Dialem

Legal

Privacy Policy

Dialem is a phone system that holds other people’s contact details. This explains exactly what we do with them - both yours, and those of the people your business calls.

Version 1.3 · Effective 23 September 2026

The short version

  • We do not sell personal data. We never have and the business model does not depend on it.
  • We do not track you around the internet. There are no analytics scripts, no advertising pixels and no third-party cookies on this site - which is why you were not asked to accept any.
  • The leads in your account are yours. We hold them on your instructions and do not use them for our own purposes.
  • Calls made through Dialem can be recorded. That is the part of this document worth reading properly, and it has its own section.
  • Anyone can ask us to delete everything we hold about them, whether or not they are a customer, using the support form.

The short version is a summary and nothing more. Where it and the full text disagree, the full text is what we are bound by.

1. Who we are

Dialem is operated by Studio 404 Development Ltd, a company registered in England and Wales (number 17241297), whose registered office is 344 Oldfield Road, Altrincham, England, WA14 4QS.

In this policy, “we” means that company. “You” means whoever is reading it - a customer, someone on a customer’s team, or a member of the public who has been contacted by one of them.

We have not appointed a Data Protection Officer, because we are not required to under Article 37 of the UK GDPR. Privacy questions go to tombrookes06@gmail.com, which is monitored by a named person rather than a queue.

2. The two different roles we play

This is the most important idea in the document, and almost every question about Dialem and data has a different answer depending on which of the two applies.

We are the controller of your account

Your name, your email address, your billing details, which features you use, the fact that you are a customer at all. We decide what to collect and why, so the responsibility is ours.

Covered by Part A.

We are a processor of your leads

The people you call, text and email. We did not choose to collect them, we do not decide what they are for, and we act on your instructions. You are their controller; we are your processor.

Covered by Part B.

The practical consequence: if one of your leads asks us to delete their data, we will normally tell them to ask you, and tell you that they asked. We will act ourselves where the law requires it or where you cannot be reached, but the decision is yours to make, because they are your contacts and you know why you hold them.

Part A - When you use Dialem

This part covers customers and their team members: the people who log in. Here we are the controller.

3. What we collect about you, and why

WhatWhy we have itLawful basis
Name, email address and password (stored only as a one-way hash - we cannot read it, and neither can anyone who steals the database)To create your account, sign you in, and attribute calls and notes to the right person on your teamPerformance of a contract
Your business name and phone number, given when you sign upTo set up your account, and to get in touch about it, including once or twice if you create an account but do not start your trial. Tell us to stop and we willLegitimate interests - helping you finish setting up
Your acceptance of our terms and this policy: when, which versions, and the internet address you accepted fromSo we can show what you agreed to, and whenLegitimate interests / legal obligation
Your plan, your billing status, the minutes your team has used, and what your calls and texts cost us, taken from our telecoms provider’s billing recordsTo apply your plan’s minutes, charge for extra minutes you turn on, and understand what running the service costsPerformance of a contract / legitimate interests
For a phone number, the details our telecoms provider requires: name, address, contact details, what the number is for, and a copy of photo ID or a company certificate and a recent billUK phone numbers must be registered to the person or company using them. Documents go straight to our telecoms provider; we do not keep a copyLegal obligation
Email verification status and the tokens behind password resets and team invitationsTo confirm the address is yours and to let you back in when you are locked outPerformance of a contract
Your team: who invited whom, their role, which flows they may open, and which leads are assigned to themSo an account can be shared without everyone seeing everythingPerformance of a contract
What you did in the product: calls made, their length and outcome, notes written, texts and emails sent, stages changedIt is the product. It is also how the scoreboard and the agent statistics are calculatedPerformance of a contract
Whether you are at your desk, updated roughly every 30 seconds while the dialler is openSo a lead is not rung by two people at once, and so inbound calls reach someone who is actually thereLegitimate interests - running a shared phone system
Your acceptance of the call-recording notice, including which wording you agreed to and whenBecause a consent that cannot be produced later is not evidence of anythingLegal obligation
Credentials for services you connect: Twilio, your mail server, Meta, TikTok. Encrypted with AES-256-GCM before they are written downTo send on your behalf. We never display them back to you or to ourselvesPerformance of a contract
Support and data-deletion requests, and beta access requests, including what you wrote in themTo answer you, and to keep a record that we didLegitimate interests / legal obligation
Rate-limiting counters, keyed to your account, and server logsTo stop abuse and to work out why something brokeLegitimate interests - security and reliability

Where we rely on legitimate interests, we have weighed our interest against your rights and concluded ours does not override them. You can ask for that assessment and we will send it.

What we do not collect. We do not run analytics, advertising or session-replay software. We do not build a profile of you. We do not buy data about you from anyone. There is no behavioural tracking in this product at all, on the website or in the app.

4. Cookies and similar technologies

The website sets one cookie: a signed session token that keeps you logged in. It is strictly necessary - the site cannot offer a logged-in area without it - so under the Privacy and Electronic Communications Regulations it does not require consent. That is the only reason you have not seen a cookie banner here, and it is a deliberate choice rather than an oversight.

The mobile app does not use cookies. It holds an opaque access token in the device’s secure storage; we store only a SHA-256 hash of it, so a copy of our database does not let anyone into your account.

If we ever add analytics, this section changes and you will be asked first.

Part B - The people you contact

This part covers leads: the members of the public whose details our customers load into Dialem. Here we are a processor acting for the customer.

5. What Dialem holds about a lead

  • Identity and contact details: name, phone number, email address, and any custom fields on the form they filled in.
  • Where they came from: the advert, ad set and campaign that produced them, the lead form, or the file they were imported in.
  • Every call: when, how long, who made it, what the agent wrote down, and the recording if recording was on.
  • Every message: the full text of SMS and email in both directions, and their delivery status.
  • Conversations with the automated assistant, where the customer has switched it on.
  • Their position in the pipeline, the value attached to them, callbacks booked, and a full timeline of everything that has happened to their record.
  • Whether they have told anyone to stop contacting them - see section 9.

We do not deliberately collect special category data (health, race, religion, politics, sex life, biometrics) about leads. We cannot stop a customer typing it into a notes field or a caller mentioning it on a recorded call, and customers are contractually responsible for not doing so.

6. The browser extension

Dialem has an optional browser extension. A customer installs it themselves, and it does nothing until they sign in to Dialem through it.

It reads the page the person is looking at, on their own computer, to find business contact details: a name, phone number, email address, postal address and social profiles, the businesses on a Google Maps or Bing Maps search, and the businesses listed on a directory page.

None of that reaches us until they press something. Importing collected businesses, adding a website as a lead, or pressing the call button beside a phone number sends those details to Dialem, where they become leads in that customer’s account and everything else in Part B applies to them. Pressing a call button also creates the lead the call is then logged against.

The extension also:

  • asks us whether a business is already a lead in one of the customer’s flows, by sending its phone number and the address of the website it was found on, so two people do not ring the same business;
  • keeps the sign-in token, the chosen flow and sheet, and the businesses collected so far in the browser’s own storage. The collected list is cleared when the browser closes.

It does not:

  • browse on its own. It reads the page in front of the person, and searches, moves the map or opens a page only when they do.
  • send us the pages they visit, their browsing history, or anything they did not choose to import.
  • read webmail, search engines, social networks or Dialem itself. Those sites are skipped.
  • carry any advertising or analytics code.

Chrome asks for access to the sites the person visits when they install it. That access is what lets it read the page in front of them, and removing the extension removes it.

7. Google Calendar

If you connect Google, each person on your team connects their own account. We ask Google for two things: permission to see and edit the events in your calendar, and your email address, so Settings can show which account is connected.

We use that access to:

  • Create the meetings you, or the assistant, book with a lead, with a Google Meet link attached.
  • Check you are free before a meeting is booked, so you are never double booked. We look at when your events start and end, and their titles so we can tell you what a new meeting clashes with.
  • Remove a meeting from your calendar when it is cancelled.

To do this we keep one item: a token from Google that lets us act on your behalf. It is encrypted, and it is deleted when you disconnect. We do not copy your calendar into Dialem or store the details of your other events.

When a meeting is booked, the lead’s name and email address are added to that event as the guest, in your calendar. That is the only lead data sent to Google, and only when a meeting is booked.

We do not:

  • Sell or share your Google data with anyone.
  • Use it for advertising.
  • Use it to train artificial intelligence models - ours or anybody else’s.
  • Let our staff read it, except to fix a fault you report.

Dialem’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

You can disconnect at any time in Settings, or remove Dialem at myaccount.google.com/permissions.

8. What we do and do not do with it

We process lead data only on the documented instructions of the customer who holds it. In practice that means: storing it, displaying it to that customer’s team, dialling and messaging the people in it when the customer tells us to, and running the automations the customer has built.

We do not:

  • Sell it, rent it or share it with other customers.
  • Use it to train artificial intelligence models - ours or anybody else’s.
  • Use it to market anything to those people ourselves.
  • Combine one customer’s leads with another’s. Accounts are separated at the database level and every query is scoped to the account that owns the data.

Our staff do not read customer data as a matter of course. Access happens only where it is needed to fix a fault you have reported or to meet a legal obligation, and is limited to the people who need it.

9. Call recording

Dialem can record calls. Recording is controlled by the customer, not by us, and before it can be switched on the customer must accept a notice setting out what the law requires of them. We record which version of that notice they accepted and when.

If you are a member of the public and you have been recorded, the business that called you is responsible for that recording - not Dialem. We hold it for them. We will pass any request straight to them, and tell you who they are.

Practical facts about recordings:

  • Audio is stored by Twilio, our telephony provider, and is streamed through Dialem rather than downloaded - a recording URL is never handed to a browser directly, so it cannot be shared by copying a link.
  • Voicemails left for a customer are recorded and transcribed to a note on the lead’s record.
  • Recordings are kept for 12 months and then deleted automatically, from Twilio as well as from our database.
  • Erasing a person deletes their audio from Twilio too, not just the row that pointed at it.
Recording a call is lawful in the UK, but telling people you are doing it is generally required, and using a recording for a purpose you did not tell them about is not. Dialem gives customers the tooling; it cannot give them a lawful basis. That remains theirs.

10. Do-not-contact and calling hours

When someone asks not to be contacted, Dialem enforces it in the server, at the moment of sending - not in the interface, which a stale page could skip.

  • A suppression is recorded against the person, not the record: the last nine digits of their number and their email address in lower case. The same human often appears in a customer’s database several times, and silencing one copy is the failure that actually causes harm.
  • It covers every channel. “Stop calling me” is not an invitation to email instead.
  • Replying STOP to a text suppresses that person automatically. START lifts it. This exists because networks will block further texts on their own but will happily keep putting calls through.
  • Calls are refused outside the account’s calling window - 8am to 9pm by default - worked out from the recipient’s own time zone where their number reveals it.

A suppression is deliberately kept after a lead is deleted. It has to be: the whole point is that re-importing the same list does not start the calls again.

11. Automated features and artificial intelligence

Some Dialem features send text to OpenAI, which processes it and sends a reply back. Those features are: the automated SMS assistant, the “draft a reply” button, and the tool that checks what a customer has written about their own business.

What is sent, when those features are used:

  • The conversation so far with that lead, their first name, and the description the customer wrote about their business.

What is not sent:

  • Call recordings. No audio ever leaves Dialem for an AI service.
  • Anyone’s password, or any connected credential.
  • Data from any other customer’s account.

OpenAI does not use data submitted through its API to train its models. It retains it for a limited period for abuse monitoring and then deletes it.

No decisions are made about people automatically. The assistant writes messages; it does not decide whether someone gets a service, a price or a rejection. Nothing in Dialem produces a legal or similarly significant effect on a person without a human involved, so the Article 22 right does not arise. If that ever changes, this section changes first.

12. Who else sees the data

We use the following sub-processors. Each is bound by a contract that holds them to standards no lower than the ones in this policy, and none of them may use the data for their own purposes.

WhoWhat they doWhat they seeWhere
TelnyxCalls, SMS, phone numbers, call recordings, and registering numbersPhone numbers, message content, call audio, and the details and documents a number is registered withUS / EU
TwilioCalls and SMS for customers who connect their own Twilio accountPhone numbers, message content, call audioUS / EU
StripePayments and invoicesYour name, email, billing address and card details (which we never see), and what you are chargedUS / EU
ResendSending account emails: sign-in, invitations, remindersYour email address and the content of those emailsUS
GoogleCalendar and Google Meet links, where a user connects their calendarCalendar availability and the meetings Dialem books - see section 7US / EU
NeonThe databaseEverything stored in DialemEU (Frankfurt)
VercelHosting, delivery and page view analyticsData in transit; request logs; page views, with no cookie or cross-site identifierEU / global edge
OpenAIThe assistant and drafted repliesMessage text and business context - see section 10US
Meta PlatformsLead ad forms, where a customer connects themLeads that Meta already holds, which we retrieveUS / EU
TikTokInstant form lead ads, where a customer connects themLeads TikTok sends us as they are submittedUS / EU
Expo and ApplePush notifications to the mobile appA device token and the notification textUS

Customers also connect their own mail server for sending and reading email. That server is chosen by the customer and is not our sub-processor; email sent through it is subject to that provider’s terms.

Beyond those, we disclose personal data only:

  • To our professional advisers - accountants and lawyers - where they are under a duty of confidence.
  • Where the law compels us, or to establish or defend legal claims. We will tell you first unless we are legally barred from doing so.
  • To a buyer, if the business is sold. They would be bound by this policy and you would be told before anything moved.

We will publish changes to this list here before a new sub-processor starts handling data, so customers have the chance to object.

13. Sending data outside the UK

Dialem’s database is hosted in the European Union, and account and lead data is held there.

Some of the services above are based in the United States, so certain data does leave the UK and the EEA - message text sent to OpenAI, notification text sent to Apple, and telephony data handled by Twilio. Where that happens we rely on the UK International Data Transfer Addendum to the European Commission Standard Contractual Clauses, together with the additional technical measures described in section 14.

You can ask us for a copy of the transfer safeguards that apply to any particular service and we will send it.

14. How long we keep things

WhatHow longThen what
Your account, and the leads, calls and messages in itFor as long as you are a customerDeleted 30 days after the account closes
Call recordings and voicemails12 months from the callDeleted automatically, including from Twilio
A lead a customer deletes by handRemoved immediately from their pipelineCall and message history is kept, unlinked, unless erasure is requested - see section 15
Do-not-contact recordsIndefinitelyKept on purpose: deleting one would allow the contact to restart
Sign-in sessions and mobile device tokensUntil you sign out, or the session expiresDeleted
Password reset and invitation tokensHoursExpire and are deleted
Background job records7 days once finished, 30 days if they failedDeleted automatically
Rate-limiting counters24 hoursDeleted automatically
Support requests and their correspondenceUp to 2 yearsDeleted
Records we must keep by law, such as invoices6 yearsDeleted

Where a retention period has passed but the data is needed to establish or defend a legal claim, we keep it until the claim is resolved, and no longer.

15. How the data is protected

  • Encrypted in transit everywhere, and encrypted at rest by our database provider.
  • Third-party credentials - a customer’s Twilio secret, their mail password - are separately encrypted with AES-256-GCM before storage, using a key held outside the database. A copy of the database on its own does not yield them.
  • Passwords are stored as one-way hashes. We cannot recover one, which is why a reset link is the only route back in.
  • Mobile access tokens are stored only as SHA-256 hashes.
  • Call recordings are streamed through an authenticated endpoint that checks the request belongs to the account that owns the call. The underlying audio URL is never exposed.
  • Requests that claim to come from our telephony provider are signature-checked before they are acted on.
  • Access to production systems is limited to those who need it and is protected by multi-factor authentication.

No system is perfect, and anyone who tells you otherwise is selling something. If a breach occurs that is likely to result in a risk to people’s rights, we will report it to the ICO within 72 hours and tell the people affected without undue delay where the risk is high.

If you think you have found a security problem, please write to tombrookes06@gmail.com. We will not pursue anyone who reports a genuine flaw in good faith.

16. Your rights

Under the UK GDPR you have the right to:

RightWhat it means here
Be informedThis document. Ask us anything it does not answer.
AccessA copy of everything we hold about you. Dialem can assemble this for a lead across every table in one operation.
RectificationHave anything wrong corrected. Customers can edit lead records directly; ask us and we will pass it on.
ErasureHave it deleted. This goes further than deleting a record: it removes calls, recordings, messages and timeline entries, and deletes the audio from Twilio.
RestrictionHave us stop processing while a dispute is resolved.
PortabilityReceive your data in a machine-readable format.
ObjectObject to processing based on legitimate interests, including any direct marketing - which we will always stop.
Withdraw consentWhere we relied on consent, withdraw it at any time. It does not undo what was lawful beforehand.

To exercise any of them, use the support form or write to tombrookes06@gmail.com. You do not need an account and there is no charge. We will respond within one month, and will tell you if we need longer because the request is complex.

We may ask you to confirm who you are before acting. That is not obstruction - handing someone’s call recordings to a stranger who claimed to be them would be a far worse failure than a delay.

If you are a lead rather than a customer:your request is usually best made to the business that contacted you, because your data is theirs and only they know why they hold it. If you do not know who they are, tell us the number that called you and we will identify them and pass your request on. An erasure request we act on covers one business’s records - the same details held by an unrelated Dialem customer are a separate matter, and their request to make.

17. Marketing to you

We email customers about the service itself - outages, changes, things that affect your account. You cannot unsubscribe from those without closing the account, because they are part of providing it.

Anything promotional is separate, is sent only where you have agreed or where you are an existing customer being told about something similar, and every one of them carries a one-click unsubscribe that works.

18. Children

Dialem is a business tool and is not intended for anyone under 18. We do not knowingly hold data about children. If you believe a child’s data is in the system, tell us and we will remove it.

19. Changes to this policy

When this policy changes we update the version and date at the top. For changes that materially affect how we handle personal data - a new sub-processor, a new purpose, a longer retention period - we will tell customers by email before it takes effect, not afterwards.

Previous versions are available on request.

20. Complaints

If you are unhappy with how we have handled your data, please tell us first at tombrookes06@gmail.com - most things are quicker to fix directly.

You also have the right to complain to the Information Commissioner’s Office at any time, and you do not have to come to us first:

Information Commissioner’s Office
Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
0303 123 1113 · ico.org.uk/make-a-complaint

21. Contact us

tombrookes06@gmail.com
Studio 404 Development Ltd, 344 Oldfield Road, Altrincham, England, WA14 4QS

For anything that is not about privacy, use the support form.