Privacy Policy
This policy explains what data Relay processes, why, and how you stay in control. Relay is designed to never see your secrets in clear.
Last updated : 13/06/2026
Template for guidance only. This document must be tailored to your company and reviewed by a lawyer before publishing. Bracketed mentions are fields to fill in.
01Data controller
The data controller is [COMPANY], [ADDRESS]. For any request about your data: [EMAIL].
02Data we collect
Account: email, name, password (hashed). Organization: workspaces, members, roles. Usage: call and SMS logs, contacts, notes — stored to provide the service.
Telecom credentials: your Auth Token is encrypted at rest (AES-256-GCM) and is never exposed to the browser nor stored in clear.
AI keys (BYOK): if you enable AI, your OpenAI/Claude key is encrypted. Content sent to the AI goes through YOUR provider; Relay does not retain it nor use it to train any model.
03Purposes
Your data is used solely to provide the service (calls, SMS, AI, billing) and to ensure its security. No data resale.
04Sub-processors
Relay relies on providers: your telecom provider (Twilio, SignalWire or Telnyx, as you choose), Stripe (payment), [HOSTING] (hosting), and your AI provider if enabled. Each processes data on Relay’s behalf under its own terms.
05Retention
Data is kept while your account is active. Deleting your account triggers a full purge (workspaces, calls, SMS, contacts, organization, user).
06Your rights
Under GDPR and Law 25, you have rights of access, rectification, erasure and portability. Exercise them from your workspace or by writing to [EMAIL].
07Security
Encryption at rest of secrets (AES-256-GCM), short-lived access tokens, signed webhooks, HTTPS everywhere, payments via Stripe (the card is never stored by Relay).
08Contact
For any question about this policy or your data: [EMAIL].