Privacy policy
Last updated: 2 September 2026
CallEye is a professional call-management tool. This page describes the data we process, the reasons we process it, and the rights you have.
1. Who processes your data
Two roles coexist. The company that subscribes to CallEye is the data controller: it decides which contacts to call and why. CallEye is the processor: we host and process that data on its behalf, following its instructions.
For any question: contact@calleye.pro.
2. Data we process
Accounts
- Name, email address, phone number, password (hashed, never readable)
- Time zone, date of last sign-in
Contacts imported by the client company
- Phone number, name, email, city, company
- Any additional column present in the imported file
This data comes from the client company. It is that company’s responsibility to make sure it has a lawful basis to process it and to call those people.
Calls
- Timestamps: dial, start and end of the call, return to the app, wrap-up
- Call duration, chosen outcome, note written by the agent, callback date
- The phone’s time zone and its drift from the server clock
No call content is recorded. CallEye has no technical access to call audio and keeps none of it.
3. Android permissions and their exact use
| Permission | Why |
|---|---|
CALL_PHONE | Place the call from the app rather than through the phone’s keypad. If it is refused, the keypad opens and the agent presses call themselves. |
READ_PHONE_STATE | Detect the start and end of the call in order to measure its duration. We read neither the caller’s number nor the identity of the line. If it is refused, the duration is estimated and flagged as such. |
POST_NOTIFICATIONS | Remind the agent of a scheduled callback or a call left un-wrapped. |
INTERNET, ACCESS_NETWORK_STATE | Sync data and detect when the network comes back. |
We do not request access to the call log (READ_CALL_LOG), the phone’s contacts, location, microphone, camera or device files.
4. What we do not do
- We do not sell any data.
- We do not share any data for advertising purposes.
- We do not use your contacts to train models.
- We do not access a customer’s data, except on an explicit and logged support request.
5. Sub-processors
- Server and database hosting (European Union)
- Transactional email delivery
- Push notifications (Google Firebase Cloud Messaging)
6. Retention
- Active account: for as long as the subscription runs.
- After termination: 30 days, then permanent deletion.
- Imported files: 30 days after processing.
- Technical logs: 90 days.
7. Your rights
You have the right of access, rectification, erasure, objection and portability (GDPR, and law 09-08 in Morocco).
If you are someone who was called by a CallEye user, send your request to the company that called you: it is the one holding your data. Write to us if you cannot identify it and we will help.
See also: ask for my data to be deleted.
8. Security
- Encryption in transit (HTTPS) on every communication
- Passwords hashed with bcrypt
- Session token stored in Android’s encrypted vault
- Strict isolation between customers: an organisation can never read another’s data
- Encrypted daily backups
9. Changes
Any substantial change will be announced by email to the administrators of the affected accounts at least 30 days before it takes effect.