GlobalCanadaEuropeAsia-Pacific
Sign in

GDPR and the European Union

GDPR practices

Distronode Corporation • Last Updated: September 21, 2026

01. Who We Are To You

Distronode Corporation is a Canadian company, incorporated federally under the Canada Business Corporations Act. We have no establishment in the European Union: no office, no branch and no staff there.

For the personal data inside your workspace, the callers, contacts, transcripts, messages and meetings your receptionist handles, you are the controller and we are your processor. Our Data Processing Agreement sets those terms. For your own account, your sign-in, your subscription and the record of how you use this site, we are the controller.

We have not appointed a representative in the Union under article 27, and we would rather say so plainly than let the absence read as an oversight. The decision sits with counsel. Every request under this page goes to legal@distronode.com, which reaches Sean Dean, our founder and the person accountable for privacy here.

legal@distronode.com

02. Where A European Workspace Runs

In the Union

A European workspace is stored in Frankfurt on Amazon Web Services, in eu-central-1, and the website that serves it runs on the same host. Speech recognition and speech synthesis run on European endpoints. The language model that reasons during a call runs in the Union, in europe-west4. The media plane carrying the audio, the signalling bus and the voice agent itself all run in Frankfurt.

Error diagnostics go to Sentry in Germany and infrastructure telemetry to New Relic in the Union, and the encrypted backup of your database is written to a bucket created in Cloudflare's European jurisdiction. Those three are out of region for a Canadian workspace and in region for a European one.

What still leaves the Union

Some processing still leaves the Union, and our Terms set it out one sentence at a time so that each item can be checked against the sub-processor register. Sign-in, the directory that routes a telephone number to a workspace, the record of who belongs to your workspace, and your subscription and payment records are held in the United States. The shared operational state that every European request touches is a United States database, and a scheduled job that sweeps all four of our regions runs on whichever origin holds the lock for it.

Our sites are reached through Cloudflare's global edge, so the encrypted connection from a browser ends at whichever location is nearest the visitor. Account, verification and newsletter email is delivered from the United States by Postmark. The key that encrypts the credentials you connect, and the store holding our own secrets, are managed by Google Cloud in a global location. The optional video avatar is rendered in the United States. A push notification that wakes your phone is delivered from outside the Union, carrying identifiers only.

Telephony splits by the number rather than by the workspace. A call on your European number is delivered at Twilio's Dublin gateway and answered in Frankfurt, and a call your workspace places is originated in Frankfurt. A call arriving on a United States or Canadian number issued through Twilio reaches us in the United States and is answered there. A text message on a number we issue through Telnyx is carried through Telnyx's United States messaging interface. A support request you send us goes to a single desk hosted in Canada.

03. Transfers

Your transfer to us rests on the European Commission's adequacy decision for Canada, Decision 2002/2/EC, which covers Canadian commercial organisations subject to PIPEDA. We are one, so the transfer from you to us needs no separate clauses.

What we send onward to the United States is our own transfer rather than yours, and it is the exposed leg. It rests on the standard contractual clauses in each vendor's data processing terms, Module Two where we are the controller and Module Three where we pass your data onward as your processor. Google LLC also holds a Data Privacy Framework certification.

We are not eligible for that Framework ourselves. It is open to organisations under the jurisdiction of the United States Federal Trade Commission or Department of Transportation, and a Canadian company is neither, so we do not claim it.

We have written a transfer impact assessment for that leg, covering the supplementary measures and United States surveillance law. It is held in our records and we provide it to a customer under the Data Processing Agreement.

04. The AI Act

Under the AI Act we are the provider of the receptionist and the business that puts it on its telephone line is the deployer. The two roles carry different duties, so this section names both rather than leaving you to work out which is yours.

What we do as the provider

The receptionist says that it is an automated assistant at the start of every call, before the greeting, and says that the call is transcribed. The sentence is fixed: we write it, and a business cannot edit it away.

A European workspace cannot switch that disclosure off. The toggle is locked on in the dashboard, the interface refuses a request to turn it off, and a workspace that stored an off value before this rule existed is overridden when the call is answered. A call we cannot route to a business at all is answered by our own fallback receptionist, and that one discloses too.

The sentence is spoken in the receptionist's own language. English, French, German, Spanish, Dutch and Italian are written out, which is every language the language picker offers. A receptionist set to anything else opens in English.

We run no emotion recognition. The optional video avatar renders and lip-syncs only, in a mode that refuses a perception layer outright, so it performs no biometric analysis for us. Where a call is given a sentiment, it is inferred from the words of the transcript after the call, never from the sound of a voice.

What the deployer owes

Telling the people it calls that they are speaking to a machine is the deployer's duty as well as ours, and the deployer is the party that knows the context of the call.

A lawful basis for outbound calling belongs to the deployer. In most member states an automated calling machine used for direct marketing needs the prior consent of the person called, and an opt-out list is not that consent.

Recording and monitoring law is national. A deployer has to meet the rules of its own member state for what is kept from a call, which on this platform is a transcript and a summary.

What the receptionist can and cannot do

It answers from the knowledge base and the instructions its business writes. It can transfer a call to a person where the business has set a number to transfer to, take a message, and book a meeting.

It does not make decisions with legal effect about the people who call. It does not price, approve, refuse or score anyone. It cannot reach another business's workspace: that boundary is enforced by the database rather than by the application on top of it.

It can be wrong. It works from what a business gave it and from what it heard on a telephone line, and a caller who would rather speak to a person should ask for one.

05. Rights

If you hold a workspace with us

You can take your data out and you can delete the account yourself. In the dashboard, under Billing, Export Workspace Data has an Export Data button that returns contacts, calls, transcripts, messages, meetings and settings as JSON.

Below it, the Danger Zone has Delete Account, which asks for your password again on purpose so that an unattended session cannot destroy an account.

A request you send us by email is answered without undue delay and within 30 days. Asking us to erase your data, or deleting the account yourself, starts the erasure immediately.

If a business called you

The business that called you is the controller of the record of that call, not us. It decides why the call was made and what is kept, so your request belongs with it first. It can act on your request inside its own workspace, and we assist it under our Data Processing Agreement.

If you cannot reach that business, write to legal@distronode.com and we will pass the request to the controller. We will not answer it in their place, because the decision is theirs to make, and telling you that is better than leaving you waiting for an answer that is not ours to give.

06. Retention

Where a window exists it is named here with what enforces it. Where none exists this page says so, rather than implying a limit that no code applies.

Call audio
None is captured. No part of the platform records a call, so there is no audio to keep or to delete. A call leaves a transcript and a summary.
Transcripts, summaries and call records
Kept while the account is active. There is no retention period a workspace can set today, so a controller cannot meet article 5(1)(e) for this category through our settings. Delete them from the dashboard, or ask us and we will.
Contacts, messages, meetings and knowledge-base content
Kept until you delete them.
Sign-in history
90 days.
Support correspondence
365 days after the request was opened. Requests still being worked on are kept until resolved.
Telephone number registration documents
Deleted 30 days after the last number in that country is released or the registration is withdrawn, and immediately when the account is deleted.
Backups
Fourteen daily and eight weekly encrypted copies of each region's database. Each is encrypted before it leaves the region and the key does not travel with it.

07. Breaches

We keep a register of confidentiality incidents and a written procedure behind it, and the person accountable for privacy maintains both.

Where a breach affects your workspace we notify you without undue delay, and in any case within 48 hours of confirming it, with the information you need to meet your own notification duties. That is the commitment our Data Processing Agreement makes.

Where we are the controller, we notify the supervisory authority within 72 hours of becoming aware of a breach, unless it is unlikely to result in a risk to people. Awareness is the moment we have reasonable certainty that one has occurred, not the moment we finish diagnosing it.

Having no establishment in the Union, we have no lead supervisory authority. A notification therefore goes to the authority of every member state whose residents are affected, which means working out where affected people live inside the 72 hours rather than after them.

08. Cookies

Nothing that needs consent runs before you give it. Analytics and advertising storage start denied, for every visitor and on every one of our sites, and stay denied until you accept.

Today the choice is accept or decline, not one purpose at a time. We would rather name that limit than describe a control we do not ship.

Cookie preferences, in the footer of every page, reopens the choice whenever you want it. Withdrawing consent takes effect from the moment you withdraw it and does not undo what was done while it was given.

Related documents