YOURCALLS — PRIVACY NOTICE
Version 1.0 · Effective from 3 September 2026. Superseded versions are available on request from hello@s4w.com.
YOURCALLS — PRIVACY NOTICE
Version 1.0
This Privacy Notice is issued by S4W L.L.C-FZ (trading as YourCalls), a company registered in the United Arab Emirates with licence number 2529741, whose registered address is Meydan Grandstand, 6th floor, Meydan Road, Nad Al Sheba, Dubai, U.A.E. S4W L.L.C-FZ is the controller or the processor of the Personal Data described in this notice, as set out in section 3. Dial Square Consultancy Ltd, a company registered in England and Wales with company number 17317079, whose registered address is 131 Finsbury Pavement, London, England, EC2A 1NT, is our representative in the United Kingdom under Article 27 of the UK GDPR.
This Privacy Notice sets out how we use, protect and share the Personal Data that we collect from you when you use our website, when you purchase or use our services, when you access our platform (Platform), or when you interact with or contact us in any other way.
CONTENTS
- About this Privacy Notice
- Who are we?
- Our role: when we are a controller and when we are a processor
- If a business has called, texted or chatted with you using our Platform
- Who are you?
- What types of Personal Data do we collect from you?
- How and why do we use your Personal Data?
- Automated decision-making and artificial intelligence
- How can you manage your marketing preferences?
- What about cookies?
- Who do we share your Personal Data with?
- What happens if we share your Personal Data with organisations outside of the UK (and/or EEA)?
- How do we protect your Personal Data?
- How long do we keep your Personal Data for?
- What are your rights in relation to the Personal Data we hold?
- Contact us if you have a question or a complaint
- Updates to this Privacy Notice
- Third-party links
1. ABOUT THIS PRIVACY NOTICE
1.1 In this Privacy Notice, Personal Data means any information relating to an identified or identifiable living individual. We use the term "Personal Data" throughout; where you see the phrase "personal information" used elsewhere in our documents, it means the same thing.
1.2 The Platform means our self-service YourCalls platform, comprising AI-enabled voice assistants (inbound and outbound calling), an embeddable website chat assistant, messaging (SMS), workflow automation, integrations with third-party systems that our customers nominate, a public API, rented telephone numbers, and Clara (an in-product AI assistant available to our customers' own staff).
1.3 This Privacy Notice is published at https://s4w.com/yourcalls/privacy. Our Terms and Conditions are published at https://s4w.com/yourcalls/terms, our Data Processing Addendum (DPA) at https://s4w.com/yourcalls/dpa, our Tier Schedule at https://s4w.com/yourcalls/tiers and our Cookies Notice at https://s4w.com/yourcalls/cookies.
1.4 Authorised User means an individual whom one of our customers has authorised to access and use the Platform on its behalf. The term has the same meaning as in our Terms and Conditions.
2. WHO ARE WE?
2.1 The entity responsible for the processing described in this Privacy Notice is:
S4W L.L.C-FZ, a company registered in the United Arab Emirates, licence number 2529741, registered address Meydan Grandstand, 6th floor, Meydan Road, Nad Al Sheba, Dubai, U.A.E. (S4W, we, us or our).
2.2 S4W trades as YourCalls and YourCalls.ai. S4W is the contracting party for the Platform, and is the controller or processor as applicable in accordance with section 3.
2.3 Payment collection agent and merchant of record. Payments for our services are collected on our behalf by Dial Square Consultancy Ltd, registered in England and Wales, company number 17317079, registered address 131 Finsbury Pavement, London, England, EC2A 1NT. Dial Square Consultancy Ltd is our payment collection agent and merchant of record. It is not a reseller and it does not contract with you. Where your payment is collected through Stripe, Dial Square Consultancy Ltd is the name that will appear on your card or bank statement; customers who subscribed before we moved to Stripe are still served by our previous payment provider, and will see that provider's descriptor until their subscription is migrated. Dial Square Consultancy Ltd is not currently registered for VAT.
2.4 Our UK representative. S4W is established outside the United Kingdom and offers services to, and monitors the behaviour of, individuals in the United Kingdom. We have appointed Dial Square Consultancy Ltd, 131 Finsbury Pavement, London, England, EC2A 1NT, contactable at hello@s4w.com, as our representative in the United Kingdom under Article 27 of the UK GDPR. You may contact our UK representative on any matter relating to our processing of your Personal Data.
2.5 Our privacy contact. You can reach us on any privacy matter at hello@s4w.com, or by writing to us at the registered address in clause 2.1. We have assessed our processing against Article 37 of the UK GDPR and have concluded that we are not required to appoint a statutory Data Protection Officer.
2.6 You can contact us at the addresses above if you have any questions about this Privacy Notice, or if you would like to exercise any of your rights under data protection laws, which we set out in section 15.
3. OUR ROLE: WHEN WE ARE A CONTROLLER AND WHEN WE ARE A PROCESSOR
3.1 Data protection law distinguishes between a controller (who decides why and how Personal Data is used) and a processor (who uses Personal Data only on the controller's instructions). Our role differs depending on the data.
3.2 S4W acts as processor, on the customer's instructions, for all call, chat, contact, lead, knowledge base and messaging data submitted to or generated by the Platform.
3.3 S4W acts as an independent controller for: customer account and Authorised User data, billing and payment data, support communications, website and product analytics (including Platform usage and service administration data such as IP addresses, device and browser information, sign-in times and configuration actions), and marketing data. Data that has been irreversibly anonymised and aggregated in accordance with clause 2.5 of our DPA is not Personal Data and falls outside this allocation of roles.
3.4 Call participants, chat visitors, SMS recipients and leads are data subjects for whom the customer is controller.
3.5 Where we act as processor, our processing is governed by our DPA with the relevant customer, published at https://s4w.com/yourcalls/dpa. Where we act as controller, this Privacy Notice describes what we do and why.
3.6 Where we act as processor, this Privacy Notice is provided for information. It does not replace the privacy information that the customer, as controller, is required to give you, and it does not change the customer's responsibility to give it.
4. IF A BUSINESS HAS CALLED, TEXTED OR CHATTED WITH YOU USING OUR PLATFORM
4.1 If you have received a telephone call or an SMS message from a business, or used a chat assistant on a business's website, and that business uses our Platform, then that business — not S4W — is the controller of your Personal Data. We handle your Personal Data only as that business's processor, on its instructions.
4.2 This means that if you want to know why you were contacted, where your details came from, to ask for a copy of your data, to have it corrected or deleted, or to object to being contacted again, you should contact the business that contacted you in the first instance. It will be able to identify you and to instruct us.
4.3 You can also contact us at hello@s4w.com if you cannot identify or reach that business, or if you have a concern about how the Platform itself operates. Where we can, we will help you to identify the relevant business and we will pass your request to it. We are not permitted to disclose, amend or delete data held on a customer's behalf without that customer's instruction, except where the law requires us to act.
4.4 It is helpful to know the following about how the Platform works:
(a) telephone calls handled by the Platform are conducted by an AI assistant, not by a person, unless the assistant transfers you to a person;
(b) calls handled by the Platform are always recorded and transcribed. There is no setting that turns recording off. Whether you are told that the call is recorded, and whether you are told that you are speaking to an AI assistant, is configured by the business that is calling you and is that business's responsibility;
(c) a recording, a written transcript, an AI-generated summary and an AI-generated assessment of the call are created and stored, and are made available to that business; and
(d) chat conversations on a business's website are conducted by an AI assistant, and the message content, together with the technical information described in clause 6.6, is stored and made available to that business.
5. WHO ARE YOU?
5.1 In this Privacy Notice, when we refer to you or your, we mean any individual whose Personal Data we process in connection with our website, our services, the Platform, or when you interact with or contact us in any other way.
5.2 This includes:
(a) Website visitors, who browse or interact with our website or online content.
(b) Authorised Users and other representatives of our customers, who create or use an account on the Platform or communicate with us about the services.
(c) Marketing contacts, who sign up to receive updates, events or other marketing communications from us, or engage with our marketing campaigns.
(d) Suppliers, advisers and their personnel, whose contact details we hold in order to run our business.
(e) Other individuals who contact us, for example by email, phone or through our support channels, or whose Personal Data is provided to us in connection with our services.
5.3 We also process Personal Data about the following individuals as a processor, on behalf of our customers (see sections 3 and 4). We are not the controller of this data:
(a) Call participants, whose calls to or from a customer's AI assistant are handled, recorded and transcribed using the Platform.
(b) Website chat visitors, who use a chat assistant that a customer has embedded on the customer's own website.
(c) SMS recipients and senders, who receive messages sent through the Platform or reply to them.
(d) Contacts and leads, whose details a customer uploads to, or sends into, the Platform.
5.4 If you fall into more than one of these categories, this Privacy Notice applies to you in each relevant capacity.
6. WHAT TYPES OF PERSONAL DATA DO WE COLLECT FROM YOU?
6.1 Where we act as controller (see clause 3.3), we may collect, use, store and transfer different kinds of Personal Data about you, including:
(a) Account and identity information, such as your name, job title, business email address, phone number and the identifiers used to authenticate you, where you register for or use the Platform or engage our services. We use a passwordless sign-in method, so we do not collect or hold passwords.
(b) Billing and payment information, such as billing contact details, company name, billing address, tax or VAT identification number, transaction records, subscription and usage records, and limited card metadata (card brand, last four digits, expiry date, and a payment-method reference issued by our payment provider). Full card details are entered directly with our payment provider and are never held by us — see clause 11.4.
(c) Communication and support information, such as the content of emails, support tickets, contact form submissions, screenshots you send us and chat messages you send to us when you contact our team.
(d) Platform usage and service administration data, such as your IP address, device and browser information, sign-in times, pages visited and configuration actions, collected as part of operating and securing the Platform.
(e) Website analytics data, such as pages visited, session duration and click behaviour, collected on our website as described in section 10.
(f) Marketing preferences and engagement data, such as your contact details, communication preferences and consent and opt-out records, where you have signed up to receive marketing communications from us.
(g) Business verification information, such as your organisation's registered name, registered address, contact details and supporting documents, where these are required by telecommunications regulation in order to provide you with a telephone number.
6.2 Where we act as processor (see clause 3.2), the Personal Data we handle on our customers' instructions includes the categories set out in clauses 6.3 to 6.7. We do not decide what is submitted to us in these categories.
6.3 Call data: the telephone numbers of both parties, the date, time, duration and direction of the call, the audio recording of the call, a written transcript of the call, an AI-generated summary, an AI-generated outcome classification and quality score, and anything a participant says during the call.
6.4 Contact and lead data: name, telephone number, email address, postal address, and any other fields a customer chooses to upload, import or send to us, including free-text fields and arbitrary additional fields submitted through our lead ingest interface. We neither control nor inspect what customers submit in these fields.
6.5 Messaging (SMS) data: the sending and receiving telephone numbers, the full content of each message, and delivery and metering records.
6.6 Chat data: for each chat session we store the full text of every message; a persistent visitor identifier written to the visitor's browser local storage; the internet address (Origin) of the website on which the chat assistant is embedded; the full browser user-agent string; a salted, truncated hash of the visitor's IP address; any information the visitor enters into a pre-chat or lead capture form; and any additional information the customer's own systems supply about the visitor. A contact record is automatically created for the visitor. The salted, truncated IP hash is pseudonymised data, not anonymous data, because we retain the means to generate it.
6.7 Knowledge base and configuration content: documents, web pages and other material a customer uploads so that its assistant can answer questions, which may contain Personal Data if the customer includes it.
6.8 Aggregated Data. We also collect, use and share Aggregated Data such as statistical or usage data for any purpose. Aggregated Data could be derived from your Personal Data but is not considered Personal Data in law as this data will not directly or indirectly reveal your identity. For example, we may aggregate usage data to calculate the percentage of users accessing a specific feature. However, if we combine or connect Aggregated Data with your Personal Data so that it can directly or indirectly identify you, we treat the combined data as Personal Data which will be used in accordance with this Privacy Notice.
6.9 AI model training. We do not use the content of calls, chats or messages to train AI models in identifiable form. We may use data derived from that content once it has been irreversibly anonymised and aggregated so that no individual can be identified, as described in clause 8.2 of our Terms and clause 2.5 of our DPA. Content is sent to third-party AI providers in order to deliver the service (see clause 11.3).
7. HOW AND WHY DO WE USE YOUR PERSONAL DATA?
7.1 How your information is collected
(a) When you interact with us. We collect Personal Data directly from you in the following circumstances:
- when you contact us via our website, submit an enquiry or contact form, or correspond with us by email or telephone;
- when your organisation sets up or manages a service engagement or an account with us, including during onboarding; and
- when you sign up to receive marketing communications from us or update your communication preferences.
(b) Automatically. We also collect certain technical and usage data automatically when you visit our website or use the Platform, including your IP address, device and browser information, pages visited, session duration and click behaviour. See section 10 for what we use on our website and what device storage is involved.
(c) From third parties. We may receive Personal Data about you from the following third-party sources:
- from your employer or organisation, where a representative's details are provided on your behalf in connection with setting up or managing a service engagement or an account with us;
- from our customers, where they upload, import or send us contact and lead data (in which case we act as processor — see section 3); and
- from our payment provider, which supplies us with transaction outcomes and limited card metadata.
(d) Automated technologies and cookies. As you interact with our website, we may automatically collect technical data about your equipment, browsing actions and patterns. Please see our Cookies Notice at https://s4w.com/yourcalls/cookies and section 10 of this Privacy Notice for further details.
7.2 The legal bases we rely on
Data protection laws require us to have a legal basis for everything that we do with your Personal Data, falling under one of the following categories:
(a) Performance of a contract with you: where we need to perform a contract we are about to enter into or have entered into with you.
(b) Legitimate interests: we may use your Personal Data where it is necessary to conduct our business and pursue our legitimate interests, for example to prevent fraud and/or enable us to give you the best user experience. We make sure we consider and balance any potential impact on you and your rights (both positive and negative) before we process your Personal Data for our legitimate interests. We do not use your Personal Data for activities where our interests are overridden by the impact on you (unless we have your consent or are otherwise required or permitted to by law).
(c) Legal obligation: we may use your Personal Data where it is necessary for compliance with a legal obligation that we are subject to.
(d) Consent: we rely on consent principally where we have obtained your active agreement to use your Personal Data for a specified purpose, in relation to receiving marketing emails from us. Consent is also the basis on which non-essential cookies and similar device storage are used where required — see section 10.
Where we act as processor (see clause 3.2), the legal basis for the processing is a matter for our customer as controller, not for us.
7.3 Account and identity information
| What do we do? | Why do we do it? | What is the legal basis? |
|---|---|---|
| Identify you when you visit our website or contact us for any reason. | So we can identify you, respond to your enquiry, and provide personalised services. | Legitimate interests: necessary for us to be able to communicate with you and manage our client relationships. |
| Send you service updates, project communications, and updates to this Privacy Notice and our Terms. | So we can keep you informed of any changes to our services, terms and data processing. | Legitimate interests: necessary for the effective provision of our products and services. Legal obligation where required by applicable law. |
| Send you information about our products and services. | So we can let you know about new AI solutions and services that we offer that you might be interested in. | Consent (for direct marketing to individuals). Legitimate interests: necessary to promote our business where permitted for B2B contacts under applicable law. |
| Send you surveys and respond to feedback and correspondence. | To understand how we are performing, gather views, and improve our services and your experience. | Legitimate interests: necessary to ensure we are providing the best service and to identify areas for improvement. |
| Create and manage client and user accounts, and authenticate you using a passwordless sign-in method. | To authenticate and manage accounts and provide access to the Platform and our services. | Performance of a contract. Legitimate interests: necessary for the provision of our products and services. |
| Onboard clients and gather information about their business workflows, systems and integration requirements. | To design, build and deploy the Platform configuration that integrates with the client's existing tools and workflows. | Performance of a contract. Legitimate interests: necessary to deliver effective and tailored solutions. |
| Provide customer support and respond to enquiries, including by accessing a customer's account where necessary to investigate a problem. | To resolve issues, assist with your requests and maintain service quality. | Legitimate interests: to maintain customer satisfaction and operational efficiency. Performance of a contract where support is part of contracted services. |
| Submit your organisation's registered business details and supporting documents to our telephony provider for regulatory verification. | Because telecommunications regulation requires the identity of the business behind a telephone number to be verified before the number can be provided. | Legal obligation. Performance of a contract: necessary to provide the telephone numbers you have ordered. |
7.4 Billing and financial information
| What do we do? | Why do we do it? | What is the legal basis? |
|---|---|---|
| Take and process payments for our services through our payment provider and our payment collection agent. | To facilitate payment for the products and services you purchase from us and to issue any refunds or corrections where necessary. | Performance of a contract with you. Legitimate interests: necessary to ensure that S4W is compensated for our products and services. |
| Meter your usage of the Platform (including call minutes, per-destination call surcharges, chat messages and SMS segments) and settle it against your subscription allowances and credit balance. | To calculate correctly what you owe and what your plan includes. | Performance of a contract with you. |
| Keep a record of our transactions with you. | For accounting, audit and financial reporting purposes. | Legal obligation. |
| Investigate and correct billing errors, including over-charges. | So that you are charged the correct amount and any error is put right. | Performance of a contract with you. Legitimate interests: necessary to run a fair and accurate billing process. |
| Analyse transaction data to improve our pricing and services. | To understand usage patterns and improve our commercial offering and service design. | Legitimate interests: necessary to improve our products and services and develop new features. |
7.5 Platform usage and technical information
| What do we do? | Why do we do it? | What is the legal basis? |
|---|---|---|
| Identify you when you visit our website. | To provide you with the best possible user experience and to maintain site security. | Legitimate interests: necessary to provide the best user experience and protect our systems. |
| Monitor visitors to our website and analyse their use of it, and perform tests on our IT systems. | To protect our website and IT systems from fraud or cyberattacks, and to improve our website and services. | Legitimate interests: necessary to ensure our systems are secure and to protect against IT security incidents. Legal obligation where applicable. |
| Administer and protect our business and our website, including troubleshooting, data analysis, testing, system maintenance and hosting of data. | For running our business, provision of administration and IT services, network security, to prevent fraud and in the context of a business reorganisation or group restructuring exercise. | Legitimate interests: necessary to run our business and to provide effective and secure administration and IT services. Legal obligation where applicable. |
| Use aggregated and statistical usage data to improve our website, services, marketing and customer experience. | To understand how customers use our services, to develop them, to grow our business and to inform our marketing strategy. | Legitimate interests: necessary to enhance our business strategies and improve customer satisfaction. |
| Monitor and maintain the security and performance of the Platform, our API and our integrations. | To ensure Platform stability and to prevent unauthorised access or misuse. | Legitimate interests: necessary to protect the Platform, our customers, and the individuals whose data they entrust to us. Legal obligation where applicable. |
7.6 Call, chat and messaging data (where we act as processor)
The table below describes what we do with the call, chat, contact, lead and messaging data that our customers submit to, or generate through, the Platform. For all of these activities we act as processor on the customer's documented instructions. The customer is the controller and is responsible for identifying its own legal basis, for giving privacy information to the individuals concerned, and for any notice or consent required before a call, message or chat takes place.
| What do we do? | Why do we do it? | What is our role and the legal basis? |
|---|---|---|
| Place, receive, route and connect telephone calls using an AI assistant configured by our customer. | To deliver the calling service the customer has bought. | Processor, on the customer's instructions. The customer determines the legal basis. |
| Record and transcribe every call. Recording and transcription are always on and there is no setting that disables them. | Because the Platform's core functionality — transcripts, summaries, outcomes and quality scoring — depends on them, and customers rely on them as a record of what was said. | Processor, on the customer's instructions. The customer is responsible for any notice or consent required. |
| Generate AI summaries, outcome classifications, extracted fields and quality scores from call and chat content. | To give the customer a usable record and analysis of each conversation. | Processor, on the customer's instructions. |
| Operate an embedded chat assistant on the customer's website, store the conversation and the technical information described in clause 6.6, and create a contact record for the visitor. | To deliver the chat service the customer has bought. | Processor, on the customer's instructions. The customer is responsible for any consent required for the device identifier and for displaying its own privacy information on its site. |
| Send and receive SMS messages, store their content, and meter them for billing. | To deliver the messaging service and to charge for it correctly. | Processor, on the customer's instructions. The customer is responsible for consent, sender identification and honouring opt-out requests. |
| Store, deduplicate and organise contacts and leads submitted or ingested by the customer, and make them available for calling and messaging. | To deliver the contact management, campaign and speed-to-lead functionality the customer has bought. | Processor, on the customer's instructions. |
| Transmit call, chat, contact and lead data to third-party systems, webhooks or endpoints that the customer has configured. | Because the customer has instructed us to send its data to a destination it has chosen. | Processor, on the customer's instructions. The customer is responsible for the destination and for that recipient's handling of the data — see clause 11.6. |
| Process knowledge base content uploaded by the customer, including sending it to a third-party AI provider for indexing and summarisation. | So that assistants can answer questions from the customer's own material. | Processor, on the customer's instructions. |
| Provide an in-product AI assistant (Clara) to the customer's own staff, which reads the data held in that customer's account — including contacts, call transcripts and summaries — in order to answer their questions and perform tasks within the account. This involves sending that data to a third-party AI provider (see clause 11.3). | To deliver the in-product AI assistance the customer has bought. | Processor, on the customer's instructions. |
| Retain and make available call recordings, transcripts, chat transcripts, contacts and usage records for the life of the customer's account. | Because the customer requires access to its own records, and because they evidence what was charged. | Processor, on the customer's instructions — see section 14. |
Our own limited uses of that data are set out in clause 7.7.
7.7 Our own limited use of Platform data
The table below states our role for each activity. Where we act as processor, we do so pursuant to the documented instructions recorded in clause 2.5 of our DPA and the security limb of clause 5.1 of our DPA. Where we act as controller, it is because we determine the purpose ourselves or because the law requires the processing of us directly.
| What do we do? | Why do we do it? | What is our role and the legal basis? |
|---|---|---|
| Measure the volume of calls, minutes, messages and chats generated by an account. | To bill the customer accurately and to manage plan allowances and credit balances. | Controller. Performance of a contract with the customer. Legal obligation (accounting records). |
| Investigate and respond to security incidents affecting the Platform, including reviewing specific records where necessary. | To protect the Platform, our customers and the people they contact. | Processor, pursuant to the security limb of clause 5.1 of our DPA. The customer remains the controller and determines the legal basis. |
| Investigate suspected fraud, abuse or breach of our Terms by a customer, including reviewing specific records where necessary. | To protect the Platform, our other customers and ourselves, and to enforce our contract. | Controller. Legitimate interests: protecting the Platform, our other customers and ourselves, and enforcing our contract. |
| Produce aggregated and statistical measures of Platform performance and reliability. | To monitor and improve the accuracy and reliability of the service. | Processor, pursuant to the documented instruction in clause 2.5 of our DPA. We only use such measures where the underlying data has first been irreversibly anonymised in accordance with clause 2.5 of our DPA. |
| Respond to a lawful request from a court, regulator or law enforcement body. | Because we are required to. | Controller. Legal obligation. |
7.8 Marketing and communications information
| What do we do? | Why do we do it? | What is the legal basis? |
|---|---|---|
| Keep a record of your communication preferences, including your opt-ins and opt-outs. | So we can make sure that you only receive the communications from us that you would like to receive and so we can update our records if you change your mind. | Consent. Legitimate interests: necessary to promote our business where permitted for B2B contacts under applicable law. Legal obligation where required to evidence consent. |
| Send you marketing communications about S4W's own products and services. | To keep you informed of new offerings and developments that may be relevant to your business. | Consent (for direct marketing to individuals). Legitimate interests: necessary to promote our business where permitted for B2B contacts under applicable law. |
7.9 All Personal Data
| What do we do? | Why do we do it? | What is the legal basis? |
|---|---|---|
| Transfer Personal Data in connection with any merger, sale, transfer of assets, investment, acquisition, bankruptcy or similar corporate transaction. | To ensure the continued service and function and to protect and grow our business. | Legitimate interests: to ensure we can protect and grow our business. |
| Comply with legal and regulatory obligations, including tax, accounting, telecommunications regulation, sanctions screening and applicable data protection laws. | So we can meet our legal responsibilities under applicable law, including UK GDPR, EU GDPR where applicable, and the law of the United Arab Emirates. | Legal obligation. |
| Retain Personal Data to establish, exercise or defend legal claims. | So we can protect our interests and those of our clients. | Legitimate interests: to seek legal advice and protect ourselves, our clients or others in legal proceedings. |
| Transfer Personal Data internationally, as described in section 12. | To enable us to operate our business and to use the specialist telephony, speech and AI providers on which the Platform depends. | Legitimate interests: necessary to operate our international business. Appropriate safeguards: the UK Addendum to the EU Standard Contractual Clauses, together with a transfer risk assessment where required. |
7.10 Other processing
In limited circumstances we may process any of the Personal Data we hold to the extent necessary to defend, establish and exercise legal claims or to comply with legal or regulatory obligations.
7.11 If you do not provide Personal Data
Where we need to collect Personal Data due to a legal or regulatory obligation, or for performance of a contract, and you do not provide that data when requested, we may not be able to perform the contract we have or are trying to enter into with you (for example, to provide you with the Platform and our services). We will notify you of this at the time.
8. AUTOMATED DECISION-MAKING AND ARTIFICIAL INTELLIGENCE
8.1 What our AI actually does. We want to be clear about the extent to which our services are automated:
(a) telephone calls and website chats handled by the Platform are conducted end to end by an AI assistant. The assistant speaks, listens, asks questions, answers questions and decides what to say next. A human is not on the line unless the assistant transfers the conversation to one, or the customer's configuration provides for it;
(b) call audio is converted to text by an automated speech-to-text service, and the assistant's replies are converted to speech by an automated text-to-speech service;
(c) the content of calls and chats is processed by large language models to generate transcripts, summaries, structured extractions and outcome classifications, and to score the quality of a call against criteria the customer has configured;
(d) messages sent by the Platform, including SMS replies, may be generated by an AI model rather than written by a person;
(e) the outcome classification produced for a call or chat may determine, under rules configured by the customer, whether and when that person is contacted again by that customer; and
(f) an in-product AI assistant (Clara) is available to our customers' own staff. It reads the data held in that customer's account — which can include contact records, call transcripts and summaries — and sends it to a third-party AI provider in order to answer their questions and carry out tasks within the account.
8.2 AI output can be wrong. Transcripts, summaries, extracted fields and scores are generated automatically and are not verified by a person unless the customer chooses to review them.
8.3 Speaking to a person. If you are speaking or writing to an AI assistant and you would prefer to deal with a person, say so, and ask the assistant to transfer you or to arrange a call back. The business that is contacting you is responsible for providing a route to a human.
8.4 Article 22 position. We do not use Personal Data to make decisions that are based solely on automated processing which produce legal effects concerning you or similarly significantly affect you, within the meaning of applicable data protection laws. The automated classifications described in clause 8.1(e) determine whether a business follows up a conversation; they do not by themselves determine access to a product, a service, credit, employment or any other benefit, and any such decision is taken by the business concerned, not by us.
8.5 If we ever introduce automated decision-making, including profiling, that has legal or similarly significant effects, we will update this Privacy Notice and provide you with additional information about the logic involved, as well as the significance and envisaged consequences of such processing for you, and the rights you have in relation to it. Where a customer configures the Platform in a way that produces such effects, that customer is the controller and is responsible for the corresponding obligations.
9. HOW CAN YOU MANAGE YOUR MARKETING PREFERENCES?
9.1 Where you give us your details through a form on our website or the Platform, we will tell you at the point of collection how we will use them and, where we need your consent to send you marketing, we will ask for it separately and clearly. Where the conditions for the "soft opt-in" are met, we may send you marketing about similar products and services on that basis, and every message will give you a way to stop.
9.2 You can opt out at any time by using the unsubscribe link in any marketing email, or by contacting us at hello@s4w.com.
9.3 We will always get your express consent before we share your Personal Data with any third party for their own direct marketing purposes.
9.4 Please note that if you opt out of receiving marketing communications, you will still receive service-related communications that are essential for administrative or customer service purposes, for example, updates to our terms with you, billing notices, and checking that your contact details are correct.
10. WHAT ABOUT COOKIES?
10.1 For information about the cookies and similar technologies we use and how to change your preferences, please see our Cookies Notice at https://s4w.com/yourcalls/cookies.
10.2 So that you know what is actually in use today:
(a) our website uses Vercel Web Analytics, a privacy-focused, cookieless analytics service provided by Vercel Inc. (United States), to count page views and measure traffic. It does not set cookies and does not store identifiers on your device. You can decline it through the banner on our website;
(b) we do not use Google Analytics or Google Tag Manager;
(c) our customer portal loads a third-party integrations software development kit from an external content delivery network on every page, which allows that provider to observe that a page has been loaded;
(d) the chat assistant that our customers embed on their own websites writes a persistent identifier to the visitor's browser local storage, so that a returning visitor's conversation can be recognised. That identifier is written on the customer's website, not ours. Obtaining any consent required for it under the Privacy and Electronic Communications Regulations, and displaying the customer's own cookie and privacy information, is the responsibility of the business operating that website; and
(e) the contact page on our website embeds Google's appointment scheduling product so that you can book a meeting with us. That embed is served by Google, which will receive your IP address and the details you enter when you book.
11. WHO DO WE SHARE YOUR PERSONAL DATA WITH?
11.1 We share Personal Data with third parties who provide services to us or to our customers. We require all third parties to respect the security of Personal Data and to treat it in accordance with the law. We instruct our service providers to process Personal Data only for specified purposes and in accordance with our instructions.
11.2 The categories of recipient we disclose Personal Data to are as follows:
(a) Infrastructure, hosting and database providers — who host the Platform, our website and our databases, and run our background processing and queues.
(b) Identity and authentication providers — who authenticate users of the Platform and manage sign-in.
(c) Telephony and messaging providers — who carry calls and SMS messages, provide telephone numbers, and verify business identity for regulatory purposes.
(d) Voice and AI providers — who orchestrate voice conversations, convert speech to text and text to speech, and run the language models that generate assistant responses, transcripts, summaries, extractions and scores. See clause 11.3.
(e) Payment providers and our payment collection agent — see clause 11.4.
(f) Email, support, collaboration and search providers — who send our transactional and marketing email, hold our support tickets, host our internal collaboration, and power search and question answering on our documentation.
(g) Workflow and event-processing providers — who run the durable workflow engine on which the Platform's workflow automations execute. Event payloads processed by that engine can include call transcripts, summaries, recording links and contact records.
(h) Professional advisers, such as our tax advisers, legal advisers, auditors, insurers and accountants, where necessary for the establishment, exercise or defence of legal claims or to protect the rights or safety of our websites, the Platform or us.
(i) Regulators, courts and law enforcement, where disclosure is required by law or in the context of an investigation, regulatory requirement, judicial proceeding, court order or legal process (including to law enforcement or competent authorities such as the police or HMRC).
(j) Parties to a corporate transaction, where information about our customers, including Personal Data, may be disclosed as part of any merger, sale, transfer of our assets, investment, acquisition, bankruptcy, or similar event, including while engaging with our actual or potential investors.
(k) Error monitoring providers — we use Sentry to monitor errors in our customer dashboard. Sentry receives diagnostic information about errors, which is configured to include the IP address, request headers and user identifier of the person who encountered the error. Sentry is not used for the processing of calls, chats or messages, and conversation content is not intentionally sent to it; error diagnostics may nonetheless include fragments of request data. Sentry processes this data in its EU (Germany) region.
(l) Analytics providers — who measure traffic to our website, as described in clause 10.2(a).
11.3 AI processing you should know about specifically. Because it is material, we state expressly that:
(a) all knowledge base content uploaded by a customer — the documents, pages and other material an assistant is given to answer questions from — is processed by a third-party AI provider (Google, using its Gemini models). There is no option to disable this;
(b) full call transcripts are sent to a third-party AI provider (OpenAI) in order to score and classify calls;
(c) voice calls are processed by third-party speech-to-text, text-to-speech, voice orchestration and language model providers. The majority of production assistants are served by Groq; OpenAI, xAI, ElevenLabs, Deepgram and our voice orchestration provider also receive conversation content; and
(d) data held in a customer's account, including contacts, call transcripts and summaries, is sent to a third-party AI provider (OpenAI) when a member of that customer's staff uses our in-product AI assistant (Clara).
11.4 Payments. Card details are entered directly with our current payment provider (Stripe) and are never received or stored by us; we hold only the card brand, the last four digits, the expiry date and a payment-method reference issued by our payment provider. Our payment provider also receives your company name, email address, billing address and any tax or VAT identification number you give us. Customers who have not yet been migrated to Stripe are served by our previous payment provider, which processes billing contact details and payment-method metadata; that provider is named in the sub-processor annex to our DPA. Payments are collected by Dial Square Consultancy Ltd as our payment collection agent and merchant of record (see clause 2.3), and Dial Square Consultancy Ltd is the name that appears on your statement.
11.5 Our full list of sub-processors. A complete, dated list of the sub-processors we engage, showing each one's role and country, is published as Annex D to our DPA at https://s4w.com/yourcalls/dpa. We will notify our customer's nominated Administrator by email at least 30 days before a new sub-processor begins processing, and the customer may object within 15 days, as set out in clauses 5.5.2 to 5.5.4 of the DPA.
11.6 Integrations you or our customer choose. Where a customer configures an integration, a webhook or an outbound connection, we transmit call, chat, contact and lead data to the destination that customer has chosen. Those destinations are not our sub-processors: they are onward transfers directed by the controller. We do not control those recipients and the customer is responsible for them and for their handling of the data. We apply technical protections to prevent our systems being used to reach internal or private network addresses, but we do not vet the destination itself.
11.7 We may provide anonymous or aggregated information to analytics providers to help us improve and optimise our services. We will only share this information in a form that does not directly or indirectly identify you.
12. WHAT HAPPENS IF WE SHARE YOUR PERSONAL DATA WITH ORGANISATIONS OUTSIDE OF THE UK (AND/OR EEA)?
12.1 Where your data is stored. The primary database and file storage for the Platform — including customer accounts, contacts, call records, transcripts, summaries and call recordings — are hosted in the United Kingdom (London), and are operated on Amazon Web Services infrastructure by our database provider. Personal Data is also processed, and in the case of call artefacts stored, by the providers identified in Annex D to our DPA, some of which are outside the UK and the EEA — see clause 12.2.
12.2 Transfers that do take place. Notwithstanding clause 12.1, some processing necessarily takes place outside the UK and the EEA:
(a) conversation content — call audio, transcripts, chat messages, knowledge base content and the prompts and responses exchanged with AI models — is processed by voice, speech and AI providers that are headquartered in, and process data in, the United States. This includes our voice orchestration provider and our speech-to-text, text-to-speech and language model providers, and the workflow engine that carries event payloads containing this content;
(b) support, collaboration, email, search and analytics providers may process contact details, correspondence and usage data outside the UK and the EEA;
(c) payment processing for customers not yet migrated to Stripe is carried out by our previous payment provider, which is established in, and processes billing contact details and payment-method metadata in, the United Arab Emirates. That provider is named in the sub-processor annex to our DPA. The United Arab Emirates is not the subject of a UK adequacy decision;
(d) S4W is established in the United Arab Emirates, and our authorised personnel there may access Personal Data in order to operate, support and secure our services. The United Arab Emirates is not the subject of a UK adequacy decision;
(e) application hosting and identity — our web application, our application programming interface and worker services, and our identity provider are operated by providers established in the United States, and Personal Data is processed by them in the course of delivering the Platform; and
(f) call artefacts — call audio, transcripts and call metadata are also held by our voice orchestration provider in the United States.
12.3 How we protect transfers. Where we transfer Personal Data outside of the UK and/or the European Economic Area (EEA), we will ensure that an adequate level of protection is afforded to it by implementing one of the following safeguards:
(a) the country has been deemed to provide an adequate level of protection for Personal Data by the UK and/or European Commission; or
(b) we use the UK Addendum to the EU Standard Contractual Clauses, issued by the Information Commissioner and approved for use in the UK, which gives Personal Data equivalent protection.
12.4 Where we rely on clause 12.3(b), we carry out a transfer risk assessment and apply supplementary measures where the assessment shows they are needed.
12.5 For more information about these safeguards, or to request a copy of the relevant transfer mechanism, please contact us at hello@s4w.com.
13. HOW DO WE PROTECT YOUR PERSONAL DATA?
13.1 We are committed to protecting individuals' Personal Data. We put in place appropriate technical and organisational measures to help protect the security of your Personal Data. However, you should be aware that no system is ever completely secure.
13.2 The measures we currently apply include:
(a) encryption in transit — data moving between you, our services and our providers is protected using industry-standard transport encryption;
(b) encryption at rest — our databases and file storage are encrypted at rest by our infrastructure providers;
(c) access controls — access to production systems is limited to personnel who need it for their role, and is granted through named accounts;
(d) passwordless authentication — customers sign in using a one-time code sent by email, or a Google sign-in. We do not store passwords;
(e) tenant scoping — customer data is scoped to the customer's own account, enforced by database row-level security policies on customer tables and by scoping in our application code for the server-side services that operate with elevated database credentials;
(f) encryption of stored secrets — credentials, API keys and integration secrets are encrypted at rest, and API keys are stored as one-way hashes rather than in plain text;
(g) input validation — requests to our services are validated against defined schemas before they are processed; and
(h) pseudonymisation — where we do not need to hold an identifier in full, we hold a truncated, salted hash of it instead (for example, visitor IP addresses in chat sessions).
13.3 What we do not claim. We do not currently hold ISO 27001, SOC 2 or equivalent certification, and we do not currently operate penetration testing, automated vulnerability scanning, multi-factor authentication, record-level access logging or automated anomaly detection. We will update this section as those measures are introduced.
13.4 Staff access to customer accounts. A limited number of authorised S4W personnel are able to access customer accounts and the data in them, including call recordings, transcripts and chat transcripts, for support, troubleshooting and security purposes. Where a member of our personnel accesses a customer account by impersonating a user of that account, that session is logged. Direct reads of individual records by authorised personnel are not individually logged.
13.5 We have procedures to deal with any suspected personal data breach. Where we act as processor, we will notify the customer concerned without undue delay after becoming aware of a personal data breach, and in any event in sufficient time to allow the customer to meet its own obligations under Article 33 of the UK GDPR. Where we act as controller, we will notify the Information Commissioner's Office and, where required, affected individuals, in accordance with our legal obligations.
14. HOW LONG DO WE KEEP YOUR PERSONAL DATA FOR?
14.1 We will only retain your Personal Data for as long as reasonably necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, regulatory, tax, accounting or reporting requirements. We may retain your Personal Data for a longer period in the event of a complaint or if we reasonably believe there is a prospect of litigation in respect of our relationship with you.
14.2 The periods we apply are set out below.
| Category of data | How long we keep it |
|---|---|
| Customer account and Authorised User data | For the life of the account. Deleted within 60 days of a written deletion request, and in any event within 12 months of termination of the account, under our own controller retention policy, which applies the same periods we apply as processor. |
| Account impersonation session logs (see clause 13.4) | For the life of the account. Deleted with the customer account data, and in any event within 12 months of termination of the account. |
| Billing, payment and transaction records | Six years from the end of the financial year to which they relate, to meet accounting and tax requirements. Card details are not held by us; we hold only card brand, last four digits, expiry date and a payment-method reference from our payment provider, for the life of the account. |
| Call recordings, transcripts, summaries, outcomes and scores | For the life of the customer's account. Deleted within 60 days of a written deletion request, and in any event within 12 months of termination of the account, as set out in clause 5.6 of our DPA. |
| Chat sessions, chat messages and chat visitor identifiers | As for call data above. |
| Contacts, leads and imported lists | As for call data above. |
| SMS message content and delivery records | As for call data above. Metering records that support a billing entry are kept for six years in line with the billing row above. |
| Usage records (minutes, messages, credit movements) | For the life of the account, and for six years where they form part of a billing record. |
| Knowledge base source files uploaded by a customer | Files uploaded to a knowledge base are retained in our storage for the life of the account, and a copy is held by our voice orchestration provider. Where a large file is converted before use, the original is deleted once conversion completes and the converted text is retained instead. The extracted content remains available to the customer's assistant for as long as the customer keeps it. |
| Contact import source files (CSV/spreadsheet uploads) | Deleted once the import completes. Files from failed imports may persist until deleted manually. |
| Exported files generated from the Platform | The download link expires after seven days. The exported file itself is retained for the life of the account and is deleted with the account data, or earlier on request. |
| Support tickets and correspondence | For the life of the account and for two years afterwards, after which they are deleted under the manual deletion process described in clause 14.3. |
| Marketing contacts and preferences | Until you opt out or withdraw consent, after which we keep the minimum record necessary (your contact identifier and the fact that you opted out) so that we do not contact you again. |
| Website and server logs held by our hosting providers | For the period applied by the hosting provider concerned, which is typically no more than 30 days. |
14.3 How deletion happens. We do not currently operate an automated deletion or purge process. Deletion is carried out manually, on written request, under a documented internal process. We aim to complete a deletion request within 60 days of receiving it and of confirming the identity and authority of the person making it, in line with clause 5.6.3 of our DPA. That is a different commitment from the one-month time limit for responding to a data subject's rights request under clause 15.6, which is a statutory response period and applies to requests made to us as controller. Deleting a contact record does not by itself delete the call, chat or message records associated with that contact; a request to delete those records should say so.
14.4 Where we hold data as processor, we act on the instructions of the customer who is the controller. Retention periods that a customer sets for its own account, and requests to delete data before the periods above, are matters for that customer to instruct us on.
14.5 Some of our providers keep their own copies of data for their own retention periods, and backups are overwritten on a rolling cycle. Personal Data may persist in our encrypted backups for up to 7 days after it has been deleted from the live system, after which those backups are overwritten. Backups are not used for any processing purpose.
15. WHAT ARE YOUR RIGHTS IN RELATION TO THE PERSONAL DATA WE HOLD?
15.1 You have a number of rights under data protection laws in relation to your Personal Data. You have the right to:
(a) Request access to your Personal Data (commonly known as a "subject access request"). This enables you to receive a copy of the Personal Data we hold about you and to check that we are lawfully processing it.
(b) Request correction of the Personal Data that we hold about you. This enables you to have any incomplete or inaccurate data we hold about you corrected, though we may need to verify the accuracy of the new data you provide to us.
(c) Request erasure of your Personal Data in certain circumstances. This enables you to ask us to delete or remove Personal Data where there is no good reason for us continuing to process it. You also have the right to ask us to delete or remove your Personal Data where you have successfully exercised your right to object to processing (see below), where we may have processed your information unlawfully or where we are required to erase your Personal Data to comply with local law. Note, however, that we may not always be able to comply with your request for erasure for specific legal reasons which will be notified to you, if applicable, at the time of your request.
(d) Object to processing of your Personal Data where we are relying on a legitimate interest (or those of a third party) as the legal basis for that particular use of your data (including carrying out profiling based on our legitimate interests). In some cases, we may demonstrate that we have compelling legitimate grounds to process your information which override your right to object.
(e) You also have the absolute right to object at any time to the processing of your Personal Data for direct marketing purposes.
(f) Request the transfer of your Personal Data to you or to a third party. We will provide to you, or a third party you have chosen, your Personal Data in a structured, commonly used, machine-readable format. Note that this right only applies to automated information which you initially provided consent for us to use or where we used the information to perform a contract with you.
(g) Withdraw consent at any time where we are relying on consent to process your Personal Data. However, this will not affect the lawfulness of any processing carried out before you withdraw your consent. If you withdraw your consent, we may not be able to provide certain products or services to you. We will advise you if this is the case at the time you withdraw your consent.
(h) Request restriction of processing of your Personal Data. This enables you to ask us to suspend the processing of your Personal Data in one of the following scenarios:
- if you want us to establish the data's accuracy;
- where our use of the data is unlawful but you do not want us to erase it;
- where you need us to hold the data even if we no longer require it as you need it to establish, exercise or defend legal claims; or
- you have objected to our use of your data but we need to verify whether we have overriding legitimate grounds to use it.
15.2 If you wish to exercise any of the rights set out above, please contact us at hello@s4w.com.
15.3 If your data is held by us on behalf of one of our customers. Where we hold Personal Data as a processor (see sections 3 and 4), we are not permitted to act on a request about that data without the controller's instruction. Please send your request to the business that contacted you or that you dealt with. If you send it to us, we will tell you so, help you identify the right business where we can, and pass your request to that business so that it can instruct us. We will then assist that business to respond to you.
15.4 You will not have to pay a fee to access your Personal Data (or to exercise any of the other rights). However, we may charge a reasonable fee if your request is clearly unfounded, repetitive or excessive. Alternatively, we could refuse to comply with your request in these circumstances.
15.5 What we may need from you
We may need to request specific information from you to help us confirm your identity and ensure your right to access your Personal Data (or to exercise any of your other rights). This is a security measure to ensure that Personal Data is not disclosed to any person who has no right to receive it. We may also contact you to ask you for further information in relation to your request to speed up our response.
15.6 Time limit to respond
We try to respond to all legitimate requests within one month. Occasionally it could take us longer than a month if your request is particularly complex or you have made a number of requests. In this case, we will notify you and keep you updated.
This one-month period is the statutory period for responding to a request to exercise the rights set out in clause 15.1. It is a different thing from the 60-day period within which we aim to complete the deletion of data under clause 14.3, which is the operational period for carrying out a deletion once it has been agreed or instructed.
16. CONTACT US IF YOU HAVE A QUESTION OR A COMPLAINT
16.1 If you have a question or a complaint about how we handle your Personal Data, please contact us at hello@s4w.com, or write to us at the address in clause 2.1. You may also contact our UK representative (clause 2.4).
16.2 You have the right to make a complaint at any time to the relevant data protection regulator. In the UK this is the Information Commissioner's Office (ICO), www.ico.org.uk. If you are in the European Economic Area, you may complain to the supervisory authority in the country where you live or work, or where you believe the issue arose.
16.3 We would, however, appreciate the chance to deal with your concerns before you approach any regulator, so in the first instance please contact us at hello@s4w.com.
17. UPDATES TO THIS PRIVACY NOTICE
17.1 This is Version 1.0 of this Privacy Notice. It does not supersede a previous version of this notice. The date from which it takes effect is stated at the head of this notice.
17.2 We may update this Privacy Notice from time to time and we keep it under regular review. Each version carries a version number and an effective date.
17.3 Where we make a material change, we will notify account holders by email to their registered address and by a notice in the Platform before the change takes effect. Continuing to use our services after the effective date of a change means the updated Privacy Notice applies to you.
17.4 Superseded versions are archived and are available on request from hello@s4w.com.
18. THIRD-PARTY LINKS
18.1 Our website may include links to third-party websites, plug-ins and applications. Clicking on those links or enabling those connections may allow third parties to collect or share data about you. We do not control these third-party websites and are not responsible for their privacy statements. When you leave our website, we encourage you to read the privacy notice of every website you visit.