Privacy Policy
This policy explains how Webespoke AI Ltd ('Webespoke AI', 'we', 'us') collects, uses and protects personal data when you use the WEBEE platform and our websites.
Last updated: 25 July 2026
1. Who we are
Webespoke AI Ltd is the data controller for personal data collected through our websites and the WEBEE platform. Where our customers use WEBEE to handle their own customers' calls, messages and leads, the customer is the data controller and Webespoke AI acts as a data processor on their behalf.
2. Data we collect
- Account data — name, email address, company details and login credentials when you create a workspace.
- Contact and enquiry data — details you submit through our contact or demo forms.
- Communications data — call recordings, transcripts, and message content processed by AI agents you or our customers deploy, where lawfully collected by the workspace owner.
- Usage data — pages visited, features used, device and browser information, and diagnostic logs.
- Billing data — subscription and invoicing details (payment card details are handled by our payment providers, not stored by us).
3. How we use data
- To provide, operate and secure the WEBEE platform.
- To deliver AI voice and messaging services configured by workspace owners.
- To respond to enquiries and provide support.
- To send service communications, and marketing where you have consented (you can opt out at any time).
- To improve the platform, using aggregated and de-identified data where practical.
- To meet legal, accounting and regulatory obligations.
4. Lawful bases
We process personal data under UK GDPR on the bases of contract performance, legitimate interests (running and improving our services), consent (marketing and certain cookies) and legal obligation.
5. Sharing and sub-processors
We share data only with service providers needed to run the platform — including cloud hosting, database, telephony, AI model and email providers — under contracts that require them to protect it. We do not sell personal data. Data may be transferred outside the UK only with appropriate safeguards such as adequacy decisions or standard contractual clauses.
6. Retention
We keep personal data only as long as needed for the purposes above, then delete or anonymise it. Workspace owners control retention of their own customer communications inside their workspace; account data is retained for the life of the account plus a limited period for legal and accounting purposes.
7. Security
Data is encrypted in transit, access is restricted on a least-privilege basis, workspaces are strictly isolated from one another, and our systems are monitored for abnormal behaviour. See our Security page for more detail.
8. Your rights
You have rights of access, rectification, erasure, restriction, portability and objection, and the right to withdraw consent at any time. To exercise them, contact us via the contact page. You can also complain to the UK Information Commissioner's Office (ico.org.uk).
9. Changes
We may update this policy from time to time. Material changes will be notified through the platform or by email. Continued use of the service after changes take effect constitutes acceptance of the updated policy.
