Relay
Legal

Privacy Policy

This policy explains what data Relay processes, why, and how you stay in control. Relay is designed to never see your secrets in clear.

Last updated : 13/06/2026

Template for guidance only. This document must be tailored to your company and reviewed by a lawyer before publishing. Bracketed mentions are fields to fill in.

01Data controller

The data controller is [COMPANY], [ADDRESS]. For any request about your data: [EMAIL].

02Data we collect

Account: email, name, password (hashed). Organization: workspaces, members, roles. Usage: call and SMS logs, contacts, notes — stored to provide the service.

Telecom credentials: your Auth Token is encrypted at rest (AES-256-GCM) and is never exposed to the browser nor stored in clear.

AI keys (BYOK): if you enable AI, your OpenAI/Claude key is encrypted. Content sent to the AI goes through YOUR provider; Relay does not retain it nor use it to train any model.

03Purposes

Your data is used solely to provide the service (calls, SMS, AI, billing) and to ensure its security. No data resale.

04Sub-processors

Relay relies on providers: your telecom provider (Twilio, SignalWire or Telnyx, as you choose), Stripe (payment), [HOSTING] (hosting), and your AI provider if enabled. Each processes data on Relay’s behalf under its own terms.

05Retention

Data is kept while your account is active. Deleting your account triggers a full purge (workspaces, calls, SMS, contacts, organization, user).

06Your rights

Under GDPR and Law 25, you have rights of access, rectification, erasure and portability. Exercise them from your workspace or by writing to [EMAIL].

07Security

Encryption at rest of secrets (AES-256-GCM), short-lived access tokens, signed webhooks, HTTPS everywhere, payments via Stripe (the card is never stored by Relay).

08Contact

For any question about this policy or your data: [EMAIL].