1. Who we are
Call Register provides a shared communications register for small businesses and teams. For account administration, service operation and billing, the intended data controller is Call Register Ltd.
Privacy enquiries and requests can be sent to privacy@callregister.uk. This address must be confirmed as active before launch.
2. Our role and your company’s role
Call Register is the controller for information needed to create and manage accounts, provide support, operate subscriptions, protect the service and communicate with administrators.
The customer company is normally the controller for personal information its users enter about callers, customers, suppliers, staff or other contacts. Call Register handles that information on the customer company’s instructions as its service provider. Users should only enter information their company is entitled to record.
3. Information we handle
- Account details, including names, email addresses, company name, role and authentication identifiers.
- Team and invitation details, including invited email addresses and membership status.
- Communications register content entered by users, including caller/contact details, telephone numbers, email addresses, notes, assignments, follow-up dates and completion history.
- To-Do information entered by users.
- Partner affiliation and branding settings where an account joins through a branding partner.
- Plan, trial and subscription information. Payment card details are intended to be handled by the payment provider rather than stored by Call Register.
- Technical information needed for security, diagnostics, syncing and service operation, such as timestamps, device/browser information, authentication records and error logs.
- Messages sent to support.
4. Why we use information
| Purpose | Typical lawful basis |
|---|---|
| Create accounts, authenticate users and provide Call Register | Performance of a contract and steps requested before a contract |
| Store and sync customer-entered register information | Customer instructions; the customer company determines its own lawful basis |
| Protect accounts, prevent misuse and maintain service security | Legitimate interests in operating a safe and reliable service; legal obligation where applicable |
| Administer trials, subscriptions, payments and service messages | Performance of a contract and legitimate interests |
| Respond to support and privacy requests | Performance of a contract, legitimate interests and legal obligation where applicable |
| Meet tax, accounting, regulatory or legal requirements | Legal obligation |
5. Who information may be shared with
Information may be shared only where needed with service providers supporting hosting, databases, authentication, file storage, email delivery, payments, security and professional advice. These currently include services supplied through Google Firebase and, when live payments are enabled, Stripe. We may also disclose information when required by law or to protect legal rights.
Branding partners do not receive access to customer calls, To-Dos or team operational data merely because their branding appears on an account. They may receive limited programme-level information such as whether an invitation was used or aggregate join totals, where this is explained and permitted.
We do not sell personal information.
6. International processing
Some technology providers may process information outside the UK. Where this occurs, appropriate UK data protection safeguards must be used, such as UK adequacy regulations or approved contractual protections.
7. How long information is kept
Account and service information is kept while the account is active and for a reasonable period afterwards for security, recovery, dispute, accounting and legal purposes. Customer-entered communications are retained according to the customer company’s instructions and the service’s no-delete/audit design. The final operational retention schedule will be documented before paid launch.
Action before launch: set and record definite retention periods for closed accounts, backups, security logs, support records and billing records.
8. Security
Call Register uses account authentication, access controls, database and storage security rules, restricted team membership and encrypted network connections. No online system can guarantee absolute security, so account holders must protect passwords, remove former users promptly and contact us if they suspect unauthorised access.
9. Your rights
Depending on the circumstances, individuals may have rights to be informed, access their personal information, correct it, have it erased, restrict or object to its use, and receive portable information. Where the information was entered by a customer company, the request may need to be handled by that company as controller.
You may also complain to the UK Information Commissioner’s Office at ico.org.uk.
10. Cookies and device storage
Call Register uses essential browser/device storage for authentication, security, app operation, offline resilience and user-requested functions. See our Cookie Information. We do not currently use optional analytics or advertising cookies on the Call Register site.
11. Changes
We will review this policy as the service develops and show a revised date when it changes. Material changes should also be brought to account administrators’ attention.