Privacy Policy

How Octanist B.V. handles personal data across its website, platform, integrations and call-tracking services.

Last updated: 29 September 2026.

Who we are

Octanist B.V. provides a business platform for lead management, attribution, reporting, integrations and optional call tracking. Our address is Turnhoutseweg 22, 5541 NX Reusel, Netherlands. KvK: 42100062. VAT: NL869723182B01. Contact us about privacy at support@octanist.com or +31 85 004 78 67.

This Policy explains how we handle personal data and the distinction between our own activities and processing instructed by our customers. It is an information notice, not a request for blanket consent.

Our role and our customers' role

Octanist determines the purposes and means of processing for its own website, customer relationships, account administration, billing, support and appropriate service-security activities. For these activities, Octanist is a controller.

When a business uses Octanist to capture leads, track visitors, record calls, analyse information or send configured conversions, that business generally determines the purposes of the processing. Octanist processes the data under its instructions and the DPA. An agency may act for a client, in which case the client, agency and Octanist's roles depend on the actual arrangements. Reselling Octanist services does not give an agency ownership of individuals' personal data.

If your enquiry concerns a call or lead handled for an Octanist customer, contact that business first. We assist with requests as required by the DPA and law, and will route requests we receive to the responsible customer where appropriate. We remain responsible for requests about processing for which we are a controller.

Information we handle

Depending on your interaction and the customer's configuration, this can include:

  • Account and business-contact details, such as name, email address, organisation, role, authentication information and account activity.
  • Subscription and billing details, payment status, invoices and payment-provider references. Payment processing also involves the selected payment provider.
  • Support requests, communications, demo bookings and information you choose to provide.
  • Website and product usage, device/browser information, IP address, timestamps, error reports and security logs.
  • Customer lead details, telephone numbers, emails, form fields, notes, custom fields, status, value and activity history.
  • Visitor and session identifiers, page views, URLs/referrers, campaign parameters, ad click identifiers, consent signals and links between visits and leads.
  • Connected-platform account identifiers, permissions, tokens, campaign and spend information, and configured import/export data.
  • Call numbers and metadata, routing and attribution information, recordings, transcripts, speaker segments, raw transcription results and AI summaries where the features are enabled.

We receive information directly from you or the customer, through use of the Services, and from integrations and tools the customer authorises. Form fields and recordings may contain more information than a standard lead record, depending on what participants submit or discuss. Customers must limit collection to data appropriate for their lawful purposes.

Provide and administer accounts and respond to service requests

Basis and limits: Performance of a contract where the individual is the contracting party; otherwise our legitimate interest in administering a business relationship and serving its authorised representatives

Billing, accounting and statutory record keeping

Basis and limits: Applicable legal obligations and legitimate interests in collecting fees and maintaining accurate records

Security, fraud prevention and resolving disputes

Basis and limits: Legitimate interests in protecting the Services, users and legal rights; legal obligations where applicable

Necessary operational measurement and service improvement

Basis and limits: Legitimate interests where the processing is necessary, proportionate and does not override individuals' rights; consent where applicable tracking rules require it

Optional analytics, advertising and marketing communications

Basis and limits: Consent where required; otherwise a specifically assessed lawful basis and applicable communications rules, with an effective opt-out

Testimonials or identifiable marketing references

Basis and limits: Applicable permission and a suitable data-protection basis; we seek approval for attributed case studies and testimonials

For customer-instructed lead and call processing, the customer establishes the legal basis for its purposes, and our DPA governs our role. We do not sell customer lead or call data or use it for our own advertising audiences.

Call recording and AI processing

Customers decide whether to enable recording, transcription and summaries and must provide required notices and permissions under the rules applicable to their business, participants and purposes. An announcement or a feature toggle does not automatically provide consent for unrelated advertising or disclosure.

Telnyx handles call routing and hosts call audio. When transcription is enabled, Octanist retrieves audio and sends it to ElevenLabs. Transcripts, speaker information and raw transcription responses are stored in Octanist's database. Where summaries are enabled, transcript content is processed through the AI Gateway using an OpenAI model, and the resulting summary is stored in Octanist.

AI-assisted form-field mapping also processes field labels, sample values and context. Matching email and phone samples are redacted before that request, but other samples may still contain personal data.

The OpenAI gateway route is configured to request zero data retention. This is specific to that processing path. It does not mean that Telnyx recordings, ElevenLabs requests, Octanist transcripts, summaries, logs or backups have zero retention. The retention section below explains those separately.

Recipients and customer-directed disclosures

We use service providers for hosting, databases, network/security services, email, analytics, billing, call handling, transcription and AI processing. The subprocessor register identifies providers processing customer data on our behalf. For our own operations, PostHog supports product analytics and error analysis, Stripe handles billing and payments, Resend delivers email, and Sanity supports website content delivery. Scheduling or embedded services receive information when you use those services. Providers may also act independently for their own account administration, security or legal duties under their privacy notices.

The current provider inventory includes Vercel, PlanetScale, Cloudflare, Telnyx, ElevenLabs, OpenAI through the gateway, Resend, PostHog and Stripe. A provider receives data relevant to its function and does not necessarily receive all categories of data or serve the same role for every activity.

Customers may authorise disclosures to ad platforms, analytics systems, CRMs, webhooks, Zapier connections, API applications and MCP clients. Those destinations process data according to the customer's configuration and their own legal arrangements. Revoking access prevents future authorised access within its scope but does not automatically erase copies already held by a recipient.

We may also disclose information to professional advisers subject to appropriate duties, or to authorities where legally required. A corporate transaction can require disclosure or a change of controller; we will apply the relevant safeguards and transparency obligations. Access to production customer data within Octanist is limited to authorised owners and management, with multi-factor authentication required. Access is limited to legitimate service, support and security purposes.

Connected Google and Meta services

Our use and transfer of information received from Google APIs will comply with the Google API Services User Data Policy, including its Limited Use requirements. Connected account information is used for the enabled functionality, such as configuring integrations, reading account/campaign/spend information and sending customer-authorised conversions or exports.

Meta integrations similarly process authorised account, advertising and lead information to provide configured ingestion, reporting and conversion features, subject to applicable Meta terms. Customers can disconnect integrations and revoke permissions through the relevant platform. Contact support@octanist.com about deletion; disconnecting access is not a representation that all historical records have already been erased. The applicable retention schedule governs remaining data.

Locations and transfers

The primary Octanist application is hosted on Vercel in Frankfurt and its database on PlanetScale using AWS Frankfurt. These locations do not mean all processing, backups, support access or other providers are limited to Germany or the EEA.

Our providers operate internationally, including in the United States. Where a restricted transfer occurs, an applicable adequacy decision or appropriate contractual safeguards, such as the European Commission's standard contractual clauses and any necessary supplementary measures, must cover it. The relevant arrangement depends on the provider, recipient and processing activity. Contact support@octanist.com for information about the safeguards relevant to your data or a copy, subject to necessary confidentiality redactions. Primary hosting in Frankfurt is not a guarantee that all processing remains in the EEA.

Retention and deletion

Subscription cancellation and data deletion are separate. Paid access normally continues to the end of the paid period. Octanist currently keeps account history without a fixed automatic expiry after cancellation so customers can reactivate with their history. We do not currently operate a routine inactivity review or automatic deletion process for abandoned accounts. Tracking and submission sources that remain enabled can continue sending new leads after the paid period ends. Cancelled Call Tracking numbers are released separately and are not kept active by this arrangement.

This continued processing must remain necessary for the customer's lawful purposes and instructions. The customer must maintain appropriate notices and permissions and review what it needs to retain. To stop website collection, remove the Octanist pixel. Also disable any API, form or integration source that continues to send leads. Removing the pixel does not delete history already stored. An organisation owner can delete the organisation in the dashboard, removing its linked live workspace data and ending collection into that organisation. A personal login used for other organisations is separate. Contact support@octanist.com for help, return requests or deletion of additional records. Cancellation does not waive deletion rights or authorise retention beyond what is lawfully necessary.

Customer leads, raw forms, sessions, page views, call metadata, transcripts, summaries and stored processing results

Retention basis and controls: Retained as account history, including after subscription cancellation, until a valid deletion instruction is carried out or the data is otherwise removed to meet legal obligations. There is currently no fixed automatic expiry for this history.

Account details and integration records

Retention basis and controls: Kept to administer the active or retained account and its authorised connections. Disconnecting a source stops future authorised access within its scope but does not automatically delete historical records. Organisation owners can use dashboard deletion, and customers can contact support about account closure or additional deletion requests.

Support correspondence

Retention basis and controls: Kept while needed to address the enquiry, maintain the relevant service relationship or establish, exercise or defend legal claims. Relevant factors include whether the issue is resolved, its subject matter and applicable limitation periods.

Billing and statutory records

Retention basis and controls: Kept for the applicable legal retention period. Dutch basic business administration generally has a seven-year retention requirement; longer requirements apply to particular record types where required by law. This does not justify keeping all lead or call data for that period.

Security, usage and error logs

Retention basis and controls: Used for operation, troubleshooting, security and investigations. Retention depends on the relevant system, incident or operational purpose and applicable legal obligations. These records are separate from customer account history.

Retention basis and controls: Stored by Telnyx under the applicable service configuration and provider terms. Account-history retention is not a promise that every recording remains available. Deletion requests concerning audio must also address the provider-held copy.

ElevenLabs processing copies and logs

Retention basis and controls: Subject to its applicable service settings and terms. Octanist does not represent this transcription path as zero retention. The transcript and related results stored in Octanist follow the account-history rule above.

OpenAI processing through AI Gateway

Retention basis and controls: The configured model route requests zero data retention. This does not delete the input transcript or output summary held in Octanist, or extend that arrangement to other providers' logs and records.

Backups

Retention basis and controls: Separate from live records. A deletion from the active service does not necessarily remove every backup immediately. Backup retention and expiry follow the relevant provider configuration; retained copies remain subject to confidentiality, purpose limitation and applicable deletion obligations.

Dashboard organisation deletion removes linked records in the active workspace, including its leads and associated call records, transcripts and summaries. The dashboard action does not itself erase every provider-held copy or operational event record. Following organisation deletion, Octanist management manually coordinates deletion of remaining customer-specific recordings and call-event records, and applicable deletion requests to transcription providers, without undue delay. Management verifies completion before confirming full erasure. Stripe customer and invoice history required for accounting, and backup copies, are handled separately under their applicable retention rules. We handle customer-controlled data under the DPA, including return or deletion at the end of processing unless law requires retention. We will explain the scope of a deletion request, any legal exception and the relevant provider or backup handling. Where specific timing depends on provider configuration, support will establish it for the request rather than represent an unverified universal deadline.

Your rights, preferences and contact

Depending on applicable law and the processing, you may request access, correction, deletion, restriction or portability, object to processing, and withdraw consent without affecting prior lawful processing. You may object to direct marketing at any time. Contact support@octanist.com. We may request proportionate information to verify identity and authority and will respond within applicable legal deadlines.

You may complain to the Autoriteit Persoonsgegevens or another competent supervisory authority. If the data belongs to a customer's processing activity, we will cooperate with that customer's response as required by law and our DPA.

Our Cookie Policy explains browser storage and tracking choices. Security measures reduce risk but cannot eliminate it. We do not represent that a privacy notice or a consent flag alone makes every use of the platform compliant.

We will identify the effective date of updates and directly communicate material changes through an appropriate channel. A change in controller identity or another material processing change will not be communicated solely by asking people to periodically revisit this page.

See our Subprocessor Register, Cookie Policy and Data Processing Agreement.