Security & Compliance Policies, CallMerlin

Last updated: 17-09-2026

1. Vulnerability disclosure program

CallMerlin maintains a coordinated vulnerability disclosure program. Report security issues to security@callmerlin.app or privacy@callmerlin.app. We also publish machine-readable contact details at https://callmerlin.app/.well-known/security.txt Please include: description of the issue, steps to reproduce, affected URLs or components, and your contact details. Do not access data belonging to other customers. We aim to acknowledge reports within 2 business days and provide a substantive update within 10 business days. We may request additional information to verify and remediate findings. We do not pursue legal action against researchers who follow this policy in good faith and avoid privacy violations, service degradation, or social engineering.

2. Sub-processor guidelines

CallMerlin (Small Guy B.V.) uses sub-processors to deliver the Platform. Each customer account is a separate tenant. Data is not commingled across accounts. Current sub-processor categories: a) Google Cloud Platform (EU, hosting and storage) b) Cloudflare, Inc. (EU configuration, CDN and DDoS protection) c) Stripe, Inc. / Stripe Payments Europe, Ltd. (payments) d) Telecommunications carriers (phone numbers, call routing, SMS) e) xAI, Inc. (Grok, AI inference for chat and voice) f) Email providers (transactional email) We inform customers at least 30 days before engaging a new sub-processor or replacing an existing one. Customers may object with reasons within 14 days as described in our Data Processing Agreement. We contractually require sub-processors to implement appropriate security measures and process data only on documented instructions. An up-to-date list is available on request at privacy@callmerlin.app. Full DPA: https://callmerlin.app/en/legal/dpa

3. LLM data tenancy

CallMerlin is multi-tenant SaaS. Each customer account (callmerlin_accounts) is logically isolated. PIN users, call logs, connections and credentials are scoped to one account ID. AI requests are executed in the context of the authenticated account. The Capability Gateway enforces per-user permissions server-side; the LLM cannot bypass PIN or capability restrictions. Customer data sent to xAI (Grok) for inference is processed only to fulfill requests for that customer session. We do not use customer content to train models. xAI is contracted with a data processing agreement and opt-out for model training on customer data. Sign in with Slack (this login app) does not send user data to an LLM. LLM processing begins only after login when the customer actively uses AI features.

4. LLM data residency

Primary CallMerlin infrastructure and customer data storage are in the European Union: Google Cloud region europe-west4 (Eemshaven, Netherlands). Firestore database cmsdb uses EU multi-region (eur3). For AI inference, chat messages, voice audio/transcripts and files shared in conversation may be sent to xAI, Inc. (United States) for processing. Transfers are based on the EU-US Data Privacy Framework where applicable, Standard Contractual Clauses (EU 2021/914), and supplementary measures including TLS encryption in transit. Telephony and payment sub-processors may also process limited data outside the EU under equivalent safeguards. Details are in our Privacy Policy: https://callmerlin.app/en/legal/privacy

5. LLM data retention

CallMerlin retention defaults: a) Call transcripts and AI summaries: maximum 90 days after the conversation, unless the customer configures a shorter period. Audio is not retained. b) Chat session data: retained for the active session and included in call logs/transcripts per account settings. c) Account data: retained while the account is active; deleted within 30 days after termination (30-day export window), except where legal retention applies. d) Access and security logs: maximum 12 months. e) Invoice data: 7 years (Dutch tax law). Customers can request deletion via privacy@callmerlin.app. Data sent to xAI for inference is processed for the request and not retained by CallMerlin on xAI infrastructure beyond what is required for the active inference call. Full retention schedule: https://callmerlin.app/en/legal/privacy