Last updated 28 July 2026 · Forms part of the terms of service
This agreement applies where Apexia Group Limited ("we", the processor) processes personal data on behalf of a customer ("you", the controller) through BytePilot. It is entered into automatically when you create an account. If you resell to your own customers, you are typically their processor and we are a sub-processor — you must have equivalent terms in place with them.
We process personal data for as long as you hold an account, and afterwards only as described in section 8.
Operating AI agents you configure: receiving and handling telephone calls and other conversations, converting speech to text and text to speech, generating responses, capturing structured messages, delivering those messages to recipients you nominate, storing transcripts and call records, and producing usage and billing reports for you.
People who contact your agents (typically your customers' customers), the recipients you nominate for messages, and your own staff who use the platform.
Telephone numbers and caller line identity; names; email addresses where a caller provides one; the content of conversations, including transcripts and any message the caller asks to be passed on; where you enable caller memory, a summary of previous conversations with a caller; and call metadata such as time, duration and outcome.
The service is not intended for special category data (health, biometrics, beliefs, and similar) or for payment card details, and you must not configure agents to collect them. Callers occasionally volunteer sensitive information unprompted; where that happens it is handled under the same safeguards as everything else, and our caller-memory feature is instructed not to retain clinical detail, financial details or full addresses.
We process personal data only on your documented instructions — which include your configuration of the platform and this agreement — unless required by law, in which case we will tell you first unless legally prevented.
You are responsible for having a lawful basis for the processing, for any notice or consent required from data subjects (including telling callers that they are speaking to an AI and that calls may be recorded, where required — the platform provides settings for both), and for the accuracy of what you configure your agents to say.
Our personnel are bound by confidentiality obligations. We maintain technical and organisational measures appropriate to the risk, including: encryption in transit; encryption at rest for secrets and credentials; hashed passwords and hashed API keys; role-based access control with immediate session revocation on removing a team member; per-key and per-agent spend limits; multi-tenant isolation enforced at every database query; audit logging of account activity; and restricted, need-to-know access to production data.
You give general authorisation for us to engage sub-processors to deliver the service. They fall into these categories: cloud hosting and managed databases; telephony and messaging carriers; speech recognition and speech synthesis providers; large language model providers and model routing; transactional email delivery; object storage; and payment processing.
Each is bound by written terms no less protective than these, and we remain liable for their performance. A current list naming each sub-processor is available at any time from support@bytepilot.ai. We will give you reasonable notice before adding or replacing one, and you may object on reasonable data protection grounds — if we can't resolve it, you may terminate the affected service without penalty.
Personal data is stored in the UK and the EEA. Any transfer outside that area relies on adequacy regulations or standard contractual clauses.
Transcripts are deleted automatically after the retention period configured for the platform (90 days by default), and caller memories after their own retention period, measured from a caller's last contact. Call records without conversation content are kept as billing evidence. On termination we delete or return personal data within 30 days of your request, except where we must keep it by law.
Taking into account the nature of the processing, we will help you respond to data subject requests, and with data protection impact assessments and prior consultations. Where a data subject contacts us directly about data we process for you, we will refer them to you.
We will notify you without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting your data, with the information you reasonably need to meet your own notification duties.
We will make available the information reasonably necessary to demonstrate compliance with this agreement and will allow for audits, on reasonable notice, no more than once a year unless a breach or a regulator requires otherwise, and subject to confidentiality and to not compromising other customers' security.
Where this agreement conflicts with the terms of service on matters of data protection, this agreement prevails. It is governed by the laws of England and Wales.
Data protection enquiries: support@bytepilot.ai