Skip to content
Legal

Privacy Policy

This policy explains what personal data DuePort collects, why we use it, who we share it with, and the rights you have under the UK GDPR and the Data Protection Act 2018.

Last updated: 13 July 2026

In short: we collect the minimum we need to run your account and your voice agents. We never sell personal data. Where your agents handle calls, the call content belongs to you — we process it on your instructions, and you can export or delete it.

Who we are

DuePort Ltd (“DuePort”, “we”, “us”) provides a platform for building and running AI voice agents that answer and make telephone calls, capture leads, book appointments and record the outcome of each call.

For the purposes of UK data protection law, the data controller for the data described in this policy — except where stated otherwise in Our role in your data — is:

DuePort Ltd
K2 Bazaar, 538 Stratford Road, Shop 19, Sparkbrook, Birmingham, B11 4AL, United Kingdom
Registered in England and Wales, company number 17350280
Email: contact@dueport.ai

Our role in your data

DuePort acts in two different capacities, and it matters which one applies:

  • As a controller — for data about our own customers and website visitors: the account you create, your billing details, the support messages you send us, and basic technical logs from our website and app. This policy governs that data.
  • As a processor — for the personal data your voice agents handle on your behalf, including the details of people who call you or whom you call. You decide what your agents ask, capture and store; you are the controller of that data and we process it on your instructions under our Terms and Conditions and, where required, a data processing agreement. If you are a member of the public who spoke to an agent operated by one of our customers, that customer’s privacy notice governs the call — please contact them directly, or contact us and we will help route your request.

Data we collect

If you visit our website

  • Technical data your browser sends automatically, such as IP address, user agent and the pages you request. Our hosting and security provider processes this to serve the site and protect it from abuse.
  • Anything you choose to type into a form on our site — for example the message, name, email address and optional phone number you send through our contact page.

If you create an account

  • Account and identity data: name, work email address, password credentials, and the organisation you represent.
  • Configuration data: the agents, scripts, phone numbers, campaigns and integrations you set up.
  • Billing data: your plan, transaction history and the billing details you give our payment processor. Card numbers are handled by the payment processor and are never stored on our systems.
  • Usage and diagnostic data: sign-in events, feature usage, minutes and credits consumed, and error logs.
  • Support data: the messages, attachments and call examples you send us when asking for help.

If you contact us by phone or email

  • Your contact details and the content of your message, so we can respond and keep a record of the enquiry.

Calls, recordings and transcripts

Because DuePort is a voice product, call data deserves its own explanation. When an agent you operate handles a call, the platform may process:

  • Call metadata — numbers involved, time, duration, direction and outcome.
  • Audio of the call, where recording is enabled.
  • A transcript and summary of the conversation.
  • Fields the agent captured, such as a caller’s name, contact details, or appointment preference.
  • Information retained between calls to recognise returning callers and continue where the last call ended, where you have enabled that feature.

We process this call data as your processor, on your instructions, to deliver the service and to keep it secure and reliable. You control whether recording and caller memory are switched on, and you can export or delete call data from your workspace.

Your obligations as the controller. You are responsible for having a lawful basis for the calls your agents make and receive, for telling callers what to expect, and for complying with the rules that apply to recording and to marketing calls — including notifying callers of recording where required, honouring opt-outs, screening against the Telephone Preference Service and other do-not-call registers, and respecting permitted calling hours. Our platform provides controls to help you meet these obligations, but the responsibility for using them remains yours.

Why we use it, and our lawful basis

Purpose Lawful basis
Creating and administering your account; providing the platform Performance of a contract with you
Taking payment and keeping accounting records Performance of a contract; legal obligation
Responding to your enquiries and providing support Performance of a contract; legitimate interests (helping people who contact us)
Keeping the service secure, preventing fraud and abuse, debugging faults Legitimate interests (protecting our service and our customers)
Improving and developing the product using aggregated or de-identified data Legitimate interests (improving a service our customers rely on)
Sending service and account notices you need to receive Performance of a contract
Sending marketing emails about DuePort Consent, or legitimate interests where the law allows it for existing customers — you can opt out at any time
Meeting our legal, tax and regulatory duties, and handling disputes Legal obligation; legitimate interests (establishing or defending legal claims)

We do not use your call content to train general-purpose AI models for other customers, and we do not sell personal data to anyone.

Who we share it with

We share personal data only where we need to, and only with organisations bound to protect it. The categories are:

  • Cloud infrastructure and hosting providers that run our platform and store its data.
  • Telecommunications and voice network providers that carry calls to and from the public telephone network.
  • Speech and language processing providers that convert speech to text, generate the agent’s replies, and produce transcripts and summaries.
  • Payment processing providers that take payment and handle billing.
  • Email delivery, support and error-monitoring tools used to communicate with you and keep the service healthy.
  • Integrations you choose to connect, such as a calendar, messaging or automation tool — data flows to those services because you asked it to, and their own terms and privacy notices then apply.
  • Professional advisers, insurers, auditors, and authorities where we are legally required to disclose, or need to establish or defend legal claims.
  • A buyer or successor if we sell or reorganise part of our business, subject to this policy continuing to apply.

We appoint these organisations as our processors or sub-processors under written terms that require appropriate security and restrict them to acting on our instructions. A current list of the named sub-processors we use to deliver the platform is available on request at contact@dueport.ai.

International transfers

Some of the providers described above operate outside the United Kingdom. Where personal data is transferred out of the UK, we rely on one of the safeguards permitted by UK data protection law — typically adequacy regulations for the destination country, or the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, together with an assessment of the protection available in practice. You can ask us for details of the safeguard applied to a particular transfer.

How long we keep it

  • Account and configuration data — for as long as your account is active, and then for a limited wind-down period so you can reactivate or export.
  • Call recordings, transcripts and captured fields — for the period set by your workspace settings and plan. You can delete individual records at any time, and we delete or irreversibly anonymise remaining call data after your account closes.
  • Billing and accounting records — for six years after the end of the relevant financial year, as UK tax law requires.
  • Support correspondence — normally up to two years after the enquiry is resolved.
  • Security and technical logs — normally up to twelve months, unless a log is relevant to an ongoing investigation.

Where we no longer need personal data, we delete it or put it beyond use. If you need a specific retention period configured for your workspace, contact us.

How we protect it

We use encryption in transit, access controls and least-privilege permissions so that staff can only reach the data they need, separation between customer workspaces, logging of administrative access, and regular patching of the systems we run. No online service can promise perfect security, but we take these measures seriously and review them as the product grows. If a personal data breach occurs that is likely to present a risk to people, we will notify the Information Commissioner’s Office and affected customers as the law requires.

Your rights

Under UK data protection law you have the right to:

  • be told how your personal data is used — which is the purpose of this policy;
  • ask for a copy of the personal data we hold about you;
  • have inaccurate data corrected;
  • ask us to delete data where there is no good reason for us to keep it;
  • ask us to restrict how we use it while a concern is resolved;
  • object to processing we carry out on the basis of legitimate interests;
  • object to direct marketing at any time;
  • receive certain data in a portable format, or have it sent to another provider;
  • withdraw consent where we rely on consent.

To exercise any of these, email contact@dueport.ai. We will respond within one month, and will tell you if we need longer because the request is complex. There is normally no charge. We may need to verify your identity first.

If your request concerns a call handled by an agent operated by one of our customers, we will pass it to that customer, who is the controller for that data.

You also have the right to complain to the UK’s data protection regulator, the Information Commissioner’s Office, at ico.org.uk/make-a-complaint or on 0303 123 1113. We would appreciate the chance to address your concern first.

Cookies

This marketing website does not use advertising or analytics cookies, and it does not track you across other websites. Our hosting and security provider may set a strictly necessary cookie to distinguish real visitors from automated abuse; under the Privacy and Electronic Communications Regulations, cookies of that kind do not require consent. Our web application uses cookies and similar storage that are strictly necessary to keep you signed in and to remember your preferences. See our Cookie Policy for details.

Children

DuePort is a business product and is not directed at children. We do not knowingly collect personal data from anyone under 18. If you believe a child has given us personal data, contact us and we will delete it.

Changes

We may update this policy as the product and the law develop. The date at the top shows when it last changed. If a change materially affects how we use your personal data, we will tell account holders by email or in the app before it takes effect.

How to contact us

For any privacy question, or to exercise a right described above:

Email: contact@dueport.ai
Phone: +44 798 858 6063
Post: DuePort Ltd, K2 Bazaar, 538 Stratford Road, Shop 19, Sparkbrook, Birmingham, B11 4AL, United Kingdom