Callix processes call recordings and transcripts on behalf of the businesses that use us. We never train foundation models on customer call content, we never sell personal information, and every retention window on this page is a setting our customers control.
Who controls the data on a call
Callix is a data processor. Our customers, the businesses whose teams make and receive the calls, are the data controller. They decide which calls are recorded, why, how long recordings are kept, and what lawful basis applies. We process that data only on their documented instructions.
If you spoke to a business that uses Callix and you want your recording or transcript deleted, the fastest route is to contact that business directly, because they control the retention setting. You can also write to us at privacy@callixhub.com and we will forward the request to them and support them in fulfilling it.
Two documents, not one
This policy describes what Callix does with data. The separate Data Processing Addendum, available from the Trust Center, is the contractual instrument our customers sign: it governs subprocessors, international transfers, and breach notification.
Call recording consent
Recording a phone call is regulated differently almost everywhere. Callix gives customers the controls to comply; the obligation to obtain consent sits with the business making the recording, not with us.
- In one-party-consent jurisdictions, the business's own participation is generally sufficient.
- In two-party (all-party) consent jurisdictions, including California, Florida, Illinois, Pennsylvania, Washington, and most of the EU/UK, every participant must be informed and must consent before recording begins.
- Callix supports automated spoken disclosure at call start, per-number recording rules, and mid-call stop-recording, so a customer can meet the stricter standard on every call rather than guessing at the caller's location.
- Where a caller declines, the customer can configure Callix to drop the audio and retain only non-content metadata such as duration and outcome.
We do not advise on which standard applies to a given customer's calls. Customers should take their own legal advice and configure Callix accordingly.
What we collect
| Category | Examples | Why |
|---|---|---|
| Call content | Audio recordings, transcripts, speaker labels, detected topics and objections | To produce the transcription, scoring, and coaching output the customer bought |
| Call metadata | Phone numbers, timestamps, duration, direction, agent identity, outcome | To organise calls, route them to the right workspace, and report on them |
| Account data | Name, work email, company, role, password hash, workspace settings | To operate accounts, authenticate users, and provide support |
| Integration data | CRM records the customer chooses to sync, such as contacts, deals, and stages | To write call outcomes back to the customer's system of record |
| Usage and diagnostics | Pages viewed, features used, IP address, browser and device type, error traces | To keep the service reliable, secure, and to improve it |
| Marketing data | Information you submit on this website, such as a demo request | To respond to you and, where permitted, to send you relevant material |
How your calls are used with AI models
This is the question customers ask most, so the answer is stated plainly: we do not use customer call audio, transcripts, or CRM data to train foundation models, and we do not permit our model vendors to do so either.
- Call content is sent to model providers only to produce output for that same customer, under zero-retention or short-retention terms.
- Model providers are contractually prohibited from training on data we send them.
- Aggregate, fully de-identified statistics, for example, average call duration across an industry, may be used to improve the product and inform benchmarks. These cannot be linked back to a person, a call, or a customer.
- Any use of customer content to tune a model for that customer's own workspace happens only with their explicit written instruction, and the result is never shared across customers.
How long we keep it
Retention is a per-workspace setting the customer controls. Where they have not changed it, our defaults apply.
| Data | Default retention |
|---|---|
| Call audio | 12 months, configurable from 30 days to 7 years |
| Transcripts and scores | As long as the workspace is active |
| Account data | For the life of the account, then 90 days after closure |
| Backups | 35 days on a rolling cycle |
| Diagnostic logs | 30 days |
When a customer closes their account, we delete or de-identify their workspace within 90 days, excluding backups which age out on the cycle above. Deletion requests for individual calls are honoured immediately and propagate to backups as they expire.
How we protect it
- Audio and transcripts are encrypted in transit with TLS 1.2 or better, and at rest with AES-256.
- Each customer's data is logically isolated, so one customer's calls are never processed alongside another's.
- Access by Callix staff is role-based, logged, and limited to what a named support or engineering task requires.
- We run independent penetration tests and publish the summaries to customers under review.
- We maintain an incident response process and will notify affected customers without undue delay, and within the timeframes set out in their DPA.
Certification status
Confirm and state your current position here before launch: for example whether a SOC 2 Type II report is available, whether you will sign a HIPAA Business Associate Agreement, and the status of any ISO 27001 work. Buyers in healthcare and insurance will not proceed without an explicit answer.
Your rights
Depending on where you live, you may have the right to access the personal data we hold about you, to correct it, to delete it, to object to or restrict processing, to receive it in a portable format, and to withdraw consent. You also have the right not to be discriminated against for exercising any of them.
Because Callix acts as a processor for call data, requests about a specific call are fulfilled by the business that recorded it. For data we hold as a controller, your account, or a form you submitted on this site, write to privacy@callixhub.com and we will respond within 30 days.
If you are in the EEA or UK and believe we have not handled your request properly, you may complain to your local supervisory authority.
International transfers
Callix is operated from Turkey, and data may be processed there and in other countries where our subprocessors operate. Where data leaves the EEA or UK, we rely on the European Commission's Standard Contractual Clauses together with the UK Addendum, supported by a transfer impact assessment available on request.
Customers with data residency requirements can ask about EU-only or UK-only processing regions before signing.
Children
Callix is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child's data has reached us through a recorded call, contact privacy@callixhub.com and we will work with the responsible customer to remove it.
Changes and contact
We will post any change to this policy on this page and update the date above. Where a change materially affects how we handle personal data, we will notify account administrators by email at least 30 days before it takes effect.
Questions, requests, or complaints: privacy@callixhub.com, or Callix, Değirmendere, Yali Mah. Saniye Altuncu Cad. No: 14 Setirali Apt. D: 1, 41950 Kocaeli, Gölcük, Turkey.