Privacy Policy

Last updated: 9 August 2026

This notice explains what personal data BotSquirrel collects, why, on what legal basis, how long we keep it and what you can do about it. It is written in plain English rather than legalese, and it covers only what we actually do.

1. Who we are

BotSquirrel is a trading name of BOTSQUIRREL LTD, a company registered in England and Wales (company number 17364331), with its registered office at 71–75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom. In this notice "we", "us" and "our" mean BOTSQUIRREL LTD.

We provide AI enquiry-management software for UK small businesses — mainly trades and tuition. Our business customers' own customers message them on WhatsApp, website live chat, Instagram, Facebook or email, and our platform answers, records the enquiry and stores the conversation so the business can follow up.

For any data protection question, email hello@botsquirrel.com. We have not appointed a statutory Data Protection Officer, because we are not required to — enquiries go to the same address and are handled by the company's directors.

2. The two roles in which we handle data

(a) As a controller. We decide why and how data is processed for: visitors to this website, people who request a demo or start a free trial, the staff accounts our business customers create, and our own billing and business records. Everything in this notice describes that controller processing.

(b) As a processor. When your customers chat with your assistant, that conversation data belongs to you, our business customer. You are the controller; we only process it on your documented instructions to run the service. The terms for that — sub-processors, security, breach notification, deletion, audits — are in our Data Processing Addendum, which applies automatically to every business customer. If your question is about data we hold on behalf of a business you messaged, please read the DPA and contact that business.

3. What we collect, and why

Website visitors

We do not track you. This marketing site sets no cookies and runs no analytics or advertising scripts. Our hosting keeps standard technical server logs (IP address, browser type, pages requested, timestamps) for a short period, purely to keep the site up and to investigate abuse or attacks.

Demo requests and free trials

Name, business name, email address, phone or WhatsApp number, the type of business you run, and anything you choose to tell us about what you need. We use it to reply to you, run the demo or trial, and follow up on it.

Business customers and their staff accounts

Account and login details (name, work email, role, hashed password or sign-in identity), the business's contact and address details, subscription and billing records, support correspondence, and audit-log records of significant actions taken in the dashboard.

People who contact us

If you email us or message our own WhatsApp number, we keep the message and your contact details for as long as we need them to deal with the matter and to keep a record of it.

End-customer data we process for our business customers

Names, phone numbers, email addresses, message and conversation content, enquiry details, addresses and job or lesson details, and booking records. We handle this as a processor — see section 2(b) and the DPA. The service is not designed for special category data (health, religion, biometrics) or criminal offence data, and our business customers are told not to configure their assistant to collect it.

We do not sell personal data, we do not share it with unrelated third parties for their own marketing, and we do not use it — yours or your customers' — to train AI models.

4. Our lawful bases

Under the UK GDPR we must have a lawful basis for each purpose. Ours are:

What we doLawful basis
Setting up and running your account; providing the platform; supportContract — performing our contract with you
Responding to a demo request or setting up a free trialContract — steps taken at your request before entering a contract
Taking payment, issuing invoices, chasing unpaid feesContract, and legal obligation for the records themselves
Keeping accounting, VAT and tax recordsLegal obligation — UK tax and company law
Replying to enquiries and following up with people who contacted usLegitimate interests — running and growing a small business, where that does not override your rights
Keeping the service secure, preventing abuse and fraud, technical logging, fixing faults and improving the productLegitimate interests — protecting our systems and our customers
Sending marketing emails to people who are not already customersConsent — you opt in, and every email has an unsubscribe link
Answering a regulator, complying with a court order, or cooperating with law enforcementLegal obligation

Where we rely on legitimate interests, we have considered whether our interest is outweighed by your interests and rights. You can object at any time (see section 8), and we will stop unless we have compelling grounds not to.

5. How long we keep it

· Conversation history, enquiries and bookings — kept while the business customer's account is active. When an account closes, or when we are asked to delete, we delete or anonymise the personal data within 30 days. Business customers can also delete individual conversations and enquiries themselves in the dashboard at any time.
· Account and staff login records — deleted with the account, on the same 30-day timetable.
· Demo and trial enquiries that never became customers — kept for up to 24 months, then deleted.
· Billing, invoicing and tax records — kept for 6 years after the end of the accounting period, because UK tax law requires it.
· Support correspondence — kept for up to 2 years after the matter is closed.
· Technical and security logs — kept for a short rolling period, then overwritten.
· Encrypted database backups — overwritten on a rolling cycle, so data removed from our live systems can persist in backup for up to 30 days before it is gone entirely. We do not restore a backup to bring deleted personal data back.

Step-by-step deletion instructions, including how to disconnect a WhatsApp, Facebook or Instagram account, are on our Data deletion page.

6. Who else sees the data

We keep the list of providers short on purpose. These are the only third parties that handle personal data for us:

ProviderWhat they do for usWhere the data is
Amazon Web ServicesHosting, database, file storage (App Runner, RDS Postgres, ECS, EFS, S3)United Kingdom (London, eu-west-2)
OpenAIGenerating the assistant's replies — conversation content is sent to their APIUnited States
Meta PlatformsDelivering WhatsApp, Instagram and Messenger conversationsGlobal infrastructure, incl. United States
StripeTaking subscription payments — we never see or store your full card numberUnited States / European Union
VapiAI voice calls (currently a pilot feature, only for customers who switch it on)United States
ZohoOur business email — so any email you send us sits in their mail serviceEuropean Union
GitHubHosting this marketing website — like any web host, their servers see visitors' IP addresses in routine server logsUnited States

Each provider is bound by a written contract with data protection terms and may use the data only to provide the service to us. We may also share data with our professional advisers (for example an accountant), or with a regulator, court or law enforcement where the law requires it. If the business is ever sold or reorganised, personal data may pass to the buyer under the same protections.

Where these providers process your end customers' conversation data on our behalf, they act as our sub-processors — see the Data Processing Addendum for the processor terms, including how we notify you before a sub-processor changes.

7. Sending data outside the UK

Your data is stored in the United Kingdom (AWS London, eu-west-2). Some of the providers above are in the United States, so a limited amount of data leaves the UK: conversation content sent to OpenAI to generate a reply, messages carried by Meta, payment details handled by Stripe, and call audio handled by Vapi if you use the voice pilot.

In plain words, that is allowed only if the data stays as protected as it would be here. We rely on the UK's approved safeguards for each transfer — either the UK government's adequacy decision for the country concerned, or the provider's standard contractual clauses combined with the UK International Data Transfer Addendum (IDTA), which is the UK's official contract for this. You can ask us for a copy of the safeguards that apply to a particular provider.

8. Your rights

Under the UK GDPR and the Data Protection Act 2018 you can ask us to:

· Access — give you a copy of the personal data we hold about you, and tell you what we do with it;
· Rectify — correct data that is wrong or incomplete;
· Erase — delete your data, where we have no continuing reason or legal duty to keep it;
· Restrict — pause what we do with your data while a dispute or accuracy question is sorted out;
· Port — hand over the data you gave us in a common, machine-readable format, or send it to another provider where that is technically feasible;
· Object — object to processing we base on legitimate interests, and object to direct marketing at any time (we always stop marketing, no questions asked);
· Withdraw consent — where we rely on consent, take it back at any time. That does not affect anything we did before you withdrew it.

We do not make decisions producing legal or similarly significant effects about you by automated means alone. The AI drafts and sends replies to enquiries, but it does not decide anything about your rights, and a person on the business's team stays in control of bookings and commitments.

To exercise any of these rights, email hello@botsquirrel.com. Rights requests are free, and we reply within one month as the law requires. We may ask you to confirm who you are, so nobody can get at your data by guessing your email address. If your request is about data held by a business that uses BotSquirrel, we will pass it to that business and help them action it — we will not answer on their behalf.

9. Cookies

This marketing site sets no cookies at all — none, not even on the pricing and demo pages. There is no analytics, no advertising pixel and no third-party tracker, so there is no consent banner for you to click through.

The BotSquirrel customer platform app sets no cookies until someone actually signs in. Once you sign in it sets strictly necessary cookies only: the sign-in session cookie authjs.session-token, a matching cross-site request forgery (CSRF) token that stops other websites acting as you, and, for our own platform staff, pa_session. These are HTTP-only, cannot be read by scripts, and exist solely to keep you logged in safely. Strictly necessary cookies do not require consent under the Privacy and Electronic Communications Regulations, but you can delete them at any time in your browser — you will simply be logged out.

10. Complaints

If you are unhappy with how we have handled your personal data or a rights request, tell us first at hello@botsquirrel.com. We would rather put it right ourselves, and we will respond within one month.

You also have the right to complain to the UK's data protection regulator, the Information Commissioner's Office (ICO), at ico.org.uk/make-a-complaint, by phone on 0303 123 1113, or by post to Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF. You do not have to come to us first, though we would appreciate the chance.

11. Changes to this notice

If we change anything material we will update this page and change the date at the top. Where the change affects you significantly, we will also tell business customers by email. Continued use of the service after that means you accept the current version.

12. Contact us

Email: hello@botsquirrel.com · WhatsApp: +44 7472 323783

Post: BOTSQUIRREL LTD, 71–75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom. Registered in England and Wales, company number 17364331.