TradieDialTradieDial← Home

Legal · Privacy

Privacy Policy

Effective and last updated: 30 August 2026

Plain-English summary. We use the minimum data needed to answer and manage business calls, operate customer accounts, provide support and conduct tightly controlled business-to-business marketing. We do not sell personal data, run advertising profiles or place tracking pixels in outreach email.

Publication details still required

Before live outreach or customer onboarding, TradieDial must publish the proprietor’s full legal name, a public business correspondence address, the appointed UK representative’s name, the appointed UK representative’s UK address, the appointed UK representative’s email. The policy deliberately does not invent these facts.

1. Who is responsible for your data

TradieDial is a trading name used by the individual operator of the TradieDial trading name in Iceland. The operator is established in Iceland and is the controller for this website, customer administration, billing, security, product improvement and TradieDial's own sales and marketing.

Controller: Legal operator name awaiting publication
Business address: Public correspondence address awaiting publication
Privacy contact: support@tradiedial.com

For call, message, booking and job data processed for a trade business using TradieDial, that trade business is normally the controller and TradieDial is its processor. Our Data Processing Addendum governs that processing.

Because we offer services in the UK from outside the UK, our UK representative details are: appointment awaiting publication.

2. Who this policy covers

This policy covers website visitors, customers and authorised users, callers and message senders, business contacts who receive TradieDial sales communications, and authorised users of configured communication integrations. The service is intended for business use and is not directed to children.

3. Data we process

Website, demos and accounts

  • name, work contact details, business name, trade, service area and enquiry details;
  • account role, authentication records, settings and product activity;
  • subscription identifiers, plan, invoice/payment status and refund records. Payment providers handle full card or bank details; TradieDial does not store them;
  • support messages, complaint records and evidence needed to resolve them; and
  • security logs, IP address, request time, browser/device information and abuse signals.

Calls, messages, jobs and bookings

  • caller name, telephone number, address/postcode, requested service and access notes;
  • call audio, transcript, AI summary, urgency flags and the actions Sam said would happen;
  • SMS replies, corrections, callback notes, voluntarily uploaded photos and job outcome/value;
  • appointment time, booking status and calendar reference; and
  • technical identifiers needed to join a call, message, booking or recovery case safely.

Sales and outreach

  • company identity, legal/entity type, trade, services, public locations, website and company-size indicators;
  • business contact name, role and work contact details;
  • the source, URL, observation date, confidence and evidence for each discovered fact;
  • email verification, suppression, eligibility and frequency-control results;
  • communications, replies, objections, meetings and customer outcomes; and
  • commercial-fit and confidence scores used to prioritise review. Deterministic legal and safety rules always run before any AI score.

4. Why we use data and our lawful bases

  • Contract and steps before contract: to provide demos, accounts, call handling, bookings, support and billing requested by customers.
  • Legitimate interests: to operate and secure the service, prevent misuse, support genuine callers, improve reliability, keep business records and market TradieDial to relevant corporate businesses. We use a documented three-part assessment where this basis applies.
  • Consent: where a feature or communication legally requires it, including marketing to an individual subscriber when no other PECR exception applies.
  • Legal obligations: tax, accounting, regulatory requests, data-protection rights and claims.
  • Vital interests: only in exceptional circumstances where processing is necessary to protect someone's life.

Where we act as processor, the customer determines the lawful basis and purpose. We process only on documented instructions, subject to the DPA and applicable law.

5. AI, call recording and human review

Sam is an AI assistant. At the beginning of a handled call, Sam identifies itself as an AI assistant and says that the call may be recorded. The service records and transcribes only when configured to do so for the customer. Customers must publish their own caller privacy information and determine a lawful basis for their use.

AI is used to transcribe speech, extract details, summarise a call, flag urgency, draft communications and assist business users. It can be wrong. It does not make decisions that produce legal or similarly significant effects about callers or sales prospects. Safety flags and important details must be reviewed by the relevant business, and people may ask for human review or correction.

We do not ask callers for health, biometric, political, religious or other special-category information. If a caller volunteers sensitive information, we limit use to handling the immediate enquiry and the customer must identify any additional Article 9 or Article 10 condition required for its continued use. We do not use sensitive information for sales targeting.

6. Outreach mailbox and email data

TradieDial uses Mailforge infrastructure for its outreach mailboxes. Mailforge handles mailbox and domain provisioning, SMTP delivery and IMAP access to replies, bounces and other inbound messages. It therefore processes sender and recipient addresses, message headers and content, and delivery, bounce and reply metadata.

TradieDial stores the mailbox identity, encrypted SMTP/IMAP credentials, provider and message identifiers, and the sent or received content needed to apply suppression, classify replies, maintain conversation history and investigate delivery. Mailforge is infrastructure only: TradieDial controls sequencing, eligibility, frequency, suppression, reply handling and booking logic.

Relevant message content may be sent to a configured AI provider only for the selected classification, drafting or executive-assistant task. We do not sell message data, use it for advertising or train a general-purpose model on it. Human access is limited to support, security, legal compliance or an authorised operational need.

7. Business-to-business marketing

Our detailed Marketing and Outreach Notice explains our sources, targeting rules and opt-out controls. UK unsolicited email is restricted to verified corporate subscribers unless valid consent or the soft opt-in applies. Unknown entities, sole traders and ordinary partnerships fail closed. We provide our identity, a privacy link and a working unsubscribe method in the first communication.

We rely on legitimate interests only after considering necessity, relevance, reasonable expectations and impact. The right to object to direct marketing is absolute: object or unsubscribe once and we stop. We keep the minimum suppression record needed to ensure the address, number, company or domain is not re-imported and contacted again.

8. Where prospect information comes from

Prospect facts may come from the business's own website, official corporate registers, public business listings, a person who supplied the information, referrals, or a provider whose terms and our source policy permit that specific use. We do not authorise unrestricted scraping. Each automated source must be explicitly approved with permitted markets, fields, uses, retention, daily volume and spend limits. The recorded source for a specific fact is available on request.

We use deterministic eligibility checks for entity type, source permission, suppression, email validity, verification, frequency and mailbox safety. AI fit scoring cannot override those checks. We contact no more than one person at a company at a time through the automated system.

9. Sharing and sub-processors

We disclose data only to personnel who need it, the customer responsible for the relevant caller/job, professional advisers or authorities where legally required, and providers that help operate TradieDial. We do not sell personal data. Our current categories and provider purposes are listed in the Sub-processor Notice.

10. International transfers

TradieDial is operated from Iceland, within the EEA. The UK recognises Iceland as adequate for UK data transfers. Some providers operate in the UK, EEA, United States or other countries. Where a restricted transfer requires additional safeguards, we use the applicable adequacy regulation, Data Privacy Framework participation, EU Standard Contractual Clauses, UK Addendum or International Data Transfer Agreement, plus a transfer risk assessment where required.

11. Retention

  • Call recordings and caller-uploaded photos: normally 90 days, then automatically deleted unless a shorter customer setting or legal hold applies.
  • Transcripts, summaries, job details, messages and outcomes: while the customer account is active, then returned or deleted under the DPA and termination process, subject to backups and legal retention.
  • Account and billing records: for the relationship and normally up to seven years where needed for tax, accounting or claims.
  • Unconverted prospect records: reviewed at least annually and normally deleted or anonymised within 12 months of the last meaningful interaction unless a fresh lawful reason applies.
  • Source evidence and verification: expires under the approved source policy and must be refreshed before reuse.
  • Suppression records: a minimal email, phone, company or domain record may be retained for as long as reasonably necessary to honour an objection permanently.
  • Security and rate-limit data: raw IP-based rate-limit entries are normally removed within 24 hours; necessary security/audit records may be kept longer for incident investigation.

12. Website telemetry and cookies

We use essential, secure, HTTP-only session cookies for authenticated areas. Public pages use Vercel Web Analytics and Speed Insights for aggregate page-view and performance information such as route, referrer, approximate country, browser, device and web vitals. These services do not use third-party advertising cookies or give us an identifiable cross-site browsing history. TradieDial excludes dashboards and token-bearing customer, subscription and unsubscribe routes from this telemetry. See our Cookie Notice.

13. Your rights

Depending on the law that applies, you may have rights to be informed, access, correct, delete, restrict or object to processing, receive portable data, withdraw consent and obtain human review of certain automated decisions. You always have the right to object to use of your personal data for direct marketing.

For caller/job data, contact the trade business first because it is normally the controller; we will assist it. For data controlled by TradieDial, email support@tradiedial.com. We may need to verify identity and will respond within the legally required period.

14. Privacy complaints

Email support@tradiedial.com with “Privacy complaint” in the subject. We will acknowledge a UK data-protection complaint within 30 days, investigate it, keep you informed where appropriate and provide an outcome without undue delay.

You may also complain to the regulator where you live or work. UK complaints can be made to the Information Commissioner's Office. Icelandic/EEA complaints can be made to Persónuvernd, the Icelandic Data Protection Authority.

15. Security

Measures include encryption in transit, provider encryption at rest, encrypted mailbox and integration credentials, least-privilege service access, tenant-scoped queries, private object storage, signed expiring customer links, suppression and frequency controls, append-only audit records for defined automation and provider events, rate limiting, backups and incident procedures. No internet service is risk-free. If a breach affects customer-controlled data, we notify the customer without undue delay and provide the information reasonably needed for its own duties.

16. Changes and contact

We may update this policy when the product, providers or law changes. Material changes will be highlighted or notified to affected customers where appropriate. Questions and legal notices may be sent to hello@tradiedial.com.

PrivacyTermsOutreachDPASub-processorsCookiesHome