PickedUp Privacy Policy

    Version 1.2
    Effective Date: 1st January 2026

    This Privacy Policy explains how OpenLabs Engineering ("we", "our", or "us") handles personal data in the PickedUp mobile application and related services (together, the "App"). We are committed to protecting your privacy and handling your personal data in compliance with applicable data protection laws, including the UK General Data Protection Regulation ("UK GDPR") and the Data Protection Act 2018.

    For most data about you as a user of the App (for example, your account and billing/subscription data), we act as a data controller. For data about your callers that we process to provide services to your business (for example, call content and transcripts), we act as a data processor on your documented instructions. You can contact us at ryan@openlabs-eng.com or sam@openlabs-eng.com (or privacy@openlabs-eng.com).

    1. Scope and Roles

    1.1 This Policy applies to personal data we collect and process through the App and related support channels worldwide. It does not cover personal data processed solely by you or other controllers outside of the App.

    1.2 "User" or "you" means the professional or business customer using the App. For data about your callers, you are typically the controller and we act as your processor, as further described in this Policy and any applicable Data Processing Addendum ("DPA").

    2. Personal Data We Collect

    We collect the following categories of personal data. Some of this data is provided directly by you; some is generated by your use of the App or provided by our service providers.

    Account and Profile Data (controller). Your name, email address, authentication details, and the information you provide to create and update your business profile (for example, business name, professional title, industry, biography, services offered and excluded, operating hours, pricing information, follow‑up preferences, and business address).

    Subscription and Billing‑Related Data (controller). Information about your subscription status (for example, active, trial, cancelled), the product or plan purchased, platform identifiers (for example, app store product IDs, purchase tokens, original transaction IDs), and basic billing metadata obtained from app stores or our billing partners. We do not receive or store your full payment card details; those are handled by the relevant store or payment provider.

    Device Contacts (controller). If you grant permission, we access contact names and phone numbers from your device solely to display caller names in your call inbox and to support certain filtering or contact‑linking features. This information is processed locally on your device and is not uploaded to or stored on our servers.

    Device and Notifications Data (controller). Device type and operating system, App version, language, notification preferences, and a unique push token required to send you notifications about new calls and other updates.

    Analytics and Usage Data (controller). Data about how you interact with the App, such as screens viewed, buttons tapped, feature usage, session length, and certain performance/diagnostic information (for example, error codes or network status). We may use internal identifiers or analytics tools to understand usage and improve the App. We avoid including call content in analytics.

    Advertising and Attribution Data (controller). If we promote the App, we may work with advertising and measurement partners to measure the effectiveness of campaigns, attribute installs, sign‑ups, subscriptions, or other conversions, and help prevent fraud.

    Caller and Call Data (processor). Caller phone numbers, call metadata (for example, direction, status, duration, timestamps), AI‑generated summaries and tags (for example, "lead", "urgency", "suspected spam"), transcripts, and—if you enable the feature—call recordings or links to them. This data relates primarily to your callers and is processed on your instructions to provide the App's services to your business.

    Communications Data (controller and processor). Copies of emails or in‑App messages you send to us, metadata about notifications we deliver (for example, whether a push notification was delivered or opened), and content of any transactional SMS messages that we send to callers on your behalf where such content is configured in the App.

    3. Permissions We Request

    Contacts. Used to display caller names and enable contact‑based features. Contacts data is processed on‑device and is not uploaded to our servers. You can revoke this permission in your device settings; contact‑based features may be limited if disabled.

    Notifications. Used to alert you to new calls, call summaries, and relevant service updates. You can change or revoke this permission in your device settings.

    Microphone. The App does not access your device microphone for call recording. Where call recording is enabled, audio is processed via telephony/voice services to provide call handling and playback, rather than through your device microphone.

    4. How We Use Personal Data and Our Lawful Bases

    We use personal data for the following purposes and rely on the legal bases indicated (under UK GDPR and, where applicable, EU GDPR or other local laws):

    Provide and operate the App (controller). We use Account, Device/Notifications, Subscription, and Analytics data to create and manage your account, provide the App's core features (including call inbox, summaries, notifications, and subscription access), and maintain service reliability. Lawful bases: performance of a contract; legitimate interests (to operate and secure our service).

    Process caller interactions for your business (processor). We process Caller and Call Data (including transcripts, summaries, and classifications) on your documented instructions to provide AI‑assisted call handling, call history, and related features. You are responsible for determining the lawful basis for processing your callers' data (for example, legitimate interests, consent, or performance of a contract) and for providing any necessary notices to callers. Lawful basis: determined by you as the controller; we act on your instructions under our DPA.

    Improve reliability, security, and troubleshoot (controller). We use Analytics and limited technical/diagnostic data to monitor performance, detect and remediate issues, prevent misuse or fraud, and improve the App. Lawful basis: legitimate interests (to improve and secure our service).

    Communications with you (controller). We use Account and Device/Notifications data to send service‑related messages (for example, onboarding messages, security alerts, important feature changes, and billing/subscription information). Lawful basis: legitimate interests (service administration; keeping users informed).

    Marketing to you (controller). Where permitted, we may use your Account data to send you optional product updates, tips, or offers about the App. Lawful basis: consent (opt‑in only where required; you can withdraw at any time) and/or legitimate interests in some business‑to‑business contexts, subject to applicable law.

    Advertising, attribution, and measurement (controller). We may use and share limited identifiers and event information to measure the effectiveness of advertising campaigns, attribute installs, sign‑ups, or subscriptions, limit frequency, and help prevent fraud. Lawful bases: consent where required (including where platform rules require opt‑in for tracking); and legitimate interests (to promote and grow our business, measure marketing effectiveness, and prevent fraud), subject to applicable law.

    Compliance and legal obligations (controller). We may process any relevant personal data to comply with our legal obligations (for example, tax, accounting, and regulatory requirements) and to respond to lawful requests from authorities. Lawful basis: compliance with a legal obligation; legitimate interests (establishing, exercising, or defending legal claims).

    Automated classification. We use automated analysis of calls to derive non‑sensitive labels (for example, lead likelihood, urgency, suspected spam) to help you prioritise. We do not make decisions that produce legal or similarly significant effects solely based on automated processing.

    5. Tracking, Advertising, and "Sale/Share"

    5.1 We may work with third‑party advertising, attribution, and measurement partners to promote the App, measure the effectiveness of campaigns, attribute installs, sign‑ups, subscriptions, or other conversions, limit frequency, and help prevent fraud.

    5.2 Depending on your device settings and permissions, we and these partners may collect or receive certain identifiers and information, such as device identifiers (including a device advertising identifier where available), basic device information, IP address, and event information about your interactions with the App (for example, completing registration or initiating a purchase).

    5.3 "Sale" / "Share". We do not sell your personal data for money. However, under some privacy laws, sharing certain identifiers or event information with advertising partners for targeted advertising or measurement may be treated as a "sale" or "sharing". Where applicable, you can control these activities via your device settings (including tracking settings) and you may contact us at contact@openlabs-eng.com.

    6. Who We Share Data With (Categories of Recipients)

    We do not sell your personal data for money. We share it only as described in this Policy, including with carefully selected service providers and partners for the purposes described below. Depending on the context, these third parties may act as processors on our behalf or as independent controllers.

    • Cloud hosting, database, and security providers that host our infrastructure, store account and call data, and help secure the service.
    • Authentication and account management providers that help us manage user accounts and sessions.
    • Telecommunications and messaging providers used for call handling, call routing, and transactional SMS you request us to send to callers.
    • Push notification delivery services that deliver notifications to your device.
    • Analytics and diagnostics services that help us understand usage, app performance, and reliability. We aim to avoid sending call content to these providers.
    • Advertising, attribution, and measurement partners that help us promote the App, measure campaign performance, attribute installs, sign‑ups, or subscriptions, and help prevent fraud. Where required, we enable tracking‑related functionality only with appropriate permission.
    • AI and voice services used to operate the voice agent, generate transcripts, and create summarised information for your business profile and call inbox.
    • Payment, subscription, and billing providers involved in managing in‑App purchases, app‑store subscriptions, and related billing metadata (for example, Apple, Google, and subscription orchestration tools). We do not store your full payment card details.
    • Customer support and operational tools that we use to provide support, respond to enquiries, and run our internal operations.

    We have contracts in place requiring appropriate confidentiality, security, and data‑protection commitments. For Caller and Call Data, where we act as your processor, we may engage subprocessors under a DPA with general written authorisation and will notify you of material subprocessor changes as set out in that agreement. A current list of our core processors is available on request.

    7. International Data Transfers

    Some of our service providers are located outside the United Kingdom, including in the European Economic Area (EEA) and the United States. Where we transfer personal data outside the UK, we ensure appropriate safeguards, such as the UK Addendum to the EU Standard Contractual Clauses, the EU Standard Contractual Clauses themselves, or adequacy regulations/decisions. You can contact us for more information about the safeguards applied to specific transfers.

    8. Data Security

    We employ industry‑standard security measures to protect personal data, including encryption in transit, access controls, and least‑privilege credentials. On your device, authentication data is stored using secure storage mechanisms where available. Within our databases, we use strict access controls to limit data visibility on a need‑to‑know basis, including fine‑grained access controls where appropriate. Notification tokens are associated with your user ID to route notifications correctly. No system can be guaranteed to be completely secure, but we work to protect your data against unauthorised access, use, or disclosure.

    9. Data Retention

    Account and Analytics Data. We retain your account and analytics data for the lifetime of your account and for a period thereafter (typically up to 5 years) where necessary for legal, accounting, or reporting requirements, or to establish or defend legal claims. We will delete or anonymise data earlier where required following verified account deletion, unless further retention is legally necessary.

    Subscription and billing records. We retain subscription and billing‑related records for as long as required by tax, accounting, and financial regulations, and for a period necessary to address disputes or chargebacks.

    Device Contacts. Contacts accessed from your device are processed on‑device only and are not stored by us beyond what is necessary for local functionality.

    Device/Notifications Data. We retain device and notification data while you have notifications enabled or until you sign out or remove the device. We endeavour to remove invalidated push tokens where possible.

    Caller and Call Data (processor). We retain caller and call data in line with your instructions and configuration, for example until you delete calls in the App or close your account. During service iterations we may adjust retention periods to ensure reliability and will notify you of any material changes where required.

    10. Your Rights (Where We Are Controller)

    For personal data where we act as controller (for example, your own account, subscription, and usage data), you have the following rights under UK data protection law, subject to certain conditions and exceptions:

    • Right of access – to obtain confirmation as to whether we process your personal data and to receive a copy of the data.
    • Right to rectification – to have inaccurate personal data corrected and incomplete data completed.
    • Right to erasure – to request deletion of your personal data in certain circumstances.
    • Right to restriction – to request restriction of processing in certain circumstances.
    • Right to data portability – to receive personal data you have provided to us in a structured, commonly used, and machine‑readable format and to transmit it to another controller where technically feasible.
    • Right to object – to object to processing based on legitimate interests and to direct marketing.
    • Rights related to automated decision‑making – to request human intervention and to contest decisions that are based solely on automated processing and which produce legal or similarly significant effects. We do not carry out such profiling for your user account.

    If you are in the EEA or another jurisdiction with similar rights, you may have equivalent rights under local law.

    11. Caller Rights and Controller Responsibilities

    For Caller and Call Data, you (or your business) are typically the controller. Callers who wish to exercise their data protection rights (for example, access, deletion, or objection) should contact you directly as the controller. If a caller contacts us directly, we may inform you and, where appropriate, assist you in responding, in line with our role as your processor and any applicable DPA.

    12. How to Exercise Your Rights

    To exercise your rights in relation to data where we are the controller, please contact us at ryan@openlabs-eng.com or sam@openlabs-eng.com (or privacy@openlabs-eng.com). We may need to verify your identity and the scope of your request before proceeding. We aim to respond within one month (30 days); in complex cases we may extend this by up to two further months and will inform you of any delay.

    13. Account Deletion

    You can delete your account at any time via App → Settings → Account → Delete Account. If you cannot access the App, email privacy@openlabs-eng.com and we will verify your identity and process your deletion request. After account deletion, we will remove or anonymise controller data unless we are required to retain it for legal, regulatory, or security reasons, and we will request that our processors do the same where applicable.

    14. Caller SMS and Communications

    If you configure the App to send automated follow‑up messages, we may send a transactional SMS to the caller on your behalf via our telecommunications/messaging providers. We do not send marketing messages to callers on our own behalf. Any marketing to callers remains your responsibility as the controller; you must ensure you have a lawful basis and provide any legally required notice or consent, including for call recording where applicable.

    15. Children

    The App is not intended for individuals under the age of 16. We do not knowingly collect personal data from children for which we would be the controller. If we become aware that we have collected such data, we will take steps to delete it. If you believe a child has provided us with personal data, please contact us.

    16. Data Sources

    We collect data from: (a) you, when you create and manage your account and business profile; (b) your device, with your permission (for example, contacts, device and notification settings); (c) your use of the App and interactions with features (analytics and diagnostic data); (d) telecommunications, AI, and messaging services during calls (for example, caller numbers, transcripts, metadata); and (e) subscription and billing platforms (for example, app stores and subscription management tools); and (f) advertising and measurement partners where you interact with our marketing or where we measure campaign performance, subject to your device settings and permissions.

    17. Use of AI and Model Training

    We use third‑party AI services to operate the voice agent, generate transcripts, and create summaries and classifications for your business profile and call inbox. We do not use your call content to train our own general‑purpose models. We contractually instruct our AI providers to use your data only to provide the services you have requested and not to train public or broadly‑available models, subject to any specific terms agreed with you.

    18. Changes to This Policy

    We may update this Policy from time to time, for example to reflect changes in law or improvements to the App. We will notify you of significant changes, for example via in‑App messages or email, and update the "Effective Date" at the top. We encourage you to review this Policy periodically.

    19. Contact and Complaints

    If you have questions or concerns about this Policy or our data practices, please contact us at ryan@openlabs-eng.com or sam@openlabs-eng.com (or privacy@openlabs-eng.com).

    You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) in the UK (www.ico.org.uk) or with your local supervisory authority if you are based outside the UK.