Skip to main content

Privacy Policy

Last updated: 23 August 2026

Draft — pending legal review. The data flows, third-party processors, and security measures described below are accurate to how FixLeakage actually operates today, but the wording has not yet been reviewed by a solicitor or data protection specialist. Do not treat this as a finalised legal document until this notice is removed.

1. Who this applies to

This policy covers two groups: businesses that sign up to use FixLeakage ("customers"), and the customers' own callers whose calls FixLeakage handles on a customer's behalf ("callers"). FixLeakage acts as a data processor for caller data on behalf of the customer, and as a data controller for customer account data.

2. Data we collect

From customers (accounts): business name, phone number, email address, hashed password, plan and billing status.

From callers (calls handled on a customer's behalf): phone number, call audio/transcript, and any job details provided during the call — for example the nature of the job, location, urgency, and the caller's name, where given.

3. How we use it

To detect missed calls and trigger an SMS response, to extract structured job details from a call so they can be actioned, to operate customer accounts and billing, to provide customer support, and to maintain the security and reliability of the service.

4. Legal basis

Processing is carried out to perform our contract with the customer, and — for calls handled on a customer's behalf — under the customer's own legal basis for contacting their caller (typically legitimate interest in responding to an enquiry). Account and billing data is processed to perform our contract with the customer and to meet accounting/legal obligations.

5. Third parties we share data with

We use a small number of specialist providers to operate the service, and only share what each needs to do its job:

  • Twilio — call and SMS delivery (receives caller phone numbers and message content).
  • OpenAI — transcription and extraction of structured job details from call audio/text.
  • Stripe — payment processing for customer subscriptions (FixLeakage does not store full card details).

We do not sell personal data, and do not share it with data brokers or advertisers.

6. International transfers

Our providers may process data outside the UK/EEA. Where they do, we rely on the safeguards those providers offer for international transfers (such as Standard Contractual Clauses).

7. Data retention

Call and lead data is retained for as long as the customer account is active, so a business can see its own recovery history, and for a limited period afterward for legal/accounting purposes. Customers can request deletion of specific caller data on request.

8. Security

Data is encrypted in transit (TLS) and passwords are stored using bcrypt hashing, never in plain text. Access to customer data is scoped per account (tenant) at the application level.

9. Cookies

The dashboard uses an httpOnly session cookie to keep you logged in, which JavaScript cannot read, and a small non-sensitive flag cookie used only to check whether a session exists. No third-party advertising or tracking cookies are set. If analytics (Google Analytics 4) is enabled in future, this policy will be updated before it goes live.

10. Your rights

Under UK GDPR you have the right to access, correct, delete, or export your personal data, and to object to or restrict certain processing. To exercise these rights, contact us through your account or the details provided when you booked a demo.

11. Children

FixLeakage is a business tool and is not directed at, or knowingly used by, children.

12. Changes to this policy

We'll update this page as the product changes and note the date at the top when we do.

13. Contact

Questions about this policy can be raised through the contact details provided when you book a demo or through your account manager once you're a customer.