Security & data
Last updated: 25 July 2026
This page is the single source of truth for who operates Double Menu, where your data is processed, and who else touches it. It also says plainly what we do not have. If something here contradicts another page on this site, this page is the one to trust.
Who operates Double Menu
WISE MONKS, UAB
Company code: 301681679
VAT: LT100004359618
Mildos g. 4, LT-10311 Vilnius, Lithuania
Email: hello@doublemenu.ai
The same team builds IdentityCall.ai, a call intelligence platform. Double Menu is a separate product with its own infrastructure and its own contract.
For the marketing website at doublemenu.ai we are the data controller. For the call data you and your callers generate inside the product application at app.doublemenu.ai, you are the controller and we are your processor.
Who you buy from
Paid subscriptions are sold by Creem B.V. as merchant of record. Creem takes the payment, issues the invoice and handles VAT; your card details never reach our servers.
Where the application and your data run
- Application, database and voice servers — Hetzner, Nuremberg, Germany. This is where your menus, call records and recordings live.
- This marketing website — Cloudflare, served from its global edge network.
- Published menu audio — Cloudflare object storage. Menu prompts are rendered to audio when you publish, so the call runtime only plays finished files.
The database is not reachable from the public internet. It sits on a private network that only our own application servers can reach.
Subprocessors
These are the providers that can process data on our behalf, and what each one does:
- Hetzner — hosting for the application, database and voice servers (Germany).
- Cloudflare — this website, DNS and content delivery, and object storage for published menu audio.
- DIDWW — phone numbers and call termination.
- ElevenLabs — speech synthesis for menu prompts, and the conversation itself on AI branches. Only reached when you enable an AI branch.
- Creem B.V. — payments and merchant of record.
- Google Ireland Limited — website analytics and advertising, and only if you accept those cookies.
Not every provider above is established in the EU. Where one is not, the transfer relies on an adequacy decision or the EU Standard Contractual Clauses. The binding, current list is attached to the data processing agreement — email hello@doublemenu.ai and we will send it.
What happens on a call with no AI branch
If a call never enters an AI branch, no caller audio leaves the call. Nothing is streamed to a speech provider, nothing is recorded and nothing is transcribed. The menu reacts to the key the caller presses, and every word they hear was rendered to audio when you published the menu.
That includes booking. Keypad booking reads out the free times from audio rendered at publish time and takes a keypress — there is no speech recognition anywhere in it. We do still process the caller's number and the time they chose, because that is what the confirmation text needs.
Speech synthesis does involve a third-party provider, but it runs on the text you typed, before any call — never on your caller's voice. Recordings and transcripts exist only for calls that went through an AI branch, and only if you switched recording on.
Call recording and caller consent
Call recording is off by default. It is a setting you switch on, per assistant, not something that happens because you signed up.
There is a separate recording notice you can switch on, with wording you write yourself, played to the caller at the start of the call. It is off by default too. Whether you need it — and what it has to say — depends on the country you operate in, so we do not write it for you.
How long recordings are kept
When you turn recording on, the default audio retention is 0 days — the call is handled and no audio is kept. The other choices are 7, 30 and 90 days, after which the audio is deleted.
Call records and transcripts are kept for your account so your dashboard and analytics work. You can delete them, and closing your account removes them.
AI and your data
AI is opt-in and off by default on every plan. The Line plan has no AI on the call path at all — if you never want a machine talking to your callers, that plan makes it structurally impossible rather than a setting someone can flip.
We do not train models on your calls. We do not build or train speech or language models of our own. AI branches are handled by a third-party voice provider under a processing contract; what that provider may and may not do with the audio is set out in the data processing agreement.
A knowledge base you upload is used to answer your own callers' questions, and nothing else.
Data processing agreement
We offer a GDPR Article 28 data processing agreement to every paying customer, with the subprocessor list attached. It is available on request rather than published here — email hello@doublemenu.ai. We would rather tell you that than imply a public document exists.
Security practices
- The website and the application are served over HTTPS.
- The production database is on a private network, not exposed to the internet.
- Server access uses deploy keys only; password login is disabled.
- Sign-in to the product is passwordless — a link sent to your email, so there is no password of yours for us to lose.
What we do not claim
This section exists because trust pages usually leave it out.
- Double Menu holds no SOC 2 and no ISO 27001 certification. We are not going to put a badge on the footer for an audit we have not had.
- “GDPR compliant” is not a certificate anyone issues. Rather than claim it, we describe what we actually do and let you judge it.
- The data processing agreement and subprocessor list are available on request, not yet published on this site.
- We have not independently tested the competing products described on our comparison pages; those pages cite each vendor's own documentation instead.
Reporting a security problem
Found something? Email hello@doublemenu.ai with enough detail to reproduce it. We will confirm we received it, and we will not pursue anyone who reports a problem in good faith and does not access other people's data.