Legal

Privacy notice

What personal data Dialspire holds, why we hold it, who else touches it, how long it stays, and what you can ask us to do about it.

Last updated 21 August 2026

Draft, pending professional review. This document describes how Dialspire actually works today, but it has not been reviewed by a solicitor and some details are still to be filled in. Please don’t rely on it as a final statement of our obligations.

Our role, and yours

Dialspire wears two hats, and which one applies decides who you should be talking to.

We are the controller for account data

When you sign up, pay, sign in, or email us, we decide what to do with that information. For that data we are the controller under UK GDPR, and this notice is our Article 13 notice to you.

We are a processor for your calling data

The leads your team imports, the calls they make, the notes and transcripts attached to them — you decide what goes in, why, and who it belongs to. For that data you are the controller and Dialspire is your processor. We act on your instructions, we do not use your lists for our own purposes, and we do not sell them to anybody. The terms governing that relationship are in our data processing agreement.

If you were called by a business using Dialspire and want to know why they hold your number, the answer is with that business, not with us — they chose to call you. We have set out what we can still do to help in “If one of our customers called you”.

Who we are

Dialspire is a trading name of [REGISTERED COMPANY NAME], a company registered in [PART OF THE UK, e.g. England and Wales] under company number [COMPANY REGISTRATION NUMBER], with its registered office at [REGISTERED OFFICE ADDRESS].

We are registered with the Information Commissioner’s Office under registration number [ICO REGISTRATION NUMBER].

For anything to do with privacy, data protection or this notice, write to [PRIVACY CONTACT EMAIL]. We have not appointed a Data Protection Officer; we are not required to.

Data we hold about our customers

This is the data we hold as controller — about the people who run and use a Dialspire workspace.

  • Your account. Your name, work email address, your role in the workspace (admin, manager or rep), and which workspace you belong to. Your password and your PIN are never stored — only a salted scrypt hash of each, which cannot be turned back into what you typed.
  • Your sessions. One record per browser you have signed in from, holding the browser’s user-agent string, the IP address the sign-in came from, and when the session was created, last used and expires. This exists so you can see and revoke a device you no longer recognise.
  • Failed sign-in attempts. A counter keyed to your email address (or, on the shared-workstation PIN screen, to your user ID or device) so repeated wrong guesses lock the account for a while. The counter is deleted the moment you get in.
  • Your caller ID. If you present your own number to the people you call, we store that number and the date the carrier confirmed you control it.
  • Billing. Your plan, billing cycle, seat count, subscription status, and the Stripe customer and subscription identifiers we use to keep in step with Stripe. We never see or store your card details — those are typed on Stripe’s own payment page and stay with Stripe.
  • Connected accounts. If you connect a mailbox or a carrier, we store what is needed to use it: the address or number, the connection status, and the credentials themselves encrypted with AES-256-GCM.
  • Support correspondence. Anything you send us by email, for as long as it is useful to keep.

Data your team puts into Dialspire

This is the data we hold as your processor. We describe it here so you can see exactly what sits on our infrastructure, but you decide what goes into it and why.

  • Leads. Name, company, phone number, email address, plus every additional column your team imported from its own spreadsheet — we store those as you sent them, so what is in there is your choice. Alongside them: status, priority, who the lead is assigned to, and when they were last contacted.
  • Calls. Who called, which lead, when it started and ended, how long it lasted, the outcome, and the disposition the rep chose.
  • Recordings and transcripts. Recording is off by default and stays off until an admin deliberately turns it on for the workspace, because consent rules for recording a call vary by jurisdiction. Where it is on, we store a link to the recording held by your carrier, a transcript, and an AI summary of the call.
  • Notes and emails. Notes typed against a lead, and emails sent through Dialspire — sender, recipient, subject, body, and the delivery, bounce or complaint events reported back by the sending provider.
  • Suppression lists. Phone numbers on your DNC or TPS lists and email addresses that have unsubscribed, so we can block a dial or a send before it happens.

We do not mine your calling data to build features, train models on it, or enrich anyone else’s lists. It is used to run the service for you, and for nothing else.

Website visitors and enquiries

Cookies and similar storage

Dialspire sets one cookie: cb_session, which keeps you signed in. It is strictly necessary and cannot be turned off without breaking sign-in. We run no analytics, advertising or tracking cookies at all. The full inventory, and what the consent banner actually does, is in our cookie policy.

If you fill in the enquiry form

The “talk to us” form on our home page stores the name, email address, company, team size, current tool and message you type, so we can reply. To stop the form being scripted we also keep a short-lived counter keyed to your IP address; it is a count, not a log of what you did.

Server logs and crash reports

Our hosting and database providers keep operational logs that can include IP addresses and request paths. Those are held under their own retention policies — see sub-processors.

When something in the app crashes we send a technical report to our error-monitoring provider so it can be fixed. Phone numbers, email addresses and free text are stripped out before the report leaves our servers, and we do not record what you did on screen.

Why we process it, and our lawful basis

Under UK GDPR every use of personal data needs a lawful basis. Ours are as follows. Where we act as your processor, the lawful basis for the underlying processing is yours to decide, not ours.

Purposes, data and lawful basis
What we doData involvedLawful basis
Run your workspace, and sign you inAccount, session and credential dataPerformance of our contract with you (Art. 6(1)(b))
Take payment and manage your subscriptionBilling identifiers, plan, seatsPerformance of our contract with you (Art. 6(1)(b))
Lock accounts after repeated failed sign-ins, and keep the service secureFailed-attempt counters, session IP and user agentOur legitimate interest in keeping accounts from being taken over (Art. 6(1)(f))
Reply to an enquiry you send usEnquiry form contentsOur legitimate interest in responding to someone who contacted us (Art. 6(1)(f))
Host, store and process your team's calling dataLeads, calls, notes, emails, transcriptsProcessing on your documented instructions as controller (Art. 28)
Keep financial recordsInvoices and payment recordsLegal obligation (Art. 6(1)(c))

Who we share it with

We share personal data with the suppliers that run parts of the service for us, and with nobody else for their own purposes. Every one of them is listed by name, with what they receive and where they are, on our sub-processors page.

We may also disclose data where the law requires it, to our professional advisers under a duty of confidence, or to a buyer if the business is sold — in which case we would tell you before it happened.

We do not sell personal data, and we do not share it for anyone else’s advertising.

Transfers outside the UK

Some of our suppliers are based in the United States, so personal data reaches a country the UK has not declared adequate. Where that happens the transfer relies on the UK International Data Transfer Addendum to the European Commission’s standard contractual clauses, or on the UK Extension to the EU–US Data Privacy Framework where the supplier is certified under it.

The mechanism we rely on for each individual supplier is recorded against that supplier on the sub-processors page. You can ask us for a copy of the safeguards at [PRIVACY CONTACT EMAIL].

How long we keep it

Retention periods
WhatHow long
Your account and workspaceFor as long as the workspace exists. Cancelling a subscription stops the billing — it does not delete anything. Deletion happens when an admin closes the workspace, which starts a 30-day grace window they can still call off; after that a nightly job deletes the workspace and everything in it
Sign-in sessions30 days from sign-in, or until you sign out or revoke the device
Failed sign-in countersCleared on the next successful sign-in
Call recordings and transcriptsKept indefinitely unless your admin sets a retention window, in which case a nightly sweep deletes anything older
Leads, calls, notes and emailsUntil you delete them, or until a closed workspace's 30-day grace window expires
Suppression list entriesKept after removal, so the reason a number was suppressed survives
Enquiry form submissions24 months from the date you submit the form, then deleted automatically
Invoices and payment recordsSix years, to meet UK tax and accounting requirements

Ending a subscription is not the same as deleting

Cancelling stops the billing. The workspace and everything in it stay where they are until an admin closes the workspace, which starts a 30-day window they can still call off, after which a nightly job deletes the lot. If you are a customer and you want your data gone, close the workspace or ask us — walking away from the subscription will not do it. The full mechanics are in clause 9 of the DPA.

What deletion actually does

When a recording is deleted under a retention policy, we clear our copy and the transcript and AI summary derived from it. Your telephony carrier holds the master recording under its own retention policy, and we cannot delete that for you — telling you the audio was gone when your carrier still had it would be a false assurance. To remove the master you need to act in your carrier’s own console, or set a retention policy there.

How we protect it

Passwords and PINs are stored as salted scrypt hashes. Every credential you type into Dialspire — carrier keys, mailbox app passwords, CRM tokens — is encrypted at rest with AES-256-GCM. Traffic is served over HTTPS with HSTS. The full picture, including how to report a vulnerability, is on our security page.

Your rights

Over the data we hold about you as controller, you have the right to:

  • be told what we hold and why — which is what this notice is for;
  • get a copy of it (Article 15). We will run a reasonable and proportionate search and reply within one month;
  • have it corrected if it is wrong (Article 16);
  • have it deleted in the circumstances the law allows (Article 17);
  • restrict or object to what we do with it, including where we rely on legitimate interests (Articles 18 and 21);
  • take it with you in a machine-readable form (Article 20);
  • withdraw consent at any time where we relied on it, without affecting what we did before you withdrew it.

Ask at [PRIVACY CONTACT EMAIL]. Exercising a right is free, and we will not treat you differently for it.

If your request is about data inside a customer’s workspace — a lead record, a call, a transcript — we will pass it to that customer, because it is their decision to make, not ours. See “If one of our customers called you”.

If one of our customers called you

If a business called you using Dialspire, that business decided to hold your number and decided to ring it. They are the controller; we only ran the software. So the questions you probably want answered — where did you get my number, why are you calling me, delete my details — have to go to them, and they are legally obliged to answer.

Tell us at [PRIVACY CONTACT EMAIL] and we will pass your request to the customer concerned and tell you we have done so. If you would rather they simply stopped, ask them to add your number to their do-not-call list — Dialspire checks that list before every dial and blocks the call.

You can also register with the Telephone Preference Service (or the Corporate TPS for a business line). Under PECR regulation 21 it is unlawful to make unsolicited live marketing calls to a number registered there unless you have told the caller they may call.

Complaints

If you think we have got something wrong, complain to us first at [PRIVACY CONTACT EMAIL]. Since 19 June 2026, section 164A of the Data Protection Act 2018 gives you the right to complain directly to a controller: we will acknowledge your complaint within 30 days, look into it, keep you posted, and tell you the outcome.

You can complain to the Information Commissioner’s Office at any time, whether or not you have raised it with us. Their address is Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF; their helpline is 0303 123 1113; and their site is ico.org.uk.

Changes to this notice

When we change this notice we update the date at the top of the page. If a change materially affects what we do with your data, we will tell customers by email before it takes effect rather than quietly re-publishing.