Last updated: 13 September 2026
Privacy policy
This privacy policy explains how AA ENTERTAINMENT LTD ("Ringhum", "we", "us") processes personal data in connection with the Ringhum website (https://ringhum.com), the Ringhum dashboard, the AI phone assistants our customers operate and our support channels. It is written to meet the requirements of the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR") and the Maltese Data Protection Act (Chapter 586 of the Laws of Malta).
1. Who is responsible
Controller for the website, customer accounts, billing, marketing and support: AA ENTERTAINMENT LTD, 152, Office No. 9, Naxxar Road, San Gwann SGN 9030, Malta, company registration number C 95383 (Malta Business Registry). Contact: [email protected].
Processor for call data: when a business uses Ringhum to answer or place calls, that business is the controller of the callers' personal data and we process it on its documented instructions under our Data Processing Agreement. If you called a business that uses Ringhum, that business is your primary point of contact for privacy requests; we will help it respond.
We have not appointed a statutory Data Protection Officer because we are not required to under Article 37 GDPR; the contact above handles all data protection matters.
2. What data we process, why, and on what legal basis
2.1 Website visitors
- Server logs (IP address, user agent, requested pages, timestamps) — to run and secure the site. Legal basis: legitimate interest (Art. 6(1)(f)) in operating a secure service. Kept for 30 days.
- Essential cookies (session, CSRF token, cookie-consent choice, theme preference) — strictly necessary to provide the site. See the Cookie policy. We do not use advertising or third-party analytics cookies.
- Contact and demo forms (name, email, company, phone, message) — to answer your request. Legal basis: pre-contractual steps (Art. 6(1)(b)) or legitimate interest in responding to enquiries. Kept for 24 months.
2.2 Customers and workspace members
- Account data: name, email, password hash, company, phone, timezone, avatar, two-factor secrets, sign-in provider ids (Google, Apple) — to create and secure your account. Legal basis: contract (Art. 6(1)(b)).
- Billing data: plan, invoices, payment status. Card details are entered directly with our payment processor Stripe and never stored by us. Legal basis: contract and legal obligation (tax and accounting records, kept 10 years under Maltese law).
- Workspace configuration: assistants, instructions, knowledge base documents, company profile, staff directory, integrations and their credentials (stored encrypted). Legal basis: contract.
- Usage and audit data: dashboard actions, API requests, IP addresses, audit log entries — for security, abuse prevention and support. Legal basis: legitimate interest; audit log kept 12 months.
- Emails we send: call summaries, appointment confirmations, weekly reports, billing alerts, product updates. Transactional emails are part of the service; product updates are sent only with your consent (Art. 6(1)(a)) and can be switched off under Settings → Notifications at any time.
2.3 Callers, message senders and contacts (processed on behalf of our customers)
- Call data: calling and called phone numbers, call audio while the call is in progress, transcripts, AI-generated summaries, detected outcome and sentiment, extracted details the caller provides (name, email, requests), recordings if the customer has enabled them, voicemails.
- Text messages sent to and from the customer's number.
- Appointments and contact records the assistant creates or updates, including data synced to the customer's connected calendars, CRMs and other tools at the customer's instruction.
- Order lookups: when a customer connects an online store, order status is read from that store during the call and is not stored by us beyond the call log.
For this data we act as processor. Retention is set by the customer (from zero retention, where transcripts and audio are deleted as soon as the summary is written, up to indefinitely) and applied automatically. The legal basis is determined by the customer as controller; typically performance of a contract with the caller, or legitimate interest in handling business calls.
3. How AI is used
During a call, audio is streamed to speech-to-text, large-language-model and text-to-speech providers to conduct the conversation and to produce transcripts and summaries. The assistant identifies itself as an AI assistant when asked and customers are required by our Acceptable use policy to disclose the use of AI where the law requires it (including Article 50 of the EU AI Act). Our AI providers are contractually prohibited from using call content to train their models. Ringhum does not make decisions producing legal or similarly significant effects on callers solely by automated means (Art. 22 GDPR); the assistant answers questions, books appointments and takes messages, and hands anything else to a human.
4. Who receives data (recipients)
We share personal data only with the service providers needed to run Ringhum, each bound by a data processing agreement: telephony and SMS carriers, speech recognition, voice and AI conversation providers, hosting and email delivery, payment processing (Stripe), and, where you connect them, the calendars, CRMs and other tools you choose. The full list, with locations and safeguards, is published on the Sub-processors page and updated at least 30 days before a new sub-processor handles customer data. We do not sell personal data and we do not share it with advertisers.
We may disclose data where required by law, to a court or authority with jurisdiction, to protect our rights, or to a successor in a merger or acquisition (who must honour this policy).
5. International transfers
AA ENTERTAINMENT LTD is established in Malta (EU). Some providers process data in the United States or other third countries. Transfers rely on an adequacy decision (including the EU–US Data Privacy Framework where the provider is certified) or on the European Commission's Standard Contractual Clauses with supplementary measures such as encryption in transit and at rest, pseudonymisation of phone numbers in logs, and minimisation of what leaves the EU. You may request a copy of the relevant safeguards at [email protected]. Customers on the Scale plan can additionally run the voice pipeline on their own infrastructure so that call audio never leaves it.
6. Retention
- Account data: for the life of the account and 30 days after deletion (backups are purged within 90 days).
- Invoices and payment records: 10 years (tax law).
- Call transcripts, recordings and voicemails: per the customer's retention setting; summaries and outcomes for the life of the workspace.
- Server and security logs: 30 days; audit log: 12 months.
- Support conversations: 24 months after the last message.
7. Security
Data is encrypted in transit (TLS 1.2+) and at rest. Integration credentials and two-factor secrets are stored encrypted with keys held separately. Access is role-based and every workspace action is written to an audit log. Webhooks we send are signed. Passwords are hashed with bcrypt; sign-in supports two-factor authentication, Google and Apple. We review access quarterly and test backups. In the event of a personal data breach we notify the competent supervisory authority within 72 hours where required and affected customers without undue delay.
8. Your rights
Under the GDPR you have the right to access your personal data, to rectification, to erasure, to restriction of processing, to data portability, to object to processing based on legitimate interest, and to withdraw consent at any time without affecting prior processing. Account holders can export or delete their workspace from Settings; for everything else, email [email protected]. We answer within one month (extendable by two further months for complex requests, in which case we will tell you). We may ask you to verify your identity.
If you believe we are processing your data unlawfully you may lodge a complaint with the Information and Data Protection Commissioner (IDPC), Malta or with the supervisory authority of your habitual residence.
9. Children
Ringhum is a business service and is not directed at children under 16. We do not knowingly collect their data as controller. Customers must not configure assistants to target children.
10. Changes
We will post changes to this policy here and, for material changes affecting customers, notify workspace owners by email at least 14 days in advance. The date at the top shows the latest version.