Skip to content
Callwright
How it worksPricingContact
Sign inTalk to us
Menu ⌄
How it worksPricingContactSign inTalk to us

Legal documents

  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Client agreement summary
  • Data Processing Addendum

Data Processing Addendum

Last updated 11 September 2026

This page describes how we handle data for a client and forms part of the written agreement a client signs. It is not legal advice; a client should take its own advice before relying on it.

1. Who Decides What

Where we answer calls on a client's phone line, or hold the records of those calls, the client decides what is collected and why. In data protection language the client is the controller and Callwright is its processor: we act on the client's instructions.

For our own website and the accounts on it, we decide, and our Privacy Policy covers that instead. The client agreement summary describes the agreement this page belongs to.

2. What We Process for a Client

On the client's behalf we process:

  • the phone numbers of people who call the client's business;
  • the transcript of each call, and what the call was about;
  • what was booked or requested, including a name, an address and a preferred time;
  • a link to the call recording, where the client has turned recording on;
  • the client's own business details and the settings it gives us; and
  • credentials for the client's scheduling software, where the client has connected it.

The people this data is about are the client's callers and the client's own staff who use our portal. We are not authorised to process health data or other special categories, and we do not serve medical, dental or other health businesses.

3. What We Use It For

We process this data only to run the service the client asked for, and to fix it when it goes wrong. We do not sell it, we do not use it to advertise, and we do not share it with anyone outside the list in section 4. If a client instructs us in writing to do something different, we follow that instruction or tell them we cannot.

4. The Companies That Handle Data for Us

A client agrees in advance that we may use the providers below to deliver the service. Each one is bound to protect the data and to use it only for the purpose named here.

ProviderWhat it doesLocation
VercelHosts our website and application, and stores files attached in the client portal.United States
NeonThe database: call records, bookings, accounts and enquiries.United States
ResendDelivers our email, including the summary sent to an owner after a call.United States
Retell AIThe voice platform: carries the call audio and holds recordings where recording is on.United States
OpenAIThe language model behind Retell that runs the conversation. Today GPT-4.1, selected through Retell; the provider may change.United States
LiveKitCarries the audio of a test call made from a web browser.United States
GoogleSign-in, for anyone who signs in with Google; and Google Workspace, which hosts our own mailboxes.United States
The client's scheduling softwareWhere the client has connected it (for example Jobber), a booking taken on a call is pushed into the client's own account.United States

If we want to add a provider to this list, we will email the client at least 30 days before we start using it.

5. Security

These are the measures we actually take:

  • data is encrypted in transit (TLS) between every system involved;
  • account passwords are stored only as bcrypt hashes;
  • credentials for a client's connected scheduling software are encrypted with AES-256-GCM before they are stored;
  • what a person can see is limited by their role on the account;
  • requests arriving from the voice platform are rejected unless their signature matches the exact bytes we received;
  • our own forms are protected against cross-site request forgery; and
  • where a client asks us not to keep transcripts, the voice platform is instructed to keep no transcript, recording or log of that line on its own side; where recording is off, we store no link to a recording.

We take no payments online and hold no card details. No system is perfectly secure.

6. How Long We Keep It

Recordings and transcripts are kept for 90 days by default and are then deleted automatically. A client can ask for a shorter period, or for no recording at all. Other records — the client's settings, bookings and the business details we hold — are kept for as long as we work together, and deleted on request afterwards. When an agreement ends we delete recordings within 30 days.

7. Requests from Callers

If someone who called a client's business contacts us asking to see or delete their data, we tell the client, acknowledge the request, and act on the client's instruction. We will help a client answer such a request with whatever we hold.

8. If Something Goes Wrong

If we confirm a breach affecting a client's data, we will tell that client without undue delay, and say what happened, whose data was involved as far as we know it, what it means and what we are doing about it.

9. Where the Data Is

Everything stays in the United States. We are an Arizona business, and every provider in section 4 processes the data there. If that ever changes we will say so here and tell our clients first.

10. Deletion at the End

When an engagement ends, we delete the personal data we hold on the client's behalf, or return it first if the client asks. If the law requires us to keep something, we keep it protected in the same way for as long as we have to.

11. Contact

Anything about this page or the data we hold: privacy@callwright.ai.

Callwright

AI phone answering for local businesses.

hello@callwright.ai

Callwright

How it worksPricingContactSign in

Legal

PrivacyTermsCookiesService agreementData processing

© 2026 Callwright. All rights reserved.