Privacy policy
Last updated: 7 June 2026
BelBuddy is a service provided by Crafty Cast, trading under the name BelBuddy. We run an AI telephone assistant that answers inbound calls for our business customers, holds conversations, captures leads and schedules appointments. In delivering that service we process personal data — carefully and in line with the General Data Protection Regulation (AVG / GDPR). In this privacy policy we explain which data we process, why, for how long and what rights you have.
1. Who we are
The controller for the processing described in this policy is:
Crafty Cast (trading as BelBuddy)Noordvestsingel 81, 3119 DC Schiedam
Chamber of Commerce (KvK) number: 87872641
Email: privacy@belbuddy.com
2. Which personal data we process
From callers (people who call a telephone number that BelBuddy answers on behalf of our customer):
- telephone number and any caller identification;
- the recording of the telephone call and its text transcription;
- your name and any other information you provide during the call;
- the reason for your call and the content of your request;
- appointment and booking details (such as date, time and address) when an appointment is scheduled;
- messages exchanged with you via SMS or WhatsApp (for example a confirmation or booking link).
From customers (the businesses that use BelBuddy) and their contacts: account, contact and company details, sign-in and usage data, and billing details.
From businesses we approach ourselves (businesses that are not yet customers and to whom we send an offer): public business contact and company details. Exactly which data that is, where we obtain it and how to make us stop is set out in section 5.
3. Purposes and legal bases
We process personal data only for clearly defined purposes, on a legal basis set out in Article 6 of the AVG (GDPR):
- Performance of the contract (Art. 6(1)(b)): answering calls, capturing leads, scheduling appointments and managing our customer's account.
- Legitimate interest (Art. 6(1)(f)): improving and securing our service, the call-back and follow-up process for our customer, preventing abuse of our free trial (see section 6), and approaching businesses with an offer for BelBuddy (see section 5).
- Consent (Art. 6(1)(a)): for recording calls and for any marketing messages. You can withdraw your consent at any time.
- Legal obligation (Art. 6(1)(c)): for example, the statutory retention requirement for billing data.
4. Call recordings
At the start of a call you are informed that the call may be recorded. We use recordings and transcriptions to handle your request correctly, capture a lead and monitor the quality of the service. If you do not want the call to be recorded, you can say so at the start of the call.
5. Businesses we approach ourselves
Did you receive an email, letter or telephone call from us without having been in contact with us before? Then this section is about you. We approach Dutch businesses that we believe BelBuddy can help. Below you can read which data we hold about your business, where we obtain it, how long we keep it and how to make us stop in one step.
Which data we process. Business data only, and no more than we need in order to make contact:
- company name, town or city and postcode;
- the business contact details the business has itself made public: email address, telephone number and website;
- the name of the contact person, where it is published alongside those public contact details;
- public company details from the Dutch Commercial Register: KvK number, establishment number, legal form, SBI activity codes, registration date and size band;
- our own notes on any contact we have had with you, and the output of a fixed calculation rule that estimates whether BelBuddy is a fit for this kind of business;
- whether and when our email was opened, and whether a link in that email was clicked.
We process no special categories of personal data here. That output is about the business, not about you as an individual, and it decides nothing automatically: a member of staff decides whether and how we make contact.
Where we obtain the data. From public sources. To find businesses we use the Dutch Commercial Register held by the Chamber of Commerce (KvK) and public business listings on Google Maps; from those we take identifying details only, such as company name, town or city, trade and the Google location code. Contact details — email address and telephone number — we never take from Google: those come from the website the business has itself published, from another public source noted down by a member of staff, or you gave them to us yourself. Wherever possible we record, per item, which source it came from.
What we use it for, and on what legal basis. We use this data to approach your business a limited number of times with information about BelBuddy and an offer, and to keep track of whether you respond. To do that our emails contain an invisible tracking pixel and measurable links, so we can see whether a message was opened and whether it was clicked; we measure this through our sending service Mailgun. The legal basis is our legitimate interest (Art. 6(1)(f) GDPR): we have a commercial interest in bringing our service to the attention of businesses, and we only approach businesses whose public profile — the trade and the location — matches what BelBuddy was built for. We have weighed your interests against ours and recorded that assessment in writing; you can request an explanation of it via privacy@belbuddy.com.
Which channels we use. Email, a telephone call from a member of staff, SMS, WhatsApp, a message on LinkedIn, post, or a visit to your premises. We never call you using an automated system or our AI assistant: that is only permitted with your prior consent (Art. 11.7(1) of the Dutch Telecommunications Act), and our software refuses to do it.
Are you a sole trader (eenmanszaak), a VOF, a CV or a maatschap? Then your business details are also your personal data and you have greater protection. As soon as we establish that your business has such a legal form, we exclude it from cold approaches: we do not add it to our approach list and we do not send it cold email, unless you have given us prior consent. We do not rely on what we happened to know already: we only approach a business cold by email or telephone once we have established in the KvK Commercial Register that it is a legal entity. If we have not looked it up, or we are not certain, we do not approach you — with us, 'unknown' counts as do not approach, never as permission. This applies to email, telephone, SMS and WhatsApp; post and door-to-door visits are governed by the KvK Non-Mailing Indicator. If you do receive a message you should not have received, tell us via the unsubscribe link in the message or via privacy@belbuddy.com — we will stop immediately, on every channel.
Who sees your data. Only ourselves and the service providers we need in order to send and store a message: our hosting provider Hetzner in Germany, and, for email, the sending service Mailgun, which we have fixed to European servers and which also measures opens and clicks. If we approach you by SMS or WhatsApp, that runs via the providers listed in section 7. We do not sell your data and we do not pass it on to others for their own purposes.
How long we keep it. If there has never been any contact, we delete the whole record six months after we captured it — along with everything attached to it: the research, the messages, the notes and any chat conversation. If there has been contact, then two years after the last contact we delete everything that points to you as a person. That is: your contact details — name, email address and telephone number — and the recorded provenance of each; our conversation notes and internal follow-up notes; the research dossier and the text we had taken from your website; the result of the check on whether your email address exists, including its verdict and date; the supporting text behind our package recommendation, which quotes our research notes verbatim; the subject line and the full content of the messages we sent you, plus which links in them were clicked and any LinkedIn profile link; the notes on a demo request together with the telephone number used and the call record; the reason a member of staff noted against a status change; the notes on a planned visit; our open tasks about you; and any chat conversation on your personal proposal page. The link to that proposal page and its PIN also expire. What remains is the business part of the record: company name, sector, town or city and postcode, website, KvK number, establishment number, legal form, SBI codes, registration date and size band, the Google location code, the output of our calculation rule estimating whether BelBuddy is a fit for this kind of business and which package we recommend as a result, which source or campaign brought us to you, which channels we have opened or closed for your business, and our own figures on how the contact progressed — when and through which channel we approached you, whether an email was delivered, opened or clicked, and how many times your preview or proposal page was viewed. We also record that we sent you the notice described in this chapter and that you have objected, if you did; without those two items we cannot demonstrate that we followed the rules, nor prevent ourselves from approaching you again.
If your business is a sole trader, a VOF, a CV or a maatschap, that remaining data is still your personal data. You can ask us to delete it — see section 10. The 730-day period in section 6 applies to callers' call data and not to this data.
How to make us stop. You have the right to object to this processing (Art. 21 GDPR). Where the approach is for commercial purposes that right is absolute: you need give no reason and we must stop. Use the unsubscribe link at the bottom of our email, reply to our email saying you want no further messages, tell the member of staff you are speaking to, or email privacy@belbuddy.com. A single objection stops every channel at once — including post and telephone — and messages already queued are no longer sent.
What we keep after your objection. So that we do not approach you again by mistake, we keep one minimal record: an obscured representation (a hash) of your email address and telephone number, your public KvK number, the date of your objection, which channel it reached us on and for what reason, any note recorded alongside it, and a reference to the record it belonged to. A hash makes the address unreadable, but it is not an absolute guarantee that it can never be traced back. The rest of your data is removed. We keep that record indefinitely, precisely because otherwise we could not honour your objection.
Your other rights — access, rectification, erasure, restriction and lodging a complaint with the Dutch Data Protection Authority — are set out in section 10 and apply to this data too.
6. Retention period
We do not keep personal data for longer than necessary. We retain call data, recordings and transcriptions for 730 days (2 years) by default, after which they are deleted automatically. We keep billing data for as long as we are legally required to (the statutory retention period of 7 years). A different retention period may be agreed for specific customers. Different, shorter periods apply to businesses we approach ourselves; those are set out in section 5.
Record of trials already used
We give the free trial once per sign-up: once per account holder's email address and once per payment method, and — if you provide a KvK number — once per business as well. To stop the same applicant requesting it over and over — each trial costs us a real phone number and real call charges — we record a minimal entry when a trial starts: an obscured representation (a so-called hash) of the KvK number provided, of the account holder's email address and of a characteristic of the payment method used, plus the date and whether a payment was ever made. So this register does not contain the KvK number, the email address or the card or account number itself. (If you are a customer or have created an account, we do of course hold your KvK number and email address with your account — that is a separate processing activity, with its own basis and retention period.) A hash makes a value unreadable, but it is not an absolute guarantee that it can never be traced back — and a KvK number is public, which makes that easier rather than harder. We therefore treat this record as personal data, not as anonymous. The basis is our legitimate interest (Art. 6(1)(f) GDPR) in preventing abuse.
We keep this record for 730 days (2 years), counted from the record itself or, where a payment was made, from the last payment; after that we delete it automatically. Someone signing up again two years later is a new or returning customer to us, not an abuser.
Important, because it differs from the rest of this section: this record remains if you ask us to delete your account. We do remove the link to your account and the KvK number you entered from your account; the obscured record itself remains. If that were removed too, the record would lose its only purpose. If you disagree, you can object to it (Art. 21 GDPR) and we can look the record up and delete it — see section 10.
Refused when you should not have been? A KvK number is public, so in theory somebody else could enter your company's KvK number. If you are told at sign-up that a trial is already recorded for your details when you have never used one, email privacy@belbuddy.com or info@belbuddy.com. We will look the record up, tell you what we hold and delete it, so that you still get the trial. A member of staff is always involved: the refusal itself is automated, but you have the right to have a human review it (Art. 22 GDPR).
7. Sharing with third parties and sub-processors
We never sell your data. To deliver our service we engage carefully selected sub-processors, with each of whom we have entered into a data processing agreement:
| Processor | Purpose | Location | Safeguard |
|---|---|---|---|
| Twilio | Telephony and SMS | US / EU | Data processing agreement + SCCs |
| Meta (WhatsApp Cloud API) | WhatsApp messages | US / EU | Data processing agreement + SCCs |
| cal.diy (self-hosted; Cal.com's MIT self-host fork) | Appointments and bookings (optional, per client; only active once the operator enables self-hosted cal.diy — by default BelBuddy only sends a booking link) | Own infrastructure (EEA) | Under our own control |
| Calendly | Appointments and bookings (optional, per client using Calendly) | US | Data processing agreement + SCCs |
| Google Calendar | Calendar synchronisation (optional, owner-connected) | US / EU | Data processing agreement + SCCs; only after the owner connects it |
| Stripe | Payments, subscriptions and billing (for our customers only, not for callers) | US / EU (Ireland) | Data processing agreement + SCCs |
| Hetzner | Hosting and infrastructure | Germany (EEA) | Data processing agreement |
| Anthropic | AI processing (language model) | US | Data processing agreement + SCCs |
| Google Workspace | US / EU | Data processing agreement + SCCs | |
| PostHog (EU Cloud) | Website analytics and telemetry (consent-based on the marketing site; legitimate interest on the dashboard) | EU (Frankfurt) | Data processing agreement; EU hosting |
| Self-hosted speech engine | Speech recognition and synthesis | Own infrastructure (EEA) | Under our own control |
8. Transfers outside the EEA
A number of our sub-processors are based in the United States. For transfers of personal data outside the European Economic Area we apply appropriate safeguards, such as the Standard Contractual Clauses of the European Commission and, where applicable, the EU-US Data Privacy Framework.
9. Security
We take appropriate technical and organisational measures to protect your data, including encryption of traffic (TLS), access restrictions and hosting within the EEA. The core processing of speech takes place on our own self-hosted infrastructure within the EEA.
10. Your rights
Under the AVG (GDPR) you have the following rights in relation to your personal data:
- the right of access;
- the right to rectification;
- the right to erasure (the "right to be forgotten");
- the right to restriction of processing;
- the right to object to processing;
- the right to data portability;
- the right to withdraw consent you have given.
You can submit a request via privacy@belbuddy.com. We respond within the statutory time limit. If you are unhappy with how we handle your data, you have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens, autoriteitpersoonsgegevens.nl).
If you are a caller and your data was processed on behalf of one of our customers, that customer may be the controller. In that case we forward your request to the relevant customer and provide support where needed.
11. Cookies, website analytics and telemetry
On our marketing website we set functional, strictly necessary cookies and — only after you give consent — privacy-friendly analytics and telemetry cookies. Read more about this in our Cookie policy.
For this analytics we use PostHog, hosted on EU servers (EU Cloud). On our marketing website it runs solely on the basis of your consent (Art. 6(1)(a) AVG/GDPR) and measures which pages and steps work and where visitors drop off. This includes an anonymised session recording (session replay) in which all entered fields — name, telephone number, email and messages — are automatically masked and never captured; only the layout and use of the page are recorded. We never use this data for advertising or cross-site tracking.
When you are signed in to your customer dashboard we collect limited, anonymised product statistics on the basis of legitimate interest (Art. 6(1)(f) AVG/GDPR). On the dashboard we do not record any session and use no automatic click capture; these events contain only technical identifiers and counts, never names, telephone numbers, conversations or messages, and no cookie is set for this.
You can withdraw your consent for analytics on the marketing website at any time via the control in our Cookie policy; we then stop measuring immediately. You can object to the legitimate-interest telemetry via privacy@belbuddy.com.
12. Contact
Do you have questions about this privacy policy or about how we process your data? Get in touch at privacy@belbuddy.com.
13. Changes
We may update this privacy policy from time to time. You will always find the most current version on this page, with the date of the latest change shown at the top.