Test preview — sample data and pricing. No real bookings or payments.

Data handling and controls

What it may do, where it stops, and what is still unanswered.

This page is written to be checkable. Where something is settled, it says what it is. Where it is not, it says so in that exact place and names who has to settle it — rather than filling the gap with a reassuring sentence.

Two labels are used throughout. Confirmed means the product behaves this way today and we will be held to it. Pending legal confirmation means the slot is genuinely empty. There is a register of every pending item at the foot of the page, with the owner for each one.

What the agent is allowed to do

It has no implicit permissions. Every action it can take is one you defined during setup, and the list is finite by design rather than by accident.

Inside the boundary

  • Answer an inbound call on a number you control, and end it.
  • Hold a conversation about the requests your workflow covers.
  • Collect the specific details that workflow needs — and only those.
  • Read back what it has understood, and wait for an explicit confirmation before writing anything.
  • Write, amend or cancel a record, where the connection permitting that has been verified for your deployment.
  • Prepare and send follow-up email to the caller or to a staff address.
  • Record a note in the caller’s own words and attach it to the record.
  • Raise a follow-up or callback request for a person.

Confirmed for the conversation, the capture and the email follow-up. Writing into a third-party record depends on that connection’s status — check it before you rely on it.

Outside the boundary, permanently

  • Diagnosing a fault, a condition or a cause of any kind.
  • Quoting a price, a range or a “usually about”.
  • Estimating how long work will take.
  • Giving safety advice, including by implication.
  • Confirming an outcome a connected system has not confirmed back.
  • Taking an action you have not configured, as a fallback or a retry.
  • Collecting payment details, or card or bank information.
  • Continuing after the caller has asked for a person.

Confirmed These are design limits, not configuration options. You cannot switch them off and neither can we.

Controls and escalation

Two halves: the points at which the agent stops and gives the call to a person, and the settings you hold rather than we do.

When it hands a call to a person

Escalation triggers and what the caller experiences. Every one of these is recorded in the record of what Marlin did.
TriggerWhat happensStatus
The caller asks for a person The agent stops trying to handle the request and routes it. Available at any point in the call, with no qualifying question first. Confirmed
The request falls outside the workflow It becomes a staff follow-up carrying what the caller said, rather than a guess at what they meant. Confirmed
The request needs judgement the agent may not exercise A diagnosis, a price, a duration or safety advice. The agent says it cannot answer, says why, and offers the escalation path instead. Confirmed
A write is not confirmed back The record of what Marlin did records an not confirmed and asks for the record to be checked. No silent retry, and no completion state the system has not confirmed. Confirmed
The caller is distressed, abusive, or reports an emergency The call is escalated rather than continued. The agent does not attempt de-escalation, triage or advice of any kind. Confirmed
Where the escalation actually goes A live transfer, a callback queue, or a message to a staff channel — this is the part that is not settled. See the slot below. Pending confirmation

Pending confirmation Owner: Founder / product, with Engineering

Handoff destination — is there a real one?

This slot is empty on purpose. Live transfer to a person is listed as Planned on integrations, which means no transfer destination exists yet. Until that changes, escalation on both industry pages is described as a callback request — a request for a person to call back, never a completed transfer and never a confirmed appointment. When a destination is confirmed, the specifics belong here.

What the business can configure

Settings you hold, not us

  • Which requests the agent handles — and therefore which ones become a staff follow-up instead.
  • Which details it must collect before a request counts as complete.
  • Which actions it may perform per connected system, chosen from that connection’s published list of permitted operations.
  • Its limits — the restaurant party-size ceiling, the authorised list of service types, and anything else your workflow caps.
  • Its wording, including how it identifies the business and how it declines something.
  • Where escalations go, once a destination exists to send them to.
  • Which staff addresses and channels receive follow-ups and unknown-outcome alerts.
  • Hours of operation. Set per deployment. This site makes no 24/7 or always-on claim, because none has been established.

Supported languages are not a configuration option today: the product ships in one language and this site makes no language claim. Pending confirmation

What is logged, and who can see it

The record of what Marlin did is the point of the product, so it is worth being precise about what it contains. A log that cannot be inspected is not a control.

What a call produces, and the current position on who can see it.
What a call producesWhat it containsWho can see it
What Marlin did Every operation attempted, its arguments, its outcome, and an event identifier for each completed action. A timeout appears as an not confirmed, never as a completion. The business, for its own calls. Confirmed
Transcript The text of what was said by both sides, including the point at which the agent declined something or escalated. The business, for its own calls. Confirmed
Call audio The recording of the conversation, where recording is enabled for that deployment. Not settled — see the retention and access slots below. Pending legal confirmation
The record itself The reservation, service request, note or follow-up written into your system, with its reference and revision. Whoever your own system’s permissions allow. It is your record, in your system. Confirmed
Operational diagnostics Error traces and connection failures, used to work out why something did not complete. Scope of internal access not yet defined. Pending legal confirmation

Note what is not in this table: no satisfaction score, no accuracy rating and no containment metric. None of those have been measured, and an unmeasured figure in a log view would be read as a fact.

Data handling — what is not yet written

Four slots. Every one of them is a real question a customer will ask, and not one of them is answered by a sentence we made up. They are reproduced in the register at the foot of this page.

Pending legal confirmation Owner: Legal / DPO, with Engineering

Retention period for call audio and transcripts

How long call audio is kept, how long transcripts are kept, whether the two differ, and whether either can be shortened or switched off per deployment. No retention period is stated anywhere on this site, and no deletion schedule is implied. We are also not claiming that audio is never stored: that would be a convenient sentence rather than a true one, and we do not know it to be true.

This slot gates the live demo. A microphone permission request without a real retention statement should not ship, so the demo’s permission dialog carries the same empty slot.

Pending legal confirmation Owner: Legal / DPO

Sub-processors

Which third parties process call audio, transcripts or the contents of a record on our behalf, what each one does, and where it does it. Speech processing, model inference, telephony carriage and any automation connector in the path all belong on that list. No sub-processor list is published yet, and until it is, this page will not say “your data stays with us”.

A published list will name each sub-processor, its purpose and its processing location, and will state how changes to it are notified.

Pending legal confirmation Owner: Legal / DPO

Legal entity, registered address and data-controller identity

The name of the company you would actually be contracting with, its registered address, which party is controller and which is processor for each category of data above, and the jurisdiction and privacy regime that governs it. None of these are confirmed, which is why the footer of every page on this site says so rather than showing a company name.

The launch market is also unset, and it determines the applicable regime. Until both are fixed, no compliance statement on this page could be accurate.

None held Owner: Legal / DPO

Certifications and audits

Call Marlin holds no certifications and has completed no third-party audits. There are no badges on this page because there is nothing to put on one. If you need a certified supplier today, we are not one, and it is better that you learn that here than in a procurement questionnaire.

Any certification published later will appear with its scope and its validity dates, not as a logo on its own.

How to ask for a deletion

Any request to delete, export or correct data from a Call Marlin call can be made in two ways, and neither of them requires an account, because there are no accounts.

If you are the business

Ask through your pilot contact, or send the request form and then reply to the email you get back with the detail — the call reference or date range, and what you want done. The form itself asks for six fields and has no free-text box on purpose, so nothing identifying a caller ever goes into a web form. We will confirm what was deleted, from which stores, and what remained, because a deletion you cannot verify is not a deletion.

If you were a caller

Contact the business you called first. They hold the record and, for the contents of that record, they are the party you have a relationship with. If you cannot reach them, or the request concerns the call audio or transcript rather than the booking, send the form and reply to our email with the specifics.

Open the request form

Pending legal confirmation Owner: Legal / DPO

Named contact, response window and escalation route

A published privacy contact address, the response time we commit to, the identity checks applied to a request, and where you can escalate if we get it wrong. All four are unset. The form above is a working route today, but it is a general intake rather than a published data-protection contact, and this page will not describe it as one.

The response window in particular has to be a commitment, not an aspiration, so it waits for the entity and the regime to be fixed.

Register of unconfirmed items

Seven items. Each appears in context above and again here, so nothing is only findable by scrolling. Nothing on this list is invented in the meantime.

Every unconfirmed item on this page, where it appears, and who signs it off.
ItemWhere it appearsSign-off ownerStatus
Retention period for call audio and transcripts Data handling, and the demo’s microphone permission dialog Legal / DPO, with Engineering Pending
Sub-processor list Data handling Legal / DPO Pending
Legal entity, registered address, controller identity, governing regime Data handling, the footer, privacy, terms Legal / DPO Pending
Certifications and audits Data handling Legal / DPO None held
Privacy contact, response window and escalation route Deletion requests Legal / DPO Pending
Handoff destination — live transfer, callback queue, or neither Controls and escalation, both industry pages, integrations Founder / product, with Engineering Pending
Internal access scope for audio and operational diagnostics What is logged Legal / DPO, with Engineering Pending

If one of these is a blocker for you, say so in your pilot request. It will not be quietly resolved in our favour, and we would rather know it is a blocker before you have spent time on a scope.

Ask us the question this page has not answered.

If a pending item above decides whether you could use this at all, put it in your pilot request. You will get the current position, including when the current position is still “we do not know”.

A submitted request is a request, not a booked meeting. We reply with next steps and confirm a time with you.