Privacy Policy

Last updated: 2026-07-10

This Privacy Policy explains how Totem Studio ("we", "us", "our") collects, uses, discloses, and protects personal data when you visit our websites, use our services (including TotemAI voice agents, automations, dashboards, and related integrations), or otherwise interact with us. It also describes your privacy rights and how to exercise them. By using our Services, you acknowledge this Privacy Policy.

Liability for Content

We have made every effort to ensure the accuracy and completeness of the content on our pages. However, we cannot guarantee the correctness, completeness, or current relevance of the content. As a service provider, our responsibility for our own content on these pages is in accordance with general laws. As a service provider, we are not required to monitor third-party information that is transmitted or stored, nor are we required to investigate circumstances that suggest illegal activities. The responsibility to remove or block the use of information under general laws remains intact. Liability in this regard can only be assumed from the moment we become aware of a specific legal violation. Upon becoming aware of such violations, we will promptly remove the offending content.

Liability for Links

Our website contains links to external websites owned by third parties, and we have no control over the content of these sites. Consequently, we cannot be held responsible for the content of these third-party sites. The individual provider or operator of the linked pages is responsible for their content. At the time of linking, the linked pages were examined for potential legal violations, and no unlawful content was identified. Continuously monitoring the content of linked pages without concrete evidence of legal violations is unreasonable. If we become aware of any legal violations, we will remove the associated links immediately.

Copyright

The content and works on our website are subject to European and international copyright law. The reproduction, modification, distribution, and any form of exploitation beyond the scope of copyright law require written consent from the respective author or creator. Downloads and copies of this website are permitted for private, non-commercial use only. In cases where the content on this site was not created by the operator, third-party copyrights have been respected. Specifically, third-party content is identified as such. If you become aware of a copyright infringement, please notify us accordingly. Upon becoming aware of legal violations, we will immediately remove the offending content.

Company Information

  • Registration: Totem Studio International Technologies S.L. — ESB45528395 — Ronda Buenavista 24, 9 4-C, 45005 Toledo, Spain
  • Contact: +34 900 433 533 · hello@totemstudio.ai · totemstudio.ai
  • Data Protection Officer: hello@totemstudio.ai

Interpretation and Definitions

Interpretation

Capitalized terms have the meanings set out below. The definitions apply whether terms appear in singular or plural.

Definitions

For the purposes of this Privacy Policy:

  • Personal Data: Any information related to an identified or identifiable natural person.
  • Data Subject: The individual to whom personal data relates.
  • Processing: Any operation performed on personal data, whether automated or not, including collection, storage, use, disclosure, and deletion.
  • Controller: The entity that determines the purposes and means of processing personal data.
  • Processor: The entity that processes personal data on behalf of the controller.
  • Consent: Any freely given, specific, informed, and unambiguous indication of the data subject's wishes.
  • Services: Our websites, apps, dashboards, TotemAI voice agents, automations (including n8n workflows), and related consulting and support.

Roles: Controller vs. Processor

We act as a Controller for personal data we collect about website visitors, leads, suppliers, and our own users. For TotemAI deployments provided to our business customers, we act as a Processor, processing personal data of end callers/contacts on behalf of our customers (who act as Controllers). Where applicable, we enter into Data Processing Agreements (DPAs) with our customers and appoint vetted sub-processors to support the Services.

Google API Services User Data

This section explains exactly what Google user data Totem Studio accesses when a user voluntarily connects a Google account. We request access incrementally and only for the capabilities the user selects.

Google data and permissions accessed

  • Google account identity (openid, email, profile) — We access the connected account's email address and basic profile information, such as display name, to identify the account inside Totem Studio. We do not use these identity permissions to read contacts.
  • Google Calendar (https://www.googleapis.com/auth/calendar) — We access calendar-list properties and event data, including calendar names, identifiers, colors, time zones, event titles, descriptions, locations, dates and times, recurrence, organizers, attendees, attendee email addresses, responses, reminders, availability, and conferencing details. At the user's request, Totem Studio can display availability and events; create, update, move, or delete events and secondary calendars; manage calendar display settings; add attendees; create Google Meet links; and subscribe to change notifications so the Totem calendar stays synchronized.
  • Gmail send-only (https://www.googleapis.com/auth/gmail.send) — We access only the content, recipients, subject, and attachments that an authorized user chooses to send from Totem Studio, and we send that message on the user's behalf. Totem Studio does not request permission to read the user's Gmail inbox, messages, labels, or settings.
  • Google Meet (https://www.googleapis.com/auth/meetings.space.settings, https://www.googleapis.com/auth/meetings.space.readonly) — When a user enables meeting intelligence, we may configure recording, transcription, or smart-note settings for meetings created through Totem Studio and access meeting-space and conference metadata, participants and display names, transcript text and speaker turns, and links to recordings, transcripts, and smart notes. We use this data only to attach the requested meeting artifacts to the relevant booking, lead, or customer record and to provide related user-facing features.

Totem Studio does not request access to Google Drive.

How we use Google user data

We use Google user data only to provide and improve the user-facing features the user or our customer requested: connecting and identifying the selected Google account; displaying and synchronizing calendars; checking availability; managing calendars, events, bookings, attendees, and conferencing; sending user-composed email; and providing enabled meeting-artifact, CRM, scheduling, reminder, automation, and support features. Totem Studio does not use Google user data for advertising, ad targeting, credit decisions, surveillance, or unrelated purposes.

Storage and security

We store the connected account identifier, enabled capabilities, calendar configuration, encrypted OAuth access and refresh tokens, and service records needed to provide the selected features. Calendar and meeting data is retrieved when needed; data needed for bookings, CRM records, meeting artifacts, synchronization, audit, security, or support may be stored in Totem Studio. OAuth tokens are encrypted at rest, data is encrypted in transit, and access is restricted by authentication, role-based authorization, tenant isolation, logging, and operational controls.

Sharing and transfer

We do not sell Google user data. We do not share or transfer it for advertising, data-broker, credit, or other unrelated purposes. We disclose it only to the user and authorized members of the user's Totem Studio organization; to vetted processors acting under contractual confidentiality and data-protection obligations when necessary to provide or secure the selected features; when the user gives specific consent; or when required for security or by law. Processors may not use Google user data for their own purposes.

Artificial intelligence and machine learning

Raw, aggregated, anonymized, or derived Google Workspace API data is not used, transferred, or sold to create, train, or improve generalized, foundation, or other non-personalized artificial intelligence or machine-learning models. Where an enabled Totem Studio feature uses artificial intelligence, Google user data is processed only to deliver that specific user-facing feature for the requesting user or customer, such as a meeting summary, scheduling workflow, or CRM action, and not to train a generalized model.

Retention, disconnection, and deletion

We retain Google OAuth credentials only while the account remains connected and retain Google user data only for as long as necessary to provide the selected features or meet documented legal, security, and contractual obligations. A user can disconnect the Google account in Totem Studio or revoke access in the Google Account permissions page; disconnection revokes access where supported and deletes the stored connected-account credentials. Users may also request deletion of associated data as described in our Data Deletion Instructions.

Google API Services Limited Use compliance

Totem Studio's access, use, storage, disclosure, and transfer of data received from Google APIs complies with the Google API Services User Data Policy and its Limited Use requirements.

The use and transfer of raw or derived user data received from Google Workspace APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Categories of Personal Data We Process

Website & Analytics

Device and usage data (IP address, timestamps, pages viewed, referrer, approximate location, device/OS/browser), event metrics, cookies/SDK identifiers.

TotemAI Voice & Messaging Interactions

Call metadata (caller ID, timestamps, duration, disposition), call audio recordings and transcripts if enabled, conversation summaries, action outcomes (e.g., booking made, reminder sent), contact details provided during a conversation (name, phone, email), and context needed to perform tasks (e.g., appointment preferences, service interest).

Communications

Emails, SMS, WhatsApp or other messages exchanged with us or via the Services (including delivery metadata).

Customer Account & Billing

Admin and user profiles, authentication identifiers, roles/permissions, subscription and billing details, invoices and payment status (payment card data is handled by our processors).

Integrations & Automations

Data exchanged with customer systems (e.g., CRM, calendar), telephony providers, and workflow automations (n8n) necessary to deliver the Service.

Special Categories

We do not seek to process special category data. If such data is disclosed by a caller during a conversation, we process it only as necessary to provide the Service, and customers (as Controllers) are responsible for the lawful basis and caller notices.

Collection and Deletion of Data

Collection of General Data and Information

We collect general technical data whenever you access our websites or dashboards, which may be logged by servers and analytics SDKs:

  • Browser type and version
  • Operating system
  • Referrer URL
  • Pages accessed
  • Date and time of access
  • IP address
  • Internet service provider
  • Other similar data used to ensure security and integrity

This data is used for:

  • Delivering and optimizing content
  • Ensuring performance and availability
  • Detecting and preventing abuse and fraud
  • Aggregated statistics to improve the Service

Technical logs are stored separately from customer account records where feasible.

Routine Deletion and Blocking of Personal Data

We retain personal data only for as long as necessary for the purposes set out in this Policy or as required by law and contracts. After expiry of retention periods, data is deleted or anonymized. See the 'Data Retention' section for category-specific periods.

Purposes and Legal Bases (GDPR)

Provide and operate TotemAI voice agents, dashboards, integrations, and support (including call handling, transcripts, reminders, and automations).

  • Art. 6(1)(b) GDPR – Contract
  • Art. 6(1)(f) GDPR – Legitimate interests (service operation and improvement)

Where we act as Processor, the customer defines the legal basis; we process under the DPA.

Call recording and transcription (configurable; OFF by default unless enabled by the customer).

  • Art. 6(1)(a) GDPR – Consent
  • Art. 6(1)(f) GDPR – Legitimate interests (quality assurance, dispute resolution) where permitted

Controllers are responsible for providing appropriate caller notices and obtaining consent where required by law.

Analytics and product improvement (web, dashboard, and agent performance).

  • Art. 6(1)(a) GDPR – Consent (cookies/SDKs where required)
  • Art. 6(1)(f) GDPR – Legitimate interests (aggregate analytics)

Security, fraud prevention, and abuse detection.

  • Art. 6(1)(f) GDPR – Legitimate interests
  • Art. 6(1)(c) GDPR – Legal obligation (where applicable)

Customer communications, onboarding, billing, and account administration.

  • Art. 6(1)(b) GDPR – Contract
  • Art. 6(1)(c) GDPR – Legal obligation
  • Art. 6(1)(f) GDPR – Legitimate interests

Marketing communications to prospects and customers.

  • Art. 6(1)(a) GDPR – Consent (where required)
  • Art. 6(1)(f) GDPR – Legitimate interests with opt-out

Sharing and Sub-Processors

We share personal data with service providers who act as Processors/Sub-processors to deliver the Service, subject to data protection agreements and appropriate safeguards. Key providers include:

  • Firebase (Google) — Analytics, database, hosting, authentication · Device and usage data, app events, crash logs, account metadata · EU and/or US (subject to configuration and Google's infrastructure) · Standard Contractual Clauses (SCCs)
  • Retell AI — Voice agent platform (telephony orchestration, transcripts, dashboards) · Call metadata, audio (if enabled), transcripts, summaries · EU-preferred storage; may involve processing in other regions depending on configuration and providers · SCCs; data-storage settings and PII redaction available
  • LLM Providers via Retell (e.g., OpenAI, Google/Vertex/Gemini) — ASR/NLU/LLM inference and summarization · Conversation snippets and prompts required for inference (subject to provider terms) · EU/US (provider-dependent) · SCCs
  • n8n — Workflow automations and integrations · Data necessary to trigger actions (e.g., CRM updates, emails, calendars) · EU (self-hosted or cloud in the EU) · SCCs (if applicable)
  • Messaging/Telephony Providers (WhatsApp Business API, Twilio, Zadarma) — Phone calls, SMS, WhatsApp · Caller/callee numbers, message content where applicable, delivery metadata · EU-preferred routing; may involve processing outside the EU depending on carrier networks · SCCs (if applicable)

We may disclose data where required by law, to protect rights and safety, or in connection with a corporate transaction. We do not sell personal data.

International Data Transfers

We aim to store data in the EU. Where personal data is transferred outside the EEA/UK to countries without an adequacy decision (e.g., when using global providers), we rely on safeguards such as Standard Contractual Clauses (SCCs) and implement supplementary measures where necessary.

Cookies and SDKs

We use cookies and SDKs to operate our websites and dashboards, remember preferences, perform analytics, and secure the Service. Where required, we obtain your consent via a consent banner. You can manage your preferences at any time.

  • Strictly necessary (authentication, security, load balancing)
  • Functional (preferences)
  • Analytics (usage measurement and performance)

Security

We implement technical and organizational measures appropriate to the risk, including access controls, encryption in transit, role-based permissions, logging and monitoring, and vendor due diligence. No method of transmission or storage is 100% secure; we continually improve our safeguards.

Call Recording, Transcription, and Notices

If call recording and/or transcription is enabled, recordings and transcripts are processed to provide the Service (quality, training, analytics, and hand-offs). Our business customers (Controllers) are responsible for providing legally required notices and obtaining consent where applicable. We provide configuration options and guidance to help customers meet their obligations.

Data Retention

We apply category-specific retention schedules and, for TotemAI data, mirror Retell AI’s configurable Data Storage Settings. Customers can choose to store everything, store everything except PII, or store only basic attributes/metadata. If a customer disables storage, we retain only what is strictly necessary for security and operations.

  • Website analytics and logs: Configured retention (e.g., 14 months) or shorter where required
  • Account, billing, and contract records: Contract term + statutory periods (e.g., up to 6 years for accounting)
  • Call audio recordings (if enabled): As configured by the customer in Retell/TotemAI; EU-storage preferred
  • Transcripts and summaries: As configured by the customer in Retell/TotemAI; EU-storage preferred
  • Operational logs (telephony/messaging metadata): As needed for operations, troubleshooting, and fraud prevention, then deleted or anonymized

Children’s Data

Our Services are not directed to children under 16, and we do not knowingly collect their personal data. If you believe a child provided personal data, please contact us to request deletion.

Legal or Contractual Obligations

Providing certain personal data may be required by law or necessary to perform a contract.

If you do not provide required data, we may be unable to deliver the requested Services.

Automated Decision-Making

TotemAI agents use automation to route calls, collect details, and perform tasks. We do not make decisions that produce legal effects concerning you or similarly significantly affect you without human oversight.

Your Rights (GDPR/UK GDPR)

Right of Access

You may request confirmation and a copy of your personal data.

Right to Rectification

You may request correction of inaccurate or incomplete data.

Right to Erasure

You may request deletion in the circumstances set out by law.

Right to Restrict Processing

You may request restriction under certain conditions (e.g., accuracy contested, processing unlawful).

Right to Data Portability

You may request export in a machine-readable format where processing is based on consent or contract and carried out by automated means.

Right to Object

You may object to processing based on legitimate interests or for direct marketing; we will honor your request unless we have compelling legitimate grounds.

Right to Withdraw Consent

Where processing is based on consent, you may withdraw it at any time without affecting prior lawful processing.

Supervisory Authority

You have the right to lodge a complaint with your local supervisory authority. Our lead authority is the Agencia Española de Protección de Datos (AEPD).

To exercise your rights, contact us at hola@totemstudio.ai. If your data was processed as part of a TotemAI deployment for one of our customers, please contact that customer directly (the Controller); we will assist them in fulfilling your request as required by our DPA.

Data Breach Notification

In the event of a personal data breach likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority without undue delay and, where required, affected individuals.

Google Ads / Advertising

We may use Google Ads and related advertising technologies to measure campaign performance and reach relevant audiences.

Where required, we obtain your consent before setting advertising cookies/identifiers. You can manage preferences via our consent banner and your browser settings.

Refer to Google's privacy documentation for details on data usage and controls.

Analytics

With your consent (where required), we use analytics tools (including Firebase/Google Analytics) to understand usage and improve the Service.

Scope of Processing

Analytics tools may collect event data, device/OS/browser information, approximate location, and identifiers. We enable IP masking where supported.

Purposes of Processing

Evaluate usage, generate reports, enhance product performance and reliability.

Recipient

Google entities operating Firebase/Analytics. We have appropriate data processing terms in place.

Transfer to Third Countries

Data may be processed in the United States or other countries with safeguards such as SCCs.

Duration of Storage

Configured retention (e.g., around 14 months) unless a different period is set.

Your Choices

You can withdraw consent via our banner or device settings and use available opt-out tools provided by Google.

Legal Basis of Processing

We rely on the following legal bases under GDPR:

  • Art. 6(1)(a) GDPR: When you provide explicit consent for specific processing activities.
  • Art. 6(1)(b) GDPR: Necessary processing to fulfill a contract with you.
  • Art. 6(1)(c) GDPR: Processing required to comply with legal obligations.
  • Art. 6(1)(f) GDPR: Processing based on our legitimate interests, provided they do not override your rights and freedoms.

Legitimate Interests in the Processing

Our legitimate interests include operating and improving the Service, ensuring security, preventing fraud, supporting customer requests, and measuring performance.

Changes to This Privacy Policy

We may update this Privacy Policy from time to time. Material changes will be posted on this page and, where appropriate, notified via email or the dashboard. The 'Last Updated' date will reflect the latest revision.

Contact Us

For questions about this Privacy Policy or our data practices, contact:

  • hello@totemstudio.ai
  • Ronda de Buenavista 24, portal 9, 4C
  • +34 900 433 533
Ready to activate your agent?

Launch your TotemAI pilot

Book a 20-minute call. Within 24 hours we’ll map your flows, analyze your tools, and scope a tailored pilot.

Arrow Book a demo

Made with by Totem Studio