Privacy Policy

Agents4You — AI Receptionist & Automation Platform

Effective Date: March 2026

1. Introduction

This Privacy Policy explains how Agents4You ('we', 'our', or 'us') collects, uses, stores, and protects personal information in connection with our AI receptionist and business automation platform.

We are committed to complying with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. We collect only what we need, we are transparent about how we use it, and we respect your rights at all times.

2. Who We Are

The data controller responsible for your personal information is:

ItemDetail
Legal entityAgents4You Ltd (to be registered in England and Wales)
Trading nameAgents4You
Contactprivacy@agents4you.co.uk
Websiteagents4you.co.uk

3. What Information We Collect

3.1 Information You Give Us (Business Clients)

When you create an account or use our platform, we collect:

  • Name and email address
  • Business name, phone number, and website
  • Business configuration — opening hours, services, FAQs, voice preferences
  • Password (stored as an encrypted hash — never in plain text)

3.2 Call Data — Collected on Behalf of Our Clients

Our AI receptionist answers calls on behalf of our business clients. When a call is handled, the following data may be collected from the caller:

Data TypePurposeAlways Collected?
Caller phone numberCall routing and callback capabilityYes
Call timestamp and durationService delivery, billing, usage reportingYes
Call transcript (text)Service quality, AI improvement, client dashboardYes — see retention below
Caller nameBooking and appointment managementOnly when caller provides it
Appointment detailsBooking confirmation and calendar syncOnly when applicable
AddressRequired for trades services (e.g. painter quoting a job)Only when client configures it
Additional custom fieldsConfigured per client (e.g. vehicle registration for garages)Only when client configures it

Important — Variable Data Collection

The data collected during a call depends on how each business client has configured their AI receptionist. Each client (the business you are calling) is the data controller for their customers' data. They are responsible for ensuring they have a lawful reason to collect it. If you have questions about data collected during a specific call, please contact the business you called directly.

3.3 What We Do NOT Collect

  • Call audio recordings — we do not store audio files. Voice is processed in real time and not retained.
  • Payment card numbers — these are processed directly by Stripe and never stored by us.
  • Sensitive personal data — we do not permit collection of health information, government ID numbers, financial account details, or data relating to children through our platform.

3.4 Technical Data

  • IP address and browser type — collected by our hosting infrastructure when you visit our website
  • Session cookies — essential authentication cookies only (see Section 9)
  • Usage statistics — call counts, minutes used, plan usage

4. Legal Basis for Processing

Legal BasisWhat We Use It For
Contract Performance (Art. 6(1)(b))Providing the AI receptionist service, processing bookings, sending account notifications
Legitimate Interest (Art. 6(1)(f))Service improvement, fraud prevention, security monitoring, AI quality improvement
Legal Obligation (Art. 6(1)(c))Retaining financial records as required by UK tax law (7 years)

5. How We Use Your Information

  • To provide and operate the AI receptionist service
  • To process appointment bookings and handle caller enquiries on behalf of our clients
  • To send transactional emails — booking confirmations, account alerts, usage notifications
  • To process subscription payments via Stripe
  • To provide customer support — including AI-assisted responses to support queries
  • To improve our AI models and service quality
  • To detect and prevent fraud or abuse
  • To comply with legal obligations

AI-Powered Voice Calls and Customer Support

We use Anthropic's Claude AI as the primary intelligence powering live voice call conversations. When a caller speaks to your AI receptionist, their speech is transcribed to text by Google Cloud, and that text is processed by Claude to generate a response. No audio is ever sent to Anthropic — only transcribed text. Claude is also used to assist with customer support enquiries. Escalations involving complex issues are handled by a human.

6. Third-Party Data Processors

We share data only with the following processors, all of whom are contractually bound (or in the process of executing data processing agreements) to protect your data and process it only according to our instructions.

ProviderPurposeData SharedLocationAgreement
TwilioPhone number provisioning and call routingCaller phone numbers, call timestamps, duration. Twilio retains call detail records on their own infrastructure subject to their retention policy and telecommunications regulations.Ireland (EU)Automatic with Terms of Service
StripeSubscription billing and payment processingName, email, billing details. Stripe retains payment and billing data as required by financial regulations, typically for 7+ years.EU / UKAutomatic with Terms of Service
SendGridTransactional email deliveryEmail addresses, email content. SendGrid retains email delivery logs on their own infrastructure subject to their retention policy.USAStandard contractual clauses
AnthropicAI language model — powers voice call conversations and customer supportCall transcript text (transcribed speech), system prompts, tool call arguments. No audio is sent to Anthropic — text only.USADirect agreement — DPA with UK IDTA
Google CloudSpeech-to-text and text-to-speech — converts caller audio to text and AI responses to speechCaller audio (real-time streaming, zero retention), AI response text (real-time, not stored)EU (EEA processing via Twilio IE1 region)Google Cloud DPA
ElevenLabsText-to-speech — premium voice synthesis (available for select voice configurations)AI response text (real-time, converted to speech)EEA processing not yet confirmedDPA available — EEA processing pending confirmation
Amazon Web Services (Polly)Text-to-speech — voice synthesis for select voice configurationsAI response text (real-time, converted to speech)EU (via Twilio ConversationRelay)Covered under Twilio DPA (sub-processor)
HostingerServer and database hostingAll platform data stored in our databaseEU (Paris, France)Data Processing Agreement
IONOSDomain hosting and inbound emailInbound email content to our support addressesEU (Germany)EU-based, GDPR compliant
VercelWebsite frontend hosting and deliveryVisitor IP addresses, web request dataUSAStandard contractual clauses
Google / MicrosoftCalendar integration (optional — only if you connect your calendar)Calendar event data for booking sync only. Calendar events created during your subscription remain in your calendar account unless you remove them directly.USAVia customer OAuth authorisation

What happens to third-party data when you delete your account?

When you delete your account, we immediately delete all your data from our own systems. We also take reasonable steps to notify our sub-processors who hold copies of your data, as required by Article 17(2) UK GDPR. For services where we have a deletion API (such as Stripe), we will request deletion on your behalf. You may also contact any sub-processor directly to exercise your rights under their respective privacy policies.

7. Data Retention

Data TypeRetention PeriodReason
Account data (name, email, business info)Duration of subscription + 30 days after cancellationService delivery
Call transcriptsMaximum 30 days from date of callService quality and AI improvement only — removed automatically thereafter
Call metadata with caller details (phone number, transcript, summary)30 daysCallback capability and service quality — personal details removed automatically thereafter
Anonymised call statistics (date, duration, status)Retained indefinitelyBilling, usage reporting, aggregate service quality — no personal data retained
Booking details (appointment, service, contact)30 days after appointment dateService delivery and dispute resolution
Financial records7 yearsUK tax law requirement — non-negotiable
Support correspondence12 monthsCustomer service and dispute resolution

After the retention period expires, personal details such as caller phone numbers, transcripts, and summaries are automatically removed. The remaining anonymised data — including call date, duration, and status — cannot be used to identify any individual and is retained for service improvement and aggregate reporting.

Your Right to Earlier Deletion

You can request deletion of your data at any time by using the account deletion feature or contacting privacy@agents4you.co.uk. Financial records required by law will be retained for 7 years regardless of deletion requests.

8. Your Rights Under UK GDPR

RightWhat It MeansHow to Exercise It
Access (Art. 15)Request a copy of all personal data we hold about youUse 'Download My Data' in account settings or email privacy@agents4you.co.uk
Rectification (Art. 16)Correct inaccurate dataUpdate via account settings or contact us
Erasure (Art. 17)Request deletion of your dataUse 'Delete Account' in settings or contact us
Data Portability (Art. 20)Receive your data in machine-readable formatUse 'Download My Data' in account settings
Object (Art. 21)Object to processing based on legitimate interestContact privacy@agents4you.co.uk
Restriction (Art. 18)Request we limit how we use your dataContact privacy@agents4you.co.uk
Lodge a ComplaintComplain to the ICO if you believe we have mishandled your dataico.org.uk — the UK's data protection regulator

9. Cookies

We use only essential cookies necessary for the service to function:

  • Authentication cookie — keeps you logged in during your session
  • Security cookie (CSRF token) — protects against cross-site request forgery attacks

We do NOT use tracking cookies, advertising cookies, analytics cookies, or any third-party cookies. No cookie consent banner is required as only essential cookies are used.

10. International Data Transfers

Some of our service providers are located outside the UK. Where data is transferred internationally, we ensure it is protected by one or more of the following:

  • Standard Contractual Clauses (SCCs) approved by the ICO
  • The provider's own adequacy certification or compliance framework
  • EU-based hosting where applicable (Twilio: Ireland, Hostinger: France, IONOS: Germany)

11. Data Security

  • All data transmitted over HTTPS (SSL/TLS encryption)
  • Passwords encrypted using bcrypt — never stored in plain text
  • OAuth tokens (calendar integrations) encrypted using PGP before storage
  • Database access restricted by firewall
  • Rate limiting on authentication endpoints
  • Webhook replay protection for payment processing

12. Children's Privacy

Our service is not intended for and does not knowingly collect data from children under 18. If you believe we have inadvertently collected data from a child, contact privacy@agents4you.co.uk immediately.

13. Changes to This Policy

We will notify you of material changes by email at least 30 days before they take effect. Continued use of the service constitutes acceptance of the updated policy.

14. Contact

Email: privacy@agents4you.co.uk

Data Controller: Agents4You Ltd, trading as Agents4You