This addendum forms part of the terms of service and governs our processing of personal data on your behalf under UK GDPR Article 28. Where it conflicts with the main terms, this addendum takes precedence for data protection matters.
You are the controller. We are the processor. You decide what is collected and why; we act on your instructions.
1. What we process, and why
| Category | Data subjects | Purpose |
|---|---|---|
| Telephone numbers (caller and dialled) | Your callers | Connecting calls, attributing them, identifying repeat callers |
| Call audio, where you enable recording | Your callers and your staff | Providing recordings to you |
| Website visit data — referrer, landing page, ad click IDs, a first-party identifier | Your website visitors | Attributing calls to marketing |
| CRM records you import — names, emails, deal values | Your customers and prospects | Matching revenue to the call that produced it |
| Your staff's account details | Your users | Access control and audit |
Processing continues for the term of your subscription plus the retention periods below.
2. Our obligations
- Process personal data only on your documented instructions.
- Ensure anyone with access is bound by confidentiality and has access only where needed for their role.
- Implement the security measures in section 4 and not materially weaken them.
- Assist you with data subject requests, DPIAs and regulator enquiries.
- Delete or return personal data on termination, except where we must retain it by law.
- Make available the information needed to demonstrate compliance, and allow audit on reasonable notice.
3. Sub-processors
You give general authorisation for the sub-processors below. We will give at least 30 days' notice before adding or replacing one, and you may object on reasonable data-protection grounds — in which case you may terminate the affected service without penalty if we cannot offer an alternative.
| Sub-processor | Purpose | Location |
|---|---|---|
| Telnyx LLC | Telephony, call recording — the carrier in use | United States |
| Twilio Ireland Limited | Telephony, call recording — standby carrier, and numbers bought before the change | United States (us1) |
| Deepgram, Inc. | Speech-to-text on call recordings, and sentiment, topics, caller intent and a short summary computed from the same audio, where the project has transcription switched on | United States |
| Cloudflare, Inc. | Object storage for call recordings (R2) | European Union |
| Stripe Payments Europe Ltd | Payment processing | EU / US (DPF) |
| Mailgun (Sinch) | Transactional email | EU region |
| Vultr Holdings LLC | Application hosting | London |
| Neon, Inc. | Database hosting (PostgreSQL) | London (AWS eu-west-2) |
Changes coming
The following will start processing data on the dates shown. Nothing is sent to them before then. You may object on reasonable data-protection grounds — email us and say so.
| Sub-processor | Purpose | Location | From |
|---|
Sentiment, topics, intent and a call summary come from Deepgram, not from a new supplier. Added 3 September 2026. They are computed from audio Deepgram already receives to produce the transcript, in the same request — so no further copy of your customers' calls is made and no additional company is involved. This is a change to what an existing sub-processor does with data it already has, which is why the row above has changed and the table has not grown. Had it needed a new supplier it would have needed the notice period above first, and we would have told you before switching anything on.
Summaries are cleaned before they are stored. A summary is written from the call audio, which is what was said before anything of ours has looked at it — so if a caller reads out a card number, a summary can repeat it. Summaries go through the same automatic removal as transcripts do, using the same rules, before they are saved. Nothing else from this processing holds any of the words spoken: sentiment, topics and intent are stored as scores, labels and positions in the recording.
No sub-processor uses your data to train its models. Deepgram operates a Model Improvement Programme under which submitted audio and transcripts may be used for model training, and taking part is the default — a request that says nothing is in it. Every transcription request we send carries the opt-out, so your customers' calls are transcribed and not learned from. Joining would be a change to this table and would take the notice period above, not a setting somebody could turn on.
Google Ads and other advertising platforms are not sub-processors. When you instruct us to upload conversions, you are directing a transfer to a party with which you have your own relationship, and that platform acts as a controller in its own right. We upload only the click identifier and the conversion value — never a phone number, and never a recording.
4. Security measures
Specific and implemented, not aspirational:
- Encryption in transit — TLS for all connections, including to the database.
- Encryption at rest for recordings — AES-256-GCM, with each recording cryptographically bound to its account and call, so it cannot be decrypted in the wrong context.
- Tenant isolation at the database layer — row-level security, so a faulty query returns nothing rather than another customer's data. The application's database role cannot bypass it.
- Least privilege — role-based access with per-scope permissions. Listening to recordings is separable from seeing revenue, and access is re-evaluated on every request so revocation is immediate.
- Audit logging — significant actions and every recording access are logged with actor, time and target.
- Credential handling — passwords hashed with Argon2id; third-party API credentials encrypted at rest with context binding.
- Retention enforcement — recording and transcript retention is applied by an automated, audited purge rather than a manual process.
We do not hold ISO 27001, SOC 2 or Cyber Essentials certification at present. We will say so plainly rather than let a procurement questionnaire assume otherwise.
5. Personal data breaches
We will notify you without undue delay and within 48 hours of becoming aware of a breach affecting your data, with what we know at the time: what happened, which categories and roughly how many records, the likely consequences, and what we are doing. We will not delay notification to complete an investigation first.
As controller, deciding whether to notify the ICO or affected individuals is yours. We will give you what you need to make it.
6. International transfers
Our own systems store your data in the UK/EU: the database is in London and recordings are held in EU object storage.
Two processing steps happen in the United States. Call recording takes place on our telephony carrier's US region, so a recording exists there before we copy it into EU storage and delete their copy. Speech-to-text is performed in the US, on projects that have transcription switched on. Both transfers rely on the UK extension to the EU-US Data Privacy Framework, or the UK International Data Transfer Addendum to the EU SCCs, as applicable. Recording and transcription can each be switched off per project.
7. Retention and deletion
- Recordings and transcripts — the shorter of the period you configure and your plan's maximum, enforced automatically. See /privacy/ for why that is not a single number.
- Call and attribution data — for the term of your subscription.
- On termination — your calls, recordings, transcripts and attribution data are deleted within 30 days of your account closing. Two categories are deliberately kept: billing records, for six years as UK tax law requires, and the access log recording who listened to which recording — destroying that would remove the evidence of who handled your customers' calls. On request we will confirm deletion in writing.
We support erasure of an individual data subject on your instruction, including their recordings and identifiers.
8. Signing this
Accepting our terms accepts this addendum. If you need a countersigned copy for your own records, ask through the contact form, choosing “Data protection or privacy”, and we will provide one.