GotAI

GotAI Privacy Policy and Data Processing Terms

This Privacy Policy explains how GotAI handles personal data when providing its AI phone answering service.

It also includes the core data-processing terms that apply when GotAI processes caller enquiry data on behalf of a business customer.

1. Who we are

David Kirwan, trading as GotAI (“GotAI”, “we”, “us”), operates the GotAI AI phone answering service at gotai.ie.

GotAI helps business customers answer missed or diverted phone calls, collect basic enquiry details, produce a call summary, and send that summary to the customer by SMS, email, or another agreed channel.

2. Scope of this policy

This policy covers:

This policy does not replace the business customer’s own privacy notice. The customer remains responsible for explaining to its own callers how it uses caller data.

3. Controller and processor roles

GotAI has different roles depending on the data involved.

3.1 Customer account and service-admin data

For customer account data, billing data, support data, security logs, website enquiries, and GotAI service administration, GotAI is the data controller.

This means GotAI decides why and how that data is used.

3.2 Caller enquiry data

For caller enquiry data collected by GotAI on behalf of a business customer, the customer is normally the data controller and GotAI acts as the customer’s data processor.

This means:

4. Personal data we process

4.1 Caller enquiry data

Depending on the customer’s configuration, GotAI may collect:

GotAI should be configured to collect the minimum information needed for the customer to understand and return the enquiry.

4.2 Call audio, transcription, and AI output

Calls handled by GotAI may be:

Where call recording retention is enabled, the caller should be told at the start of the call that the call may be recorded and/or transcribed.

GotAI does not use caller call content to train general-purpose AI models unless this is separately agreed in writing.

4.3 Customer account data

For business customers, GotAI may process:

GotAI does not store card numbers. Card payments are handled by Stripe.

4.4 Website and technical data

When someone visits gotai.ie or contacts GotAI online, GotAI may process:

If GotAI later uses non-essential cookies or tracking tools, GotAI must provide any required cookie notice or consent mechanism.

5. Sensitive data restrictions

GotAI is designed for basic business enquiry capture. It is not designed to collect highly sensitive information.

Customers must not configure GotAI to intentionally collect the following unless this has been separately agreed in writing and the customer has confirmed the necessary lawful basis and safeguards:

If a caller volunteers sensitive information during a call, GotAI may capture it incidentally in the transcript or summary. Where practical, GotAI may delete, redact, or minimise such data.

Customers are responsible for telling callers not to provide unnecessary sensitive information.

6. What we use personal data for

GotAI uses personal data for the following purposes:

6.1 To provide the AI answering service

This includes:

6.2 To administer customer accounts

This includes:

6.3 To maintain security and reliability

This includes:

This includes:

6.5 What GotAI does not do

GotAI does not:

7. Lawful basis

7.1 Where GotAI is controller

Where GotAI acts as controller, GotAI relies on the following lawful bases:

Processing activity Lawful basis
Creating and managing customer accounts Contract
Providing customer support Contract and legitimate interests
Billing and payment administration Contract and legal obligation
Accounting and tax records Legal obligation
Service security, logging, abuse prevention, and troubleshooting Legitimate interests
Responding to legal claims or disputes Legitimate interests and legal obligation
Website enquiries Legitimate interests and/or steps prior to contract
Optional marketing to customers Consent or legitimate interests, depending on the context

7.2 Where GotAI is processor

Where GotAI processes caller enquiry data on behalf of a customer, the customer is responsible for selecting and documenting the lawful basis.

Possible lawful bases may include contract, legitimate interests, consent, legal obligation, or another lawful basis depending on the customer’s business, industry, caller relationship, and call purpose.

GotAI does not decide the customer’s lawful basis for caller data.

7.3 Recording and transcription

Customers are responsible for ensuring that call recording, transcription, and AI processing are lawful for their business and callers.

GotAI can provide a call-opening notice stating that the call may be answered by AI and may be transcribed or recorded for enquiry capture.

Where a customer relies on consent for recording or transcription, the customer must ensure that consent is valid and that callers have a genuine choice.

Where a customer relies on another lawful basis, the customer must ensure that basis is properly documented.

8. Caller notice

Where GotAI answers calls for a customer, the call should include a short notice at or near the start of the call.

Example notice:

Where recording retention is enabled, the notice should say so clearly.

Example recording notice:

The customer is responsible for approving the notice used for its business and ensuring it is suitable for its industry.

9. Third-party processors and sub-processors

GotAI uses third-party service providers to operate the service.

These may include:

Provider/category Purpose Data involved
AI voice and speech providers, such as Retell AI call answering, voice processing, transcription, summaries Caller audio, transcripts, call metadata
Phone and telecom providers, such as VoIPLine and Twilio Call handling, routing, telephony infrastructure Phone numbers, call metadata, call audio where applicable
SMS providers, such as Sinch Sending enquiry notifications by SMS Customer phone number, caller enquiry summary
Email providers, such as Resend or Zoho Sending enquiry notifications and service emails Email address, enquiry summary, service emails
Payment provider, Stripe Payments, subscriptions, billing status Customer billing data and payment references
Hosting, DNS, and security providers, such as Cloudflare Hosting, security, network delivery Technical logs, IP addresses, website traffic metadata

GotAI will use sub-processors only as needed to provide, secure, support, and bill for the service.

GotAI requires sub-processors to process personal data only for the relevant service purpose and under appropriate data-protection terms.

GotAI may update its sub-processors from time to time. Where a change materially affects customer personal data, GotAI will take reasonable steps to notify active customers.

10. International transfers

Some service providers may process data outside the European Economic Area, including in the United States or the United Kingdom.

Where personal data is transferred outside the EEA, GotAI will rely on appropriate safeguards where required, such as:

Customers acknowledge that AI voice, telecoms, SMS, email, hosting, and payment infrastructure may involve international processing.

11. Retention

GotAI keeps personal data only for as long as needed for the relevant purpose, unless a longer period is required for legal, tax, accounting, security, or dispute reasons.

Default retention periods are:

Data type Default retention
Caller enquiry summaries 90 days after the call unless agreed otherwise
Caller transcripts 90 days after the call unless agreed otherwise
Call recordings Off by default; if enabled, 30 days unless agreed otherwise
Call metadata and technical logs Up to 180 days unless needed for security, debugging, billing, or disputes
Customer account data Life of the customer account plus a reasonable closure period
Billing, invoice, tax, and accounting records Generally 6 years
Support emails and service correspondence Up to 2 years after the issue is closed unless needed longer
Backups Deleted or overwritten on the normal backup cycle, usually within 30 to 90 days

Customer copies of enquiry summaries, SMS messages, emails, CRM entries, or downloaded data are controlled by the customer, not GotAI.

Customers are responsible for their own retention of caller data after GotAI sends it to them.

12. Security

GotAI uses reasonable technical and organisational measures to protect personal data.

These may include:

No system is perfectly secure. Customers should avoid sending unnecessary sensitive information through the service.

13. Data breaches

If GotAI becomes aware of a personal data breach affecting caller data processed on behalf of a customer, GotAI will notify the affected customer without undue delay after becoming aware of the breach.

The customer is responsible for deciding whether the breach must be notified to a supervisory authority or affected individuals, unless GotAI is acting as controller for the affected data.

Where GotAI is controller for the affected data, GotAI will handle any required notifications under applicable data-protection law.

14. Data subject rights

Individuals may have rights under GDPR, including:

Requests can be sent to hello@gotai.ie.

Where the request concerns caller enquiry data controlled by a GotAI customer, GotAI may need to forward the request to that customer or ask the requester to contact the customer directly.

GotAI will assist customers with data subject requests where required by GDPR and the applicable data processing terms.

GotAI aims to respond to valid requests within one month, subject to identity verification and any lawful extensions or exemptions.

15. Complaints

Individuals have the right to complain to a data protection supervisory authority.

In Ireland, the supervisory authority is the Data Protection Commission.

GotAI encourages individuals to contact GotAI first at david@gotai.ie so that the issue can be reviewed quickly.

16. Automated decision-making

GotAI does not use caller data to make decisions that produce legal effects or similarly significant effects on callers.

GotAI produces enquiry summaries and notifications for the customer. The customer remains responsible for deciding whether and how to respond to the caller.

GotAI does not provide legal, medical, financial, insurance, emergency, or professional advice.

17. Children’s data

GotAI is not aimed at children.

Customers must not configure GotAI to intentionally collect children’s personal data unless this has been separately agreed in writing and the customer has confirmed the necessary lawful basis and safeguards.

18. Customer obligations

Customers using GotAI must:

19. Data processing terms for customers

This section applies where GotAI processes caller enquiry data as processor on behalf of a customer.

19.1 Subject matter

GotAI processes caller enquiry data to provide AI phone answering, call transcription, enquiry summarisation, notification delivery, service support, and related technical services.

19.2 Duration

Processing continues for the duration of the customer’s subscription and any additional period needed for deletion, backup expiry, legal compliance, billing, dispute handling, or agreed retention.

19.3 Nature and purpose of processing

The nature and purpose of processing are:

19.4 Types of personal data

The personal data may include:

19.5 Categories of data subjects

The categories of data subjects are:

19.6 Customer instructions

GotAI will process caller enquiry data only on the customer’s documented instructions, including the Terms of Service, this policy, customer configuration, written support requests, and any agreed data-processing instructions.

GotAI may process data without customer instruction where required by law. Where legally permitted, GotAI will notify the customer of that requirement.

19.7 Confidentiality

GotAI will ensure that people authorised to process personal data are subject to appropriate confidentiality obligations.

19.8 Security

GotAI will implement reasonable technical and organisational measures appropriate to the risk of the processing.

19.9 Sub-processors

The customer gives GotAI general authorisation to use sub-processors needed to provide the service.

GotAI remains responsible to the customer for sub-processors’ data-processing obligations where required by GDPR.

GotAI will take reasonable steps to ensure sub-processors are bound by appropriate data-protection terms.

19.10 Assistance

Taking into account the nature of the processing and the information available to GotAI, GotAI will reasonably assist the customer with:

GotAI may charge a reasonable fee for assistance that is excessive, repetitive, outside normal support, or caused by the customer’s own configuration or legal obligations.

19.11 Deletion or return

At the end of the service, GotAI will delete or return caller enquiry data on the customer’s reasonable instruction, unless GotAI is required to retain it by law or for legitimate legal, billing, accounting, security, or dispute reasons.

Data in backups may remain until overwritten or deleted in the normal backup cycle.

19.12 Audit and compliance information

GotAI will make available reasonable information necessary to demonstrate compliance with these data-processing terms.

Audits must be reasonable, proportionate, limited to relevant processing, and subject to confidentiality, security, and operational restrictions.

20. Changes to this policy

GotAI may update this policy from time to time.

Where practical, GotAI will notify active customers of material changes.

The latest version will be maintained at gotai.ie or otherwise made available to customers.

21. Contact

Questions, privacy requests, or data-protection issues should be sent to:

hello@gotai.ie

22. Governing law

This policy is governed by the laws of Ireland, unless mandatory data-protection law provides otherwise.