Privacy Policy
Last updated: 7 August 2026
Who we are
What we collect
- Account data (tradespeople): business name, trade, phone number, email, and payment details. Payments are handled by Stripe — we never see your full card number.
- Call data (callers): when you ring a business that uses Graftline, an AI-powered automated receptionist processes the call audio and creates a transcript, summary and structured enquiry details. These can include your name, callback number, message or job description, urgency, postcode, service address, email and practical access details where relevant. We do not ask for health details; the service records only an urgency flag and practical information needed for the enquiry. The opening message tells you that the call is recorded and transcribed.
- Usage data: call minutes and outcomes, used for billing and the business's own reporting.
- App and device data: if you use the Graftline mobile app and turn on job alerts, we store an opaque push token, phone platform and app version. Alerts contain no customer name, number, address or job description. We do not collect precise location, contacts, photos or advertising identifiers.
Why we process it (legal bases)
We process account data to perform our contract with the tradesperson (UK GDPR Article 6(1)(b)). The trade business normally relies on its legitimate interest in receiving and responding to customer enquiries (Article 6(1)(f)); Graftline processes that data on its documented instructions. Where Graftline acts as controller for service security, support or quality assurance, we also rely on legitimate interests, limited by access controls, data minimisation and the 90-day call-content retention period.
We give the recording and transcription notice directly when we collect the data, as required by UK GDPR Article 13. Continuing in silence is not treated as consent. You can object or ask a question using the contact details below.
Where it goes (our processors)
Job details are delivered to the tradesperson you were trying to reach, by WhatsApp or SMS and their dashboard. We never sell personal data, full stop. To run the service we use these processors and sub-processors. Some process data outside the UK; where restricted transfers apply, the relevant controller uses an applicable adequacy mechanism or contractual safeguards:
- Retell AI — automated voice, call audio, transcription, call analysis and call logs.
- Twilio — phone numbers, call routing and SMS delivery (US/EU).
- Supabase — our database and account login (hosted in the EU).
- Stripe — payments and billing (US/EU).
- Resend — transactional email (US).
- Vercel — website and API hosting (US/EU edge).
- Expo — delivery of optional mobile push notifications through Apple or Google (US). Push payloads contain no customer personal data.
- Google — site analytics (GA4) and advertising measurement, only after cookie consent (US).
- Rewardful — affiliate referral tracking, only after cookie consent (US).
How long we keep it
If you called a business that uses Graftline
This is the direct-collection notice for callers under UK GDPR Article 13. When you ring a trade business using Graftline, an automated AI receptionist run by Graftline answers on that business's behalf. The opening tells you that the call is recorded so the details can be captured accurately. The recording is transcribed to help the business receive the enquiry and decide how to respond.
The trade business receives the transcript, summary and collected enquiry fields, but it is not given audio playback access. Audio is retained in Retell for up to 90 days and is accessible only to authorised Graftline administrators for quality and support. You can object to this processing, decline to provide further details, or end the call. Contact Graftline or the business you called to exercise your rights.