Privacy
Privacy Policy
We handle lead data and we record every call. This policy explains exactly what that means, in the two different roles we act in.
Counsel review copy — read this page first
These documents are in conflict with the entity that publishes them.
Callrez is registered in the Arab Republic of Egypt. Both the privacy policy and the terms of service were drafted against UK law: the privacy policy takes its lawful bases from the UK GDPR and routes complaints to the Information Commissioner's Office, and the terms use English-law drafting conventions throughout. The governing law clause now says Egypt. Nothing has been done to reconcile the two, because that reconciliation is a matter for counsel rather than for the person who filled in the entity details.
Please treat every reference to UK law in these documents as unverified against the Egyptian position, not as a settled drafting choice.
The four most serious points
- No UK or EU representative is appointed or named. A controller established outside the UK or EU that offers services to, or monitors, UK or EU data subjects is generally required to appoint a representative in writing and publish their contact details in the privacy notice. Callrez calls UK consumers from Egypt. No representative appears anywhere in the document. No clause has been drafted and no person named — that is counsel's to settle.
- Egypt's data protection regime is not mentioned anywhere. The privacy policy is built on UK GDPR and US state law. It says nothing about the law of the jurisdiction in which the controller is actually registered. Counsel should determine what Egyptian law requires here, including whether a data protection officer must be appointed, whether processing or electronic direct marketing requires a permit or licence, what the breach notification timetable is, and how financial data is classified — the debt settlement records described in this policy contain financial information, which the policy currently treats as sensitive only as a matter of practice rather than of law. Nothing has been asserted about Egyptian requirements, deliberately.
- Cross-border transfers are described backwards. The international transfers section describes moving data from the UK or EU to countries whose laws differ, in generic terms. With an Egyptian controller the principal transfer runs the other way, and Egypt is not the subject of a UK or EU adequacy decision. Separately, the business model involves supplying lead records from Egypt to clients in the US and UK, which is an outbound transfer in the opposite direction again. Counsel should specify the mechanism for each direction and confirm whether any Egyptian authorisation is required.
- The claim "we do not sell personal data" has been removed. It previously appeared under who we share data with. It was removed because the business supplies lead records in exchange for payment, and the claim is not obviously sustainable — it is the kind of sentence that is litigated under US state privacy law. It was deliberately not replaced with a softer formulation. Counsel should decide what, if anything, this policy can accurately say about sale of personal data, in particular under the California Consumer Privacy Act. Note that removing the sentence also removed a second clause that was probably true and may be worth restoring on its own: that lead data is not supplied to anyone other than the client who commissioned or purchased it.
Further points for review
- Terms, liability. The carve-outs are verbatim English-law drafting: death or personal injury caused by negligence, fraud, fraudulent misrepresentation. Egypt is a civil-law jurisdiction. These have not been redrafted.
- Terms, warranties. The exclusion covers terms "implied by statute or common law". The concept of common law does not carry over to an Egyptian governing law clause.
- Terms, jurisdiction. The clause now gives the Egyptian courts exclusive jurisdiction, over a client base of US and UK businesses. There is no arbitration clause anywhere in the document. None has been added.
- Terms, data protection. The clause refers to a data processing agreement governing processing carried out on a client's instructions. No such agreement exists or is referenced.
- Privacy, complaints. Routes are given for the UK, the EU and the US. There is no route for a data subject in Egypt.
- Privacy, breach notification. The policy says the regulator will be notified but states no timetable.
- Privacy, lawful bases. The UK GDPR framework has been left in place despite the Egyptian entity. Which regime leads, and whether extraterritorial application is being relied on, is unresolved.
- Privacy, suppression records. These are kept indefinitely and the policy describes that retention as a legal obligation. The specific obligation is not identified, and now needs identifying across three regimes.
- Privacy, contact point. A role mailbox is given for data subject requests. If a named data protection officer is required, a mailbox may not satisfy it.
- Both documents. The "last updated" date has deliberately been left at its previous value. The client sets it on publication.
- Forms. The website forms are now connected. Submissions, including voice recordings and CVs from job applicants, are stored on a virtual server rented from DigitalOcean in its London region, and a notification email is sent through Hostinger, the company's mail provider. The policy now names both as processors and states retention periods for each kind of submission. Four questions this raises are listed under "Statutory disclosures and processors" below.
- Statutory disclosures and processors. Counsel is asked to confirm: (1) whether a processor agreement with DigitalOcean and with Hostinger is required and in place; (2) which transfer mechanism covers form data held in the UK by a US-headquartered host and mail relayed through a Lithuanian provider, given the Egyptian controller; (3) whether each provider must be named in the policy or whether a category description suffices in each applicable jurisdiction; (4) whether Egypt's Personal Data Protection Law imposes any additional requirement on these transfers or on the retention periods stated. Separately, whether either the Egyptian Commercial Register Law or, if the company has any UK establishment, the UK trading disclosure rules require the registration number to be published despite counsel's instruction to withhold it.
Judgement calls made without legal input
These were decided in order to produce a complete document. Each may be wrong.
- The registered name has no legal form suffix. It appears as "CallRez", with no S.A.E., L.L.C. or equivalent. This is the item most likely to be simply wrong, and it appears in the opening line of both documents.
- The commercial registration number is deliberately not published. Counsel instructed that it be withheld. The entity sentences in both documents now identify the company by name, country of registration and registered office only. Whether Egyptian or UK law requires the number to appear on the website or in these documents is a question for counsel (see the note on statutory disclosures below).
- Capitalisation is inconsistent by design. The entity is written "CallRez" as instructed; the defined short form and the brand used everywhere else is "Callrez".
- The registered office was corrected and extended. It was supplied as "39 East City, 8th Distrct, Nasr City". The spelling of District was corrected and Cairo was added. It must be checked against the commercial register.
- The registered office is also used as the public contact address on the website contact page. If operations are elsewhere, that is now wrong in two places.
- Governing law is expressed as "the laws of the Arab Republic of Egypt" rather than "Egypt".
- Jurisdiction was left as exclusive. Only the placeholder was replaced; the surrounding clause, including the word exclusive, is as previously drafted.
- Call recording retention now states criteria rather than a period. The criteria describe the purposes served and provide for deletion once none applies. No duration was invented, because the actual retention practice was not known.
- The two website bullets on third-party requests and server logging were rewritten to separate browser-initiated requests from server-side logging. This is a clarity change; the underlying factual claims were verified against the built site and are accurate as at the date of this copy.
- The lawful basis framework was not touched. Reworking it is the substance of point 2 above.
Who this applies to
This policy explains how CallRez, a company registered in the Arab Republic of Egypt with its registered office at 39 East City, 8th District, Nasr City, Cairo, Egypt ("Callrez", "we", "us") handles personal information. It covers three groups of people: individuals whose contact details appear in the lead data we source or process, individuals who receive calls from our agents, and people who contact us through this website or apply for a job with us.
It does not cover the separate privacy practices of clients who receive leads from us or engage us to run a campaign. Once a lead is delivered to a client, that client decides what happens next and is responsible for its own handling of that data.
The two roles we act in
This distinction matters, and most privacy policies in our industry avoid it. We handle personal data in two different capacities, and your rights work slightly differently in each.
As a controller
When we source lead data ourselves, decide how it is verified and structured, and determine which clients it may be supplied to, we are the controller of that data. We are also the controller for our own business contacts, job applicants and website enquiries.
As a processor
When a client engages us to run an outbound campaign on data they supply, they are the controller and we act on their documented instructions as a processor. In that arrangement the client decides who is called and why; we decide how the call is placed and enforce the compliance rules described on our compliance page. Requests about that data may need to be directed to the client, and we will tell you who they are where we are permitted to.
Lead data we hold
A lead record typically contains the following:
- Name
- Postal address
- Telephone number
- Email address, where it was provided
- Vertical-specific qualifying information, which varies by campaign. For residential solar this includes homeowner status, property type, roof condition and current energy spend. For roofing it includes ownership, roof age, damage or claim status and timeline. For debt settlement it includes unsecured balance, number of accounts and payment status. For business energy and utilities it includes the decision maker, contract end date, current supplier, site count, annual consumption and meter type.
- A record of where and when the data was obtained
- Contact history: attempts made, outcomes recorded, and any opt-out or do-not-call request
We do not deliberately collect special category data such as health information, and our qualifying fields are not designed to capture it. Debt settlement records include financial information, which we treat as sensitive in practice and restrict accordingly.
Where lead data comes from
We source contact data through our own channels rather than buying finished lists from brokers. Depending on the campaign, that means data supplied directly by the individual through a form or enquiry, data gathered in the course of a call, or business contact information relating to a company rather than a private individual.
Where a client supplies data for us to call, the source is the client, and the client is responsible for having obtained it lawfully and for having a lawful basis to have it called. We screen supplied data on the same terms as our own before it is dialled, but we cannot retrospectively create consent that was never obtained.
Call recordings
We record every call our agents make. This is central to how we operate, so it deserves a direct explanation rather than a single line.
Why we record
Recordings are used to review call quality against a written standard, to train and coach agents, to investigate complaints, and to evidence compliance with calling rules and required disclosures. They are not used for any purpose unrelated to the call.
How consent is handled
Recording consent is applied according to the rules of the state or country being called. In one-party consent states a disclosure is read. In two-party consent states the consent gate is armed and the required consent is obtained before recording proceeds. UK calls carry the notification required there. These controls are enforced by our dialing platform before the call connects, not left to the agent to remember.
Who can access recordings
Access is limited to our quality reviewers, the relevant campaign supervisors, and staff investigating a complaint or compliance issue. Where we run a campaign for a client, that client may request recordings of calls made on their campaign.
If you do not want to be recorded
Tell the agent during the call. Where the campaign cannot proceed without recording, we will end the call rather than continue without the required consent, and we will add you to our suppression list if you ask.
Why we are allowed to process it
For individuals in the UK and EU, we rely on the following lawful bases under UK GDPR:
- Legitimate interests for business-to-business contact, for quality review of calls, and for maintaining suppression records. We have assessed that these interests do not override the rights of the people concerned.
- Consent where consent is the appropriate basis for marketing contact, and where recording consent is required.
- Legal obligation for maintaining do-not-call and suppression records and for retaining evidence of compliance.
- Contract where we process data to deliver services a client has engaged us for.
Individuals in the United States have rights under state law rather than a single federal regime. Where a state privacy law such as the California Consumer Privacy Act applies to you, we honour the rights it gives you, described below.
Who we share data with
We share personal data in a small number of defined situations:
- Clients. Lead records are supplied to the client who purchased them. Campaign data and recordings are available to the client whose campaign generated them.
- Service providers. Telecommunications carriers who carry our calls, and infrastructure providers who host our systems. Our dialing platform is our own software, so it is not shared with a third-party dialer vendor.
- Website hosting. The server that runs this website and stores what you submit through its forms is rented from DigitalOcean, LLC, and located in its London data centre. DigitalOcean processes that data only to host it for us.
- Email delivery. Notifications about form submissions, the compliance pack link, and our replies to job applicants are sent through Hostinger, which provides the callrez.com mailboxes. Hostinger processes the contents of those messages in order to deliver them.
- Screening services. Telephone numbers are checked against do-not-call registers, and against TPS and CTPS for UK data.
- Legal and regulatory. Where we are required to disclose data by law, or where disclosure is necessary to establish or defend a legal claim.
How long we keep things
International transfers
We operate across US and UK markets, which means personal data may be transferred between jurisdictions, including from the UK or EU to countries whose data protection laws differ. Where we transfer UK or EU personal data outside those regions, we put appropriate safeguards in place, such as standard contractual clauses or an applicable adequacy decision. You can ask us for detail on the safeguards applying to your data.
Your rights
Depending on where you are, you may have the right to:
- Ask what personal data we hold about you and receive a copy of it
- Have inaccurate data corrected
- Have your data deleted, subject to the suppression exception below
- Object to processing based on legitimate interests, including direct marketing, which we will always honour for marketing
- Ask us to restrict processing while a dispute is resolved
- Receive your data in a portable format
- Withdraw consent at any time, where we relied on consent
- Not be discriminated against for exercising these rights, where US state law provides this
If your data reached us through a form on this website, a deletion request removes the database record, the voice recording and the CV from our server, your address from our sending logs, and the notification email in our mailbox; the encrypted backups age out within five weeks; and the deletion is logged as described above. To exercise any of these rights, contact us at [email protected]. We will ask for enough information to identify your records, and we will respond within the period the applicable law requires. Where we are acting as a processor for a client, we will pass your request to that client and tell you we have done so.
Opting out and suppression
You can ask us to stop calling you at any time: tell the agent during a call, or contact us at [email protected]. The request is applied across every campaign we run, not only the one you were called on.
One thing to be aware of. If you ask us to delete all of your data, we will retain the minimum necessary to keep you on our suppression list, which is your telephone number and the fact that you asked not to be contacted. Deleting that record entirely would mean we could call you again, which is the opposite of what you asked for. This retention is a legal obligation as well as a practical one.
Security
Lead data and call recordings are held on systems we control, with access restricted to staff who need it for their role. Agents can see the records assigned to their campaign and no more. Access to recordings is limited to quality review, supervision and complaint investigation. We keep our dialing platform, which is our own software, under our own change control rather than depending on a third-party vendor's release schedule.
No system is perfectly secure. If a breach occurs that is likely to result in a risk to people's rights, we will notify the relevant regulator and, where required, the individuals affected.
This website
This site is deliberately simple, and we can be precise about what it does.
- It sets no cookies and runs no analytics, advertising or tracking scripts.
- The contact form, the job application form and the compliance pack request form send what you enter to a server we rent from DigitalOcean, where it is stored in a database until the retention period above expires. A job application also includes the voice recording you upload and, if you attach one, your CV; both are stored on that server and nowhere else. When a form is submitted, a notification containing the text fields you entered, but not the recording or CV, is emailed to us through Hostinger, our email provider, and sits in our mailbox until we delete it. Applicants and enquirers are the only people who see this data apart from us: it is never shown to a client.
- Each form fetches a short signed token from our own server when you start filling it in, so that automated submissions can be told apart from people. That token is not a cookie, contains nothing about you, and is discarded once the form is sent.
- The admin pages where we review submissions are protected by Cloudflare Access, so a request to those pages passes through Cloudflare's identity check before it reaches our server. Cloudflare already carries every request to this site as our network proxy; this does not give it access to anything stored on our server.
- Typefaces are served from our own domain rather than a font CDN, so loading a page here causes your browser to make no request to any third-party server. No advertising network, analytics provider or font CDN learns your IP address as a result of your visit.
- That is a statement about what your browser is asked to fetch, not a claim that your visit leaves no trace. Reaching this site means connecting to the server that hosts it, and our hosting provider keeps standard server logs of those connections, including IP addresses, for security and operational purposes. The host is the one third party necessarily involved in delivering this page to you, and what it records is the connection itself rather than anything you do once the page has loaded.
Complaints
If you are unhappy with how we have handled your data, contact us first at [email protected] and we will try to put it right.
You also have the right to complain to a supervisory authority. In the UK that is the Information Commissioner's Office at ico.org.uk. In the EU it is the authority in your country of residence. In the United States, your state attorney general's office handles consumer privacy complaints, and unwanted call complaints can be made to the Federal Trade Commission.
Changes to this policy
We update this policy when our handling of data changes. The date below records the most recent version. Where a change materially affects how we use data about you, we will take reasonable steps to bring it to your attention rather than relying on you to re-read the page.
Last updated 16 September 2026