Pharmaphone – AI phone assistant for pharmaciesPharmaphone

Privacy policy

This is a courtesy translation of our German Datenschutzerklärung. The German version is the legally binding one; where the two differ, the German text applies.

1. Controller

The controller within the meaning of the GDPR is RR42 UG (haftungsbeschränkt), Marienstraße 4, 31832 Springe, Deutschland. Contact: info@rr42.de or via the contact form on this website. We have appointed an external data protection officer; in data protection matters you can reach them at datenschutz@rr42.de.

2. Data we collect

This website sets no cookies and stores no persistent identifiers in your browser. Merely opening a page loads only the cookieless reach measurement, which transmits your IP address to the analytics provider (see “Web analytics”). Every other service loads only once you start a feature yourself. We process personal data where you give it to us or actively start a feature: in the contact form and the live chat, in the demo call in your browser, in the customer area and in billing. Unavoidable on top of that are the access data that arise whenever the website is retrieved (see “Hosting”). For the calls Pharmaphone takes on behalf of our customers, the section “Phone calls on behalf of our customers” applies.

3. Hosting

This website and our application and database servers run on Railway (Railway Corp., USA) in a data centre region inside the EU. When the website is retrieved, the hosting provider logs technical access data (IP address, timestamp, requested resource). The legal basis is our legitimate interest in secure and stable operation (Art. 6(1)(f) GDPR). An order processing agreement (Auftragsverarbeitungsvertrag, AVV) under Art. 28 GDPR is in place with the hosting provider. Railway is nonetheless a US company, so access from the United States – during operation, maintenance and support, for example – cannot be ruled out. We base that transfer on standard contractual clauses under Art. 46(2)(c) GDPR.

4. Phone calls on behalf of our customers

When Pharmaphone answers the phone for a business, we process the caller’s data on that business’s behalf: our customer is then the controller and we are the processor under Art. 28 GDPR. Callers should therefore send requests for access or erasure to the business they called – we support that business in handling them and erase data on its instruction. We process the phone numbers of the calling and the called party, the time and duration of the call, the audio stream of the call, the text transcript generated from it and the details given during the call (e.g. name, callback number, what the call is about). At the start of the call the assistant identifies itself as an AI assistant (Art. 50(1) EU AI Act). We do not use the content of calls to train AI models of our own.

5. Service providers in voice processing

A phone call passes through several specialised services. We engage them as sub-processors and have concluded an order processing agreement (Auftragsverarbeitungsvertrag, AVV) under Art. 28 GDPR with each of them. Part of this processing takes place outside the EU – we state that per provider below rather than give a blanket assurance of processing in Europe only. Transfers to third countries are based on standard contractual clauses under Art. 46(2)(c) GDPR; where a provider is additionally certified under the EU-US Data Privacy Framework, that adequacy decision applies on top. The complete current list, with company, registered seat and place of processing, is Annex 3 to the order processing agreement; every customer receives it with the contract and on every change.

  • easybell (easybell GmbH, Berlin) and fonial (fonial GmbH, Cologne) – telephony: connecting the call, phone numbers, connection data and metadata. Processing in Germany.
  • DigitalOcean (DigitalOcean, LLC, USA) – running the servers the audio stream of the call passes through, and storage for the encrypted backups. Processing in the EU (Amsterdam and Frankfurt am Main).
  • Deepgram (Deepgram Inc., USA) – speech recognition: turns the caller’s audio stream into text. We call the provider’s EU endpoint (Frankfurt am Main) exclusively.
  • Corti (Corti ApS, Copenhagen, Denmark) – medically trained speech recognition, used to double-check medicine names that have been recognised and as a fallback path for speech recognition. Only in the medical industry versions (pharmacy, doctor’s practice). Processing in the EU.
  • OpenRouter (OpenRouter, Inc., USA) – routing of the language models: processes the transcript of the call and the stored information about the business that was called in order to phrase the reply. We call the provider’s EU access point with routing inside the EU exclusively; if no endpoint inside the EU is available for a request, the request fails rather than leaving the EU.
  • Language models via that routing, exclusively on platforms inside the EU: Microsoft (Azure, EU Data Zone), Google (Vertex EU), Amazon Web Services (Bedrock, Ireland) and Mistral AI (France); the models served there are authored by Anthropic Ireland, Limited and OpenAI Ireland Ltd. There is no direct access to those providers’ global interfaces.
  • Speech synthesis – produces the assistant’s voice. What is processed is the text the assistant speaks, not the caller’s speech; because the assistant reads names back for confirmation, that text contains personal data. We use one provider seated in the USA and, on the fallback path, one seated in Ireland; both paths process outside the EU.
  • Google (Google Ireland Limited, Ireland) and Resend (Plus Five Five, Inc., USA) – sending the call summaries by email to the business that was called. Delivery runs over infrastructure in the USA.
  • Railway (Railway Corp., USA) – running the application and the database that holds the call log. Processed in an EU region (see “Hosting”).

6. Demo call in your browser

On our home page you can try the assistant directly in your browser. The demo call starts only once you start it yourself and allow your browser to use the microphone – no audio is transmitted before that. From that point on, your speech is sent to our voice infrastructure and processed there by the same service providers named in the section “Service providers in voice processing” (speech recognition, language model, speech synthesis); the telephony providers are not involved, because no phone network is used. We process the audio data of what you say, the text transcript generated from it and technical connection data. For the demo call we are the controller ourselves; the legal basis is your consent (Art. 6(1)(a) GDPR), which you give by starting the call and releasing the microphone. You can end the call at any time with the hang-up button and withdraw the microphone permission in your browser; the call also ends automatically after two minutes. No audio recording of the conversation is stored – the audio data is processed in memory for the duration of the call only. The text transcript, by contrast, is stored in our call log just as it is for a regular call (see “Retention period”). Please do not mention sensitive data during the demo call.

7. Retention period

For every call we store a call log: time, duration, phone numbers, the text transcript and what the caller asked for. We delete this data automatically after fixed maximum periods, counted from the end of the call: transcript and call summary after 30 calendar days, the caller profile and the suggestions derived from it after 30 calendar days, the structured request including the callback number after 90 calendar days, call metadata without any content after 12 months. The business that was called can agree shorter periods with us for the transcript, the call summary and the caller profile, and can ask for earlier erasure at any time. The technical detail log of a call, which records the individual processing steps for troubleshooting, is cleared 24 hours after the call begins, at the latest in the nightly run that follows. Queries made with the research feature in the customer area are deleted together with their result after 180 calendar days. When the contract with the business that was called ends, we delete its production data after 30 calendar days at the latest; backups are overwritten no later than 180 calendar days after that deletion. Audio recordings of calls are not stored in our systems; the audio data is processed during the call only. We keep contact enquiries and chat histories for as long as we need them to deal with your enquiry and to meet retention obligations under commercial and tax law.

8. Web analytics (PostHog)

To measure reach we use the analytics service PostHog (PostHog Inc.) in its EU cloud region: all analytics data is processed exclusively on servers in Frankfurt am Main (AWS eu-central-1). The integration on this website works without cookies and without persistent identifiers in the browser; only anonymised usage data is recorded, such as the pages viewed, the referrer/UTM source, the type of device and the approximate location (derived from a truncated IP address). No link to an identifiable person is established. The legal basis is our legitimate interest in statistical analysis of how the website is used (Art. 6(1)(f) GDPR). An order processing agreement under Art. 28 GDPR is in place with PostHog.

9. Live chat and contact form (Chatwoot)

For the live chat and for handling contact enquiries we use the open-source software Chatwoot, which we run ourselves on our own servers in the EU — no data is passed to third parties. The chat loads only once you actively start it with a click; only then are the browser storage entries that the chat needs to work written (§ 25(2) TDDDG, the German act on data protection in telecommunications and digital services). The data you enter in the chat or the contact form (e.g. name, email address, message) is processed solely in order to deal with your enquiry. We protect the contact form against automated submissions with a hidden field and a server-side limit on how often it can be sent — we use no captcha service, and nothing is passed to a third party in the process. An AI system writes the first reply to chat messages; a person takes over at any time on request. The legal basis is Art. 6(1)(b) GDPR (steps prior to, or performance of, a contract) together with our legitimate interest in efficient customer communication (Art. 6(1)(f) GDPR).

10. Cookies in the customer area

In the customer area (dashboard) we use strictly necessary cookies only: session cookies from our authentication service Clerk (Clerk Inc., USA — processing on the basis of standard contractual clauses under Art. 46(2)(c) GDPR) and one functional cookie (“signup_source”) that stores the industry chosen at registration in order to pre-fill the setup. These cookies are required for operation (§ 25(2) TDDDG) and need no consent.

11. Payment processing (Stripe)

To handle subscriptions and payments we use Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland. Name, email address, billing address, VAT identification number and payment details (e.g. SEPA mandate or card data) are processed directly by Stripe – payment details never reach our servers at any point. The legal basis is Art. 6(1)(b) GDPR (performance of the contract and billing). An order processing agreement under Art. 28 GDPR is in place with Stripe. Data may be transferred to Stripe Inc. (USA) on the basis of the EU-US Data Privacy Framework and of standard contractual clauses. More information: https://stripe.com/privacy.

12. Your rights

You have the right to access, rectification, erasure, restriction of processing, data portability and objection. You can withdraw consent you have given at any time with effect for the future. To do so, write to the email address given above. If your enquiry concerns a call to a business that uses our assistant, that business is your point of contact; we will forward your enquiry if you wish.

13. Right to lodge a complaint

You have the right to lodge a complaint with the competent data protection supervisory authority. The authority responsible for us is the State Commissioner for Data Protection of Lower Saxony (Landesbeauftragte für den Datenschutz Niedersachsen).

14. Changes

We reserve the right to amend this privacy policy when needed. The current version is always available on this page.

Questions? info@rr42.de