Privacy Policy

Effective date: 29 May 2026  |  Last updated: 20 June 2026

1. Who We Are

CallClinch is a trading name of Andrew Richards, a sole trader based in Nottingham, England.

Contact email: andrew@callclinch.co.uk
Website: callclinch.co.uk

2. What This Policy Covers

This policy explains how CallClinch collects, uses, stores, and protects personal data when you use our website or our AI receptionist and Google review automation services. It also explains your rights under UK GDPR.

3. What Data We Collect

From website visitors:

  • Email address if you contact us directly
  • Basic usage data via Cloudflare (IP address, page views, device type)

From callers to your AI receptionist:

  • Name, phone number, address, postcode
  • Job description and availability preference
  • Audio recording and transcription of the call
  • Call metadata (date, time, duration)

From client businesses (our customers):

  • Business name, contact details, service area
  • Onboarding information provided during setup

We do not intentionally collect special category data (health, financial, or sensitive personal information) through our services.

4. How We Use Your Data

  • To provide the AI receptionist service on behalf of our client businesses
  • To send call summary SMS messages to the relevant business owner
  • To send a brief SMS confirmation, and later a Google review request, to the caller following a completed job
  • To store call records and manage the review request queue
  • To respond to enquiries and provide customer support
  • To operate and improve our services
  • To comply with legal obligations

The legal basis for processing call data is legitimate interests, specifically the legitimate interest of the business in receiving accurate records of customer enquiries. The post-call confirmation message and the Google review request relate directly to a job or enquiry that has just taken place, contain no promotional or advertising content, and on that basis are treated as service messages rather than direct marketing under the Privacy and Electronic Communications Regulations 2003 (PECR).

5. Our Subprocessors

To deliver our services we use the following third-party providers. Each is contractually required to process data only under our instructions and in compliance with UK data protection law.

Provider Purpose Data location
Retell AI AI voice agent platform - manages inbound calls and conversation flow USA
Deepgram Speech-to-text transcription of call audio USA
ElevenLabs Text-to-speech voice synthesis USA
Vonage UK inbound phone number and call routing EU/UK
The SMS Works UK SMS delivery for lead notifications and review requests UK
Supabase Database storage for call records and review queue EU (Ireland)
Railway Backend application hosting and API infrastructure USA
Cloudflare Website hosting and delivery EU / Global CDN

Some providers process data outside the UK and EEA. Where this occurs we rely on Standard Contractual Clauses or adequacy decisions to ensure appropriate protection. This is the same list of subprocessors referenced in Schedule 1 of our Terms of Service.

6. Who We Share Data With

Call data collected on behalf of a business is shared with that business only. We do not sell personal data. We do not share caller data with any third party other than the subprocessors listed above and the client business the call was made to.

We may disclose data to legal authorities if required by law or to protect our legal rights.

7. How Long We Keep Data

Call records and transcriptions are retained for 90 days from the date of the call and then permanently deleted, regardless of whether the client's contract is still active. Review request records are deleted once the request has been sent or cancelled. Client business account data is retained for the duration of the service agreement and deleted within 30 days of termination.

Call recordings and transcripts are stored by Retell AI on our behalf for the same 90-day period before automatic deletion. You can request earlier deletion of your call data at any time by contacting us.

8. Security

We use technical and organisational measures to protect personal data including encrypted data transmission, access controls, and secure EU-region database storage. No method of transmission is completely secure. If you believe your data may be at risk please contact us immediately.

9. Your Rights

Under UK GDPR you have the right to:

  • Access the personal data we hold about you
  • Request correction of inaccurate data
  • Request deletion of your data
  • Object to certain processing
  • Request restriction of processing
  • Lodge a complaint with the ICO at ico.org.uk

To exercise any of these rights contact us at andrew@callclinch.co.uk. We will respond within 30 days.

10. Cookies

This website does not use tracking cookies or advertising pixels. Cloudflare may collect basic anonymised analytics data (page views, device type, approximate location) as part of standard hosting infrastructure. No personal data is collected via cookies on this site.

11. Children

Our services are not directed at children under 13. We do not knowingly collect data from children. If you believe a child has provided us with personal data please contact us and we will delete it promptly.

12. Changes to This Policy

We may update this policy from time to time. The effective date at the top of this page will reflect any changes. We recommend reviewing this page periodically.

13. Contact Us

CallClinch

Email: andrew@callclinch.co.uk

Website: callclinch.co.uk

To make a complaint to the UK Information Commissioner's Office: ico.org.uk