Privacy
Privacy Policy
Last updated: July 2026
This policy explains how Aether Reception handles personal data when providing managed AI front desk, lead capture, booking request, notification, and dashboard services.
1. Who we are
Aether Reception provides a managed AI front desk system for businesses. The service helps businesses answer calls, capture enquiries, create booking requests, summarise calls, and manage follow-up through a private dashboard.
For general privacy questions, contact Aether Reception at aetherreceptionenquiries@gmail.com.
2. Controller and processor roles
For caller, lead, and customer enquiry data, the client business using Aether is normally the data controller. The client decides why the data is collected and how it is used.
Aether normally acts as a data processor for that caller and lead data, processing it on the client’s behalf to provide call handling, lead capture, booking request, notification, dashboard, and support services.
For Aether’s own business contacts, prospects, billing contacts, and website enquiries, Aether may act as the data controller.
3. What data we process
Depending on configuration, Aether may process caller name, phone number, email address where provided, reason for calling, call summaries, booking request details, preferred appointment times, business contact details, dashboard user account details, call metadata such as time, duration, and status, and support or onboarding information provided by the client.
4. Why we process data
We process data to answer and handle calls, capture leads and enquiries, create booking requests, send lead notifications, provide dashboard access, support and improve the receptionist setup, monitor service performance, troubleshoot issues, provide customer support, and manage billing or client communication.
5. Legal basis
Where Aether acts as processor, the client is responsible for identifying the lawful basis for processing caller data. This may include legitimate interests, contract-related processing, or consent depending on the client’s business and call handling practices.
Where Aether acts as controller for its own business contacts and enquiries, the legal basis may include legitimate interests, performance of a contract, taking steps before entering a contract, legal obligations, or consent where applicable.
6. Call recording, transcripts, and summaries
If call recording or transcripts are enabled through a voice provider, the client should inform callers where required by law. Clients are responsible for their own caller notices, call-recording notices, and compliance with UK GDPR, PECR, and any sector-specific obligations.
Aether may process call summaries, transcripts where enabled, and call metadata to provide the service, troubleshoot issues, improve receptionist configuration, and support launch tuning.
7. Sub-processors and third-party providers
Aether may use third-party providers to deliver the service. These may include hosting providers, database providers, voice AI providers, email notification providers, payment processors, telecoms providers, analytics, monitoring, and support tools.
Current or planned provider categories include hosting and deployment, database hosting, voice AI/call handling, email delivery, payments, and telecoms/SMS where enabled. Aether will use reasonable care when selecting providers and will only use them as needed to deliver the service.
8. International transfers
Some service providers may process or access data outside the United Kingdom. Where international transfers occur, Aether will seek to rely on appropriate safeguards such as standard contractual clauses, adequacy regulations, or provider transfer mechanisms where applicable.
9. Data sharing
Aether does not sell caller data. Data may be shared with the client business using Aether and with service providers required to operate the system. Data may also be disclosed where required by law or to protect the security and integrity of the service.
10. Data retention
Aether retains call, lead, booking, dashboard, and support data for as long as needed to provide the service, unless a different retention period is agreed with the client.
As a default MVP position, call logs, leads, summaries, and booking requests may be retained while the client account remains active. Clients may request deletion or export of relevant data, subject to operational, legal, security, or billing requirements.
If call recordings or full transcripts are enabled through a third-party voice provider, retention may also depend on that provider’s configuration and the client’s agreed setup.
11. Security
Aether uses reasonable technical and organisational measures to protect data, including secure hosting, protected dashboard access, environment-based secret management, restricted access to operational systems, and care around API keys and credentials.
No system can be guaranteed 100% secure, but Aether takes security seriously and works to reduce risk.
12. Client responsibilities
Clients are responsible for informing callers where required, maintaining their own privacy notices, confirming whether calls are recorded, identifying a lawful basis for processing, responding to data subject requests from their customers, and using captured leads and caller data lawfully.
13. Data subject rights
Individuals may have rights to access, correct, delete, restrict, or object to processing of their personal data. They may also have rights relating to portability or complaints to the ICO depending on the circumstances.
Requests about caller or customer data should normally be made to the business the caller contacted, as that business is usually the controller. Aether may assist clients with reasonable data requests where applicable.
14. Data Processing Agreement
Where required, Aether can provide or agree a Data Processing Agreement with business clients to document processor obligations, sub-processor use, security measures, assistance with data subject requests, and data handling on termination.
15. ICO and data protection fee
UK organisations that process personal data may need to register with the Information Commissioner’s Office and pay a data protection fee unless exempt. Clients are responsible for their own registration obligations. Aether will review its own registration requirements as the service develops.
16. Changes to this policy
Aether may update this Privacy Policy from time to time as the service, providers, or legal requirements change. The latest version will be published on this page.
Contact
For privacy questions, contact Aether Reception at aetherreceptionenquiries@gmail.com.