GDPR Compliance Statement
GDPR Compliance Statement — Reached
Issued by Reached | August 2026 version
1. Reached’s roles
Reached is a business telephony solution — parallel dialer, call recording and transcription, and CRM synchronization — available through start.reachedapp.com. For Customer data, including leads, contacts, campaigns, call recordings, notes, and transcripts, the Customer is the Controller and Reached acts as a Processor within the meaning of Article 28 GDPR, on the Customer’s documented instructions. The detailed terms are set out in the Data Processing Agreement (DPA). For its own processing activities — user-account management, billing, customer support, security, and fraud prevention — Reached acts as the Controller. Contact: nathan@reachedapp.com.
2. Legal basis for processing
In accordance with Article 6 GDPR, Reached processes personal data on the following legal bases: performance of a contract under Article 6(1)(b), necessary to provide the parallel dialing service; legitimate interests under Article 6(1)(f), for service improvement, security, and fraud prevention; consent under Article 6(1)(a), for marketing communications and revocable at any time; and legal obligations under Article 6(1)(c), for retaining billing data. For prospecting data processed on the Customer’s behalf, the legal basis is the Customer’s responsibility.
3. Legal framework for telephone prospecting
Reached is a tool: it is not the tool that is regulated, but how it is used. The same rules apply whether the Customer uses Reached, a cloud-telephony solution, or a conventional telephone. The Customer remains responsible for the compliance of its campaigns. B2B prospecting: telephone prospecting to professionals is permitted in France and may rely on legitimate interests, provided targeted contacts are relevant to their professional role, the called person is informed of the caller’s identity and the source of their data, every objection is honored without delay, and solicitations are neither abusive nor excessive. B2C prospecting: since 11 August 2026, telephone canvassing of individuals is subject to prior consent, except where the law provides exemptions. The Customer must collect, document, and be able to prove that consent, respect the right to object, and comply with legal calling hours. Call recording: at the beginning of every conversation, the Customer must inform call recipients about the recording, its purpose, and their right to object.
4. Data location and hosting
Data processed by Reached is hosted in Europe: the database — leads, campaigns, notes, and users — is hosted in Paris, France, through Supabase on AWS eu-west-3; telephone call recordings are hosted in Germany in the Twilio Europe data center; and transcripts and AI summaries are hosted in Europe. No data transfer to third countries is carried out without the appropriate safeguards provided for by the GDPR, including the European Commission’s standard contractual clauses or another recognized compliant mechanism.
5. Technical and organizational security measures
Data protection: AES-256 encryption for sensitive database data, HTTPS/TLS encryption in transit, logical customer-data isolation through Row Level Security (RLS), and daily automated backups retained for at least seven days. Access controls: secure authentication, session management and automatic expiry, production access limited to Reached team members who need it, and confidentiality commitments. Traceability and monitoring: access and audit logs, system logging and monitoring, and an incident-management procedure. Service providers and documentation: Reached uses providers with recognized security certifications, including ISO 27001 and/or SOC 2; a detailed description is available on request and attached to the DPA.
6. Data subject rights
Reached guarantees the exercise of the rights of access, rectification, erasure, restriction of processing, portability, and objection, in accordance with Articles 15 to 21 GDPR. To exercise these rights: nathan@reachedapp.com — response within 30 days. When a request concerns data processed on a Customer’s behalf, Reached forwards it to the relevant Customer and assists with the response.
7. Retention periods
Data category
Retention period
User account data
Subscription term + 3 years
Call recordings
90 days
Transcripts and summaries
90 days
Call logs
2 years
Billing data
10 years (legal obligation)
Data deleted on request
30 days, then permanently deleted
8. Personal data breach management
In the event of a personal data breach, Reached informs the affected Customer within 72 hours of becoming aware of the incident, enabling the Customer to meet its notification obligations to the CNIL and, where there is a high risk, to data subjects. For its own processing activities, Reached directly notifies the CNIL and data subjects within the deadlines provided by the GDPR.
9. Sub-processors
Reached uses the following sub-processors, all bound by equivalent contractual data-protection obligations: Supabase for the database and backend, in France on AWS Paris eu-west-3; Twilio for telephony infrastructure and recordings, in Germany in an EU data center; Deepgram for call transcription, in Europe; OpenAI for AI summaries, in Europe; and Stripe for payments, in Europe. Any addition or replacement of a sub-processor is notified to the Customer with reasonable prior notice.
10. What Reached allows — and does not allow
Reached helps optimize prospecting time and increase the number of conversations, while structuring and tracing interactions through history, timestamps, and call status. Reached does not allow users to circumvent the GDPR or consumer-protection rules, impersonate a number or hide the caller’s identity, or use numbers that do not comply with electronic communications regulations (ARCEP). The Customer retains full control of its campaigns and remains responsible for their compliance: targeting, informing people, collecting consent, honoring objections, and respecting calling hours and frequency.
11. Contact and DPO
For any question regarding the protection of personal data: Email: nathan@reachedapp.com. Website: www.reachedapp.com. Reached is not subject to the obligation to appoint a Data Protection Officer (DPO) within the meaning of Article 37 GDPR. Requests relating to personal data are handled directly by the Reached team.