This Privacy Policy explains how CallGuard AI ("we", "us", "our") collects, uses, shares and safeguards personal data. It applies to our website at callguardai.co.uk, our SaaS platform, and any related services (together, the "Services").
We act as the data controller for personal data we collect about visitors and prospects (for example, people who request a demo, and people at relevant firms we contact about CallGuard AI). We act as the data processor for personal data our customers upload or stream into the Services on behalf of their own end-users (e.g., call recordings of conversations between our customer's agents and their customers). The two roles are kept separate throughout this policy.
Contents
1. Who we are
CallGuard AI is an AI compliance scoring platform for customer conversations, operated by CallGuard AI Ltd, a company registered in England and Wales (company number 17279006, registered office at 106 Haytor Avenue, Paignton, England, TQ4 7TB). You can contact us at privacy@callguardai.co.uk for any privacy-related question.
We are registered as a data controller with the UK's data protection regulator, the Information Commission (which took over from the Information Commissioner's Office, the ICO, on 30 September 2026), registration number ZC177601. If you are not satisfied with how we handle your data, you can complain to us (see Your rights), and you have the right to complain to the Information Commission at ico.org.uk/make-a-complaint.
2. What data we collect
When you visit our website or contact us (we are the controller)
- Identity and contact data: name, work email, employer, job title, phone number when you submit a demo request, sign up for an account, or email us, and anything you tell us in a demo request form.
- Technical data: IP address (logged transiently for abuse prevention), browser type, time of visit. With your consent, we use Google Analytics to understand how visitors use this website (see Cookies and tracking); we do not run advertising pixels or behavioural ad trackers.
- Communication data: the content of emails and meeting notes when you correspond with us.
- Where a request came from: when you use the form on our website to ask for a demo or a template, we also record the page you sent it from, the button you used, and any campaign tags in the link you arrived by, such as utm_source (see Cookies and tracking). For a request sent from our app, we record only that it came from the app. We use this to see which pages and campaigns lead to enquiries.
If we contacted you about CallGuard AI (we are the controller)
If you work in compliance, sales or leadership at a UK protection or mortgage advice firm that is authorised by the FCA or is an appointed representative, we may contact you about CallGuard AI because it is relevant to your role. We contact people by email and LinkedIn. We don't make marketing calls unless you ask us to call you. If we ever call without being asked, we first check the number against the Telephone Preference Service and Corporate Telephone Preference Service registers, no more than 28 days before the call.
- What we hold: your name, job title, employer, work email address, work phone number and LinkedIn profile address; when and where we got them; and a record of our contact with you (what we sent, your replies and any objection).
- What we don't use: we don't look for or use personal email addresses, personal mobile numbers, home addresses, or anything from your personal social media, unless you give them to us yourself, and we remove any we find from our contact records.
- Where it comes from: your firm's website, LinkedIn (including LinkedIn Sales Navigator), the Companies House register of company directors, business contact data providers (Apollo.io), introductions and referrals, and industry events where the organiser's terms allow it. To make our message relevant, we also use public information about your firm: the FCA Register, Companies House filings, and your firm's website and job adverts.
- Who we contact: people at limited companies, LLPs and other corporate bodies. We don't send marketing emails or LinkedIn messages to sole traders or partners in other partnerships without their consent.
- Our messages: the emails in our outreach sequences are plain text, contain no tracking pixels, and each one links to this notice and tells you how to opt out. If we contact you only on LinkedIn, our first message does the same.
Our lawful basis is legitimate interests: direct marketing to businesses (see section 3). To stop hearing from us, reply "stop" to any of our emails, tell us on LinkedIn, or email privacy@callguardai.co.uk. We stop contacting you and record your objection on our suppression list, which we keep so that we don't contact you again. If you ask us to erase your details, we keep only what we need to recognise you (your email address or LinkedIn profile address) on that list, for the same reason.
When you (a customer) use the Services (we are the processor)
- Account data: names, work emails and roles of users you grant access to. Treated as controller-supplied data.
- Audio recordings: call audio you upload or stream from a dialler. May contain personal data of your end-customers (voice, name, financial details, health data).
- Transcripts and metadata: text transcripts derived from audio, plus call metadata you supply (agent ID, customer ID, date, duration, GPS for field visits).
- Scoring outputs: pass/fail per scorecard item, breach records, coaching briefs, AI-generated insight digests.
- Usage data: logs of which users took which actions in the platform, for security, audit and billing purposes.
3. Why we process it (lawful basis)
Under UK GDPR Article 6 we rely on the following lawful bases:
- Contract: to provide the Services to customers, manage their accounts, and respond to demo and support requests.
- Legitimate interests: to keep the Services secure, prevent abuse, improve product quality, and run direct marketing to businesses, including contacting people at relevant firms who have not contacted us first (see If we contacted you).
- Legal obligation: to comply with UK tax, accounting and law-enforcement obligations.
- Consent: for any optional marketing communications from us, where required.
For audio recordings of end-customers (where we are the processor), the customer is responsible for establishing a lawful basis for capturing and processing those recordings, including any required consent under PECR or equivalent, and for disclosing call recording to their end-customers.
4. How long we keep it
| Category | Retention period |
|---|---|
| Demo and template requests / sales enquiries | 24 months from last contact |
| People we contacted about CallGuard AI who don't engage | Deleted after 12 months without a reply or other engagement. If we add your details but haven't sent you our first message within 30 days, we delete them then |
| People we contacted who engage with us | While we're in touch, then 24 months from our last contact |
| Objections to marketing (our suppression list) | For as long as we carry out marketing, so that we don't contact you again |
| Customer account data | Duration of contract + 7 years (UK statutory minimum for business records) |
| Audio recordings, transcripts, scores (customer data) | Retained while held in the customer's account. Customers can delete calls at any time, and we delete a customer's data within 30 days of a deletion request or contract termination, unless retention is required by law |
| Server access logs, security logs | Retained for operational and security purposes |
| Backups | Automated daily backups, retained 7 days, then overwritten |
5. Who we share it with
We share personal data with service providers who help us deliver the Services or run our business, and in the other cases described in this section. We do not sell personal data to anyone, ever. Our sub-processors for customer data are listed publicly at callguardai.co.uk/sub-processors and include providers of:
- Cloud hosting and infrastructure (AWS), to host the application and store encrypted data at rest.
- Speech transcription (Deepgram), to convert audio recordings into text transcripts.
- AI scoring and analysis (Anthropic / Claude API), to generate scores, breach evidence and coaching from transcripts.
- Transactional email (Resend), to send platform notifications and invoices.
- DNS and edge networking (Cloudflare), for performance and DDoS protection.
For our own sales and marketing, where we are the controller, we also use:
- Sales software (Apollo.io), which holds the details of people we contact about CallGuard AI and of people who ask us for a demo or a template (their name, work email and company), and sends our outreach emails from our own mailboxes.
- Hosting and email delivery (AWS and Resend), which store demo and template requests and deliver them to our team.
- Email and calendar services, which hold the emails we exchange with you and any meeting you book with us.
Messages we exchange on LinkedIn are held by LinkedIn under its own privacy policy. We use an AI service (Anthropic) to research firms and help draft outreach emails. It works from public information about the firm, such as its website, job adverts and the FCA Register. We don't give it your contact details or anything else we hold about you, though a firm's own web pages can name its staff.
We also disclose personal data when required by law (court order, regulatory request) or in connection with a corporate transaction (merger, acquisition), in which case we will require the recipient to honour this Privacy Policy.
6. International transfers
Some of our sub-processors and service providers, including Apollo.io for our sales records, are headquartered outside the UK and may process data in the United States or other regions. Where such transfers occur, we rely on one of the safeguards UK data protection law provides:
- UK adequacy regulations, including the UK Extension to the EU-US Data Privacy Framework where the recipient is certified under it;
- the UK International Data Transfer Agreement (IDTA), or the UK Addendum to the EU Standard Contractual Clauses (SCCs); or
- binding corporate rules.
Data is also encrypted in transit (TLS) and at rest, and we give each provider only the data it needs for its service.
You can request a copy of the relevant transfer mechanism from privacy@callguardai.co.uk.
7. Security
We apply technical and organisational measures appropriate to the risk of the processing, including:
- Encryption in transit: TLS 1.2+ for all client connections and inter-service traffic.
- Encryption at rest: uploaded audio files encrypted with AES-256-GCM. Database disk encryption applied at the cloud-provider level.
- Access control: JWT-based authentication, role-based access, principle of least privilege for all internal access.
- Audit logging: every action that touches customer data is logged with user, timestamp and source IP.
- Regular review: security configurations, dependencies and access permissions are reviewed at least quarterly.
If we discover a personal data breach affecting you, we will notify the Information Commission within 72 hours where required and notify affected customers without undue delay.
8. Your rights
Under UK GDPR you have the following rights, free of charge in most cases:
- Access: get a copy of the personal data we hold about you.
- Rectification: have inaccurate or incomplete data corrected.
- Erasure ("right to be forgotten"): have your data deleted, subject to limited exceptions.
- Restriction: limit how we process your data while a query is resolved.
- Portability: receive your data in a structured, machine-readable format.
- Object: object to processing based on legitimate interests. An objection to direct marketing is absolute: reply "stop" to any of our emails, tell us on LinkedIn, or email us, and we stop.
- Withdraw consent: at any time, where our processing relies on your consent.
- Complain to us: email privacy@callguardai.co.uk if you are unhappy with how we have used your personal data. We will acknowledge your complaint within 30 days, look into it, and tell you the outcome.
- Complain to the regulator: to the Information Commission, or your local supervisory authority.
To exercise any of these, email privacy@callguardai.co.uk. We will respond within one calendar month.
If you are an end-customer of one of our customers (e.g., your call to a financial adviser was recorded and processed in CallGuard AI), you should contact that customer first. We are processing your data on their behalf, so they hold primary responsibility. We will assist them in responding to your request.
9. Cookies and tracking
Strictly necessary cookies. These are required to keep you logged in and to remember your session preferences when you use the application. They are always active and do not require consent.
Analytics cookies (consent-based). With your consent, this website uses Google Analytics 4, provided by Google Ireland Limited, to measure how visitors find and use the site. No analytics cookies are set and no usage data is sent to Google until you accept them via our cookie banner. If you decline, no analytics cookies are stored. You can change your choice at any time using the "Cookie preferences" link in the footer of any page. We enable IP anonymisation and Google Consent Mode, and we do not use Google Analytics for advertising or remarketing.
Campaign tags. If you accept analytics cookies and arrived by a link with campaign tags (such as utm_source), we also keep those tags in your browser's session storage until you close the tab, so that a demo request you send later in the visit can include them. Unless you accept, or if you later withdraw your consent, we don't keep them, and a demo request includes only the tags in the address of the page you send it from.
We do not embed Facebook Pixel, LinkedIn Insight Tag or similar advertising trackers on this website.
10. Children
Our Services are intended for business use and are not directed at individuals under the age of 18. We do not knowingly collect personal data from children. If you believe a child's data has been submitted to us, contact privacy@callguardai.co.uk and we will delete it promptly.
11. Changes to this policy
We may update this Privacy Policy from time to time. The "Last updated" date at the top of this page reflects the most recent change. Material changes will be communicated to active customers via email or in-app notification at least 30 days before they take effect.
12. How to contact us
- Privacy enquiries and rights requests
- privacy@callguardai.co.uk
- General contact
- hello@callguardai.co.uk
- Postal address
- Available on request to privacy@callguardai.co.uk
- UK supervisory authority
- Information Commission (formerly the Information Commissioner's Office) · ico.org.uk · 0303 123 1113