Calling Bees
Back home

Privacy Policy

Last updated: July 2026

Draft — pending legal review. This policy describes how the Calling Bees platform actually handles data, but it has not yet been reviewed by counsel. Call recording is regulated differently across jurisdictions, and this text should not be treated as final or relied upon as legal advice until that review is complete.

This policy explains how Calling Bees handles personal data across our website, our operator application, and the client portal. If you are a customer processing personal data of EU, UK, or Swiss residents through our platform, our Data Processing Addendum governs that processing and takes precedence where the two differ.

Controller and processor roles

Our role depends on whose data is involved. For our own customers — the businesses that sign up for Calling Bees — we act as a data controller for account, billing, and usage data. For the contact records our customers upload and the people they call, our customers are the controller and we act as a processor on their documented instructions. If you received a call from an AI agent running on Calling Bees and want your data removed, the business that called you controls that decision; contact us and we will route your request to them and assist in responding.

Data we collect

  • Account data — name, work email, hashed credentials, workspace and team membership, and authentication tokens.
  • Contact records — the names, phone numbers, email addresses, and custom fields our customers upload in order to place calls.
  • Call audio and transcripts — recordings of calls placed or received through the platform, and the machine-generated transcripts derived from them.
  • Call metadata — timestamps, duration, outcome and disposition, detected intent, and meeting-booking results.
  • Billing data — subscription tier and usage counts. Card details are handled by our payment processor and do not reach our servers.

Call recording and consent

Calls placed through Calling Bees may be recorded and transcribed so that the platform can operate and so our customers can review outcomes. Recording laws differ by jurisdiction — some require the consent of every party on the call. Our customers are responsible for determining what notice and consent their calling programs require and for configuring their agents accordingly. We provide controls to announce recording at the start of a call; we do not determine on a customer’s behalf whether a particular use is lawful in a given jurisdiction.

How we use data

We use personal data to place and receive calls, transcribe and interpret conversations in real time, book meetings on connected calendars, sync outcomes to connected CRMs, produce analytics for the account that owns the data, bill for usage, and secure the platform against abuse. We do not sell personal data, and we do not use customer call content to train our own models.

Who we share data with

Delivering a live AI phone call requires several specialist providers, each of which processes some data on our behalf: telephony carriers, real-time voice infrastructure, speech recognition, text-to-speech, and large language model providers, plus cloud hosting, payment processing, and email delivery. Data also flows to the CRM and calendar systems a customer chooses to connect, at that customer’s direction. Every sub-processor is reviewed before onboarding; the current list, naming each provider and the regions it operates in, is available on request — see our DPA for details. We may also disclose data where legally required, or in connection with a merger or acquisition, in which case we will give notice before your data becomes subject to a different policy.

International transfers

We operate infrastructure in multiple regions, and our sub-processors may process data outside your country. For customers in the EU, UK, or Switzerland we rely on the Standard Contractual Clauses, together with the UK Addendum or Swiss equivalent where applicable, to legitimize those transfers.

Retention

Call recordings, transcripts, and contact records are retained for as long as the owning account remains active, unless that customer configures a shorter retention period or deletes the records sooner. When a customer requests deletion, we remove the data within 30 days, excluding backup copies that expire on their own cycle and records we are legally required to keep. Account and billing records are retained as long as needed to meet tax and accounting obligations.

Security

We encrypt data in transit and at rest, isolate tenant data by workspace, apply least-privilege access controls, and encrypt per-workspace telephony credentials with a separate key. Our Security page describes these measures in more detail. No system is immune to compromise; if a breach affects your personal data we will notify you and the relevant authorities as required by law.

Your rights

Depending on where you live, you may have the right to access the personal data we hold about you, correct it, delete it, object to or restrict how it is processed, receive it in a portable format, or withdraw consent you previously gave. Residents of California, and of jurisdictions with comparable laws, have the right not to be discriminated against for exercising these rights. To make a request, email the address below. Where we act as a processor, we will forward your request to the customer who controls the data. You may also lodge a complaint with your local supervisory authority.

Children

Calling Bees is a business product and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child’s data has reached our platform, contact us and we will delete it.

Changes to this policy

We will update this page when our practices change and revise the date at the top. For material changes affecting how we use personal data, we will notify account holders directly.

Contact

For privacy questions or to exercise any of the rights above, email privacy@callingbees.io. For data processing agreements, email legal@callingbees.io.