Privacy Policy
How We Handle Your Data
At GetTheCall, we believe your data should be handled with clarity and respect. This Privacy Policy explains what information we collect when you use getthecall.uk, how we use it, and the limited circumstances under which it is shared. We keep things simple: we collect only what we need to operate the service.
1Introduction
Optqo Framework s.r.o. (“GetTheCall,” “we,” “us,” or “our”) operates the pay-per-job advertising and call-routing platform accessible at getthecall.uk. This Privacy Policy applies to all information collected through our website and services.
By using our site or services, you agree to the collection and use of your information in accordance with this policy. If you do not agree, please do not use our services.
2Information We Collect
We collect information only when you actively provide it to us, or when it is generated as part of your use of the service. This falls into the following categories:
- Personal Data: Your name, email address, telephone number, and business trading name — provided voluntarily during account registration or when you contact us directly.
- Call & Platform Data: Calls made through GetTheCall tracking numbers are recorded and transcribed. Recordings, written transcripts, and call metadata (numbers, timestamps, routing and outcome data) are generated by the call-routing platform and used to verify Confirmed Jobs, operate billing, and resolve disputes.
- Credential & Verification Data: Where a regulated trade requires certification, we collect the registration details you provide and the review record. For Heating members this includes private front-and-back Gas Safe card images, fields extracted from those images, model/provider provenance, your confirmation or retake choice, reviewer corrections, register findings, approved categories, expiry dates, and the resulting decision. Electrical evidence is recorded as scheme, registration, expiry or periodic-recheck information and does not use Gas Safe card images.
- Right-to-Work & Identity Data: We collect the name, date of birth, share code or identity-document details needed for a right-to-work check; the Home Office result page and portrait or Vouchsafe result and document images; a short, fresh, session-bound challenge video and an ephemeral still captured halfway through it for the share-code route, or a Vouchsafe face scan; the issued prompts, capture time, technical face-presence result and model provenance; immigration follow-up dates; and the comparison, reviewer decision, and audit record. When facial images are compared to verify a person's identity, they are biometric special-category data.
- Financial Data: We do not store your full card details. Payment processing is handled entirely by Stripe (PCI-DSS Level 1 compliant). We may retain a limited reference such as card brand and last four digits solely for account identification.
- Usage & Tracking Data: We may use cookies, web beacons, or analytics tools (such as Google Analytics) to measure basic, aggregated traffic data — number of visitors, page views, and similar. This data does not personally identify you and is used solely to improve the site.
3How We Use Your Information
Information collected is used only for purposes directly related to operating the GetTheCall service:
- Processing and managing your account registration and onboarding
- Fulfilling payments, billing, and transaction records
- Delivering the advertising and call-routing services you signed up for
- Checking required trade credentials, keeping human register review authoritative, and removing expired or unverified credentials from eligible routing
- Establishing and maintaining right-to-work compliance and confirming that the person checked is the person using the account
- Detecting a clear out-of-scope refusal, temporarily preventing the same member or same telephone from being offered on that caller's recovery attempt, and arranging the recovery notice
- Sending account-related communications (setup confirmations, billing receipts, service alerts)
- Responding to support requests or disputes
- Analysing aggregated usage data to improve our platform
Until 1 October 2026, right-to-work processing relies on our legitimate interests in preventing illegal working and preparing for an enacted obligation (UK GDPR Article 6(1)(f)). From that date it is necessary to comply with a legal obligation (Article 6(1)(c)). Biometric identity verification relies throughout on Article 9(2)(g) and Data Protection Act 2018 Schedule 1 Part 2 paragraph 10 (preventing or detecting unlawful acts), and additionally from 1 October 2026 on Article 9(2)(b) and Schedule 1 Part 1 paragraph 1 (employment-law obligations).
We will never use your data for unsolicited marketing from third parties, or sell it in any form to any party.
4Disclosure of Your Information
We do not sell, rent, or trade your personal information. We disclose only the data reasonably required to service providers acting for the Platform, including:
- Stripe: Your payment information is transmitted directly to Stripe for processing. Stripe operates under its own Privacy Policy, which we encourage you to review at stripe.com/privacy.
- Hosting, database, and private object storage: Cloudflare processes the application and private EU-jurisdiction image and challenge-video storage; Supabase stores account, verification, decision, and audit records. Private evidence is served only through authenticated internal review.
- Communications and call processing: Telephone, WhatsApp, email, transcription, and related delivery providers process the recipient, message, recording, or transcript needed to provide the relevant service and delivery record.
- AI and verification processing: Cloudflare-hosted models and, during a documented outage path, configured model partners may receive a Gas Safe card image, call transcript, or the ephemeral midpoint challenge still needed for the specific extraction, classification, or face-presence check. The native midpoint pair is Cloudflare-hosted Moondream and Llama Vision; only if that pair is unavailable or disagrees is the still sent through Cloudflare's AI Gateway to Gemini Flash and OpenAI GPT-4o-mini. These models do not receive the GOV.UK portrait or full challenge video, do not compare faces, and cannot accept or reject identity. Vouchsafe separately processes identity-document and face checks for its verification route; its artefacts are not sent to our models. The Home Office receives the share code, date of birth, and checking-organisation details used in its employer journey. We limit each input to the task and retain applicable provider/model provenance for review.
We may disclose information if required to do so by law or in response to valid legal process (such as a court order), but only to the extent legally required.
5Data Retention
We retain your personal data only for as long as your account is active or as necessary to provide the service and fulfil legal obligations. Once your account is closed and all outstanding billing matters are resolved, we will delete or anonymise your personal data within a reasonable period.
Call recordings generated by the call-routing platform are retained only for a short period — normally no longer than around 10 days — to verify Confirmed Jobs and handle billing queries, after which they are deleted. A written transcript and basic call details are kept for longer where necessary for billing, dispute resolution, fraud prevention, and our legal obligations, then deleted or anonymised. Internal operational records age out on a fixed schedule: machine logs after 90 days, resolved internal action items after 180 days, and resolved support tickets and routing audit records after 12 months. Call analysis is automated; we do not routinely listen to recordings, but where a charge is disputed a member of our team may review the relevant transcript or recording in order to resolve it.
Private Gas Safe card images for an uncompleted initial capture are normally scheduled for deletion within 24 hours. Images attached to a completed, approved, rejected, abandoned, or superseded certification episode are retained only for the bounded review and challenge period, normally no more than 30 days after the relevant decision or settlement, and then deleted. If an object deletion cannot be confirmed, the case is marked for operator action and is not falsely recorded as deleted; it remains access-controlled until deletion is repaired. Extracted fields, the decision, and the audit record may be retained for the account, legal, safety, and regulatory purposes that require them.
Right-to-work evidence is stored in Supabase and a private Cloudflare EU-jurisdiction object bucket. It includes the Home Office result page and, for Vouchsafe checks, identity-document images, together with identity fields, the human reviewer receipt, decision time, finding, and audit record. The midpoint still exists only in memory for the face-presence check and is discarded rather than stored. Fresh challenge videos, Vouchsafe face scans, and all artefacts from a provider check that did not pass automatically are short-lived review material and are automatically deleted after 30 days. A temporary portrait extracted from the Home Office page is deleted when the check settles. The statutory check copy is scheduled for deletion two years after the member's participation ends or two years after that check is superseded; abandoned evidence with no owning record is deleted after 30 days.
6Security
We implement appropriate technical and organisational measures to protect your personal information against unauthorised access, alteration, disclosure, or destruction. This includes encrypted data transmission, access controls, and secure third-party payment handling via Stripe.
No system is 100% secure. If you have reason to believe your interaction with us is no longer secure, please contact us immediately.
7Your Rights
Under applicable data protection law, you have the right to:
- Request access to the personal data we hold about you
- Request correction of inaccurate or incomplete data
- Request deletion of your personal data (subject to legal obligations)
- Object to or restrict processing of your data in certain circumstances
- Withdraw consent at any time where processing is based on consent
To exercise any of these rights, contact us at the address below. We will respond within 30 days.
8Cookies
This site uses cookies for analytics purposes only. These cookies collect anonymous, aggregated data and do not track you personally across other websites. You can disable or manage cookies at any time through your browser settings without affecting your ability to use the service.
9Children's Privacy
GetTheCall is a business-to-business platform intended solely for use by registered trade contractors. We do not knowingly collect any information from individuals under the age of 18.
10Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will revise the “Last Updated” date at the top of this page. We encourage you to review this policy periodically. Continued use of our services after any update constitutes your acceptance of the revised policy.
11Contact
If you have any questions or concerns about this Privacy Policy or your personal data, please contact us:
Optqo Framework s.r.o.
Registered seat: Uralská 7, Bubeneč, 160 00 Prague 6, Czech Republic (IČO 23716606)
UK correspondence: Office 17255, 182–184 High Street North, East Ham, London, E6 2JA
office@getthecall.uk