Privacy and Cookies Policy
Last updated: 2026-08-25
1. Who we are and how to contact us
- 1.1Otengo is operated by Frominbox, MB (mažoji bendrija), company code 307162506, VAT LT100019538712, registered at A. Juozapavičiaus g. 28, LT-09311 Vilnius, Lithuania.
- 1.2For anything about privacy or data protection, email info@otengo.com. We answer data protection questions within 30 days and usually much sooner.
- 1.3We have not appointed a data protection officer. We keep that decision under review as the service grows, and the general address above reaches the person responsible.
- 1.4Where we are required to designate a UK representative under Article 27 of the UK GDPR, we will do so and name them here.
2. Our role, and yours
- 2.1For your customers’ data we are a processor. You decide who is called, why, and what the assistant says. We act on your instructions. You are the controller, and it is your privacy policy that has to tell your customers about it - not this one.
- 2.2For your own data we are a controller. Your account, your billing, the emails we send you and the way you use the app are ours to explain, and section 4 does that.
- 2.3For the record of who has opted out we are also a controller. This is the odd one, and it is deliberate: if that list were only held on your behalf, deleting your data would erase the only proof that somebody asked never to be called again. Keeping it protects them, not us. It contains phone numbers and nothing else.
3. Your customers' data
Processed on your behalf, under the Data Processing Agreement. In outline:
- 3.1People who call your store - their phone number, what they say, the transcript, a recording if you have switched recording on, what the call was about and how it ended, and the order or account we matched them to.
- 3.2People we call or text for you - name, phone number, the order or delivery details the call is about, whether they have given permission to be contacted, when they were last contacted, and what happened on the call.
- 3.3From Shopify- we read the orders, customers, products and fulfilment records your chosen features need, so the assistant can answer “where is my order” without asking the caller to recite it. We do not request access to every historical order.
- 3.4Consent records - who agreed to be contacted, when, through which channel, and the exact wording they saw or heard. Kept because it is the only thing that answers a challenge months later.
Otengo is not built for sensitive data and you should not configure the assistant to collect it. Someone may still mention something personal on a call; where that reaches a transcript it is protected like everything else and deleted on the same schedule.
4. Your data, and visitors to this site
4.1. If you use Otengo
- Your name, email, store domain and role, from Shopify when you install.
- What you configure, and a log of administrative actions on the account.
- Usage: minutes used, messages sent, what to bill. Billing itself runs through Shopify, so we never see your card details.
- Support conversations with us.
We rely on our contract with you for running the service and billing it, our legal obligations for tax and records, and our legitimate interests in keeping the service secure, supporting you, and telling you about changes that affect you.
4.2. If you just visit this website
- Necessary cookies, and technical request data such as your IP address, kept briefly to keep the site working and secure.
- Analytics and marketing cookies only if you agree - see section 14.
- Anything you send us through a form or by email.
5. Call recording and what the caller hears
- 5.1Callers are always told they are speaking with an AI assistant. This is not a reminder in a help page: the system will not save a greeting that leaves it out, and if a stored greeting somehow lacks it, the disclosure is added before the call connects.
- 5.2Recording is off until the merchant switches it on, and it can only be switched on once the greeting says calls are recorded. Remove that from the greeting and recording switches itself off. Recording silently is not something this product can do.
- 5.3You can check that claim rather than trust it. Open a trial account, take the AI disclosure out of the greeting, and try to save.
- 5.4The reasons differ by country - several US states require everyone on a call to agree to recording, the UK requires reasonable efforts to inform people, and the EU requires the AI to be disclosed - but the behaviour is the same everywhere, because building three versions of this would mean getting one of them wrong.
7. Where data is held
- 7.1Records are stored in the European Union: call history, transcripts, recordings, contacts, consent records, accounts.
- 7.2Live calls are different. Audio travels through the telephone network and the speech provider as it happens, and some of that is outside the EEA. We are not going to claim everything stays in Europe, because it does not.
- 7.3Those transfers are covered by the Standard Contractual Clauses, with the UK Addendum for UK data, and we keep a written risk assessment for each provider. Where a supplier also holds an EU-US Data Privacy Framework certification we treat it as an extra safeguard, not the main one.
8. How long we keep things
| What | How long |
|---|---|
| Call recordings, transcripts, caller names and numbers | Chosen by the merchant: 30, 90, 180, 365 days, 90 by default. Afterwards only the date and duration remain, for billing. There is no unlimited option. |
| Everything about your customers, after you uninstall | Deleted within 48 hours. |
| Your agent settings and flows, after you uninstall | Kept up to 30 days so a reinstall restores your setup, then deleted. |
| Consent records | For as long as the account exists - they are the proof a call was permitted. The IP address attached to them is erased after 24 months. |
| The list of people who asked not to be contacted | Indefinitely, and it holds phone numbers only. Deleting it is the one thing that could cause them to be called again. |
| Records of data exports and of staff access to an account | 24 months. |
| In-progress call records | 24 hours. |
| Billing and accounting records | As long as the law requires, typically 10 years, with names and numbers stripped. |
These periods are enforced by a job that runs every day, not by anyone remembering. A table holding personal data that is not on that job’s list is treated as a defect.
9. Security
- 9.1Encrypted in transit and at rest, backups included.
- 9.2Recordings sit in private storage and are reachable only through short-lived links issued after a permission check.
- 9.3Each store’s data is isolated at the database level, so one merchant cannot read another’s even if application code is wrong.
- 9.4Access is limited to the few people who need it, with individual accounts and strong authentication, and any access to a merchant’s account is logged.
- 9.5Personal data is never written to our application logs - no transcripts, phone numbers, names or whole payloads. Identifiers and metrics only.
- 9.6More detail is on our security page.
10. Deleting data
- 10.1Deleting a call deletes the recording and the transcript, including the copy held by our speech provider. A promise that data is gone is worth nothing if it only covers our own database.
- 10.2Uninstalling deletes your customers’ data within 48 hours, automatically.
- 10.3Before you go, you can export your call records and contacts yourself.
- 10.4The suppression list survives deletion, on purpose, for the reason in section 2.
11. Your rights
As a merchant, in relation to your own data, you can ask for a copy, correction, deletion, a portable export, or restriction, and you can object to processing based on legitimate interests. Email info@otengo.com. There is no charge and we respond within 30 days.
For your customers’ data, the requests come to you - you are the controller. Most of what you need is in the app already, and we help with the rest.
12. If you received a call
If an Otengo number called you, the store that called is responsible for deciding to do so, and we placed the call for them. You can stop all future calls immediately, ask for the recording, or ask for it to be deleted. How to do each is on the page for people who received a call, in plain language and without needing an account.
Saying “stop” on the call itself is the fastest way, and it is acted on straight away rather than at the end of the campaign.
13. Complaints
- 13.1Tell us first if you can - info@otengo.com. Most complaints are faster to fix than to escalate.
- 13.2Lithuania and the EU - our lead authority is the State Data Protection Inspectorate (Valstybinė duomenų apsaugos inspekcija). You may also complain to the authority where you live.
- 13.3United Kingdom - the Information Commissioner's Office (ICO), at https://ico.org.uk/make-a-complaint/ or 0303 123 1113.
- 13.4United States - unwanted calls can be reported to the Federal Communications Commission (FCC), and other complaints to the Federal Trade Commission (FTC) or your state attorney general.
15. Changes to this policy
- 15.1The date at the top is the current version. Material changes are notified in the app before they take effect.
- 15.2If a change affects how your customers’ data is handled, we tell you in time to look at it, because you may need to update your own privacy policy.