Privacy Policy
Last updated 28 July 2026
Before launch: this document describes the system accurately but has not been reviewed by a solicitor. Company details marked [ ] must be completed, and the international transfer position in section 6 needs a decision.
This policy explains how [Legal entity name, company number, registered address] (“Aiderra”, “we”) handles personal data in Aiderra OS. It covers both the people who use the product and the people whose details our customers put into it.
1. Two different roles
We act in two capacities, and your rights differ depending on which applies.
- Controller — for account data: the names, email addresses, credentials and billing records of the people who sign in to Aiderra OS. We decide why and how that is processed.
- Processor — for customer data: the contacts, leads, callers, invoices and messages our customers load into or generate within their workspace. The customer is the controller; we process it only on their instructions. If you are a member of the public who contacted a business using Aiderra OS, that business is your first point of contact.
2. What we process
Account data (we are controller)
- Name, work email address, and the workspace you belong to.
- A password stored only as a salted
scrypthash — never in a readable form — and, where two-factor authentication is enabled, a TOTP secret. - Session records, sign-in times, and IP-derived rate-limiting counters.
- Subscription and payment status. Card details are handled by Stripe and never reach us.
Customer data (we are processor)
- Contacts, companies, leads and deals, including names, email addresses and phone numbers.
- Telephone and chat conversations handled by the receptionist, including transcripts and the details a caller gives — their name, number, and what they were asking about.
- Invoices, payment chasing records, support tickets and scheduled meetings.
- The business profile a customer writes to ground their agents’ answers.
Special category data. Aiderra OS is used by care providers, and a caller may volunteer health information when enquiring about care. We do not ask for it and no feature is designed around it, but it can be captured in a call transcript or an enquiry note. Customers processing health data are responsible for their own lawful basis under Article 9 UK GDPR, and should complete a Data Protection Impact Assessment.
3. Why we process it, and on what basis
- To provide the service — performance of our contract with the customer.
- To keep accounts secure — legitimate interests in preventing unauthorised access, covering authentication, audit logging and rate limiting.
- To take payment — performance of contract, and legal obligation for retaining financial records.
- To meet legal obligations — including the tamper-evident audit trail, which exists so that automated actions remain accountable.
We do not sell personal data, do not use it to train third-party AI models, and run no advertising or profiling of visitors.
4. Automated processing
Aiderra OS drafts communications, qualifies enquiries and prepares actions automatically. Two things are true of that by design and are worth stating plainly:
- Every action that leaves the business — an email, a published article, a social post — is held for a person’s approval before it is sent. The system does not contact anyone on its own authority.
- Every action is recorded in an audit trail that cannot be silently altered, so a decision can be traced back to who or what took it.
No automated decision produces a legal or similarly significant effect on an individual without a person reviewing it first.
5. Who we share it with
These are our sub-processors. Each one appears here because the software genuinely calls it.
| Provider | Purpose | Region |
|---|---|---|
| Neon | Database hosting | United States (AWS us-east-1) |
| Railway | Application hosting | United States |
| Anthropic | Language model used by the agents | United States |
| OpenAI | Voice for the receptionist; marketing image generation | United States |
| Twilio | Telephone calls and messaging | United States / global |
| Resend | Transactional and outbound email | United States |
| Stripe | Subscriptions and payments | United States / global |
| Calendar scheduling, where connected | Global | |
| LinkedIn / Meta | Publishing posts, only where a customer connects an account | Global |
| GitHub | Code review, only where a customer connects a repository | United States |
Companies House and the Care Quality Commission registers are also queried. Those are public registers of businesses, and we send no personal data to them.
6. Where data is stored
Aiderra OS data is currently stored in the United States (AWS us-east-1), not the United Kingdom. Transfers out of the UK require an approved safeguard — the UK International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses — with each provider above. Complete this section with the mechanism relied on for each, or move hosting to a UK or EU region and update this page.
7. How long we keep it
- Account data: for the life of the account, then deleted within 90 days of closure.
- Customer data: for as long as the customer’s workspace exists. They can delete records at any time, and we delete the workspace on request when the contract ends.
- Audit records: retained longer than the data they describe, because an audit trail that can be erased is not an audit trail. Personal data within an audit entry can be redacted on a valid erasure request, and the redaction itself is logged.
- Financial records: six years, as UK law requires.
8. How it is protected
- Encrypted in transit, and at rest by our hosting providers.
- Each workspace’s data is isolated at the database level by row-level security, so one customer’s queries cannot reach another’s rows.
- Credentials a customer connects — website keys, social tokens — are encrypted with AES-256-GCM and are never returned by any API or shown in the interface.
- Passwords are salted and hashed. Two-factor authentication is available and can be required.
- Access is role-based, and privileged actions are recorded.
9. Your rights
Under UK GDPR you may request access to your data, correction, erasure, restriction, portability, or object to processing. Where we act as processor we will pass your request to the customer who controls the data, and assist them in answering it.
Contact [privacy@ contact address]. We respond within one month. You may also complain to the Information Commissioner’s Office at ico.org.uk.
10. Changes
We will update this page when the service changes and revise the date above. Material changes will be notified to account holders by email.