legal

Privacy Policy

CallHQ handles two very different kinds of personal data, under two different legal roles. This explains both, because conflating them is how privacy policies end up meaningless.

Version 1.0 · last updated 2026-08-09

Draft — not yet in force

These documents are complete in substance but still need 9 facts only the operator can supply: registered legal entity, company number, registered office address, privacy contact address, security contact address, support contact address, ICO registration number, governing law, hosting region. Until those are filled in and a solicitor has reviewed them, do not rely on this page or present it to a customer.

The two hats we wear

Almost every privacy policy for a B2B tool is confusing because it pretends there is one relationship. There are two, and which one applies changes your rights and our obligations.

We are the controller of data about our customers — the people who sign up, log in and pay. We decide why and how that data is used.

We are a processor for data about your prospects — the businesses and people you source, enrich, email, message and call using CallHQ. You decide who to contact and what to say. We supply the machinery and act on your instructions. You are the controller of that data, which means the legal responsibility for contacting those people lawfully is yours, not ours.

If you are a prospect who has been contacted by a CallHQ customer and you want your data removed, see Your rights — we can suppress you across every customer immediately, and we will, but we may need to route your wider request to the customer who holds it.

When we are the controller

For our own customers, we hold:

  • Account data — name, work email, hashed password, role, and the workspace you belong to. Used to authenticate you and scope what you can see.
  • Usage records — which actions your account performed and when, kept as an audit trail so a workspace administrator can see who changed what. This is also what makes a compliance claim defensible.
  • Billing data — your billing contact and subscription state. Card details are handled by Stripe and never reach our systems.
  • Support conversations — anything you send us through the chat widget or the contact form.

Our lawful basis is contract for anything needed to give you the service, and legitimate interest for security, fraud prevention and keeping the audit trail. We do not sell any of it, and we do not use it to train models.

When we are a processor

The prospect records inside your workspace — business names, addresses, phone numbers, email addresses, contact names, call notes, recordings, reply text — are processed on your instruction, for as long as you keep them, and only for the purposes you configure.

Workspaces are isolated at the database level, not by convention: one workspace physically cannot read another's records. Our staff do not access your prospect data except where you ask us to for support, or where we are legally compelled.

The terms governing that relationship are in the Data Processing Agreement, which forms part of your contract with us.

Where prospect data comes from

CallHQ builds prospect records from public sources, not from a bought or rented contact database. That distinction is the product, and it matters legally as well as commercially: we can tell you exactly where a record came from, and so can you.

  • Public map and business listings — OpenStreetMap, Google Maps business listings.
  • The UK statutory register — Companies House.
  • A business's own public website.
  • Optional enrichment providers you switch on with your own account — see the sub-processor register.

Every field carries its provenance in the product, so any record can be traced back to the source and the run that produced it.

Lawful basis for outreach

If you use CallHQ to contact people, you are the controller for that outreach and you need a lawful basis for it. CallHQ enforces the technical controls; it cannot supply your justification.

In practice, for the B2B outreach this product is built for, that basis is normally legitimate interest, plus the marketing rules that sit on top of it:

  • UK and EU email and SMS — PECR and the ePrivacy Directive. Corporate subscribers (limited companies, LLPs, public bodies) may generally be emailed without prior consent provided you identify yourself and offer an opt-out every time. Sole traders and unincorporated partnerships are treated as individuals and normally require consent. CallHQ records legal form where it can determine it, so you can filter on it — but the decision is yours.
  • US calling — the TCPA and state equivalents. CallHQ enforces local calling-hours windows and will not surface a number outside them.
  • Everywhere — an unsubscribe or do-not-call request suppresses that contact across every channel immediately, not just the one it arrived on, and the suppression cannot be overridden by re-importing the record.

These controls fail closed. If CallHQ cannot confirm a send is permitted, it refuses the send rather than allowing it and logging a warning.

Call recording

Call recording is off unless switched on, and the product requires the person placing the call to confirm they have announced the recording before it will start. Where a jurisdiction requires all-party consent, meeting that requirement is the caller's responsibility — the announcement checkbox is a control, not a legal opinion.

Recordings are stored on operator-controlled infrastructure. A retention period can be configured, after which recordings are deleted automatically. If no retention period is configured, recordings are kept indefinitely — we state that plainly rather than implying a default that does not exist, and we recommend setting one.

Who else sees the data

A current list of every third party that can process personal data on our behalf, what each one does and what it can see, is kept at the sub-processor register.

Several are optional: they are only engaged if you connect your own account. If you never connect an enrichment provider, no prospect data reaches one.

A structural point worth knowing: the CallHQ application holds no third-party API credentials at all. Vendor keys live in a separate self-hosted automation layer, so a compromise of the web application does not hand an attacker your vendor accounts.

International transfers

Some sub-processors are in the United States. Where personal data leaves the UK or EEA, transfers rely on the UK International Data Transfer Addendum and the EU Standard Contractual Clauses, together with the vendor's own supplementary measures.

Primary storage — the database and object storage — is on infrastructure in [hosting region — not yet supplied].

How long we keep things

  • Account data — for as long as your workspace exists, then deleted within 90 days of closure except where we must keep records for tax or legal reasons.
  • Prospect data — for as long as you keep it. You can delete any record at any time, and deleting it deletes it, rather than hiding it.
  • Suppression records — kept indefinitely and deliberately. If someone opts out, the only way to guarantee they are never contacted again is to remember that they opted out. Retaining that minimal record is itself the protection.
  • Call recordings — per the retention period you configure. See above.
  • Audit logs — retained to give administrators a defensible history of who did what.

Security

  • Transport is encrypted end to end; the application refuses to start without its signing secrets.
  • Workspace isolation is enforced at the database client, so cross-tenant reads are not possible by mistake.
  • Passwords are hashed, never stored or logged in the clear. Two-factor authentication is available.
  • Every inbound webhook is signature-verified and fails closed on mismatch.
  • Administrative actions are recorded in an append-only audit trail.

If you believe you have found a vulnerability, report it to [security contact address — not yet supplied]. We will not pursue anyone who reports a genuine issue in good faith and does not access or destroy other people's data.

Your rights

Under UK and EU data protection law you can ask for access to your data, correction, erasure, restriction, portability, and you can object to processing based on legitimate interest. You will never be charged or treated differently for exercising any of them.

If you are a prospect rather than a customer: write to [privacy contact address — not yet supplied] and we will suppress your details across every CallHQ workspace immediately, which stops all further contact through this platform. For anything beyond suppression — a full erasure or an access request — the controller is the customer who holds your record, and we will identify them to you and pass the request on.

Complaints and contact

[registered legal entity — not yet supplied], [registered office address — not yet supplied].

Privacy contact: [privacy contact address — not yet supplied].

If we have not resolved a complaint to your satisfaction you can complain to the UK Information Commissioner's Office at ico.org.uk, or to your local supervisory authority in the EEA.

Questions about this document? Ask through the contact form or the chat widget on any page.