Last updated 2026-09-26
Privacy policy
This policy explains what personal data 100 Dials collects, why, how long we keep it, and the rights you have. It is written to be read, not skimmed.
1. Who we are
100 Dials, (“100 Dials”, “we”) operates the 100 Dials service at https://100dials.com. We are the data controller for the data described in sections 3 and 4, and a data processor for the customer content described in section 5. Contact: privacy@100dials.com.
2. Scope
This policy covers visitors to our website, people who sign up for a trial or subscription, and people who use the service as members of a customer workspace. Where your employer created the workspace, your employer decides why the service is used and is the controller for content you create in it; this policy describes our role as their processor.
3. Data we collect on the website
- Server logs: IP address, user agent, requested pages, timestamps. Kept for 30 days for security and debugging. Legal basis: legitimate interest in running a secure service.
- Analytics cookies (only with your consent): pages viewed, referrer, approximate location derived from IP, device type, and interactions such as button clicks. Processed by an analytics provider hosted in the EU. See our cookie policy. Legal basis: consent. You can withdraw it any time from the cookie settings link in the footer.
- Contact: if you email us, we keep the correspondence for as long as needed to handle it and for up to 24 months afterwards.
4. Account data
- Identity: name, work email address, password hash, workspace membership and role. Legal basis: performance of a contract.
- Billing: plan, seats, invoices. Payment card details are handled by our payment provider and never touch our servers.
- Product usage: calls made, scores, streaks, assignments, and events such as sign-ins. Used to provide the service and, in aggregate, to improve it. Legal basis: contract and legitimate interest.
- Transactional email: invites, security notices, trial status. These are not marketing and cannot be opted out of while you have an account.
5. Customer content: recordings, transcripts and targets
When a rep makes a practice call, the audio and its transcript are processed to run the conversation and to score it. When a manager uploads call transcripts, they are processed to extract phrasing, objections and patterns. This content may contain personal data about reps and, in uploaded transcripts, about third parties. Your workspace owner is the controller of this content and is responsible for having a lawful basis to upload it.
- We use this content only to provide the service to your workspace. We do not use it to train machine-learning models, and our AI subprocessors are contractually prohibited from doing so.
- Content is isolated per workspace and enforced at the database level.
- Content is deleted when you delete the call, the source, or the workspace, and removed from subprocessors within 30 days.
6. Subprocessors and international transfers
We use a small number of specialised providers for hosting, real-time voice, call scoring and analytics, each bound by a data processing agreement. The named list is part of our DPA, available on request. Where a provider processes data outside the EEA, transfers rely on the European Commission's Standard Contractual Clauses and, where applicable, the EU-US Data Privacy Framework. A data processing agreement is available on request.
7. Retention
| Data | Retention |
|---|---|
| Server logs | 30 days |
| Analytics (with consent) | 12 months |
| Account data | Life of the account, then 90 days |
| Recordings and transcripts | Life of the workspace, or until deleted |
| Invoices | 10 years (statutory) |
8. Your rights
Under the GDPR you can ask us to access, correct, delete, restrict or export your personal data, and you can object to processing based on legitimate interest. Email privacy@100dials.com; we respond within 30 days. If you are a member of a customer workspace, we may refer your request to your workspace owner where they are the controller. You can complain to your local supervisory authority; ours is the State Data Protection Inspectorate of the European Union.
9. Security
Encryption in transit and at rest, per-workspace isolation, least-privilege access for staff, and logged support access. Details on the trust page. If we learn of a breach affecting your data we will notify you without undue delay.
10. Children
The service is for business use by adults. We do not knowingly collect data from anyone under 16.
11. Changes
We will post changes here and, for material changes, email workspace owners at least 14 days in advance.