Who we are
Proofbell is a call tracking and marketing attribution platform operated by Cambray Design Limited, a company registered in England and Wales (company number 06123943), registered office 14–15 Montpellier Arcade, Cheltenham GL50 1SU, England. Proofbell is a trading name of that company.
Contact us about anything in this policy through the contact form, choosing “Data protection or privacy”.
Two different roles, and why it matters to you
Proofbell handles personal data in two distinct capacities, and your rights differ depending on which applies:
- As a controller — for our own customers and website visitors. If you sign up, contact us, or browse proofbell.com, we decide what we collect and why. This policy governs that.
- As a processor — for the call and visitor data our customers collect using Proofbell. If you rang a business that uses us, that business is the controller and decides what happens to your data. We process it on their instructions. Our data processing terms cover that relationship, and requests about your call should go to the business you rang.
What we collect as a controller
| Data | Why | Lawful basis |
|---|---|---|
| Name, work email, company name | To create and administer your account | Contract |
| Password (hashed with Argon2id — never stored or recoverable in plain text) | To authenticate you | Contract |
| IP address and user agent at sign-in and signup | To detect abuse and rate-limit account creation | Legitimate interests (platform security) |
| Billing name, address and card details | To take payment. Card details go directly to Stripe; we never receive or store them | Contract |
| An audit log of significant actions in your account | Security, and answering "who changed this and when" | Legitimate interests, and legal obligation where applicable |
What the platform collects on our customers' behalf
When a business uses Proofbell on their website, the tag and our telephony provider collect the following for that business. We are a processor for all of it.
- A first-party visitor identifier, set as an HttpOnly cookie on the customer's own domain. It is not shared across customers and cannot be used to track someone from one customer's site to another.
- Referrer, landing page, UTM parameters and ad click identifiers
(such as Google's
gclid) — how the visit arrived. - Call metadata — the caller's number, the number dialled, time, duration and outcome.
- Call recordings, where the customer has enabled them. Recording is off unless switched on per project, and the customer is responsible for the notifications and consent their jurisdiction requires.
- Conversion and revenue data the customer imports from their own CRM.
How we protect it
These are specific, verifiable measures rather than assurances:
- Call recordings are encrypted at rest with AES-256-GCM. Each recording is cryptographically bound to the account and call it belongs to, so a recording cannot be decrypted in the wrong context even with the key.
- Tenant isolation is enforced at the database, not only in application code. Row-level security means a mistake in a query returns nothing rather than another customer's data.
- Passwords are hashed with Argon2id. We cannot see or recover them.
- Listening to a recording is a separate permission from seeing deal values, so access can be granted to one without the other. Every recording access is individually logged.
- Our own storage is in the UK/EU. The database is hosted in London
(
eu-west-2) and recordings are held in EU object storage. - A call recording is created in the United States before it reaches us. Our telephony carrier's account is in its US region, so the recording exists on their systems first. We copy it into EU storage and then delete their copy. If US processing of a recording is a problem for you, recording can be switched off per project and everything else on this page still works.
We do not currently hold ISO 27001, SOC 2 or Cyber Essentials certification. We would rather tell you that than imply otherwise.
Who we share data with
Sub-processors, each used for a specific purpose. A current list is maintained in our data processing terms.
| Provider | Purpose | Data |
|---|---|---|
| Telnyx | Telephony and call recording | Call metadata, audio |
| Twilio | Telephony and call recording, as a standby carrier | Call metadata, audio |
| Neon | Database hosting | All platform data |
| Stripe | Payments | Billing details, card data (direct to Stripe) |
| Mailgun | Transactional email | Email address, message content |
| Google Ads | Conversion upload, at the customer's instruction | Click identifier, conversion value — never a phone number or recording |
We do not sell personal data, and we do not use customer data to train machine learning models. Attribution modelling runs per account on that account's own data.
Health and other sensitive information
We accept every industry. If your callers might discuss their health, there is a declaration you can make that renders transcription unavailable on your account — rather than a filter that claims to detect medical conditions in ordinary speech, which would miss most of what people actually say and would be relied on anyway. Everything else keeps working. What this means if you take clinical calls.
How long we keep it
- Recordings and transcripts — the shorter of the period you set and the maximum your plan allows, so a plan with a 30-day maximum deletes at 30 days whatever is configured. Your current window is shown on your account. Deletion is an audited automatic purge, not a manual process.
- Recordings and transcripts after your subscription ends — we keep them for 30 days and then delete them. We email your account administrators first, naming the date, and nothing is deleted until that email has actually gone out. Starting a subscription again before the date cancels the deletion. Your call and attribution records are not affected.
- Call and attribution records — for the life of the account, then erased when it closes. This is the append-only record of what happened on each call, and because it cannot be edited it is erased through an audited purge that records what was deleted and why, rather than by an ordinary delete. On an agency account, closing one client erases that client only; every other client on the same agency is untouched.
- Account and billing records — six years after the account closes, as UK tax law requires.
- Audit logs — for the life of the account. They are what answers "who accessed this recording" years later, so they are not pruned.
Your rights
Under UK GDPR you can request access to your data, correction, erasure, restriction, portability, or object to processing based on legitimate interests. Use the contact form, choosing “Data protection or privacy”, and we will respond within one month.
If you are asking about a call you made to a business, that business is the controller and we cannot action your request directly — we will tell you who they are if you can identify the number you rang, and we will pass the request on.
You can also complain to the Information Commissioner's Office at ico.org.uk.
Cookies on this website
proofbell.com uses no advertising or analytics cookies. Signing in stores a session token in your browser, which is strictly necessary to keep you signed in and is removed when you close the tab.
Changes
If we change this policy materially we will email account holders before it takes effect rather than relying on you noticing the date above.