Privacy Policy
Last updated: 6 February 2026
1. Introduction
Every Call Handled ("we", "our", "us") is committed to protecting your privacy and the privacy of your callers. This Privacy Policy explains how we collect, use, store, and protect personal data when you use our AI receptionist service.
We are the data controller for the personal data we process.
2. Information We Collect
From You (Our Customers)
- Name and business name
- Email address
- Phone number
- Payment information (processed securely by Stripe)
- Business type and trade
From Callers (Your Customers)
- Phone number (caller ID)
- Name (if provided during the call)
- Call audio recordings
- Transcripts of conversations
- Enquiry details shared during the call
3. How We Use Your Information
- To provide and operate our AI receptionist service
- To send you call summaries and notifications
- To process payments and manage your subscription
- To improve our AI and service quality
- To provide customer support
- To suggest relevant product features, upgrades and improvements
- To comply with legal obligations
4. Legal Basis for Processing
We process personal data on the following legal bases:
- Contract: To fulfil our service agreement with you
- Legitimate interests: To improve our service and prevent fraud
- Legal obligation: To comply with applicable laws
- Consent: Where explicitly provided (e.g., marketing communications)
5. Call Recordings & Transcripts
We record calls and generate transcripts to provide our service. These are:
- Stored securely using encryption at rest and in transit
- Accessible only to you (the subscriber) and authorized personnel
- Retained for a maximum of 90 days, then automatically deleted
- Used to generate summaries sent to you via email/SMS
6. Data Sharing
We share data with:
- Twilio: Our telephony provider for call handling
- OpenAI and Google: For AI conversation processing
- Stripe: For payment processing
- Amazon Web Services: Our cloud infrastructure provider
- Email providers: To send you notifications
All third-party providers are bound by data processing agreements and comply with applicable data protection laws.
7. International Data Transfers
Some of our service providers are located outside the UK/EEA.
8. Data Security
We implement appropriate technical and organizational measures to protect personal data, including:
- Encryption of data in transit and at rest
- Access controls and authentication
- Regular security assessments
- Staff training on data protection
9. Your Rights
Under UK GDPR, you have the right to:
- Access: Request a copy of your personal data
- Rectification: Correct inaccurate or incomplete data
- Erasure: Request deletion of your data ("right to be forgotten")
- Restrict processing: Limit how we use your data
- Data portability: Receive your data in a portable format
- Object: Object to certain types of processing
- Withdraw consent: Where processing is based on consent
To exercise these rights, contact us at hello@everycallhandled.com
10. Data Retention
- Account data: Retained while your account is active, plus 2 years
- Call recordings: Deleted after 90 days
- Call summaries: Retained for 12 months
- Billing records: Retained for 7 years (legal requirement)
11. Cookies
Our website uses essential cookies for functionality and analytics cookies to understand how visitors use our site. You can manage cookie preferences through your browser settings.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes via email. The latest version will always be available on our website.
13. Contact Us
For any privacy-related questions or to exercise your rights, contact us at:
- All enquiries: hello@everycallhandled.com
You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk