Legal

Privacy
policy.

We built a product that listens to phone calls. That obliges us to be unusually specific about what happens to them.

Last updated August 12, 2026

Callix processes call recordings and transcripts on behalf of the businesses that use us. We never train foundation models on customer call content, we never sell personal information, and every retention window on this page is a setting our customers control.

Who controls the data on a call

Callix is a data processor. Our customers, the businesses whose teams make and receive the calls, are the data controller. They decide which calls are recorded, why, how long recordings are kept, and what lawful basis applies. We process that data only on their documented instructions.

If you spoke to a business that uses Callix and you want your recording or transcript deleted, the fastest route is to contact that business directly, because they control the retention setting. You can also write to us at privacy@callixhub.com and we will forward the request to them and support them in fulfilling it.

Two documents, not one

This policy describes what Callix does with data. The separate Data Processing Addendum, available from the Trust Center, is the contractual instrument our customers sign: it governs subprocessors, international transfers, and breach notification.

What we collect

CategoryExamplesWhy
Call contentAudio recordings, transcripts, speaker labels, detected topics and objectionsTo produce the transcription, scoring, and coaching output the customer bought
Call metadataPhone numbers, timestamps, duration, direction, agent identity, outcomeTo organise calls, route them to the right workspace, and report on them
Account dataName, work email, company, role, password hash, workspace settingsTo operate accounts, authenticate users, and provide support
Integration dataCRM records the customer chooses to sync, such as contacts, deals, and stagesTo write call outcomes back to the customer's system of record
Usage and diagnosticsPages viewed, features used, IP address, browser and device type, error tracesTo keep the service reliable, secure, and to improve it
Marketing dataInformation you submit on this website, such as a demo requestTo respond to you and, where permitted, to send you relevant material

How your calls are used with AI models

This is the question customers ask most, so the answer is stated plainly: we do not use customer call audio, transcripts, or CRM data to train foundation models, and we do not permit our model vendors to do so either.

  • Call content is sent to model providers only to produce output for that same customer, under zero-retention or short-retention terms.
  • Model providers are contractually prohibited from training on data we send them.
  • Aggregate, fully de-identified statistics, for example, average call duration across an industry, may be used to improve the product and inform benchmarks. These cannot be linked back to a person, a call, or a customer.
  • Any use of customer content to tune a model for that customer's own workspace happens only with their explicit written instruction, and the result is never shared across customers.

Who we share data with

We do not sell personal information, and we do not share it for cross-context behavioural advertising as those terms are defined under the CCPA/CPRA. We share data only with the subprocessors needed to run the service.

  • Cloud hosting and storage providers, which hold call audio and transcripts at rest.
  • Speech-to-text and language model providers, which process call content to produce transcripts and scores.
  • Telephony and CRM platforms that the customer has connected to their workspace.
  • Payment, support, and product-analytics vendors, which receive account and usage data but not call content.
  • Law enforcement or regulators, where we are legally compelled, and, unless legally prohibited, we tell the affected customer first.

The current subprocessor list, with each vendor's role and location, is published in the Trust Center. Customers may subscribe to be notified before a new subprocessor is added.

How long we keep it

Retention is a per-workspace setting the customer controls. Where they have not changed it, our defaults apply.

DataDefault retention
Call audio12 months, configurable from 30 days to 7 years
Transcripts and scoresAs long as the workspace is active
Account dataFor the life of the account, then 90 days after closure
Backups35 days on a rolling cycle
Diagnostic logs30 days

When a customer closes their account, we delete or de-identify their workspace within 90 days, excluding backups which age out on the cycle above. Deletion requests for individual calls are honoured immediately and propagate to backups as they expire.

How we protect it

  • Audio and transcripts are encrypted in transit with TLS 1.2 or better, and at rest with AES-256.
  • Each customer's data is logically isolated, so one customer's calls are never processed alongside another's.
  • Access by Callix staff is role-based, logged, and limited to what a named support or engineering task requires.
  • We run independent penetration tests and publish the summaries to customers under review.
  • We maintain an incident response process and will notify affected customers without undue delay, and within the timeframes set out in their DPA.

Certification status

Confirm and state your current position here before launch: for example whether a SOC 2 Type II report is available, whether you will sign a HIPAA Business Associate Agreement, and the status of any ISO 27001 work. Buyers in healthcare and insurance will not proceed without an explicit answer.

Your rights

Depending on where you live, you may have the right to access the personal data we hold about you, to correct it, to delete it, to object to or restrict processing, to receive it in a portable format, and to withdraw consent. You also have the right not to be discriminated against for exercising any of them.

Because Callix acts as a processor for call data, requests about a specific call are fulfilled by the business that recorded it. For data we hold as a controller, your account, or a form you submitted on this site, write to privacy@callixhub.com and we will respond within 30 days.

If you are in the EEA or UK and believe we have not handled your request properly, you may complain to your local supervisory authority.

International transfers

Callix is operated from Turkey, and data may be processed there and in other countries where our subprocessors operate. Where data leaves the EEA or UK, we rely on the European Commission's Standard Contractual Clauses together with the UK Addendum, supported by a transfer impact assessment available on request.

Customers with data residency requirements can ask about EU-only or UK-only processing regions before signing.

Cookies and this website

This website uses strictly necessary cookies to keep the site working and, where you consent, analytics cookies that tell us which pages are useful. We do not run advertising cookies.

You can change your choice at any time using the Privacy choices control in the footer, or by clearing cookies in your browser. We honour Global Privacy Control signals sent by your browser as an opt-out of any sale or sharing.

Children

Callix is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child's data has reached us through a recorded call, contact privacy@callixhub.com and we will work with the responsible customer to remove it.

Changes and contact

We will post any change to this policy on this page and update the date above. Where a change materially affects how we handle personal data, we will notify account administrators by email at least 30 days before it takes effect.

Questions, requests, or complaints: privacy@callixhub.com, or Callix, Değirmendere, Yali Mah. Saniye Altuncu Cad. No: 14 Setirali Apt. D: 1, 41950 Kocaeli, Gölcük, Turkey.

Common questions

Questions we get asked.

The business you spoke to. They are the data controller and decide whether the call was recorded, why, and how long it is kept. Callix processes it on their instructions, which is why deletion requests are fastest when sent to them directly.

No. Customer call audio, transcripts, and CRM data are never used to train foundation models, and our model vendors are contractually prohibited from training on data we send them. Only fully de-identified aggregate statistics inform product work.

The default is 12 months, configurable by the customer from 30 days to 7 years. Transcripts and scores persist for the life of the workspace, diagnostic logs for 30 days, and backups age out on a 35-day rolling cycle.

It depends on jurisdiction, and the obligation sits with the business making the recording. All-party consent applies in California, Florida, Illinois, Pennsylvania, Washington, and most of the EU and UK. Callix provides automated disclosure and mid-call stop-recording to meet the stricter standard.

Email privacy@callixhub.com. For data we hold as a controller, your account, or a form you submitted on this site, we respond within 30 days. For a specific call, we forward the request to the business that recorded it and support them in fulfilling it.