MissLess, Bouloue (trading as MissLess)
Chamber of Commerce 91137985 · VAT NL004868775B72
Kronenburgsingel 545-47, 6831 GM Arnhem, the Netherlands
info@missless.tel · +31 6 4752 4058
This is a translation for convenience. The Dutch text is the binding version; in case of any discrepancy, the Dutch prevails.
1. Who we are
MissLess (missless.tel) provides an AI phone assistant for businesses. For privacy questions you can contact us at info@missless.tel.
2. Our two roles under the GDPR
a. Controller. For the account data of our clients and partners, and for the data of visitors and leads via our website, we determine the purposes and means of processing ourselves. For this data we are the controller.
b. Processor. Call data, recordings, transcripts, names, phone numbers and orders from callers are processed by us on the instructions of and on behalf of our clients. For this data the client is the controller and MissLess is the processor. Callers with questions about their data can turn to the business they called; we support our clients in handling such requests.
3. Data processing agreement (DPA)
For the processing of call data on behalf of the client, the following processing arrangements apply between the client and MissLess, and form part of the agreement:
- Purpose: answering, recording, transcribing and summarising phone calls and logging orders, reservations and callback requests, solely for the benefit of the client.
- Sub-processors: Google (Gemini, voice AI), Twilio (telephony/SMS), Pay.nl (payments), OpenRouter/OpenAI (summaries) and Hetzner (hosting). Changes to sub-processors are announced in advance.
- EU hosting: data is hosted on Hetzner servers in Germany.
- Deletion on termination: after termination of the agreement, call data is deleted within 30 days.
- Security: appropriate technical and organisational measures, including encrypted connections (TLS), per-account access restriction, and logging.
- MissLess processes the data solely on the client’s instructions, imposes confidentiality on the staff involved, supports the client with data subject requests and data breach notifications, and enables the client to meet its obligations under the GDPR.
4. Which data we process
- Call data (as processor): call recordings, transcripts, names, phone numbers, orders, reservations and callback requests from callers.
- Account data (as controller): business name, email address, password (encrypted), settings and usage data of clients and partners.
- Billing data: payments run through Pay.nl; we do not store full card or bank account details ourselves.
5. Legal bases
- Performance of the agreement: delivery of the service, account management and billing.
- Legal obligation: statutory tax retention obligations for our records.
- Legitimate interest: security, abuse prevention and limited product improvement.
- For call data that we process as a processor, the client as controller determines the legal basis.
6. Retention periods
Our policy is: transcripts and call data are kept for as long as the client’s account is active, and are deleted within 30 days of termination of the agreement. Account data is deleted after termination, except for data we are legally required to keep longer (such as invoices, subject to the 7-year Dutch tax retention obligation).
7. Your rights
Under the GDPR you have the right of access, rectification and erasure of your personal data, as well as the right to restriction of and objection to processing, and to data portability. Send your request to info@missless.tel; we respond within one month.
You also have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens, autoriteitpersoonsgegevens.nl).
Are you a caller of a business that uses MissLess? Then address your request to that business in the first instance; it is the controller for that data.
8. Cookies and localStorage
We work with three categories:
- Necessary (always on): functional cookies and localStorage for your language preference, currency preference, login session and security. No consent is required for these because the site does not work without them.
- Analytics (only with consent): to measure anonymously how visitors use the site so that we can improve it (e.g. Google Analytics).
- Marketing (only with consent): to make advertising more relevant and to measure reach (e.g. Meta Pixel).
On your first visit we ask for your choice via a cookie banner. Analytics and marketing cookies are only placed after you have given consent; refusing is just as easy as accepting. You can change or withdraw your choice at any time via Cookie settings at the bottom of every page.