This policy explains what BytePilot does with personal data as a controller — essentially, data about our own customers and visitors to this site.
When our customers run AI agents on the platform, the personal data flowing through those agents (callers' names, numbers, what they said) is handled by us as a processor on that customer's instructions. That is covered by our data processing agreement, not this policy. If an agent called you and you want your information removed, contact the business you were calling — they control it. If you can't reach them, tell us and we will pass it on.
What we collect
- Account data — name, business name, email address, password (stored hashed), and the roles of people you invite.
- Billing data — credit balance, ledger history and invoices. Card details are handled by our payment provider and never stored by us.
- Usage data — how you use the dashboard and API, which agents exist, and the volume and cost of calls, so we can bill you and support you.
- Support correspondence — emails you send us.
- Technical logs — IP address, browser type and request logs, kept for security, abuse prevention and debugging.
We do not use tracking or advertising cookies. The only cookies we set are the ones needed to keep you signed in and to protect forms against cross-site request forgery.
Why we use it, and our lawful basis
- To provide the service — performance of our contract with you.
- To take payment and keep accounts — contract, and legal obligation for tax and accounting records.
- To keep the platform secure and prevent abuse — our legitimate interest in running a safe service.
- To tell you about service changes — contract, or legitimate interest. Marketing email, if we ever send it, is consent-based and always has an unsubscribe link.
Who we share it with
We use a small number of suppliers to run the service: cloud hosting and databases, telephony and messaging carriers, speech and language model providers, email delivery, object storage, and payment processing. They act on our instructions under contract and may not use your data for their own purposes. A current list of these sub-processors is available on request and is maintained as part of our data processing agreement.
We also share data where the law requires it, and we may transfer data if the business is ever sold — in which case you'll be told.
We do not sell personal data, and we do not contact our customers' clients.
Where your data lives
Data is stored in the UK and the European Economic Area. Where a supplier processes data outside the UK/EEA, we rely on adequacy regulations or standard contractual clauses with appropriate safeguards.
How long we keep it
- Account and billing records: for the life of the account and then as long as tax and accounting law requires (currently six years).
- Call records and transcripts processed on our customers' behalf: per the retention period set on the account — transcripts default to 90 days.
- Technical and security logs: typically 90 days.
Your rights
You can ask us for a copy of the personal data we hold about you, to correct it, to delete it, to restrict or object to how we use it, or to receive it in a portable format. Where we rely on consent, you can withdraw it at any time. Email support@bytepilot.ai and we will respond within one month.
If you are unhappy with how we've handled your data you can complain to the UK Information Commissioner's Office at ico.org.uk, though we'd appreciate the chance to put it right first.
Security
Passwords are hashed, secrets are encrypted at rest, access to production data is restricted to the people who need it, and traffic is encrypted in transit. No system is perfectly secure, but we take this seriously and will tell you promptly if something goes wrong that affects you.
Contact
BytePilot, United Kingdom — support@bytepilot.ai