1. Who We Are
ConvertNest.biz is the trading name of ConvertNest Limited, a company registered in England and Wales (Company No. 17124946). We provide AI receptionist services (Zara), call automation, website design, CRM integration, and related digital services for SMBs. References to "we", "us", or "our" refer to ConvertNest Limited.
Email: info@convertnest.biz
ICO Registration No.: [ICO Reg No. — to be added on registration]
2. What Data We Collect
From prospective and existing clients:
- Contact information: name, email address, phone number
- Business information: business name, industry, requirements
- Payment data: processed securely via Stripe (we do not store card details)
- Chat data: messages submitted via our website chat widget
- Technical data: IP address, browser type, pages visited (via analytics)
From callers handled by our Zara AI receptionist service (on behalf of our clients):
- Caller name and phone number
- Call transcripts and conversation content
- Call recordings (where enabled by the client)
- Appointment details: date, time, service requested
- Email address (if provided by the caller)
When processing caller data on behalf of a client, ConvertNest acts as a Data Processor. The client business is the Data Controller for their callers' data and is responsible for ensuring callers are informed that calls may be handled by an AI system.
3. How We Collect It
- Directly from you: via contact forms, chat widget, email, or phone
- Via telephony: through calls handled by our Zara AI system on behalf of clients
- Automatically: via cookies and analytics tools when you visit our website
4. Why We Use It (Legal Basis)
- To deliver the services you have engaged us for — contract performance
- To respond to enquiries — legitimate interests
- To send service-related communications — contract performance
- To process payments — contract performance
- To improve our services and AI systems — legitimate interests
- To comply with legal and regulatory obligations — legal obligation
5. Third-Party Processors
We do not sell your data. We share data only with trusted sub-processors who help us deliver our services. All are contractually bound to handle data securely and in accordance with UK GDPR:
- Twilio — telephony infrastructure and call handling (US-based; Standard Contractual Clauses in place)
- OpenAI — AI processing for call and chat automation (US-based; Standard Contractual Clauses in place)
- Amazon Web Services (S3) — secure cloud storage for call logs and data (EU region: eu-west-2, London)
- Google Workspace — business email communications and email delivery (US-based; Standard Contractual Clauses in place)
- Stripe — payment processing (US-based; Standard Contractual Clauses in place)
- Google Analytics — website analytics, main site only
6. International Data Transfers
Some of our sub-processors are based outside the UK (primarily in the United States). Where data is transferred internationally, we ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) approved under UK GDPR. Our primary data storage (AWS S3) is in the EU West 2 region (London).
7. How Long We Keep It
- Enquiry and lead data: up to 2 years
- Client account and project data: up to 6 years (accounting and legal requirements)
- Call transcripts and logs: up to 12 months, unless otherwise agreed in writing
- Call recordings: up to 12 months, unless the client requests earlier deletion
- Payment records: up to 7 years (HMRC requirements)
- Analytics data: as per provider retention policies
8. Your Rights
Under UK GDPR you have the right to:
- Access the personal data we hold about you
- Correct inaccurate or incomplete data
- Request deletion of your data ("right to be forgotten")
- Object to or restrict processing
- Data portability (receive your data in a machine-readable format)
- Withdraw consent at any time (where processing is based on consent)
To exercise any of these rights, email info@convertnest.biz. We will respond within 30 days. We may need to verify your identity before processing your request.
If you are a caller whose data was collected via a client's Zara service, please contact that business directly as they are the Data Controller for your data.
9. Call Recording & AI Disclosure
Where our Zara AI receptionist service is deployed by a client business, calls may be handled by an AI system and may be recorded. It is the client's responsibility under UK GDPR and PECR to inform callers of this before or at the start of each call. ConvertNest provides guidance on compliant call handling to all clients.
10. Cookies
We use cookies on our website. See our Cookie Policy for full details.
11. Data Processing Agreements
Business clients using our Zara AI receptionist service may request a Data Processing Agreement (DPA) at any time by emailing info@convertnest.biz.
12. Changes to This Policy
We may update this policy from time to time. The latest version will always be posted on this page with the date of last update shown above.
13. Contact & Complaints
For any privacy concerns, email info@convertnest.biz.
If you are unhappy with how we have handled your data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk or by calling 0303 123 1113.