Security and privacy
This page describes how the platform is built. It is written for an owner deciding whether to trust it with their customers’ details, and it says what is not true as carefully as what is.
It is not a privacy policy and not a legal undertaking. Our written terms and privacy policy are being prepared and will be published before general availability.
1. Each business’s data is separate
Callahand serves many businesses from one system. Every record that belongs to a business carries that business’s identifier, and every read and write is authorised on the server against the account making the request.
An identifier supplied by a browser is treated as untrusted input and is never used to decide what somebody may see. Separation is enforced where the data is read, not by what a screen chooses to display — the difference matters, because the second kind can be undone by changing a URL.
2. What Callahand stores from a call
Callahand’s application does not intentionally store a call recording or full live-call transcript as part of the V1 voice path — nothing in the running system writes one. Voice infrastructure providers may process, transcribe, record, or retain call data according to the service configuration and their applicable terms; our privacy policy names the providers involved.
What is kept is the structured outcome: who rang, the number they rang from, what they needed, what was booked, how the call ended, and whether something still needs a person. That is what an owner actually uses the next morning, and it is a great deal less than a recording.
3. What is collected, and why
Only what a call requires in order to be useful to you:
- From the caller — their name, the number they rang from, the address the job is at, what the job is, and how urgent it sounded.
- From you — your services, hours, service area, emergency rules, appointment settings, and the address a summary should reach.
- About the call — when it started and ended, what was offered, what was booked, and what could not be done.
Nothing is collected for advertising, resale or profiling, and customer data is not used to train any model.
4. The services involved in a call
A phone call reaches Callahand through a telephony provider, and understanding what a caller has just said is done by an external language-model service. The most recent thing the caller said is sent to that service, classified, and discarded; we hold it in memory for the length of one request and do not store it. What that service retains is governed by its own configuration and terms.
What is deliberately not sent is as important: no accumulating transcript, no business identifier, no caller phone number, no address, no email address, and no credential. The service is asked to choose among options this platform supplies, and an answer outside those options is discarded.
Callahand has not approved the use of any customer data to train or improve any model, ours or a vendor’s.
5. Credentials and access
When you connect a calendar, the access granted is the narrowest the booking needs. The resulting credentials are encrypted before they are stored, and they are never written to a log or sent to a browser.
Connecting a credential, publishing a configuration, changing who has access and removing somebody are all recorded, so there is a record of who changed what.
6. What your callers are told
The receptionist identifies itself as an AI assistant at the start of every call. This is part of the product rather than a setting, and it cannot be quietly switched off.
It does not claim to be a person if asked, it does not promise a technician, a price, a time or a service area that has not been confirmed, and when it cannot help it says so rather than improvising. Emergency handling is written as fixed rules with their own tests, and it overrides ordinary intake — a caller describing a hazard is not taken through a booking flow.
7. What we do not claim
Callahand holds no security certification and no privacy certification, has not completed a third-party audit, and does not describe itself as compliant with any particular regulation. We are not going to display a badge we have not earned.
Canadian privacy and telecom requirements vary by province, by industry, by where your customers are and by the kind of communication involved. We can tell you accurately how the system behaves, which is what this page does. Whether that meets an obligation specific to your business is a question for your own advisers, and we would rather you asked them than took our word for it.
8. Where it runs
The platform is built and hosted in North America, and the database holding business and call records is in Canada. Where a particular supporting service processes data is something we will state specifically, in writing, before you go live — not something we will summarise generously here.
9. Asking us something
If you need detail this page does not cover — for a client, an insurer, or your own counsel — email support@callahanddigital.com and a person will answer it directly. If the honest answer is “not yet”, that is the answer you will get.