Privacy Policy
Last updated: 9 August 2026
Diska builds AI voice agents that answer calls, qualify contacts and carry out processes over the phone. This policy explains what personal data we process, on what basis, for how long, and who we pass it to.
It is written to be read. Where the technical reality matters — for example, that a call is only recorded after the caller is told — we say so concretely rather than in generic terms.
Who we are
Diska is the controller of the data described in this policy.
- Privacy contact: hello@diska.ai
- Scope: the
diska.aiwebsite, the application atapp.diska.ai, the API atapi.diska.ai, the embeddable voice widget, and the calls conducted by the agents our customers configure.
Two different roles
This distinction determines who to approach to exercise your rights.
When you are our customer (you created an account and configured agents), we are the controller of your account, billing and usage data.
When you speak to a customer's agent, that customer decides why the call happens and what it is for. In that case Diska acts as a processor: we handle the call data on the customer's instructions and within the limits they set. If you want to access or delete what was said on a call, the request goes to the company that answered you; we help them respond.
What we process
Account data
Name, email address, password (stored only as a hash), company, role, phone, language and time zone. If you sign in with Google, we receive your name, email and profile picture from Google — never your Google password.
Agent configuration
Instructions, conversation flows, variables, actions, and documents you upload to the knowledge base. Those documents are split into passages and converted into numeric representations (embeddings) so the agent can consult them during a call.
Call data
This is the core of the service, and worth being precise about:
- Real-time audio. While the call runs, audio is streamed to the voice provider to be transcribed and answered. It is processed in transit.
- Transcript. The text of what was said, kept in the call history.
- Metadata. Start time, duration, status, outcome, the agent involved and — on telephone calls — the phone number.
- Collected variables. Whatever the agent was configured to ask for: name, contact details, reason for calling, preferred times.
- Audio recording, only where applicable — see below.
Recordings are never silent
Recording is off by default. It is a per-agent decision made by the customer, and the platform enforces two technical guarantees:
- An agent with no notice wording configured does not record, even if recording is switched on. Recording without a notice is not possible.
- The notice is spoken by the agent at the start of the call. In explicit mode, the agent waits for spoken confirmation before continuing.
The exact wording used is stored alongside the recording, so it is later possible to know what the caller was told — not merely that "consent existed".
Website and widget data
- Contact form: the name, email, company and phone you send us.
- Public demo: you can speak to Ísis, our demo agent, without an account. That conversation is treated like any other call.
- Analytics: we use Google Analytics to understand how the site is used. Parameters are filtered before they are sent — emails, phone numbers, identifiers and opaque strings are stripped, and paths containing identifiers are anonymised.
- Technical data: IP address and user agent, used for security and abuse limiting.
Legal bases
| Purpose | Basis |
|---|---|
| Providing the service to account holders | Performance of a contract |
| Conducting calls on customers' behalf | Customer instructions (as processor) |
| Recording calls | Consent of the caller, obtained at the start of the call |
| Security, abuse prevention, technical logs | Legitimate interest |
| Responding to enquiries | Pre-contractual steps |
| Meeting legal and tax obligations | Legal obligation |
Who we share with
We do not sell personal data. We rely on providers who process it on our behalf, under contract, and only for the stated function:
| Provider | Function | Data involved |
|---|---|---|
| OpenAI | Real-time voice, transcription, synthesis, embeddings | Call audio and text, knowledge base passages |
| Inworld AI | Real-time speech-to-speech, transcription, synthesis | Call audio and text |
| ElevenLabs | Speech synthesis | Text the agent is to speak |
| Cartesia | Speech synthesis | Text the agent is to speak |
| Supabase | Database, storage and authentication | Account, configuration, transcripts, recordings |
| Sign-in and site analytics | Email and profile; navigation events | |
| Twilio | Telephony, where the customer enables phone calls | Phone number and call audio |
We may also disclose data where the law requires it, or to defend legal claims.
International transfers
The providers above operate mainly outside Angola, which means data is transferred to other jurisdictions — chiefly the United States and the European Union. We require appropriate contractual safeguards for those transfers.
How long we keep it
- Account data: while the account exists, and up to 12 months afterwards for accounting and legal purposes.
- Transcripts and call metadata: while the customer's account is active, unless deletion is requested earlier.
- Audio recordings: for the period the customer sets; absent a setting, the same period as transcripts.
- Technical and security logs: up to 12 months.
- Contact form submissions: up to 24 months after the last contact.
A customer can request early deletion of any call.
Your rights
Under Angola's Law no. 22/11 of 17 June (Personal Data Protection Law) and, where applicable, the GDPR, you have the right to access your data, correct it, delete it, object to processing, request its restriction, and receive it in a portable format. You may withdraw recording consent at any time, without affecting what was lawfully recorded beforehand.
Write to hello@diska.ai. We respond within the statutory period. Where we hold the data on a customer's behalf, we route the request to that customer and help them answer.
You also have the right to lodge a complaint with Angola's Data Protection Agency (APD).
Security
Security is covered in detail in the security documentation. In short: connections are encrypted in transit, third-party credentials stay server-side and never reach the browser, each organisation's data is isolated, and the session credentials used by anonymous calls are short-lived and scoped to that call alone.
No system is immune. If we detect an incident affecting you, we notify the customers concerned and, where the law requires, the competent authority.
Children
The service is not intended for anyone under 18 and we do not knowingly collect their data. If you believe a minor has provided us with data, contact us and we will delete it.
Changes
We may update this policy. Material changes are communicated to customers by email or in the application, with reasonable notice. The date at the top marks the version in force.

