Call Covered

Legal

Data Processing Terms

Version dated 30 August 2026

These terms describe the controller and processor responsibilities for the Call Covered service. They apply only when incorporated into a customer's order form or service agreement.

1. Scope and application

These Data Processing Terms apply where they are incorporated into an order form or service agreement between CALLCOVERED LIMITED (Call Covered) and a business customer, and Call Covered processes personal data on that customer's behalf.

The customer is normally the controller of personal data relating to people who call its business. Call Covered acts as processor for that call data. Each party remains responsible for personal data it processes as an independent controller, such as its own business-contact and billing records.

2. Processing details

The processing enables the AI receptionist to answer calls, record and transcribe calls, create summaries, capture enquiries, route urgent requests, send notifications, and provide account support and reporting.

Data may include caller names, telephone numbers, voice recordings, transcripts, summaries, enquiry details, appointment or job requests, location or postcode, call metadata, and instructions supplied by the customer. Data subjects are callers, customer personnel, and other people whose details are included in an enquiry.

3. Customer instructions and responsibilities

Call Covered will process customer call data only on documented instructions, including the service agreement, order form, approved call scripts, routing rules, and lawful support requests, unless UK law requires otherwise.

The customer is responsible for having a lawful basis, giving callers appropriate privacy information, approving accurate scripts, limiting collection to what is necessary, responding to data-subject requests, and not using the service for unlawful, emergency, medical, health, or other special-category-data use cases unless separately approved in writing.

4. Confidentiality and security

Call Covered will ensure people authorised to process customer data are bound by confidentiality and will maintain proportionate technical and organisational safeguards for access control, transmission, storage, service continuity, incident handling, and secure deletion.

The customer must protect its account credentials, restrict dashboard access, and notify Call Covered promptly of suspected unauthorised access.

5. Subprocessors and international transfers

The customer authorises Call Covered to use subprocessors needed to provide hosting, databases, telephony, voice AI, model processing, notifications, payments, support, and security. Call Covered will impose data-protection obligations appropriate to each subprocessor's role.

Where personal data is transferred outside the United Kingdom, Call Covered will use an applicable lawful transfer mechanism and any supplementary safeguards reasonably required by UK data-protection law. Material changes to subprocessors will be communicated through the service or by email where reasonably practicable.

6. Assistance and incidents

Taking account of the nature of processing, Call Covered will provide reasonable assistance with data-subject requests, security obligations, data protection impact assessments, regulatory consultations, and information needed to demonstrate compliance.

Call Covered will notify the customer without undue delay after becoming aware of a personal-data breach affecting customer data and will provide available information needed for the customer's assessment and notifications.

7. Retention and deletion

Recordings, transcripts, and call summaries are retained while the customer account remains active so the service can be delivered and the customer can access its call history.

Following termination, Call Covered will delete or irreversibly anonymise customer call data from active systems within 30 days, unless the customer requests an earlier export or deletion, UK law requires retention, or secure backups require a limited additional overwrite period. Any legally retained data will be isolated and used only for that legal purpose.

8. Information and audits

Call Covered will make information reasonably necessary to demonstrate compliance available to the customer. Audits must be proportionate, protect other customers and security information, avoid unnecessary disruption, and normally begin with documentation or independent assurance before an onsite inspection is considered.

9. Priority and contact

If these terms conflict with an agreed data-processing addendum or order form, the specifically agreed document takes priority for that conflict. The remainder continues to apply.

Data-protection enquiries can be sent to kotirobert@callcovered.co.uk. CALLCOVERED LIMITED, company number 17204690, registered office: 48 Endymion Mews, Hatfield, England, AL10 0EW.