Privacy & trust

Callytics Privacy Notice

Last updated: 2 November 2025

Regulatory scope

UK GDPR & DPA 2018

ICO registration ZB933305

Hosting region

United Kingdom

Primary infra + storage

This Privacy Notice was written for callytics.ai and is reviewed regularly so it stays aligned with applicable privacy laws, regulations, and industry guidance.

The purpose of this notice is to explain, in plain language, how Callytics handles personal data across our public website, platform, and supporting services.

  • How we collect and process personal data across the Callytics platform, integrations, and public website.
  • The lawful bases we rely on, retention timelines, and controls that keep your data secure.
  • The subprocessors and regulators we work with, plus how to exercise your data subject rights.
  • The tools available to manage marketing preferences, cookies, and international transfers.

1. Introduction

1.1 We are committed to safeguarding the privacy of our website visitors and service users.

1.2 This policy applies where we are acting as a data controller with respect to the personal data of our website visitors and service users; in other words, where we determine the purposes and means of the processing of that personal data.

1.3 We will ask you to consent to our use of cookies in accordance with the terms of this policy when you first visit our website.

1.4 Our website incorporates privacy controls which affect how we process your personal data. By using these controls, you can specify whether you would like to receive direct marketing communications and limit the publication of your information.

1.5 In this policy, “we”, “us” and “our” refer to Callytics Ltd (“Callytics”).

2. Credit

2.1 This document was created in part by using a template from SEQ Legal (https://seqlegal.com) and has been heavily modified by Callytics to reflect our services, subprocessors, and governance model.

3. How we use your personal data

3.1 This section sets out the categories of personal data we may process, the source of that data, the purposes of processing, and the relevant legal bases.

3.2 Usage data. We may process data about your use of our website and services (“usage data”). This includes IP address, approximate location, browser type and version, operating system, referral source, length of visit, page views, navigation paths, timing/frequency/pattern of service use, and non-sensitive ecommerce events (such as coupons used or checkout interactions). We collect this data via Google Analytics, Google Ads, Meta (Facebook), and Hotjar. Purchase information (for example card data) is never captured by Callytics and is handled exclusively by payment providers such as Stripe and PayPal. Usage data helps us monitor and improve our website and services and is processed under our legitimate interests.

3.3 Account data. We may process account data such as your name and email address, supplied by you or your employer. Account data is used to operate the website, provide services, secure the platform, maintain backups, and communicate with you. The legal basis is consent or the performance of a contract where applicable.

3.4 Profile data. Profile data may include your name, address, telephone number, email address, gender, date of birth, and interests. It is processed to enable and monitor the use of our website and services on the basis of consent.

3.5 Service data. Service data comprises information provided during the use of our services, for example start and end dates, delivery preferences, or dietary and macronutrient requirements supplied by you or your employer. Service data is processed to deliver and secure our services, maintain backups, and communicate with you. The legal basis is consent or, where applicable, contractual necessity.

3.6 Enquiry data. Information contained in enquiries about our goods and/or services (“enquiry data”) is processed to offer, market, and sell relevant services. The legal basis is consent or legitimate interests in responding to business enquiries.

3.7 Transaction data. Information relating to purchases (“transaction data”) may include your contact details and transaction details. Card data is processed only by Stripe or PayPal. Transaction data is processed to supply purchased goods and services, maintain records, and protect our business, relying on contractual necessity and legitimate interests.

3.8 Notification data. If you subscribe to our email notifications or newsletters, we process your email address (“notification data”) to send the requested communications on the basis of consent.

3.9 Correspondence data. Communications you send us (“correspondence data”) may include content and metadata, including that generated by our contact forms. We process correspondence data for communication and record-keeping under our legitimate interests in running the platform and supporting users.

3.10 Legal claims. We may process any personal data identified in this policy where necessary for the establishment, exercise, or defence of legal claims. The legal basis is our legitimate interest in protecting our rights and those of others.

3.11 Risk management. We may process personal data to obtain or maintain insurance coverage, manage risks, or obtain professional advice. The legal basis is our legitimate interest in safeguarding our business.

3.12 Legal obligation and vital interests. We may process personal data where required to comply with legal obligations or to protect vital interests.

3.13 Third party data. Please do not supply us with another person’s personal data unless we have requested it or you have their explicit permission to do so.

3.14 Marketing data. We occasionally use purchased profiled data from accredited opt-in data suppliers for customer acquisition on a legitimate interest basis.

4. Providing your personal data to others

4.1 We may disclose personal data to our insurers and professional advisers where reasonably necessary for obtaining or maintaining insurance coverage, managing risk, seeking professional advice, or establishing, exercising, or defending legal claims.

4.2 Financial transactions relating to our website and services are handled by Stripe and GoCardless. We share transaction data with these providers only as necessary to process payments, issue refunds, and manage complaints. You can read their privacy notices at stripe.com/privacy and gocardless.com/privacy.

4.3 We may disclose personal data where required to comply with a legal obligation, to protect vital interests, or to establish, exercise, or defend legal claims.

5. Retaining and deleting personal data

5.1 Our retention policies help ensure we meet legal obligations while keeping personal data only as long as necessary.

5.2 Personal data processed for any purpose shall not be kept longer than required for that purpose.

5.3 We generally retain data as follows:

  • Usage data: retained until the related account is deleted.
  • Account data: retained until the related account is deleted.
  • Profile data: retained until the related account is deleted.
  • Service data: retained until the related account is deleted.
  • Enquiry data: retained for two years.
  • Transaction data: retained until the related account is deleted.
  • Notification data: retained until you unsubscribe.
  • Correspondence data: retained until the related account is deleted.

5.4 We may retain personal data beyond these periods where required to comply with legal obligations or to protect vital interests.

6. Amendments

6.1 We may update this policy by publishing a new version on our website.

6.2 You should check this page occasionally to ensure you are happy with any changes.

6.3 We may notify you of changes via email or through the messaging system in our platform.

7. Your rights

7.1 This section summarises the rights you have under data protection law. They are subject to specific conditions and exemptions in law.

  • Right of access
  • Right to rectification
  • Right to restrict processing
  • Right to object to processing
  • Right to data portability
  • Right to complain to a supervisory authority
  • Right to withdraw consent
  • Right to erasure

7.3 You may request confirmation of whether we process your personal data and obtain a copy along with additional information about how it is used. The first copy is free; additional copies may incur a reasonable fee.

7.4 You have the right to have inaccurate personal data rectified and incomplete data completed.

7.5 In some circumstances you may request erasure of your personal data. Exceptions apply, for example where processing is necessary for freedom of expression, legal compliance, or legal claims.

7.6 You may request that we restrict processing in certain situations (such as disputed accuracy or pending objections).

7.7 You may object to processing based on our legitimate interests. We will stop processing unless we can demonstrate compelling legitimate grounds or need the data for legal claims.

7.8 You may object at any time to processing for direct marketing (including profiling), and we will stop processing for that purpose.

7.9 You may object to processing for research or statistical purposes on grounds relating to your situation unless the processing is necessary for reasons of public interest.

7.10 Where processing is based on consent or on contractual necessity and carried out by automated means, you may request to receive your personal data in a structured, commonly used, and machine-readable format, and to have it transmitted to another controller where technically feasible.

7.11 If you believe our processing infringes data protection laws, you can lodge a complaint with the ICO (https://ico.org.uk/make-a-complaint/) or the supervisory authority where you live or work. You can also contact the Callytics Data Protection Officer at dpo@callytics.ai.

7.12 Where processing relies on consent, you may withdraw that consent at any time. Withdrawal does not affect the lawfulness of prior processing.

7.13 You may exercise your rights by contacting us using the details in Section 10 or by using the controls provided inside the Callytics platform.

8. About cookies

8.1 A cookie is a file containing an identifier (a string of letters and numbers) that is sent by a web server to a web browser and stored there. The identifier is sent back to the server each time the browser requests a page.

8.2 Cookies may be “persistent” (stored until their expiry date or until deleted) or “session” cookies (expiring when you close your browser).

8.3 Cookies typically do not contain information that identifies a user, but personal information we store may be linked to information stored in cookies.

9. Managing cookies

9.1 Most browsers allow you to refuse cookies and delete them. Instructions can be found below:

9.2 Blocking all cookies may negatively impact the usability of many websites.

9.3 If you block cookies, some Callytics features may not function correctly.

10. Our details

10.1 This website is owned and operated by Callytics Ltd.

10.2 Callytics Ltd is registered in England and Wales, and our registered office is at 207 Knutsford Road Grappenhall, Warrington, Cheshire, United Kingdom, WA4 2QL.

10.3 You can contact us by post at the address above, via the contact form on our website, or by emailing dpo@callytics.ai.

11. Data protection officer

11.1 Our Data Protection Officer can be contacted using the details in Section 10. For urgent privacy matters, please email dpo@callytics.ai.

© 2026 Callytics Ltd. All rights reserved. ICO: ZB933305 · VAT: GB492363375