CallHippo on GDPR

CH ST
Written by admin · Updated 3 Jul, 2026

The General Data Protection Regulation (GDPR) introduced far-reaching changes to data protection law across the EU. This page explains how CallHippo approaches GDPR compliance, how we handle personal data, and the rights you have as a data subject.

Introduction

GDPR defines “personal data” as any information relating to an identified or identifiable natural person (a data subject). An identifiable person is one who can be identified, directly or indirectly, by reference to an identifier such as a name, an identification number, location data, an online identifier, or one or more factors specific to their physical, physiological, genetic, mental, economic, cultural, or social identity. Every organization that processes personal data is required to be GDPR compliant.

Company profile

CallHippo is a virtual telephony system provider. We understand that your privacy matters and that you care about how your information is used and shared online. We respect and value the privacy of everyone who visits our site, and we only collect and use information in ways that are useful to you and consistent with your rights and our obligations under the law.

CallHippo has taken the necessary measures to ensure GDPR compliance to the best of its ability. You can reach us by email at [email protected] or by telephone on +1-740-848-2535.

Personal and sensitive data

We ensure your personal data is processed lawfully, fairly, and transparently, without adversely affecting your rights. For more information, please refer to our privacy policy.

Staff awareness and training: We follow privacy by design so that privacy is embedded into every new process or product we deploy. We have a process in place for structured assessment and systematic validation, and we run annual GDPR training for all employees, including management.

Lawful data processing: All personal data is stored securely in accordance with the EU General Data Protection Regulation (Regulation (EU) 2016/679).

Consent

We obtain informed consent under GDPR to ensure your personal data is processed lawfully, fairly, and transparently. We only process your personal data where at least one of the lawful bases described in our Privacy Policy applies.

Internal policies and procedures

We review and update our policies and contracts to ensure they remain GDPR compliant, including our privacy policies and notices, data protection policies, data security, employee data policies, data sharing policies, IT security policies, and data retention policies.

Third-party processing

We have contacted the third-party processors who work with us and have received a Data Processing Agreement (DPA), or an update on the steps they are taking to become GDPR compliant. We continue to work with our processors to secure DPAs. If you have questions about DPAs or our list of third-party processors, please contact us at [email protected].

Data storage

Some or all of your data may be stored or transferred outside the European Economic Area (EEA), which consists of all EU member states plus Norway, Iceland, and Liechtenstein. Whenever we store or transfer data outside the EEA, we take all necessary steps to ensure it is treated as safely and securely as it would be within the EEA and under GDPR. These steps include, but are not limited to, legally binding contractual terms with any third parties we engage, as well as the use of EU-approved Model Contractual Arrangements.

Data retention

We only keep your data for as long as we need it for the purposes described in our privacy policy, and/or for as long as we have your permission to keep it. We conduct an annual review to determine whether we still need to retain your data. Data that is no longer needed is deleted in line with our Data Retention Policy.

Your rights as a data subject

Data subject access rights: You have the legal right to request access to any of your personal data held by us. Within our products, we give customers the ability to access, modify, and delete data in line with GDPR guidelines.

Data subject requests: You can contact us via chat, email at [email protected], or phone on +1-740-848-2535. We respond to all requests within 2 working days.

Right to data portability: We let customers export their data in formats such as XLS and CSV. If you need data that is not currently available for export, please contact us.

Right to erasure: If you discontinue our services, your data may be stored for up to 6 months with us or our third-party vendor, kept confidential and not shared, in case you want to revive the service or for analysis purposes. Finance-related data required for accounting and auditing will not be deleted. We ensure that identifiers of the individual are erased.

Right to rectification: You have full rights to rectify your personal data at any point, unless doing so interferes with a technical constraint. For other rectification requests, contact us.

Right to object: You may object to the processing of your personal data based on legitimate interests (including profiling), direct marketing (including profiling), and processing for scientific or historical research and statistical purposes.

Still need help? Reach us at [email protected].

Still need a hand?

Can't find what you're looking for?

Our support team is here around the clock. Open a ticket or chat with us and we'll get you back on the call.