Legal

Privacy Policy

Last updated: 2 February 2026

1. Who We Are

This Privacy Policy explains how Square Peg Innovations Limited, trading as CallHandler AI ("we", "us", "our"), collects, uses and protects personal data.

We provide AI consultancy and AI-powered products and services to businesses, including AI phone agents and related automation, which operate on behalf of our clients.

We are committed to handling personal data responsibly and in accordance with applicable data protection laws, including:

  • UK General Data Protection Regulation (UK GDPR)
  • EU GDPR (where applicable)
  • Australian Privacy Act 1988
  • New Zealand Privacy Act 2020
  • Applicable United States privacy laws

2. Our Role in Data Processing

In most cases:

  • Our clients are the Data Controllers.
  • CallHandler AI acts as a Data Processor.

We process personal data strictly on the instructions of our clients and only to deliver the services they have requested. We do not determine how our clients use personal data outside of our platform.

3. Personal Data We May Process

Depending on client configuration, we may process:

  • Names and contact details
  • Call audio recordings
  • Call transcripts and interaction metadata
  • Appointment, scheduling or booking information
  • Notes or outcomes generated during calls
  • Limited identifiers to recognise returning callers

We only process the minimum data necessary to provide the service.

4. How Personal Data Is Collected

Personal data may be collected:

  • Through inbound and outbound phone calls handled by our AI services
  • Through secure integrations with third-party systems authorised by our clients
  • Through use of our website or platform by clients

5. How We Use Personal Data

We use personal data solely to:

  • Deliver the services configured and approved by our clients
  • Operate, monitor and support our platform
  • Ensure service quality, reliability and performance
  • Comply with legal obligations

We do not use personal data for advertising, resale, or unrelated profiling.

6. Call Recordings and Transcripts

By default, call recordings and transcripts are securely stored within our platform.

They are used only for:

  • Quality assurance
  • Performance monitoring
  • Service improvement and troubleshooting

Access is restricted to authorised personnel and the relevant client. Recordings are never used to train external or third-party AI models. Retention periods may be configured by the client where applicable.

7. AI Use and Human Oversight

Our AI services operate within rules and permissions defined by each client.

Key principles:

  • AI acts on behalf of the client, similar to a trained human team member
  • Clients control what actions the AI may perform
  • Human oversight, monitoring and configuration are always maintained

We do not use client or end-user data to train general-purpose AI models. Any internal testing is performed using our own test data or internal calls.

8. Data Sharing and Sub-Processors

We do not sell or rent personal data.

Personal data may be shared only with:

  • The relevant client
  • Trusted sub-processors who provide infrastructure or operational services (such as hosting, telephony or analytics), all of whom are contractually required to protect personal data
  • Regulators or authorities where required by law

A list of sub-processors is available upon request.

9. International Data Transfers

Where personal data is transferred across borders, we ensure appropriate safeguards are in place, including contractual protections and recognised transfer mechanisms, in accordance with applicable laws.

10. Data Security

We apply appropriate technical and organisational measures to protect personal data, including access controls, secure infrastructure, monitoring and encryption where appropriate.

11. Data Retention

Personal data is retained only for as long as necessary to provide the services or meet legal and contractual obligations. Retention periods may vary based on client configuration and jurisdiction.

12. Individual Rights

Depending on location, individuals may have rights to access, correct, delete or restrict the processing of their personal data, or to object to certain processing activities.

Where we act as a Data Processor, requests should be directed to the relevant client. We will assist our clients in responding to such requests as required by law.

13. Cookies and Website Data

Our website may use cookies or similar technologies for essential functionality and analytics. Further information is available in our Cookie Policy.

14. Changes to This Policy

We may update this Privacy Policy from time to time. The current version will always be available on our website.

15. Contact Us

If you have questions about this Privacy Policy or our data practices, please contact: