Privacy Policy
Last updated: 18 September 2026
This Privacy Policy explains what personal data FrontDesk AI collects, why we collect it, how we use and protect it, and the rights you have over it. It covers the FrontDesk AI website and the AI receptionist service (the “Service”).
Our two roles: controller and processor
Under data protection law, FrontDesk AI plays two different roles depending on the data:
- We are the controller of the data relating to your own use of FrontDesk AI — your account information, your billing details, and how you use our website. This Privacy Policy explains how we handle that data.
- We are a processor of the conversation data that flows through your AI receptionist — the messages your own customers send and the details captured from them. For that data, the business using FrontDesk AI is the controller, and we process it only on that business's documented instructions under our Data Processing Agreement.
If you are a customer of a business that uses FrontDesk AI and you want to exercise your rights over your personal data, please contact that business directly — they are the controller of that data. We will assist them in responding to your request.
For any questions about this policy or how we handle your data, contact us at [email protected].
What we collect
We keep data collection to what the Service actually needs to work:
- Account information — your name, your business name, and your email address. Your password is stored only as a secure one-way hash; we never store or have access to your actual password.
- Records created by the AI receptionist — conversations with your AI receptionist are processed to answer the customer and to create the records your business needs. What is retained is those records: the lead's name and contact details, appointment and booking details, and the knowledge base you configure. The message-by-message conversation is not retained as a stored transcript. This data belongs to your business; we process it on your behalf so the Service can function.
- Billing information — a Stripe customer ID and subscription ID that link your account to your payment record. Your card details never touch our servers: all payment information is entered directly into Stripe's secure checkout and is handled entirely by Stripe.
- Usage data — basic analytics about how visitors use our website, collected through Google Analytics (for example, pages visited and general region). This helps us understand and improve the Service.
Legal basis for processing (GDPR)
We rely on the following legal bases under the GDPR:
| Data | Purpose | Legal basis |
|---|---|---|
| Account information | Create and manage your account and provide the Service | Performance of a contract |
| Lead, appointment and knowledge base records | Operate the AI receptionist and capture leads on your behalf | Performance of a contract |
| Billing information | Process subscription payments | Performance of a contract; legal obligation |
| Usage / analytics data | Understand and improve the Service | Legitimate interests (or consent where required) |
Sub-processors
We use a small number of trusted service providers to run the Service, each processing data only as needed to provide their part of it. You can see the full, current list — including each provider's role, the data they handle and where they are located — on our sub-processors page.
We do not sell your personal data, and we do not share it for cross-context behavioural advertising.
Data retention
We keep your account information and the records created by the AI receptionist for as long as your subscription is active, so the Service can function and your history stays available to you. If you cancel, all of your data — account details and the records created for your business — is permanently deleted 30 days after cancellation. We retain only the limited billing records we are legally required to keep.
International transfers
Some of our sub-processors may process data outside your country, including outside the European Economic Area. Where that happens, we rely on appropriate safeguards — such as the European Commission's Standard Contractual Clauses — to ensure your data receives an equivalent level of protection.
Security
We maintain technical and organisational measures appropriate to the risk, including:
- account passwords are stored only as a one-way hash, never in a form we can read;
- payment card details never touch our servers — they are entered directly into Stripe's secure systems;
- access to your data is restricted to your authenticated account, enforced on every request to our systems;
- data is encrypted in transit using TLS (HTTPS) across the Service.
No online service can be completely secure, but we work to protect your data and to keep these measures under review. If we ever become aware of a personal data breach affecting your data, we will notify you without undue delay and in any event within 48 hours of becoming aware of it, and will report to supervisory authorities where the law requires.
Cookies
When you first visit our website we show a cookie banner. Essential cookies — which keep you signed in and keep the Service secure — are always on, because the site cannot work without them. We only use analytics and advertising cookies if you give us permission through the banner or the cookie settings panel.
- Essential — sign-in and security. Always active; no consent required.
- Analytics — help us understand how the website is used. Off until you allow them.
- Advertising — let us measure the performance of our ads. Off until you allow them.
Until you choose, analytics and advertising cookies stay switched off. You can accept all, reject all, or choose per category, and you can change your choice at any time using the “Cookie settings” link in the footer. For a full list of the cookies we use, see our Cookie Policy.
Your rights
Under the GDPR and similar laws, you have the right to:
- access the personal data we hold about you;
- have inaccurate data corrected;
- have your data erased;
- restrict or object to how we process your data;
- receive your data in a portable format;
- withdraw consent at any time, where we rely on consent;
- lodge a complaint with a data protection supervisory authority. If you are in the EU, this is the authority in your country of residence; in Bulgaria this is the Commission for Personal Data Protection (CPDP).
How to make a data request
To exercise any of these rights, email us at [email protected] and describe your request. We will respond within the time required by law (normally within one month). We may need to verify your identity before acting on a request.
Changes to this policy
We may update this policy from time to time. When we make material changes, we will update the “Last updated” date above and, where appropriate, notify you by email.