Scope of this notice
What types of information do we collect
Why do we collect this information?
Who do we give your information to?
Where we store your information?
Automated processing and decisions
How is your personal information protected?
Contacting Callsign about privacy questions or concerns
Privacy notice changes
The purpose of this Privacy Notice is to provide you with a clear explanation about how your personal information is collected and used by us during your interaction with us as well as your rights in relation to your personal information. It relates to the Callsign websites ("the Sites") and Employee Authentication App (our "App") available to download on App Stores (together the "Services"). To learn about how we process personal information as part of our products, please see the Callsign Data Processing on behalf of Subscriber Organizations.
“Callsign Limited” is registered at 8th floor, One Bartholomew Close, London, EC1A 7BL with this company number 07277719 and is a subsidiary of "Callsign Inc." which is registered at 4 Palo Alto Square, 3000 El Camino Real, Building 4, Suite 200, Palo Alto 94306, California. For the purposes of European Economic Area and United Kingdom data protection law, (the "Data Protection Law"), Callsign products are offered to our clients on a Business to Business (B2B) basis, in this instance, Callsign is identified as a data processor. For all data held by Callsign in relation to employees and marketing of Callsign services, Callsign is identified as a data controller.
This Privacy Notice applies to Callsign Ltd. (“Callsign” or “we”), its affiliates, subsidiaries and business users. The individual at an organization that subscribes to the Services will be referred to as the “Subscriber” or “you”.
By accepting our Services or engaging with the Sites you acknowledge you have read and understood this privacy policy.
If you have any questions regarding our Privacy Notice or use of your personal information, please contact us using the below method:
Address: Callsign Ltd. 8th floor, One Bartholomew Close, London, EC1A 7BL
Email: dpo@callsign.com
We may process your personal data if:
We may process your personal data that we have either obtained from you or obtained from somewhere else. Personal data which is not collected directly from you may be collected:
Personal data relating to you that we process may include:
Failure to provide information or provide correct information could lead to Callsign not being able to comply with the request or provide the Services.
Callsign may also collect information about how you use the Sites and the App via cookies. We do this so that we can tailor and personalize your experience and, improve the content, layout and performance of our Services. Further details are set out in our Cookies policy.
Platform | Information Category | What we collect information for | Lawful basis for processing | Retention Period |
---|---|---|---|---|
Website and other online platforms such as blogs and micro-sites. | Transaction details, fulfilment data, Personal information including contact information as listed above. | To fulfil any requests that are made to us. To email you regarding details of the Services or marketing related information. |
Our Legitimate Interests, where we have considered these are not overridden by your rights. Contractual Performance. We may use some automation to help process data. This includes using cookies and preferences you have selected such as area of interest, location or industry to show or contact you with relevant information |
For as long as consent to communicate is given. At any time, you can update your preferences (including amending Personal Data) or opt out of all communications by clicking the links in the footer of any emails you receive from us. You can also contact us via the methods outlined in this document. In the instance where you have chosen to opt out of communications from Callsign, we will not use your personal data for direct marketing purposes, but we will continue to use your personal data in relation to the administration of the service, or to provide technical and other support to you in relation to the service. |
Online Demos |
Personal information including username or email address chosen when registering, data associated with your device and behavioral data associated with your keystroke, mouse movements. |
To fulfil any requests that are made to us for online demos. |
Our Legitimate Interests, where we have considered these are not overridden by your rights. |
Data will be kept for as long as relevant for the purposes of follow-up from the demo. Following a period of one year without interaction (opening correspondence, interacting with our website etc.) we will remove your details from our accounts. |
Using the Callsign Mobile App |
We collect registration information - data about who you are - including user alias, passwords, email address and telephone number to help provide a mobile app-based authentication service. We use this data along with behavioral data about how you swipe and device data to authenticate you as an individual when accessing protected resources and collateral. We also collect IP and User Agent Strings (info about your device) for security reasons (Security Operations & Forensic) |
This information is necessary to fulfil the contract as part of authentication service when using the Callsign app. The same data points also help us detect illegitimate registration attempts by fraudulent parties and thereby protect our legitimate interests and protect our genuine users. |
Our Legitimate Interests, where we have considered these are not overridden by your rights. |
Callsign will keep your data until you as a user provide written request and / or delete your profile in the Callsign app. Following this request, your data may be stored for up to seven years for legal purposes. As a user you can delete your Callsign account at any time within the settings in the app. |
Where permitted in our legitimate interest or with your prior consent where required by law, we will use your personal information for marketing analysis and to provide you with promotional update communications by email, SMS, Push Notification, Telephone, Post and Social Media about our products and Services.
You can object to further marketing at any time by selecting the "unsubscribe" link at the end of all our marketing and promotional update communications to you, or by sending us an email to
dpo@callsign.com.
You can also request that we send marketing material to a non-personal email address instead of one which identifies you as an individual.
We may share your information with:
Our selected third parties may include:
We will disclose your personal information to third parties:
The data that we collect from you may be transferred to, and stored at, a destination outside the UK or the European Economic Area ("EEA") that may not be subject to equivalent Data Protection Law.
Where your information is transferred outside the UK or the EEA, we will take all steps reasonably necessary to ensure that your data is subject to appropriate safeguards, such as relying on a recognized legal adequacy mechanism or standard contractual clauses, and that it is treated securely and in accordance with this privacy notice.
We may transfer your personal information outside the UK or the EEA:
During the registration journey on the Callsign Mobile App we make automated decisions based upon interpretation of profiled data points that assess associated risk with your device. From time to time we may refuse your attempt to register with Callsign via the Mobile App when we detect anomalous details about your device that suggest it is compromised.
Likewise, post-registration Callsign assesses and decides upon authentication attempts made by users by assessing your behavior and device details. If we assess a deviation from your normal profile, we challenge you for further authentication.
When using the Callsign App, we process data because it is necessary to fulfil a contract with your organization and you should contact your organization regarding any questions about the processing of your personal data in relation to the service.
Please note that beyond the above authentication outcomes may also be augmented by Subscriber Organization policies set in the Callsign Dashboard. These policies - which could include specific blacklisting or location policies - are not defined by Callsign and wholly outside the scope of our automated decision making. For more information on these, please contact your organization.
We may also process your information following an interaction with the Sites such as filling in a form. As a user you have many rights to challenge and object to these automated processes and outcomes. For more information please see Your rights as a data subject or, contact us via the methods outlined in this privacy notice.
Confidentiality is maintained throughout our systems in accordance with the General Data Protection Regulation. This includes encryption of data when stored and in transport.
Our site may, from time to time, contain links to external sites. We are not responsible for the privacy policies or the content of such sites.
We retain personal data for as long as you have an account with us in order to meet our contractual obligations to you and for seven years after that to identify any issues and resolve any legal proceedings. We may also retain aggregate information beyond this time for research purposes and to help us develop and improve the Services. You cannot be identified from aggregate information retained or used for these purposes. Please see 'Why Do We Collect This Information?' for retention periods around marketing communications.
Regarding your personal data, you, the data subject, have the following rights under certain circumstances:
You can exercise the rights listed above at any time by contacting us at dpo@callsign.com.
If you have any questions about this Privacy Notice or the use of your Personal Data, please contact Callsign by sending an email to the following address (indicating “PRIVACY NOTICE REQUEST” in the message line): dpo@callsign.com, or a letter to the below postal address.
Data Protection Officer
Address: Callsign Limited 8th floor, One Bartholomew Close, London, EC1A 7BL
Email:
dpo@callsign.com.
We have also appointed IT Governance Europe Limited to act as our EU representative. If you wish to exercise your rights under the EU General Data Protection Regulation (EU GDPR) or have any queries in relation to your rights or general privacy matters, please email our Representative at eurep@itgovernance.eu. Please ensure to include our company name in any correspondence you send to our Representative.
If you contact Callsign by e-mail or letter, we may keep a record of your correspondence or comments. We may ask for your name, e-mail address and contact information in order to send you a reply.
This Privacy Notice was last changed on 26/04/2022. Callsign may change, modify, add or remove portions of this Privacy Notice at any time, and any updates will be published here and changes will become effective immediately upon being posted unless stated otherwise.