Privacy Policy

Last updated August 2026

This policy covers the personal data that passes through CallsPicked. It has two halves, because we hold two different kinds of data and we are not in the same role for both. Read the next section first: it decides which of the rest applies to you. For any privacy question, email hello@callspicked.com.

Which role we are in

  • Your business's own data: we are the controller. Your account and business details, your billing, anyone who asks us for a demo, anyone who enquires and does not sign up, and visits to this website. We decide why and how that data is used, and this policy is the whole answer for it.
  • Your customers' data: we are your processor. The people who ring you, text you, message your social accounts and get booked into your diary. You are the controller for them. We act only on your instructions, under the Article 28 processor terms in the Terms of Service. We do not use that data for our own purposes, we do not sell it, and we do not train AI models on it.
  • If you rang a business that uses us. We hold the transcript of that call on their behalf, not on our own. Ask them, and we will do the work so they can answer you inside the month the law gives them.

What we collect

As controller, for our own purposes:

  • Account and business details you give us: your name, business name, contact details, opening hours, services and prices.
  • Billing: your plan and its status. Card details go straight to Stripe and we never hold them.
  • Demo requests: the number you enter for a call back, and whatever you tell us on that call or in an enquiry.
  • Website usage: only if you accept cookies. What that means exactly is on the cookie page.

As your processor, on your instructions:

  • Call data: caller phone numbers, the transcript of the call and its outcome. We do not keep call audio. The voice service transcribes the call as it happens and stores the text, so there is no recording to play back.
  • Messages: the content of texts, WhatsApp messages, social comments and DMs we handle for you, with the sender's number or handle.
  • Contacts and bookings: your customers' names and contact details, appointments, and the extra details your trade records, such as a pet's name and breed.
  • Connected accounts: when you connect Instagram, Facebook, TikTok, WhatsApp or your calendar, we access only what is needed to post, reply and book on your behalf.

Why we use it, and the lawful basis for each purpose

These are the purposes we are the controller for. Each one names the basis in Article 6 of the UK GDPR that we rely on.

  • Running the service you signed up for, setting you up and supporting you. Basis: performance of our contract with you.
  • Taking your subscription payment. Basis: performance of our contract. Keeping the accounting records behind it. Basis: our legal obligation.
  • Calling you back when you ask for a demo, and following up on that enquiry afterwards. Basis: steps taken at your request before a contract, for the call itself. Our legitimate interest in following up an enquiry you started, for the follow-up. Tell us to stop and we stop.
  • Keeping the service secure and available: request logs, abuse and fraud prevention, and diagnosing faults. Basis: our legitimate interest in a service that stays up and is not abused.
  • Improving the service: which features get used, and looking at what went wrong on a call you report to us. Basis: our legitimate interest in a product that works. We do not train AI models on your data or your customers' data.
  • Measuring how this website is used. Basis: your consent, given or refused on the cookie banner and changeable at any time.
  • Meeting our own legal duties and establishing or defending legal claims. Basis: our legal obligation, and our legitimate interest in defending ourselves.

Where we rely on a legitimate interest you can object, and we will stop unless we have compelling grounds not to. For your customers' data we are the processor, so the lawful basis for that processing is yours to choose as the controller. We do not pick one for you, and we act on your instructions.

Where the data sits

Your database is Supabase in Ireland (eu-west-1). The website and your dashboard are served by Vercel from Dublin (dub1). The voice service that answers your calls runs on Fly in London (lhr). So the three places your data is stored and served from are Ireland, Ireland and the United Kingdom. Other providers we use are elsewhere, and the next section says which and on what basis.

Sending data outside the UK

Some of our providers are outside the UK, and we would rather name them than describe the whole list with one sweeping sentence.

  • Ireland is covered by the UK's adequacy regulations for the EEA, so the data held there by Supabase and Vercel needs no further safeguard.
  • The United States. OpenAI, Twilio, Stripe, Firecrawl, Google Analytics and Microsoft Clarity process there. For each of them we rely on the UK Addendum to the EU Standard Contractual Clauses in that provider's data processing terms.
  • Support access. Supabase, Vercel and Fly are US companies even though the machines are in Ireland and London, so their staff can reach that infrastructure to keep it running. The same clauses cover that access.
  • Zernio, which carries our connection to your social and WhatsApp accounts, has not confirmed which country it processes in. Until it does we treat it as an international transfer rather than print a guess.
  • Services you connect yourself, such as your Google Calendar or your Savvy diary, are systems you already have your own agreement with. We pass data to them at your instruction.

Provider by provider, with what each one touches and where, is on the sub-processors page. That page is the register and this one does not restate it, so the two cannot drift apart.

How long we keep it

These are the periods we work to, and they are maximums rather than targets.

  • Call transcripts: 12 months from the date of the call, then deleted.
  • Texts, WhatsApp messages, DMs and comments: 24 months from the date of the message, then deleted. They run longer than transcripts because a message thread is the running history of a customer relationship, not a single event.
  • Demo leads: 6 months. The number you give us for a call-back demo, and the notes from it. This one has no exceptions: if you go on to become a customer, your account is a separate record with its own retention, and the demo lead still goes.
  • Unconverted prospects: 6 months from our last contact with you. If an enquiry never becomes an account, it goes.
  • Your account, settings and contacts: while you are a customer. When your plan ends, the Terms of Service govern: tell us to export or delete and we do it within 30 days, and until you tell us we keep it so nothing is lost if you come back.
  • Billing records: 6 years, because tax law requires us to keep them. That is the invoice trail, not your call or message content.
  • Analytics cookies: only if you accepted them, and to the lifetimes set out on the cookie page.

Erasure and export, on request

You do not have to wait for the periods above. Ask us to delete your data, or to send you a copy of it, and we will do it free of charge and within one month. Email hello@callspicked.com. The owner on an account can also download the whole account from Settings without asking us, and can schedule the account for deletion there, which runs after a short grace period so it cannot happen by accident. If one of your own customers asks you for erasure or a copy, send it to us and we will do the work so you can answer them in time.

Your rights

You can ask for access to your data, correction of it, erasure, restriction of what we do with it, or a portable copy, and you can object to processing we base on a legitimate interest. Where we rely on consent, you can withdraw it without affecting what was done before. To use any of these, email hello@callspicked.com. If we get it wrong, you can complain to the UK Information Commissioner's Office at ico.org.uk, though we would rather you gave us the chance to fix it first.

What the AI decides

Oma answers calls, drafts replies and books appointments. None of that is a decision taken solely by automated means with a legal or similarly significant effect on anyone: the business sets what it may do, can change or undo any of it, and public social replies are drafted for approval before they go out.

How we keep it safe

Connections are encrypted, each business's records are separated in the database by row-level security, incoming requests from our telephony and social providers are signature-checked, the database in Ireland is encrypted at rest, and credentials live in our hosting platforms' secret stores rather than in the code. The full list, which we owe you contractually as your processor, is in the Terms of Service.

If this policy changes

The date at the top of this page changes with it. If a change matters to your account, such as a new retention period or a new country, we will email the owner on the account rather than leave you to notice.

Contact

CallsPicked · hello@callspicked.com

Oma answers our phone too

07380 307044

Call now