GotAI Privacy Policy and Data Processing Terms
This Privacy Policy explains how GotAI handles personal data when providing its AI phone answering service.
It also includes the core data-processing terms that apply when GotAI processes caller enquiry data on behalf of a business customer.
1. Who we are
David Kirwan, trading as GotAI (“GotAI”, “we”, “us”), operates the GotAI AI phone answering service at gotai.ie.
GotAI helps business customers answer missed or diverted phone calls, collect basic enquiry details, produce a call summary, and send that summary to the customer by SMS, email, or another agreed channel.
2. Scope of this policy
This policy covers:
- business customers who use GotAI;
- callers who phone a business customer and are answered by GotAI;
- people who contact GotAI directly;
- visitors to gotai.ie.
This policy does not replace the business customer’s own privacy notice. The customer remains responsible for explaining to its own callers how it uses caller data.
3. Controller and processor roles
GotAI has different roles depending on the data involved.
3.1 Customer account and service-admin data
For customer account data, billing data, support data, security logs, website enquiries, and GotAI service administration, GotAI is the data controller.
This means GotAI decides why and how that data is used.
3.2 Caller enquiry data
For caller enquiry data collected by GotAI on behalf of a business customer, the customer is normally the data controller and GotAI acts as the customer’s data processor.
This means:
- the customer decides the purpose of the call handling;
- the customer decides what caller information is needed;
- the customer is responsible for having a lawful basis for collecting and using caller data;
- GotAI processes caller data only to provide the service, on the customer’s instructions, unless required by law.
4. Personal data we process
4.1 Caller enquiry data
Depending on the customer’s configuration, GotAI may collect:
- caller name;
- caller phone number;
- optional email address;
- general location, area, or job location;
- full address only where the customer has requested this and it is necessary for the enquiry;
- type of job, claim, service request, or business enquiry;
- short description of the issue;
- urgency;
- preferred callback time;
- call timestamp;
- call duration;
- call status;
- call summary;
- transcript;
- extracted enquiry fields;
- technical call metadata.
GotAI should be configured to collect the minimum information needed for the customer to understand and return the enquiry.
4.2 Call audio, transcription, and AI output
Calls handled by GotAI may be:
- answered by an AI voice agent;
- processed by speech-to-text systems;
- transcribed;
- summarised;
- analysed to extract enquiry fields;
- temporarily processed to operate, debug, secure, and improve the service.
Where call recording retention is enabled, the caller should be told at the start of the call that the call may be recorded and/or transcribed.
GotAI does not use caller call content to train general-purpose AI models unless this is separately agreed in writing.
4.3 Customer account data
For business customers, GotAI may process:
- customer name;
- business name;
- business address or billing country;
- contact email;
- mobile number;
- payment status;
- subscription status;
- Stripe customer or payment reference;
- service configuration;
- call-routing configuration;
- support communications;
- usage records;
- invoices and billing history.
GotAI does not store card numbers. Card payments are handled by Stripe.
4.4 Website and technical data
When someone visits gotai.ie or contacts GotAI online, GotAI may process:
- IP address;
- browser and device information;
- pages visited;
- timestamps;
- form submissions;
- email enquiries;
- security logs;
- cookie or analytics data where used.
If GotAI later uses non-essential cookies or tracking tools, GotAI must provide any required cookie notice or consent mechanism.
5. Sensitive data restrictions
GotAI is designed for basic business enquiry capture. It is not designed to collect highly sensitive information.
Customers must not configure GotAI to intentionally collect the following unless this has been separately agreed in writing and the customer has confirmed the necessary lawful basis and safeguards:
- PPS numbers;
- passport numbers;
- driver’s licence numbers;
- bank details;
- card details;
- insurance policy numbers;
- medical or health details;
- criminal offence data;
- trade union membership;
- political opinions;
- religious beliefs;
- sexual orientation;
- biometric data;
- detailed financial information;
- passwords or security codes.
If a caller volunteers sensitive information during a call, GotAI may capture it incidentally in the transcript or summary. Where practical, GotAI may delete, redact, or minimise such data.
Customers are responsible for telling callers not to provide unnecessary sensitive information.
6. What we use personal data for
GotAI uses personal data for the following purposes:
6.1 To provide the AI answering service
This includes:
- answering calls;
- collecting enquiry details;
- creating call summaries;
- sending call summaries to the customer;
- routing calls or messages;
- operating call forwarding;
- providing SMS and email notifications;
- maintaining service availability.
6.2 To administer customer accounts
This includes:
- onboarding customers;
- configuring the service;
- billing and payment administration;
- subscription management;
- customer support;
- account communications;
- fraud prevention;
- enforcing the Terms of Service.
6.3 To maintain security and reliability
This includes:
- access controls;
- logging;
- debugging;
- abuse prevention;
- system monitoring;
- incident investigation;
- preventing misuse of the service.
6.4 To meet legal and accounting obligations
This includes:
- keeping invoices and accounting records;
- responding to lawful requests;
- handling disputes;
- complying with applicable Irish and EU law.
6.5 What GotAI does not do
GotAI does not:
- sell caller data;
- use caller data to market to callers;
- make legal, financial, medical, insurance, or emergency-service decisions;
- use the service to make decisions that produce legal or similarly significant effects on callers;
- use caller content to train general-purpose AI models unless separately agreed in writing.
7. Lawful basis
7.1 Where GotAI is controller
Where GotAI acts as controller, GotAI relies on the following lawful bases:
| Processing activity | Lawful basis |
|---|---|
| Creating and managing customer accounts | Contract |
| Providing customer support | Contract and legitimate interests |
| Billing and payment administration | Contract and legal obligation |
| Accounting and tax records | Legal obligation |
| Service security, logging, abuse prevention, and troubleshooting | Legitimate interests |
| Responding to legal claims or disputes | Legitimate interests and legal obligation |
| Website enquiries | Legitimate interests and/or steps prior to contract |
| Optional marketing to customers | Consent or legitimate interests, depending on the context |
7.2 Where GotAI is processor
Where GotAI processes caller enquiry data on behalf of a customer, the customer is responsible for selecting and documenting the lawful basis.
Possible lawful bases may include contract, legitimate interests, consent, legal obligation, or another lawful basis depending on the customer’s business, industry, caller relationship, and call purpose.
GotAI does not decide the customer’s lawful basis for caller data.
7.3 Recording and transcription
Customers are responsible for ensuring that call recording, transcription, and AI processing are lawful for their business and callers.
GotAI can provide a call-opening notice stating that the call may be answered by AI and may be transcribed or recorded for enquiry capture.
Where a customer relies on consent for recording or transcription, the customer must ensure that consent is valid and that callers have a genuine choice.
Where a customer relies on another lawful basis, the customer must ensure that basis is properly documented.
8. Caller notice
Where GotAI answers calls for a customer, the call should include a short notice at or near the start of the call.
Example notice:
Where recording retention is enabled, the notice should say so clearly.
Example recording notice:
The customer is responsible for approving the notice used for its business and ensuring it is suitable for its industry.
9. Third-party processors and sub-processors
GotAI uses third-party service providers to operate the service.
These may include:
| Provider/category | Purpose | Data involved |
|---|---|---|
| AI voice and speech providers, such as Retell | AI call answering, voice processing, transcription, summaries | Caller audio, transcripts, call metadata |
| Phone and telecom providers, such as VoIPLine and Twilio | Call handling, routing, telephony infrastructure | Phone numbers, call metadata, call audio where applicable |
| SMS providers, such as Sinch | Sending enquiry notifications by SMS | Customer phone number, caller enquiry summary |
| Email providers, such as Resend or Zoho | Sending enquiry notifications and service emails | Email address, enquiry summary, service emails |
| Payment provider, Stripe | Payments, subscriptions, billing status | Customer billing data and payment references |
| Hosting, DNS, and security providers, such as Cloudflare | Hosting, security, network delivery | Technical logs, IP addresses, website traffic metadata |
GotAI will use sub-processors only as needed to provide, secure, support, and bill for the service.
GotAI requires sub-processors to process personal data only for the relevant service purpose and under appropriate data-protection terms.
GotAI may update its sub-processors from time to time. Where a change materially affects customer personal data, GotAI will take reasonable steps to notify active customers.
10. International transfers
Some service providers may process data outside the European Economic Area, including in the United States or the United Kingdom.
Where personal data is transferred outside the EEA, GotAI will rely on appropriate safeguards where required, such as:
- European Commission Standard Contractual Clauses;
- UK transfer mechanisms where relevant;
- adequacy decisions where applicable;
- equivalent contractual or organisational safeguards.
Customers acknowledge that AI voice, telecoms, SMS, email, hosting, and payment infrastructure may involve international processing.
11. Retention
GotAI keeps personal data only for as long as needed for the relevant purpose, unless a longer period is required for legal, tax, accounting, security, or dispute reasons.
Default retention periods are:
| Data type | Default retention |
|---|---|
| Caller enquiry summaries | 90 days after the call unless agreed otherwise |
| Caller transcripts | 90 days after the call unless agreed otherwise |
| Call recordings | Off by default; if enabled, 30 days unless agreed otherwise |
| Call metadata and technical logs | Up to 180 days unless needed for security, debugging, billing, or disputes |
| Customer account data | Life of the customer account plus a reasonable closure period |
| Billing, invoice, tax, and accounting records | Generally 6 years |
| Support emails and service correspondence | Up to 2 years after the issue is closed unless needed longer |
| Backups | Deleted or overwritten on the normal backup cycle, usually within 30 to 90 days |
Customer copies of enquiry summaries, SMS messages, emails, CRM entries, or downloaded data are controlled by the customer, not GotAI.
Customers are responsible for their own retention of caller data after GotAI sends it to them.
12. Security
GotAI uses reasonable technical and organisational measures to protect personal data.
These may include:
- access controls;
- limited internal access;
- encryption in transit;
- secure configuration of service providers;
- logging and monitoring;
- least-privilege access where practical;
- separation of customer configurations where practical;
- use of reputable infrastructure providers;
- deletion or minimisation of data no longer needed.
No system is perfectly secure. Customers should avoid sending unnecessary sensitive information through the service.
13. Data breaches
If GotAI becomes aware of a personal data breach affecting caller data processed on behalf of a customer, GotAI will notify the affected customer without undue delay after becoming aware of the breach.
The customer is responsible for deciding whether the breach must be notified to a supervisory authority or affected individuals, unless GotAI is acting as controller for the affected data.
Where GotAI is controller for the affected data, GotAI will handle any required notifications under applicable data-protection law.
14. Data subject rights
Individuals may have rights under GDPR, including:
- access;
- rectification;
- erasure;
- restriction;
- objection;
- data portability;
- rights relating to automated decision-making, where applicable;
- the right to complain to a supervisory authority.
Requests can be sent to hello@gotai.ie.
Where the request concerns caller enquiry data controlled by a GotAI customer, GotAI may need to forward the request to that customer or ask the requester to contact the customer directly.
GotAI will assist customers with data subject requests where required by GDPR and the applicable data processing terms.
GotAI aims to respond to valid requests within one month, subject to identity verification and any lawful extensions or exemptions.
15. Complaints
Individuals have the right to complain to a data protection supervisory authority.
In Ireland, the supervisory authority is the Data Protection Commission.
GotAI encourages individuals to contact GotAI first at david@gotai.ie so that the issue can be reviewed quickly.
16. Automated decision-making
GotAI does not use caller data to make decisions that produce legal effects or similarly significant effects on callers.
GotAI produces enquiry summaries and notifications for the customer. The customer remains responsible for deciding whether and how to respond to the caller.
GotAI does not provide legal, medical, financial, insurance, emergency, or professional advice.
17. Children’s data
GotAI is not aimed at children.
Customers must not configure GotAI to intentionally collect children’s personal data unless this has been separately agreed in writing and the customer has confirmed the necessary lawful basis and safeguards.
18. Customer obligations
Customers using GotAI must:
- have a lawful basis for collecting and using caller data;
- provide appropriate privacy information to callers;
- approve the call notice used by the GotAI agent;
- collect only the minimum caller data needed;
- avoid configuring the service to collect unnecessary sensitive data;
- handle caller data securely after GotAI sends it to them;
- comply with data subject rights requests;
- comply with any sector-specific rules that apply to their business;
- tell GotAI promptly if they need caller data deleted, exported, corrected, or restricted;
- not use GotAI for emergency calls or services where immediate human response is legally or practically required.
19. Data processing terms for customers
This section applies where GotAI processes caller enquiry data as processor on behalf of a customer.
19.1 Subject matter
GotAI processes caller enquiry data to provide AI phone answering, call transcription, enquiry summarisation, notification delivery, service support, and related technical services.
19.2 Duration
Processing continues for the duration of the customer’s subscription and any additional period needed for deletion, backup expiry, legal compliance, billing, dispute handling, or agreed retention.
19.3 Nature and purpose of processing
The nature and purpose of processing are:
- receiving or handling calls;
- converting speech to text;
- generating summaries;
- extracting enquiry fields;
- sending notifications;
- storing enquiry records temporarily;
- maintaining service logs;
- supporting, debugging, securing, and improving the customer’s service configuration.
19.4 Types of personal data
The personal data may include:
- caller identity and contact details;
- call content;
- job or enquiry details;
- location or address where configured;
- call metadata;
- transcripts;
- summaries;
- customer contact details;
- technical logs.
19.5 Categories of data subjects
The categories of data subjects are:
- callers;
- customer staff or representatives;
- GotAI customer contacts;
- other individuals mentioned during a call.
19.6 Customer instructions
GotAI will process caller enquiry data only on the customer’s documented instructions, including the Terms of Service, this policy, customer configuration, written support requests, and any agreed data-processing instructions.
GotAI may process data without customer instruction where required by law. Where legally permitted, GotAI will notify the customer of that requirement.
19.7 Confidentiality
GotAI will ensure that people authorised to process personal data are subject to appropriate confidentiality obligations.
19.8 Security
GotAI will implement reasonable technical and organisational measures appropriate to the risk of the processing.
19.9 Sub-processors
The customer gives GotAI general authorisation to use sub-processors needed to provide the service.
GotAI remains responsible to the customer for sub-processors’ data-processing obligations where required by GDPR.
GotAI will take reasonable steps to ensure sub-processors are bound by appropriate data-protection terms.
19.10 Assistance
Taking into account the nature of the processing and the information available to GotAI, GotAI will reasonably assist the customer with:
- data subject rights requests;
- security obligations;
- personal data breach handling;
- data protection impact assessments where required;
- prior consultation with a supervisory authority where required.
GotAI may charge a reasonable fee for assistance that is excessive, repetitive, outside normal support, or caused by the customer’s own configuration or legal obligations.
19.11 Deletion or return
At the end of the service, GotAI will delete or return caller enquiry data on the customer’s reasonable instruction, unless GotAI is required to retain it by law or for legitimate legal, billing, accounting, security, or dispute reasons.
Data in backups may remain until overwritten or deleted in the normal backup cycle.
19.12 Audit and compliance information
GotAI will make available reasonable information necessary to demonstrate compliance with these data-processing terms.
Audits must be reasonable, proportionate, limited to relevant processing, and subject to confidentiality, security, and operational restrictions.
20. Changes to this policy
GotAI may update this policy from time to time.
Where practical, GotAI will notify active customers of material changes.
The latest version will be maintained at gotai.ie or otherwise made available to customers.
21. Contact
Questions, privacy requests, or data-protection issues should be sent to:
22. Governing law
This policy is governed by the laws of Ireland, unless mandatory data-protection law provides otherwise.