Privacy Policy
Last updated: 23 August 2026
Draft — pending legal review. The data flows, third-party processors, and security measures described below are accurate to how FixLeakage actually operates today, but the wording has not yet been reviewed by a solicitor or data protection specialist. Do not treat this as a finalised legal document until this notice is removed.
1. Who this applies to
This policy covers two groups: businesses that sign up to use FixLeakage ("customers"), and the customers' own callers whose calls FixLeakage handles on a customer's behalf ("callers"). FixLeakage acts as a data processor for caller data on behalf of the customer, and as a data controller for customer account data.
2. Data we collect
From customers (accounts): business name, phone number, email address, hashed password, plan and billing status.
From callers (calls handled on a customer's behalf): phone number, call audio/transcript, and any job details provided during the call — for example the nature of the job, location, urgency, and the caller's name, where given.
3. How we use it
To detect missed calls and trigger an SMS response, to extract structured job details from a call so they can be actioned, to operate customer accounts and billing, to provide customer support, and to maintain the security and reliability of the service.
4. Legal basis
Processing is carried out to perform our contract with the customer, and — for calls handled on a customer's behalf — under the customer's own legal basis for contacting their caller (typically legitimate interest in responding to an enquiry). Account and billing data is processed to perform our contract with the customer and to meet accounting/legal obligations.
5. Third parties we share data with
We use a small number of specialist providers to operate the service, and only share what each needs to do its job:
- Twilio — call and SMS delivery (receives caller phone numbers and message content).
- OpenAI — transcription and extraction of structured job details from call audio/text.
- Stripe — payment processing for customer subscriptions (FixLeakage does not store full card details).
We do not sell personal data, and do not share it with data brokers or advertisers.
6. International transfers
Our providers may process data outside the UK/EEA. Where they do, we rely on the safeguards those providers offer for international transfers (such as Standard Contractual Clauses).
7. Data retention
Call and lead data is retained for as long as the customer account is active, so a business can see its own recovery history, and for a limited period afterward for legal/accounting purposes. Customers can request deletion of specific caller data on request.
8. Security
Data is encrypted in transit (TLS) and passwords are stored using bcrypt hashing, never in plain text. Access to customer data is scoped per account (tenant) at the application level.
9. Cookies
The dashboard uses an httpOnly session cookie to keep you logged in, which JavaScript cannot read, and a small non-sensitive flag cookie used only to check whether a session exists. No third-party advertising or tracking cookies are set. If analytics (Google Analytics 4) is enabled in future, this policy will be updated before it goes live.
10. Your rights
Under UK GDPR you have the right to access, correct, delete, or export your personal data, and to object to or restrict certain processing. To exercise these rights, contact us through your account or the details provided when you booked a demo.
11. Children
FixLeakage is a business tool and is not directed at, or knowingly used by, children.
12. Changes to this policy
We'll update this page as the product changes and note the date at the top when we do.
13. Contact
Questions about this policy can be raised through the contact details provided when you book a demo or through your account manager once you're a customer.
