Privacy Policy
This Privacy Policy explains how VOICE BOT AI LTD (“we”, “our”, or “us”) collects, uses, stores, and protects personal data when you interact with our website (https://voicebot-ai.com) and use our AI chatbot services.
We are committed to handling your data responsibly and in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
Who We Are
VOICE BOT AI LTD is a company registered in the United Kingdom, providing AI chatbot solutions to businesses. We act as a data controller when we collect personal data via our website or for providing our services directly.
Information We Collect
We may collect and process the following types of data:
- Your name, email address, and contact details when you communicate with us or request a demo.
- Chat content submitted through our platform (where applicable).
- Technical and automatic data such as IP address, device type, browser type, and usage patterns via cookies and analytics tools.
- Business information if you become a client or contact us in a commercial capacity.
How We Use Your Information
We use your personal data to:
- Provide and operate out chatbot services.
- Respond to enquires and support requests.
- Improve the performance and functionality of our AI Tools.
- Maintain business communication
- Comply with applicable legal obligation
Purpose & Legal Basis
We use this data to:
- Provide, maintain, and enhance chatbot services.
- Support client integrations, customizations, and inquiries.
- Comply with legal obligations and meet contractual obligations.
We use this data to:
- Contractual necessity
- Legitimate interests
- Consent, where required
Integrations with Other Platforms
If our AI chatbot is integrated into third-party platforms (e.g., WhatsApp, Messenger, custom APIs) at your request, you (the client) are responsible for ensuring compliance with those platforms’ requirements:
- You are responsible for ensuring your integration complies with any applicable data protection requirements of those platforms.
- We process data solely as necessary to support the requested integration.
- We are not responsible for the privacy practices, data handling, or security measures of third-party platforms.
We act only under your instructions—consistent with the setup of other providers— and disclaim liability for third-party platform breaches.
Legal Basis for Processing
We process personal data on one or more of the following lawful grounds:
- Consent – where you provide it (e.g. when subscribing to updates)
- Contract – to fulfil a service or demo request
- Legitimate interests – to run, grow, and secure our business
- Legal obligation – if required by UK law or regulation
Data Sharing
We may share data with trusted third-party service providers who help us deliver our services (e.g., hosting, analytics, communication tools), all of whom are subject to data processing agreements.
We do not sell or rent your personal data to third parties.
Security and Limitation of Liability
We implement appropriate technical and organisational measures to protect your personal data from unauthorised access or disclosure.
However, no system is completely secure. Therefore:
- VOICE BOT AI LTD does not accept liability for any loss, damage, or disclosure of data caused by hacking, unauthorised access, or third-party breaches outside our control.
- By using our services, you accept this limitation.
Your Rights Under UK GDPR
You have the right to:
- Access your personal data
- Correct inaccuracies in your data
- Request deletion of your data
- Object to or restrict processing in certain situations
- Withdraw consent at any time (where applicable)
To exercise any of these rights, please email us at: info@voicebot-ai.com
Cookies and Tracking
Our website may use cookies or tracking technologies for essential functionality and basic analytics.
You can manage or disable cookies through your browser settings.
Limitations & Liability
Although we implement security measures, we disclaim liability for unauthorized access or breaches—especially via third-party platforms you choose to integrate
Changes to This Privacy Policy
We may update this policy from time to time. Any changes will be reflected on this page with a revised effective date.
VOICE BOT AI LTD
Registered in the United Kingdom Website:
Internal GDPR Compliance Guidelines
For: VOICE BOT AI LTD
Purpose: To ensure all internal processes and operations comply with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018
Overview
These internal guidelines are designed to help VOICE BOT AI LTD manage and protect personal data handled during the provision of AI chatbot services. All team members, contractors, or partners must follow these policies when processing personal data.
Key Definitions
Personal Data: Any information that identifies an individual (e.g. name, email, IP address, chatbot conversation
Data Controller: The entity that determines the purpose and means of processing (VOICE BOT AI LTD)
Data Processor: A third party processing data on behalf of the controller
Data Subject: The individual whose personal data is being processed
Lawful Basis for Processing
All personal data must be processed under at least one of the six legal bases under UK GDPR. The most relevant for our business are:
- Contractual necessity (e.g. delivering chatbot services to clients)
- Legitimate interest (e.g. analytics for improvement)
- Consent (e.g. newsletter subscriptions)
Team members should always confirm the correct basis before collecting or using data.
Data Types and Sources
- (Type of Data) Client contact info – (Sources) Contact forms, email – (Usage Purpose) Onboarding, communication
- (Type of Data) Chat interactions – (Sources) Embedded chatbot or integrations – (Usage Purpose) To deliver chatbot functionality
- (Type of Data) IP and usage data – (Sources) Website and platform logs – (Usage Purpose) Analytics and service improvement
Data Security Requirements
We implement the following to protect all personal data:
- Encryption: All data in transit must use SSL/TLS
- Access Control: Only authorised staff/developers can access client or user data
- Cloud Storage: Any data hosted on third-party platforms (e.g. AWS, DigitalOcean) must follow UK GDPR-compliant practices
- Audit Logs: Maintain access logs for sensitive client integrations
💡 We do not store or process sensitive data (e.g. health, racial, biometric data) and actively avoid collecting such categories.
Data Sharing & Processors
We only use trusted, GDPR-compliant sub-processors. Current examples may include:
- Cloud hosting (e.g., AWS, Google Cloud, Hetzner)
- Communication tools (e.g., email or ticketing software)
- Analytics platforms (e.g., Matomo, Plausible, or GDPR-friendly Google Analytics setup)
A Data Processing Agreement (DPA) must be in place before onboarding any new service provider.
Data Retention
Data retention policies must be:
- Minimalist: Only store what is needed
- Justified: For contract, legal, or client request reasons
- Reviewable: Periodically assess and delete non-essential data
We do not set fixed timeframes for deletion in public policies, but we ensure regular reviews internally.
Data Subject Rights Process
If a data subject (e.g. chatbot user or client) makes a GDPR rights request:
- Acknowledge the request within 72 hours
- Fulfill access/rectification/deletion within 30 days
- Document all steps and confirmations
- Escalate any complex or unclear requests to senior staff
Breach Response Plan
In case of a suspected breach:
- Identify and isolate the affected system
- Notify internal team and developer(s) immediately
- Log the incident and determine if personal data was exposed
- If risk is significant, notify the ICO within 72 hours
- Notify affected users or clients if required
- Document the cause, resolution, and prevention measures
Staff Responsibilities
All staff (including freelancers/contractors) must:
- Complete basic GDPR awareness training (online or internal)
- Follow secure coding and data access practices
- Use secure passwords and 2FA for all systems
- Report any suspicious activity or data mishandling immediately
Annual Review
These guidelines must be reviewed at least once per year or sooner if:
- UK GDPR rules change
- New tools or integrations are adopted
- We expand into new markets or data types
Summary for VOICE BOT AI LTD
✅ Client & user data – Covered by internal and external policies
✅ Integrations – Client-controlled, disclaimers included
✅ Legal basis – Mostly contractual, some consent
⚠️ ICO registration – May be required depending on volumes – check
✅ Data exports – We limit exports; client consent needed
✅ Sub-processors – Must be GDPR-compliant with DPAs
VOICE BOT AI LTD
Registered in the United Kingdom Website:
