← Back to Voice Booking AI

Privacy Policy

Last updated: 25 August 2026

This policy explains what personal data we collect through voicebookingrestaurant.com and through the Voice Booking AI service, why we collect it, who else handles it and what you can do about it. It is written under Regulation (EU) 2016/679 (GDPR) and Spanish Organic Law 3/2018 (LOPDGDD).

1. Who is responsible for your data

Daniel Perramón Calonge (trading as Webs Barcelona) — Tax ID (NIF) 48096283V — Barcelona, Spain.
Email: info.websbarcelona@gmail.com · Phone: +34 631 736 802.

We have not appointed a Data Protection Officer, as we are not required to. Data protection questions go to the email above and are answered by us directly.

2. What we collect, and why

DataWhy we have itLegal basisHow long
Contact form: restaurant name, email, phone, city, plan of interest To get back to you about setting up the service Your consent (Art. 6.1.a), given with the tick box on the form Up to 2 years from your last contact, unless you ask us to delete it sooner
Customer account: business details, billing details, phone line configuration To provide and bill the service Performance of a contract (Art. 6.1.b) and legal obligation for invoicing (Art. 6.1.c) For the life of the contract; accounting records are kept 6 years (Spanish Commercial Code)
Call data: phone number of the caller, call time and length, transcript, and the booking created To create and manage the booking, show it in the restaurant's dashboard and let the restaurant check what was said Performance of a contract with the restaurant (Art. 6.1.b); for the caller, the restaurant's legitimate interest in taking the booking (Art. 6.1.f) Defined by the restaurant. By default, transcripts are kept 90 days and bookings for the life of the account
Browser demo: the audio you speak into the microphone and its transcript To run the demo conversation Your consent, given by starting the demo and allowing the microphone The demo runs in your browser. We do not keep a recording of it; any test booking is deleted with the demo data
Technical logs: IP address, browser, pages visited, errors Keeping the site up, security and abuse prevention (the demo is rate-limited by IP) Our legitimate interest in a secure, working service (Art. 6.1.f) Up to 12 months
Analytics and advertising cookies Measuring traffic and the effect of our ads Your consent, through the cookie notice (Art. 6.1.a and Spanish Law 34/2002) See the cookie policy

If you called a restaurant and spoke to its AI: the restaurant is the one deciding what happens with that call — it is the data controller. We act as its data processor and only handle the call to provide the service it hired. To have that data corrected or deleted, ask the restaurant directly, or write to us and we will pass it on.

3. Who else sees the data

We do not sell personal data and we do not share it for anyone else's marketing. We do rely on these providers, each bound by a data processing agreement:

ProviderWhat it doesWhere
OpenAIThe voice model that holds the conversation and transcribes itUnited States
TwilioPhone numbers and call routingUnited States / EU
StripePayments and invoicing. Card details go straight to Stripe — they never reach our serversUnited States / EU
HetznerServers where the application and database runEuropean Union
Google (Ads, Analytics)Measurement and advertising, only after you accept cookiesUnited States

Where a provider processes data outside the European Economic Area, the transfer relies on the European Commission's Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework.

4. Recorded calls and what the AI hears

The AI receptionist processes what the caller says in order to take the booking. Transcripts are visible to the restaurant in its dashboard. Each restaurant is responsible for telling its callers that calls are handled by an automated system — we provide the wording for that announcement during setup, and we recommend keeping it switched on.

We do not use the content of calls, transcripts or bookings to train AI models.

5. Your rights

You can ask us at any time to:

Write to info.websbarcelona@gmail.com from the address concerned, or by post to the address in the legal notice. We reply within one month. If you are not happy with the answer, you can complain to the Spanish Data Protection Agency (aepd.es).

6. Security

The site runs over HTTPS. Passwords are stored hashed, never in plain text. Access to the production database is restricted to the operator of the service. In the event of a personal data breach that puts your rights at risk, we notify the AEPD within 72 hours and inform you when the law requires it.

7. Children

The service is aimed at businesses. We do not knowingly collect data from anyone under 14.

8. Changes

If we change this policy we update the date at the top, and if the change is significant we tell existing customers by email. Older versions are available on request.