caller; to detect and prevent fraud, abuse, and misuse; to maintain security and enforce usage and spend limitations; and to comply with legal obligations.
6.2 Account Data and Billing Information. We process Account Data and billing information to establish and administer accounts; to authenticate users and enforce role-based access controls; to provision, configure, and operate the Services; to invoice and collect fees and to enforce plan entitlements; to provide support; to communicate service, security, and administrative notices; and to comply with legal, tax, and accounting obligations.
6.3 Service Improvement. We process Personal Information to monitor, diagnose, secure, maintain, and improve the Services, including by investigating faults, measuring reliability, and evaluating the accuracy of AI Output.
6.4 Restriction on Model Training. DoorCall AI does not use Caller Data, the content of Communications, audio recordings, transcripts, or AI Output to train, fine-tune, or otherwise develop generalized artificial-intelligence or machine-learning models for the benefit of DoorCall AI or any third party. DoorCall AI contractually requires its voice and language-model Subprocessors to observe the same restriction. Nothing in this Section restricts DoorCall AI from generating and using aggregated or de-identified statistics that cannot reasonably be re-identified.
6.5 Marketing. We use business contact details of Customer personnel to send product and commercial communications. Every such communication contains a functioning mechanism to decline further communications, and a person who declines will continue to receive transactional and administrative messages necessary to the operation of the account.
7. Legal Bases for Processing (European Economic Area, United Kingdom, and Switzerland)
Where the GDPR applies, DoorCall AI relies on the following legal bases:
| Processing activity | Role | Legal basis |
|---|---|---|
| Providing the Services to a Customer | Processor | Customer's legal basis, established under Article 6 |
| Administering an account and providing support | Controller | Article 6(1)(b) — performance of a contract |
| Billing, collection, tax and accounting records | Controller | Article 6(1)(b) and Article 6(1)(c) |
| Security, fraud prevention, abuse detection, service improvement | Controller | Article 6(1)(f) — legitimate interests |
| Marketing to business contacts | Controller | Article 6(1)(f), subject to the right to object |
| Recording of Communications where consent is the operative basis | Processor | Customer's reliance on Article 6(1)(a) — consent |
| Responses to lawful requests from public authorities | Controller | Article 6(1)(c) |
7.1 Legitimate Interests Assessment. Where we rely on Article 6(1)(f), our legitimate interests are the secure and reliable operation of the Services, the prevention of fraud and abuse, the protection of our infrastructure and our Customers, and the promotion of our business to commercial counterparties. We have assessed these interests against the interests, rights, and freedoms of data subjects and have implemented the safeguards described in Section 12.
7.2 Special Category Data. DoorCall AI does not solicit data falling within Article 9 of the GDPR. Where such data is incidentally volunteered during a Communication, the Customer, as Controller, is responsible for identifying an applicable Article 9(2) condition. DoorCall AI processes such data only on the Customer's documented instructions.
8. Cookies and Similar Technologies
We use cookies and similar technologies for authentication, session continuity, security, load balancing, preference retention, and product analytics. Cookies that are strictly necessary to deliver a service the user has requested are set without consent. Analytics and other non-essential cookies are set only where consent has been obtained in jurisdictions requiring it, and consent may be withdrawn at any time. A complete description of each category, its purpose, and its duration, together with the mechanisms available to control cookies, appears in the Cookie Policy.
8.1 Global Privacy Control. We treat a Global Privacy Control signal, or an equivalent browser-transmitted opt-out preference signal, as a valid request to opt out of the sale or sharing of Personal Information and of targeted advertising for the browser transmitting it.
9. Analytics
We operate first-party product analytics to measure feature adoption, diagnose faults, and evaluate reliability. Analytics events are keyed to workspace and user identifiers rather than to Caller identity, and Caller Data is not used for analytics purposes beyond the operational metrics presented to the Customer within its own workspace. We do not permit third-party advertising networks to collect Personal Information through the Services, and we do not operate advertising pixels or cross-context behavioural advertising tags within the authenticated application.
10. Automated Processing and Artificial Intelligence
10.1 Automated Processing Performed. The Services perform the following automated operations without human intervention at the time of processing: speech recognition and transcription; classification of a service request against the Customer's service catalogue; assignment of an urgency designation; detection of safety indicators; validation of a service location against the Customer's configured service area; computation of available appointment times; and, where the Customer has enabled automatic booking, creation of an appointment.
10.2 Absence of Legal or Similarly Significant Effects. These operations determine how a service enquiry is categorized and scheduled. They do not determine eligibility for credit, insurance, employment, housing, education, or any other benefit, and they do not produce legal effects concerning a Caller or similarly significantly affect a Caller within the meaning of Article 22(1) of the GDPR. DoorCall AI does not engage in profiling for the purpose of evaluating personal aspects relating to economic situation, health, personal preferences, interests, reliability, behaviour, location, or movements.
10.3 Human Oversight. Every appointment, classification, and summary produced by the Services is presented to the Customer's personnel, who may review, correct, override, reschedule, or cancel it. A Caller who wishes a determination to be reviewed by a natural person may request review from the Customer, or may contact DoorCall AI at privacy@doorcall.ai, in which case the request will be referred to the Customer under Section 3.3.
10.4 Accuracy Limitations. AI Output is generated by probabilistic systems and may contain errors, including misheard names, addresses, or telephone numbers, mischaracterized service requests, and inaccurate summaries. AI Output is not a verbatim record of a Communication. Where a recording exists, the recording is the authoritative record. Neither AI Output nor any classification generated by the Services constitutes professional advice of any kind, and the Services are not an emergency-response service.
11. Recording of Communications
11.1 Customer-Controlled Setting. Recording is disabled unless affirmatively enabled by the Customer within its workspace. Where enabled, the Services deliver a disclosure at the outset of each Communication using wording configured by the Customer.
11.2 Allocation of Legal Responsibility. Laws governing the recording of telephone communications differ by jurisdiction. Certain jurisdictions, including California, Connecticut, Delaware, Florida, Illinois, Maryland, Massachusetts, Michigan, Montana, Nevada, New Hampshire, Oregon, Pennsylvania, and Washington, require the consent of all parties to a communication, whether by statute or by judicial construction. The Customer is solely responsible for determining whether recording is lawful in each jurisdiction in which it and its Callers are located, for configuring disclosure wording sufficient to obtain any consent required, and for enabling or disabling recording accordingly. DoorCall AI provides the technical means to deliver a disclosure and to disable recording; it does not determine the legal sufficiency of a Customer's configuration.
11.3 Access Control. Recordings are not published, indexed, or made available at any persistent public address. Access is restricted to authenticated personnel of the Customer workspace to which the recording belongs, and each request is authorized against workspace membership at the time of access.
11.4 Objection by a Caller. A Caller who does not wish a Communication to be recorded may state that objection during the Communication or terminate the Communication. A Caller who has objected may contact the Customer to request deletion of the recording, and DoorCall AI will give effect to such a deletion instruction upon receipt from the Customer.
12. Security
12.1 Technical and Organizational Measures. We maintain a security programme that includes: encryption of data in transit using industry-standard transport-layer cryptography and encryption of data at rest; encryption of third-party integration credentials using authenticated symmetric encryption, with such credentials never transmitted to any browser; logical tenant isolation enforced both in the application layer and at the database layer through row-level security policies; role-based access control with least-privilege provisioning; authenticated, workspace-scoped access to recordings; cryptographic verification of the authenticity of inbound webhooks; rate limiting and abuse controls; hard usage ceilings that bound the consequences of anomalous activity; structured logging with redaction of credentials and recording locations; audit logging of material administrative actions; and separation of production credentials from application code.
12.2 Personnel. Personnel with access to Personal Information are bound by written confidentiality obligations, receive security training, and are granted access only to the extent necessary to perform their duties. Access is revoked promptly upon change of role or separation.
12.3 Limitation. No method of transmission or storage is entirely secure. While we implement and maintain measures appropriate to the risk, we do not warrant that the Services will be free from unauthorized access.
12.4 Breach Notification. Where DoorCall AI becomes aware of a personal data breach affecting Caller Data, it will notify the affected Customer without undue delay and in any event within forty-eight (48) hours of confirming the breach, and will provide the information reasonably required for the Customer to discharge its own notification obligations. Where a breach affects Personal Information for which DoorCall AI is the Controller, DoorCall AI will notify affected individuals and competent supervisory authorities as required by applicable law.
13. Disclosure of Personal Information
13.1 No Sale or Sharing. DoorCall AI does not sell Personal Information, and does not share Personal Information for cross-context behavioural advertising, as those terms are defined under the California Consumer Privacy Act as amended. DoorCall AI has not sold or shared Personal Information within the preceding twelve (12) months, including the Personal Information of any consumer under sixteen (16) years of age.
13.2 Subprocessors and Service Providers. We disclose Personal Information to the categories of recipients set out below, each engaged under a written contract restricting use of the information to the provision of services to DoorCall AI:
| Recipient category | Function | Categories disclosed |
|---|---|---|
| Voice artificial-intelligence provider | Conducting and transcribing telephone Communications | Call audio, transcripts, telephony metadata |
| Telephony and messaging provider | Call carriage, number provisioning, SMS delivery | Telephone numbers, message content, delivery status |
| Database and authentication provider | Hosting of the application database and authentication | All stored categories |
| Transactional email provider | Delivery of notifications and confirmations | Recipient address, message content |
| Payment processor | Subscription billing and payment collection | Billing contact, subscription status, payment credentials collected directly by the processor |
| Calendar provider | Availability retrieval and appointment creation, where the Customer connects the integration | Appointment details, customer name, service address |
| Cloud infrastructure provider | Application hosting and content delivery | All stored categories |
| Error-monitoring provider | Diagnosis of faults | Technical telemetry and redacted error context |
A current list identifying each Subprocessor by name and processing location is maintained at doorcall.ai/legal/subprocessors and is incorporated into the DPA.
13.3 The Customer. Caller Data is disclosed to the Customer on whose behalf the Communication was handled. The Customer's own privacy practices govern its subsequent use of that information.
13.4 Legal and Protective Disclosures. We may disclose Personal Information where we determine in good faith that disclosure is reasonably necessary to comply with applicable law, regulation, legal process, or an enforceable governmental request; to enforce our agreements, including investigation of potential violations; to detect, prevent, or address fraud, security, or technical issues; or to protect against harm to the rights, property, or safety of DoorCall AI, our users, or the public.
13.5 Government Requests. We require legal process for compelled disclosure and evaluate each request for legal validity and scope. Where we receive a request for Caller Data, we will, unless legally prohibited or where there is a risk to life or serious injury, redirect the requesting authority to the relevant Customer and notify that Customer with sufficient time to seek protective relief.
13.6 Corporate Transactions. In connection with a merger, acquisition, financing, reorganization, or sale of assets, Personal Information may be disclosed to counterparties and their advisers subject to confidentiality obligations, and may be transferred as part of the transaction. Personal Information transferred in such a transaction remains subject to this Policy until the recipient provides notice of a change consistent with Section 20.
14. International Transfers
DoorCall AI is established in the United States and processes Personal Information there. Where Personal Information is transferred from the European Economic Area, the United Kingdom, or Switzerland to a jurisdiction that has not been the subject of an adequacy decision, the transfer is made subject to appropriate safeguards, being: (a) the Standard Contractual Clauses approved by the European Commission in Implementing Decision (EU) 2021/914, incorporating Module Two (controller to processor) or Module Three (processor to processor) as applicable; (b) for transfers subject to the UK GDPR, the International Data Transfer Addendum to the EU Standard Contractual Clauses issued by the Information Commissioner; and (c) for transfers subject to the Swiss Federal Act on Data Protection, the Standard Contractual Clauses as adapted by the Federal Data Protection and Information Commissioner. DoorCall AI conducts transfer impact assessments where required and implements supplementary technical measures, including encryption in transit and at rest and a policy of challenging overbroad governmental requests. A copy of the safeguards applicable to a given transfer is available on written request to privacy@doorcall.ai.
15. Data Retention
15.1 Retention Schedule. We retain Personal Information for the periods set out below, or for such longer period as is required by law or necessary to establish, exercise, or defend legal claims:
| Category | Retention period |
|---|---|
| Call recordings | The period configured by the Customer, not exceeding twenty-four (24) months from the date of the Communication in the absence of a configured period |
| Transcripts, AI Output, and call metadata | Thirty-six (36) months from the date of the Communication, unless a shorter period is configured |
| Lead and appointment records | For the duration of the Customer's subscription and thirty (30) days thereafter |
| Account Data | For the duration of the subscription and thirty (30) days thereafter |
| Billing and transaction records | Seven (7) years, to satisfy tax and accounting obligations |
| Audit logs | Twenty-four (24) months |
| Security and application logs | Ninety (90) days |
| Support correspondence | Twenty-four (24) months from resolution |
| Records of SMS consent and opt-out | Five (5) years following the last Communication, to evidence compliance |
15.2 Deletion on Termination. Upon termination of a Customer's subscription, and following the thirty (30) day recovery period described in Section 16.5, DoorCall AI permanently deletes all Personal Information associated with that Customer's workspace, save for records within the categories in Section 15.1 that are subject to a longer statutory retention period and for backup media, which are overwritten on a rolling cycle not exceeding thirty-five (35) days.
15.3 Legal Hold. Where Personal Information is subject to a legal hold, litigation, or regulatory investigation, deletion is suspended for the duration of the hold.
16. Individual Rights
16.1 Rights Under the GDPR. Where the GDPR applies, a data subject has the right to: obtain confirmation as to whether Personal Information concerning them is processed and to access that information; obtain rectification of inaccurate information and completion of incomplete information; obtain erasure in the circumstances set out in Article 17; obtain restriction of processing in the circumstances set out in Article 18; receive Personal Information provided to us in a structured, commonly used, and machine-readable format and to transmit it to another controller; object to processing carried out on the basis of legitimate interests, and to object at any time and without qualification to processing for direct marketing purposes; withdraw consent at any time where processing is based on consent, without affecting the lawfulness of processing carried out before withdrawal; and lodge a complaint with a supervisory authority in the member state of their habitual residence, place of work, or place of the alleged infringement.
16.2 Rights Under California Law. A California resident has the right to: know the categories and specific pieces of Personal Information collected, the categories of sources, the business or commercial purposes for collection, and the categories of third parties to whom it is disclosed; delete Personal Information, subject to the exceptions in Section 1798.105(d) of the California Civil Code; correct inaccurate Personal Information; opt out of the sale or sharing of Personal Information, which DoorCall AI does not conduct; limit the use and disclosure of sensitive Personal Information, noting that DoorCall AI uses such information only for purposes permitted under Section 7027(m) of the California Code of Regulations; and be free from unlawful discrimination for exercising any of these rights. DoorCall AI does not offer financial incentives in exchange for the retention or sale of Personal Information. A California resident may also request, under Section 1798.83 of the California Civil Code, information regarding disclosure of Personal Information to third parties for direct marketing purposes; DoorCall AI makes no such disclosures.
16.3 Rights Under Other United States State Laws. Residents of Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, and Virginia, and of any other state whose comprehensive privacy statute is in force, have rights of access, correction, deletion, and portability, and rights to opt out of targeted advertising, sale, and certain profiling, in each case as provided by and subject to the exceptions in the applicable statute. Residents of jurisdictions providing a right to appeal a denied request may appeal by writing to privacy@doorcall.ai with the subject line "Privacy Request Appeal"; we will respond within forty-five (45) days with a written explanation of our decision.
16.4 Exercising Rights. A verifiable request may be submitted to privacy@doorcall.ai. We will acknowledge receipt within ten (10) business days and respond substantively within thirty (30) days where the GDPR applies, or within forty-five (45) days where United States state law applies, in each case with a single extension where permitted by the applicable statute and where notice of the extension is given. We will verify identity by matching information supplied in the request against information already held, and, for requests concerning Communications, by verifying control of the telephone number that placed the Communication. An authorized agent may submit a request on behalf of a data subject upon provision of written authorization and verification of the agent's identity. No fee is charged unless a request is manifestly unfounded or excessive, in which case we may charge a reasonable fee or decline to act, and will explain the basis for doing so.
16.5 Deletion of a Workspace. A Customer may request deletion of its entire workspace from within the application. Deletion is scheduled to occur thirty (30) days after the request, during which period the Customer may cancel the request. On expiry of that period, all records associated with the workspace are permanently deleted, and completion of the deletion is verified programmatically across every data store before the operation is recorded as complete.
17. Children's Privacy
The Services are directed exclusively to businesses and are not intended for, marketed to, or designed for use by children. We do not knowingly collect Personal Information from any individual under the age of sixteen (16), and we do not knowingly collect Personal Information from any individual under the age of thirteen (13) within the meaning of the Children's Online Privacy Protection Act. A Caller may in principle be a minor placing a call on behalf of a household. Where we become aware that Personal Information of a child has been collected other than as an incident of such a Communication, we will delete it promptly. A parent or guardian who believes that a child's Personal Information has been collected may contact privacy@doorcall.ai, and we will investigate and delete the information where required.
18. Telephone and Messaging Communications
SMS messages sent through the Services to Callers are transactional in character and relate to a service appointment, a callback acknowledgement, or a change to a scheduled visit. Such messages are sent only where the Customer has enabled customer-facing messaging and a record of the Caller's consent exists. Each message identifies the sending business and includes opt-out instructions. A Caller may opt out by replying with the word STOP or any equivalent keyword recognized by the messaging carrier, and the opt-out is given effect immediately across the Customer's workspace. Message and data rates imposed by the Caller's carrier may apply. DoorCall AI does not send marketing messages to Callers and does not permit the Services to be used for that purpose.
19. Contact and Supervisory Information
19.1 Privacy Contact. Questions, requests, and complaints concerning this Policy may be addressed to privacy@doorcall.ai. Postal correspondence may be sent to the registered address of DoorCall AI, Inc. published at doorcall.ai/legal/contact.
19.2 Data Protection Officer. DoorCall AI has appointed a data protection officer who may be contacted at dpo@doorcall.ai.
19.3 European Union and United Kingdom Representatives. DoorCall AI has appointed representatives pursuant to Article 27 of the GDPR and Article 27 of the UK GDPR, who may be contacted at eu-rep@doorcall.ai and uk-rep@doorcall.ai respectively. The identity and address of each representative is published at doorcall.ai/legal/contact.
19.4 Complaints. A data subject who is dissatisfied with our response may lodge a complaint with a competent supervisory authority. In the United Kingdom, that authority is the Information Commissioner's Office. In the European Economic Area, it is the supervisory authority of the data subject's habitual residence, place of work, or place of the alleged infringement.
20. Changes to This Policy
We may amend this Policy from time to time. Where an amendment is material, we will provide notice at least thirty (30) days before it takes effect, by electronic mail to the administrative contact of each affected Customer and by a prominent notice within the application. The "Last Updated" date at the head of this Policy identifies the date of the most recent revision, and superseded versions are retained and made available on request. Continued use of the Services following the effective date of an amendment constitutes acceptance of the amended Policy. Where an amendment would materially reduce the protections applicable to Personal Information already collected, and where consent is required by applicable law, we will obtain that consent before applying the amendment to that information.