Merdial is a business-to-business platform for sales-development teams. It records and transcribes the calls your agents make, scores them, coaches those agents live, and drafts qualified leads from what was said. This policy explains what personal data is involved, on whose behalf we handle it, and what you can ask us to do about it.
Two audiences, and they need different things
If you are a customer administrator, this policy tells you what we do with the data your organisation puts in. If you are an agent, an employee or someone who was on a call, the organisation that runs the Merdial account decides what is collected and for how long — start with them, and see §10.1. Scope
This policy covers merdial.com, the Merdial web application, the Merdial desktop application for Windows, the browser extension and our sales and support communications. It does not cover our customers’ own websites, dialers or CRMs, which have their own policies.
2. Who is the controller, and who is the processor
This distinction decides who you go to for what, so it comes first.
| Data | Merdial acts as | Who decides what happens to it |
|---|---|---|
| Call audio, transcripts, scores, coaching, leads, contacts, appointments, attendance and payroll records | Processor | The customer organisation. It is the controller. We act on its documented instructions. |
| Account identity, seat and billing records, support correspondence, security and audit telemetry, product analytics | Controller | Merdial, for the limited purposes of running, securing and billing for the Service. |
| Prospect and website-visitor data (marketing forms, demo requests) | Controller | Merdial, for its own sales and marketing. |
Where we are a processor, the terms of that processing are the Data Processing Agreement, which is part of every customer contract.
3. What we collect
3.1 Customer Data — processed on behalf of the customer
- Call audio and recordings. Captured only when a member starts a session in a capture client. Capture is an explicit act, not a background state.
- Transcripts and derived text. Speaker-attributed transcripts, summaries, detected objections, outcomes, sentiment and the reason a caller needed a person.
- Quality and performance records. Rubric scores, band, calibration disagreements, disputes, coaching plans, spot checks and leaderboard position.
- Contacts, leads and appointments. Names, phone numbers, email addresses, company, qualification answers and appointment details for the people the customer calls or who call the customer.
- Knowledge and configuration. Scripts, playbooks, rubrics, qualification criteria and the account “brain” — the objection library the live coaching draws from.
- Workforce records. Shifts, attendance, breaks, lateness and payslip data, where the customer uses those modules.
3.2 Data we hold as controller
- Account and identity. Name, work email, organisation, department, role and permission set, hashed authentication credentials and session tokens.
- Billing. Plan, seat count, metered usage, invoice history and the billing contact. Card details are handled by our payment provider and never reach Merdial’s systems.
- Security telemetry. Sign-in time, device and browser, and the public IP address of the device at sign-in — used to enforce IP blocks and to auto-block an address after repeated failed logins. This is brute-force protection, and switching it off would make the product less safe, so it is not optional.
- Support and sales. Correspondence, demo and onboarding notes, and what you told us in them.
- Product analytics. Page and feature usage, latency, error traces. We do not use these to profile individuals.
What we never do
- We do not sell personal information, and we do not share it for cross-context behavioural advertising, as those terms are defined by California law.
- We do not give call content to a third party for that party’s own purposes, and we do not use it to train a third-party foundation model.
- We do not capture audio unless a member starts a session or a call arrives on a connected number.
- We do not track browsing outside the Merdial application.
- We do not run advertising, and there are no advertising cookies on our product surfaces.
4. Why we process it, and the lawful basis
| Purpose | Data | Lawful basis (GDPR/UK GDPR) |
|---|---|---|
| Provide the Service — transcribe, score, coach, qualify, deliver | Customer Data | Performance of a contract with the customer; we act on the controller’s instructions (Art. 6(1)(b) for the controller; Art. 28 for us) |
| Run and secure accounts, authenticate, prevent brute-force and abuse | Account identity, security telemetry | Legitimate interests — keeping a multi-tenant platform secure (Art. 6(1)(f)) |
| Bill, collect and account for fees | Billing records | Contract, and legal obligation for tax records (Art. 6(1)(b), (c)) |
| Support you when you ask | Correspondence, diagnostic context | Contract and legitimate interests |
| Improve reliability and performance of the platform | Aggregated, de-identified telemetry | Legitimate interests |
| Improve, train and fine-tune Merdial’s own models (see §5) | De-identified transcripts and derived text | Legitimate interests (Art. 6(1)(f)), authorised by the controller in the DPA — opt-out available |
| Sales and marketing to business contacts | Prospect data | Legitimate interests, or consent where required |
| Comply with law and respond to lawful requests | As required | Legal obligation (Art. 6(1)(c)) |
5. Using call data to improve our models
Merdial does use call transcripts and related data to improve, train and fine-tune its own models — the scoring, coaching, qualification and voice-agent systems that make up the product. This is stated plainly because the alternative phrasings used across this industry (“we may use data to improve our services”) are how the same practice gets hidden, and because a customer deciding whether to sign should be able to find it in one read.
5.1 What is removed first
Before content enters model improvement, direct identifiers are stripped:
- Names — of the caller, of your agent, and of third parties mentioned on the call.
- Email addresses.
- Phone numbers.
- Payment-card numbers.
De-identified is not the same as anonymous
Free-form speech can be identifying from context even with the direct identifiers gone — an unusual company name, a specific address, a rare set of circumstances. We treat de-identified transcripts as personal data and keep them under the same access controls, encryption and tenant-scoped handling as everything else. We do not attempt to re-identify them, and we do not permit anyone else to.5.2 The limits on that use
- Our own models only. Not a third-party foundation model. Our model vendors are engaged on terms that forbid training on the content we send them.
- Never sold, never shared. We do not sell call data and do not give it to any third party for that party’s own purposes.
- Never surfaced to another customer. Identified content stays inside your tenant. A model improved on de-identified data does not reproduce another organisation’s records to you, and we do not build features that would.
- Lawful basis. Legitimate interests in improving the Service (Art. 6(1)(f)), with the de-identification above and the safeguards in §12 as the balancing measures. The customer organisation, as controller, authorises this use in the DPA.
5.3 Opting out
A customer organisation can exclude its data from model improvement entirely. Email team@merdial.com from an administrator address and we will apply it to the whole organisation. The Service works identically either way — nothing is withheld from an account that opts out.
6. Automated processing, and where a human sits
The Service scores and classifies calls automatically. One thing follows, and we treat it as a commitment rather than a disclosure:
- No solely-automated decisions with legal or similar effect. Scores, coaching plans and qualification verdicts are recommendations. The product ships review queues, disputes and calibration precisely so a person decides. Customers agree in the Terms not to use Output as the sole basis for discipline, pay or termination.
Under California’s ADMT rules and equivalent regimes, individuals may ask for an explanation of how an automated decision affecting them was reached, and may opt out of certain uses. Route those requests through the customer organisation, or to team@merdial.com and we will assist it.
7. Who receives personal data
- Sub-processors. A short, named list of infrastructure and AI vendors, published with their location and function at Sub-processors. Each is bound by contract to process only on our instructions.
- Within the customer’s organisation. Owners, managers and administrators see the data their role and permission set allows. Client-portal users see only approved records for their own campaigns.
- Professional advisers — auditors, lawyers, accountants — under duties of confidence.
- Authorities, where legally compelled. We require valid legal process, and where we are permitted to do so we will notify the customer before disclosing Customer Data so it can seek protective relief.
- A successor in a merger, acquisition or asset sale, subject to this policy and on notice.
We do not disclose personal data to anyone else, and we do not sell it.
8. How long we keep it
| Category | Retention |
|---|---|
| Call audio, transcripts, scores, leads and workflow records | For as long as the customer’s account is active, or until the customer’s configured retention period expires — whichever is shorter. Deleted on the customer’s instruction. |
| After account termination | Exportable for 30 days, then deleted or irreversibly anonymised within 90 days. |
| Encrypted backups | Rolling 35-day window, after which restores can no longer reach deleted data. |
| Account, seat and audit records | Life of the account plus 12 months. |
| Billing and tax records | Up to 7 years, as tax law requires. |
| Security telemetry (sign-in IP, failed attempts) | 12 months. |
| Support correspondence | 24 months from last contact. |
| Prospect and marketing data | 24 months from last engagement, or until you object. |
9. International transfers
Merdial and its sub-processors operate in the United States, the European Union and the United Kingdom. Where personal data leaves the EEA or the UK to a country without an adequacy decision, the transfer is covered by the European Commission’s Standard Contractual Clauses (Modules 2 and 3, as applicable), the UK International Data Transfer Addendum, and a transfer risk assessment with supplementary technical measures — encryption in transit and at rest, and tenant isolation. The specific location of each sub-processor is listed on the Sub-processors page. Customers who need processing confined to a particular region should contact us before onboarding.
10. Your rights
Depending on where you live, you may have the right to access, correct, delete, port, restrict or object to the processing of your personal data, to withdraw consent, and to complain to a supervisory authority.
Where to send the request
If your data is in a customer’s Merdial account — you are an agent, or you were on a call — the customer is the controller. Ask them first. If you contact us instead, we will forward the request to them and assist as their processor requires; we cannot delete a customer’s records on a third party’s instruction. For data we hold as controller (your Merdial account, billing, support), write to team@merdial.com and we will respond within 30 days.We do not charge for a request or discriminate against anyone who makes one. We may need to verify identity before acting, and will only ask for what verification requires.
11. Regional disclosures
12. Security
Encryption in transit and at rest, per-tenant row-level isolation enforced in the database rather than in application code, authenticated and role-scoped API surfaces, redaction of payment-card patterns before any generative call, and least-privilege internal access. The detail — including the controls, the breach process and the notification timelines — is in the Security Overview.
13. Cookies
The product surfaces use only strictly-necessary storage — a session token and your interface preferences. The marketing site uses a small amount of privacy-preserving analytics. The full inventory is in the Cookie Policy.
14. Children
Merdial is a workplace tool. It is not directed to anyone under 16, and we do not knowingly collect their personal data. If you believe we have, write to team@merdial.com and we will delete it.
15. Changes
We will update this policy as the product changes. Material changes are announced to account administrators by email at least 30 days before they take effect, and the “Last updated” date at the top of this page always reflects the current version.
16. Who we are, and how to reach us
Privacy: team@merdial.com. Security reports: team@merdial.com. Everything else: team@merdial.com. This policy is effective 6 September 2026.

