Privacy Policy

Last Updated: 1 January 2026

1. Introduction

This Privacy Policy explains how XEROTECH LTD (“we”, “us”, “our”), trading as CallGPT, collects, uses, and protects your personal data when you use our AI-powered communication platform at callgpt.co.uk and web.callgpt.co.uk (the “Service”).

We are committed to protecting your privacy and handling your data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

2. Data Controller

XEROTECH LTD 71-75 Shelton Street Covent Garden London, WC2H 9JQ United Kingdom

Company Registration No: 14474495 ICO Registration No: ZC065188

Contact: privacy@xerotech.io

3. Information We Collect

3.1 Information You Provide

Data TypeExamplesPurpose
Account InformationName, email address, password (hashed)Create and manage your account
Payment InformationProcessed by Stripe (we don’t store card details)Process subscriptions and payments
Communication ContentChat messages, prompts, uploaded filesProvide AI conversation services
Support CommunicationsEmails, support ticketsRespond to your enquiries

3.2 Information Collected Automatically

Data TypeExamplesPurpose
Usage DataFeatures used, session duration, message countsImprove service and enforce usage limits
Technical DataIP address, browser type, device informationSecurity, troubleshooting, analytics
CookiesSession cookies, preference cookiesEssential service functionality

3.3 AI-Generated Content

When you use CallGPT, your prompts are processed by third-party AI providers (OpenAI, Anthropic, Google) to generate responses. We implement automatic privacy protection that strips sensitive information (such as National Insurance numbers, payment card numbers, and phone numbers) from messages before processing where technically feasible.

4. How We Use Your Information

We process your personal data based on the following legal bases under UK GDPR:

PurposeLegal Basis
Provide and maintain the ServiceContract performance
Process payments and subscriptionsContract performance
Send service-related communicationsContract performance
Respond to support requestsContract performance
Prevent fraud and abuseLegitimate interests
Improve and develop the ServiceLegitimate interests
Comply with legal obligationsLegal obligation
Send marketing communications (with consent)Consent

5. Data Sharing

We share your personal data with the following categories of recipients:

5.1 Service Providers

ProviderPurposeLocationSafeguards
Vercel Inc.Website hostingUnited StatesStandard Contractual Clauses
MongoDB Inc.Database hostingIreland (EU)EU Adequate
Stripe Inc.Payment processingUnited StatesEU-US Data Privacy Framework
OpenAI LLCAI processingUnited StatesStandard Contractual Clauses
Anthropic PBCAI processingUnited StatesStandard Contractual Clauses
Google LLCAI processingUnited StatesEU-US Data Privacy Framework
Resend Inc.Email deliveryUnited StatesStandard Contractual Clauses

5.2 Other Disclosures

We may also disclose your data:

  • To comply with legal obligations or court orders
  • To protect our rights, property, or safety
  • In connection with a business transfer or merger (with prior notice)

We do not sell your personal data to third parties.

6. International Transfers

Some of our service providers are located outside the UK and European Economic Area (EEA). When we transfer your data internationally, we ensure appropriate safeguards are in place:

  • Standard Contractual Clauses (SCCs): Approved contractual terms that provide adequate protection
  • EU-US Data Privacy Framework: For US companies certified under this framework
  • Adequacy Decisions: For countries the UK has deemed to provide adequate protection

7. Data Retention

We retain your personal data for as long as necessary to provide the Service and fulfil the purposes described in this policy:

Data TypeRetention Period
Account informationDuration of account + 30 days after deletion
Chat messages and sessionsDuration of account + 30 days after deletion
Generated artifactsDuration of account + 30 days after deletion
Payment records7 years (legal requirement)
Support communications3 years
Server logs90 days

After these periods, data is securely deleted or anonymised.

8. Your Rights

Under UK GDPR, you have the following rights:

RightDescription
AccessRequest a copy of your personal data
RectificationRequest correction of inaccurate data
ErasureRequest deletion of your data (“right to be forgotten”)
RestrictionRequest limitation of processing
PortabilityReceive your data in a portable format
ObjectionObject to processing based on legitimate interests
Withdraw ConsentWithdraw consent at any time (where consent is the legal basis)

To exercise any of these rights, contact us at privacy@xerotech.io. We will respond within one month.

8.1 Account Deletion

You can delete your account and all associated data at any time through:

Upon deletion, we will:

  • Remove your account and profile information
  • Delete all chat sessions and messages
  • Delete all generated artifacts
  • Cancel any active subscriptions
  • Retain only data required by law (e.g., payment records for 7 years)

9. Data Security

We implement appropriate technical and organisational measures to protect your personal data, including:

  • Encryption in transit (TLS 1.2+)
  • Encryption at rest (AES-256)
  • Secure password hashing
  • Access controls and authentication
  • Regular security assessments
  • Incident response procedures

Our infrastructure providers maintain industry certifications including SOC 2 Type II and ISO 27001.

10. Children’s Privacy

CallGPT is not intended for users under 18 years of age. We do not knowingly collect personal data from children. If you believe we have collected data from a child, please contact us immediately at privacy@xerotech.io.

11. Cookies

We use essential cookies to operate the Service and optional analytics cookies with your consent. For details, see our Cookie Policy.

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes by:

  • Posting a notice on our website
  • Sending an email to your registered address

The “Last Updated” date at the top indicates when the policy was last revised.

13. Complaints

If you are unhappy with how we handle your personal data, you have the right to lodge a complaint with the Information Commissioner’s Office (ICO):

Information Commissioner’s Office Wycliffe House Water Lane Wilmslow Cheshire, SK9 5AF

Website: https://ico.org.uk Telephone: 0303 123 1113

14. Contact Us

For any questions about this Privacy Policy or our data practices:

Email: privacy@xerotech.io Address: XEROTECH LTD, 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ


XEROTECH LTD | Company No: 14474495 | ICO Registration: ZC065188