Privacy Policy
Last updated: August 2026.
Overview
Callout AI ("we", "us") provides an AI phone-receptionist service for UK small businesses. This policy explains what information we collect, how we use it, and your choices.
Information we collect
- Contact details you give us (name, email, phone, business) via our forms, email, or a demo call.
- Business information you provide to configure your receptionist (services, hours, pricing, service area).
- Basic technical data from visiting this site (e.g. IP, browser) for security and reliability.
Calls we handle on behalf of clients
When we operate the AI receptionist for a client, we process the information callers provide (such as name, number, and the reason for the call) on that client's behalf. The client is responsible for how that information is used and for any call-recording consent required in their area.
WhatsApp messages we handle on behalf of clients
When a client enables WhatsApp, we process the messages their customers send and receive (including phone numbers, message content, and any photos shared) on that client's behalf, through the WhatsApp Business Platform provided by Meta Platforms. The client is the controller of those conversations and we act as their processor. Customers can stop messages at any time by replying STOP, and message data is retained according to the client's settings and deleted on request (see Data Deletion).
Tenant directories synced from a client's repairs platform
Where a client is a letting agent or property manager, they can connect their repairs platform (currently Fixflo) so their AI recognises a tenant who calls in, rather than asking someone to read out an address their agent already holds. When they do, we keep a small directory on that client's behalf, refreshed from their own account: the tenant's name, contact number, property reference and address. We do not copy tenancy dates, email addresses, rent or payment details, contact history, or past repair records.
The client is the controller of that directory and we act as their processor. It is used for one purpose — matching an incoming number to a property during a call — and is never used to contact anyone, never shared between clients, and never sold or used for marketing. Disconnecting the platform from their account deletes the whole directory, as does closing the account, and entries for tenants their platform no longer returns are removed as the directory refreshes.
Urgency flags on a repair
A caller sometimes explains who a repair affects — that there is someone elderly or unwell in the property, that there are small children, that there is no heating or power, or that getting access is difficult. Because those things change how quickly a repair should be handled, the AI records them against the call as one of a fixed set of short labels.
We deliberately record only that priority should be raised, and never why. The AI is instructed never to ask about anyone's health, and the labels cannot hold a condition, a diagnosis, medication or any other health detail — there is a closed list of permitted values and anything else is discarded rather than stored. We do not treat this as special category data and do not seek to collect any. Anything a caller says in their own words stays in the call record held for the client, under that client's own policies.
Systems our clients connect
A client can connect their own business systems — a CRM, a repairs or maintenance platform, a calendar, or a team chat tool. When they do, we send the details captured on a call to that system at their instruction and into their own account: typically the caller's name and number, what they called about, and any address or preferred time they gave.
The client chooses which systems to connect and can disconnect any of them at any time from their account, which stops further transfer immediately. Once information reaches their system it is held under that provider's terms and the client's own policies. The systems available today are Fixflo, Jobber, HubSpot, Zendesk, Slack, Cal.com, Google Calendar and Microsoft Outlook, together with any address a client configures for our outbound webhook.
Google user data (Google Calendar)
This section applies only when a client chooses to connect their Google Calendar to Callout AI from their account dashboard. It sets out exactly what Google user data Callout AI accesses, how we use it, how we store and protect it, how long we keep it, and with whom we share it. Connecting is entirely optional, and the client can disconnect at any time.
What Google user data we access
We request two scopes and use each one only for the purpose stated:
- Read-only calendar access
(
https://www.googleapis.com/auth/calendar.readonly) — used solely to read free/busy information: the start and end times at which the client is already committed, so the AI receptionist can tell a caller which appointment slots are available. We do not read event titles, descriptions, guests, locations, or attachments, and we never download or keep a copy of the client's calendar. We also read the address of the connected calendar once, so the client can see which Google account is linked. - Calendar events access
(
https://www.googleapis.com/auth/calendar.events) — used solely to create, update, and cancel the appointments our AI books during a call. An event we create contains the caller's name and phone number, the service they asked for, and the agreed time.
How we use Google user data
We use it only to provide the user-facing features the client asked for, and for nothing else:
- To check availability while a call is in progress, so the AI can offer the caller a time that is genuinely free.
- To create the appointment on the client's calendar when the caller accepts a time.
- To move or cancel that appointment when the client or the caller asks us to, including when a returning caller reschedules by phone.
- To display the resulting bookings to the client in their own Callout AI dashboard.
How we store and protect Google user data
We store the OAuth refresh token that keeps the connection alive, the address of the connected calendar, and the Google event ID of each appointment we create (the event ID is what lets a returning caller reschedule or cancel that booking by phone). We do not store the contents of the client's calendar.
- All data is transmitted over encrypted HTTPS/TLS connections and is encrypted at rest in our database, which is hosted in the EU.
- The refresh token is held server-side only. It is never sent to a browser, never exposed to client-side code, and never visible to the client's website visitors, to callers, or to any other Callout AI account.
- Every record is scoped to the account that owns it, and access to production systems is limited to a small number of authorised personnel who need it to operate the service.
- The token is excluded from the data export a client can download for themselves, so it cannot be copied out of the system.
How long we keep it, and how to delete it
We keep Google user data only for as long as it is needed for the purposes above. Disconnecting Google Calendar in the dashboard deletes the stored token immediately and ends our access to the calendar. Closing the account deletes the associated booking records. A client may also ask us to delete their data at any time by emailing [email protected] — see Data Deletion. Events we have already created remain on the client's own Google Calendar under their control; they can delete those in Google Calendar itself.
With whom we share, transfer, or disclose Google user data
We do not sell Google user data, and we do not transfer or disclose it to third parties for any purpose other than the ones described in this policy. Specifically, we disclose it only:
- To the client whose calendar it is — the account owner and any team members they invite, in their Callout AI dashboard and in the email alerts we send them.
- To our infrastructure sub-processors, strictly to deliver the booking feature, acting on our instructions and under contract: Supabase (EU database hosting — stores the connection and the booking records), Cloudflare (hosting and edge compute — transmits the data), LiveKit, Deepgram, ElevenLabs and OpenAI (the live-call stack — an available time the AI offers a caller, for example "Thursday at 2pm is free", passes through them so that it can be spoken aloud), Twilio (carries the phone call itself), and Resend (delivers the confirmation email to the client). These providers may use the data only to perform their part of the service, and we do not permit them to use it to train their models.
- Where the law requires it, or where strictly necessary to detect and investigate fraud, abuse, or a security incident.
No Callout AI employee or contractor reads Google user data except with the client's explicit consent, where necessary for security purposes, or to comply with applicable law.
Uses we expressly prohibit
We never use, and never allow anyone else to use, Google user data for:
- Advertising of any kind, including targeted, personalised, retargeted, or interest-based advertising.
- Selling to data brokers, or providing to information resellers.
- Determining credit-worthiness, or for lending purposes.
- Building or enriching a database or profile beyond what is needed to deliver the client's own bookings.
- Developing, improving, or training artificial-intelligence or machine-learning models. In particular, we do not use Google Workspace APIs, or any data obtained through them, to develop, improve, or train non-personalized AI and/or ML models, and we do not transfer Google user data to any third party for the purpose of training generalized AI or ML models. The AI models used to answer calls process this information only in order to hold that live conversation.
Limited Use disclosure
Callout AI's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Equally, the use and transfer of raw or derived user data received from Google Workspace APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In line with those requirements:
- We limit our use of Google user data to providing or improving the user-facing features that are prominent in our app's interface.
- We transfer it only as necessary to provide or improve those features, to comply with applicable law, or as part of a merger, acquisition, or sale of assets — and in that last case only after notifying the client.
- We do not use or transfer it for serving advertisements.
- We do not allow humans to read it, unless the client gives explicit consent, it is necessary for security purposes such as investigating abuse, it is required to comply with applicable law, or the data has been aggregated and anonymised for internal operations.
If we ever change how our app uses Google user data, we will update this policy and notify affected clients by email before the change takes effect.
How we use information
- To provide, configure, and improve the service.
- To respond to your enquiries and send leads/transcripts to the relevant business.
- For billing and account administration.
Service providers (sub-processors)
We rely on the following trusted processors to deliver the service. They each process data under their own privacy terms and only as needed to provide their part of the service:
- LiveKit (real-time voice infrastructure and call orchestration) — call audio and session metadata
- Deepgram (speech-to-text) — call audio and transcripts
- ElevenLabs (text-to-speech) — the AI's spoken responses
- OpenAI (language model) — call and message transcripts, to generate replies
- Twilio (UK telephony — inbound calls and number provisioning) — caller phone numbers and call metadata
- Meta Platforms (WhatsApp Business Platform — when WhatsApp messaging is enabled) — customer phone numbers and message content
- Supabase (database hosting in the EU) — lead and client records
- Cloudflare (website hosting and edge compute) — basic request metadata for security and reliability
- Resend (transactional email delivery) — email content and recipient addresses
- Stripe (payment processing — when self-serve checkout is enabled) — card and subscription data
- Google (Calendar API, Tag Manager) — only when the client enables calendar booking or website analytics
A current list of sub-processors is available on request — email [email protected].
Cookies & analytics
We use Google Tag Manager and Google Analytics 4 to understand how visitors find and use this site. These set first-party cookies that may include a randomised identifier. We do not run advertising cookies and we do not sell or share your data with advertising networks.
You can opt out of non-essential analytics cookies at any time by using a privacy-focused browser extension or by blocking cookies in your browser settings. Where required by UK or EU law, we ask for your consent before non-essential cookies are set.
Data retention & security
We keep information only as long as needed to provide the service or as agreed with each client, and we delete or anonymise it once that purpose has ended, unless a longer period is required by law. You may ask us to delete your information at any time — see Data Deletion.
Security procedures are in place to protect the confidentiality of your data. All traffic to and from this site and our APIs is encrypted in transit (HTTPS/TLS), stored data is encrypted at rest in our EU-hosted database, credentials and access tokens are held server-side only and are never exposed to a browser, every record is scoped to the account that owns it, and access to production systems is limited to a small number of authorised personnel.
Your rights
You may request access to, correction of, or deletion of your personal information by emailing [email protected].
Changes
We may update this policy from time to time; the latest version will always be posted here.
Who we are (data controller)
Callout AI is the data controller for personal information collected through this site and our service.Callout AI Ltd is registered in England and Wales (company number 17276054), registered office 128 City Road, London, EC1V 2NX, United Kingdom. You also have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk.
Contact
Questions? Email [email protected].
Stop paying for missed calls.
Your AI receptionist goes live in minutes. Answers every call with a natural British voice, captures the lead, and alerts you instantly — 24/7.
From £79/mo · UK phone number included · cancel anytime