Graftline

Privacy Policy

Last updated: 7 August 2026

Who we are

Graftline provides an automated phone answering service for UK tradespeople. Graftline is the controller of tradespeople's account, billing and service data. For customer enquiry data, the tradesperson or trade business you called is normally the controller and Graftline acts as its processor. Graftline is a separate controller where we decide a purpose ourselves, including our public demo line and proportionate service security, support and quality assurance. Contact: contact@graftline.co.uk.

What we collect

  • Account data (tradespeople): business name, trade, phone number, email, and payment details. Payments are handled by Stripe — we never see your full card number.
  • Call data (callers): when you ring a business that uses Graftline, an AI-powered automated receptionist processes the call audio and creates a transcript, summary and structured enquiry details. These can include your name, callback number, message or job description, urgency, postcode, service address, email and practical access details where relevant. We do not ask for health details; the service records only an urgency flag and practical information needed for the enquiry. The opening message tells you that the call is recorded and transcribed.
  • Usage data: call minutes and outcomes, used for billing and the business's own reporting.
  • App and device data: if you use the Graftline mobile app and turn on job alerts, we store an opaque push token, phone platform and app version. Alerts contain no customer name, number, address or job description. We do not collect precise location, contacts, photos or advertising identifiers.

Why we process it (legal bases)

We process account data to perform our contract with the tradesperson (UK GDPR Article 6(1)(b)). The trade business normally relies on its legitimate interest in receiving and responding to customer enquiries (Article 6(1)(f)); Graftline processes that data on its documented instructions. Where Graftline acts as controller for service security, support or quality assurance, we also rely on legitimate interests, limited by access controls, data minimisation and the 90-day call-content retention period.

We give the recording and transcription notice directly when we collect the data, as required by UK GDPR Article 13. Continuing in silence is not treated as consent. You can object or ask a question using the contact details below.

Where it goes (our processors)

Job details are delivered to the tradesperson you were trying to reach, by WhatsApp or SMS and their dashboard. We never sell personal data, full stop. To run the service we use these processors and sub-processors. Some process data outside the UK; where restricted transfers apply, the relevant controller uses an applicable adequacy mechanism or contractual safeguards:

  • Retell AI — automated voice, call audio, transcription, call analysis and call logs.
  • Twilio — phone numbers, call routing and SMS delivery (US/EU).
  • Supabase — our database and account login (hosted in the EU).
  • Stripe — payments and billing (US/EU).
  • Resend — transactional email (US).
  • Vercel — website and API hosting (US/EU edge).
  • Expo — delivery of optional mobile push notifications through Apple or Google (US). Push payloads contain no customer personal data.
  • Google — site analytics (GA4) and advertising measurement, only after cookie consent (US).
  • Rewardful — affiliate referral tracking, only after cookie consent (US).

How long we keep it

Retell-hosted call audio, transcripts and call logs are retained for no more than 90 days. Graftline's local product makes the transcript, summary and collected call fields available for up to 90 days; call-content references are then removed. Operational enquiry or job records supplied to the trade business can be kept for longer as its business records. Account data is deleted within 30 days of account closure, except records we must retain for legal, tax, security or dispute purposes. Mobile push tokens are revoked when alerts are turned off or the account is closed.

If you called a business that uses Graftline

This is the direct-collection notice for callers under UK GDPR Article 13. When you ring a trade business using Graftline, an automated AI receptionist run by Graftline answers on that business's behalf. The opening tells you that the call is recorded so the details can be captured accurately. The recording is transcribed to help the business receive the enquiry and decide how to respond.

The trade business receives the transcript, summary and collected enquiry fields, but it is not given audio playback access. Audio is retained in Retell for up to 90 days and is accessible only to authorised Graftline administrators for quality and support. You can object to this processing, decline to provide further details, or end the call. Contact Graftline or the business you called to exercise your rights.

Your rights

Depending on the circumstances, you can ask for access, correction, deletion or restriction, obtain portable data, and object to processing based on legitimate interests. These rights can have legal limits. To exercise them or raise an objection, email contact@graftline.co.uk . We will respond within the period required by data protection law and may need to involve the trade business as controller. If you're unhappy with how your data was handled, you can complain to the ICO (ico.org.uk).

Security

Access is restricted according to role. Contractors can access the transcript, summary and collected fields for their own calls; they do not receive call-audio access. Retell-hosted audio is limited to authorised Graftline administrators for quality and support and is subject to the 90-day retention setting. We use technical and organisational measures appropriate to the service and require our processors to protect personal data.