Skip to content
SIMCOAIYour 24/7 Digital Front Desk
Home FeaturesResources Pricing News AboutCompany Contact
Docs Login Start free trial
Legal centre

Privacy Policy

This policy explains how SIMCOAI handles personal data for business accounts, dashboard users, website visitors and customer interactions processed through the platform. It is designed around UK GDPR transparency, data minimisation and clear controller/processor roles.

  • Effective: 18 August 2026
  • Last updated: 26 August 2026
  • Contact: hello@simcoai.co.uk
TermsPrivacyGDPRCookies

This document forms part of your agreement with SIMCOAI LTD. It is not legal advice for your own business; take independent advice for regulated, sensitive or high-volume use cases.

ContentsPlain-English summaryController and processor rolesPersonal data we may processCustomer reviewsWhere data comes fromWhy we process dataLawful bases under UK GDPRAI processing and automated decisionsCalls, recordings, transcripts and disclosureCookies and similar technologiesSharing and subprocessorsSIMCOAI namesInternational transfersRetentionYour rightsSecurity controlsChildren and sensitive dataCustomer evidence and proof uploadsContact and complaints
Guidance referencesUK data protection overviewICO lawful basis guidanceICO cookies and PECR guidance

No matching sections found.

01

Plain-English summary

SIMCOAI processes account, billing, support, usage, call/chat and website data to provide the service, secure it, bill for it, improve it and meet legal obligations. We avoid asking for unnecessary sensitive data and encourage customers to configure human handoff for risky topics.

Your business is usually the controller for data about its own customers. SIMCOAI is usually a processor for those customer workflows, and an independent controller for account, billing, website, security and business-contact data.

02

Controller and processor roles

For dashboard users, billing contacts, website visitors, support requests and sales enquiries, SIMCOAI LTD normally acts as controller. For customer calls/chats handled on behalf of a business customer, SIMCOAI normally acts as processor and the business customer is the controller.

Some suppliers such as Stripe, Twilio or our AI and voice providers may act as processors or independent controllers depending on the specific processing activity and their own terms.

03

Personal data we may process

Account data: name, email, company, sign-in provider, user ID, role, legal acceptance and support history. Business profile data: business name, website, services, opening hours, policies, escalation contacts and configuration.

Customer workflow data: chat messages, call metadata, transcripts or summaries where enabled, bookings, refund/order details, escalation notes and audit logs. Customer records: where a business customer uses the customer database, one record per person containing the name, email address, phone number, company and any additional fields that business has chosen to record, together with the bookings, refunds, orders and escalations linked to it. Records are created from details a caller gives, and a caller is matched to an existing record using the number they are calling from. Billing/security data: Stripe references, invoices, plan status, IP-derived security data, device/browser metadata and request IDs.

03

Customer reviews you choose to publish

If you write a review of SIMCOAI we process the words you wrote, the star rating, the name, role and business name you enter, the account the review came from where we know it, the date, and technical metadata about the submission (a one-way hash of the network address it came from and the browser user agent). We do not ask for and do not want any other personal data in a review.

Lawful basis. Publishing a review, and the name, role and business name alongside it, is done on the basis of your consent, given by the tick box on the submission form. Nothing is published without it. Holding the review internally and checking it before publication rests on our legitimate interests in running an honest, moderated review process and in preventing fraudulent or abusive submissions.

What is published and what is not. We publish the rating, the review text, the headline, and the name, role and business name you gave us, together with a “Verified customer” marker where the review came from the single-use link we emailed a paying customer. We never publish your email address, your account identifier, your network address or any other technical metadata, and we do not sell or license reviews to any third party.

Withdrawing consent. You can withdraw consent and have a published review removed at any time, for any reason and without giving one, by emailing hello@simcoai.co.uk. We aim to unpublish within one working day; because pages are cached, a removed review can remain visible for a short period after that (currently up to about a minute for the review list itself). Withdrawal does not affect the lawfulness of publication before you withdrew.

Review requests. We email each customer once, about fourteen days after they start, to ask whether they would like to write a review. That email is sent on the basis of our legitimate interests in obtaining customer feedback about a service you already buy from us (the “soft opt-in” in regulation 22 of PECR). It carries a working unsubscribe link and a one-click list unsubscribe header, and opting out stops feedback requests without affecting service, billing or security emails, which you cannot unsubscribe from while you hold an account.

Retention. A published review is kept for as long as it is published. An unpublished, rejected or withdrawn review, and the record of the invitation that produced it, are kept for up to 24 months so that we can show how a review was obtained and moderated, and are then deleted. Review invitation links themselves expire after 90 days.

04

Where data comes from

Data may come from you, authorised users, your customers, connected integrations, Stripe, Twilio, our own authentication system, support communications, website forms, logs and security tools.

Do not upload data you do not have rights to use or data that is not needed for customer support, booking, refund, order, analytics or compliance workflows.

05

Why we process data

We process data to create and secure accounts, provide AI chat and phone workflows, maintain knowledge bases, route customer tasks, produce analytics, manage subscriptions, provide support, prevent abuse, troubleshoot providers and keep legal acceptance records.

We may also process limited data to improve reliability, user experience, prompts, safeguards, documentation and fraud/security controls.

06

Lawful bases under UK GDPR

Depending on the context, lawful bases may include contract, legitimate interests, legal obligation and consent. Consent is especially relevant for non-essential cookies or marketing communications where required.

For customer workflow data, the business customer must determine and document the lawful basis it relies on. SIMCOAI processes that data under customer instructions unless another legal requirement applies.

07

AI processing and automated decisions

SIMCOAI may send relevant prompts, business knowledge, conversation content or summaries to AI providers to generate responses, classifications or workflow suggestions. We configure the product to escalate sensitive or uncertain topics rather than making final regulated decisions.

SIMCOAI manages all AI provider credentials centrally on SIMCOAI-managed infrastructure; customers do not add or manage their own provider keys. The approved managed AI provider is OpenAI, used subject to plan, add-on and pay-as-you-go controls. AI usage is metered and the available model options are shown in the dashboard.

SIMCOAI should not be used for solely automated legal, employment, credit, medical, housing, insurance, eligibility or similarly significant decisions without a separately reviewed contract and controls.

08

Calls, recordings, transcripts and disclosure

Phone features may process caller number, call time, duration, call status, routing events, recordings or transcripts where configured. Businesses must provide lawful disclosure and recording notices required for their use case and location.

Call logs and transcripts should be reviewed regularly. Payment card details, medical details and unnecessary sensitive information should be redirected to appropriate secure human or provider flows.

09

Cookies and similar technologies

We use essential cookies/storage for site and dashboard operation. Non-essential analytics or marketing technologies should only run where the user has been given appropriate information and choice.

Cookie choices may be stored on your device or in our legal acceptance records. See the Cookies page for categories, purpose, duration and preference controls.

10

Sharing and subprocessors

We may share data with suppliers that help us operate the service, such as Stripe for billing, Twilio for communications, our managed AI model provider OpenAI for AI features, Deepgram for speech recognition and ElevenLabs for voice on phone-enabled plans, Cloudflare for security/delivery, and Fasthosts for hosting, domain services and transactional email. SIMCOAI manages all AI provider credentials centrally; customers do not add their own provider keys. AI requests for your account are handled by OpenAI, which is the only approved managed provider. Sign-in and account security are handled by SIMCOAI's own sign-in service, which runs on SIMCOAI-controlled infrastructure rather than a third party's; it is described in full in the “Identity provider processing” clause of our GDPR page. This service processes identity and login data: your email address and its verification state, sign‑in and sign‑out events, multi‑factor authentication and authenticator‑app enrolments, passkey and passwordless registrations, email sign‑in links and codes, and the account identifier returned by a Google or Microsoft sign‑in. Each of these is available where enabled for your account rather than on every plan by default. Against your SIMCOAI account we keep a linked authentication record holding the user reference, the identity provider name, the provider‑issued subject identifier, the email address and its verification flag, basic profile metadata and the last sign‑in timestamp. That record exists so a sign‑in can be matched to the right account; it does not contain your password. Passwords are set and checked by the sign-in service, never by the SIMCOAI dashboard, so the dashboard does not receive your password when you sign in, reset it or change it — and the sign-in service itself does not expose a readable password back to us: it stores your password only as a one-way hash, and the only administrative capability it offers is to set a new one, never to read an existing one. The migration away from storing password hashes in the SIMCOAI dashboard's own database is complete and the legacy local password hashes have been removed: SIMCOAI holds no password record for any account, in any form. If you ask us to erase or correct authentication data we action it directly, because the sign-in service runs on our own infrastructure and there is no separate third party to instruct. Neither sign-in service receives your business operational data. SIMCOAI stores that operational data — your business profile, customer records, call and conversation logs and workflow history — in its own self-hosted Supabase instance on SIMCOAI-controlled infrastructure. Supabase Inc. is not a subprocessor and does not receive your data; the relevant processor for that storage is our hosting provider, Fasthosts.

We do not sell personal data. We may disclose data if required by law, to protect rights and security, to complete a corporate transaction, or with your instruction/consent.

10

Which SIMCOAI name means which processor

Across the SIMCOAI product, the marketing site and the documentation, the parts of the service are referred to by SIMCOAI names — SIMCOAI Calling, SIMCOAI Voice, SIMCOAI Speech, SIMCOAI Intelligence — and the AI models, voices and speech engines have SIMCOAI names of their own. Those names describe configurations SIMCOAI builds, operates and can change; they are not a claim to have built the underlying engines, and they are not used here.

This page names the actual processor, because that is a legal requirement rather than a presentational choice. The table below is the map between the two, so you can tell exactly who processes what when you read a SIMCOAI name anywhere else.

SIMCOAI nameWhat it doesProcessor behind it
SIMCOAI CallingInbound and outbound telephone calls, and the streaming connection that carries themTwilio Inc.
SIMCOAI MessagingText messagesTwilio Inc.
SIMCOAI Voice — Rapid, Natural, Studio, SignatureThe synthesised speaking voice your callers hearElevenLabs Inc.
SIMCOAI Speech — Live, Precise, StandardRecognising what a caller said, and when they finished saying itDeepgram Inc.
SIMCOAI Intelligence — Lite, Swift, Core, Insight, LiveThe AI models that compose replies and capture requestsOpenAI, L.L.C.
SIMCOAI PaymentsSubscriptions, checkout, invoices and card detailsStripe, Inc. and Stripe Payments Europe Ltd
SIMCOAI IdentitySigning in, passwords, passkeys and two-step verificationSIMCOAI's own self-hosted sign-in service, which is not a third party
SIMCOAI platformHosting, servers, storage, domains and transactional email; the database is self-hosted, so its software vendor receives no customer dataFasthosts Internet Ltd; Cloudflare, Inc. for security and delivery

Where a SIMCOAI name is used elsewhere, it always refers to the row above. If SIMCOAI changes the processor behind one of these, this page and the supplier table are updated and notice is given under the subprocessor clause; the SIMCOAI name may stay the same, which is precisely why this map exists.

11

International transfers

Some suppliers may process data outside the UK or EEA. Where personal data is transferred internationally we ensure a lawful transfer mechanism is in place, such as a UK adequacy decision, the UK International Data Transfer Agreement or Addendum to the EU Standard Contractual Clauses, together with any supplementary measures needed.

Where we rely on the IDTA or the Addendum we also carry out a transfer risk assessment before the transfer begins. The mechanism relied on for an individual supplier is listed on our GDPR & Data Processing page and the underlying assessment is available on request. Business customers should assess whether their own use case requires additional transfer terms or a data processing agreement.

12

Retention

We keep personal data only as long as necessary for the purpose it was collected: account records for the life of the account plus up to 6 years after closure where needed for legal claims; billing and tax records for 6 years as required by UK tax law; security and audit logs typically for 12 months; and support correspondence for up to 3 years. If you cancel, your workspace content — business profile, knowledge, configured workflows and settings — is kept for 2 years after your subscription ends so you can reactivate later without rebuilding your setup, after which it is deleted. That is separate from the account, billing and legal-claim records described above, which follow their own periods. You can ask us to delete your workspace sooner by emailing hello@simcoai.co.uk, and we will do so except where we must keep specific records to meet a legal or tax obligation. A detailed retention schedule is available on request.

Customers should delete or export records they no longer need and avoid storing unnecessary sensitive data. Backup deletion can lag live deletion because backups are rotated for security and continuity.

13

Your rights

Under UK GDPR you have the rights to be informed, of access, to rectification, to erasure, to restrict processing, to data portability, to object, and rights in relation to automated decision-making. We will respond to a valid request within one month (extendable by two further months for complex requests, in which case we will tell you). Where the business customer is controller for a record, we will pass your request to them without undue delay. You also have the right to complain to the Information Commissioner’s Office at ico.org.uk or on 0303 123 1113.

Contact hello@simcoai.co.uk with the account/business involved, the right you want to exercise and enough information to locate the record safely.

14

Security controls

SIMCOAI protects personal data with encryption in transit (HTTPS/TLS), role-based access controls, rate limiting, audit records, isolated supplier credentials and least-privilege administrative access. We review these measures regularly. No system is entirely risk-free, so customers must also use strong account hygiene and keep escalation processes available.

Service credentials and payment secrets must never be shared, embedded in your website or app, or pasted into chat, prompts or support tickets. Do not paste secrets, card numbers or unnecessary sensitive data into chat, voice prompts or support tickets.

15

Authentication and account access data

SIMCOAI supports several ways to sign in, and each stores a little data so that the method works. We describe them here because they are account security data rather than general usage data.

Passwords are set and checked by SIMCOAI's own self-hosted sign-in service, rather than by the dashboard. It does not give SIMCOAI, including our own support team, a way to read an existing password: it stores it only as a one-way hash and offers, at most, a way to set a new one, never to view one already set. We will never ask you for your password. SIMCOAI holds no password record for your account, in any form. Passkeys store a public key and a credential identifier registered by your device. The private key never leaves your device and is never transmitted to us. Where you unlock a passkey with a fingerprint or face scan, that check happens entirely on your own device: neither SIMCOAI nor the sign-in service ever receives, processes or stores biometric data of any kind, and none is used to identify you. Two-step sign-in may add an authenticator app, a hardware security key or single-use recovery codes. Where used, the shared secret or key registration is held by the sign-in service as part of the account, not by the SIMCOAI dashboard. Magic links and password resets store a single-use, short-lived token tied to your email address. Google sign-in stores the account identifier Google returns so we can match you to your SIMCOAI account; we do not receive your Google password.

We also record sign-in events — time, approximate origin and method — to help detect unauthorised access and to give you an audit trail. This is processed on the basis of our legitimate interest in keeping accounts secure.

Sign-in methods are added and removed on the SIMCOAI sign-in service itself, at the point you sign in, rather than inside the dashboard — so a change applies wherever you sign in and does not depend on one browser. Your dashboard shows what is available and links you to it. Sessions can be ended from the dashboard, and signing out ends the session on this device and on the sign-in service. Removing every method except one may leave you unable to sign in, so keep a backup method configured.

15

Children and sensitive data

SIMCOAI is not directed at children. Do not configure workflows intentionally targeting children or collecting children data unless your contract, notices and controls specifically permit it.

Special category data should be avoided unless necessary, lawful and covered by your own controller obligations and written arrangements.

16

Customer evidence and proof uploads

Where a business enables proof uploads, it can send its own customer a secure one-off link to submit supporting evidence against a refund, order, booking or escalation. Using that link we process the uploaded file itself (typically a photograph, receipt or document), an optional barcode, tracking or reference value, an optional free-text note, and technical upload metadata such as file name, size, type, timestamp and the single-use link token. No SIMCOAI account is created for the person uploading.

Roles. The SIMCOAI customer (the business) decides what evidence to request and why, and is the controller for that evidence. SIMCOAI acts as processor on the business's instructions. The business is responsible for telling the person what is being collected and why, and for having a lawful basis to collect it. It should not request payment card details, passwords, or special category data it has no lawful basis to process.

Automated checks. Barcode, reference and document checks are assistive only. They help the business's staff review a request; they do not make the decision. No refund, booking or escalation outcome is decided solely by automated means — a person reviews and approves every outcome, as described in our AI Policy.

Access and retention. Uploaded files are retrieved through authenticated requests and are visible to the business's authorised dashboard users. SIMCOAI staff access them only where necessary for support, security or legal compliance. Evidence is retained alongside the related workflow record under the retention rules described above and in the business's own settings, and can be deleted on the business's instruction, subject to any record-keeping we are legally required to maintain.

Rights. Where evidence concerns a business's own customer, that person should exercise their data protection rights with the business as controller in the first instance; SIMCOAI will assist the business in responding. If you cannot reach the business, contact us at hello@simcoai.co.uk and we will help route the request.

17

Contact and complaints

Email hello@simcoai.co.uk for privacy questions. You may also complain to the UK Information Commissioner if you believe your data protection rights have not been handled properly.

We may update this policy as the service, providers, law or guidance changes. Material changes may require dashboard acknowledgement.

Supplier overview

Common service providers

Actual providers and roles can vary by feature, plan, region and contract.

ProviderTypical purposeRisk control
FasthostsHosting, servers, storage, networking, domain registration and transactional email delivery for the SIMCOAI platform and its self-hosted databaseUK hosting, restricted administrative access, encryption in transit and authenticated email sending
DeepgramSpeech recognition for answered calls on phone-enabled plansCall audio only; not used for advertising or model training by SIMCOAI
ElevenLabsText-to-speech voices for answered calls on phone-enabled plansUsed only to generate the assistant voice; no customer records sent
StripeCheckout, portal, invoices, payment methods and subscription stateHosted payment flows with automatic entitlement updates
TwilioVoice, phone numbers, call events and messaging where enabledNumber assignment, disclosure wording and compliance review
OpenAIAI responses, summaries, classifications and assistant featuresHuman handoff for sensitive, uncertain or regulated topics
CloudflareSecurity, performance and bot protectionTraffic filtering, HTTPS and abuse controls
SIMCOAIYour 24/7 Digital Front Desk

Smart Intelligent Management & Communications Operations.

Product

FeaturesTechnologyResourcesPricingReviewsNewsDashboard

Company

AboutCompany detailsContactDocs

Legal

TermsPrivacyGDPR & DPACookiesAcceptable UseAI PolicyTelecomsBilling & TaxRefundsSLA & Support

Contact

Call us: +44 7576 569444Contact formFAQReport a bugSystem status
SIMCOAI LTD · Registered in the UK, company number 17247747 · SIMCOAI LTD, registered in England and Wales. These policies form part of your customer agreement.