You're rolling out an AI receptionist or a phone system with transcription, and you want to know exactly what's left after one call, who's responsible for it, and what to settle with the vendor before anyone actually calls. Short answer: a call usually leaves behind an audio recording, a transcript, a summary and CRM fields, and each of these has a specific party responsible for it — you as the data controller and the vendor as the processor, sometimes both liable at once, as real GDPR enforcement decisions show.
This page covers exactly what's left after a call and where it lives, what a data processing agreement needs before you sign it, whether you need to keep the raw audio at all, how retention works at the language model provider using OpenAI as an example, what to tell the caller, and what to do when a customer asks for a copy of their data from a recording.

What's left after one call with an AI receptionist
A single call with an AI receptionist usually leaves more traces than it first appears: the audio recording itself, a text transcript, a call summary, specific fields saved in the CRM (name, phone number, reason for contact), and technical logs on the side of both the AI receptionist vendor and the language model provider that processes the speech.
The data's path looks like this:
- 01phone call
- →02AI receptionist vendor
- →03language model provider
- →04transcript and summary
- →05CRM
- →06deletion after a set period
| Artifact | Where it lives | Who has access | Who decides the retention period |
|---|---|---|---|
| Audio recording | Vendor's servers (sometimes passed on to the model provider) | Vendor's team under the processing agreement, your company on request | Your company, written into the vendor contract |
| Transcript | CRM or vendor panel | People with CRM access | Your company |
| Call summary | CRM | Staff handling the inquiry | Your company |
| Model provider's technical logs | Model provider's infrastructure (e.g. abuse monitoring logs) | Model provider, usually without your company's access | Model provider, under its own policy |
Technical logs at the model provider
The last row is easy to miss: the model provider behind the AI receptionist's speech recognition keeps its own logs, independently of whatever your direct vendor does with the recording. This is worked through with OpenAI as an example further down.
Who's responsible: the controller and the processor
In this setup, your company is the data controller — you decide why the caller leaves their data and how long to keep it. The AI receptionist vendor is the processor: it processes data on your behalf, on your instructions. If the vendor relies on another company's language model, that company becomes a sub-processor.
Important: responsibility doesn't stop at the controller. According to the UODO's announcement on fines for McDonald's Polska, the President of UODO imposed fines totaling 16 932 657 PLN on the controller (McDonald's Polska) and, separately, a total of 183,858 PLN on the processor — 24/7 Communication. Both the controller and the processor are responsible for personal data protection — handing telephony off to a vendor doesn't close the subject.
The processing agreement: what GDPR requires before you sign
Before you sign anything with an AI receptionist vendor, you need a written data processing agreement — and a check on whether the vendor even provides guarantees of adequate technical and organizational measures. This isn't a formality to skip: according to a UODO decision from 21 September 2022, a cultural institution was fined 2.5 thousand PLN for entrusting data processing (bookkeeping, records, reports) without a written processing agreement and without verifying the vendor beforehand.
Before you sign with an AI receptionist vendor, it's worth asking directly:
| Question for the vendor | Why it matters |
|---|---|
| Where are the servers with recordings and transcripts physically located? | Affects which rules and safeguards apply |
| Which sub-processors does it use, e.g. which language model? | Every extra party in the chain is another responsibility to settle |
| What's the default retention period for the recording and the transcript? | Without this you can't set your own retention policy |
| How does deletion on request and export when switching vendors work? | Without this it's hard to meet a customer's request or change vendors |
| Who at the vendor has access to recordings, and how is that limited? | Determines how many people can even hear a customer's call |
| What's the procedure in a security incident? | You need to know when and how you'll be informed |

Do you even need to keep the raw audio at all
The data minimization principle applies here too: often a transcript, or even just a summary, is enough to handle the inquiry going forward, and the raw audio isn't needed anymore once the transcript exists and has been checked. How long to actually keep each artifact is your company's decision — best made together with a lawyer or data protection officer, not something you can read off a general rule.
| Artifact | Why keep it | Who decides the retention period |
|---|---|---|
| Audio | Verifying a disputed call, evidence in a complaint | Your company with a lawyer/DPO |
| Transcript | Day-to-day handling of the inquiry, search | Your company |
| Summary | Quick review without listening to the whole call | Your company |
Special category data the caller volunteers
Sometimes a caller mentions something on their own, unprompted, that's special category data — health status, for example. The AI receptionist's script shouldn't probe for this or write it into a summary field as a permanent fact about the customer. The industry-specific nuances of this for medical practices go beyond this page — the point here is simply the rule: don't extend the call script with questions you don't need to ask.

Retention at the model provider: OpenAI as an example
Even if your AI receptionist vendor deletes the recording and transcript according to an agreed policy, the language model provider behind the speech recognition may keep its own logs. According to OpenAI's documentation on customer data, abuse monitoring logs are generated by default for all API usage and retained for up to 30 days, unless longer retention is required by law or reasonably necessary to protect the services. Eligible API customers can have their content excluded from these logs through Zero Data Retention or Modified Abuse Monitoring — but only after prior approval by OpenAI.
This describes one specific model provider's feature, not a general market rule — so the question to your own AI receptionist vendor should be direct: which language model does it use, and what retention settings does that model provider have.
What to tell the caller at the start of the call
The caller has a right to know they're talking to a system that records and processes their voice. In practice, a short notice at the start of the call plus the full text available via a link works well — in a confirmation SMS or on the company website.
One specific element is mandatory and often skipped: information about the right to lodge a complaint with the supervisory authority. According to UODO's clarification from 25 April 2025, the information provided when collecting data must include the right to lodge a complaint with a supervisory authority (Article 13(2)(d) and Article 14(2)(e) GDPR) — but these provisions don't require stating the UODO's own address in that notice. So one sentence without an address is formally enough, though a link to the full privacy notice should still be easy to find.
A customer asks for a copy of their data from a recording
A customer has the right to request a copy of their personal data, and a voice recording is exactly that kind of data. A decision by the President of UODO, DS.523.4826.2020, ordered a company that had previously refused to provide the complainant — under Article 15(3) GDPR — with a copy of her personal data recorded in the calls with a consultant, including her voice.
This has a concrete technical consequence: the system needs to be able to find a recording by phone number and date within a reasonable time, not after days of searching through an archive. If you're rolling out an AI receptionist, it's worth checking upfront whether such a search function even exists in the vendor's panel.
Recording voice without a legal basis: what a monitoring case teaches
Recording voice — even outside a telephony context — always requires a legal basis. According to a UODO decision from 23 June 2022, a facility that recorded sound through a monitoring system without a legal basis was fined 10 thousand PLN.
This isn't a verdict on your phone line
This particular case involved video monitoring with sound, not telephony or an AI receptionist — it's used here as an example of the general rule that recording voice requires a legal basis, not as evidence that recording phone calls is automatically a problem. Telephony with a clearly stated purpose (handling an inquiry) and notice to the caller stands on different ground than a hidden microphone in a monitoring system.
Do it yourself: what to check this week
- Export one of your own recordings and its transcript — check where they actually live and who has access according to the vendor's panel.
- Ask your vendor directly when the recording and transcript get deleted — compare the answer with what your privacy notice on the website actually says.
- Check whether you can find a specific recording by phone number and date within minutes, not hours.
- Verify you have a signed written processing agreement with every vendor that touches recordings or transcripts.
What it looks like when a system handles the call data
The call reaches the system: a short disclosure at the start → transcript and summary land in the CRM → audio is kept or deleted according to a rule your company sets → a recording can be found by phone number and date on a customer's request. Without promising "full GDPR compliance" — that's always shared responsibility between the controller and what's settled with the vendor, not something a configuration setting handles by itself.
AI reception and telephony answers calls and records everything in CRM with a summary and a recording of the conversation — what happens to that data afterward depends on the arrangements described above. CRM and automations brings inquiries from every channel into one place, and Customer Data merges records of the same person into one card instead of five scattered lists. If you already have several systems that need to exchange customer data without manual re-entry, that's the scope of Integrations. A confirmation after the call can go out on its own through Automatic messages, always with the customer's consent and an opt-out.
Before you decide to roll this out, it's also worth reading Errors when implementing automation: five situations where we advise against starting and Automation and GDPR: where your customer data physically ends up — they give a broader picture of where automation data ends up beyond just the AI receptionist. How an AI receptionist differs from a plain chatbot is covered in AI agent vs chatbot: the difference visible in three process characteristics, and how much missed calls actually cost before you even consider an AI receptionist can be worked out in How much do missed calls cost in a company – a formula to calculate with your own numbers.
Frequently asked questions
Is a voice recording from a call with an AI receptionist personal data?
Yes. A voice that can identify a person is personal data — this is confirmed by a UODO decision ordering the disclosure of a copy of a phone call recording under Article 15(3) GDPR, including the complainant's voice.
Who's liable if data from a call leaks — me or the AI receptionist vendor?
Both can be liable at the same time. In the McDonald's Polska case, the President of UODO imposed separate fines on the controller and on the processor — both the controller and the processor are responsible for data protection.
Do I need a written contract with an AI receptionist vendor?
Yes, a written data processing agreement is required, along with prior verification that the vendor provides guarantees of adequate technical and organizational measures. The absence of such an agreement was the reason for a 2.5 thousand PLN fine against one institution.
Do I have to state the UODO's address in the notice to callers?
No. Information about the right to lodge a complaint with a supervisory authority is required, but the regulations don't require stating the UODO's own address in that notice.
A customer asks for a copy of the recording of their call — do I have to provide it?
Yes, as a rule a customer has the right to a copy of their personal data, and a recording of their voice is exactly that — this is exactly what a UODO decision ordered in a case involving a refusal to disclose a recording of a call with a consultant.
Can I keep call recordings indefinitely, "just in case"?
How long to keep each artifact is your company's decision, made with a lawyer or data protection officer based on the data minimization principle — keeping something indefinitely "just in case" isn't the same as a set and justified retention period.