LEGAL · GDPR

GDPR compliance.


Last updated: 3 June 2026.

1. Overview

Every Call Handled ("we", "our", "us") is built to handle calls on behalf of businesses, which means we process personal data with care. We comply with the UK GDPR and the EU GDPR, the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations where they apply.

This page summarises how we meet our obligations. It sits alongside our Privacy Policy (the full detail of what we collect and why) and our Data Processing Agreement (the contractual terms that apply when we process caller data on your behalf).

2. Controller and processor roles

Our role depends on whose data is being processed:

  • Your account data (your name, business details, billing) - we are the controller.
  • Your callers’ data (caller ID, names, recordings, transcripts, enquiry details captured on your behalf) - you are the controller and we act as your processor under the terms of our Data Processing Agreement.

3. Lawful bases for processing

  • Contract: to deliver the service you have signed up for.
  • Legitimate interests: to operate, secure, and improve the service and prevent fraud.
  • Legal obligation: to meet our regulatory and tax duties.
  • Consent: for optional communications and non-essential cookies, which you can withdraw at any time.

4. Your rights

Individuals whose data we process have the right to:

  • access a copy of their personal data;
  • have inaccurate or incomplete data corrected;
  • request erasure (the “right to be forgotten”);
  • restrict or object to certain processing;
  • data portability; and
  • withdraw consent where processing relies on it.

To exercise any of these, email hello@everycallhandled.com. If you are a caller and your enquiry relates to a specific business, we may direct your request to that business as the controller of your data, and assist them in responding.

5. Sub-processors

We use a small number of trusted providers to deliver the service. Each is bound by a data processing agreement:

  • Amazon Web Services - cloud hosting and storage
  • Twilio - telephony and call handling
  • OpenAI, Anthropic, and Google - AI conversation processing
  • Cartesia - speech (text-to-speech) synthesis
  • Stripe - payment processing
  • Email and messaging providers - to deliver summaries and notifications

6. International transfers

We host data in the UK/EEA where practicable. Where a provider processes data outside the UK/EEA, that transfer is protected by an appropriate safeguard - typically the UK International Data Transfer Addendum or the EU Standard Contractual Clauses, together with additional technical measures such as encryption.

7. Retention

  • Call recordings: retained for a maximum of 30 days by default, then deleted. This can be configured down, including to no retention, on request.
  • Call summaries: retained for 12 months.
  • Account data: retained while your account is active, plus 2 years.
  • Billing records: retained for 7 years to meet legal obligations.

8. Security

We apply appropriate technical and organisational measures, including encryption in transit and at rest, access controls and authentication, and regular review. See our Privacy Policy for more detail.

9. Personal data breaches

We maintain procedures to detect, investigate, and respond to personal data breaches. Where we act as your processor, we will notify you without undue delay after becoming aware of a breach affecting your data so you can meet your own reporting obligations.

10. Contact and complaints

For any data protection question, contact hello@everycallhandled.com.

You also have the right to lodge a complaint with the Information Commissioner’s Office (ICO) at ico.org.uk.