Gå til indhold

Privacy Policy

Last updated: 10 September 2026

We know that customer conversations contain sensitive information. This policy explains in plain language what data EasyAfterCall processes, what we use it for, who we share it with, how long we keep it – and what choices you have. It covers both this website and the platform, and it includes a dedicated section about Google Workspace data if you choose to connect your Google account.

1. About this policy and who we are

EasyAfterCall is a platform that helps teams turn customer conversations into structured knowledge and follow-up. “EasyAfterCall”, “we” and “us” refer to the company operating EasyAfterCall.

The policy applies to website visitors, to users of the platform and to the individuals our customers register in their own workspace.

If you have questions about anything in this policy, write to us at info@roi-online.dk.

2. Our role: controller or processor

When you visit our website, and when we process account, support and billing data about our customers, we are the data controller.

When a customer uses the platform and puts content into it – conversations, notes, contacts or data from an integration the customer has connected – we process that data on the customer's behalf as a processor and on the customer's instructions. Where relevant or required, a data processing agreement is entered into as part of the contractual relationship.

3. What data we process

User and account data: name, work email, organisation, role and permissions, plus sign-in and support history.

Customer contact data: the contacts and companies a customer registers in the platform, such as name, title, phone number, email address and notes.

Conversation data: where the customer has enabled the capability, recordings, transcripts and derived summaries and tasks may be processed.

Integration data: the data exchanged with a service the user has explicitly connected and enabled, plus the tokens required to maintain the connection.

Technical data: operational logs, error reporting and security-related events, such as IP address, browser type and timestamps.

4. How we use the data

We use the data to deliver and operate the platform, provide access, handle support and debugging, maintain security and prevent abuse, handle billing, and improve the capabilities customers actually use.

The legal basis is typically performance of the contract with the customer (Art. 6(1)(b)), our legitimate interest in secure and stable operation (Art. 6(1)(f)), legal obligations such as accounting (Art. 6(1)(c)), and consent where relevant – for example when you connect an integration or sign up for emails (Art. 6(1)(a)).

We do not use the data for advertising, retargeting or sale to data brokers.

5. Conversations, recording, transcription and AI

Recording and transcription only happen when the customer has enabled the capability. The customer is the controller for that content and is responsible for having a lawful basis and for informing the parties to the conversation as local rules require.

The content is processed to deliver transcription, summaries, tasks and history inside the customer's own workspace. AI output is generated automatically, can contain errors and should be reviewed by a human before it is relied on for decisions or communication.

EasyAfterCall does not use customer conversation content to train general or foundation AI models. We use external AI providers for AI processing; their processing is governed by the terms and data protection agreements applicable to each provider, and we configure them with the aim that content is processed only to deliver the capability.

6. Integrations and third-party services

Integrations are optional. No third-party account is connected automatically – a user must actively start the connection and approve access with the provider.

We request access incrementally: only the permissions needed for the capability the user enables, and only when that capability is put to use. We work to a principle of data minimisation, and some providers themselves determine which permissions a given action requires.

The connection uses a secure authorisation flow. The main access and refresh tokens for a connected account are exchanged and handled server-side and stored protected in Supabase Vault. Some provider-owned browser components may require a separate short-lived authorisation token for a specific interaction; where that is used, it is limited to that purpose and is not stored by EasyAfterCall.

A user can disconnect an integration in EasyAfterCall at any time. Future calls to that service then stop and the associated token material is deleted; if a cleanup exceptionally fails, it is flagged so it can be followed up.

7. Google Workspace and Google API data

This section describes separately how we access, use, store, share and delete Google user data. Connecting Google is optional and user-initiated; the platform can be used without it.

Google identity: we use the account id, email address and basic profile information to identify the connected account and show which account is linked. For Google Workspace accounts we also use the organisation's workspace domain, solely to identify and validate the connected account.

Gmail: EasyAfterCall uses send-only access to send emails the user has written or approved, from the user's own address. This access does not allow reading the inbox, and we do not read the Gmail inbox through this capability.

Google Calendar: calendar access is used for actions the user initiates – for example creating a meeting after a conversation. After an event has been created, EasyAfterCall may read back that same event to confirm it and retrieve details created by Google, such as a Google Meet link. This capability does not list or read the user's other calendar entries.

Google Sheets import: if the user chooses to import from a spreadsheet, EasyAfterCall uses read-only access to the Google Sheets selected by the user. We do not modify, write to, or delete the user's spreadsheets. File selection can be handled in Google's own Picker, which uses a separate short-lived browser authorisation limited to the Picker and file-selection interaction; EasyAfterCall does not store, log or send that browser token to its servers. EasyAfterCall itself does not list or browse the general contents of the user's Google Drive.

Use: Google data is used to deliver the capability the user has enabled, and for necessary debugging and security around it. If the user deliberately imports spreadsheet rows into the EasyAfterCall workspace, those imported values become ordinary workspace CRM data – for example leads, and contacts if the user later converts them – and are then handled under this policy like other workspace data, including in other features the user chooses to run. Where such later features use AI processors, sections 5 and 9 apply. There are no hidden or secondary purposes, and Google data is not used to train general or foundation AI models.

Storage: the main Google connection access and refresh tokens are handled server-side and stored protected in Supabase Vault. The separate browser authorisation used by Google's Picker is short-lived and is not stored by EasyAfterCall. Data that a capability saves into the customer's workspace – such as an imported contact or a created appointment – is retained as described in section 10.

Sharing: we do not sell Google user data and do not transfer it to data brokers. It may only be processed by the providers necessary to deliver and secure the enabled capability, under contractual data protection and confidentiality requirements, or where required by law or necessary to investigate security or abuse.

Human access: our staff do not access Google user data except where the user specifically requests support or consents in that case, where it is necessary to investigate a security or abuse issue, or where required by law.

Disconnection and deletion: you can disconnect the Google integration in EasyAfterCall at any time. Future Google calls then stop and the connection token material EasyAfterCall stores is deleted. Separately, you can revoke EasyAfterCall's access in your Google Account under “Third-party apps with account access” (myaccount.google.com/permissions). Data already stored in the workspace is handled as described in section 10.

Limited Use: EasyAfterCall's use and transfer of information received from Google Workspace APIs to any other app will adhere to the Google User Data Policy, including the Limited Use requirements.

We do not use Google user data for advertising, retargeting, sale, data brokerage, credit scoring or lending, and we do not use Google Workspace data to develop, improve or train general or foundation AI/ML models.

Your choices: you decide which Google capabilities to enable, access is requested incrementally per capability, and you can disconnect the integration or revoke access in your Google Account at any time.

8. Microsoft 365 and other providers

If a user connects a Microsoft account, identity data is used to identify the connected account, mail access to send user-initiated emails, and calendar access for the calendar actions the user initiates in the implemented integration.

Where calendar data is used to find suitable meeting times, the same data minimisation principle applies: free/busy information rather than meeting content where those details are not necessary.

Other integrations, such as telephony, follow the same principles: optional connection, scoped access, server-side token handling and the ability to disconnect.

9. Sharing, providers and international transfers

We do not sell personal data. We share data only where it is necessary to deliver and secure the service, where the customer has asked us to, or where the law requires it.

We use providers for hosting, operations, AI processing, email and support. Where relevant or required, we enter into data processing agreements and impose contractual confidentiality and security requirements.

Where processing involves transfers of personal data outside the EU/EEA, a valid transfer mechanism under Chapter V of the GDPR is applied. Customers can request specific provider details and the mechanism used on request or as part of the contract.

10. Retention and deletion

We keep data for as long as necessary for the purposes it was collected for, and generally for as long as the customer's subscription is active.

Some data can be handled directly in the product. If you want other data deleted or a workspace wound down, our support team handles the request under our internal procedure. Just contact us and we will take care of it.

Tokens for a connected integration are deleted when the integration is disconnected.

Data we are required to retain – such as accounting records or necessary security logs – may be kept for the period the law requires or permits.

11. Security and access

Data is transmitted encrypted over TLS/HTTPS. Secrets and the main integration access and refresh tokens are handled server-side and stored protected in Supabase Vault, separated from ordinary application data. Any short-lived browser authorisation required by a provider – such as Google's Picker – is limited to that specific interaction and is not persisted by EasyAfterCall.

Access within the platform is governed by permissions and entitlements, and customer data is logically separated between workspaces. Internal staff access customer data only where there is a specific work-related need as described above, and relevant administrative actions can be traced.

We do not claim certifications or compliance attestations we cannot document.

12. Your rights

You have the right to access, rectification, erasure, restriction, objection and data portability, and to withdraw a consent.

If you are registered as a contact by one of our customers, that customer is the controller and your request should generally be directed to them. We are happy to pass it on.

You can complain to the Danish Data Protection Agency, Carl Jacobsens Vej 35, 2500 Valby, Denmark.

13. Cookies

This website uses only the cookies and local storage necessary for operation – such as your language choice. We do not use advertising or tracking cookies here. If we add analytics, we will update this policy before doing so.

14. Changes

We may update this policy. Material changes will be announced on the website or directly to the customer, and the date of the latest update is shown at the top.

15. Contact

Questions about this policy or about the processing of your data can be sent to info@roi-online.dk.