Security & Trust

TJP365 Ltd t/a RingDesk  -  How we protect your calls, messages and account data

Security you can build a phone line on

RingDesk answers real calls and messages for real businesses, so security is not a bolt-on - it is built into how the platform stores, isolates and deletes your data. This page sets out the technical and organisational measures we use to keep your callers' information safe, and the providers we rely on to deliver the service.

RingDesk is built on infrastructure operated by SOC 2-certified providers such as Supabase, Amazon Web Services and Stripe. RingDesk itself does not hold ISO 27001, SOC 2 or PCI certification - we are transparent about the difference between our own posture and the certified infrastructure underneath us.

Encryption

  • All data in transit is encrypted with TLS 1.2 or higher.
  • Call recordings, transcripts and messages are stored encrypted at rest.

Access control & isolation

  • Access to the platform requires an authenticated login.
  • Row-level security isolates each account so it can only ever see its own data - one customer can never reach another customer's calls, messages or settings.
  • Access to personal data by staff and contractors is subject to confidentiality obligations.

Where your data lives

Our infrastructure is hosted within the UK/EEA on SOC 2-certified providers. Where individual sub-processors are located outside the UK, those international transfers are covered by the UK IDTA (International Data Transfer Agreement) or UK adequacy regulations - see the sub-processor table below.

Data retention & minimisation

We hold your data no longer than we need to. Deletion is automatic and time-based, enforced by a daily process rather than left to manual clean-up:

  • Call recordings, transcripts and messages are deleted after 90 days. Recording retention is configurable at account level.
  • Account configuration is deleted 7 days after an account is closed.
  • Billing records are kept only for the legally required period.

Your data, your control

For calls and messages handled on your behalf, you are the Data Controller and RingDesk acts as your Data Processor. That relationship is governed by our published Data Processing Agreement (DPA), which sets out our obligations, the sub-processors we use, and how we support you in meeting your own data protection duties.

Sub-processors

We use the following third-party sub-processors to deliver the service. International transfers are covered by the UK IDTA or UK adequacy regulations.

ProviderPurposeLocation
TwilioTelephony & SMS routingUSA
DeepgramSpeech-to-textEU (Ireland)
AnthropicAI language modelUSA
Amazon Web Services (Bedrock)Model hostingEU (Ireland)
CartesiaText-to-speechUSA
SupabaseDatabase & authEU (West Europe)
StripePayments (RingDesk does not store card numbers)USA
NetlifyDashboard hostingUSA
ResendTransactional emailUSA

Breach notification

In the event of a personal data breach, we notify affected account holders and, where required, the Information Commissioner's Office (ICO) within 72 hours of becoming aware.

AI transparency

Callers are told they are speaking with an AI assistant. A transparency notice is played before the greeting, so no caller is ever misled about who - or what - they are talking to.

Cookies

The RingDesk admin app uses session cookies for authentication only. There are no third-party tracking or advertising cookies. See our Cookie policy for detail.

Questions?

Security and privacy enquiries are welcome. Email us at privacy@ringdesk.co.uk and we will get back to you. For the full detail on how we handle personal data, see our Privacy policy and Data Processing Agreement.