Legal

Privacy Policy

Last updated: September 9, 2026

MyDaddy.io (“MyDaddy.io”, “we”, “us”) provides a business phone system and AI agent stack for small teams. This policy describes what data we collect, why, how long we keep it, and the choices you have. It applies to both visitors to mydaddy.io and to workplaces created on the platform.

TL;DR We only collect what's needed to run your phone system, route your calls, train/operate the AI agents you turn on, sync with the CRMs/helpdesks you connect, and bill you. We don't sell personal data. You can export or delete your workplace data at any time by emailing privacy@mydaddy.io.

1. Who this policy covers

If you're an end user of a workplace (for example, someone calling a business that uses MyDaddy.io), the business — not MyDaddy.io — is the data controller for the record of that interaction. MyDaddy.io acts as the data processor on that business's behalf. Data subject requests should go to that business first. We'll honour the request if they direct us to.

2. What we collect

2.1 Account data

2.2 Phone data

2.3 AI agent sessions

2.4 Integration data

2.5 Product telemetry

2.6 Cookies

2.7 Cliq Huddle install

Installing the published Huddle extension creates a workplace on MyDaddy.io. We store the installer’s Cliq identity and a directory snapshot (up to 50 people) so roster mapping works. We also create a sales Lead in mydaddy.io’s own Zoho CRM (not your CRM) so we can follow up on the workplace. That Lead is not written to tenant Redis zoho-mcp-* keys.

2.8 Slack / Crossbar

Installing the published Crossbar Slack app creates or revives a workplace on MyDaddy.io. Slack sends us user and team (and, on Grid, enterprise) ids, slash-command text, interactivity payloads, file bytes for greetings and voicemail, and work emails used only to bind a Slack user to the workplace roster. We do not use Slack huddle media. Fields Slack sends that we do not need are received and unused. Call audio stays on mydaddy.io. Retention follows the same workplace clocks as other call and voicemail data. To delete Slack-derived data, email privacy@mydaddy.io or uninstall Crossbar from Slack (that cancels Billing; it does not by itself delete the Workplace).

2.9 Google Chat / Crossbar

Installing the published Crossbar Google Chat app creates or revives a workplace on MyDaddy.io. Google Chat sends us Workspace email, Chat user id, and Workspace domain / customer ids, plus slash-command text used to mint a Join URL. We do not use Google Meet or in-Chat audio. Consumer Gmail and Chat guests cannot place calls. Call audio stays on mydaddy.io. We also create a sales Lead in mydaddy.io’s own Zoho CRM (not your CRM). Retention follows the same workplace clocks as other call data. To delete Chat-derived data, email privacy@mydaddy.io or uninstall Crossbar from Google Workspace Marketplace (that cancels Billing; it does not by itself delete the Workplace). Leaving one Chat space is not uninstall.

2.10 Microsoft Teams / Crossbar

Installing the published Crossbar Microsoft Teams app creates or revives a workplace on MyDaddy.io. Teams / Entra sends us work email, Entra object id, and tenant id, plus slash-command text used to place a call. We use Azure Communication Services to ring the Teams desktop or web client; we do not use Graph application-hosted media or a browser Join page. Personal Microsoft accounts and Teams guests cannot place calls. Call audio is mixed on mydaddy.io. We also create a sales Lead in mydaddy.io’s own Zoho CRM (not your CRM). Retention follows the same workplace clocks as other call data. To delete Teams-derived data, email privacy@mydaddy.io or uninstall Crossbar from the Teams tenant (that cancels Billing; it does not by itself delete the Workplace). Closing a 1:1 chat is not uninstall.

2.11 WhatsApp / Crossbar

Connecting WhatsApp via Embedded Signup creates or revives a workplace on MyDaddy.io. Meta sends us the WhatsApp Business Account id, Cloud API phone number id, business E.164, work email of the installer, and message text used to place a call. Call audio uses SIP-TLS + SDES SRTP + G.711 between Meta and mydaddy.io; we do not use a browser Join page. We store Meta-generated SIP credentials as write-only workplace secrets. Group chats cannot place calls. Business-initiated agent rings require the user’s WhatsApp call permission. We also create a sales Lead in mydaddy.io’s own Zoho CRM (not your CRM). Retention follows the same workplace clocks as other call data. To delete WhatsApp-derived data, email privacy@mydaddy.io or disconnect WhatsApp (that cancels Billing; it does not by itself delete the Workplace). Losing one chat is not uninstall.

3. How we use it

We do not sell personal data, share it with advertisers, or train our own foundation models on your workplace content. Third-party AI providers (OpenAI and related STT/TTS vendors) process content on a per-request basis under their own data-processing terms. The current processor list is on the DPA & subprocessors page.

4. Legal bases (GDPR)

5. Retention

There is no Settings → Retention page today. Email privacy@mydaddy.io to request deletion or a shorter hold.

6. Sharing

We only share data with processors that are essential to operating the service:

7. International transfers

Each MyDaddy.io workplace is pinned to a combo (a regional server instance). Your workplace's Postgres row records the combo id, and every call / agent session for that workplace is handled on that combo's infrastructure. If you need your data to stay in a specific jurisdiction, choose a combo located there during signup. Cross-combo transfer only happens with an explicit admin action (migration between regions).

8. Security

9. Your rights

Depending on where you live (GDPR, UK GDPR, CCPA/CPRA, etc.) you may have the right to:

Email privacy@mydaddy.io from the address on your workplace. We'll reply within 30 days.

10. Children

MyDaddy.io is a B2B product. It is not intended for, and not marketed to, anyone under 16. If you believe a child's data has been collected by a workplace, email privacy@mydaddy.io so we can work with the workplace admin to remove it.

11. Changes to this policy

We'll post material changes to this page and update the “Last updated” date at the top. If a change meaningfully reduces your rights, we'll also email workplace admins at least 14 days before the change takes effect.

12. Contact

Privacy questions, data-access or deletion requests, and security reports all go to privacy@mydaddy.io. For general product questions, see the Contact page or chat us through the widget on this site.