Legal
Privacy policy
AgentDesk listens to phone calls, so it is worth being precise about what is captured, who can see it, and how long it stays.
Who this covers
This policy covers two groups. Customers are the businesses who use AgentDesk to answer their phone line. Callers are the people who ring that line and speak to the agent.
For a customer's own line, the customer decides why calls are answered and what is captured; we process that information on their instructions. For our own website and account records, we decide, and this policy applies directly.
What we collect
From callers: the phone number they call from, the audio of the call where recording is enabled, a written transcript, and the details the agent captures during the conversation — for an acquisitions line that typically means a property address, postcode, tenure, condition, price expectation and the reason for selling.
From customers: name, work email, business name, the phone number issued to the workspace, agent configuration, team members and their roles, API keys, webhook endpoints, and an audit log of who changed what.
Technical records: request logs containing timestamps, IP address, request identifiers and error details, kept for security and troubleshooting.
Why we hold it
To answer calls and pass the enquiry to the customer's desk — the service itself.
To keep accounts secure, prevent abuse, and investigate faults.
To improve accuracy of the agent. We do not use call content to train third-party general-purpose models.
Recording and notice to callers
Where recording is switched on, the agent tells the caller at the start of the call. Callers can ask for a human, and can ask for their recording and transcript to be deleted.
Customers are responsible for making sure recording is lawful for their line and for keeping the notice accurate if they edit the greeting.
How long we keep it
Transcripts and captured details are retained for the retention window set on the workspace. Recordings follow the same window and can be switched off entirely.
Account records are kept while the workspace is active and for a limited period afterwards for legal and accounting reasons. Request logs are kept for a short operational period.
Deleting a workspace removes calls, transcripts, recordings, opportunities and contacts from live systems, and from backups as they age out.
Who we share it with
Suppliers who make the service work: telephony carriage, speech recognition and speech synthesis, cloud hosting, and error monitoring. Each is bound by contract and may only process what it needs.
Systems the customer connects themselves, such as a CRM receiving webhook events or a calendar receiving bookings.
We do not sell personal data and we do not share it for advertising.
Where it is processed
Processing takes place in the United Kingdom and the European Economic Area wherever possible. Where a supplier processes data elsewhere, it happens under an approved transfer mechanism.
Security
Data is encrypted in transit and at rest. Access is limited to staff who need it and is logged. API keys are stored hashed and shown once, at creation. Webhook deliveries are signed so receivers can prove they came from us.
Your rights
Callers and customers can ask for a copy of their information, ask for it to be corrected, or ask for it to be deleted. Callers should contact the business they rang first, since that business controls its own call records; if they cannot reach us any other way, they can contact us and we will pass the request on.
You can also object to processing, ask us to restrict it, and complain to your data protection regulator.
Changes
If we change this policy in a way that materially affects you, we will tell account owners by email before it takes effect.
Contact
Privacy questions and requests can be sent through our contact page until a dedicated address is published here.