legal
Sub-processors
Every third party that can touch personal data on our behalf, what each one does, and exactly what it can see. This is the list your procurement team will ask for.
Version 1.0 · last updated 2026-08-09
Draft — not yet in force
These documents are complete in substance but still need 9 facts only the operator can supply: registered legal entity, company number, registered office address, privacy contact address, security contact address, support contact address, ICO registration number, governing law, hosting region. Until those are filled in and a solicitor has reviewed them, do not rely on this page or present it to a customer.
How to read this list
Three categories, kept separate because conflating them misstates the relationship:
- Sub-processors receive personal data that you put into CallHQ and process it on our instruction. These are the ones the DPA governs.
- Data sources are public registers we read from. No data of yours flows to them. They are listed because you should know where your prospect records originate, not because they process anything for us.
- Self-hosted components run on infrastructure the operator controls. They are not third parties, and they are listed so you do not assume a SaaS vendor is involved where none is.
6 of the sub-processors are optional — engaged only if you connect your own account. Connect none and no prospect data leaves the platform except through the channel you are actually sending on.
Sub-processors
| Provider | What it does | What it can see | Where |
|---|---|---|---|
| Telnyx | Places and receives calls, sends SMS, and looks up line type for numbers you dial. | Prospect phone number, call metadata (time, duration, disposition), call audio where recording is enabled, SMS content. | United States and EU, depending on the number's region. |
| Instantlyonly if you connect it | Sends cold email sequences on your behalf. | Prospect email address, name, company, and the message body you send. | United States |
| Postmark | Sends transactional email — password resets, invitations, notifications. | Your users' email addresses and names. Not prospect data. | United States |
| HeyReachonly if you connect it | Sends LinkedIn connection requests and messages. | Prospect LinkedIn profile identifier and message content. | European Union |
| Reoononly if you connect it | Verifies whether an email address is deliverable before you send to it. | Prospect email address only. | United States |
| Apolloonly if you connect it | Supplies additional contact and company detail for a prospect. | Prospect name, company, role, and business contact details. | United States |
| Anthropiconly if you connect it | Classifies inbound replies, drafts suggested responses, writes research columns and summarises calls. | The text of inbound replies, prospect business details, and call transcripts where transcription is enabled. | United States |
| ElevenLabsonly if you connect it | Generates synthetic speech for voicemail drops and video narration. | The script text you supply. No prospect identifiers unless you place them in the script. | United States |
| Stripe | Takes payment for your CallHQ subscription. | Your billing contact and payment details. Card numbers go directly to Stripe and are never stored by CallHQ. | United States and European Union |
Where records come from
CallHQ builds prospect records from public sources rather than a bought or rented database. Nothing of yours is sent to any of these.
| Provider | What it does | What it can see | Where |
|---|---|---|---|
| OpenStreetMap | A public map database CallHQ reads to find local businesses. | Publicly listed business name, address and category. No customer data is sent. | Public register. |
| Companies House | The UK statutory register, read to confirm a company's legal form and status. | Publicly filed company information. No customer data is sent. | United Kingdom — public register. |
| Google Maps | A public business listing source, read for business details and reviews. | Publicly listed business name, address, phone number, opening hours and reviews. No customer data is sent. | Public listing. |
Self-hosted components
Worth stating explicitly: the CallHQ application holds no third-party API credentials. Vendor keys live in a separate self-hosted automation layer, so compromising the web application does not expose your vendor accounts.
| Provider | What it does | What it can see | Where |
|---|---|---|---|
| PostgreSQL (self-hosted) | The primary database. Every tenant's records are scoped so one tenant cannot read another's. | All customer and prospect data. | Operator-controlled infrastructure. |
| SeaweedFS (self-hosted) | Object storage for call recordings and generated media. | Call audio, transcripts, rendered video. | Operator-controlled infrastructure. |
| Cal.com (self-hosted) | Meeting booking and availability. | Attendee name, email, and meeting time. | Operator-controlled infrastructure. |
| Twenty CRM (self-hosted) | Mirrors deals and contacts so pipeline state is queryable outside CallHQ. | Prospect company, contact and deal records. | Operator-controlled infrastructure. |
| n8n (self-hosted) | Runs the automation workflows. Vendor API keys live here rather than in the application, so the app itself holds no third-party credentials. | Prospect name, company, email, phone and message content, in transit to whichever vendor a workflow calls. It brokers every outbound integration, so it can see any field those integrations carry. | Operator-controlled infrastructure. |
Changes
We give at least 30 days' notice before adding or replacing a sub-processor that handles your data. If you object on reasonable data protection grounds, the DPA gives you the right to terminate the affected part of the service with a pro-rata refund. You will not be locked into a change you object to.