Legal

Data processing agreement

The terms on which we process your callers' personal data. This forms part of our contract and applies automatically to every client.

Last updated 14 August 2026

Who is who

You are the controller of your callers’ personal data. Fixology Ltd, trading as Callwise, is the processor, acting only on your documented instructions. This agreement is entered into under Article 28 of the UK GDPR and forms part of our terms of service.

Your instructions are what you approve during setup: the script, the calendar rules and the escalation list, plus anything you later ask for in writing. We will tell you if we think an instruction breaches data protection law.

The processing

Subject matter
Answering, recording, transcribing and summarising inbound telephone calls to your business, and booking appointments arising from them.
Duration
For as long as we provide the service, plus the retention periods below.
Nature and purpose
Receiving calls, speech to text transcription, applying your configured rules, writing bookings to your calendar, and producing summaries.
Data subjects
Anyone who telephones your business, and your own staff named in your configuration.
Categories of data
Caller telephone number, name, the audio of the call and its transcript, appointment details, and whatever the caller chooses to say.
Special category data
Health data in calls to dental practices and clinics, and data about legal matters in calls to law firms. Processed only under your lawful basis and never analysed for our own purposes.

Our obligations

  • Process personal data only on your documented instructions, including on international transfers.
  • Ensure everyone with access is under a duty of confidence.
  • Apply appropriate technical and organisational security measures, described below.
  • Not engage a sub-processor without your general authorisation, and give you notice of changes so you can object.
  • Help you respond to data subject requests, and to your obligations on security, breach notification and impact assessments.
  • Delete or return the data at the end of the contract, at your choice.
  • Make available the information you need to demonstrate compliance, and allow audits.

Security

Encryption in transit and at rest. Access limited to named individuals who need it, protected by individual accounts and multi-factor authentication, and reviewed when somebody changes role or leaves. Recordings are not stored on laptops or removable media. Separation between clients, so no client’s staff or data can reach another’s. Logging of access to recordings. Backups, and a documented restore process.

Sub-processors

You give general authorisation for us to appoint sub-processors. We use a telephony and voice platform to carry and transcribe calls, and cloud infrastructure providers to host the service. Each is bound by written terms no less protective than these.

A current list naming every sub-processor, what they do and where they process, is available on request and is provided as part of any procurement or security review. We will give you at least 30 days notice before adding or replacing one. If you reasonably object on data protection grounds, tell us within that period and we will either find an alternative or you may terminate without penalty.

International transfers

Personal data is processed in the United Kingdom and the European Economic Area. Where a sub-processor processes data outside the UK, we rely on UK adequacy regulations or on the International Data Transfer Addendum to the European Commission’s standard contractual clauses, supported by a transfer risk assessment which we will share on request.

Data subject requests

Requests usually reach you, because the caller dealt with your business. Tell us and we will locate, export or delete the relevant recordings and transcripts, normally within five working days and always in time for you to meet your own one month deadline.

If a caller comes to us directly we will not respond substantively on your behalf. We will pass the request to you promptly and help you answer it.

Personal data breaches

We will notify you without undue delay and in any event within 24 hours of becoming aware of a personal data breach affecting your data. The notification will describe what happened, the categories and approximate number of records affected, the likely consequences and what we are doing about it, so that you can meet your own 72 hour obligation to the ICO.

Retention, deletion and return

Call recordings
12 months
Transcripts and summaries
24 months
After the contract ends
Available for download, then deleted after 30 days

You may agree different periods with us in writing, and an agreed period overrides the table above. You may ask for deletion or return at any time, and we will confirm in writing once it is done, including from backups on their normal cycle.

Audit

On reasonable notice, no more than once a year unless a breach or a regulator requires it, we will answer a security questionnaire and provide the documentation you need. Where that is not enough for your regulator, we will accommodate an audit by you or an independent auditor bound by confidentiality.

Getting a signed copy

Most clients rely on this page, which applies automatically. If your procurement process needs a signed document, email hello@call-wise.com and we will send one for signature the same working day, along with the named sub-processor list.

Questions about any of this

Email hello@call-wise.com or write to Fixology Ltd, 47 Bradley Road, Luton, Bedfordshire, England, LU4 8SL. The other documents are privacy, terms, cookies and data processing.