LEGAL INFORMATION · 2026-09-08.2
Privacy policy
How Strath AI handles personal information. Updated 8 September 2026. This notice covers visitors, subscribers and people whose information is processed through the service.
1. Identity and contact
Strathern OPEX Consulting Ltd (company number 17166345), trading as Strath AI, is based at 11 Aske Road, Redcar, TS10 2BS, United Kingdom. Contact support@strath.io with a privacy request or write to this address, marked Privacy.
We are controller for our own subscriber administration, billing, website security and support. For information a business processes about its callers and customers through our receptionist and CRM, that business normally acts as controller and we act as its processor. Its privacy notice explains its purposes and lawful basis.
2. Information and sources
You supply account and business contact details, settings, registration details, support messages and information entered into the diary or CRM. Callers supply their telephone number and information spoken during a call. Businesses may enter information received elsewhere, such as an existing customer’s job or contact details.
We receive subscription, invoice, payment-status and transaction references from Stripe; call identifiers, timing, usage and outcomes from voice providers; and message delivery information from messaging providers. Stripe collects payment details through its hosted payment facilities. Our application does not need your full card number or card security code.
Technical records can include IP address, browser/device information, request timestamps, authentication and security events. Calls are processed by AI voice services and may generate summaries, enquiries and bookings. The current receptionist uses minimal provider storage rather than retaining full recordings and transcripts by default; this does not mean speech is never transmitted or processed. Where recordings or full transcripts are retained, the retention schedule below applies.
3. Purposes and lawful bases
For an individual subscriber, we process information necessary to enter and perform the service contract, including setup, account access, billing and support. For representatives of a business subscriber, our legitimate interest is administering and supporting that business relationship. We also rely on proportionate legitimate interests to secure the service, detect abuse, investigate faults and establish or defend claims, taking account of individuals’ rights.
We retain necessary accounting and other legally required records to comply with legal obligations. If we ask for consent for optional processing, we identify that purpose separately and you can withdraw consent without affecting earlier lawful processing. We do not treat agreement to contractual terms as blanket consent to marketing or unrelated use of personal data.
For caller and CRM information processed on a customer’s behalf, we follow that customer’s documented instructions. Supplying essential account, billing and number-registration information is necessary to provide the relevant features; without it we may be unable to activate or maintain them. Optional fields are identified in the service.
4. Recipients and international processing
The service uses Supabase for database and authentication, Render for application hosting and workers, Retell for AI voice processing, Twilio for telephony/registration/SMS, Resend for email and Stripe for payments. Where address lookup is used, relevant address/postcode queries may be sent to Ideal Postcodes. Providers may use their own contracted subprocessors. Payment providers can act as independent controllers for some purposes.
Authorised personnel may access relevant records to provide support, correct settings, investigate incidents or fulfil a request. Information may also be disclosed to professional advisers, regulators or authorities where necessary and lawful, or in a business transfer subject to appropriate protections. We do not sell customer personal information.
Database and application hosting in Europe does not make the service UK-only or EU-only: voice, email, payment and support processing can involve other countries, including the United States. Supplier-specific transfer mechanisms and assessments are being verified before new paid subscriptions open. We do not represent an unverified supplier agreement or adequacy certification as already in place. Contact us for the applicable supplier information and copies or a description of relevant safeguards.
5. Retention
Our approved schedule is: recordings and full transcripts, where retained, 30 days from the call; call summaries and notification content, 12 months from creation; closed support tickets, 12 months from closure; security and administrator audit records, 12 months from the event; temporary provider export files, 24 hours from generation.
CRM and job records are kept while the account is active and they remain necessary, with annual review of inactive records. Operational data is scheduled for deletion within 30 days of account closure. Necessary company accounting records are retained for six years from the relevant financial year end, or longer where a specific legal obligation applies.
A valid erasure request may shorten a period. A documented legal obligation or hold may require limited longer retention, with restricted use. Provider expiry jobs and backup cycles mean removal from every copy is not instantaneous. Supabase’s configured daily database backups have a seven-day retention window; downloaded exports and independent provider records require separate handling. We record unresolved exceptions rather than claiming complete deletion. Contact us for the status and scope of a particular request.
6. Your rights and complaints
Depending on the circumstances, you can request access, correction, erasure, restriction and portability. You can object to processing based on legitimate interests, and object at any time to direct marketing. Where processing depends on consent, you can withdraw it. These rights are subject to applicable legal conditions; we will explain any refusal or retained exception.
Email support@strath.io with enough information to identify the relevant account or interaction. Do not send passwords, payment-card details or identity documents unless we explain a secure and necessary verification process. We may need proportionate identity or authority checks. We normally respond within one month, with extensions or permitted pauses explained where applicable law allows them. Requests are normally free.
If you called one of our customers, contact that business first about its service records. We will help route a request and assist the controller. You may complain to the UK Information Commissioner’s Office at ico.org.uk/make-a-complaint/ or telephone 0303 123 1113. You do not have to complain to us first.
7. Cookies, browser storage and communications
Authentication cookies and browser storage support sign-in, session security and sign-out. The workspace records recent activity locally to enforce its inactivity timeout. Your cookie-popup choice is stored in this browser until you change it or clear browser storage. Use Cookie settings in the footer to reopen the choices; neither choice authorises future optional tracking. Blocking necessary storage can prevent account features working. This website does not currently add advertising or analytics trackers through the application.
Account, billing and service messages are operational communications. Any future optional marketing or non-essential tracking will require its own applicable notice and choice. Third-party services you choose to visit, including hosted payment pages, operate under their own notices.
8. Security, AI and changes
Access restrictions, tenant controls, administrator verification and encrypted connections help protect information. No system can be guaranteed free of error or compromise. Report suspected disclosure or account misuse to support@strath.io. We assess incidents and make notifications required by applicable law and customer agreements.
AI processing is used to answer enquiries and assist with appointments, not to make solely automated decisions intended to have legal or similarly significant effects. Ask the business for human assistance where an answer is important or appears incorrect. The service is intended for business subscribers, not for accounts held by children.
We update this notice when practices or requirements change, show the revision date and provide additional notice where a change materially affects people. A change to this notice does not itself authorise an incompatible new use of personal data.
Questions? Contact support@strath.io.