Legal

Security

How we hold your data, who can reach it, how long we keep it, and what we do not have.

  1. 1. Where the data lives

    The application and its database run on managed infrastructure in the European Union. Files and documents are held in managed object storage. Some of the providers involved in a voice call: speech recognition, speech synthesis, language models, telephony: process data outside the European Union; those transfers are covered by Standard Contractual Clauses or an equivalent mechanism, and the providers are listed in the data processing agreement.

  2. 2. Encryption

    All traffic to and from our services runs over TLS. Credentials that would give access to a third-party account on your behalf: calendar authorisations, two-factor secrets: are encrypted at rest and are never stored in clear text. Passwords and the personal codes used to identify someone by voice are stored as hashes, never as the value itself: if a code is lost it is replaced, not recovered.

  3. 3. Secrets

    API keys and webhook secrets live in the deployment environment, never in the database and never in the source code. Where a provider sends us a payload that contains one of our own tokens, the token is stripped before the payload is stored: a secret written to a database leaves through every reader that comes after it. Secrets are compared in constant time, so a wrong value cannot be guessed by measuring how long the answer takes.

  4. 4. Access

    Access is by role. A client account sees only its own data, enforced in the database query and not in the interface, so a mistake in a page cannot expose another tenant. Two-factor authentication is available on accounts. Access can be revoked for a single person without touching the rest of the team, and a revoked account stops working on the next request: including on the telephone.

  5. 5. Retention and deletion

    Data is kept for as long as the service requires it and then deleted. Call transcripts and recordings are kept for 90 days. Discarded lead data is stripped after 30 days. Accounting records are kept for the period the law requires.

    Requests not to be contacted are kept indefinitely, deliberately: deleting one would mean calling that person again.

  6. 6. Recording

    Call recording is off by default and is switched on per client, knowingly. A written transcript is produced regardless, so that a conversation can be reviewed without keeping the audio.

  7. 7. If something goes wrong

    If we become aware of a personal data breach affecting a client, we notify that client without undue delay and in any case within 48 hours of becoming aware of it, with what we know at the time rather than waiting for a complete picture, and we support them in their own notifications. The detail is in the data processing agreement.

  8. 8. What we do not have

    We do not hold SOC 2, ISO 27001 or HIPAA certification today, and we do not display badges for them. Several of our competitors do; we would rather tell you plainly than imply an audit that has not happened.

    What we can give you instead: this page, the data processing agreement with the named providers, and a direct answer to any security questionnaire you send us.

  9. 9. Reporting a vulnerability

    If you believe you have found a security problem, tell us before telling anyone else, from the contact page. We will confirm receipt, keep you informed, and will not pursue anyone who reports a genuine issue in good faith and without accessing data that is not theirs.

    Last updated: 14 September 2026.