Skip to content
STAKKER
VoiceWebsitesSoftwarePayRoadPricingBlog
ES Book an assessment
AI receptionistPremium websitesCustom softwarePayRoadPricingBlog Versión en español Book an assessment
Call
Legal notice AI and data protection

AI and data protection

How STAKKER SYSTEMS approaches the use of artificial intelligence, GDPR, the AI Act and data protection in phone agents, chatbots, automations and forms.

This page is for guidance only. It does not constitute legal advice. STAKKER designs systems built with compliance in mind, but the specific legal scope must be validated case by case with the client's legal adviser or DPO.

Audit my case Review an AI automation

On this page

  • General approach
  • GDPR applied to AI
  • Consent
  • Personal data
  • Sensitive data
  • Call recording
  • Legal basis
  • Data processors
  • External providers
  • International transfers
  • Logs and retention
  • Human review
  • Limits of the service
  • Contract and DPA requirement
  • Client's legal validation
  • Frequently asked questions

General approach

STAKKER SYSTEMS builds AI systems to automate customer service, calls, messaging, forms, leads, bookings and internal processes. When those systems process personal data, they do so under Regulation (EU) 2016/679 (GDPR), Organic Law 3/2018 (LOPDGDD, Spanish data protection law), Law 34/2002 (LSSI-CE) and Regulation (EU) 2024/1689 (AI Act, in force in phases until 2027).

STAKKER technically acts as a data processor for the client's data. The client remains the data controller towards its end users.

We do not promise absolute compliance. We design systems to reduce risk, document what they do and give the client what its DPO or legal adviser needs to validate them.

GDPR applied to AI systems

Any AI system that receives or processes information about an identified or identifiable person processes personal data: a phone agent that listens to the user, a chatbot that stores conversations, a form that captures an email address, an n8n workflow that syncs a CRM.

STAKKER applies the GDPR principles by default:

  • Lawfulness, fairness and transparency: the user knows they are interacting with AI and why.
  • Purpose limitation: data is used only for the declared purposes.
  • Data minimisation: only the necessary data is collected.
  • Accuracy: the client can rectify and delete data where applicable.
  • Storage limitation: retention is defined by default (see Logs and retention ).
  • Integrity and confidentiality: encryption in transit, encryption at rest where applicable, role-based access control (RBAC).
  • Accountability: records of processing activities, assessments where appropriate and system documentation.

When consent is needed

Explicit consent (Art. 6(1)(a) GDPR) is usually the legal basis when the processing is not covered by contract, legal obligation, vital interests, public interest tasks or legitimate interests. Typical cases in AI systems:

  • Commercial communications by email, SMS or WhatsApp (LSSI + GDPR).
  • Call recording for purposes other than contractual evidence.
  • Outbound calls with no prior contractual relationship.
  • Non-essential cookies or tracking technologies.
  • Processing based on profiling or automated decisions with a significant effect (Art. 22 GDPR).

For outbound AI voice calls, STAKKER requires the client to provide a documented legal basis (prior consent or a legitimate interests assessment / LIA). Without that basis, campaigns are not activated.

Processing of personal data

The systems that STAKKER builds typically process:

  • Identification data: name, email, phone number, NIF/CIF (Spanish tax ID).
  • Contact data: address, postcode, professional profile.
  • Interaction data: message content, transcripts, stated preferences, history.
  • Technical data: IP address, user agent, usage events, workflow logs.
  • Commercial or contractual data depending on the system (CRM, invoicing, calendar).

STAKKER does not train public models with the client's data. When external LLMs (Claude, GPT, etc.) are used, they are run with a configuration that excludes use for training.

Sensitive data (special categories)

The GDPR recognises special categories (Art. 9): health, racial or ethnic origin, political opinions, religious beliefs, trade union membership, sexual orientation, genetic and biometric data, and criminal data (Art. 10).

STAKKER does not accept projects where the system must process sensitive data unless the client meets all of the following conditions:

  • A designated DPO whose appointment can be evidenced.
  • Reinforced explicit legal basis (Art. 9(2) GDPR).
  • Data protection impact assessment (DPIA) before deployment, Art. 35.
  • Encryption in transit and at rest.
  • Role-based access control and full traceability (audit log).
  • Mandatory human review for critical decisions.
  • External providers with verified safeguards.

In clinics, law firms, HR or similar environments, STAKKER can automate the non-sensitive side of the process (reception, appointments, reminders, administrative FAQs) and hand over to a human when the flow enters sensitive territory.

Recording calls with AI

Recording calls in Spain requires an explicit legal basis (GDPR + LOPDGDD + Spanish Data Protection Agency (AEPD) case law) and prior information at the start of the call. STAKKER applies by default:

  • Audio is not recorded unless the client expressly requests it with a documented legal basis.
  • When a call is recorded, a notice is given at the start of the call ("this call is being handled by a virtual assistant and may be recorded for purposes X").
  • Text transcripts are stored in preference to audio where feasible.
  • Default retention of 30-90 days, configurable by contract.
  • Encryption at rest and access restricted to the team members who need it.

For outbound calls, STAKKER particularly requires an LIA or the recipient's prior consent. The AEPD has published circulars warning about commercial AI calls without consent (reference: AEPD, June 2023).

Legal basis for processing

Each flow declared in the contract must have a clear legal basis depending on the case:

  • Consent (Art. 6(1)(a)): forms, marketing, commercial communications.
  • Contract (Art. 6(1)(b)): support for active customers, order management, support.
  • Legal obligation (Art. 6(1)(c)): invoicing, tax.
  • Legitimate interests (Art. 6(1)(f)): security, fraud prevention, service improvement, with a documented LIA.

STAKKER does not decide the legal basis: it validates it with the client before configuring the system and records it in the record of processing activities.

Data processors

STAKKER acts as a data processor (Art. 28 GDPR) with respect to the client's personal data. Before going into production, we sign:

  • A data processing agreement (DPA) with Art. 28 GDPR clauses.
  • A list of sub-processors (external providers) with identity, country and purpose.
  • Technical and organisational measures (encryption, access control, backups, incident management).
  • A breach notification procedure within GDPR deadlines (72 hours to the controller).
  • A confidentiality undertaking from staff with access.
  • Return or deletion of data at the end of the contract.

Typical external providers

The systems that STAKKER builds may involve sub-processors. The exact list depends on the project and is documented in the DPA. Common providers:

Infrastructure

Hetzner Online GmbH (Germany, EU).

DNS and backups

Cloudflare Inc. (United States, with EU standard clauses): DNS resolution for the domain and storage of backups, encrypted before they leave our server. The website does not pass through their network: it is served directly from Hetzner.

LLMs

Anthropic PBC (United States), OpenAI Inc. (United States), DeepSeek or others depending on the case. Configured so that data is not used for training.

AI voice

ElevenLabs Inc. (United States), Vapi, Retell AI or equivalents. Twilio Inc. (United States) or equivalent as the telephony gateway.

Transactional email

Resend, Postmark, SendGrid or others depending on the case.

CRM and client tools

HubSpot, Pipedrive, Notion, Calendly, Cal.com, Slack, Telegram or others that the client already uses.

International transfers

Some providers are located outside the European Economic Area (mainly the United States). STAKKER applies the safeguards provided for in Chapter V GDPR:

  • Adequacy decisions (EU-US Data Privacy Framework for certified companies).
  • Standard Contractual Clauses (SCCs).
  • Additional technical measures: encryption, anonymisation where applicable.

The exact list of transfers and safeguards is delivered to the client with the DPA before production.

Logs, traceability and retention

STAKKER keeps operational logs for debugging, monitoring and traceability. By default:

  • Technical logs (errors, latencies, system events): retained for 30-90 days.
  • AI transcripts and conversations: configurable retention, by default 30-90 days for support and flow improvement.
  • Raw call audio: only if enabled, same period.
  • Security and access logs (auth, admin panel): extended retention for security reasons.
  • Client business data (CRM, calendar, invoices): according to the client's rules and applicable tax obligations.

The specific periods are fixed in the DPA. The client can request early deletion of conversations where there is a legal basis to do so (exercise of the end user's rights).

Human review and escalation

By default, STAKKER systems keep a human in the loop:

  • Handoff to a human when the system detects a complex case, a complaint, vulnerability or an out-of-scope topic.
  • The end user can always ask to speak to a human.
  • Automated decisions with a significant effect are not carried out without human verification or without having informed the user under Art. 22 GDPR and obtained a legal basis.
  • In regulated sectors (healthcare, financial, legal), human validation is mandatory before communicating a decision to the end user.

Limits of the service

STAKKER does not take on:

  • The role of the client's DPO.
  • Sector-specific regulatory audits (healthcare, financial, education, insurance). These are carried out by the client's adviser.
  • Final legal validation of the client's own legal texts (notices, consents, B2C contracts, terms).
  • Guarantee of commercial results: STAKKER guarantees the agreed technical implementation, not specific commercial results.
  • Responsibility for data that the client processes outside the system built by STAKKER.
  • Cover for incidents arising from a configuration chosen by the client against STAKKER's documented recommendation.

STAKKER accepts its responsibility as a technical processor: designing, documenting, maintaining and monitoring the system; applying technical and organisational measures; notifying incidents on time and complying with the DPA clauses.

The need for a contract and DPA

Before any system goes into production with real personal data, the client and STAKKER sign:

  • Services contract covering scope, term, fees, support and warranties.
  • DPA (data processing agreement) with Art. 28 GDPR clauses, sub-processors and technical/organisational measures.
  • Specific annexes where applicable (outbound voice LIA, DPIA for high-risk processing, particular conditions by sector).

STAKKER does not hand over production credentials, carry out real outbound calls, or activate flows on real users without those documents being signed.

Legal validation by the client

STAKKER is a technical provider, not a law firm. The client must validate with its legal adviser or DPO:

  • Suitability of the system for its specific sector (healthcare, financial, legal, education, minors, public data).
  • Legal texts that the client publishes on its website, forms or contracts with its end users.
  • Legal bases declared in each flow and compatibility with its corporate policy.
  • Whether a DPIA is needed under Art. 35 GDPR.
  • Whether adaptations are needed because of sector agreements or specific regulation.

STAKKER can work with the client's advisers and deliver the necessary technical documentation, but it does not replace those advisers.

Frequently asked questions

Does STAKKER provide legal advice?

No. STAKKER is a technical provider. We design systems built with compliance in mind, but the specific legal validation of each case (especially regulated sectors such as healthcare, financial services or minors) must be carried out by the client's legal adviser or DPO.

What happens to recordings of the AI agent's calls?

By default, STAKKER does not record audio unless the client explicitly requests it and a documented legal basis exists. If a call is recorded, the caller is informed at the start of the call, limited retention applies (30-90 days by default) and the recording is encrypted at rest.

Do we need to sign a DPA?

Yes. STAKKER acts as a data processor when it processes the client's personal data. Before going into production, we sign a data processing agreement with a list of sub-processors and technical and organisational measures.

Can AI be used with sensitive data (health, minors, criminal records)?

Only under reinforced conditions: a verified client DPO, an explicit legal basis, a data protection impact assessment (DPIA), providers with adequate safeguards and, almost always, mandatory human review. If the client does not meet these requirements, STAKKER does not accept the case.

Can the AI make decisions that affect the end user?

STAKKER designs systems with a human in the loop by default. Automated decisions with legal or similarly significant effects on a person require compliance with Article 22 GDPR: explicit information, the right to human review and a legal basis other than implied consent.

What happens to the data when the contract ends?

The DPA provides for the return or deletion of the personal data processed, as the client chooses. STAKKER documents the operation and the client receives confirmation.

How do you notify a security breach?

STAKKER monitors incidents and notifies the client without undue delay after becoming aware of a breach. The client, as data controller, decides whether to notify the AEPD (72 hours, Art. 33 GDPR) or the individuals affected (Art. 34).

Does STAKKER comply with the AI Act?

Regulation (EU) 2024/1689 is being phased in until 2027. STAKKER already applies the obligations currently in force (transparency when interacting with AI, prohibitions on unacceptable practices) and plans adaptations in line with the application timetable. Systems that qualify as high-risk are audited specifically.

More information on legal compliance by service

  • AI phone agent
  • WhatsApp chatbot
  • AI automation
  • Privacy policy
  • Cookie policy
  • Legal notice

Audit my case

If you would like to review how to adapt your chatbot, agent or automation to the GDPR and the AI Act, get in touch. Initial diagnosis is free.

Message us on WhatsApp Other channels

For information only. Last updated: 3 May 2026. Any substantial regulatory change will be reflected here. This page does not replace the contract or the DPA signed with each client.

STAKKER

AI and automation agency. We build and run your business's AI from Málaga, Spain, for anywhere in the world.

Talk to us

+34 951 870 512 WhatsApp [email protected]

Monday to Friday until 21:00 CET. The AI answers around the clock.

What we do

AI receptionistPremium websitesCustom softwarePricingBlogSolutions by sectorGlossary

Legal

Legal noticePrivacyCookiesAI and data protection

© 2026 STAKKER SYSTEMS, Málaga, Spain.

No tracking cookies: we measure the site without identifying you.