legal

Sub-processors

Every third party that can touch personal data on our behalf, what each one does, and exactly what it can see. This is the list your procurement team will ask for.

Version 1.0 · last updated 2026-08-09

Draft — not yet in force

These documents are complete in substance but still need 9 facts only the operator can supply: registered legal entity, company number, registered office address, privacy contact address, security contact address, support contact address, ICO registration number, governing law, hosting region. Until those are filled in and a solicitor has reviewed them, do not rely on this page or present it to a customer.

How to read this list

Three categories, kept separate because conflating them misstates the relationship:

  • Sub-processors receive personal data that you put into CallHQ and process it on our instruction. These are the ones the DPA governs.
  • Data sources are public registers we read from. No data of yours flows to them. They are listed because you should know where your prospect records originate, not because they process anything for us.
  • Self-hosted components run on infrastructure the operator controls. They are not third parties, and they are listed so you do not assume a SaaS vendor is involved where none is.

6 of the sub-processors are optional — engaged only if you connect your own account. Connect none and no prospect data leaves the platform except through the channel you are actually sending on.

Sub-processors

ProviderWhat it doesWhat it can seeWhere
TelnyxPlaces and receives calls, sends SMS, and looks up line type for numbers you dial.Prospect phone number, call metadata (time, duration, disposition), call audio where recording is enabled, SMS content.United States and EU, depending on the number's region.
Instantlyonly if you connect itSends cold email sequences on your behalf.Prospect email address, name, company, and the message body you send.United States
PostmarkSends transactional email — password resets, invitations, notifications.Your users' email addresses and names. Not prospect data.United States
HeyReachonly if you connect itSends LinkedIn connection requests and messages.Prospect LinkedIn profile identifier and message content.European Union
Reoononly if you connect itVerifies whether an email address is deliverable before you send to it.Prospect email address only.United States
Apolloonly if you connect itSupplies additional contact and company detail for a prospect.Prospect name, company, role, and business contact details.United States
Anthropiconly if you connect itClassifies inbound replies, drafts suggested responses, writes research columns and summarises calls.The text of inbound replies, prospect business details, and call transcripts where transcription is enabled.United States
ElevenLabsonly if you connect itGenerates synthetic speech for voicemail drops and video narration.The script text you supply. No prospect identifiers unless you place them in the script.United States
StripeTakes payment for your CallHQ subscription.Your billing contact and payment details. Card numbers go directly to Stripe and are never stored by CallHQ.United States and European Union

Where records come from

CallHQ builds prospect records from public sources rather than a bought or rented database. Nothing of yours is sent to any of these.

ProviderWhat it doesWhat it can seeWhere
OpenStreetMapA public map database CallHQ reads to find local businesses.Publicly listed business name, address and category. No customer data is sent.Public register.
Companies HouseThe UK statutory register, read to confirm a company's legal form and status.Publicly filed company information. No customer data is sent.United Kingdom — public register.
Google MapsA public business listing source, read for business details and reviews.Publicly listed business name, address, phone number, opening hours and reviews. No customer data is sent.Public listing.

Self-hosted components

Worth stating explicitly: the CallHQ application holds no third-party API credentials. Vendor keys live in a separate self-hosted automation layer, so compromising the web application does not expose your vendor accounts.

ProviderWhat it doesWhat it can seeWhere
PostgreSQL (self-hosted)The primary database. Every tenant's records are scoped so one tenant cannot read another's.All customer and prospect data.Operator-controlled infrastructure.
SeaweedFS (self-hosted)Object storage for call recordings and generated media.Call audio, transcripts, rendered video.Operator-controlled infrastructure.
Cal.com (self-hosted)Meeting booking and availability.Attendee name, email, and meeting time.Operator-controlled infrastructure.
Twenty CRM (self-hosted)Mirrors deals and contacts so pipeline state is queryable outside CallHQ.Prospect company, contact and deal records.Operator-controlled infrastructure.
n8n (self-hosted)Runs the automation workflows. Vendor API keys live here rather than in the application, so the app itself holds no third-party credentials.Prospect name, company, email, phone and message content, in transit to whichever vendor a workflow calls. It brokers every outbound integration, so it can see any field those integrations carry.Operator-controlled infrastructure.

Changes

We give at least 30 days' notice before adding or replacing a sub-processor that handles your data. If you object on reasonable data protection grounds, the DPA gives you the right to terminate the affected part of the service with a pro-rata refund. You will not be locked into a change you object to.

Questions about this document? Ask through the contact form or the chat widget on any page.