This policy explains how [Legal entity name] (“ParlioTec”, “we”) collects and uses personal data. We are registered with the Information Commissioner’s Office (ICO) under reference [ICO reference]. Contact: [[email protected]], [registered office address].
1. Who this policy covers
- Website visitors — people using parliotec.co.uk, including the “Hear it live” demo and the contact form.
- Customers and their team members — people who create or use a ParlioTec account.
- Callers and contacts of our customers — people who phone, message or chat with a business that uses ParlioTec. For this data the business is the controller and we are the processor; their privacy notice applies, and section 7 explains how we handle it on their behalf.
2. Data we collect as controller
| Context | Data | Purpose & lawful basis |
|---|---|---|
| Website | IP address, browser and device information, pages viewed (server logs; analytics only if you accept cookies) | Run and secure the site; legitimate interests. Analytics with consent. |
| Contact form | Name, email, company, phone, your message | Reply to your enquiry; legitimate interests / steps prior to a contract. |
| “Hear it live” demo | Your voice during the demo call, a transcript, an anonymous visitor identifier, IP address, any name you type | Provide the demo, prevent abuse (rate limits), improve the demo assistant; legitimate interests. Do not share sensitive personal data in the demo. |
| Account | Name, email, phone, company, role, login and security data (2FA, sessions), billing details | Provide the Service under our contract; legal obligations (accounting); security (legitimate interests). |
| Product usage | Dashboard actions, audit log, support tickets and help questions | Operate, support and improve the Service; legitimate interests. |
| Marketing | Email, preferences | Product news and offers to business contacts; legitimate interests with easy opt-out, or consent where required. |
3. How long we keep it
- Contact-form enquiries: [24 months] from last contact.
- Demo recordings and transcripts: [30 days], then deleted.
- Account data: for the life of the account plus [30 days]; billing records 6 years (HMRC).
- Server and security logs: [90 days].
4. Who we share it with
Service providers acting on our instructions: cloud hosting (UK regions), telephony carriers, speech-to-text, text-to-speech and language-model providers, email/SMS delivery, payment processing and analytics. The current list with locations is in the sub-processor schedule of our DPA. We may disclose data where required by law. We do not sell personal data.
5. International transfers
We host in the UK. Where a provider processes data outside the UK we rely on UK adequacy regulations or the UK International Data Transfer Agreement / Addendum, with additional safeguards where needed.
6. Your rights
You can ask for access to, correction or erasure of your data, object to or restrict processing, request portability, and withdraw consent at any time by emailing [[email protected]]. You can complain to the ICO (ico.org.uk, 0303 123 1113), but we would appreciate the chance to resolve concerns first.
7. Callers and contacts of our customers (processor role)
When you call, message or chat with a business using ParlioTec, we process your voice, phone number, messages, transcripts, summaries and any details you give (such as name, address or appointment preferences) on that business’s instructions. Calls may be recorded and are announced where the business has enabled it. The business decides retention and can export or delete your data on request; please contact them directly. Our processing is governed by our Data Processing Agreement with them. We do not use this data to train general AI models, and platform staff access it only for support with the business’s permission, logged in an audit trail.
8. Cookies
See our Cookie Policy.
9. Security
Encryption in transit and at rest, role-based access with two-factor authentication, audit logging, PII redaction options, tested backups and a documented incident process. We will notify affected customers and, where required, the ICO within 72 hours of becoming aware of a personal data breach.
10. Children
The Service and website are for businesses and are not directed at children under 16.
11. Changes
We will post updates here and, for material changes, notify account holders by email.
