Privacy Policy
E-mail: [email protected]
Website: www.baydardigital.com
Chamber of Commerce (KvK): 93519702
Established in: The Hague, the Netherlands
Version: 2.0
Last updated: September 2026
Baydar Digital respects your privacy and is committed to protecting your personal data.
This Privacy Policy explains:
what personal data we collect;
how we obtain your personal data;
why we process your personal data;
the legal bases we rely on;
how long we retain personal data;
which third parties may process personal data;
how we protect personal data;
how international transfers are handled;
how AI Agents and voice systems may process data;
what rights you have under applicable data protection law.
This Privacy Policy applies when you:
visit www.baydardigital.com;
contact Baydar Digital;
request information or a quotation;
become a customer;
purchase or use our Services;
interact with one of our own AI systems;
communicate with us by telephone, e-mail, web form, chat or another channel;
otherwise provide personal data directly to Baydar Digital.
Where Baydar Digital processes personal data solely on behalf of one of its business customers, the customer generally acts as the Controller and Baydar Digital acts as Processor. In such cases, the customer's own privacy policy and the Baydar Digital Data Processing Agreement may also apply.
For personal data that Baydar Digital determines how and why to process, Baydar Digital acts as the Controller.
Contact details:
Baydar Digital
The Hague, the Netherlands
Chamber of Commerce (KvK): 93519702
E-mail: [email protected]
Website: www.baydardigital.com
Where applicable, correspondence may also be sent to:
Rijwijkseweg 528-28
2516 HT The Hague
The Netherlands
For questions about privacy or data protection, contact:
Baydar Digital may have different legal roles depending on the processing activity.
Baydar Digital generally acts as Controller when it processes personal data for its own purposes, including:
website enquiries;
sales enquiries;
quotation requests;
customer administration;
invoicing;
marketing;
customer support;
supplier management;
website security;
business administration.
In these situations, Baydar Digital determines why and how the relevant personal data is processed.
Baydar Digital generally acts as Processor when it processes personal data solely on behalf of a customer through Services such as:
AI voice assistants;
AI receptionists;
chatbots;
appointment systems;
reservation systems;
workflow automation;
CRM integrations;
calendar integrations;
communication integrations;
customer-service automation.
For example, where a restaurant uses a Baydar Digital AI receptionist to receive customer calls, the restaurant will generally determine the purpose of the processing and act as Controller.
Baydar Digital will then process personal data on behalf of that customer as Processor.
Such processing is governed by the applicable Data Processing Agreement (DPA).
Depending on the circumstances, we may process data relating to:
website visitors;
prospective customers;
existing customers;
Consumers;
Business Customers;
employees and representatives of customers;
suppliers;
business partners;
persons requesting quotations;
persons contacting Baydar Digital;
people interacting with Baydar Digital-operated AI systems;
people interacting with AI systems operated on behalf of our customers;
callers;
website chatbot users;
appointment or reservation customers;
other business contacts.
We may obtain personal data directly from you when you:
visit our website;
submit a contact form;
request a quotation;
send us an e-mail;
call us;
communicate through a chatbot;
create an account;
enter into an Agreement with us;
purchase a Service or digital product;
make a payment;
provide information during a project;
subscribe to communications;
communicate through social media;
interact with an AI Agent.
We may also receive personal data from:
our business customers;
authorized integrations;
CRM systems;
calendar systems;
payment providers;
communication platforms;
AI and automation systems;
publicly available business sources where legally permitted;
business partners;
service providers acting on our behalf.
The personal data we process depends on your relationship with Baydar Digital.
We may process:
first name;
last name;
company name;
job title;
address;
business address;
e-mail address;
telephone number.
customer number;
account details;
login information;
subscription information;
Service history;
support requests;
project information.
invoice information;
billing address;
payment status;
transaction information;
VAT information;
business administration records.
Baydar Digital does not normally need to store full payment-card details where payment is handled by an external payment provider.
Depending on our website configuration, we may process:
IP address;
browser information;
device information;
operating system;
website interaction data;
referring pages;
log information;
cookie identifiers;
security data.
We may process:
e-mails;
contact form messages;
chatbot conversations;
support conversations;
call information;
other correspondence.
Baydar Digital provides AI-powered services including AI voice assistants, AI receptionists, chatbots and automation systems.
When an individual interacts with an AI Agent, the following information may be processed depending on the configuration:
telephone number;
caller name;
e-mail address;
voice/audio;
conversation content;
transcripts;
appointment information;
reservation information;
customer-service enquiries;
dates and times;
call duration;
call metadata;
CRM information;
information voluntarily provided during the conversation;
AI-generated responses;
technical information relating to the interaction.
The exact information processed depends on the AI Agent and the instructions provided by the relevant customer.
We may process personal data for the following purposes.
Including:
providing AI Agents;
operating chatbots;
managing automation systems;
developing websites;
providing digital products;
maintaining integrations;
providing technical support;
fulfilling customer orders.
Including:
answering enquiries;
responding to quotation requests;
managing projects;
providing customer service;
communicating about Services.
Including:
preparing quotations;
entering into Agreements;
performing contractual obligations;
managing subscriptions;
administering Services.
Where relevant, personal data may be processed to:
check availability;
create appointments;
create reservations;
send confirmations;
change bookings;
cancel bookings.
Personal data may be processed to:
understand spoken or written requests;
generate AI responses;
execute authorized actions;
transfer data to connected systems;
route calls;
escalate conversations;
provide requested information.
We may process information to:
issue invoices;
process payments;
maintain financial records;
comply with tax obligations;
manage outstanding payments.
We may process information to:
protect our systems;
prevent unauthorized access;
detect abuse;
investigate incidents;
maintain technical logs;
prevent fraud.
We may use limited information to:
troubleshoot technical problems;
improve configurations;
analyze Service performance;
improve reliability;
develop our Services.
Where possible and appropriate, information used for statistical analysis is aggregated or anonymized.
Where legally permitted, we may use contact information to:
communicate about relevant Baydar Digital Services;
send newsletters;
provide business updates;
follow up on enquiries.
You may object to direct marketing at any time.
Baydar Digital processes personal data only where a valid legal basis applies.
Depending on the circumstances, we may rely on the following legal bases.
We may process personal data where necessary to:
provide purchased Services;
process orders;
provide customer support;
fulfil an Agreement;
administer an account;
manage subscriptions.
We may process personal data to:
respond to quotation requests;
prepare proposals;
discuss requirements;
communicate before entering into an Agreement.
We may process personal data where necessary to comply with legal obligations, including:
tax obligations;
accounting obligations;
legal record-keeping;
lawful requests from authorities.
Where legally permitted, we may process personal data where necessary for legitimate interests such as:
operating and improving our business;
securing our website and systems;
preventing fraud;
managing business relationships;
troubleshooting;
defending legal claims;
B2B communication.
Where we rely on legitimate interests, we consider whether your privacy rights outweigh our interests.
Where required, we may rely on your consent for activities including:
certain marketing communications;
optional cookies;
tracking technologies;
other optional processing.
You may withdraw consent at any time.
Withdrawal does not affect processing carried out lawfully before the withdrawal.
Baydar Digital does not generally intend to collect special categories of personal data.
However, in some AI interactions users may voluntarily provide information that could reveal:
health information;
allergy information;
medical dietary restrictions;
religious information;
disability information;
other sensitive information.
For example, an individual making a restaurant reservation may mention an allergy or dietary requirement.
Where Baydar Digital acts as Processor, the relevant customer is responsible for determining whether such information should be collected and what legal basis applies.
Baydar Digital aims to configure systems according to the principle of data minimisation and to avoid unnecessary processing of sensitive personal data.
Some AI voice systems may technically support call recording.
Call recording is not automatically enabled simply because the technology permits it.
Where calls are recorded, processing may include:
voice recordings;
transcripts;
call metadata.
Where Baydar Digital acts as Processor, the customer is generally responsible for determining:
whether recording is necessary;
the lawful basis;
what information must be provided to callers;
how long recordings should be retained.
Where technically supported, Baydar Digital may configure:
recording settings;
retention settings;
deletion settings;
PII redaction;
access restrictions.
AI conversations may generate transcripts.
Transcripts may be used to:
conduct the conversation;
execute workflows;
create appointments;
create reservations;
provide customer support;
troubleshoot technical issues;
analyze technical performance;
maintain security.
Transcripts are not intended to be retained indefinitely.
Retention depends on:
the applicable Service;
customer instructions;
technical requirements;
legitimate operational requirements;
applicable law.
Baydar Digital uses artificial intelligence and automated technologies in certain Services.
AI systems may automatically:
understand speech;
generate responses;
classify enquiries;
route calls;
create appointment requests;
execute workflows;
transfer information to connected systems.
Unless expressly designed and legally configured for such a purpose, Baydar Digital AI Services are not intended to make decisions solely through automated processing that produce legal or similarly significant effects on individuals.
Where required by law, users interacting with an AI system will be informed that they are interacting with AI.
Baydar Digital does not sell personal data.
We may share or make personal data available to selected service providers where necessary to provide our Services.
Depending on the relevant Service and configuration, these may include:
Used for AI voice and telephone-agent infrastructure.
Depending on configuration, Retell AI may process:
telephone numbers;
audio;
transcripts;
call metadata;
conversation information;
appointment or reservation information.
AI providers may process relevant portions of conversation data or instructions required to generate AI responses.
The specific AI provider depends on the Service configuration.
Used for workflow automation and integrations.
Used for workflow automation and integrations.
May be used for development, applications, APIs or hosting components.
These may include:
Cal.com;
Calendly;
Google Calendar;
Microsoft Outlook;
similar scheduling systems.
Such providers may process information including:
names;
e-mail addresses;
telephone numbers;
appointment details;
reservation details.
Personal data may be processed using hosting, cloud, database or infrastructure providers.
We may use providers for:
telephone services;
SMS;
e-mail;
messaging;
video communication.
Where applicable, payments may be processed through external payment-service providers.
We may share personal data with:
accountants;
lawyers;
insurers;
professional advisers
where reasonably necessary.
We may disclose information where required by:
law;
court order;
regulatory authority;
competent government authority.
Not every provider listed above is used for every Customer or Data Subject.
Where Baydar Digital engages a service provider to process personal data on its behalf, Baydar Digital takes reasonable steps to ensure appropriate contractual data-protection obligations are in place.
Where Baydar Digital acts as Processor for a business customer, applicable Sub-processors are governed by the Baydar Digital Data Processing Agreement.
An up-to-date Sub-processor list may be made available where appropriate.
Baydar Digital and its service providers may process personal data both within and outside the European Economic Area ("EEA").
Some technology providers used in connection with AI, cloud, communications or automation Services may operate from countries outside the EEA.
Where personal data is transferred outside the EEA and GDPR requires additional safeguards, Baydar Digital will seek to use a lawful transfer mechanism.
Depending on the situation, this may include:
an adequacy decision by the European Commission;
Standard Contractual Clauses ("SCCs");
supplementary contractual, technical or organizational measures;
another legally permitted international-transfer mechanism.
You may contact us for further information about the safeguards applicable to a specific transfer.
We retain personal data only for as long as reasonably necessary for the purposes for which it was collected, unless a longer period is required by law.
Different categories of information may have different retention periods.
Records that must be retained under applicable Dutch tax or accounting laws may generally be stored for the legally required period, which is commonly seven years for relevant basic administration.
Customer and contractual information may be retained:
during the customer relationship;
for a reasonable period afterwards;
for legal, administrative or claims purposes where necessary.
Contact enquiries that do not lead to a customer relationship are retained only as long as reasonably necessary to:
respond;
follow up;
maintain relevant business records.
Where recording is enabled, retention depends on:
customer instructions;
Service configuration;
operational necessity;
legal requirements.
Recordings are not intended to be retained indefinitely.
Transcripts are retained according to:
the relevant service configuration;
customer instructions;
technical and support requirements;
applicable law.
Technical and security logs may be retained for a limited period necessary for:
security;
troubleshooting;
abuse prevention;
system reliability.
Marketing data may be retained until:
you unsubscribe;
you object;
consent is withdrawn where consent applies;
the data is no longer reasonably required.
Certain records may be retained afterwards where necessary to demonstrate compliance with legal obligations.
Baydar Digital aims to collect and process only the personal data reasonably necessary for the relevant purpose.
AI Agents are, where practical, configured to request only information required to perform their intended function.
We do not intentionally collect personal data merely because a system is technically capable of doing so.
Baydar Digital takes appropriate technical and organizational measures designed to protect personal data against:
unauthorized access;
unlawful processing;
accidental loss;
alteration;
disclosure;
destruction.
Depending on the system and Service, measures may include:
TLS/HTTPS encryption;
secure API connections;
authentication controls;
multi-factor authentication where available;
role-based access controls;
least-privilege access;
secure credential management;
API-key protection;
logging;
monitoring;
data-retention settings;
backups where appropriate;
software updates;
access revocation procedures;
incident-response procedures;
PII redaction or masking where appropriate.
No method of electronic storage or transmission over the internet can be guaranteed to be completely secure.
Baydar Digital therefore cannot guarantee absolute security, but takes reasonable measures appropriate to the nature and risks of the processing.
If Baydar Digital becomes aware of a Personal Data Breach, we will take appropriate steps to:
investigate the incident;
limit its impact;
secure affected systems;
document the incident;
notify relevant parties where required.
Where Baydar Digital acts as Processor, we will notify the relevant Controller without undue delay in accordance with the applicable Data Processing Agreement.
Where Baydar Digital acts as Controller, we will notify the competent supervisory authority and affected individuals where required by GDPR.
Baydar Digital may use cookies and similar technologies on:
Cookies are small files or technologies used to store or access information on a device.
Depending on the website configuration, we may use:
Required for:
website functionality;
security;
session management;
consent settings;
essential website features.
These cookies do not require consent where they are strictly necessary.
May remember settings selected by the user.
May be used to understand:
website usage;
traffic;
page performance;
visitor interactions.
Where consent is legally required, these cookies will not be placed before consent.
Where used, marketing cookies may be used for:
advertising;
campaign measurement;
retargeting;
audience measurement.
Where required by law, marketing cookies will be used only after consent.
Users can manage non-essential cookies through the cookie banner or cookie-settings functionality where available.
Withdrawal of cookie consent should be as easy as giving consent.
Our website or Services may contain links to third-party websites or integrations.
Baydar Digital is not responsible for the privacy practices of independent third parties where those parties determine their own processing purposes.
We recommend reviewing the privacy policies of those providers.
Where permitted by law, Baydar Digital may send commercial communications relating to its Services.
You may object to direct marketing at any time.
Marketing e-mails will normally contain an unsubscribe option where required.
You may also contact:
to request that we stop using your personal data for direct marketing.
Under GDPR, you may have the following rights depending on the circumstances.
You may request information about personal data Baydar Digital processes about you.
You may request correction of inaccurate or incomplete personal data.
You may request deletion of your personal data where the legal requirements are met.
This right is not absolute. We may retain information where processing remains legally required or permitted.
You may request restriction of processing in certain circumstances.
You may object to certain processing based on legitimate interests.
You have the right to object to direct marketing at any time.
Where applicable, you may request personal data in a structured, commonly used and machine-readable format and may have the right to transmit it to another organization.
Where processing is based on consent, you may withdraw your consent at any time.
Withdrawal does not affect the lawfulness of processing before withdrawal.
Where applicable, you may have rights relating to decisions based solely on automated processing that produce legal or similarly significant effects.
To exercise a privacy right, contact:
Please describe your request clearly.
We may request additional information where reasonably necessary to verify your identity and protect personal data from unauthorized disclosure.
We will generally respond within one month of receiving a valid request.
Where permitted by GDPR, this period may be extended by up to two additional months where necessary due to:
complexity;
number of requests.
If an extension is required, we will inform you within the initial one-month period.
Privacy-right requests are generally free of charge.
Where requests are manifestly unfounded or excessive, applicable law may allow us to charge a reasonable fee or refuse the request.
If your personal data was processed through an AI Agent operated for one of Baydar Digital's business customers, that customer may be the Controller responsible for your request.
For example, if you contacted a restaurant, salon, company or other organization through an AI Agent provided by Baydar Digital, you may need to contact that organization directly.
Baydar Digital will reasonably assist its customers with applicable Data Subject requests in accordance with the Data Processing Agreement.
If you have concerns about how Baydar Digital processes your personal data, please contact us first at:
We will try to resolve your concern.
You also have the right to submit a complaint to the Dutch supervisory authority:
Autoriteit Persoonsgegevens
You may also exercise any judicial remedies available to you under applicable law.
Baydar Digital's Services and website are not intentionally directed at children.
We do not knowingly collect personal data from children where parental or guardian authorization is legally required without such authorization.
If you believe that a child has provided personal data to Baydar Digital without the required authorization, please contact:
We will investigate the matter and, where appropriate, delete the relevant information.
If Baydar Digital is involved in:
a merger;
acquisition;
sale;
restructuring;
transfer of business activities,
personal data may be transferred as part of that transaction where legally permitted.
Appropriate confidentiality and data-protection safeguards shall apply.
Baydar Digital may update this Privacy Policy from time to time.
Changes may be necessary because of:
changes to our Services;
changes to technology;
changes to Sub-processors;
changes to applicable law;
changes to business operations.
The most current version will be published on:
The date at the top of this Privacy Policy indicates when it was last updated.
Where changes materially affect the way we process personal data, we may provide additional notice where appropriate.
This Privacy Policy should be read together with, where applicable:
Baydar Digital General Terms and Conditions;
Baydar Digital Data Processing Agreement;
applicable Service Agreements;
applicable cookie information;
individual project agreements.
Where Baydar Digital processes personal data solely on behalf of a Customer, the Data Processing Agreement governs Baydar Digital's obligations as Processor.
This Privacy Policy is intended to comply with applicable data-protection legislation, including:
Regulation (EU) 2016/679, the General Data Protection Regulation ("GDPR");
the Dutch GDPR Implementation Act (Uitvoeringswet Algemene verordening gegevensbescherming – UAVG);
other applicable Dutch and European privacy and electronic-communications legislation.
For questions, requests, complaints or concerns regarding privacy or personal data, contact:
Baydar Digital
The Hague, the Netherlands
Chamber of Commerce (KvK): 93519702
E-mail: [email protected]
Website: www.baydardigital.com
Postal address:
Rijwijkseweg 528-28
2516 HT The Hague
The Netherlands
Baydar Digital – Privacy Policy v2.0
Last updated: September 2026