Data-processing statement
Wording last edited: 2026-09-28. Not yet published.
A plain description of what Ordella does with your customers' personal data, written for the tradesperson who is answerable for it. It states facts about the software, not legal positions.
docs/legal-review.md.Why this is its own page
The privacy notice is written for the person whose data it is — usually a member of the public who has just rung you. This page is written for you: it is the document you would send to somebody who asks how their data is handled, and it is the document a solicitor will turn into a data-processing agreement. Mixing the two would make both harder to read, and the audiences want different levels of detail.
1. What is processed
On an answered call the agent collects:
- the caller's name;
- the number they rang from;
- their address and postcode;
- a description of the problem, and a short written summary of it;
- the call audio and a transcript of it;
- the appointment, where one is booked.
From you we hold your business details, working hours, services, prices, working area, calendar connection and billing record.
2. What the caller is told
Before the caller has said anything, the agent says your business name and “this call may be recorded for training and quality”. That is part of the agent's opening line on every call, not a message played only sometimes.
3. Who is answerable for what
The facts, without a conclusion drawn from them. Your customer rings your number and speaks to an agent that carries your business name. Ordella stores their details in its own database, under your business. You decide your services, hours, prices and patch, and what counts as urgent. Ordella decides how the agent is worded, how long data is kept, and which suppliers are used.
4. Separation between businesses
Every record carries the business it belongs to, and the database enforces that on every read: one Ordella customer cannot read another's calls, bookings or messages. An erasure request made to one business does not touch another business's records of the same person, because the same number may have rung two tradespeople and each holds his own record of his own customer.
5. Suppliers
The complete list of companies that receive personal data, and what each one gets.
Retell AI · Voice agent
Call audio, the transcript, and the caller's number. Audio is deleted at Retell after 90 days.
Twilio · Telephony and SMS
The caller's number and the call itself, and the text of any SMS we send to a caller or to the tradesperson.
Cal.com · Calendar and booking
The appointment: date, time, and the customer's name, number, email and address where given.
Supabase · Database, storage and sign-in
Everything we hold: accounts, calls, transcripts, bookings, messages and enquiries.
Stripe · Payments
The tradesperson's billing details and subscription. No caller data goes to Stripe.
postcodes.io · Postcode lookup
The postcode alone, to check whether a job is inside the tradesperson's patch. No name, number or address.
Resend (or the configured SMTP server) · Email delivery
The address the email is going to and the contents of the email: a booking confirmation or an enquiry alert.
Hostinger · Hosting
Web and server logs, including IP addresses, for the site and its APIs.
6. How long things are kept
- Call audio: 90 days. Deleted at our voice supplier first, and only then marked as deleted here. If the supplier refuses, the recording is left alone and tried again the following day, so our records never claim audio is gone while it still exists.
- Transcript and caller details: 12 months. The transcript, caller name, address, postcode, problem summary and phone number are removed.
- The call row: kept. Stripped of everything identifying, because it records the minutes you were billed for.
- Bookings: kept as your business record. Personal detail is removed on an erasure request.
- Your account and billing records: kept while you are a customer.
7. Deleting one person's data
A caller emails us, or tells you and you forward it. We match on the number they rang from, because that is the only thing they reliably know about themselves in our records — they never had an account. Then, for your business only:
- the recording is deleted at our voice supplier and here;
- the transcript, name, number, address, postcode and summary are removed from the call;
- the booking keeps its date, time and duration, and loses the name, number, email, address and notes — you keep the job, they lose the personal detail;
- follow-up notes and sent messages addressed to them are stripped;
- the call row survives with nothing identifying in it, because it carries billed minutes.
We record that the request was handled using a one-way coded form of the phone number, keyed by a secret that is not in the database. That is enough to answer “did you deal with my request?” and not enough to rebuild a list of people who asked.
8. Security
Access to a business's records requires a sign-in, and the database filters every read by the business the signed-in person belongs to. Credentials for our suppliers are held as environment configuration on the server, never in the browser. Recordings are not publicly listed anywhere on the site.
9. Telling you about a breach
If personal data belonging to your customers is exposed, we will tell you what happened, what data was involved and what we have done, without waiting to be asked.