LEGAL · PRIVACY

Privacy policy.


Last updated: 29 May 2026.

1. Introduction

Every Call Handled ("we", "our", "us") is committed to protecting your privacy and the privacy of your callers. This Privacy Policy explains how we collect, use, store, and protect personal data when you use our AI receptionist service.

We are the data controller for the personal data we process.

2. Information we collect

From you (our customers)

  • Name and business name
  • Email address
  • Phone number
  • Payment information (processed securely by Stripe)
  • Business type and trade

From callers (your customers)

  • Phone number (caller ID)
  • Name (if provided during the call)
  • Call audio recordings
  • Transcripts of conversations
  • Enquiry details shared during the call

3. How we use your information

  • To provide and operate our AI receptionist service
  • To send you call summaries and notifications
  • To process payments and manage your subscription
  • To improve our AI and service quality
  • To provide customer support
  • To suggest relevant product features, upgrades and improvements
  • To comply with legal obligations

Connected third-party accounts (e.g. Google): information we receive from a third-party account you choose to connect — for example, your Google Calendar — is used only to provide the specific feature you enabled. It is never used for any of the other purposes listed above, including to improve, train or develop AI or machine-learning models, to suggest products or upgrades, or for marketing. See Calendar integration (Google) below.

We process personal data on the following legal bases:

  • Contract: to fulfil our service agreement with you
  • Legitimate interests: to improve our service and prevent fraud
  • Legal obligation: to comply with applicable laws
  • Consent: where explicitly provided (e.g., marketing communications)

5. Call recordings & transcripts

We record calls and generate transcripts to provide our service. These are:

  • Stored securely using encryption at rest and in transit
  • Accessible only to you (the subscriber) and authorized personnel
  • Retained for a maximum of 30 days by default, then automatically deleted
  • Used to generate summaries sent to you via email/SMS

6. Data sharing

We share data with:

  • Twilio: our telephony provider for call handling
  • OpenAI, Anthropic and Google (Gemini): for AI processing of the call conversation itself — this does not include any data from a connected Google Calendar
  • Cartesia: for speech (text-to-speech) synthesis
  • Stripe: for payment processing
  • Amazon Web Services: our cloud infrastructure provider
  • Email providers: to send you notifications
  • Nylas: calendar connectivity (EU region), if you connect a calendar

All third-party providers are bound by data processing agreements and comply with applicable data protection laws.

Calendar integration (Google)

If you choose to connect a Google Calendar so your AI receptionist can check availability and book appointments, we ask Google for permission to read your calendars' free/busy times and to create, view and remove calendar events on your behalf. We request this access only after you explicitly connect your Google account, and you can disconnect it at any time from your dashboard, or revoke it directly at myaccount.google.com/permissions.

We use this Google Calendar data solely to provide the appointment-booking feature: checking when you are free and writing the bookings your callers make. The general uses described in section 3 above do not apply to your Google Calendar data. Specifically, we do not use it for advertising, we do not sell or transfer it to others (except as needed to provide this feature, with your consent, or as required by law), we do not use it to suggest products or for marketing, and we do not use it to train, improve or develop AI or machine-learning models — including any generalised or third-party models.

Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Calendar data is processed transiently to fulfil booking requests and is retained only as long as needed to provide the service; booking records we create are kept under the retention terms described in this policy.

7. International data transfers

Some of our service providers are located outside the UK/EEA.

8. Data security

We implement appropriate technical and organizational measures to protect personal data, including:

  • Encryption of data in transit and at rest
  • Access controls and authentication
  • Regular security assessments
  • Staff training on data protection

9. Your rights

Under UK GDPR, you have the right to:

  • Access: request a copy of your personal data
  • Rectification: correct inaccurate or incomplete data
  • Erasure: request deletion of your data ("right to be forgotten")
  • Restrict processing: limit how we use your data
  • Data portability: receive your data in a portable format
  • Object: object to certain types of processing
  • Withdraw consent: where processing is based on consent

To exercise these rights, contact us at hello@everycallhandled.com.

10. Data retention

  • Account data: retained while your account is active, plus 2 years
  • Call recordings: deleted after 30 days (default)
  • Call summaries: retained for 12 months
  • Billing records: retained for 7 years (legal requirement)

11. Cookies

Our website uses essential cookies for functionality and analytics cookies to understand how visitors use our site. You can manage cookie preferences through your browser settings.

12. Changes to this policy

We may update this Privacy Policy from time to time. We will notify you of significant changes via email. The latest version will always be available on our website.

13. Contact us

For any privacy-related questions or to exercise your rights, contact us at:

You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.