Snapshot 36022
Normalized text
Scripts and page chrome removed; this is what change detection compares.
Sales: Support: Log in Skip to content CALILIO PTE. LTD. runs a cloud business phone system for voice calls, text messaging and WhatsApp business messaging. This policy explains what personal data we collect, why we collect it, who we share it with, how long we keep it, and what rights you have over it. It covers calilio.com, the Calilio web and mobile applications, our help centre at support.calilio.com, and our support channels. This policy is for customers, users, website visitors, and people whose details are stored in a customer account. The part most people want to know We do not sell personal data. We do not listen to your calls or read your messages. Your call content, recordings, transcripts and contacts are used to run the service for you and are never given to an advertising provider. 1. Two roles, and why the difference matters to you Calilio handles personal data in two different roles. The role depends on the purpose, not on the type of data, so the same call record can sit in both roles for different reasons. Calilio as the processor For the content of a customer's workspace, the customer decides and we act on their instructions: call recordings, voicemail and transcripts message content and attachments contacts and notes stored in the workspace workspace settings and user lists Calilio as the controller For these purposes Calilio decides what is collected and why, and this policy governs it: your account, billing and invoicing website visits and marketing measurement support conversations with our team fraud detection, abuse monitoring and account risk scoring routing calls and messages through carriers, and administering the numbers allocated to us keeping call detail records for the period telecom rules require responding to a lawful request from a regulator, court or law enforcement body Why that second list matters. Some of it looks like customer data but is not held on the customer's instructions. We keep call detail records because telecom rules require it of us, not because a customer asked. We investigate fraud to protect the network. In those cases we are answerable for the decision, and you can come to us directly. A practical example. If your employer gave you a Calilio account and you want a call recording deleted, ask your employer. They own the workspace and the decision is theirs. But if you want to know what call records Calilio itself holds for regulatory reasons, ask us, because that is our decision. Our Data Processing Agreement sets out what we commit to when we act as a processor. 2. What personal data we collect Information you give us Account details. Name, username, email address, phone number, country, language preference, and profile or cover images. Verification status. Whether your email address and phone number have been confirmed, and your multi-factor authentication settings. Identity documents. Where a plan or a telecom regulator requires an identity check, the documents you upload and the result of the check. Our verification partner processes these for us. Billing details. Plan, invoices, wallet ledger entries and payment records. Card numbers are entered directly into our payment providers and never reach Calilio's own systems. Support conversations. Whatever you tell us in chat, by email, or on a call with our support team. Information your use of the service creates Call and message records. Numbers called, timestamps, duration and outcome. Recordings, messages and attachments, where you have turned those features on. Transcripts and call analysis. Where you use transcription, call summaries or sentiment analysis, the audio is processed to produce text and analysis. Contacts you store. Name, phone number, email address, postal address, company, website, time zone, tags and notes. Campaign records. Bulk messaging and campaign history. Information we collect automatically Session and device data. Session identifier, access and refresh tokens, issue and expiry times, browser and device details, operating system, device model, platform, and a device identifier used to recognise a device you chose to remember. IP address. Recorded on every request. We use it to check a request comes from a person rather than a script, to apply security rules, and to block abusive traffic. Device fingerprint. At sign-up we build a technical fingerprint from browser and hardware characteristics. This is how we detect one person opening many accounts to abuse free credit or commit call fraud. Website and product analytics. How pages and features are used. Our Cookie Policy names every cookie and tracking tool. Marketing attribution. Which campaign, advert or partner link brought you to us. Kept for 90 days and stored against your account. Error reports. When something breaks, a technical error report is sent to our monitoring provider. It includes your IP address. 3. Why we use it, and on what legal basis What we do Why we do it Legal basis Create and run your account To provide the service you signed up for Performance of a contract Carry your calls and messages The core service Performance of a contract Take payment and issue invoices To bill you and keep tax records Contract, and legal obligation Verify identity where required To meet telecom and anti-fraud rules Legal obligation, and legitimate interests Detect fraud, call fraud and abuse To protect customers, carriers and Calilio Legitimate interests Provide support To answer your questions Performance of a contract Improve the product To fix faults and decide what to build Legitimate interests Send marketing emails To tell you about Calilio Consent, or legitimate interests for existing customers Analytics and advertising cookies To measure our marketing Consent, through our cookie banner Where we rely on legitimate interests, we have weighed our interest against your rights and freedoms. You can object at any time using the contact details at the end of this policy. 4. Who we share it with We do not sell personal data, and we do not share it for anyone else's marketing. We share it with the suppliers who make the service work. Our Sub-processor List names every one of them, what they do, and where they are. In summary: Carriers, including Twilio, to connect calls and deliver messages. Amazon Web Services, for hosting, storage and transcription. Meta, for WhatsApp business messaging, if you use that channel. Chargebee and Stripe, for subscriptions and payments. Crisp, for support chat. Crisp receives your name, email address, phone number, plan and workspace identifier so our team can help you. Our identity verification partner, where an identity check is required. Our analytics and error-monitoring providers, to measure usage and diagnose faults. We also share personal data where the law requires it, where we need to establish or defend a legal claim, and if Calilio is ever sold or merged, in which case we will tell you before your data moves. Law enforcement requests. We disclose customer data to a law enforcement or government body only where we are legally required to. We check that each request is valid and properly served, we give only what the request covers, and we tell the affected customer unless we are legally barred from doing so. 5. If you are not a Calilio customer You may be reading this because a Calilio customer called you, messaged you, or stored your details as a contact. You did not choose Calilio, and that matters. The Calilio customer decides what to hold about you, and why. They are the controller. We hold it for them. Ask them first. To see, correct or delete your details, contact the business that called or messaged you. They can do it themselves in the product. If you cannot identify them, ask us. Email [email protected] with the number that contacted you and the date and time. We will identify the customer and pass your request to them, and we will tell you we have done so. To stop being contacted, reply STOP to a message, or tell the caller. Both work, and our Messaging Policy requires our customers to act on either. To report misuse, such as a scam call or a message you never agreed to receive, write to [email protected] with the number, the date and time, and any message text. We investigate every report and we act on our customers. 6. What we do not do Stating the negatives plainly, because they are the questions people actually ask. What we do not do We do not sell personal data. Not to data brokers, not to advertisers, not to anyone. We do not listen to your calls or read your messages. Access to customer content is restricted, logged, and only happens where a customer asks us to investigate a problem or where the law requires it. We do not use call content, recordings, transcripts, messages or contacts to train advertising models, and we do not give that content to advertising providers. We do not use your customer list for our own marketing. We do not require you to accept advertising cookies to use the website or the product. 7. Marketing, and how to stop it We send product and marketing emails to customers and to people who asked to hear from us. Every marketing email has an unsubscribe link, and it works immediately. You can also email [email protected] and ask to be removed. Unsubscribing from marketing does not stop service messages such as invoices, security alerts and outage notices. Those are part of the service and cannot be switched off while your account is open. We do not send marketing by text message to customers without separate consent. 8. Where your data is stored Our primary hosting region is Singapore. Some platform services, such as error monitoring and analytics, run elsewhere. Call and message traffic is routed through carriers in the country of the number being used, which is how telephony works everywhere. Our Sub-processor List states the primary location of every supplier, and our Data Processing Agreement records the processing details for business customers. 9. Where your data goes Calilio is a Singapore company and our systems run in more than one country. Some suppliers are outside Singapore, the United Kingdom and the European Economic Area, mainly in the United States. Where personal data leaves the United Kingdom or the European Economic Area, we rely on recognised safeguards, in this order: the United Kingdom International Data Transfer Addendum, the European Commission's Standard Contractual Clauses, or the supplier's certification under the EU-US Data Privacy Framework. You can ask us for a copy of the safeguards that cover a particular supplier. 10. How long we keep it What How long Why Your account and profile While your account is open To run the service Invoices, payment and tax records 5 years from the end of the financial year Required of a Singapore company by the Companies Act 1967 section 199, the Income Tax Act 1947 section 67, and the Goods and Services Tax Act 1993 section 46 Call detail records: numbers, times, duration, outcome 12 months To bill accurately, settle disputes, answer carrier queries and investigate misuse Call recordings, messages and transcripts Set by the customer who owns the workspace The customer decides, and can delete them at any time Fraud, abuse and security logs 12 months To detect and investigate call fraud, spam and account takeover Marketing attribution 90 days from capture To credit the campaign or partner that referred you Session and login records Until the session expires To keep your account secure Record of a deletion request 3 years Proof the request was received, verified and completed When a retention period ends we delete the data, or remove whatever links it to you. 11. Your rights Depending on where you live, you can ask us to: Give you a copy of the personal data we hold about you. Correct it if it is wrong or incomplete. Delete it. Our Data Deletion Request page explains that route in full. Restrict or object to how we use it, including anything based on legitimate interests. Give it to you in a portable form, or send it to another provider. Withdraw consent you gave, without affecting what we did before you withdrew it. Opt out of marketing, using the unsubscribe link in any marketing email. How to use a right. Email [email protected]. We acknowledge within 5 business days and reply within one calendar month, the deadline set by GDPR Article 12(3). We do not charge a fee. We may ask you to confirm who you are first, so that nobody else can request your data. If our answer does not satisfy you, you can complain to the Personal Data Protection Commission in Singapore at pdpc.gov.sg. In the United Kingdom you can complain to the Information Commissioner's Office at ico.org.uk. In the European Economic Area you can complain to the data protection authority in your country. 12. United States state privacy rights If you live in a United States state with a comprehensive privacy law, you also have the right to opt out of targeted advertising and of the sale or sharing of personal information. Calilio does not sell personal data for money. However, the advertising cookies on our marketing website count as sharing under several state laws. You can opt out in three ways: turn off Advertising cookies in our cookie settings, switch on Global Privacy Control in your browser, or email [email protected]. We honour the Global Privacy Control signal. A browser signal applies to the browser that sends it, so switch it on in each browser you use. If you would rather the opt-out was recorded against your whole account, email [email protected] from the address on the account and we will do that and confirm it. 13. Automated decisions We score new accounts for fraud risk. The signals include the result of identity verification, how many numbers an account asks for, whether the name on the payment card matches the account name, the country of the account and the country of the card, and how the account reached us. A high score can delay activation or limit what an account can do while we review it. A person reviews any decision that stops an account being used. If a decision affects you, write to [email protected] and ask for it to be looked at again. 14. Children Calilio is a business product and is not intended for anyone under 16. We do not knowingly collect personal data from children. If you believe a child has given us personal data, write to [email protected] and we will delete it. 15. Security We protect personal data with encryption in transit, access controls, multi-factor authentication, device recognition and monitoring for abuse. Our Data Security Policy describes this in more detail. No service can promise perfect security, so please use a strong and unique password and turn on multi-factor authentication. If a breach puts your rights at risk we will tell you. We will notify the Personal Data Protection Commission no later than 3 calendar days after we assess that a breach is notifiable, and we will tell affected individuals without undue delay. 16. Changes to this policy We update this policy when our service, our suppliers or the law change. The date at the top always shows the current version. If a change materially affects how we use your personal data, we will tell you before it takes effect. 17. How to contact us Contact Details Privacy and data protection [email protected] Support [email protected] Registered office CALILIO PTE. LTD., UEN 202433643W, 14 Robinson Road, #08-01, Far East Finance Building, Singapore 048545 Questions. To use any right in this policy, or to ask a question about it, write to [email protected]. We acknowledge within 5 business days and answer within one calendar month.