This Privacy Policy explains how CallGuard AI ("we", "us", "our") collects, uses, shares and safeguards personal data. It applies to our website at callguardai.co.uk, our SaaS platform, and any related services (together, the "Services").
We act as the data controller for personal data we collect about visitors and prospects (e.g., people who book a demo). We act as the data processor for personal data our customers upload or stream into the Services on behalf of their own end-users (e.g., call recordings of conversations between our customer's agents and their customers). The two roles are kept separate throughout this policy.
Contents
1. Who we are
CallGuard AI is an AI compliance scoring platform for customer conversations, operated by CallGuard AI Ltd, a company registered in England and Wales (company number 17279006, registered office at 106 Haytor Avenue, Paignton, England, TQ4 7TB). You can contact us at privacy@callguardai.co.uk for any privacy-related question.
We are registered with the UK Information Commissioner's Office (ICO) as a data controller, registration number ZC177601. If you are not satisfied with how we handle your data, you have the right to complain to the ICO at ico.org.uk/make-a-complaint.
2. What data we collect
When you visit our website or contact us (we are the controller)
- Identity and contact data: name, work email, employer, job title, phone number when you submit a demo request, sign up for an account, or email us.
- Technical data: IP address (logged transiently for abuse prevention), browser type, time of visit. With your consent, we use Google Analytics to understand how visitors use this website (see Cookies and tracking); we do not run advertising pixels or behavioural ad trackers.
- Communication data: the content of emails and meeting notes when you correspond with us.
When you (a customer) use the Services (we are the processor)
- Account data: names, work emails and roles of users you grant access to. Treated as controller-supplied data.
- Audio recordings: call audio you upload or stream from a dialer. May contain personal data of your end-customers (voice, name, financial details, health data).
- Transcripts and metadata: text transcripts derived from audio, plus call metadata you supply (agent ID, customer ID, date, duration, GPS for field visits).
- Scoring outputs: pass/fail per scorecard item, breach records, coaching briefs, AI-generated insight digests.
- Usage data: logs of which users took which actions in the platform, for security, audit and billing purposes.
3. Why we process it (lawful basis)
Under UK GDPR Article 6 we rely on the following lawful bases:
- Contract: to provide the Services to customers, manage their accounts, and respond to demo and support requests.
- Legitimate interests: to keep the Services secure, prevent abuse, improve product quality, and run direct B2B marketing to prospects who have shown interest.
- Legal obligation: to comply with UK tax, accounting and law-enforcement obligations.
- Consent: for any optional marketing communications from us, where required.
For audio recordings of end-customers (where we are the processor), the customer is responsible for establishing a lawful basis for capturing and processing those recordings, including any required consent under PECR or equivalent, and for disclosing call recording to their end-customers.
4. How long we keep it
| Category | Retention period |
|---|---|
| Demo requests / sales enquiries | 24 months from last contact |
| Customer account data | Duration of contract + 7 years (UK statutory minimum for business records) |
| Audio recordings, transcripts, scores (customer data) | Retained while held in the customer's account. Customers can delete calls at any time, and we delete a customer's data within 30 days of a deletion request or contract termination, unless retention is required by law |
| Server access logs, security logs | Retained for operational and security purposes |
| Backups | Automated daily backups, retained 7 days, then overwritten |
5. Who we share it with
We share personal data only with sub-processors who help us deliver the Services. We do not sell personal data to anyone, ever. Our current sub-processors are listed publicly at callguardai.co.uk/sub-processors and include providers of:
- Cloud hosting and infrastructure (AWS), to host the application and store encrypted data at rest.
- Speech transcription (Deepgram), to convert audio recordings into text transcripts.
- AI scoring and analysis (Anthropic / Claude API), to generate scores, breach evidence and coaching from transcripts.
- Transactional email (Resend), to send platform notifications and invoices.
- DNS and edge networking (Cloudflare), for performance and DDoS protection.
We also disclose personal data when required by law (court order, regulatory request) or in connection with a corporate transaction (merger, acquisition), in which case we will require the recipient to honour this Privacy Policy.
6. International transfers
Some of our sub-processors are headquartered outside the UK and may process data in the United States or other regions. Where such transfers occur, we rely on:
- UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses (SCCs); and
- Supplementary technical measures including end-to-end encryption in transit and at rest.
You can request a copy of the relevant transfer mechanism from privacy@callguardai.co.uk.
7. Security
We apply technical and organisational measures appropriate to the risk of the processing, including:
- Encryption in transit: TLS 1.2+ for all client connections and inter-service traffic.
- Encryption at rest: uploaded audio files encrypted with AES-256-GCM. Database disk encryption applied at the cloud-provider level.
- Access control: JWT-based authentication, role-based access, principle of least privilege for all internal access.
- Audit logging: every action that touches customer data is logged with user, timestamp and source IP.
- Regular review: security configurations, dependencies and access permissions are reviewed at least quarterly.
If we discover a personal data breach affecting you, we will notify the ICO within 72 hours where required and notify affected customers without undue delay.
8. Your rights
Under UK GDPR you have the following rights, free of charge in most cases:
- Access: get a copy of the personal data we hold about you.
- Rectification: have inaccurate or incomplete data corrected.
- Erasure ("right to be forgotten"): have your data deleted, subject to limited exceptions.
- Restriction: limit how we process your data while a query is resolved.
- Portability: receive your data in a structured, machine-readable format.
- Object: object to processing based on legitimate interests, including direct marketing.
- Withdraw consent: at any time, where our processing relies on your consent.
- Lodge a complaint: with the ICO or your local supervisory authority.
To exercise any of these, email privacy@callguardai.co.uk. We will respond within one calendar month.
If you are an end-customer of one of our customers (e.g., your call to a financial adviser was recorded and processed in CallGuard AI), you should contact that customer first. We are processing your data on their behalf, so they hold primary responsibility. We will assist them in responding to your request.
9. Cookies and tracking
Strictly necessary cookies. These are required to keep you logged in and to remember your session preferences when you use the application. They are always active and do not require consent.
Analytics cookies (consent-based). With your consent, this website uses Google Analytics 4, provided by Google Ireland Limited, to measure how visitors find and use the site. No analytics cookies are set and no usage data is sent to Google until you accept them via our cookie banner. If you decline, no analytics cookies are stored. You can change your choice at any time using the "Cookie preferences" link in the footer of any page. We enable IP anonymisation and Google Consent Mode, and we do not use Google Analytics for advertising or remarketing.
We do not embed Facebook Pixel, LinkedIn Insight Tag or similar advertising trackers on this website.
10. Children
Our Services are intended for business use and are not directed at individuals under the age of 18. We do not knowingly collect personal data from children. If you believe a child's data has been submitted to us, contact privacy@callguardai.co.uk and we will delete it promptly.
11. Changes to this policy
We may update this Privacy Policy from time to time. The "Last updated" date at the top of this page reflects the most recent change. Material changes will be communicated to active customers via email or in-app notification at least 30 days before they take effect.
12. How to contact us
- Privacy enquiries and rights requests
- privacy@callguardai.co.uk
- General contact
- hello@callguardai.co.uk
- Postal address
- Available on request to privacy@callguardai.co.uk
- UK supervisory authority
- Information Commissioner's Office · ico.org.uk · 0303 123 1113