Data Processing Addendum
Effective: August 31, 2026
1. Roles
You are the controller of the personal data FieldCue processes for you, and FieldCue is your processor. You decide whose calls are recorded, what is extracted from them, and where the results are sent. FieldCue processes that data only to run the service and only on your documented instructions — which, in practice, are the settings you save and the integrations you connect.
Where a sub-processor is engaged, FieldCue remains responsible to you for its performance.
2. What is processed
- Categories of data subject: your staff who use FieldCue, and the callers and prospects on the calls you process.
- Categories of personal data: names, email addresses, phone numbers, call audio, call transcripts, and whatever else is spoken on a call or configured for extraction.
- Nature and purpose: transcription, summarisation, field extraction, scoring, and synchronisation of the results to your CRM.
- Duration: for as long as your account is open, plus the deletion windows in section 6.
FieldCue does not ask for special-category data. Callers may nonetheless mention health, financial, or other sensitive details on a call, and those words end up in the transcript. Deciding whether that is acceptable for your business is your call as controller, not ours.
3. Consent and call recording
FieldCue processes recordings you already have. It does not make them, and it cannot tell whether the people on a call were told it was being recorded. Obtaining any consent or giving any notice that applicable call-recording law requires is your responsibility as controller, in every jurisdiction you operate in.
4. Security
FieldCue maintains technical and organisational measures appropriate to the risk, described in full on the Security page. In summary: transport encryption for all traffic, AES-256-GCM encryption at rest for OAuth tokens and customer-supplied API keys, salted scrypt password hashing, tenant isolation enforced in the data-access layer, multi-factor authentication, and role-based access within each account.
Personnel with access to customer data are bound by confidentiality obligations, and access is limited to those who need it to operate or support the service.
5. Sub-processors
You give FieldCue general authorisation to engage sub-processors. The current list is published at fieldcue.app/subprocessors, which names each provider, what it handles, and where it processes data. Each is bound by written terms no less protective than this Addendum.
Ask to join the notification list and you will receive 30 days' notice before a new sub-processor begins handling customer data. If you object on reasonable data-protection grounds within that window, you may terminate the affected service and receive a pro-rata refund of prepaid fees.
6. Retention and deletion
- Call audio is downloaded only to be transcribed and is discarded as soon as processing finishes. It is never stored at rest.
- Call records — transcripts, summaries, extracted fields, and scores — are retained for as long as the location they belong to exists, so that they remain visible on your dashboard.
- Expired credentials — password reset links, email verification links, unaccepted invitations, and failed-login counters — are deleted automatically by a daily job once they are past expiry.
- On deletion. Deleting a location removes its call records immediately. Deleting your account removes the account, every location it owns, and all of their call history immediately. Both are irreversible.
- Backups. Deleted data may persist in encrypted database backups until those backups age out on their normal cycle, after which it is gone. It is not restored to the live service in the meantime.
7. Your rights, and your callers' rights
Everything FieldCue holds for your account can be exported at any time from Settings → Your Data as a machine-readable JSON file, and your account can be deleted from the same place. Between the two, you can satisfy most access and erasure requests without contacting us at all.
For anything those controls do not cover — erasing one caller's records while keeping the rest, for instance — email privacy@fieldcue.app and we will assist within 30 days. If a data subject contacts FieldCue directly, we will not respond on your behalf; we will refer them to you.
8. Breach notification
FieldCue will notify you without undue delay, and in any case within 72 hours, of becoming aware of a personal data breach affecting your data. The notice will describe what happened, which data was affected as far as it is known, and what is being done about it, so that you can meet your own notification obligations.
9. International transfers
FieldCue and its sub-processors process data in the United States. Where you are subject to UK or EU data protection law, transfers out of your region are made under the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum where applicable), which are incorporated into this Addendum by reference and take effect on the terms set out in them.
10. California
For the purposes of the CCPA and CPRA, FieldCue is a service provider. FieldCue does not sell or share personal information, does not retain, use, or disclose it for any purpose other than performing the service, and does not combine it with data obtained from anyone else. Personal information is never used to train AI models.
11. Audit
On written request, and no more than once a year, FieldCue will provide the information reasonably necessary to demonstrate compliance with this Addendum, and will respond to a reasonable security questionnaire. Where a formal audit is required by law, the parties will agree its scope in advance so that it does not disrupt the service or expose other customers' data.