Legal
Privacy policy
Last updated 14 September 2026
Information collection and purpose
We may process the following categories of personal data about you:
- Communication Data that includes any communication that you send to us whether that be through the contact form on our website, through email, text, social media messaging, social media posting or any other communication that you send us.
- Name, email address, telephone numbers, and identities on third party systems that you use to cross authenticate onto our systems.
- Usage Data, which is how you move through our website: the pages you view, how far you read, the links you follow, which form fields you begin and which you leave empty, the site or campaign that referred you, the country your connection resolves to, and the general type of browser you use. We do not record what you type into a field unless you submit it to us.
- Incomplete submissions. If you begin a request for an invite and it is not accepted, we keep what you entered and the reason it was not accepted, so that we can fix the problem or contact you about it.
- Session recordings, while you are taking part in our beta. These record how you move through the product so we can find what gets in your way. Passwords and payment details are never recorded, and other fields that may hold personal information are masked. You can turn this off at any time in your account settings, which stops new recording immediately.
Where you submit a form to us, we may associate the Usage Data above with that submission, so that we can understand what led to it and why it may have failed. Usage Data from visits that do not submit anything is not associated with any individual.
We process this data for the purposes of verifying your identity and communicating with you; replying to your queries, managing our business relationship, and keeping you informed about products and services you sign up for or expressly enquire about.
Our lawful ground for this processing is our legitimate interests which in this case are to reply to communications sent to us, to keep business records and administer our communication with you about our products and services, managing our commercial relationship, and technically administering our systems.
Measuring how our website and product are used, including the session recordings described above, is also carried out under our legitimate interests: we cannot fix what we cannot see, and a product that is hard to use is a problem for the people using it as much as for us. We hold ourselves to three limits that make this reasonable. We do not collect special category data through it. We do not sell it, and we do not share it with anyone outside Aplisay Ltd in a form that identifies you. And we keep it only for the periods set out under Data retention.
Because this rests on our legitimate interests rather than your consent, you have the right to object to it at any time and without giving a reason. For session recording you can do this yourself: the switch is in your account settings, and turning it off stops new recording at once. For anything else described here, email us at hello@polite.ai and we will stop unless we have compelling grounds not to, which we would explain to you.
Connected accounts and Google user data
Some polite.ai features let a workspace administrator connect a third-party account — for example a Google account — so that AI voice agents can act on it during telephone calls: offering appointment times, booking appointments into a calendar, and recognising callers. This section explains how we handle data from connected Google accounts (“Google user data”); the same principles apply to other connected providers such as Microsoft.
We request only the granular OAuth permissions needed for the features you enable, and we access only the data those features require:
- Viewing and managing events on the calendars you select — to offer appointment times and create bookings.
- Reading your list of calendars — so you can choose which calendar receives bookings.
- Reading free/busy availability — to compute open appointment slots without reading the details of your events.
- Reading contacts — to recognise existing callers from their phone number.
- Creating contacts (only where you enable capture) — to save new callers to your address book.
- Your account email address — to label which account is connected.
We use Google user data solely to provide these features to your workspace. We do not sell it and do not use it for advertising. The use of raw or derived user data received from Workspace APIs adheres to the Google User Data Policy, including the Limited Use requirements: no Google user data — raw, aggregated or derived — is used to create, train or improve machine-learning or artificial-intelligence models, whether ours or anyone else’s.
Where an AI model handles a call, feature-scoped results — free appointment slots, a matched caller’s name, or (for tools you explicitly enable) the results of a specific event or contact lookup — are passed to the model transiently, solely to serve that request. We route this data to AI providers only for inference, under terms that do not permit them to use it for training, and we do not run models that learn from it. OAuth tokens themselves are never passed to any model or model provider.
We protect this sensitive data with the following mechanisms:
- All data moving between your browser, our services and Google is encrypted in transit using HTTPS/TLS.
- OAuth credentials are held by a dedicated credential-custody service, isolated from the rest of the platform. The long-lived refresh token is encrypted at rest with AES-256-GCM; short-lived access tokens are held in memory only and expire within an hour.
- Tokens are never exposed to your browser, to callers, to the AI models that handle calls, or to any third party. All requests to Google are made server-side, and agents can invoke only the narrow operations you have configured, authorised by opaque per-agent keys.
- During booking, the AI model receives only free/busy slots and the confirmation of the event it created — not the contents of your calendar.
- Access to systems holding this data is limited to authorised personnel with a business need, who must keep it confidential.
We keep Google account credentials only while the connection is active. If you disconnect the account in the dashboard we delete the stored tokens immediately and ask Google to revoke them; you can also revoke polite.ai’s access at any time from your Google account permissions page. Events booked by your agents live in your own calendar, not on our systems. You can ask us to delete any remaining data associated with a connection by emailing hello@polite.ai.
Data retention
We will only retain your personal data for as long as necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements.
Some periods are fixed. Records of how our website was used, incomplete form submissions, and beta session recordings are deleted after 90 days. Aggregate counts that cannot identify anyone may be kept for longer.
Your legal rights
Under data protection laws you have rights in relation to your personal data that include the right to request access, correction, erasure, restriction, transfer, to object to processing, to portability of data and (where the lawful ground of processing is consent) to withdraw consent. You can see more about these rights at the ICO website.
If you wish to exercise any of the rights set out above, please email us at hello@polite.ai. You will not have to pay a fee to access your personal data (or to exercise any of the other rights), however, we may charge a reasonable fee if your request is clearly unfounded, repetitive or excessive or refuse to comply with your request in these circumstances.
We may need to request specific information from you to help us confirm your identity and ensure your right to access your personal data (or to exercise any of your other rights). This is a security measure to ensure that personal data is not disclosed to any person who has no right to receive it.
We may also contact you to ask you for further information in relation to your request to speed up our response. We try to respond to all legitimate requests within one month. Occasionally it may take us longer than a month if your request is particularly complex or you have made a number of requests. In this case, we will notify you. If you are not happy with any aspect of how we collect and use your data, you have the right to complain to the Information Commissioner’s Office (ICO), the UK supervisory authority for data protection issues (www.ico.org.uk). We should be grateful if you would contact us first if you do have a complaint so that we can try to resolve it for you.
Third party links
This website may include links to third-party websites, plug-ins and applications. Clicking on those links or otherwise connecting to those services may allow third parties to collect or share data about you. We do not control these third-party websites and are not responsible for their privacy statements. When you leave our website, we encourage you to read the privacy notice of every website you visit.
Acceptance of terms
By accessing and using this website, you agree to be bound by these Terms and Conditions of Use. If you do not agree with any part of these terms, you must not use the website. By accessing or using our website, you consent to the practices described in this policy.
Changes to terms
We reserve the right to modify or replace these terms at our sole discretion. It is your responsibility to check these terms periodically for changes. Your continued use of the website after the posting of any changes constitutes acceptance of those changes.
User conduct
You agree to use this website only for lawful purposes and in a manner consistent with all applicable local, national, and international laws and regulations.
Intellectual property
All content on this website, including but not limited to text, graphics, logos, images, audio clips, video clips, digital downloads, and data compilations, is the property of Aplisay Ltd or its content suppliers and protected by international copyright laws.
User-generated content
If you submit any material to this website, you grant Aplisay a perpetual, royalty-free, worldwide licence to use, reproduce, modify, adapt, publish, translate, create derivative works from, distribute, and display such material.
Limitation of liability
In no event shall Aplisay or its affiliates be liable for any direct, indirect, incidental, special, or consequential damages resulting from the use or inability to use this website.
Indemnity
You agree to indemnify and hold harmless Aplisay and its affiliates from any claims, actions, demands, damages, liabilities, costs, or expenses, including reasonable legal fees, arising out of or related to your use of the website or any violation of these terms.
Governing law
These terms are governed by and construed in accordance with the laws of the United Kingdom, without regard to its conflict of law principles.