Legal
Privacy Policy
Dialem is a phone system that holds other people’s contact details. This explains exactly what we do with them - both yours, and those of the people your business calls.
Version 1.3 · Effective 23 September 2026
The short version
- We do not sell personal data. We never have and the business model does not depend on it.
- We do not track you around the internet. There are no analytics scripts, no advertising pixels and no third-party cookies on this site - which is why you were not asked to accept any.
- The leads in your account are yours. We hold them on your instructions and do not use them for our own purposes.
- Calls made through Dialem can be recorded. That is the part of this document worth reading properly, and it has its own section.
- Anyone can ask us to delete everything we hold about them, whether or not they are a customer, using the support form.
The short version is a summary and nothing more. Where it and the full text disagree, the full text is what we are bound by.
1. Who we are
Dialem is operated by Studio 404 Development Ltd, a company registered in England and Wales (number 17241297), whose registered office is 344 Oldfield Road, Altrincham, England, WA14 4QS.
In this policy, “we” means that company. “You” means whoever is reading it - a customer, someone on a customer’s team, or a member of the public who has been contacted by one of them.
We have not appointed a Data Protection Officer, because we are not required to under Article 37 of the UK GDPR. Privacy questions go to tombrookes06@gmail.com, which is monitored by a named person rather than a queue.
2. The two different roles we play
This is the most important idea in the document, and almost every question about Dialem and data has a different answer depending on which of the two applies.
We are the controller of your account
Your name, your email address, your billing details, which features you use, the fact that you are a customer at all. We decide what to collect and why, so the responsibility is ours.
Covered by Part A.
We are a processor of your leads
The people you call, text and email. We did not choose to collect them, we do not decide what they are for, and we act on your instructions. You are their controller; we are your processor.
Covered by Part B.
The practical consequence: if one of your leads asks us to delete their data, we will normally tell them to ask you, and tell you that they asked. We will act ourselves where the law requires it or where you cannot be reached, but the decision is yours to make, because they are your contacts and you know why you hold them.
Part A - When you use Dialem
This part covers customers and their team members: the people who log in. Here we are the controller.
3. What we collect about you, and why
| What | Why we have it | Lawful basis |
|---|---|---|
| Name, email address and password (stored only as a one-way hash - we cannot read it, and neither can anyone who steals the database) | To create your account, sign you in, and attribute calls and notes to the right person on your team | Performance of a contract |
| Your business name and phone number, given when you sign up | To set up your account, and to get in touch about it, including once or twice if you create an account but do not start your trial. Tell us to stop and we will | Legitimate interests - helping you finish setting up |
| Your acceptance of our terms and this policy: when, which versions, and the internet address you accepted from | So we can show what you agreed to, and when | Legitimate interests / legal obligation |
| Your plan, your billing status, the minutes your team has used, and what your calls and texts cost us, taken from our telecoms provider’s billing records | To apply your plan’s minutes, charge for extra minutes you turn on, and understand what running the service costs | Performance of a contract / legitimate interests |
| For a phone number, the details our telecoms provider requires: name, address, contact details, what the number is for, and a copy of photo ID or a company certificate and a recent bill | UK phone numbers must be registered to the person or company using them. Documents go straight to our telecoms provider; we do not keep a copy | Legal obligation |
| Email verification status and the tokens behind password resets and team invitations | To confirm the address is yours and to let you back in when you are locked out | Performance of a contract |
| Your team: who invited whom, their role, which flows they may open, and which leads are assigned to them | So an account can be shared without everyone seeing everything | Performance of a contract |
| What you did in the product: calls made, their length and outcome, notes written, texts and emails sent, stages changed | It is the product. It is also how the scoreboard and the agent statistics are calculated | Performance of a contract |
| Whether you are at your desk, updated roughly every 30 seconds while the dialler is open | So a lead is not rung by two people at once, and so inbound calls reach someone who is actually there | Legitimate interests - running a shared phone system |
| Your acceptance of the call-recording notice, including which wording you agreed to and when | Because a consent that cannot be produced later is not evidence of anything | Legal obligation |
| Credentials for services you connect: Twilio, your mail server, Meta, TikTok. Encrypted with AES-256-GCM before they are written down | To send on your behalf. We never display them back to you or to ourselves | Performance of a contract |
| Support and data-deletion requests, and beta access requests, including what you wrote in them | To answer you, and to keep a record that we did | Legitimate interests / legal obligation |
| Rate-limiting counters, keyed to your account, and server logs | To stop abuse and to work out why something broke | Legitimate interests - security and reliability |
Where we rely on legitimate interests, we have weighed our interest against your rights and concluded ours does not override them. You can ask for that assessment and we will send it.
4. Cookies and similar technologies
The website sets one cookie: a signed session token that keeps you logged in. It is strictly necessary - the site cannot offer a logged-in area without it - so under the Privacy and Electronic Communications Regulations it does not require consent. That is the only reason you have not seen a cookie banner here, and it is a deliberate choice rather than an oversight.
The mobile app does not use cookies. It holds an opaque access token in the device’s secure storage; we store only a SHA-256 hash of it, so a copy of our database does not let anyone into your account.
If we ever add analytics, this section changes and you will be asked first.
Part B - The people you contact
This part covers leads: the members of the public whose details our customers load into Dialem. Here we are a processor acting for the customer.
5. What Dialem holds about a lead
- Identity and contact details: name, phone number, email address, and any custom fields on the form they filled in.
- Where they came from: the advert, ad set and campaign that produced them, the lead form, or the file they were imported in.
- Every call: when, how long, who made it, what the agent wrote down, and the recording if recording was on.
- Every message: the full text of SMS and email in both directions, and their delivery status.
- Conversations with the automated assistant, where the customer has switched it on.
- Their position in the pipeline, the value attached to them, callbacks booked, and a full timeline of everything that has happened to their record.
- Whether they have told anyone to stop contacting them - see section 9.
We do not deliberately collect special category data (health, race, religion, politics, sex life, biometrics) about leads. We cannot stop a customer typing it into a notes field or a caller mentioning it on a recorded call, and customers are contractually responsible for not doing so.
6. The browser extension
Dialem has an optional browser extension. A customer installs it themselves, and it does nothing until they sign in to Dialem through it.
It reads the page the person is looking at, on their own computer, to find business contact details: a name, phone number, email address, postal address and social profiles, the businesses on a Google Maps or Bing Maps search, and the businesses listed on a directory page.
None of that reaches us until they press something. Importing collected businesses, adding a website as a lead, or pressing the call button beside a phone number sends those details to Dialem, where they become leads in that customer’s account and everything else in Part B applies to them. Pressing a call button also creates the lead the call is then logged against.
The extension also:
- asks us whether a business is already a lead in one of the customer’s flows, by sending its phone number and the address of the website it was found on, so two people do not ring the same business;
- keeps the sign-in token, the chosen flow and sheet, and the businesses collected so far in the browser’s own storage. The collected list is cleared when the browser closes.
It does not:
- browse on its own. It reads the page in front of the person, and searches, moves the map or opens a page only when they do.
- send us the pages they visit, their browsing history, or anything they did not choose to import.
- read webmail, search engines, social networks or Dialem itself. Those sites are skipped.
- carry any advertising or analytics code.
Chrome asks for access to the sites the person visits when they install it. That access is what lets it read the page in front of them, and removing the extension removes it.
7. Google Calendar
If you connect Google, each person on your team connects their own account. We ask Google for two things: permission to see and edit the events in your calendar, and your email address, so Settings can show which account is connected.
We use that access to:
- Create the meetings you, or the assistant, book with a lead, with a Google Meet link attached.
- Check you are free before a meeting is booked, so you are never double booked. We look at when your events start and end, and their titles so we can tell you what a new meeting clashes with.
- Remove a meeting from your calendar when it is cancelled.
To do this we keep one item: a token from Google that lets us act on your behalf. It is encrypted, and it is deleted when you disconnect. We do not copy your calendar into Dialem or store the details of your other events.
When a meeting is booked, the lead’s name and email address are added to that event as the guest, in your calendar. That is the only lead data sent to Google, and only when a meeting is booked.
We do not:
- Sell or share your Google data with anyone.
- Use it for advertising.
- Use it to train artificial intelligence models - ours or anybody else’s.
- Let our staff read it, except to fix a fault you report.
Dialem’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
You can disconnect at any time in Settings, or remove Dialem at myaccount.google.com/permissions.
8. What we do and do not do with it
We process lead data only on the documented instructions of the customer who holds it. In practice that means: storing it, displaying it to that customer’s team, dialling and messaging the people in it when the customer tells us to, and running the automations the customer has built.
We do not:
- Sell it, rent it or share it with other customers.
- Use it to train artificial intelligence models - ours or anybody else’s.
- Use it to market anything to those people ourselves.
- Combine one customer’s leads with another’s. Accounts are separated at the database level and every query is scoped to the account that owns the data.
Our staff do not read customer data as a matter of course. Access happens only where it is needed to fix a fault you have reported or to meet a legal obligation, and is limited to the people who need it.
9. Call recording
Dialem can record calls. Recording is controlled by the customer, not by us, and before it can be switched on the customer must accept a notice setting out what the law requires of them. We record which version of that notice they accepted and when.
If you are a member of the public and you have been recorded, the business that called you is responsible for that recording - not Dialem. We hold it for them. We will pass any request straight to them, and tell you who they are.
Practical facts about recordings:
- Audio is stored by Twilio, our telephony provider, and is streamed through Dialem rather than downloaded - a recording URL is never handed to a browser directly, so it cannot be shared by copying a link.
- Voicemails left for a customer are recorded and transcribed to a note on the lead’s record.
- Recordings are kept for 12 months and then deleted automatically, from Twilio as well as from our database.
- Erasing a person deletes their audio from Twilio too, not just the row that pointed at it.
10. Do-not-contact and calling hours
When someone asks not to be contacted, Dialem enforces it in the server, at the moment of sending - not in the interface, which a stale page could skip.
- A suppression is recorded against the person, not the record: the last nine digits of their number and their email address in lower case. The same human often appears in a customer’s database several times, and silencing one copy is the failure that actually causes harm.
- It covers every channel. “Stop calling me” is not an invitation to email instead.
- Replying STOP to a text suppresses that person automatically. START lifts it. This exists because networks will block further texts on their own but will happily keep putting calls through.
- Calls are refused outside the account’s calling window - 8am to 9pm by default - worked out from the recipient’s own time zone where their number reveals it.
A suppression is deliberately kept after a lead is deleted. It has to be: the whole point is that re-importing the same list does not start the calls again.
11. Automated features and artificial intelligence
Some Dialem features send text to OpenAI, which processes it and sends a reply back. Those features are: the automated SMS assistant, the “draft a reply” button, and the tool that checks what a customer has written about their own business.
What is sent, when those features are used:
- The conversation so far with that lead, their first name, and the description the customer wrote about their business.
What is not sent:
- Call recordings. No audio ever leaves Dialem for an AI service.
- Anyone’s password, or any connected credential.
- Data from any other customer’s account.
OpenAI does not use data submitted through its API to train its models. It retains it for a limited period for abuse monitoring and then deletes it.
12. Who else sees the data
We use the following sub-processors. Each is bound by a contract that holds them to standards no lower than the ones in this policy, and none of them may use the data for their own purposes.
| Who | What they do | What they see | Where |
|---|---|---|---|
| Telnyx | Calls, SMS, phone numbers, call recordings, and registering numbers | Phone numbers, message content, call audio, and the details and documents a number is registered with | US / EU |
| Twilio | Calls and SMS for customers who connect their own Twilio account | Phone numbers, message content, call audio | US / EU |
| Stripe | Payments and invoices | Your name, email, billing address and card details (which we never see), and what you are charged | US / EU |
| Resend | Sending account emails: sign-in, invitations, reminders | Your email address and the content of those emails | US |
| Calendar and Google Meet links, where a user connects their calendar | Calendar availability and the meetings Dialem books - see section 7 | US / EU | |
| Neon | The database | Everything stored in Dialem | EU (Frankfurt) |
| Vercel | Hosting, delivery and page view analytics | Data in transit; request logs; page views, with no cookie or cross-site identifier | EU / global edge |
| OpenAI | The assistant and drafted replies | Message text and business context - see section 10 | US |
| Meta Platforms | Lead ad forms, where a customer connects them | Leads that Meta already holds, which we retrieve | US / EU |
| TikTok | Instant form lead ads, where a customer connects them | Leads TikTok sends us as they are submitted | US / EU |
| Expo and Apple | Push notifications to the mobile app | A device token and the notification text | US |
Customers also connect their own mail server for sending and reading email. That server is chosen by the customer and is not our sub-processor; email sent through it is subject to that provider’s terms.
Beyond those, we disclose personal data only:
- To our professional advisers - accountants and lawyers - where they are under a duty of confidence.
- Where the law compels us, or to establish or defend legal claims. We will tell you first unless we are legally barred from doing so.
- To a buyer, if the business is sold. They would be bound by this policy and you would be told before anything moved.
We will publish changes to this list here before a new sub-processor starts handling data, so customers have the chance to object.
13. Sending data outside the UK
Dialem’s database is hosted in the European Union, and account and lead data is held there.
Some of the services above are based in the United States, so certain data does leave the UK and the EEA - message text sent to OpenAI, notification text sent to Apple, and telephony data handled by Twilio. Where that happens we rely on the UK International Data Transfer Addendum to the European Commission Standard Contractual Clauses, together with the additional technical measures described in section 14.
You can ask us for a copy of the transfer safeguards that apply to any particular service and we will send it.
14. How long we keep things
| What | How long | Then what |
|---|---|---|
| Your account, and the leads, calls and messages in it | For as long as you are a customer | Deleted 30 days after the account closes |
| Call recordings and voicemails | 12 months from the call | Deleted automatically, including from Twilio |
| A lead a customer deletes by hand | Removed immediately from their pipeline | Call and message history is kept, unlinked, unless erasure is requested - see section 15 |
| Do-not-contact records | Indefinitely | Kept on purpose: deleting one would allow the contact to restart |
| Sign-in sessions and mobile device tokens | Until you sign out, or the session expires | Deleted |
| Password reset and invitation tokens | Hours | Expire and are deleted |
| Background job records | 7 days once finished, 30 days if they failed | Deleted automatically |
| Rate-limiting counters | 24 hours | Deleted automatically |
| Support requests and their correspondence | Up to 2 years | Deleted |
| Records we must keep by law, such as invoices | 6 years | Deleted |
Where a retention period has passed but the data is needed to establish or defend a legal claim, we keep it until the claim is resolved, and no longer.
15. How the data is protected
- Encrypted in transit everywhere, and encrypted at rest by our database provider.
- Third-party credentials - a customer’s Twilio secret, their mail password - are separately encrypted with AES-256-GCM before storage, using a key held outside the database. A copy of the database on its own does not yield them.
- Passwords are stored as one-way hashes. We cannot recover one, which is why a reset link is the only route back in.
- Mobile access tokens are stored only as SHA-256 hashes.
- Call recordings are streamed through an authenticated endpoint that checks the request belongs to the account that owns the call. The underlying audio URL is never exposed.
- Requests that claim to come from our telephony provider are signature-checked before they are acted on.
- Access to production systems is limited to those who need it and is protected by multi-factor authentication.
No system is perfect, and anyone who tells you otherwise is selling something. If a breach occurs that is likely to result in a risk to people’s rights, we will report it to the ICO within 72 hours and tell the people affected without undue delay where the risk is high.
If you think you have found a security problem, please write to tombrookes06@gmail.com. We will not pursue anyone who reports a genuine flaw in good faith.
16. Your rights
Under the UK GDPR you have the right to:
| Right | What it means here |
|---|---|
| Be informed | This document. Ask us anything it does not answer. |
| Access | A copy of everything we hold about you. Dialem can assemble this for a lead across every table in one operation. |
| Rectification | Have anything wrong corrected. Customers can edit lead records directly; ask us and we will pass it on. |
| Erasure | Have it deleted. This goes further than deleting a record: it removes calls, recordings, messages and timeline entries, and deletes the audio from Twilio. |
| Restriction | Have us stop processing while a dispute is resolved. |
| Portability | Receive your data in a machine-readable format. |
| Object | Object to processing based on legitimate interests, including any direct marketing - which we will always stop. |
| Withdraw consent | Where we relied on consent, withdraw it at any time. It does not undo what was lawful beforehand. |
To exercise any of them, use the support form or write to tombrookes06@gmail.com. You do not need an account and there is no charge. We will respond within one month, and will tell you if we need longer because the request is complex.
We may ask you to confirm who you are before acting. That is not obstruction - handing someone’s call recordings to a stranger who claimed to be them would be a far worse failure than a delay.
17. Marketing to you
We email customers about the service itself - outages, changes, things that affect your account. You cannot unsubscribe from those without closing the account, because they are part of providing it.
Anything promotional is separate, is sent only where you have agreed or where you are an existing customer being told about something similar, and every one of them carries a one-click unsubscribe that works.
18. Children
Dialem is a business tool and is not intended for anyone under 18. We do not knowingly hold data about children. If you believe a child’s data is in the system, tell us and we will remove it.
19. Changes to this policy
When this policy changes we update the version and date at the top. For changes that materially affect how we handle personal data - a new sub-processor, a new purpose, a longer retention period - we will tell customers by email before it takes effect, not afterwards.
Previous versions are available on request.
20. Complaints
If you are unhappy with how we have handled your data, please tell us first at tombrookes06@gmail.com - most things are quicker to fix directly.
You also have the right to complain to the Information Commissioner’s Office at any time, and you do not have to come to us first:
Information Commissioner’s OfficeWycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
0303 123 1113 · ico.org.uk/make-a-complaint
21. Contact us
tombrookes06@gmail.com
Studio 404 Development Ltd, 344 Oldfield Road, Altrincham, England, WA14 4QS
For anything that is not about privacy, use the support form.