Privacy Policy

Last updated: 18 September 2026

This Privacy Policy explains what personal data FrontDesk AI collects, why we collect it, how we use and protect it, and the rights you have over it. It covers the FrontDesk AI website and the AI receptionist service (the “Service”).

Our two roles: controller and processor

Under data protection law, FrontDesk AI plays two different roles depending on the data:

  • We are the controller of the data relating to your own use of FrontDesk AI — your account information, your billing details, and how you use our website. This Privacy Policy explains how we handle that data.
  • We are a processor of the conversation data that flows through your AI receptionist — the messages your own customers send and the details captured from them. For that data, the business using FrontDesk AI is the controller, and we process it only on that business's documented instructions under our Data Processing Agreement.

If you are a customer of a business that uses FrontDesk AI and you want to exercise your rights over your personal data, please contact that business directly — they are the controller of that data. We will assist them in responding to your request.

For any questions about this policy or how we handle your data, contact us at [email protected].

What we collect

We keep data collection to what the Service actually needs to work:

  • Account information — your name, your business name, and your email address. Your password is stored only as a secure one-way hash; we never store or have access to your actual password.
  • Records created by the AI receptionist — conversations with your AI receptionist are processed to answer the customer and to create the records your business needs. What is retained is those records: the lead's name and contact details, appointment and booking details, and the knowledge base you configure. The message-by-message conversation is not retained as a stored transcript. This data belongs to your business; we process it on your behalf so the Service can function.
  • Billing information — a Stripe customer ID and subscription ID that link your account to your payment record. Your card details never touch our servers: all payment information is entered directly into Stripe's secure checkout and is handled entirely by Stripe.
  • Usage data — basic analytics about how visitors use our website, collected through Google Analytics (for example, pages visited and general region). This helps us understand and improve the Service.

Legal basis for processing (GDPR)

We rely on the following legal bases under the GDPR:

DataPurposeLegal basis
Account informationCreate and manage your account and provide the ServicePerformance of a contract
Lead, appointment and knowledge base recordsOperate the AI receptionist and capture leads on your behalfPerformance of a contract
Billing informationProcess subscription paymentsPerformance of a contract; legal obligation
Usage / analytics dataUnderstand and improve the ServiceLegitimate interests (or consent where required)

Sub-processors

We use a small number of trusted service providers to run the Service, each processing data only as needed to provide their part of it. You can see the full, current list — including each provider's role, the data they handle and where they are located — on our sub-processors page.

We do not sell your personal data, and we do not share it for cross-context behavioural advertising.

Data retention

We keep your account information and the records created by the AI receptionist for as long as your subscription is active, so the Service can function and your history stays available to you. If you cancel, all of your data — account details and the records created for your business — is permanently deleted 30 days after cancellation. We retain only the limited billing records we are legally required to keep.

International transfers

Some of our sub-processors may process data outside your country, including outside the European Economic Area. Where that happens, we rely on appropriate safeguards — such as the European Commission's Standard Contractual Clauses — to ensure your data receives an equivalent level of protection.

Security

We maintain technical and organisational measures appropriate to the risk, including:

  • account passwords are stored only as a one-way hash, never in a form we can read;
  • payment card details never touch our servers — they are entered directly into Stripe's secure systems;
  • access to your data is restricted to your authenticated account, enforced on every request to our systems;
  • data is encrypted in transit using TLS (HTTPS) across the Service.

No online service can be completely secure, but we work to protect your data and to keep these measures under review. If we ever become aware of a personal data breach affecting your data, we will notify you without undue delay and in any event within 48 hours of becoming aware of it, and will report to supervisory authorities where the law requires.

Cookies

When you first visit our website we show a cookie banner. Essential cookies — which keep you signed in and keep the Service secure — are always on, because the site cannot work without them. We only use analytics and advertising cookies if you give us permission through the banner or the cookie settings panel.

  • Essential — sign-in and security. Always active; no consent required.
  • Analytics — help us understand how the website is used. Off until you allow them.
  • Advertising — let us measure the performance of our ads. Off until you allow them.

Until you choose, analytics and advertising cookies stay switched off. You can accept all, reject all, or choose per category, and you can change your choice at any time using the “Cookie settings” link in the footer. For a full list of the cookies we use, see our Cookie Policy.

Your rights

Under the GDPR and similar laws, you have the right to:

  • access the personal data we hold about you;
  • have inaccurate data corrected;
  • have your data erased;
  • restrict or object to how we process your data;
  • receive your data in a portable format;
  • withdraw consent at any time, where we rely on consent;
  • lodge a complaint with a data protection supervisory authority. If you are in the EU, this is the authority in your country of residence; in Bulgaria this is the Commission for Personal Data Protection (CPDP).

How to make a data request

To exercise any of these rights, email us at [email protected] and describe your request. We will respond within the time required by law (normally within one month). We may need to verify your identity before acting on a request.

Changes to this policy

We may update this policy from time to time. When we make material changes, we will update the “Last updated” date above and, where appropriate, notify you by email.