Otengo

How we handle your data

Last updated: 2026-08-25

The other pages here are the contract. This one is the explanation. If you are reviewing Otengo for your store, or answering questions from someone who is, start here - and then check the claims against the Privacy Policy and the Data Processing Agreement, which are the documents that actually bind us.

1. The short version

  1. 1.1Your records are stored in the European Union.
  2. 1.2Calls are kept for 90 days by default, and you can choose anywhere from 30 to 365. There is no “keep forever” option.
  3. 1.3Call recording is off for a new account. You switch it on.
  4. 1.4Callers are always told they are speaking with an AI assistant. Recording silently is not technically possible.
  5. 1.5Anyone who says stop is never contacted again - by any flow, on any channel, for your store.
  6. 1.6Nothing is used to train AI models - not by us, and not by our suppliers, who are contractually bound to the same rule before any call data reaches them.
  7. 1.7Uninstall and your customers’ data is gone within 48 hours, automatically.
  8. 1.8Billing runs through Shopify, so we never see a card number.

2. Who is responsible for what

You are the data controller for your customers. You decide who gets called and why. We are your processor - we do it on your instruction, and we do not contact your customers for our own purposes.

That has one practical consequence worth knowing before you install: your own privacy policy should say that calls to and from your store may be handled by an AI assistant, and may be recorded. It is your notice to give, not ours, and it takes a sentence.

There is one deliberate exception. The list of people who have asked never to be contacted is held by us as controller, not on your behalf, so that deleting your data cannot delete it. If it went, the only record that someone opted out would go with it - and the first thing a reinstall would do is call them again.

3. Where data is held

  1. 3.1Stored in the EU. Call history, transcripts, recordings, contacts, consent records and accounts all live in a European data centre.
  2. 3.2Live calls are not storage. While a call is happening, the audio moves through the telephone network and the speech provider in real time, and some of that is outside Europe. We are not going to tell you everything stays in the EU, because it does not - and a supplier who tells you otherwise about a voice product is either wrong or is not describing the call itself.
  3. 3.3Those transfers run on the Standard Contractual Clauses, with the UK Addendum for UK data. We keep a written risk assessment for each provider and will share it with you.

4. How long we keep it

  1. 4.1Recordings and transcripts: your choice of 30, 90, 180, 365 days. After that only the date and duration survive, for billing - which is no longer personal data.
  2. 4.2Consent records: for as long as your account exists. They are the evidence a call was allowed, and they are the thing you would need if challenged.
  3. 4.3The opt-out list: indefinitely. It holds phone numbers and nothing else.
  4. 4.4After you uninstall: your customers’ data goes within 48 hours; your own settings are held for up to 30 days so a reinstall restores your setup.

These are enforced by a job that runs daily, not by anyone remembering to do it. Any new place we store personal data has to be added to that job - in this codebase, forgetting to is treated as a defect, not a nice-to-have.

5. What the caller hears

Every call opens by telling the caller they are speaking with an AI assistant, and - if you have turned recording on - that the call is recorded.

You can word it however you like. You cannot remove it. The system refuses to save a greeting without the disclosure, and if you take the recording notice out of a greeting, recording switches itself off and we tell you why.

This is checkable rather than promised. Start a trial, delete the AI disclosure from your greeting, and press save. It will not let you.

6. Who can see it

6.1. Other merchants - never

Each store’s data is separated at the database level, not just in the application. Even a bug in our code cannot show one merchant another merchant’s calls.

6.2. Our team - in two situations only

  • You ask us for help with something specific and we need to look at it.
  • We are investigating a fault or a suspected abuse of the calling rules.

Access is limited to the people who need it, each with their own account and strong authentication, and every access to a merchant’s account is logged with who, when and why. Those logs are kept for 24 months, and you can ask for the entries relating to your store.

7. What we do to protect it

  1. 7.1Encryption in transit and at rest, backups included.
  2. 7.2Recordings in private storage, reachable only through a short-lived link issued after a permission check - never a public address that could be guessed or shared.
  3. 7.3Separate test and production systems, with no real customer data in testing.
  4. 7.4No personal data in our logs. Not transcripts, not phone numbers, not names, not whole payloads. Identifiers and timings only. This is the rule most often broken quietly by software, so we made it a hard rule in the codebase.
  5. 7.5Written incident response and data loss prevention procedures.

8. Deletion, and getting your data out

  1. 8.1Export your call records and contacts yourself, at any time, without asking us.
  2. 8.2Export your consent records the same way - who agreed, when, and to exactly what wording. That export is the point of collecting them.
  3. 8.3Deleting a call deletes the recording and the transcript, including the copy held by our speech provider. Deleting only our own copy would make the promise worthless.
  4. 8.4Uninstalling deletes everything about your customers automatically.

9. Your customers' rights

Requests come to you, because you are the controller. Almost everything you need is already in the app: find the person, see their calls, export them, delete them.

One request we act on ourselves, immediately, however it reaches us: a request to stop being contacted. Waiting for you to action it would mean calling somebody who has already said no. We suppress the number and tell you. There is a page for your customers explaining this at otengo.com/received-a-call.

10. If something goes wrong

  1. 10.1We tell you within 48 hoursof becoming aware of a breach affecting your customers’ data - not when the investigation finishes.
  2. 10.2You have 72 hours to notify your regulator if it is notifiable. Our deadline is shorter than yours on purpose, so the clock is not already running out when you hear about it.
  3. 10.3We keep a register of incidents, including the ones we decide are not notifiable and the reasoning.

11. Who we use

Named individually, with what each one does and what it can see, at otengo.com/subprocessors. We give 30 days’ notice before a new one starts, and you can object.

Shopify is not on that list, and that is not an oversight: Shopify is your platform under your own agreement with them, so it is not a supplier we engage on your behalf.

12. What we do not do

  1. 12.1Sell personal data. Any of it. Ever.
  2. 12.2Use your data, or your customers’ data, to train AI models - including in anonymised or aggregated form, and including by our suppliers.
  3. 12.3Use one merchant’s data to improve another merchant’s results.
  4. 12.4Contact your customers for our own purposes.
  5. 12.5Record calls without telling the caller.
  6. 12.6Offer unlimited retention, or a way to keep recordings forever.
  7. 12.7Take payment card details on a call.

13. Documents we can give you

  1. 13.1A signed Data Processing Agreement, if your process needs a signature.
  2. 13.2A pre-completed data protection impact assessment for a typical Otengo deployment, which you adapt rather than write from scratch.
  3. 13.3Our transfer risk assessments for suppliers outside the EEA.
  4. 13.4A summary of our security measures and incident procedure.
  5. 13.5The access log entries relating to your store.

Ask at info@otengo.com. If your reviewer needs something not on this list, ask anyway - we would rather answer it than have them assume.

If you think we have got something wrong, tell us first. You can also complain to the State Data Protection Inspectorate (Valstybinė duomenų apsaugos inspekcija) in Lithuania, to the Information Commissioner's Office (ICO) in the UK, or to your own supervisory authority.