MyDaddy.io (“MyDaddy.io”, “we”, “us”) provides a business phone system and AI agent stack for small teams. This policy describes what data we collect, why, how long we keep it, and the choices you have. It applies to both visitors to mydaddy.io and to workplaces created on the platform.
1. Who this policy covers
- Visitors to our marketing site (
mydaddy.io,/home.html,/integrations.html, etc.) — anonymous browsing. - Workplace owners & agents — people who sign up for an account and configure the phone system.
- End users of a workplace — the customers, prospects, and website visitors who interact with a workplace's AI agent or call its phone numbers.
If you're an end user of a workplace (for example, someone calling a business that uses MyDaddy.io), the business — not MyDaddy.io — is the data controller for the record of that interaction. MyDaddy.io acts as the data processor on that business's behalf. Data subject requests should go to that business first. We'll honour the request if they direct us to.
2. What we collect
2.1 Account data
- Name, email, and authentication identity (Google, Microsoft, or username + password).
- Workplace name, subdomain, and the combo (region) your workplace runs on.
- Per-workplace single sign-on configuration (identity-provider details and credentials) if you've enabled it.
- Billing contact information (when a paid plan is active).
- For a Cliq Huddle install: Cliq name, email, ZUID, Cliq organization id, workplace name, and up to 50 directory people from that Cliq org.
2.2 Phone data
- Outbound and inbound call metadata: extension, to/from phone number, start/end time, outcome, duration.
- SMS metadata: to/from, timestamp, delivery status.
- Registration state for desk phones and softphones (username, device, last seen).
- Voicemail audio when a caller leaves a message. Call recordings and AI transcripts when the product records or transcribes that session (there is no Settings → Retention toggle today).
2.3 AI agent sessions
- Chat/voice transcripts between an end user and the embedded site widget.
- Verification metadata (one-time SMS code delivery status — the code itself is never stored in plaintext after use).
- Inferred intent and a session summary the AI agent writes back to the workplace's CRM/helpdesk, if one is connected.
- For the AI caller agent: the list of leads pulled from the connected CRM under the filters you've configured, plus each call's outcome.
2.4 Integration data
- Access tokens for CRMs and helpdesks you connect (Zoho CRM, Zoho Desk, Freshdesk, etc.). Stored per workplace and used only to read/write records on your behalf.
- Webhook destination URLs and the signing secrets you configure.
2.5 Product telemetry
- Anonymous request logs at the edge (nginx access logs; retained 30 days and then rotated).
- Aggregate usage metrics in Graphite / Grafana (call volume, active workplaces, error rates). No per-call payload is included.
- Crash/exception traces from the sip-server and portal, scrubbed of caller/callee identity before storage.
2.6 Cookies
- Session cookies for portal login (
sessionid,csrftoken) — essential, first-party, HTTP-only. - No advertising, no cross-site tracking. We do not use Google Analytics or similar third-party trackers on the marketing site.
2.7 Cliq Huddle install
Installing the published Huddle extension creates a workplace on MyDaddy.io. We store the installer’s Cliq identity and a directory snapshot (up to 50 people) so roster mapping works. We also create a sales Lead in mydaddy.io’s own Zoho CRM (not your CRM) so we can follow up on the workplace. That Lead is not written to tenant Redis zoho-mcp-* keys.
2.8 Slack / Crossbar
Installing the published Crossbar Slack app creates or revives a workplace on MyDaddy.io. Slack sends us user and team (and, on Grid, enterprise) ids, slash-command text, interactivity payloads, file bytes for greetings and voicemail, and work emails used only to bind a Slack user to the workplace roster. We do not use Slack huddle media. Fields Slack sends that we do not need are received and unused. Call audio stays on mydaddy.io. Retention follows the same workplace clocks as other call and voicemail data. To delete Slack-derived data, email privacy@mydaddy.io or uninstall Crossbar from Slack (that cancels Billing; it does not by itself delete the Workplace).
2.9 Google Chat / Crossbar
Installing the published Crossbar Google Chat app creates or revives a workplace on MyDaddy.io. Google Chat sends us Workspace email, Chat user id, and Workspace domain / customer ids, plus slash-command text used to mint a Join URL. We do not use Google Meet or in-Chat audio. Consumer Gmail and Chat guests cannot place calls. Call audio stays on mydaddy.io. We also create a sales Lead in mydaddy.io’s own Zoho CRM (not your CRM). Retention follows the same workplace clocks as other call data. To delete Chat-derived data, email privacy@mydaddy.io or uninstall Crossbar from Google Workspace Marketplace (that cancels Billing; it does not by itself delete the Workplace). Leaving one Chat space is not uninstall.
2.10 Microsoft Teams / Crossbar
Installing the published Crossbar Microsoft Teams app creates or revives a workplace on MyDaddy.io. Teams / Entra sends us work email, Entra object id, and tenant id, plus slash-command text used to place a call. We use Azure Communication Services to ring the Teams desktop or web client; we do not use Graph application-hosted media or a browser Join page. Personal Microsoft accounts and Teams guests cannot place calls. Call audio is mixed on mydaddy.io. We also create a sales Lead in mydaddy.io’s own Zoho CRM (not your CRM). Retention follows the same workplace clocks as other call data. To delete Teams-derived data, email privacy@mydaddy.io or uninstall Crossbar from the Teams tenant (that cancels Billing; it does not by itself delete the Workplace). Closing a 1:1 chat is not uninstall.
2.11 WhatsApp / Crossbar
Connecting WhatsApp via Embedded Signup creates or revives a workplace on MyDaddy.io. Meta sends us the WhatsApp Business Account id, Cloud API phone number id, business E.164, work email of the installer, and message text used to place a call. Call audio uses SIP-TLS + SDES SRTP + G.711 between Meta and mydaddy.io; we do not use a browser Join page. We store Meta-generated SIP credentials as write-only workplace secrets. Group chats cannot place calls. Business-initiated agent rings require the user’s WhatsApp call permission. We also create a sales Lead in mydaddy.io’s own Zoho CRM (not your CRM). Retention follows the same workplace clocks as other call data. To delete WhatsApp-derived data, email privacy@mydaddy.io or disconnect WhatsApp (that cancels Billing; it does not by itself delete the Workplace). Losing one chat is not uninstall.
3. How we use it
- To run your phone system: route calls, deliver SMS, keep phones registered, store voicemail and recordings, transcribe audio when asked.
- To run your AI agents: process a visitor's chat/voice with your configured LLM / STT / TTS providers, keep transcripts for review, update your CRM/helpdesk with session summaries.
- To secure the platform: rate-limit abusive traffic, detect fraudulent calls, investigate incidents.
- To bill you: track usage against the plan you're on.
- To communicate service updates: outages, security patches, significant feature changes.
We do not sell personal data, share it with advertisers, or train our own foundation models on your workplace content. Third-party AI providers (OpenAI and related STT/TTS vendors) process content on a per-request basis under their own data-processing terms. The current processor list is on the DPA & subprocessors page.
4. Legal bases (GDPR)
- Performance of a contract: running the phone system and agents you've signed up for.
- Legitimate interest: platform security, abuse prevention, aggregate product metrics.
- Consent: installing Huddle, creating a workplace, or using optional AI features. Email privacy@mydaddy.io or uninstall Huddle to stop new collection going forward.
- Legal obligation: responding to valid court orders and subpoenas.
5. Retention
- Account + workplace config: kept while the workplace is active; deleted within 30 days of workplace deletion.
- Call/SMS metadata: 13 months by default.
- Voicemail and any recorded audio: 90 days by default.
- AI chat/voice transcripts: 90 days by default.
- Edge access logs: 30 days, then rotated.
- Backups: encrypted daily Postgres snapshots retained 35 days.
There is no Settings → Retention page today. Email privacy@mydaddy.io to request deletion or a shorter hold.
6. Sharing
We only share data with processors that are essential to operating the service:
- Phone carriers you provision (Twilio, SignalWire, Telnyx, Bandwidth, or any other phone provider) — they see the minimum call data they need to carry the call.
- AI providers you select (OpenAI, Deepgram, ElevenLabs, etc.) — they see only the specific request content needed for a single inference.
- CRMs & helpdesks you connect (Zoho CRM, Zoho Desk, Freshdesk, etc.) — they receive the records you've authorised the workplace to write.
- Our cloud hosting provider — for compute, network, and storage underlying the MyDaddy.io platform.
- Authorities, when compelled by valid legal process. We push back on overbroad requests.
7. International transfers
Each MyDaddy.io workplace is pinned to a combo (a regional server instance). Your workplace's Postgres row records the combo id, and every call / agent session for that workplace is handled on that combo's infrastructure. If you need your data to stay in a specific jurisdiction, choose a combo located there during signup. Cross-combo transfer only happens with an explicit admin action (migration between regions).
8. Security
- Encrypted (TLS) connections for all public traffic, including browser calling and the admin portal.
- Phone signalling is encrypted end-to-end where your phone provider supports it.
- Per-workplace credential isolation: CRM tokens, provider keys, and embed keys stay scoped to the workplace they belong to.
- Our managed database is the source of truth for workplace config; fast caches store only what the phone system needs at call time.
- Third-party credentials are never logged or returned through the portal API.
- Superadmin actions are recorded in an append-only audit log.
9. Your rights
Depending on where you live (GDPR, UK GDPR, CCPA/CPRA, etc.) you may have the right to:
- Access a copy of the personal data we hold about you.
- Correct inaccurate data.
- Delete your data (subject to retention we're legally required to keep).
- Port your data to another service.
- Object to or restrict certain processing.
- Ask us to stop optional AI processing by emailing privacy@mydaddy.io or by uninstalling Huddle.
Email privacy@mydaddy.io from the address on your workplace. We'll reply within 30 days.
10. Children
MyDaddy.io is a B2B product. It is not intended for, and not marketed to, anyone under 16. If you believe a child's data has been collected by a workplace, email privacy@mydaddy.io so we can work with the workplace admin to remove it.
11. Changes to this policy
We'll post material changes to this page and update the “Last updated” date at the top. If a change meaningfully reduces your rights, we'll also email workplace admins at least 14 days before the change takes effect.
12. Contact
Privacy questions, data-access or deletion requests, and security reports all go to privacy@mydaddy.io. For general product questions, see the Contact page or chat us through the widget on this site.