Regions & compliance
HeyMello is built for businesses globally, with local numbers, currencies, and data practices in mind. We started with the UK and India — where billing, numbering, and compliance are most deeply supported — and serve many other countries alongside them. This page summarizes how HeyMello handles your data and what you’re responsible for when running voice agents.
This page is general guidance, not legal advice. You’re responsible for how you use HeyMello. Consult your own legal/compliance team for your specific situation.
Regions we serve
| United Kingdom | India | Other countries | |
|---|---|---|---|
| Phone numbers | Local +44 numbers | Local +91 numbers | Available via Twilio and other telephony providers |
| Currency & payments | GBP via Stripe | INR via Razorpay | Stripe (multi-currency) |
| Language | English (UK) + 30 more | English (India), Hindi + 30 more | Full 30+ language catalog |
Numbers from many other countries can be provisioned the same way — see Phone numbers. If your region isn’t listed in the dashboard yet, talk to your account team.
How your data is protected
- Isolation. Your data belongs to your organization and is never shared with other customers.
- Secure recordings. Call recordings are stored securely.
- Access control. Roles limit who can see and do what, and MFA protects sign-ins.
- Audit trail. Sensitive actions and call events are logged.
Data retention
- Call transcripts are retained for a limited period (by default around 90 days) and then removed.
- Login history is retained for a limited period and then removed.
If your organization has specific retention requirements, talk to your account team.
Your privacy rights (GDPR & similar)
HeyMello supports individual data rights:
- Data export — a user can download all the personal data held about them.
- Erasure — a user can request that their personal data be anonymized/removed, while anonymized records are kept only where needed for audit integrity.
Your responsibilities when calling customers
Running outbound calls and campaigns comes with legal obligations. At a minimum:
- Consent. Only call people who have agreed to be contacted.
- Identify yourself. Have your agent state who is calling and why at the start.
- Respect calling hours. Keep to reasonable local hours for the country you’re calling — every market has its own norms and rules.
- Honor opt-outs. Give people a clear way to opt out, and stop calling them.
- Disclosure. Depending on your jurisdiction and use case, you may need to disclose that the caller is speaking with an AI assistant.
- Recording notice. Where required, inform callers that the call is recorded.
UK-specific
Be mindful of UK GDPR, PECR (rules on marketing calls), and the TPS/CTPS do-not-call registers.
India-specific
Be mindful of India’s DPDP Act and TRAI telemarketing/UCC regulations.
Other countries
Calling rules vary widely — EU/EEA (GDPR and national marketing rules), US (TCPA and state do-not-call lists), Canada (CASL/CRTC), Australia (Do Not Call Register), and others. Check the requirements for each country you dial into before launching a campaign.
Security best practices for your team
- Turn on MFA for every user.
- Use least-privilege roles — not everyone needs Admin.
- Review login history periodically.
- Keep API credentials secret and rotate them if exposed.
Next: FAQ →