Privacy and retention

GDPR-compliant handling of call transcripts

Calls2CRM processes call data under the GDPR principle of data minimisation: only what is needed, for as long as needed, fully under your organisation's control.

Automatic retention

Each organisation sets a retention period in days. Optionally, Calls2CRM can delete a transcript immediately once it has been successfully posted to the CRM. Otherwise, transcripts are automatically deleted after the configured retention period.

Real-time lookup, no shadow CRM

Calls2CRM does not copy your contact or company database. CRM relations are retrieved in real time at the moment a call is processed — no sooner, nothing more.

Minimal storage for manual review

When manual review is required, only the matched name and CRM reference can temporarily be stored alongside the transcript — never the full contact record.

Control stays with the organisation

The processing organisation sets its own retention period and can delete transcripts earlier. CRM access is used solely for the agreed data processing.

Frequently asked questions about privacy

Is Calls2CRM GDPR-compliant?

Yes. Calls2CRM is built on the GDPR principle of data minimisation: no full CRM databases are copied, transcripts are automatically deleted after the configured retention period, and CRM access is used only for the agreed processing.

How long are transcripts retained?

Calls2CRM offers two deletion points: transcripts can optionally be deleted immediately once they have been successfully posted to the CRM. If that option is not enabled, they are automatically deleted after the organisation's configured retention period in days.

Does Calls2CRM copy contacts from the CRM?

No. Calls2CRM does not maintain a copy of the CRM. Relations are looked up in real time by phone number at the moment a call is processed. See also how Calls2CRM works.

Who sets the retention period?

The organisation using Calls2CRM sets its own retention period via the portal. Organisation-specific data processing agreements can also be put in place.

Specific roles, data processing agreements and retention periods are established per organisation. Get in touch for organisation-specific questions.