Privacy Policy

Last updated: 7 September 2026

Introduction

Odendaal Limited Trading as AGS Support (“we”, “our”, “us”) is the data controller responsible for your personal data. We are committed to protecting your privacy and ensuring that your personal information is handled in a safe and responsible manner. This policy explains how we collect, use, store, and protect your personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

Using AGS Calls? Read the Android app privacy supplement, including call recordings and data requests. You can also request AGS Calls account or data deletion by email.

Data We Collect

We may collect and process the following categories of personal data:

  • Identity data: name, job title, and organisation
  • Contact data: email address, phone number, and postal address
  • Enquiry data: information you provide when contacting us or requesting our services
  • Technical data: IP address, browser type, and usage data collected via cookies when you visit our website
  • Employment data: CV details, references, and right-to-work documentation (for job applicants and staff)

How We Use Your Data

We use personal data for the following purposes:

  • To provide, manage, and improve our staffing and support services
  • To respond to enquiries and communicate with you about our services
  • To process job applications and manage our workforce
  • To comply with legal and regulatory obligations, including safeguarding duties
  • To send you relevant updates about our services, where you have given consent

Our legal bases for processing include: performance of a contract, compliance with a legal obligation, legitimate interests, and consent (where applicable).

Data Retention

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by law. Enquiry data is typically retained for up to 24 months. Employment-related records are retained in line with HMRC and regulatory requirements. When data is no longer needed, it is securely deleted or anonymised.

Your Rights

Under the UK GDPR, you have the right to:

  • Access your personal data and obtain a copy of it
  • Rectification of inaccurate or incomplete data
  • Erasure of your data in certain circumstances
  • Restrict processing of your data
  • Object to processing based on legitimate interests
  • Data portability to transfer your data to another organisation
  • Withdraw consent at any time, where processing is based on consent

To exercise any of these rights, please contact us using the details below. We will respond to your request within one month.

Cookies

Our website uses cookies to improve your browsing experience and to analyse website traffic. Cookies are small text files stored on your device. You can control cookie settings through your browser preferences. We use essential cookies required for the website to function and analytics cookies to understand how visitors use our site.

Third-Party Sharing

We do not sell your personal data to third parties. We may share your data with trusted service providers who assist us in operating our business (e.g., IT support, payroll providers) under appropriate data processing agreements. We may also disclose data where required by law or regulation.

AGS Calls Android app

App supplement updated: 7 September 2026

Who is responsible

AGS Calls is the Android business-calling companion to AGS Portal. Odendaal Limited trading as AGS Support is responsible for AGS's use of your personal data. Our company number is 16221058 and our registered office is 71–75 Shelton Street, Covent Garden, London WC2H 9JQ, United Kingdom.

Contact developer@agssupport.co.uk about AGS Calls support, privacy, access, correction or deletion requests. Read this supplement alongside the general policy above, which explains our wider workforce and business processing and your rights. The website's general contact remains solutions@agssupport.co.uk.

Information used by AGS Calls

The workforce workspace in AGS Calls uses your existing AGS Portal account and permissions. Authentication processes your email address, password and verification information, and may use your name or phone number to deliver a verification code. The app receives your employee profile and the employee/business contact directory you are permitted to use, including names, roles, contact details and existing profile images.

When you make or receive a business call, our calling systems process the caller and destination, account and call identifiers, line, timing, duration, answer status and relevant employee attribution. Microphone audio is transmitted for the conversation. Calls on recording-enabled routes, including the current main business line, are recorded; voicemail audio is also recorded. Authorised users can access the shared call history and available media in AGS Calls or the portal.

Voicemail is shared within the permitted business access, but viewed/unread status is personal to each user. The system stores your viewed/unread changes. Searching the shared call history sends your search terms to the backend to retrieve matching results.

When you enable incoming calls or voicemail alerts, the app registers a device identifier and push token with the relevant services. Account/session and registration information determines whether that phone can receive calls or alerts. Calling and push services also process app/SDK versions, operating-system/device information, IP addresses and service diagnostics. Twilio derives approximate location from IP addresses for communications operations, quality and security; AGS Calls does not request GPS or precise-location permission.

The app does not read your phone's address book, system call log or SMS inbox, and it does not upload photos from your camera or gallery. Existing directory avatars are displayed from the shared system. There are no advertising or in-app purchase features in the current app.

Separate Play review workspace

The review workspace uses separately supplied review credentials and a device-bound session that expires after 24 hours. It does not sign you into an AGS Portal employee account. Its directory, sample history and sample voicemail are fictional. Its fixed in-app audio test and requested callback are live calls through Twilio; they do not call workforce contacts or ordinary phone numbers.

In the live audio test, pressing 1 records up to five seconds of your voice and plays it back to you. We attempt to delete this test recording shortly after the call, with a fallback cleanup when recorded audio reaches 15 minutes. A service failure can delay deletion; this is not a guaranteed deletion deadline. New test requests and further recording are paused while overdue audio needs cleanup.

Review login, device, session and call records are held separately from workforce records and remain until administrative deletion. Changes to review settings, including the reason you enter, are also saved in a private audit record linked to your review account and installation, and remain until administrative deletion. The calling and push providers described in this notice still process the information needed for live review tests and alerts. The account and data request route below also applies to the review workspace: contact developer@agssupport.co.uk and identify the review account and relevant data.

Why we use this information

We use this information to authenticate authorised users, apply business-line permissions, connect calls, provide shared call records and voicemail, deliver requested alerts, and maintain and troubleshoot the service. These functions form part of AGS's business and workforce systems. The general privacy policy explains our existing processing purposes and legal bases; this supplement does not make every use of employee information dependent on an Android permission.

Existing shared call records may contain transcripts or summaries where separate portal processing has been enabled or requested. As of this notice's preparation, the main business line does not automatically request AI transcription or summarisation. The shared backend can process authorised requests using OpenAI, sending the selected audio for transcription and relevant text for a summary. Such results become shared call-record information under the applicable access permissions.

Service providers and other recipients

We use Supabase for authentication, backend records and media storage; Twilio for voice calling and call-related processing; and Google Firebase Cloud Messaging for incoming-call and voicemail push delivery. Telephone networks carry calls to and from ordinary phone numbers. OpenAI is used by the separate shared transcription/summary workflow when enabled or requested.

Service providers process information needed for these functions. Twilio also has independent responsibilities and uses for communications metadata and certain content, including service operations, security, legal obligations and improvement, described in its privacy notice and data protection terms. Its role is not limited to acting on AGS's instructions. We do not sell your personal data.

Providers may process information outside the United Kingdom or European Union under their applicable data-protection and transfer terms. App-to-service connections use encrypted transport, including HTTPS and protected voice media; ordinary telephone calls are not described as end-to-end encrypted.

Storage and retention

Shared call logs, recordings, voicemail, viewed receipts and registration records remain in the business systems until managed or deleted administratively. The current implementation does not establish a fixed automatic purge period for these records. Retention requests need to account for the relevant business purpose and any applicable legal requirement; the general policy's enquiry-retention period is not a call-recording deletion schedule.

Provider retention can differ from AGS's own storage. Twilio currently documents a 30-day period for Voice Insights data; that is not a promise to delete AGS recordings, shared call history or all provider communications data after 30 days. Provider records may be retained separately for service and legal purposes.

The phone keeps private local session, registration, voicemail and media data to support the app. Session/registration/voicemail stores use Android Keystore-backed encryption. Downloaded audio is held in the app's private storage; older audio is cleaned during later downloads and media is cleared on sign-out. Some cache data has a 24-hour validity check, which does not mean every local file or any shared business record is automatically erased after 24 hours.

Local incoming-ring diagnostics record a short, bounded history of notification/sound settings, audio mode, app version and timing. They contain no caller numbers, call identifiers or push tokens and are not uploaded by the app. You can explicitly copy diagnostic text if you choose to share it with support.

Your choices

You can disable incoming-call reception or voicemail alerts in the app and manage microphone, notifications, call sound and full-screen access in Android settings. These choices can limit the corresponding feature. Android sound, notification and Do Not Disturb settings also affect how alerts appear and sound.

Signing out or unregistering a phone stops or removes local access/registration as applicable; it does not delete the AGS account or shared business call records.

Request AGS Calls account or data deletion

To request deletion of your AGS Calls account and associated personal data, email developer@agssupport.co.uk. You can email an AGS Calls deletion request or copy the address into your own email service. You do not need to sign in or reinstall the app to make a request. Opening the email link does not submit a request; send the email when you are ready.

Identify the email address used for your AGS account and say whether you are requesting account deletion with associated data, or deletion of particular data. Do not send your password or verification codes. We may ask for information needed to verify the request and locate the relevant records. This is an administrative request process, not an instant account-deletion button. Our general privacy policy sets out our rights-request response commitment.

An account-deletion request covers your AGS login and associated profile information, device and push registrations, personal voicemail viewed receipts, and other account-linked personal data. Associated call history, recordings, voicemail and any transcripts or summaries are included in the review. You may also identify particular records in a data-only request. A request is not limited to signing out or stopping incoming calls.

Some shared call, employment or business records may contain other people's information or need to be retained for specific security, fraud-prevention or regulatory obligations. Any exception must be assessed for the relevant records; using AGS Calls does not make every record exempt from deletion. We will explain what will be deleted, any data retained, the reason, and the applicable retention period or criteria. Provider-held data must also be considered where relevant. As described above, shared records currently persist until administrative deletion; no fixed automatic purge schedule is promised. Deleting an account does not mean other users' independent accounts or unrelated records are deleted.

Contact Us

If you have any questions about this privacy policy, wish to exercise your rights, or have a complaint about how we handle your data, please contact us:

  • Data Controller: Odendaal Limited Trading as AGS Support
  • Registered office: 71-75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ
  • Trading address: Centurion House, London Road, Staines-upon-Thames, Surrey, TW18 4AX
  • Company No.: 16221058
  • VAT Registration No.: 515 4383 00
  • Email: solutions@agssupport.co.uk

You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk if you are not satisfied with our response.