PRIVACY POLICY — TransCall
Last updated: 1 August 2026
This Policy explains what personal data the TransCall application (the “App”, the “Service”) processes, why, on what legal basis, who we pass it to, and what rights you have.
The Policy is drawn up in accordance with the EU General Data Protection Regulation (GDPR, Regulation (EU) 2016/679) and Finnish data protection law.
Where this Policy and the Terms of Use conflict on matters of personal data processing, this Policy prevails.
1. WHO PROCESSES YOUR DATA
The operator (data controller) of the Service is:
[Operator name, registration number and registered address — to be filled in once the business is registered]
Contact for data protection matters: support@transcall.org
No separate Data Protection Officer has been appointed: the Service does not carry out large-scale systematic monitoring and does not process special categories of data on a large scale, so an appointment is not required by Article 37 GDPR.
2. WHAT DATA WE PROCESS
2.1. Account data
| Data | Why |
|---|---|
| Your phone number | Registration, sign-in, caller ID for your calls |
| One-time code from SMS | Confirming that the number is yours |
Account identifier (e.g. TC-100001) | Contacting support without revealing your number |
| Access token | Recognising your device without a password |
| Balance, registration date | Billing and running the Service |
2.2. Call data
For each call we store: the number you called, its country and type, the duration, the amount charged and the time of the call. This is needed for billing, for verifying that charges are correct, and for resolving disputes.
2.3. Payment data
The top-up amount, date and the payment provider’s transaction identifier. We neither receive nor store your bank card details — they are handled by the payment provider in its own secure, PCI DSS certified environment. We only see that a payment succeeded and for how much.
2.4. Speech, transcripts and translations
To make translation possible, the following are processed during a call:
- the audio stream of your speech (from the device microphone);
- the audio stream of the other party’s speech (from the phone line);
- text transcripts of both sides and their translations;
- synthesised speech of the translation.
This data is processed in memory in real time and is not stored on our server. We do not make or keep recordings of conversations. Transcripts exist on the server only for a fraction of a second — exactly as long as is needed to translate a sentence and speak it aloud — and are then discarded.
A copy of the transcript is kept only on your device (see section 6).
2.5. Technical logs
The server keeps a technical log (request times, error codes, service events) needed to diagnose failures and to protect against abuse. The content of conversations does not go into the log. Logs are kept for no longer than 30 days.
2.6. Reference data about numbers
To show the price before a call, we determine the country, type (mobile or landline) and carrier of the number being dialled, and cache the result so that we do not have to look it up again.
2.7. What we do NOT do
We do not collect and do not use:
- your contact list, phone call log or SMS messages;
- location data;
- advertising or tracking identifiers;
- analytics, statistics or behaviour-tracking systems;
- automated decision-making or profiling producing legal effects for you (Article 22 GDPR).
The App contains no advertising and passes no data to ad networks. It requests only four permissions: internet, microphone, audio control, and keeping the screen awake during a call.
3. THE OTHER PARTY’S DATA
The person you call is not our user, but their speech inevitably passes through translation. We process it on the same terms: in real time, without storing recordings, solely so that the two of you can understand each other.
So that they know what is happening, at the start of the conversation the Service automatically plays them a notice in their own language stating that the conversation is going through an automatic translator and that a delay is possible.
This notice also satisfies Article 50 of the EU Artificial Intelligence Act: the translation is spoken by a synthesised machine voice, and the person at the other end must know they are hearing AI-generated speech. Disabling or circumventing this notice is prohibited by the Terms of Use.
You, as the person placing the call, are responsible for the appropriateness of the call and for complying with local laws on recording and intercepting conversations.
4. LEGAL BASES FOR PROCESSING
| Data | Basis (GDPR) |
|---|---|
| Number, account, token, balance | Performance of a contract — Art. 6(1)(b) |
| Speech, transcripts, translations | Performance of a contract — Art. 6(1)(b) |
| Call log, payments | Contract and legal obligation (accounting) — Art. 6(1)(b) and 6(1)(c) |
| Technical logs, protection against abuse | Legitimate interest — Art. 6(1)(f) |
| Microphone access | Your consent in the device’s system dialog; revocable in settings |
The content of a conversation may incidentally contain special categories of data (for example, health information when calling a clinic) — Article 9 GDPR. We do not single out, analyse or store such data; it is processed solely for translation at the moment it is spoken, on the basis of your explicit consent given by starting the call — Art. 9(2)(a).
5. WHO WE SHARE DATA WITH
We do not sell your personal data and share it only in the following limited circumstances:
Service providers. We engage trusted third-party providers to operate the Service. They are bound by strict data processing agreements, act only on our instructions, and may not use your data for their own purposes.
We do not use the content of your conversations to train artificial intelligence models, and we do not permit our providers to do so. We also pass no data to advertising networks or data brokers.
Legal requirements. We disclose data to competent authorities where required by law, court order or a decision of a public authority.
Business transfer. If the Service is sold, reorganised or merged with another company, your data may pass to the new operator as part of that transaction. We will notify you in advance — before your data comes under a different privacy policy — and you will be able to delete your account.
6. DATA THAT STAYS ON YOUR DEVICE
Call history, together with transcripts and translations of what was said, is stored locally in your device’s memory and is not sent to our server. Your settings (languages, last dialled number, account identifier) are stored there too, and the access token is kept in the operating system’s secure storage.
This data is entirely under your control: you can delete an individual call from the history in the App, or delete the App — in which case all local information is erased with it.
Please note: transcripts on the device are not protected by a separate password. If other people use your device, protect it with a screen lock.
7. TRANSFERS OUTSIDE THE EEA
Some processors are located outside the European Economic Area, mostly in the United States. Data is transferred there on the basis of the EU Standard Contractual Clauses (Commission Decision 2021/914) and/or the recipient’s participation in the EU–US Data Privacy Framework.
In practice this means that the audio of your conversation and its transcript briefly leave the EEA. If that is unacceptable to you, please do not use the Service.
8. RETENTION PERIODS
| Data | Period |
|---|---|
| Call audio, transcripts, translations (on the server) | Not stored — processed in memory during the call |
| Account (number, token, balance) | While the account exists; up to 30 days after deletion |
| Call log and payment history | 6 years from the end of the calendar year — required by Finnish accounting law |
| Technical server logs | Up to 30 days |
| One-time SMS codes | A few minutes, until they expire |
| Cached reference data about numbers | Up to 12 months |
Once these periods expire, the data is deleted or anonymised.
9. YOUR RIGHTS
In relation to your personal data you have the right to:
- access it and request a copy (Art. 15);
- rectify inaccurate data (Art. 16);
- erase it — the “right to be forgotten” (Art. 17);
- restrict processing (Art. 18);
- receive it in a machine-readable format and transfer it to another controller (Art. 20);
- object to processing based on legitimate interest (Art. 21);
- withdraw consent at any time, without affecting the lawfulness of processing carried out beforehand (Art. 7).
Please note: data we are required to keep under accounting law (the call log and payments) cannot be deleted before the statutory period expires, even at your request.
How to exercise them: write to support@transcall.org, quoting your account identifier (TC-…). We will reply within one month. To protect you against requests by others, we may ask you to confirm that the number is yours.
Account deletion: on request to the same address. We will delete your number, token and remaining balance (any unused balance is refunded under the rules in the Terms of Use); accounting data is kept until its statutory period expires.
Complaints. If you believe we are infringing your rights, you may lodge a complaint with a supervisory authority — in Finland this is the Office of the Data Protection Ombudsman (Tietosuojavaltuutetun toimisto, tietosuoja.fi) — or with the authority in your country of residence.
10. SECURITY
We apply reasonable technical and organisational measures:
- all traffic between the App and the server goes over encrypted channels (HTTPS/WSS, TLS);
- the access token is kept in the operating system’s secure storage;
- the App’s screen content is protected against screenshots and recording by Android;
- server access is by cryptographic key only; password login is disabled;
- only the operator of the Service has access to the data.
No method of transmitting data over the internet is completely secure, so we cannot give an absolute guarantee. In the event of a breach that threatens your rights, we will notify the supervisory authority within 72 hours and you without undue delay (Art. 33–34 GDPR).
11. CHILDREN
The Service is intended for people aged 18 and over. We do not knowingly collect children’s data. If we learn that an account was registered by a minor, it will be deleted.
12. EMERGENCY CALLS
The App is not intended for calling emergency services (112 or others) and does not transmit your location to them. In an emergency, call 112 from an ordinary phone.
If you enter an emergency number, the App will offer to open your device’s ordinary phone dialler with the number already entered. From there the call goes through your mobile operator’s network — we take no part in it and receive no data about it.
13. CHANGES TO THIS POLICY
We may update this Policy. The date of the latest change is shown at the top. We will notify you of significant changes in the App or by SMS before they take effect. Continuing to use the Service after changes take effect means you accept the updated Policy.
14. CONTACTS
Data protection questions and requests to exercise your rights:
support@transcall.org
Please quote your account identifier TC-… — it is shown in the App next to your balance.