Legal
Privacy Policy
Last updated: August 1, 2026
This policy explains how Barking Studio operates Mylla and handles personal data across the public website, dashboard, voice service, embedded demo, integrations, and Companion App.
1. Who we are and our roles
Barking Studio, Amsterdam, Netherlands, operates Mylla. For privacy questions, contact our privacy lead at support@mylla.ai.
For caller, customer, request, calendar, and knowledge-base data a business puts into Mylla, that business normally decides why the data is processed and acts as controller. Barking Studio processes that data on the business's instructions. Barking Studio acts as controller for Mylla account administration, billing, security, direct support, website visits, and marketing-demo interactions.
2. Personal data we collect
- Account and business data: name, email, business name, role, membership, authentication identifiers, preferences, and audit activity.
- Call and request data: caller number, call metadata, recordings, transcripts, summaries, messages, and fields configured by the business.
- Website and demo data: demo voice or text content, contact details a visitor chooses to provide, IP-derived rate-limit data, browser information, and lead classification.
- Integration data: connected-account identifiers and the calendar, CRM, email, or workflow data required for enabled features.
- Companion App data: installation identifier, push token, platform, app version, environment, optional device name, and authorized workflow actions.
- Diagnostics: routes, timestamps, release and performance data, crash details, opaque correlation identifiers, and limited network or device metadata.
- Billing and support: subscription, invoice, tax, transaction, and support-communication data. Stripe receives payment-card details directly.
Device biometrics and passcodes are checked by the operating system. Mylla receives only the local success or failure result and does not receive the biometric template or device passcode.
3. Purposes and legal bases
- Provide and support Mylla: contract and steps requested before entering a contract.
- Process business-directed calls and workflows: the business's documented instructions; the business is responsible for its own legal basis and required notices.
- Secure, diagnose, and improve the service: legitimate interests in service reliability, fraud prevention, security, and product quality, balanced against individual rights.
- Billing, tax, disputes, and required records: contract, legitimate interests, and legal obligations.
- Service communications: contract and legitimate interests. We use consent for optional marketing where required.
- Website performance measurement: legitimate interests or consent where local law requires it. Mylla does not use data for cross-context behavioral advertising.
4. Voice, knowledge bases, and AI processing
Mylla sends live call audio and relevant prompt context to Google Gemini for realtime conversation processing. After a call, Mylla may send the recording to OpenAI to create a diarized transcript that separates speakers and supports summaries, request extraction, and follow-up workflows.
Mylla does not create voiceprints and does not use voice data to identify a caller by their voice. Diarization labels speakers within a conversation; it is not biometric identification.
When a business uploads or imports knowledge-base material, Mylla may send document bytes, source URLs, and extracted text to Google Gemini for extraction, OCR, and digestion. Mylla may send the resulting text chunks to OpenAI to create embeddings used for knowledge search.
Businesses are responsible for configuring required AI and recording notices and for using Mylla lawfully in their jurisdictions. A caller can submit a privacy request through the business they contacted or by emailing Mylla support.
5. Service providers and international transfers
The following subprocessors, conditional feature providers, and business-directed integration recipients may process data only for the service purposes described below:
- Amazon Web Services (AWS) (EC2, ECS, S3, SSM, CloudWatch; Subprocessor) — Voice infrastructure, compute, encrypted object storage, backups, and operational monitoring.
- Google (Gemini) (Gemini API; Subprocessor) — Realtime voice-model processing for Mylla’s default pipeline, optional text reasoning in a split pipeline, and extraction, OCR, and digestion of uploaded or imported knowledge-base material.
- Google (Firebase Cloud Messaging) (Firebase Cloud Messaging; Conditional subprocessor) — Deliver privacy-safe Companion App notifications to Android devices.
- OpenAI (API services; Subprocessor) — Optional realtime or split-pipeline speech recognition, text reasoning, and speech synthesis; post-call diarization and structured processing; selected assistant features; and knowledge-base search embeddings.
- Deepgram (Speech-to-text API; Conditional subprocessor) — Transcribe live caller audio when an administrator selects Deepgram for a split voice pipeline.
- Cartesia (Text-to-speech API; Conditional subprocessor) — Generate agent speech when an administrator selects Cartesia for a split voice pipeline.
- ElevenLabs (Text-to-speech API; Conditional subprocessor) — Generate agent speech when an administrator selects ElevenLabs for a split voice pipeline.
- Supabase (Database, authentication, and storage; Subprocessor) — Business accounts, authentication, application data, and stored call artifacts.
- Vercel (Web hosting, functions, Analytics, and Speed Insights; Subprocessor) — Serve the web application, execute API routes, and measure aggregate reliability and performance.
- Twilio (Voice, phone numbers, SIP, and SMS; Subprocessor) — Telephony routing, phone-number management, call signaling, and configured SMS delivery.
- Twilio SendGrid (Transactional email; Subprocessor) — Send invitations, request notifications, and service emails.
- Stripe (Payments, subscriptions, tax, and billing; Processor and independent controller) — Process payments, manage subscriptions, prevent fraud, and meet financial obligations.
- Sentry (Functional Software) (Error monitoring and diagnostics; Subprocessor) — Detect crashes, delivery failures, performance problems, and security-relevant errors.
- Linear (Linear Orbit, Inc.) (Issue tracking and incident triage; Subprocessor) — Track product work and receive operational diagnostic context when a signed production Sentry alert creates or updates an incident issue.
- Expo (650 Industries) (Expo Push Service and EAS; Conditional subprocessor) — Deliver Companion App notifications and support mobile build and release operations.
- Apple (Apple Push Notification service; Conditional subprocessor) — Deliver privacy-safe Companion App notifications to Apple devices.
- Browser-selected Web Push services (Web Push delivery (for example, Google, Mozilla, or Apple endpoints); Conditional subprocessor) — Deliver browser notifications after a user enables Web Push for Mylla.
- Microsoft (Microsoft sign-in and Outlook Calendar; Business-directed recipient) — Optional account authentication and calendar availability or booking features.
- Google (connected account services) (Google sign-in and Google Calendar; Business-directed recipient) — Authenticate an account or check availability and create calendar events when a user connects Google.
- Calendly (Calendly scheduling; Business-directed recipient) — Read scheduling configuration and availability when a business connects its Calendly account.
- Cal.com (Cal.com scheduling; Business-directed recipient) — Check availability and create bookings when a business connects a Cal.com cloud or self-hosted account.
- Asana (Asana project tasks; Business-directed recipient) — Create project tasks from call requests when a business connects Asana.
- Slack (Salesforce) (Slack incoming webhooks; Business-directed recipient) — Send new request notifications to a channel selected by the business.
- HubSpot (HubSpot CRM; Business-directed recipient) — Search, create, or update CRM contacts when a business connects HubSpot.
- Zapier (Webhooks by Zapier; Business-directed recipient) — Send configured call and lead events to a Zap selected by the business.
- Business-selected webhook or MCP provider (Custom webhook and MCP connector; Business-directed recipient) — Send configured events or allow an agent to call external tools chosen and configured by the business.
Business-directed recipients receive data only after a business or account user connects the service. The connecting business is responsible for that provider agreement, configuration, transfer mechanism, and any downstream recipients it selects.
LiveKit's open-source software runs on infrastructure managed by Mylla. Mylla does not use LiveKit Cloud for these calls, so LiveKit is not a separate subprocessor in this deployment.
Provider locations, published DPA status, and transfer mechanisms are listed in the public subprocessor register. For restricted transfers, provider terms may use an adequacy decision, the Data Privacy Framework, or the European Commission's Standard Contractual Clauses. Module 2 applies where Barking Studio is controller and a provider is processor; Module 3 applies where Barking Studio acts as processor and appoints a subprocessor. The register identifies account-level verification that is still pending.
6. Retention and deletion
- Voice recordings, transcripts, calls, customers, and requests follow the business's service configuration and applicable contractual or legal requirements.
- Business audit-log entries follow a three-year platform retention period and are then handled by the retention process.
- Account, billing, tax, fraud-prevention, dispute, and security records are kept for the service relationship and any period required by law or needed to establish or defend claims.
- Companion App push registrations are disabled on sign-out, detected permission revocation, or an invalid-token response. Browser Web Push registrations are deleted after the push service reports an invalid or expired endpoint.
- Diagnostic and provider backup data follows the relevant provider's retention schedule and Mylla's security and legal obligations.
Cancellation does not automatically delete business or call data. Contact support to request deletion. We verify the requester's authority and review applicable retention duties before taking action.
7. European privacy rights
Depending on the processing and applicable law, individuals may have rights to information, access, correction, deletion, restriction, portability, and objection, and a right to withdraw consent without affecting earlier lawful processing.
Submit a request to the responsible business or to support@mylla.ai. If you are in the Netherlands, you may also lodge a complaint with the Autoriteit Persoonsgegevens, or with another competent supervisory authority.
8. California privacy notice
California residents may have rights to know or access categories and specific pieces of personal information, request correction or deletion, receive portable information, and receive equal service after exercising a privacy right. Mylla does not sell personal information and does not share it for cross-context behavioral advertising.
The categories collected and disclosed for business purposes are identifiers, account and commercial information, internet or device activity, audio information, professional information, approximate geolocation derived from network data, and inferences needed for call summaries or demo-lead classification. Sections 2, 3, and 5 explain the sources, purposes, and provider categories.
9. Canada and Quebec
Mylla supports access and correction requests under applicable Canadian privacy law. Quebec residents may also ask about deletion, portability, consent withdrawal, or a decision made using personal information where those rights apply. Send requests or complaints to the privacy lead at support@mylla.ai.
Data may be processed outside Quebec or Canada in the provider locations listed in the subprocessor register. This policy does not claim that Mylla is certified for healthcare privacy laws, and businesses must assess whether Mylla is appropriate for regulated health data before use.
10. Children's privacy
Mylla accounts are for people aged 18 or older, and the service is not directed to children. A minor may incidentally call a business that uses Mylla; in that case the business acts as controller, and Mylla processes the call on the business's instructions as its processor. A parent or guardian can request review or deletion through that business or support@mylla.ai, subject to verification and applicable retention requirements.
11. Security and cookies
Mylla uses encrypted transport, managed encryption at rest, business-scoped database policies, server-side authorization, application-level encryption for selected OAuth integration credentials, audit logs, and minimized diagnostics. No internet service can guarantee absolute security.
Mylla uses essential storage and cookies for authentication and preferences and privacy-conscious measurement for reliability and performance. It does not use advertising or cross-site tracking cookies.
12. Changes and contact
We publish the effective date and a summary for material policy updates. Where required, we also provide notice through an appropriate account or communication channel before the change takes effect.
Contact: Barking Studio, Amsterdam, Netherlands — support@mylla.ai.