Session recording and call recording policy
Last reviewed 22 July 2026
We record two very different things: remote support sessions on your own devices, and, as a service, calls for clients running phone systems. This sets out how each is handled.
This is our current, working policy, written to match how we actually operate and the UK law that applies. Our ICO registration number and Companies House number will be added here and in the footer once confirmed. For a specific contractual form, ask us and we will provide a signed version.
Remote support sessions
When we help you over a remote session, you can see everything we do on your screen and you can end the session at any time. We record a session only where it is needed for security or as evidence of what was changed, we tell you beforehand, and we do not access files unrelated to the problem you asked us to fix.
Call recording and transcription we run for clients
Where we set up or operate call recording, transcription or dialler systems, the client is the controller of those recordings and we are the processor. That means the legal duty to have a lawful basis, to inform callers, and to honour their rights sits with the business operating the line, and we build the system to make meeting those duties possible.
What the law requires of a recording business
Recording calls engages UK GDPR, PECR and, for outbound dialling, Ofcom's rules. In practical terms that means:
- Callers must be told that calls are recorded and why, before the substance of the call
- There must be a genuine lawful basis; a bare training purposes line is not enough on its own
- Feeding recordings or transcripts into an AI model needs its own basis and, often, its own notice
- Predictive diallers must keep abandoned calls under three percent and play an information message within two seconds of a person answering
- Outbound lists must be screened against the TPS and CTPS, and typically refreshed every twenty eight days
Retention and security
Recordings and transcripts are kept only as long as the controlling business instructs, are access controlled, and are deleted on schedule or on a valid erasure request. Where required, everything can be kept within the UK. We will not configure a system in a way we believe breaches these rules, and we will say so in writing if asked to.
Questions about this policy? Email [email protected] or see the rest of our legal and policy pages.