Security & Compliance
Data Protection
What we hold, where it lives, and how to meet UK GDPR obligations.
Running a phone system means processing personal data: numbers called, call times, recordings, voicemail and transcripts. UK GDPR applies to all of it.
What is stored
| Data | Typical purpose |
|---|---|
| Call detail records | Numbers called, timestamps and duration — billing and reporting |
| Recordings | Optional, only if you enable them |
| Voicemail and transcripts | Message delivery and search |
| Account and activity logs | Security, audit and support |
Your responsibilities
- •You are the data controller for your calls; we process on your behalf
- •Tell callers what you record and why
- •Set retention periods and let them run
- •Be able to answer subject access and deletion requests
- •Keep your own staff access under control — every user with dashboard access can see call data
Tools we provide
- •Configurable retention with automatic deletion
- •Card-number redaction in transcripts
- •Per-tenant activity logs showing who accessed what
- •A data processing agreement, available from the legal pages
Deleting a recording removes the audio. Call detail records are retained for billing and legal obligations even after a recording is deleted.