Privacy Policy
Last updated: 5 August 2026
[BRACKETED] value below with your
real company details, and have this reviewed by a lawyer in your jurisdiction. This is a
starting template written to match how the product actually behaves — it is not legal advice.
1. Who we are
AI Employee ("we", "us", "the Service") provides an AI assistant that business owners embed on their websites to answer visitor questions, book appointments, and capture enquiries.
The Service is operated by [LEGAL COMPANY NAME], registered at [REGISTERED ADDRESS]. You can reach us at [PRIVACY CONTACT EMAIL].
2. Controller and processor roles
This distinction matters because two different groups of people are involved:
- Business owners (our customers). When you create an account with us, we are the data controller for your account information.
- Website visitors (your customers). When a visitor chats with an AI Employee on a business owner's website, that business owner is the data controller and we act as their data processor. We process visitor data on the owner's instructions and do not use it for our own purposes.
If you are a website visitor and want your conversation or contact details deleted, contact the business you were chatting with. If they ask us, we will action it on their behalf.
3. Information we collect
| Category | Examples | Source |
|---|---|---|
| Account data | Name, email address, hashed password, session token, plan and trial status | Business owner at signup |
| Business knowledge | Opening hours, services, prices, FAQs, custom instructions, uploaded or imported text | Business owner while training the assistant |
| Conversation data | Messages exchanged between a visitor and the assistant, timestamps, session identifier | Website visitor |
| Lead data | Name, phone number, email address, and stated intent a visitor chooses to provide | Website visitor |
| Appointment data | Requested service, date and time, contact details, booking status | Website visitor |
| Usage data | Monthly message counts used to apply plan limits | Generated by the Service |
We do not intentionally collect special category data (such as health, biometric, or financial account information). Please do not train your assistant on it, and configure your assistant not to request it.
Payments
Card details are never sent to or stored on our servers. Payments are handled by our payment provider, [PAYMENT PROVIDER], under their own privacy policy.
4. How we use information
- To operate the assistant and generate replies from the knowledge an owner has provided.
- To capture leads and appointments and show them to the business owner.
- To authenticate owners and keep accounts secure.
- To apply plan limits and process subscriptions.
- To diagnose faults and improve reliability.
- To send service messages about your account.
We do not sell personal data, and we do not use your business knowledge or your visitors' conversations to train foundation models for anyone else.
5. Legal bases for processing
Where UK/EU data protection law applies, we rely on:
- Contract — to provide the Service you signed up for.
- Legitimate interests — to keep the Service secure, prevent abuse, and improve it.
- Consent — where you opt in to non-essential communications.
- Legal obligation — where we must retain records by law.
7. Data retention
- Account data — kept while your account is active, then deleted within [30] days of closure.
- Conversations, leads, and appointments — retained until the business owner deletes them or closes the account.
- Business knowledge — retained until you change or delete it.
- Billing records — retained as long as tax and accounting law requires.
8. Your rights
Depending on where you live, you may have the right to:
- Access the personal data we hold about you.
- Correct inaccurate data.
- Delete your data ("right to erasure").
- Export your data in a portable format.
- Object to or restrict certain processing.
- Withdraw consent at any time.
- Complain to your data protection authority.
To exercise any of these, email [PRIVACY CONTACT EMAIL]. We respond within [30] days. We may ask you to verify your identity first.
9. Security
Passwords are stored using a one-way hash, never in plain text. Sessions use random tokens. Traffic is served over HTTPS in production, and API credentials are held in server-side environment variables that are never exposed to the browser. See our Security page for detail.
No system is perfectly secure. If we become aware of a breach affecting your personal data, we will notify affected users and the relevant authority as required by law.
10. Children
The Service is intended for businesses and is not directed at children under 16. We do not knowingly collect their data. If you believe a child has provided us personal data, contact us and we will delete it.
11. Changes to this policy
We may update this policy as the Service evolves. We will change the "last updated" date above, and for material changes we will notify account holders by email before the change takes effect.
12. Contact us
Questions about this policy or your data:
[LEGAL COMPANY NAME]
[REGISTERED ADDRESS]
[PRIVACY CONTACT EMAIL]