Legal
Privacy Policy
Who we are
PrimerCall is operated by Eduardo García Ruiz, Plaza la Soledad 6, 03300 Orihuela, Alicante, Spain. For any privacy question you can reach us at hola@primercall.com. This policy explains what personal data we collect, why, and the rights you have over it.
Data we collect
- Account data — name, work email and organisation, when you sign up.
- Conversation data — the answers leads give in a PrimerCall pre-call conversation, and the briefs generated from them.
- Source material — URLs, text and documents you provide so the agent can learn your product.
- Usage data — logs, device and browser information collected to keep the service secure and working.
How we use it
We use personal data to provide and improve the service, generate the pre-call brief, secure the platform, and communicate with you about your account. We do not sell personal data. We process it on the legal bases of contract performance, our legitimate interest in running the service, and your consent where required.
Google user data
If you connect a Google account, PrimerCall requests only the two permissions it needs, and uses them for nothing else:
- See your calendar events (
calendar.readonly) — to detect when a prospect books a meeting with you, so we can prepare the pre-call conversation. We read event details (title, time, participants) only to identify the booking and the invited prospect. - Send email on your behalf (
gmail.send) — to send the prep message to that prospect from your own mailbox, so it reaches them as an email from you.
We never read your mailbox. We do not request, receive or store the contents of your inbox; the send-only permission cannot read email. Access is limited to the operations described above and to staff only where strictly necessary for support or security. You can disconnect your Google account at any time from Settings, which revokes our access.
We never store your Google credentials. The OAuth tokens are held by our integration provider (Nylas); PrimerCall stores only an opaque reference to the connection, never an access or refresh token.
Limited Use. PrimerCall’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, Google Workspace API user data is not used to develop, improve, or train non-personalized AI and/or ML models, is not used for advertising, and is not sold or transferred to data brokers or information resellers. This applies to raw, aggregated, anonymised and derived data alike.
AI processing
PrimerCall uses one AI provider: Anthropic (Claude models), called directly through the Anthropic API on a paid commercial plan. We do not route requests through aggregators, gateways or model hubs, and we use no other AI or ML provider.
What is sent: the source material you provide about your product, the prospect’s identity from the booking (name, email, company, meeting time) and the messages of the pre-call conversation. It is sent for the sole purpose of generating your conversation, report and brief.
Under Anthropic’s commercial terms, customer content sent through the API is not used to train their models, and inputs and outputs are deleted within 30 days by default. See Anthropic’s commercial data retention policy. We do not train any model, foundational or otherwise, on your data or on Google user data.
Security and data protection
Security procedures are in place to protect the confidentiality of your data. In particular:
- Encryption in transit. All traffic to PrimerCall and to every provider we call travels over TLS (HTTPS). We make no request over an unencrypted channel.
- Encryption at rest. The database is hosted on managed infrastructure with encryption at rest enabled, in the European Union.
- No Google credentials stored. Access and refresh tokens are held by our integration provider; our database keeps only an opaque connection reference.
- Isolation between customers. Every read and write is scoped to the authenticated account: one customer can never reach another customer’s data.
- Secrets kept out of logs. Credentials, tokens and webhook secrets are never written to logs or sent to the AI provider.
- Signed webhooks. Incoming calendar notifications are rejected unless their signature verifies.
- Least privilege. We request the narrowest scopes that make the product work: read-only calendar and send-only email. Staff access is limited to what support or security strictly requires.
If you believe you have found a security issue, write to hola@primercall.com and we will respond promptly.
Retention and deletion
We keep personal data for as long as your account is active, and afterwards only as long as needed to meet legal obligations or resolve disputes.
You can delete everything yourself. Deleting your account from Settings removes your workspace and cascades to your agents, leads, conversations, reports and briefs, and revokes our access to any Google account you had connected. Disconnecting a Google account on its own revokes our access to it immediately, in the same way. You can also write to hola@primercall.com and we will delete your data within 30 days.
Your rights
Depending on where you live (including under the EU/UK GDPR) you may have the right to access, correct, delete, restrict or port your data, and to object to certain processing. To exercise any of these, contact hola@primercall.com.
You may also lodge a complaint with your local data-protection authority in Spain.
Contact
Questions about this policy? Email hola@primercall.com.