Last updated: 9 August 2026
This notice explains what personal data BotSquirrel collects, why, on what legal basis, how long we keep it and what you can do about it. It is written in plain English rather than legalese, and it covers only what we actually do.
BotSquirrel is a trading name of BOTSQUIRREL LTD, a company registered in England and Wales (company number 17364331), with its registered office at 71–75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom. In this notice "we", "us" and "our" mean BOTSQUIRREL LTD.
We provide AI enquiry-management software for UK small businesses — mainly trades and tuition. Our business customers' own customers message them on WhatsApp, website live chat, Instagram, Facebook or email, and our platform answers, records the enquiry and stores the conversation so the business can follow up.
For any data protection question, email hello@botsquirrel.com. We have not appointed a statutory Data Protection Officer, because we are not required to — enquiries go to the same address and are handled by the company's directors.
(a) As a controller. We decide why and how data is processed for: visitors to this website, people who request a demo or start a free trial, the staff accounts our business customers create, and our own billing and business records. Everything in this notice describes that controller processing.
(b) As a processor. When your customers chat with your assistant, that conversation data belongs to you, our business customer. You are the controller; we only process it on your documented instructions to run the service. The terms for that — sub-processors, security, breach notification, deletion, audits — are in our Data Processing Addendum, which applies automatically to every business customer. If your question is about data we hold on behalf of a business you messaged, please read the DPA and contact that business.
We do not track you. This marketing site sets no cookies and runs no analytics or advertising scripts. Our hosting keeps standard technical server logs (IP address, browser type, pages requested, timestamps) for a short period, purely to keep the site up and to investigate abuse or attacks.
Name, business name, email address, phone or WhatsApp number, the type of business you run, and anything you choose to tell us about what you need. We use it to reply to you, run the demo or trial, and follow up on it.
Account and login details (name, work email, role, hashed password or sign-in identity), the business's contact and address details, subscription and billing records, support correspondence, and audit-log records of significant actions taken in the dashboard.
If you email us or message our own WhatsApp number, we keep the message and your contact details for as long as we need them to deal with the matter and to keep a record of it.
Names, phone numbers, email addresses, message and conversation content, enquiry details, addresses and job or lesson details, and booking records. We handle this as a processor — see section 2(b) and the DPA. The service is not designed for special category data (health, religion, biometrics) or criminal offence data, and our business customers are told not to configure their assistant to collect it.
We do not sell personal data, we do not share it with unrelated third parties for their own marketing, and we do not use it — yours or your customers' — to train AI models.
Under the UK GDPR we must have a lawful basis for each purpose. Ours are:
| What we do | Lawful basis |
|---|---|
| Setting up and running your account; providing the platform; support | Contract — performing our contract with you |
| Responding to a demo request or setting up a free trial | Contract — steps taken at your request before entering a contract |
| Taking payment, issuing invoices, chasing unpaid fees | Contract, and legal obligation for the records themselves |
| Keeping accounting, VAT and tax records | Legal obligation — UK tax and company law |
| Replying to enquiries and following up with people who contacted us | Legitimate interests — running and growing a small business, where that does not override your rights |
| Keeping the service secure, preventing abuse and fraud, technical logging, fixing faults and improving the product | Legitimate interests — protecting our systems and our customers |
| Sending marketing emails to people who are not already customers | Consent — you opt in, and every email has an unsubscribe link |
| Answering a regulator, complying with a court order, or cooperating with law enforcement | Legal obligation |
Where we rely on legitimate interests, we have considered whether our interest is outweighed by your interests and rights. You can object at any time (see section 8), and we will stop unless we have compelling grounds not to.
· Conversation history, enquiries and bookings — kept while the business customer's account is active. When an account closes, or when we are asked to delete, we delete or anonymise the personal data within 30 days. Business customers can also delete individual conversations and enquiries themselves in the dashboard at any time.
· Account and staff login records — deleted with the account, on the same 30-day timetable.
· Demo and trial enquiries that never became customers — kept for up to 24 months, then deleted.
· Billing, invoicing and tax records — kept for 6 years after the end of the accounting period, because UK tax law requires it.
· Support correspondence — kept for up to 2 years after the matter is closed.
· Technical and security logs — kept for a short rolling period, then overwritten.
· Encrypted database backups — overwritten on a rolling cycle, so data removed from our live systems can persist in backup for up to 30 days before it is gone entirely. We do not restore a backup to bring deleted personal data back.
Step-by-step deletion instructions, including how to disconnect a WhatsApp, Facebook or Instagram account, are on our Data deletion page.
We keep the list of providers short on purpose. These are the only third parties that handle personal data for us:
| Provider | What they do for us | Where the data is |
|---|---|---|
| Amazon Web Services | Hosting, database, file storage (App Runner, RDS Postgres, ECS, EFS, S3) | United Kingdom (London, eu-west-2) |
| OpenAI | Generating the assistant's replies — conversation content is sent to their API | United States |
| Meta Platforms | Delivering WhatsApp, Instagram and Messenger conversations | Global infrastructure, incl. United States |
| Stripe | Taking subscription payments — we never see or store your full card number | United States / European Union |
| Vapi | AI voice calls (currently a pilot feature, only for customers who switch it on) | United States |
| Zoho | Our business email — so any email you send us sits in their mail service | European Union |
| GitHub | Hosting this marketing website — like any web host, their servers see visitors' IP addresses in routine server logs | United States |
Each provider is bound by a written contract with data protection terms and may use the data only to provide the service to us. We may also share data with our professional advisers (for example an accountant), or with a regulator, court or law enforcement where the law requires it. If the business is ever sold or reorganised, personal data may pass to the buyer under the same protections.
Where these providers process your end customers' conversation data on our behalf, they act as our sub-processors — see the Data Processing Addendum for the processor terms, including how we notify you before a sub-processor changes.
Your data is stored in the United Kingdom (AWS London, eu-west-2). Some of the providers above are in the United States, so a limited amount of data leaves the UK: conversation content sent to OpenAI to generate a reply, messages carried by Meta, payment details handled by Stripe, and call audio handled by Vapi if you use the voice pilot.
In plain words, that is allowed only if the data stays as protected as it would be here. We rely on the UK's approved safeguards for each transfer — either the UK government's adequacy decision for the country concerned, or the provider's standard contractual clauses combined with the UK International Data Transfer Addendum (IDTA), which is the UK's official contract for this. You can ask us for a copy of the safeguards that apply to a particular provider.
Under the UK GDPR and the Data Protection Act 2018 you can ask us to:
· Access — give you a copy of the personal data we hold about you, and tell you what we do with it;
· Rectify — correct data that is wrong or incomplete;
· Erase — delete your data, where we have no continuing reason or legal duty to keep it;
· Restrict — pause what we do with your data while a dispute or accuracy question is sorted out;
· Port — hand over the data you gave us in a common, machine-readable format, or send it to another provider where that is technically feasible;
· Object — object to processing we base on legitimate interests, and object to direct marketing at any time (we always stop marketing, no questions asked);
· Withdraw consent — where we rely on consent, take it back at any time. That does not affect anything we did before you withdrew it.
We do not make decisions producing legal or similarly significant effects about you by automated means alone. The AI drafts and sends replies to enquiries, but it does not decide anything about your rights, and a person on the business's team stays in control of bookings and commitments.
To exercise any of these rights, email hello@botsquirrel.com. Rights requests are free, and we reply within one month as the law requires. We may ask you to confirm who you are, so nobody can get at your data by guessing your email address. If your request is about data held by a business that uses BotSquirrel, we will pass it to that business and help them action it — we will not answer on their behalf.
This marketing site sets no cookies at all — none, not even on the pricing and demo pages. There is no analytics, no advertising pixel and no third-party tracker, so there is no consent banner for you to click through.
The BotSquirrel customer platform app sets no cookies until someone actually signs in. Once you sign in it sets strictly necessary cookies only: the sign-in session cookie authjs.session-token, a matching cross-site request forgery (CSRF) token that stops other websites acting as you, and, for our own platform staff, pa_session. These are HTTP-only, cannot be read by scripts, and exist solely to keep you logged in safely. Strictly necessary cookies do not require consent under the Privacy and Electronic Communications Regulations, but you can delete them at any time in your browser — you will simply be logged out.
If you are unhappy with how we have handled your personal data or a rights request, tell us first at hello@botsquirrel.com. We would rather put it right ourselves, and we will respond within one month.
You also have the right to complain to the UK's data protection regulator, the Information Commissioner's Office (ICO), at ico.org.uk/make-a-complaint, by phone on 0303 123 1113, or by post to Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF. You do not have to come to us first, though we would appreciate the chance.
If we change anything material we will update this page and change the date at the top. Where the change affects you significantly, we will also tell business customers by email. Continued use of the service after that means you accept the current version.
Email: hello@botsquirrel.com · WhatsApp: +44 7472 323783
Post: BOTSQUIRREL LTD, 71–75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom. Registered in England and Wales, company number 17364331.