SuperbCall
Privacy statement.
Last updated: 24 August 2026
Introduction
Your privacy matters to us. At SuperbCall, we are committed to handling personal data carefully and transparently. This statement helps you understand:
This Privacy Statement covers:
- Our role and what SuperbCall does
- The types of information we gather about you
- How we use the information we collect
- How we share collected information
- How we store and safeguard personal information
- The legal bases we rely on for processing (especially for EEA users)
- International data transfers
- Your data protection rights
- How we use cookies on our site
This Privacy Statement explains how we collect personal information via our website at superbcall.com, including its sub-domains (“Website”), and through our AI phone receptionist platform and related services (“Services”).
It also explains your choices: how you can object to certain uses of your information, and how to access or correct your personal data. Our Website and Services are designed for use by businesses and their representatives, and for processing information of individuals on behalf of our customers (for example callers to a physiotherapy practice). They are not intended for personal, family, or household use. If you disagree with this statement, please do not use our Services or otherwise engage with our business.
For questions about how we handle personal information, contact us using the details at the end of this Privacy Statement.
Our role and functions at SuperbCall
SuperbCall helps physiotherapy practices in the Netherlands adopt voice AI through our cloud-based AI phone receptionist. Our customers use the platform to answer inbound calls, handle appointment requests, answer frequently asked questions, and stay reachable outside reception hours — with human-like conversations in the caller’s language.
SuperbCall’s Services use conversational AI that may interact directly with end-users (callers) on behalf of our customers. Customers are responsible for informing their callers appropriately that they may be interacting with an AI system, and for obtaining any consents required under applicable law. We aim to develop and deploy these technologies in a transparent and responsible way.
For healthcare-specific architecture (including that SuperbCall is designed around scheduling and reception workflows rather than clinical record access), see our Healthcare Trust page. We do not claim formal certifications in this statement that we cannot substantiate.
SuperbCall is based in the Netherlands and works with partners, service providers, and customers primarily in that market. For product information, visit superbcall.com.
The types of information we gather about you
If you use SuperbCall’s Services as an individual interacting with a physiotherapy practice (or other organisation) that has engaged us, we typically process your personal information under that organisation’s direction. In those cases we act as a processor and follow the customer’s instructions. Questions about how that organisation uses your data should go to them first, and you should consult their privacy notice.
Information you provide to us
When you use our Website or Services, you may provide information such as business name, your name, email address, phone number, and details about your practice or your relationship with a SuperbCall customer. Through the phone Services operated for a customer, callers may share information needed for reception and scheduling (for example appointment preferences). We do not collect clinical or medical record data through the marketing Website, and our product architecture is designed so the AI does not request clinical healthcare data — see Healthcare Trust.
Information we collect in an automated way
When you visit superbcall.com, we act as a controller for personal data related to that visit. Depending on your cookie choices and how you use the site, we may collect:
- Device and browser information: device or browser type and version, operating system, and similar technical settings.
- Usage and diagnostics: how the Website is used, technical errors, and basic performance signals.
- Navigation details: pages viewed, referring URLs, timestamps, and similar interaction data.
- Contact details you submit: email addresses and phone numbers entered in demo or early-access forms.
- Cookies and similar identifiers: as described in our Cookie policy, and only for non-essential categories after consent where required.
Information provided through our support or sales channels
If you contact us (for example by email), we may process your contact details, a description of your request, and any materials you send so we can respond.
Information from third-party sources
We may receive limited information from service providers that help us run the Website or email delivery (for example hosting or transactional email). We expect those parties to be authorised to share what they share with us.
Use of collected information
- Communication related to services: to respond to demo or early-access requests, answer inquiries, and send important service or administrative messages.
- Providing the Services: to operate the AI phone receptionist for our customers, including call handling and appointment-related workflows under the customer’s instructions.
- Improving our Services: to understand Website and product usage (where permitted), fix issues, and improve reliability and usability.
- Legal and business interests: to comply with law, protect our rights, and support audits or corporate transactions where needed.
- Safety and security: to detect abuse, protect against security threats, and enforce our policies.
Data storage and security
Retention
We keep personal information only as long as there is a valid reason — for example to follow up on a demo request, provide the Services, or meet legal obligations. When the purpose is fulfilled, we delete or anonymise the data where reasonably possible. If immediate deletion is not possible (for example backups), we protect the data and stop further use until deletion can be completed.
Where SuperbCall acts as a processor for a customer, retention follows that customer’s instructions and the applicable agreement.
Sub-processors
We use trusted sub-processors (for example hosting and transactional email). They are bound by contracts requiring appropriate protection. Where processing occurs outside the EEA, we use appropriate safeguards such as Standard Contractual Clauses where required. A current list of relevant sub-processors is available on request via the contact email below.
Security measures
We apply technical and organisational measures appropriate to the risk, including HTTPS on the Website. Healthcare-oriented architecture details are described on the Healthcare Trust page.
Legal basis for data processing in the EEA
For individuals in the European Economic Area (EEA), we process personal data only where a legal basis under the GDPR applies. Depending on the context, that may include:
- Contract / steps prior to contract: for example responding to a demo request or providing Services you have asked for.
- Legitimate interests: for example securing our systems, improving the Website in a privacy-respecting way, and defending our legal rights — balanced against your rights.
- Consent: for example non-essential cookies or analytics, where we ask for consent via our cookie banner.
- Legal obligation: where processing is required by law.
International data transfers
We primarily serve customers in the Netherlands. Some service providers may process data in other countries. When we transfer personal data from the EEA to a country without an adequacy decision, we use appropriate safeguards (such as Standard Contractual Clauses approved by the European Commission) unless another lawful mechanism applies.
Where a customer has specific data-location requirements, those are addressed in the customer agreement where applicable.
Your data protection rights
If you interact via a SuperbCall customer
If your data is processed because you called or dealt with a practice that uses SuperbCall, please contact that organisation first. We will assist them in responding in line with their instructions, our agreements, and applicable law.
Rights when we are the controller (Website and direct contacts)
Depending on applicable law (including the GDPR), you may have the right to:
- Request access to a copy of your personal information.
- Object to certain processing, including for direct marketing.
- Request rectification, erasure, or restriction of processing.
- Request portability of your data in a structured, commonly used format.
- Withdraw consent where processing is based on consent (without affecting prior lawful processing).
- Lodge a complaint with a supervisory authority (in the Netherlands: Autoriteit Persoonsgegevens).
How we handle requests
We respond to requests in line with applicable data protection law. We may need to verify your identity before disclosing or changing information. To exercise your rights, contact us at the email below. We aim to respond within one month where the GDPR applies.
Updates to our privacy statement
We may update this Privacy Statement to reflect changes in our practices or for legal or operational reasons. We will post the updated statement on this page and revise the “Last updated” date. For significant changes, we may provide a more prominent notice where appropriate.
We encourage you to review this page periodically. If you do not agree with an updated statement, please stop using the Website and Services.
Contact SuperbCall
If you have questions or concerns about how we use personal information, please contact us: