Back to the homepage

Security & data protection

CoBuilders processes calls and customer data. That is why the roles, the storage and the agreements are written down before you ask for them.

GDPRData inside the EUProcessor agreement (DPA)IMY guidelines

You are the controller. We are the processor.

CoBuilders acts as data processor under article 28 GDPR. Your organisation is the data controller. That means you keep full control of your data and decide the purpose of the processing.

We provide a data processing agreement (DPA) as standard when signing. You don't have to ask for it.

Your CRM data stays in your CRM.

CoBuilders does not replace your systems. We read and enrich data through API integrations and write the outcome back, but the data stays where it lives today.

Nothing is written to your CRM without human approval.

Your data is stored inside the EU.

Call transcripts and AI-generated insights are stored encrypted inside the EU and linked to your CRM.

You decide the retention period and can request deletion at any time. Subprocessors outside the EU are used only under the EU-US Data Privacy Framework or standard contractual clauses, and are held to the same requirements.

We follow IMY's guidelines.

CoBuilders follows the guidelines of the Swedish Authority for Privacy Protection on call recording and the processing of personal data in a sales context.

If your organisation requires a data protection impact assessment (DPIA), we help with the documentation.

Questions from your data protection officer?

Bring them to the demo. We go through agreements, storage and processing alongside the product.

Book a demo