CCall Census
PricingIntegrationsDocumentationSupportAbout
Sign in Start for free

Privacy Policy

Last updated: July 19, 2026

1. Who we are

This policy explains how CallCensus handles personal information through its website, business-facing service, and connected integrations. CallCensus is a trading name of Fermi Systems Ltd, registered in England and Wales under company number 11799965. Registered office: 128 City Road, London, England, EC1V 2NX.

Privacy contact: privacy@callcensus.com

For information supplied by a CallCensus customer, that customer will often decide why and how caller information is processed and may be the controller. CallCensus may act as its processor or service provider. For our own account, website, security, billing, and business-administration processing, Fermi Systems Ltd may act as controller.

2. What the service does

CallCensus helps organisations:

  • Connect customer-authorised call-tracking platforms;
  • Retrieve call metadata and recording URLs;
  • Transcribe inbound calls;
  • Generate AI-assisted predictions, summaries, and evidence;
  • Support human call review and produce reviewed conversion outcomes; and
  • Send customer-approved offline conversion data to authorised advertising platforms.

3. Calls, recordings, and customer responsibilities

Customers are responsible for having lawful authority, notices, and permissions for call recording, transcription, monitoring, and processing through connected platforms. CallCensus records the customer's attestation about these permissions during onboarding. That attestation records a customer confirmation; it is not, by itself, the sole lawful basis for processing caller information.

The connected call-tracking provider remains the system storing the original audio recording. CallCensus accesses audio transiently when needed for transcription and does not intentionally retain the source audio after transcription. CallCensus stores the resulting transcript, call metadata, AI-assisted outputs, human review decisions, and derived conversion outcomes.

The source call-tracking provider's privacy policy and terms continue to apply. CallCensus's own processing and its subprocessors are governed separately by CallCensus's terms, this privacy policy, and applicable agreements.

4. Information we process

Depending on how the website, service, and integrations are used, we may process:

  • Customer account and authentication information;
  • Organisation, workspace, user, and permission information;
  • Billing and subscription records;
  • Call metadata, caller and business telephone numbers, and recording URLs supplied by connected providers;
  • Call transcripts;
  • Campaign, source, landing-page, and attribution information;
  • GCLID, GBRAID, WBRAID, MSCLKID, and related identifiers;
  • Review decisions, notes, booked or qualified outcomes, and conversion values;
  • AI-assisted predictions, summaries, evidence, and confidence information;
  • Integration configuration and encrypted OAuth credentials;
  • Device, browser, IP, security, diagnostic, and audit information;
  • Website analytics and consent records, where applicable; and
  • Communications sent to support or privacy contacts.

CallCensus does not intentionally collect caller demographics or use transcripts to infer protected demographic characteristics. A transcript may incidentally contain personal information volunteered during a call.

5. Purposes and lawful bases

We use information to provide and administer the service. Where UK or EEA law applies, relevant lawful bases may include:

  • Contract: accounts, integrations, transcription, review, billing, and requested exports;
  • Legitimate interests: security, fraud prevention, reliability, product improvement, and business administration, balanced against affected people's rights;
  • Consent: non-essential analytics, marketing measurement, and processing that specifically requires consent; and
  • Legal obligation: tax, accounting, regulatory, dispute, and lawful-request requirements.

A customer may rely on a different lawful basis when it determines the purpose of processing caller information. Customers are responsible for identifying and documenting the basis that applies to their use.

6. AI-assisted processing and human review

AI predictions assist call classification. Human confirmation is the default. A customer administrator may optionally enable automatic finalisation for recommendations that meet its chosen confidence threshold; lower-confidence calls remain for human review, and authorised users can review and correct automated outcomes. These classifications are used for call reporting and customer-directed advertising feedback, not to make decisions that have legal or similarly significant effects on callers. CallCensus does not intentionally infer caller demographics or protected traits.

7. Platforms, service providers, and destinations

Customer-controlled source platforms

Customers may authorise CallRail, WhatConverts, CallTrackingMetrics, or another customer-authorised call-tracking service as a source. The customer chooses and controls this relationship; these source platforms are not described here as subprocessors selected by CallCensus.

CallCensus service providers and subprocessors

  • Clerk for authentication;
  • OpenAI for transcription and AI-assisted processing;
  • Stripe for payments;
  • DigitalOcean for US-hosted production infrastructure;
  • Google Analytics for consent-based website analytics, when enabled; and
  • PostHog for consent-based product analytics, when enabled.

Customer-authorised destinations

At the customer's direction, CallCensus may send approved conversion data to Google Ads, Google Data Manager, or another destination explicitly connected by the customer.

8. Google user data

Google Ads and Google Data Manager permissions are requested only when a customer initiates a connection. We use those permissions to read the authorised manager and client-account hierarchy, conversion-customer configuration, conversion actions, and goal usage; validate the conversion action selected by the customer; send customer-approved conversion events through Google Data Manager; check ingestion status; and correct or retract supported conversions originally uploaded by CallCensus when a final outcome changes. CallCensus does not create or edit conversion actions, goals, campaigns, bidding, budgets, attribution settings, counting settings, or lookback windows. Launch conversion events use only an eligible GCLID, GBRAID, or WBRAID supplied with the call; CallCensus does not send caller telephone numbers or telephone-number hashes in this workflow. OAuth tokens are encrypted at rest.

Customers can disconnect Google integrations. Stored integration credentials are removed or revoked through the disconnection workflow. Google user data is used only to provide or improve the customer-requested integration.

CallCensus's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.

9. Retention and deletion

CallCensus retains transcripts, call metadata, review outcomes, and derived conversion data while the customer account is active. Customers may request account closure or deletion through the privacy contact below. Our intended inactivity process is to give 30 days' notice after 12 consecutive months without an authorised-user login and then delete applicable service data, but that automated inactivity workflow is not yet active and remains a post-launch implementation item. Residual backup copies expire through the ordinary backup cycle. Limited billing, security, fraud-prevention, dispute, and legal records may be retained for longer where reasonably necessary or required by law.

Customers may request earlier deletion by emailing privacy@callcensus.com. We may retain genuinely de-identified or aggregated information. Information may also be preserved where required for legal claims, fraud prevention, security investigations, or regulatory obligations.

10. International processing

Primary production data is currently hosted in New York City, United States. CallCensus and its providers may process information outside the customer's or caller's country. US hosting does not remove privacy rights that apply based on the relevant person, customer, controller, or jurisdiction. Where required, CallCensus uses appropriate contractual, organisational, and technical safeguards.

11. Analytics, cookies, and consent

Essential authentication and security processing may run immediately. Google Analytics, PostHog analytics, and marketing measurement are non-essential. CallCensus's policy is that non-essential analytics and marketing tracking must remain disabled until a visitor gives affirmative consent where consent is required. Rejecting must be as easy as accepting, visitors must be able to withdraw or change consent, and consent choices should be recorded.

Google Analytics and PostHog privacy terms do not replace CallCensus's own responsibilities. Browser settings can also be used to limit cookies, although doing so may affect some website features.

12. US privacy disclosures and browser signals

CallCensus does not sell personal information. CallCensus does not share personal information for cross-context behavioural advertising without the required notice, consent, or opt-out mechanism. CallCensus does not currently use recognised browser-based opt-out signals, including Global Privacy Control, because it does not currently sell personal information or use it for cross-context behavioural advertising. If those practices change or applicable law otherwise requires recognition, CallCensus will treat those signals as applicable opt-out requests.

13. Your privacy rights

Depending on applicable law and subject to relevant exceptions, individuals may have rights to:

  • Receive information about processing and access personal information;
  • Correct inaccurate information;
  • Request deletion;
  • Restrict or object to processing;
  • Withdraw consent;
  • Receive portable data;
  • Opt out of applicable sale, sharing, targeted advertising, or profiling;
  • Appeal certain US privacy-rights decisions where applicable; and
  • Complain to a privacy regulator.

Send requests to privacy@callcensus.com. CallCensus may verify your identity and authority before fulfilling a request. Callers may sometimes need to contact the business they called because that customer may be the controller responsible for the call and recording.

14. UK and EEA

Fermi Systems Ltd's identity and contact details appear in section 1. Where UK or EEA law applies, section 5 explains relevant lawful bases, section 10 explains international processing, and section 13 describes data-subject rights. You may complain to the relevant EEA supervisory authority or to the UK Information Commissioner's Office. The ICO provides information on making a data protection complaint.

15. California and other US states

Depending on applicable state law, the categories in section 4 may be collected for the purposes in section 5 and disclosed to the sources, service providers, and customer-authorised destinations described in section 7. Section 9 describes our retention approach. Applicable rights may include access, correction, deletion, opt-out, and appeal rights. CallCensus does not sell personal information. This section does not state that any particular state privacy statute applies when its thresholds or other applicability requirements have not been established.

16. Canada

Where Canadian privacy law applies, CallCensus follows the relevant PIPEDA principles: accountability; identified purposes; consent; limited collection; limited use, disclosure, and retention; accuracy; safeguards; openness; individual access; and the ability to challenge compliance. The accountable privacy contact is privacy@callcensus.com.

17. Australia

Where Australian privacy law applies, CallCensus aims to manage personal information openly and transparently. Sections 4, 5, 7, and 10 explain the categories collected, purposes, disclosures, and overseas processing. Individuals can request access or correction, or make a complaint, through privacy@callcensus.com. AI supports human review and does not make legally significant decisions about callers.

18. Children and age

CallCensus accounts are intended for business users aged 18 or over, and CallCensus is not directed to children. We do not intentionally track caller demographics. Customers control which calls are connected to the service, and transcripts may incidentally contain information relating to minors. Customers are responsible for lawful use and appropriate notices or permissions for connected calls.

19. Security

CallCensus uses safeguards intended to protect information, including encryption of OAuth credentials at rest, authentication and access controls, workspace and account permissions, logging and monitoring, data minimisation, secure transport, incident investigation and response, and restricted internal access where applicable. No system can guarantee absolute security.

20. Policy changes and contact

We may update this policy as the service or legal requirements change. If a change is material, we may provide notice through the website, product, or account communication channels. Questions and privacy requests can be sent to privacy@callcensus.com or by post to FERMI SYSTEMS LTD, 128 City Road, London, England, EC1V 2NX. You may also complain to an applicable privacy regulator.

CCall Census

How CallCensus handles personal information.

SupportTermsPrivacy

CallCensus is a trading name of Fermi Systems Ltd, registered in England and Wales under company number 11799965. Registered office: 128 City Road, London, England, EC1V 2NX.