1. Who we are
CallForge Ltd ("CallForge", "we", "us") provides AI outbound calling software to business customers in the United Kingdom and elsewhere. We are the data controller for personal data processed through our marketing website and platform account administration.
For questions about this policy, contact privacy@callforge.uk or write to CallForge Ltd, United Kingdom.
2. What data we collect
We collect information you provide directly, data generated through use of the platform, and limited technical data needed to operate and secure the service.
- Account data: name, work email, company name, billing details, and team member invitations.
- Campaign data: lead lists you upload (names, phone numbers, companies, and other fields you choose), call recordings, transcripts, and outcomes.
- Usage data: log-ins, feature usage, API calls, and support correspondence.
- Security and technical data: IP address and browser user-agent string associated with account registration, sign-in, and sign-out events (stored in our audit logs for security and fraud prevention).
- Website data: IP address, browser type, pages visited, and cookie identifiers where applicable (see our Cookie Policy).
3. Security logs (IP address and device browser)
When you register, sign in, or sign out of CallForge, we record your IP address and user-agent (browser/device description) in an internal audit log. Under UK GDPR, an IP address can be personal data.
We process this information under our legitimate interests in protecting accounts, investigating unauthorised access, preventing abuse, and resolving security disputes. We do not use these logs for marketing.
We do not collect or store MAC (hardware network) addresses. Web browsers do not provide MAC addresses to websites, and we have no operational need to obtain them.
- Purpose: account security, fraud prevention, and auditability.
- Fields: IP address, user-agent, timestamp, related account/organisation identifiers.
- Retention: security audit logs are kept for up to 12 months, then automatically deleted.
- Access: limited to authorised CallForge personnel and systems that need them for security or support.
4. How we use your data
We process personal data to provide and improve the CallForge service, authenticate users, process payments (via Stripe for subscription billing), deliver customer support, and meet legal obligations.
Where you upload lead data, you act as data controller for that data and we process it on your instructions as a data processor under our Data Processing Agreement.
- Providing AI calling, qualification, and appointment booking features.
- Billing, fraud prevention, and account security (including IP / user-agent audit logs).
- Product analytics in aggregated or pseudonymised form.
- Marketing communications where you have opted in or we have a legitimate interest (you may opt out at any time).
5. Legal bases (UK GDPR)
Depending on the activity, we rely on contract performance, legitimate interests, legal obligation, or consent. For B2B marketing we may contact you where relevant to your role and you may object at any time.
For security audit logs containing IP addresses and user-agents, we rely on legitimate interests (Article 6(1)(f) UK GDPR) balanced against your rights — limited purpose, short retention, and no secondary use for advertising.
6. Sharing and subprocessors
We share data with infrastructure providers, payment processors (including Stripe for subscription checkout and billing), telephony and AI voice partners, and support tools under contractual safeguards. A current subprocessor list is available on request or in your DPA.
We do not sell personal data. Security logs are not sold or used for third-party advertising.
7. International transfers
Data may be processed in the UK, EEA, or United States. Where transfers occur outside the UK, we use appropriate safeguards such as UK International Data Transfer Agreements or equivalent mechanisms.
8. Retention
We retain account and billing records for as long as your subscription is active and for a reasonable period thereafter for legal and accounting purposes. Call recordings and transcripts are retained according to your organisation settings and our default retention schedule unless you configure shorter periods.
Security audit logs that include IP address and user-agent are retained for a maximum of 12 months from the date of the event, after which they are automatically deleted from our systems.
If you close a company account, we keep a recoverable copy of the organisation (with a one-time recovery code) for up to 90 days so you can restore access. After that window the company is permanently deleted. We do not store MAC addresses.
9. Your rights
Under UK data protection law you may have the right to access, rectify, erase, restrict, or port your data, and to object to certain processing (including processing based on legitimate interests). You may also lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.
Company admins can close their organisation from Settings → Account & data (a recovery code is shown once). Individual users can delete their own login when another teammate remains. Where you request erasure, we will delete or anonymise personal data we no longer need, subject to the recovery window and any compelling legitimate interest for limited security records.
Submit requests to privacy@callforge.uk. We respond within one month.
10. Security
We implement technical and organisational measures including encryption in transit, access controls, activity history, and regular security reviews. See our Security page for more detail.
11. Changes
We may update this policy from time to time. Material changes will be notified via email or in-app notice. The "last updated" date at the top of this page indicates the current version.