Privacy Policy

Last Updated: 19-Aug-2024

1. Introduction

This Privacy Policy explains how askjohngeorge.com ("we," "our," or "us") collects, uses, and protects your personal information when you use our website and AI voice assistant services. This policy is designed to comply with UK data protection laws, including the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, as well as the EU General Data Protection Regulation (GDPR) and relevant US privacy laws.

2. Information We Collect

We collect the following types of information:

  • Voice recordings and transcripts from interactions with our AI voice assistant
  • Your full name, use case information for voice agents, and project budget when you engage with our services
  • Website usage data through Vercel Analytics

3. AI and Voice Technology Disclosure

Our AI voice assistant uses natural language processing to interact with users. During these interactions, the AI:

  • Records and processes your voice input
  • Generates real-time responses based on your input
  • Creates transcripts of the conversation
  • Analyzes the conversation for lead qualification purposes

The AI does not make automated decisions that have legal or similarly significant effects on users.

4. How We Use Your Information

We use your information to:

  • Demonstrate AI voice capabilities to potential clients
  • Qualify potential leads
  • Improve our AI services through analysis of interactions
  • Analyze website traffic and usage patterns

5. Legal Basis for Processing and Consent

For users in the UK and EU, we process your personal data on the following legal bases:

  • Consent: When you interact with our AI voice assistant, you will be verbally informed that the call will be recorded and processed. By continuing the call after this disclosure, you provide your consent for this processing.
  • Legitimate Interests: For website analytics and service improvement.

You can withdraw your consent at any time by ending the call or by contacting us through our website.

6. Data Storage, Security, and Retention

Voice recordings are stored by our service provider, Vapi.

  • Metadata from voice calls is stored in a Google account.
  • Website analytics data is hosted on Vercel.

Data is retained for as long as necessary to fulfill the purposes outlined in this policy, unless a longer retention period is required or permitted by law.

We implement appropriate technical and organisational measures to protect your data, including:

  • Encryption of data in transit and at rest
  • Regular security audits
  • Access controls and authentication measures
  • Employee training on data protection and security

7. Sharing Your Information and Third-Party Service Providers

We share your information with:

  • Vapi (for voice recording storage and processing): Vapi processes and stores call audio and transcripts. They implement encryption and secure storage for all data.
  • Vercel (for website analytics): Vercel collects anonymized website usage data. They are SOC 2 Type 2 compliant and ISO 27001:2013 certified.
  • Google (for metadata storage): We use Google Workspace, which provides robust security measures and complies with major privacy and security standards.

For more detailed information on how these services handle your data, please refer to their respective privacy policies.

8. Your Rights and How to Exercise Them

Depending on your location, you may have the following rights:

  • Access your personal information
  • Have inaccurate information corrected
  • Have information erased in certain circumstances
  • Restrict processing of your information
  • Data portability
  • Object to processing based on legitimate interests

To exercise these rights, please contact us through the contact form on our website. We will respond to your request within one month. To verify your identity, we may require additional information before processing your request.

9. Age Restrictions

Our services are not intended for use by individuals under the age of 18. We do not knowingly collect or process data from anyone under this age. If we become aware that we have collected personal data from a child under 18, we will take steps to delete that information as quickly as possible.

10. International Data Transfers

Your data may be transferred to and processed in countries outside your country of residence, including the United States. We ensure appropriate safeguards are in place for these transfers in compliance with applicable data protection laws, such as Standard Contractual Clauses approved by the European Commission.

11. California Privacy Rights

If you are a California resident, you may have additional rights under the California Consumer Privacy Act (CCPA). Please contact us for more information.

12. Changes to This Policy

We may update this policy from time to time. We will notify you of any significant changes by posting the new policy on this page and updating the "Last Updated" date at the top of this policy.

13. Contact Us

For any questions about this Privacy Policy or to exercise your rights, please use the contact form on our website.

14. Complaints

If you have a concern about our use of your information, please contact us first. If you are not satisfied with our response, you have the right to complain to your local data protection authority, such as the Information Commissioner's Office (ICO) in the UK.