This Privacy Policy explains what information we collect directly or indirectly (including through our partners), how we use it, and what data-protection rights you have when you use our Allo solution.
Its purpose is to provide clear, transparent and comprehensive information about:
- the data we collect directly or via our partners;
- how and why we use that data; and
- your rights in relation to that data and how to exercise them.
This Privacy Policy applies only to the data we collect and process in connection with the provision of our Allo solution (the “Solution”), delivered as SaaS and a mobile application.
By using the Solution, you consent to those processing activities for which consent is the lawful basis, as set out in this Privacy Policy.
Please read this Privacy Policy carefully together with any just-in-time notices we may present at the point of collection so that you are fully informed about how and why we use your personal data.
Processing we carry out to run our own business operations, and processing undertaken in other applications, are governed by their respective privacy policies, to which we refer you.
1. Identity and role of the controller
Mobile First acts as a data controller for the processing of personal data necessary for the operation, security and improvement of the services (e.g., account management, billing, technical logs, analytics). For call content and related communications data processed on behalf of the client (e.g., recordings, transcripts, routing data), Mobile First acts as a data processor within the meaning of Article 28 GDPR.
1.1 Processing carried out by Mobile First as processor
Where the Solution is subscribed by professional clients (businesses, sole traders, associations, etc.) to provide outsourced receptionist services (call forwarding, voice transcription, virtual receptionist, blocking unwanted calls, etc.), Mobile First acts as a processor within the meaning of Article 28 GDPR.
In that context, Mobile First processes data on behalf of and in accordance with the documented instructions of its clients, who act as controllers.
For further information regarding such processing, please contact the relevant client organisation directly.
1.2 Processing carried out by Mobile First as controller
The processing activities described in this Privacy Policy (e.g., user-account management, marketing, security, legal compliance, etc.) are carried out by Mobile First in its capacity as controller.
In certain cases, Mobile First may also act as an independent controller, in particular where it processes data for:
- the continuous improvement of the Solution;
- aggregated performance analysis or detection of unwanted calls; or
- the training and evaluation of its artificial-intelligence models.
MOBILE FIRST, a société par actions simplifiée registered with the Créteil Trade and Companies Register under No. 978 534 543, CS 20010, 110 Rue de Fontenay, 94300 Vincennes, France (“Mobile First”, “we”, “us” or “our”)
Email: [email protected]
2. Why we use your personal data and how long we keep it
To provide the services relating to the Solution
- Data processed: identification data (name, surname, email address, telephone number); professional data (organisation, role within the organisation, professional email address and telephone number); log-in data (IP address, device used, date and time of log-in).
- Purpose: to manage your registration for, and use of, the Solution so that we can provide services to you.
- Lawful basis: performance of a contract to which you are party (Article 6(1)(b) GDPR).
- Retention: term of the contract plus five (5) years after expiry for the establishment, exercise or defence of legal claims.
- Third-party recipients: Apple Inc. where you register via the Apple App Store and Google Inc where you register via the Google Play Store.
To measure interest in, and usage of, our Solution
- Data processed: browsing and usage data; advertising identifiers (IDFA/GAID); device ID; session statistics; cookies/trackers; aggregated usage data (frequency, retention, activation).
- Purpose: to understand how the Solution is used (user numbers, session duration, journeys, retention) and improve performance and services.
- Lawful basis: our legitimate interests (Article 6(1)(f) GDPR); and your consent where advertising trackers are used for this measurement (Article 6(1)(a) GDPR).
- Retention: 13 months.
- Third-party recipients: Google Analytics 4, AppsFlyer Ltd and PostHog, Inc.
To provide personalised advertising within our Solution
- Data processed: advertising identifiers; browsing data; conversion data; trackers; advertising preferences and inferred or declared interests; advertising interaction history; audience segments; records of consent and choices regarding personalised advertising.
- Purpose: to serve personalised adverts, measure campaign performance and build audience segments to better target marketing communications, including the collection and sharing of data with advertising partners to display relevant ads within the Solution or on third-party platforms.
- Lawful basis: your consent (Article 6(1)(a) GDPR).
- Retention: 13 months.
- Third-party recipients: Meta Platforms, Inc. (Meta Pixel).
To communicate with you
- Data processed: email address; telephone number; usage data (e.g., event triggers); technical identifiers (device ID, notification token); history of message delivery and interactions (opens, clicks).
- Purpose: to send transactional, technical and marketing communications (push notifications, SMS, emails).
- Lawful basis: performance of a contract (Article 6(1)(b) GDPR) for technical/service notifications; your consent (Article 6(1)(a) GDPR) for marketing communications.
- Retention: until account deactivation or withdrawal of consent (for marketing messages).
- Third-party recipients: Vonage Holdings Corp. (SMS); Peaberry Software Inc. (Customer.io – emails); Firebase Cloud Messaging (push).
To manage payments and subscriptions to our Solution
- Data processed: user identifier; email address; payment information (processed via app stores and not stored by Mobile First); advertising/technical identifiers; subscription and billing history.
- Purpose: to enable secure payment of subscriptions and premium features, and manage billing and purchase tracking.
- Lawful basis: performance of a contract (Article 6(1)(b) GDPR).
- Retention: contract term plus statutory accounting retention periods.
- Third-party recipients: Apple Inc. (App Store) and RevenueCat, Inc.
To host and operate the Solution
- Data processed: aggregated usage data (diagnostics, logs); device technical information.
- Purpose: to ensure the technical delivery and availability of the Solution.
- Lawful basis: performance of a contract and our legitimate interests (Articles 6(1)(b) and 6(1)(f) GDPR).
- Retention: aggregated data retained in line with the relevant store's policies.
- Third-party recipients: Amazon Web Services, Inc. (cloud hosting) and Apple Inc. (App Store).
To ensure compliance with the Solution's terms of use and its secure operation
- Data processed: technical and application logs; device and app-version information; IP addresses (within logs).
- Purpose: to monitor technical performance and detect errors, incidents and security vulnerabilities.
- Lawful basis: our legitimate interests (Article 6(1)(f) GDPR).
- Retention: for the period necessary for incident resolution and audit trail.
- Third-party recipients: Functional Software, Inc. (Sentry).
To comply with our legal obligations
- Data processed: identification data (name, surname, email address, telephone number); call logs; call and conversation content; account and transaction history; data-subject requests.
- Purpose: to comply with legal obligations, respond to official requests and manage data-subject rights.
- Lawful basis: legal obligation (Article 6(1)(c) GDPR).
- Retention: in accordance with applicable statutory limitation periods.
- Third-party recipients: competent administrative and judicial authorities (as applicable).
5. Google User Data – Google Calendar
This section describes how Allo (“we”, “the Application”) accesses, uses, stores, shares and protects data obtained from your Google Calendar through Google APIs. It applies specifically to Google user data and is in addition to the general terms of this Privacy Policy. Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Data we access. When you connect your Google Calendar to Allo, you authorise us, through Google's OAuth consent screen, to access:
- Your availability (free/busy) information in your calendars.
- Events on Google calendars you own, including their details such as title, date, time, description, location and attendees, which Allo can view, create, change and delete.
- The name and profile picture of the connected Google account, solely to identify and maintain the connection.
We only request the minimum Google Calendar scopes needed to provide this feature, and we do not access Gmail or Google Drive.
How we use this data. We use your Google Calendar data exclusively to provide Allo's appointment feature on your behalf, namely to:
- Read your calendar availability so the Allo agent can offer accurate open time slots to your callers.
- Create, update and cancel calendar events (including their attendees) that correspond to appointments booked, rescheduled or cancelled through Allo.
We do not use Google Calendar data for advertising, and we do not use it to train generalised artificial intelligence or machine-learning models. We do not sell Google Calendar data.
How we share this data. We do not sell, rent or disclose your Google Calendar data to third parties, except:
- To sub-processors that operate our infrastructure strictly to enable the functionality described above, including Nango, which securely manages the Google connection and OAuth credentials on our behalf, and our secure cloud hosting provider, under contractual confidentiality and data-protection obligations.
- Where required to comply with applicable law, regulation, legal process, or an enforceable governmental request.
We do not transfer Google Calendar data to others for purposes unrelated to providing the calendar feature you enabled.
How we protect this data. We treat Google Calendar data as sensitive and protect it using appropriate technical and organisational measures, including encryption of data in transit (TLS) and at rest, access controls restricting access to authorised personnel on a need-to-know basis, and secure storage of OAuth credentials (managed by our authentication provider, Nango) to prevent unauthorised access, disclosure, alteration or destruction.
Data retention and deletion. We retain your Google Calendar data only for as long as your Google account is connected to Allo and as needed to provide the feature. You can revoke Allo's access at any time by disconnecting the integration within the Application or via your Google Account permissions. When you disconnect the integration or delete your Allo account, we delete the associated Google Calendar data and revoke the corresponding OAuth credentials within a reasonable period, except where retention is required by law. You may also request deletion at any time by contacting us at [email protected].
Limited Use disclosure. Allo's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
6. External links
The Solution may contain links or references to other websites that we do not control and to which this Privacy Policy does not apply. You should review the privacy policy of each website you visit. You are solely responsible for your interactions with such sites.
7. Use of artificial intelligence (AI)
Mobile First uses artificial-intelligence technologies to provide certain features, including:
- automated handling of inbound calls;
- transcription and summarisation of conversations;
- intelligent call routing; and
- automated detection and blocking of unwanted calls.
These processing operations rely on automated language analysis and call-classification to improve service quality and user safety.
These features are intended to support users but do not make legally binding decisions. The Client is responsible for reviewing and supervising outputs generated by these features.
Indeed, where such features are enabled on behalf of clients, Mobile First acts as processor.
For processing carried out for continuous improvement or for shared spam-detection purposes, Mobile First acts as an independent controller.
In accordance with Article 22 GDPR, where an automated decision produces significant effects (e.g., the automatic blocking of a call), data subjects may contest the decision, request human intervention, and present their point of view.
8. Your rights and how to exercise them
Under Articles 15–22 GDPR, you have the following rights:
- Right of access to your data;
- Right to rectification of inaccurate data;
- Right to erasure (“right to be forgotten”);
- Right to restriction of processing;
- Right to object on grounds relating to your particular situation;
- Right to data portability;
- Right to withdraw consent at any time (where processing is based on consent);
- Right to set post-mortem instructions under Article 40-1 of the French Loi Informatique et Libertés.
To exercise your rights, please contact us:
- by email: [email protected]
- by post: MOBILE FIRST – CS 20010, 110 Rue de Fontenay, 94300 Vincennes, France
If you have concerns about how we process your personal data, you may lodge a complaint with the CNIL or with the supervisory authority of your habitual residence within the EU/EEA.
9. How long we keep your data
Personal data collected by Mobile First are retained only for as long as necessary for the purposes for which they were collected and in accordance with the retention periods indicated for each purpose above. Certain data may be retained in archival storage beyond those periods for evidential purposes, in line with applicable limitation periods. Archiving means such data are extracted and kept on a separate, secure medium.
Call recordings and transcripts are stored for the duration determined by the client in its account settings. In the absence of specific configuration, they are retained for as long as the account remains active, and are automatically deleted six (6) months after deletion of the account. Technical logs and metadata related to communications are stored for 12 months for security and traceability purposes. Account data is retained for the duration of the contractual relationship and for a legal archiving period thereafter, where required.
10. Changes to this Privacy Policy
Mobile First reserves the right to amend this Privacy Policy at any time. Material changes will be notified via the Solution and/or by email. The “Last updated” date at the top of this document indicates when it was most recently revised.