Privacy Policy
Metrix LTD
last updated: 09th June 2026
This Privacy Policy explains how Metrix Ltd (“Metrix”, “we”, “us” or “our”) collects, uses, stores and protects personal data. Metrix Ltd is a company registered in England and Wales, with its registered office at Amelia House, Crescent Road, Worthing, England, BN11 1RL.
We are the “data controller” for the personal data described in this policy, and we process personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. If you have any questions about this policy or how we handle your data, contact us at privacy@metrixanalytics.ai.
1. About Metrix and our services
Metrix Ltd provides analytics software to businesses. This policy covers personal data processed across our products and services, which include:
• Call intelligence (our primary product) — a platform that scores and analyses customer-service calls for quality assurance, processing call recordings and transcripts on behalf of our business customers.
• Reviews dashboard — a platform that consolidates a business customer’s Google reviews and related Business Profile information into a single dashboard, allowing them to monitor review activity, analyse trends and respond to reviews.
Our services are provided to businesses (“business customers”). In delivering these services we may process personal data relating to our business customers’ own staff and end customers. Where we process such data on behalf of a business customer and under their instructions, we act as a “data processor” and the business customer is the “data controller”. Where we determine how and why data is processed (for example, account administration), we act as the data controller.
2. Personal data we collect
2.1 Account and contact data
When you register for or use our services, we collect information such as name, business email address, business name, job role, and login credentials. We use this to create and administer your account, provide support, and communicate with you.
2.2 Call recordings and transcripts (Call intelligence)
In providing our Call intelligence product, we process call recordings and transcripts on behalf of our business customers. These may contain personal data relating to the business’s staff and end customers, including spoken or transcribed personal information. We receive this data in two main ways:
• Directly from third-party call platforms used by our business customers (for example, Elevate). The specific platform varies depending on the systems each customer uses; and
• As recordings that we convert into transcripts using Microsoft Azure.
Data minimisation through redaction: we apply redaction to call recordings and transcripts to minimise the personal data we retain, and we do so as early as possible. In some cases, personal data is redacted at source by the third-party platform before we receive it, so we do not receive the unredacted recording. In other cases, we apply redaction ourselves using Microsoft Azure upon receipt. Where we apply redaction ourselves, the original recording may contain personal data for a limited period during processing; the original recording is stored for no more than 24 hours and is then automatically deleted. Our objective is to ensure personal data is removed or masked at the earliest practicable point and not retained beyond what is necessary to provide the service.
2.3 Google Business Profile data (Reviews dashboard)
Where a business customer connects their Google Business Profile to our Reviews dashboard, we access and process data made available through the Google Business Profile API, including:
• Business location information (such as business name, address, and listing details);
• Reviews and ratings left on the business’s profile, including review text, star ratings, dates, and the reviewer’s public display name and any reviewer information made available by Google;
• Replies to reviews, which we may submit on the business customer’s behalf at their request;
• Account and location identifiers used to retrieve the correct data.
Important: we only access a business’s Google data after the business has explicitly authorised us to do so — either by granting access through Google’s OAuth consent flow, or by adding us as a manager of their Google Business Profile. We request only the access necessary to provide the service (the business.manage scope). A business can withdraw this access at any time through their Google account settings, after which we will no longer be able to access their data.
2.4 Usage and technical data
We collect technical information when you use our services, such as IP address, device and browser type, log data, and information about how you interact with our products. We use this to operate, secure and improve our services.
3. Why we process your data and our lawful bases
Under UK GDPR we must have a lawful basis to process personal data. We rely on the following:
• Contract — to provide our services to business customers under our agreement with them.
• Legitimate interests — to operate, secure, maintain and improve our services, and to communicate with business customers, where these interests are not overridden by individuals’ rights.
• Consent — where required, for example where a business authorises access to its Google Business Profile data. Consent can be withdrawn at any time.
• Legal obligation — to comply with applicable laws and regulatory requirements.
Where we process data on behalf of a business customer as a processor, that business customer is responsible for ensuring an appropriate lawful basis for the underlying processing (for example, for recording calls or collecting reviews).
4. Use of Google user data
Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
• We only use Google Business Profile data to provide and improve the user-facing features of our Reviews dashboard for the authorising business;
• We do not sell Google user data, and we do not use it for advertising;
• We do not transfer Google user data to third parties except as necessary to provide the service, to comply with applicable law, or as part of a merger or acquisition;
• We do not use Google user data for any purpose unrelated to the services the business customer has connected their profile to receive;
• Human access to Google user data is limited to the cases permitted by the policy (for example, with the user’s consent, for security purposes, or as required by law).
5. How we share data and our sub-processors
We do not sell personal data. We share personal data only with service providers (“sub-processors”) that help us deliver our services, and only to the extent necessary. These providers are bound by contractual obligations to protect data and to process it only on our instructions. Our sub-processors include:
• Microsoft Azure — cloud hosting and infrastructure, data storage, and conversion of call recordings into transcripts. Our infrastructure is located in the UK South region.
• Twilio SendGrid — sending transactional and service-related emails.
• Google LLC — Business Profile API, for accessing authorised review and listing data for the Reviews dashboard.
• Third-party call platforms — call platforms used by our business customers (for example, Elevate) from which we receive call recordings and transcripts. The specific platform depends on the systems each customer uses.
• Data providers — where applicable, third-party providers used to retrieve publicly available review information for competitor benchmarking.
We may also disclose personal data where required to comply with a legal obligation, to enforce our agreements, to protect our rights, property or safety, or in connection with a corporate transaction such as a merger or acquisition.
6. How we share data and our sub-processors
We host and store personal data on infrastructure located in the United Kingdom (Microsoft Azure, UK South region). Some of our sub-processors are headquartered outside the UK and may process limited personal data (such as email contact details) outside the UK. Where personal data is transferred outside the UK, we ensure an appropriate safeguard is in place as required by UK data protection law — such as an adequacy decision covering the destination country, or the UK International Data Transfer Agreement or the International Data Transfer Addendum to the EU Standard Contractual Clauses.
7. How long we keep data
We keep personal data only for as long as necessary for the purposes set out in this policy, including to provide our services, comply with legal obligations, resolve disputes and enforce our agreements.
• Call recordings — original recordings that we redact ourselves are stored for no more than 24 hours and are then automatically deleted.
• Transcripts — redacted transcripts are retained only as long as necessary to provide the quality-assurance service to the relevant business customer.
• Review data — retained for the duration of the business customer’s subscription and deleted or anonymised when no longer required.
When a business customer ends its relationship with us, we delete or anonymise associated personal data within a reasonable period, unless we are required to retain it by law.
8. How we protect your data
We implement appropriate technical and organisational measures to protect personal data against unauthorised access, loss, misuse or alteration. These include encryption of data in transit and at rest, access controls limiting who can access data, secure handling of authentication tokens, prompt deletion of original call recordings, and applying redaction to call recordings and transcripts to minimise the personal data we hold. No method of transmission or storage is completely secure, but we work to protect your data using industry-standard practices.
9. Your rights
Under UK GDPR, you have the following rights in relation to your personal data:
• The right to be informed about how your data is used;
• The right of access to your personal data;
• The right to rectification of inaccurate or incomplete data;
• The right to erasure (“the right to be forgotten”) in certain circumstances;
• The right to restrict processing in certain circumstances;
• The right to data portability;
• The right to object to processing based on legitimate interests;
• Rights relating to automated decision-making and profiling.
To exercise any of these rights, contact us at privacy@metrixanalytics.ai. Where we process data on behalf of a business customer as a processor, you may need to direct your request to that business (the controller), and we will assist them in responding. We will respond to valid requests within the timeframes required by law.
If you are not satisfied with how we handle your data, you have the right to lodge a complaint with the UK Information Commissioner’s Office (ICO) at ico.org.uk. We would, however, appreciate the chance to address your concerns before you approach the ICO.
10. Cookies and similar technologies
Our website and products may use cookies and similar technologies to operate the service, remember your preferences, and understand how the service is used. We use strictly necessary cookies to provide core functionality such as keeping you signed in. Where we use any non-essential cookies, we will ask for your consent.
11. Children’s data
Our services are intended for use by businesses and are not directed at children. We do not knowingly collect personal data from children.
12. Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the “Last updated” date at the top of this policy and, where appropriate, notify you. We encourage you to review this policy periodically.
13. Contact us
If you have any questions, concerns or requests regarding this Privacy Policy or your personal data, please contact:
Metrix Ltd
Amelia House, Crescent Road, Worthing, England, BN11 1RL
Email: privacy@metrixinsights.ai
