Callkept
Legal

Privacy Policy

Last updated 2 September 2026. Draft prepared for professional legal review; not yet reviewed by a solicitor.

This policy explains how Callkept processes personal data as a controller: data about people who visit our website, use our free audit, receive our business-to-business emails, or hold an account. Where we handle your customers' data on your behalf (missed callers, web enquirers) we act as a processor; see the DPA.

What we collect and why

Automated processing

Our assistants use automated software including language models to classify and answer messages. They identify themselves as automated. No decisions with legal or similarly significant effects on individuals are made solely by automation.

Sharing

We use sub-processors listed on our sub-processors page (hosting, telephony, email, payments, AI models). We do not sell personal data. We may disclose data where required by law.

International transfers

Some sub-processors are outside the UK; transfers are protected by the UK International Data Transfer Agreement / Addendum or adequacy regulations.

Retention

Account data: for the life of the account plus 30 days. Conversation data: 90 days by default (configurable by the account holder). Prospect data: 12 months from collection unless you engage with us or opt out (suppression records are kept permanently so we don't contact you again). Logs: 30 days.

Your rights

You can ask for access, rectification, erasure, restriction, portability, and object to processing, including to direct marketing at any time (every email has an unsubscribe link; or email callkept@maib.io). You can complain to the ICO (ico.org.uk).

Security

Encryption in transit, encrypted secrets, access controls, tenant isolation, audit logging, backups. No system is perfectly secure; we will notify affected parties of breaches as the law requires.

Contact

callkept@maib.io. Callkept, United Kingdom.

Privacy Policy · Callkept