MerdialMerdialerdial

Privacy Policy

What we process, why, and your rights. · Last updated 6 September 2026

Merdial is a business-to-business platform for sales-development teams. It records and transcribes the calls your agents make, scores them, coaches those agents live, and drafts qualified leads from what was said. This policy explains what personal data is involved, on whose behalf we handle it, and what you can ask us to do about it.

Two audiences, and they need different things

If you are a customer administrator, this policy tells you what we do with the data your organisation puts in. If you are an agent, an employee or someone who was on a call, the organisation that runs the Merdial account decides what is collected and for how long — start with them, and see §10.

1. Scope

This policy covers merdial.com, the Merdial web application, the Merdial desktop application for Windows, the browser extension and our sales and support communications. It does not cover our customers’ own websites, dialers or CRMs, which have their own policies.

2. Who is the controller, and who is the processor

This distinction decides who you go to for what, so it comes first.

DataMerdial acts asWho decides what happens to it
Call audio, transcripts, scores, coaching, leads, contacts, appointments, attendance and payroll recordsProcessorThe customer organisation. It is the controller. We act on its documented instructions.
Account identity, seat and billing records, support correspondence, security and audit telemetry, product analyticsControllerMerdial, for the limited purposes of running, securing and billing for the Service.
Prospect and website-visitor data (marketing forms, demo requests)ControllerMerdial, for its own sales and marketing.

Where we are a processor, the terms of that processing are the Data Processing Agreement, which is part of every customer contract.

3. What we collect

3.1 Customer Data — processed on behalf of the customer

  • Call audio and recordings. Captured only when a member starts a session in a capture client. Capture is an explicit act, not a background state.
  • Transcripts and derived text. Speaker-attributed transcripts, summaries, detected objections, outcomes, sentiment and the reason a caller needed a person.
  • Quality and performance records. Rubric scores, band, calibration disagreements, disputes, coaching plans, spot checks and leaderboard position.
  • Contacts, leads and appointments. Names, phone numbers, email addresses, company, qualification answers and appointment details for the people the customer calls or who call the customer.
  • Knowledge and configuration. Scripts, playbooks, rubrics, qualification criteria and the account “brain” — the objection library the live coaching draws from.
  • Workforce records. Shifts, attendance, breaks, lateness and payslip data, where the customer uses those modules.

3.2 Data we hold as controller

  • Account and identity. Name, work email, organisation, department, role and permission set, hashed authentication credentials and session tokens.
  • Billing. Plan, seat count, metered usage, invoice history and the billing contact. Card details are handled by our payment provider and never reach Merdial’s systems.
  • Security telemetry. Sign-in time, device and browser, and the public IP address of the device at sign-in — used to enforce IP blocks and to auto-block an address after repeated failed logins. This is brute-force protection, and switching it off would make the product less safe, so it is not optional.
  • Support and sales. Correspondence, demo and onboarding notes, and what you told us in them.
  • Product analytics. Page and feature usage, latency, error traces. We do not use these to profile individuals.

What we never do

  • We do not sell personal information, and we do not share it for cross-context behavioural advertising, as those terms are defined by California law.
  • We do not give call content to a third party for that party’s own purposes, and we do not use it to train a third-party foundation model.
  • We do not capture audio unless a member starts a session or a call arrives on a connected number.
  • We do not track browsing outside the Merdial application.
  • We do not run advertising, and there are no advertising cookies on our product surfaces.

4. Why we process it, and the lawful basis

PurposeDataLawful basis (GDPR/UK GDPR)
Provide the Service — transcribe, score, coach, qualify, deliverCustomer DataPerformance of a contract with the customer; we act on the controller’s instructions (Art. 6(1)(b) for the controller; Art. 28 for us)
Run and secure accounts, authenticate, prevent brute-force and abuseAccount identity, security telemetryLegitimate interests — keeping a multi-tenant platform secure (Art. 6(1)(f))
Bill, collect and account for feesBilling recordsContract, and legal obligation for tax records (Art. 6(1)(b), (c))
Support you when you askCorrespondence, diagnostic contextContract and legitimate interests
Improve reliability and performance of the platformAggregated, de-identified telemetryLegitimate interests
Improve, train and fine-tune Merdial’s own models (see §5)De-identified transcripts and derived textLegitimate interests (Art. 6(1)(f)), authorised by the controller in the DPA — opt-out available
Sales and marketing to business contactsProspect dataLegitimate interests, or consent where required
Comply with law and respond to lawful requestsAs requiredLegal obligation (Art. 6(1)(c))

5. Using call data to improve our models

Merdial does use call transcripts and related data to improve, train and fine-tune its own models — the scoring, coaching, qualification and voice-agent systems that make up the product. This is stated plainly because the alternative phrasings used across this industry (“we may use data to improve our services”) are how the same practice gets hidden, and because a customer deciding whether to sign should be able to find it in one read.

5.1 What is removed first

Before content enters model improvement, direct identifiers are stripped:

  • Names — of the caller, of your agent, and of third parties mentioned on the call.
  • Email addresses.
  • Phone numbers.
  • Payment-card numbers.

De-identified is not the same as anonymous

Free-form speech can be identifying from context even with the direct identifiers gone — an unusual company name, a specific address, a rare set of circumstances. We treat de-identified transcripts as personal data and keep them under the same access controls, encryption and tenant-scoped handling as everything else. We do not attempt to re-identify them, and we do not permit anyone else to.

5.2 The limits on that use

  • Our own models only. Not a third-party foundation model. Our model vendors are engaged on terms that forbid training on the content we send them.
  • Never sold, never shared. We do not sell call data and do not give it to any third party for that party’s own purposes.
  • Never surfaced to another customer. Identified content stays inside your tenant. A model improved on de-identified data does not reproduce another organisation’s records to you, and we do not build features that would.
  • Lawful basis. Legitimate interests in improving the Service (Art. 6(1)(f)), with the de-identification above and the safeguards in §12 as the balancing measures. The customer organisation, as controller, authorises this use in the DPA.

5.3 Opting out

A customer organisation can exclude its data from model improvement entirely. Email team@merdial.com from an administrator address and we will apply it to the whole organisation. The Service works identically either way — nothing is withheld from an account that opts out.

6. Automated processing, and where a human sits

The Service scores and classifies calls automatically. One thing follows, and we treat it as a commitment rather than a disclosure:

  • No solely-automated decisions with legal or similar effect. Scores, coaching plans and qualification verdicts are recommendations. The product ships review queues, disputes and calibration precisely so a person decides. Customers agree in the Terms not to use Output as the sole basis for discipline, pay or termination.

Under California’s ADMT rules and equivalent regimes, individuals may ask for an explanation of how an automated decision affecting them was reached, and may opt out of certain uses. Route those requests through the customer organisation, or to team@merdial.com and we will assist it.

7. Who receives personal data

  • Sub-processors. A short, named list of infrastructure and AI vendors, published with their location and function at Sub-processors. Each is bound by contract to process only on our instructions.
  • Within the customer’s organisation. Owners, managers and administrators see the data their role and permission set allows. Client-portal users see only approved records for their own campaigns.
  • Professional advisers — auditors, lawyers, accountants — under duties of confidence.
  • Authorities, where legally compelled. We require valid legal process, and where we are permitted to do so we will notify the customer before disclosing Customer Data so it can seek protective relief.
  • A successor in a merger, acquisition or asset sale, subject to this policy and on notice.

We do not disclose personal data to anyone else, and we do not sell it.

8. How long we keep it

CategoryRetention
Call audio, transcripts, scores, leads and workflow recordsFor as long as the customer’s account is active, or until the customer’s configured retention period expires — whichever is shorter. Deleted on the customer’s instruction.
After account terminationExportable for 30 days, then deleted or irreversibly anonymised within 90 days.
Encrypted backupsRolling 35-day window, after which restores can no longer reach deleted data.
Account, seat and audit recordsLife of the account plus 12 months.
Billing and tax recordsUp to 7 years, as tax law requires.
Security telemetry (sign-in IP, failed attempts)12 months.
Support correspondence24 months from last contact.
Prospect and marketing data24 months from last engagement, or until you object.

9. International transfers

Merdial and its sub-processors operate in the United States, the European Union and the United Kingdom. Where personal data leaves the EEA or the UK to a country without an adequacy decision, the transfer is covered by the European Commission’s Standard Contractual Clauses (Modules 2 and 3, as applicable), the UK International Data Transfer Addendum, and a transfer risk assessment with supplementary technical measures — encryption in transit and at rest, and tenant isolation. The specific location of each sub-processor is listed on the Sub-processors page. Customers who need processing confined to a particular region should contact us before onboarding.

10. Your rights

Depending on where you live, you may have the right to access, correct, delete, port, restrict or object to the processing of your personal data, to withdraw consent, and to complain to a supervisory authority.

Where to send the request

If your data is in a customer’s Merdial account — you are an agent, or you were on a call — the customer is the controller. Ask them first. If you contact us instead, we will forward the request to them and assist as their processor requires; we cannot delete a customer’s records on a third party’s instruction. For data we hold as controller (your Merdial account, billing, support), write to team@merdial.com and we will respond within 30 days.

We do not charge for a request or discriminate against anyone who makes one. We may need to verify identity before acting, and will only ask for what verification requires.

11. Regional disclosures

12. Security

Encryption in transit and at rest, per-tenant row-level isolation enforced in the database rather than in application code, authenticated and role-scoped API surfaces, redaction of payment-card patterns before any generative call, and least-privilege internal access. The detail — including the controls, the breach process and the notification timelines — is in the Security Overview.

13. Cookies

The product surfaces use only strictly-necessary storage — a session token and your interface preferences. The marketing site uses a small amount of privacy-preserving analytics. The full inventory is in the Cookie Policy.

14. Children

Merdial is a workplace tool. It is not directed to anyone under 16, and we do not knowingly collect their personal data. If you believe we have, write to team@merdial.com and we will delete it.

15. Changes

We will update this policy as the product changes. Material changes are announced to account administrators by email at least 30 days before they take effect, and the “Last updated” date at the top of this page always reflects the current version.

16. Who we are, and how to reach us

Privacy: team@merdial.com. Security reports: team@merdial.com. Everything else: team@merdial.com. This policy is effective 6 September 2026.