CallMate is built for UK businesses. This page summarises how we support compliance with the UK GDPR and EU GDPR.
Last updated: 18 June 2026
For your account data, CallMate acts as a data controller. For the personal data of your callers and leads that flows through your account, CallMate acts as a data processor on your behalf.
To exercise any of these rights, email privacy@getcallmate.co.uk. We aim to respond within 30 days.
Business customers can request our Data Processing Agreement (DPA) for signature. Email legal@getcallmate.co.uk.
We use a small set of carefully chosen sub-processors to deliver the service, including Twilio (telephony), Stripe (payments), Supabase (database & auth) and our cloud hosting provider. A current list is available on request.
Where personal data is transferred outside the UK or EEA, we rely on UK-recognised safeguards such as the UK International Data Transfer Agreement (IDTA) or the UK addendum to the EU Standard Contractual Clauses.
We use TLS in transit, encryption at rest, role-based access controls, and audit logging. Find more detail in our Privacy Policy.
If you believe your data has been mishandled, email privacy@getcallmate.co.uk. You may also contact the UK Information Commissioner's Office (ICO).