AURA

AI receptionist recordings and transcripts: what you must settle with the vendor and tell the caller

A call with an AI receptionist leaves a recording, a transcript and a CRM entry — and a specific party is responsible for each. What to settle with the vendor before signing and what to tell the caller, with real UODO enforcement decisions.

Published
12 min read2387 words

AURA — a virtual business manager. Management on facts, not impressions. Who we are

Key takeaways

  • Both the controller (your company) and the processor (the vendor) are responsible for protecting call data at the same time — confirmed by UODO fines against McDonald's Polska and 24/7 Communication.
  • A written processing agreement with vendor verification is mandatory — its absence cost one institution a 2.5 thousand PLN fine.
  • A customer has the right to a copy of their data from a recording, including their voice — ordered by a UODO decision under Article 15(3) GDPR.
  • Notice of the right to complain to a supervisory authority is mandatory, but stating the UODO's address in that notice is not required.
  • Logs at the language model provider (e.g. OpenAI) are a separate matter from your AI receptionist vendor's retention policy — kept for up to 30 days by default.

A few words that show up in this text

Explained in plain language — you do not need to know the trade to read on.

CRM
One place holding clients and enquiries: who asked, about what, and what happened next.
API
The way two programs hand data to each other without a person in between.
chatbot
A program that answers questions according to a ready-made scenario.

You're rolling out an AI receptionist or a phone system with transcription, and you want to know exactly what's left after one call, who's responsible for it, and what to settle with the vendor before anyone actually calls. Short answer: a call usually leaves behind an audio recording, a transcript, a summary and CRM fields, and each of these has a specific party responsible for it — you as the data controller and the vendor as the processor, sometimes both liable at once, as real GDPR enforcement decisions show.

This page covers exactly what's left after a call and where it lives, what a data processing agreement needs before you sign it, whether you need to keep the raw audio at all, how retention works at the language model provider using OpenAI as an example, what to tell the caller, and what to do when a customer asks for a copy of their data from a recording.

Vintage studio microphone on a stand in a dimly lit room
A voice recorded in a call with an AI receptionist is personal data, just like a name or a phone number

What's left after one call with an AI receptionist

A single call with an AI receptionist usually leaves more traces than it first appears: the audio recording itself, a text transcript, a call summary, specific fields saved in the CRM (name, phone number, reason for contact), and technical logs on the side of both the AI receptionist vendor and the language model provider that processes the speech.

The data's path looks like this:

  1. phone call
  2. AI receptionist vendor
  3. language model provider
  4. transcript and summary
  5. CRM
  6. deletion after a set period
The diagram shows the same process step by step — from the first link to the last.
ArtifactWhere it livesWho has accessWho decides the retention period
Audio recordingVendor's servers (sometimes passed on to the model provider)Vendor's team under the processing agreement, your company on requestYour company, written into the vendor contract
TranscriptCRM or vendor panelPeople with CRM accessYour company
Call summaryCRMStaff handling the inquiryYour company
Model provider's technical logsModel provider's infrastructure (e.g. abuse monitoring logs)Model provider, usually without your company's accessModel provider, under its own policy

Technical logs at the model provider

The last row is easy to miss: the model provider behind the AI receptionist's speech recognition keeps its own logs, independently of whatever your direct vendor does with the recording. This is worked through with OpenAI as an example further down.

Who's responsible: the controller and the processor

In this setup, your company is the data controller — you decide why the caller leaves their data and how long to keep it. The AI receptionist vendor is the processor: it processes data on your behalf, on your instructions. If the vendor relies on another company's language model, that company becomes a sub-processor.

Important: responsibility doesn't stop at the controller. According to the UODO's announcement on fines for McDonald's Polska, the President of UODO imposed fines totaling 16 932 657 PLN on the controller (McDonald's Polska) and, separately, a total of 183,858 PLN on the processor — 24/7 Communication. Both the controller and the processor are responsible for personal data protection — handing telephony off to a vendor doesn't close the subject.

The processing agreement: what GDPR requires before you sign

Before you sign anything with an AI receptionist vendor, you need a written data processing agreement — and a check on whether the vendor even provides guarantees of adequate technical and organizational measures. This isn't a formality to skip: according to a UODO decision from 21 September 2022, a cultural institution was fined 2.5 thousand PLN for entrusting data processing (bookkeeping, records, reports) without a written processing agreement and without verifying the vendor beforehand.

Before you sign with an AI receptionist vendor, it's worth asking directly:

Question for the vendorWhy it matters
Where are the servers with recordings and transcripts physically located?Affects which rules and safeguards apply
Which sub-processors does it use, e.g. which language model?Every extra party in the chain is another responsibility to settle
What's the default retention period for the recording and the transcript?Without this you can't set your own retention policy
How does deletion on request and export when switching vendors work?Without this it's hard to meet a customer's request or change vendors
Who at the vendor has access to recordings, and how is that limited?Determines how many people can even hear a customer's call
What's the procedure in a security incident?You need to know when and how you'll be informed
Closed steel lockbox on a desk with a brass key beside it
Access to recordings and transcripts is limited by the processing agreement, not a default setting

Do you even need to keep the raw audio at all

The data minimization principle applies here too: often a transcript, or even just a summary, is enough to handle the inquiry going forward, and the raw audio isn't needed anymore once the transcript exists and has been checked. How long to actually keep each artifact is your company's decision — best made together with a lawyer or data protection officer, not something you can read off a general rule.

ArtifactWhy keep itWho decides the retention period
AudioVerifying a disputed call, evidence in a complaintYour company with a lawyer/DPO
TranscriptDay-to-day handling of the inquiry, searchYour company
SummaryQuick review without listening to the whole callYour company

Special category data the caller volunteers

Sometimes a caller mentions something on their own, unprompted, that's special category data — health status, for example. The AI receptionist's script shouldn't probe for this or write it into a summary field as a permanent fact about the customer. The industry-specific nuances of this for medical practices go beyond this page — the point here is simply the rule: don't extend the call script with questions you don't need to ask.

Reel of audio tape on a dark wooden surface
Not every artifact of a call needs to be kept as long as the recording itself

Retention at the model provider: OpenAI as an example

Even if your AI receptionist vendor deletes the recording and transcript according to an agreed policy, the language model provider behind the speech recognition may keep its own logs. According to OpenAI's documentation on customer data, abuse monitoring logs are generated by default for all API usage and retained for up to 30 days, unless longer retention is required by law or reasonably necessary to protect the services. Eligible API customers can have their content excluded from these logs through Zero Data Retention or Modified Abuse Monitoring — but only after prior approval by OpenAI.

This describes one specific model provider's feature, not a general market rule — so the question to your own AI receptionist vendor should be direct: which language model does it use, and what retention settings does that model provider have.

What to tell the caller at the start of the call

The caller has a right to know they're talking to a system that records and processes their voice. In practice, a short notice at the start of the call plus the full text available via a link works well — in a confirmation SMS or on the company website.

One specific element is mandatory and often skipped: information about the right to lodge a complaint with the supervisory authority. According to UODO's clarification from 25 April 2025, the information provided when collecting data must include the right to lodge a complaint with a supervisory authority (Article 13(2)(d) and Article 14(2)(e) GDPR) — but these provisions don't require stating the UODO's own address in that notice. So one sentence without an address is formally enough, though a link to the full privacy notice should still be easy to find.

A customer asks for a copy of their data from a recording

A customer has the right to request a copy of their personal data, and a voice recording is exactly that kind of data. A decision by the President of UODO, DS.523.4826.2020, ordered a company that had previously refused to provide the complainant — under Article 15(3) GDPR — with a copy of her personal data recorded in the calls with a consultant, including her voice.

This has a concrete technical consequence: the system needs to be able to find a recording by phone number and date within a reasonable time, not after days of searching through an archive. If you're rolling out an AI receptionist, it's worth checking upfront whether such a search function even exists in the vendor's panel.

Recording voice — even outside a telephony context — always requires a legal basis. According to a UODO decision from 23 June 2022, a facility that recorded sound through a monitoring system without a legal basis was fined 10 thousand PLN.

This isn't a verdict on your phone line

This particular case involved video monitoring with sound, not telephony or an AI receptionist — it's used here as an example of the general rule that recording voice requires a legal basis, not as evidence that recording phone calls is automatically a problem. Telephony with a clearly stated purpose (handling an inquiry) and notice to the caller stands on different ground than a hidden microphone in a monitoring system.

Do it yourself: what to check this week

  1. Export one of your own recordings and its transcript — check where they actually live and who has access according to the vendor's panel.
  2. Ask your vendor directly when the recording and transcript get deleted — compare the answer with what your privacy notice on the website actually says.
  3. Check whether you can find a specific recording by phone number and date within minutes, not hours.
  4. Verify you have a signed written processing agreement with every vendor that touches recordings or transcripts.

What it looks like when a system handles the call data

The call reaches the system: a short disclosure at the start → transcript and summary land in the CRM → audio is kept or deleted according to a rule your company sets → a recording can be found by phone number and date on a customer's request. Without promising "full GDPR compliance" — that's always shared responsibility between the controller and what's settled with the vendor, not something a configuration setting handles by itself.

AI reception and telephony answers calls and records everything in CRM with a summary and a recording of the conversation — what happens to that data afterward depends on the arrangements described above. CRM and automations brings inquiries from every channel into one place, and Customer Data merges records of the same person into one card instead of five scattered lists. If you already have several systems that need to exchange customer data without manual re-entry, that's the scope of Integrations. A confirmation after the call can go out on its own through Automatic messages, always with the customer's consent and an opt-out.

Before you decide to roll this out, it's also worth reading Errors when implementing automation: five situations where we advise against starting and Automation and GDPR: where your customer data physically ends up — they give a broader picture of where automation data ends up beyond just the AI receptionist. How an AI receptionist differs from a plain chatbot is covered in AI agent vs chatbot: the difference visible in three process characteristics, and how much missed calls actually cost before you even consider an AI receptionist can be worked out in How much do missed calls cost in a company – a formula to calculate with your own numbers.

Frequently asked questions

Is a voice recording from a call with an AI receptionist personal data?

Yes. A voice that can identify a person is personal data — this is confirmed by a UODO decision ordering the disclosure of a copy of a phone call recording under Article 15(3) GDPR, including the complainant's voice.

Who's liable if data from a call leaks — me or the AI receptionist vendor?

Both can be liable at the same time. In the McDonald's Polska case, the President of UODO imposed separate fines on the controller and on the processor — both the controller and the processor are responsible for data protection.

Do I need a written contract with an AI receptionist vendor?

Yes, a written data processing agreement is required, along with prior verification that the vendor provides guarantees of adequate technical and organizational measures. The absence of such an agreement was the reason for a 2.5 thousand PLN fine against one institution.

Do I have to state the UODO's address in the notice to callers?

No. Information about the right to lodge a complaint with a supervisory authority is required, but the regulations don't require stating the UODO's own address in that notice.

A customer asks for a copy of the recording of their call — do I have to provide it?

Yes, as a rule a customer has the right to a copy of their personal data, and a recording of their voice is exactly that — this is exactly what a UODO decision ordered in a case involving a refusal to disclose a recording of a call with a consultant.

Can I keep call recordings indefinitely, "just in case"?

How long to keep each artifact is your company's decision, made with a lawyer or data protection officer based on the data minimization principle — keeping something indefinitely "just in case" isn't the same as a set and justified retention period.

Who writes this

See your business as a system.

Aura is a virtual business manager: management on facts, not impressions. For a company that wants a system running its processes instead of the owner’s memory.

The website, CRM, admin panel and automations are modules of the same system. We are not a website agency.

Look at my business

You will land on the home page. Give a company name — Aura looks at it in public data and shows what a client sees before calling you. No promises of a result.

See what we do

Related services

Read next Scroll for more

Let us look at your numbers

Tell us how enquiries are handled today — how many there are, who picks them up, where they get lost. Aura walks the process with you and shows what can be taken off a person, and what is better left alone.

Talk to Aura

The home page with Aura opens. Give a company name — she looks at it in public data and shows what a client sees. No promises of a result.

Prefer to write? marketing@auraglobal-merchants.com

Next step

Let us check whether Aura fits your place

We do not take everyone: first we look at your processes, sales and current systems and tell you honestly whether it makes sense for us to come in. A few questions, about five minutes.

Take the assessment →