Privacy Policy

Effective date: August 28, 2026

This Privacy Policy explains how 2473230 Ontario Inc. o/a Call Helm (“Call Helm,” “we,” “us,” or “our”) collects, uses, shares, and protects personal information in connection with the Call Helm platform, website, and related services (the “Service”). Call Helm is a business tool used by organizations (our “Customers”) to run call-center and customer-communication workflows: voice calling, SMS/text messaging, call recording and transcription, and AI-assisted analysis. This Policy covers visitors to our website, people who create or use Call Helm accounts, people who exchange text messages with us, and — to the extent described below — the contacts and end users our Customers communicate with through the Service.

1. Our Roles: Controller and Processor

We act as a controller (or “business”) for information we collect for our own purposes: account, billing, website, support, and marketing information, and any text messages exchanged directly between you and Call Helm.

We act as a processor (or “service provider”) for Customer Data — the contacts, call recordings, transcripts, message content, and related records a Customer uploads to or generates through the Service. We process Customer Data only to provide the Service and on the Customer’s documented instructions. If you are an individual whose information is in the Service because one of our Customers contacted you, that Customer is responsible for that data; please direct privacy requests to them. We will support our Customers in responding.

2. Information We Collect

The categories below use the labels found in US state privacy laws in parentheses so you can map them to your rights.

  • Account and contact information (identifiers): name, email address, phone number, organization name, role, and authentication data used to create and secure accounts.
  • Billing information (commercial information): subscription plan, seat count, billing contact, invoices, and payment metadata. Card details are collected and stored by our payment processor, Stripe; we never store full card numbers.
  • Telephony and messaging registration data (identifiers, professional or commercial information): information Customers submit to register phone numbers and 10DLC brands and campaigns, such as legal business name, tax ID, address, website, and sample messages. Tax IDs are stored encrypted.
  • Customer Data (identifiers, audio/electronic information, professional information): contact records Customers import (names, phone numbers, email addresses, notes); call recordings; call and message transcripts; SMS content; and metadata such as timestamps, phone numbers, direction, duration, and disposition.
  • AI-derived data (inferences): summaries, sentiment, keywords, scores, and similar analysis generated from calls and messages to provide product features.
  • SMS opt-in and opt-out records (identifiers): the mobile number, the date, time, and method of consent or opt-out, and keyword replies such as STOP or HELP.
  • Usage, device, and log data (internet or network activity; approximate geolocation derived from IP address): IP address, browser and device information, pages and features used, error and performance diagnostics, and security logs.
  • Support and communications: messages you send us by email or through the Service, and our records of those conversations.

We do not intentionally collect government identifiers of individuals, precise geolocation, biometric identifiers, or health information, and we do not use sensitive personal information to infer characteristics about anyone.

3. Where Information Comes From

  • Directly from you when you sign up, configure your organization, subscribe, text us, or contact support.
  • From our Customers when they upload contacts or communicate with their contacts through the Service.
  • Automatically from your browser and devices, and from our telephony and messaging providers as calls and messages are delivered (for example, delivery status and call metadata).
  • From service providers such as our payment processor (payment status) and error-monitoring service (diagnostics).

4. How We Use Information and Our Legal Bases

  • To provide, maintain, secure, and support the Service and to perform our contract with you.
  • To place and receive calls and send and receive text messages that Customers initiate through the Service.
  • To process payments, manage subscriptions and seats, and send billing notices.
  • To generate the features Customers request, such as transcription, summaries, and AI analysis.
  • To register phone numbers, brands, and messaging campaigns with carriers and registries when a Customer asks us to.
  • To send account, security, and service communications, and — only with your consent where required — product updates and marketing.
  • To monitor for abuse and fraud, enforce our Terms and carrier requirements, and comply with law.
  • To improve the Service using aggregated or de-identified data.

Where the GDPR or similar laws apply, our legal bases are: performance of a contract (providing the Service); our legitimate interests (security, fraud prevention, product improvement, and business communications), balanced against your rights; compliance with legal obligations; and consent, where we ask for it (for example, marketing messages), which you may withdraw at any time.

We do not sell personal information, we do not “share” it for cross-context behavioral advertising, and we do not use Customer Data to train general-purpose AI models.

5. SMS / Text Messaging

This section describes text messaging with Call Helm and applies to anyone who provides a mobile number to us or exchanges text messages with us.

Program description and message types. When you opt in to receive text messages from Call Helm, we may send you account and service notifications, security and verification messages, replies to your support or sales inquiries, and — only where you have separately and expressly agreed — product updates or promotional messages. Message frequency varies depending on your account activity and the messages you request. Message and data rates may apply. Carriers are not liable for delayed or undelivered messages.

How to opt in. You opt in by providing your mobile number and agreeing to receive text messages from Call Helm, for example on a web form, in your account settings, or by texting a keyword to one of our numbers. Consent to receive text messages is not a condition of purchasing any goods or services.

How to opt out. You can cancel at any time by replying STOP to any message from us (we also honor UNSUBSCRIBE, CANCEL, END, and QUIT). You will receive one final confirmation that you have been unsubscribed, after which we will not send further messages to that number unless you opt in again. You can also opt out by emailing hello@callhelm.com.

Help. Reply HELP to any message for assistance, or contact us at hello@callhelm.com.

Your mobile information is not sold or shared for marketing. No mobile information, phone numbers, SMS opt-in data, or consent information will be sold, rented, or shared with third parties or affiliates for marketing or promotional purposes at any time. All categories of information described in this Policy exclude text messaging originator opt-in data and consent; that information will not be shared with any third parties. We will not share your opt-in to an SMS campaign with any third party for purposes unrelated to providing you with the services of that campaign. The only exception is that we may share mobile information with the service providers that help us deliver text messages — such as our messaging platform provider (Telnyx), telephone carriers, and vendors that assist in message delivery — strictly to provide the messaging service, and under contractual confidentiality obligations.

Messages sent by our Customers. Our Customers use the Service to send text messages to their own contacts under their own brand and messaging-campaign registrations. For those messages, the Customer is the sender and is responsible for obtaining your consent, honoring your opt-out, and complying with applicable messaging laws. When you reply STOP (or a similar keyword) to a Customer’s number, the Service automatically records the opt-out and blocks further messages from that Customer to your number. The same protection applies to your mobile information in Customer programs: it is used only to deliver that Customer’s messaging and is never sold or shared with third parties or affiliates for marketing or promotional purposes.

6. How We Share Information

We share personal information only as described here. We do not sell it and do not share it for cross-context behavioral advertising.

  • Service providers and sub-processors that process information on our behalf under contractual confidentiality and data-protection obligations, and only to provide the Service. Our key providers are:
    • Vercel — application hosting and delivery.
    • Supabase — database, authentication, and file storage for Customer Data.
    • Telnyx — voice calling, SMS messaging, phone numbers, and 10DLC registration.
    • Stripe — subscription billing and payment processing.
    • OpenAI — AI analysis and summarization of calls and messages.
    • AssemblyAI — speech-to-text transcription of call recordings.
    • Resend — transactional and notification email delivery.
    • Sentry — error and performance monitoring (configured not to send default personal identifiers).
  • Telecommunications carriers and registries (for example, The Campaign Registry) to deliver calls and messages and to register numbers, brands, and campaigns.
  • Within a Customer’s organization: administrators and members of the Customer’s workspace can see Customer Data according to the roles the Customer assigns.
  • Legal, safety, and compliance: to comply with law, subpoenas, or lawful requests; to enforce our Terms; and to protect the rights, safety, and property of Call Helm, our Customers, or others.
  • Business transfers: in a merger, acquisition, financing, or sale of assets, subject to this Policy.
  • With your direction or consent.

This list may change as the Service evolves; we will update this Policy when we add or replace a key sub-processor.

7. Call Recording and Transcription

The Service can record and transcribe calls when a Customer enables it. Customers are responsible for providing any legally required notice and for obtaining any consent required by applicable law (including one-party and all-party consent rules) before recording. The Service may play a recording announcement when configured, but using that feature does not by itself satisfy a Customer’s legal obligations. Recordings and transcripts are Customer Data and are handled as described in this Policy and the Customer’s instructions.

8. AI Features

When a Customer enables AI features, call recordings, transcripts, and message content are sent to our AI providers (OpenAI and AssemblyAI) to produce transcripts, summaries, sentiment, keywords, and scores. These providers process the content on our behalf under agreements that prohibit using it to train their models. AI outputs may be inaccurate and are provided to assist, not replace, human judgment. We do not make decisions with legal or similarly significant effects about individuals solely by automated means.

9. Cookies and Similar Technologies

We use strictly necessary cookies and similar technologies to keep you signed in, secure your session, remember preferences, and protect against abuse. We also use an error-monitoring tool that collects diagnostic information (such as browser type and error details) to keep the Service reliable. We do not use advertising cookies or cross-site tracking. Because we do not sell or share personal information for targeted advertising, there is no sale or sharing to opt out of; if that changes, we will update this Policy and honor Global Privacy Control signals. You can control cookies in your browser settings, but disabling essential cookies may prevent you from using the Service.

10. Data Retention

  • Account and billing information: for as long as your account is active and afterwards as needed for legal, tax, accounting, and dispute-resolution purposes (generally up to seven years for financial records).
  • Customer Data (contacts, recordings, transcripts, messages): for as long as the Customer’s account is active or as the Customer configures. After account termination we make Customer Data available for export for 30 days, then delete or de-identify it in the ordinary course, subject to legal holds and backups that expire on a rolling basis.
  • SMS opt-in and opt-out records: retained for as long as needed to honor your choices and to demonstrate compliance, including after you opt out.
  • Logs and diagnostics: typically 30 to 90 days, longer where needed for security investigations.

11. Security

We use administrative, technical, and organizational measures designed to protect information, including encryption in transit, encryption of especially sensitive fields at rest, role-based access controls, tenant isolation enforced at the database layer, and monitoring. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If we learn of a breach affecting your personal information, we will notify you and regulators as required by law.

12. International Data Transfers

We are based in Canada, and our service providers process information primarily in the United States and other countries that may not provide the same level of data protection as your home jurisdiction. Where required, we rely on appropriate safeguards for such transfers, such as the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Addendum, and provider commitments under applicable data-protection frameworks. You may contact us for more information about these safeguards.

13. Your Rights and Choices

Depending on where you live, you may have the right to access, correct, delete, or receive a copy of your personal information; to restrict or object to certain processing; to withdraw consent; to opt out of marketing; and to not be discriminated against for exercising these rights. Customers can exercise many of these rights directly in the Service (for example, editing account details, managing members, or deleting contacts).

  • How to submit a request: email hello@callhelm.com with “Privacy Request” in the subject line, or write to the address in Section 19. Requests through the Service’s account settings are also accepted.
  • Verification: we will verify your identity using the email address or account associated with the information, and may ask for additional details where necessary.
  • Authorized agents: an agent may submit a request on your behalf with your signed permission; we may still verify your identity directly.
  • Timing: we respond within 45 days (extendable once by a further 45 days where permitted, with notice).
  • Appeals: if we decline a request, you may appeal by replying to our decision; we will respond in writing, and where applicable tell you how to contact your state attorney general or privacy regulator.
  • Marketing choices: unsubscribe links in emails and the STOP keyword for texts always work; we will still send transactional and security messages.

If your information is in the Service because a Customer contacted you, please direct your request to that Customer; we will assist them in responding within the timelines that apply to them.

14. US State Privacy Rights

California (CCPA/CPRA). To the extent the CCPA applies to us, California residents have the right to know the categories and specific pieces of personal information we collect, the sources, our purposes, and the categories of third parties we disclose it to; to delete and to correct personal information; to opt out of the sale or sharing of personal information; to limit the use of sensitive personal information; and to non-discrimination. In the preceding 12 months we collected the categories listed in Section 2 for the purposes in Section 4 and disclosed them for business purposes to the categories of recipients in Section 6. We have not sold or shared personal information (as those terms are defined in the CCPA) in the preceding 12 months, and we do not sell or share the personal information of anyone under 16. We do not use or disclose sensitive personal information for purposes other than those permitted by the CCPA. Submit requests as described in Section 13. Because we do not sell or share personal information, we do not offer a “Do Not Sell or Share My Personal Information” link.

Virginia, Colorado, Connecticut, Texas, Oregon, and other states. Residents of states with comprehensive privacy laws have rights to access, correct, delete, and obtain a portable copy of personal data, and to opt out of targeted advertising, sales, and profiling in furtherance of decisions that produce legal or similarly significant effects. We do not engage in targeted advertising, sales, or such profiling. You may exercise your rights and appeal any denial as described in Section 13.

15. Canada (PIPEDA and Provincial Laws)

We are accountable for personal information under our control and have designated a Privacy Officer responsible for our compliance with the Personal Information Protection and Electronic Documents Act and applicable provincial laws. You may access or correct your personal information, withdraw consent (subject to legal and contractual restrictions), or raise a complaint by contacting our Privacy Officer at hello@callhelm.com. If we do not resolve your concern, you may contact the Office of the Privacy Commissioner of Canada. Commercial electronic messages we send comply with Canada’s Anti-Spam Legislation, including consent, sender identification, and unsubscribe requirements.

16. European Economic Area and United Kingdom

If you are in the EEA or the UK, 2473230 Ontario Inc. o/a Call Helm is the controller of the information described in Section 1, and our legal bases are set out in Section 4. You have the rights described in Section 13, including the right to lodge a complaint with your local supervisory authority (or the UK Information Commissioner’s Office). Where we rely on legitimate interests, you may object and we will stop unless we have compelling grounds to continue. Providing account information is necessary to enter into our contract; if you do not provide it, we cannot provide the Service. We have not appointed a data protection officer or an EU/UK representative; privacy inquiries should be sent to hello@callhelm.com. International transfers are described in Section 12.

17. Children’s Privacy

The Service is intended for business use and is not directed to children under 18 (or under 13 where a lower age applies). We do not knowingly collect personal information from children; if you believe a child has provided us information, contact us and we will delete it.

18. Changes to This Policy

We may update this Policy from time to time. If we make material changes, we will provide notice (for example, by email or in-product), and the “Effective date” above will be updated. We review this Policy at least once every 12 months.

19. Contact Us

For privacy questions or requests, or to reach our Privacy Officer, contact us at hello@callhelm.com. Text-message help is also available by replying HELP to any message from us.

This Service is operated by 2473230 Ontario Inc. o/a Call Helm, registered at 774 Du Golf Road, Hammond (Clarence-Rockland), ON K0A 2A0, Canada.