Legal
Privacy policy
Last updated 26 July 2026
Information collection and purpose
We may process the following categories of personal data about you:
- Communication Data that includes any communication that you send to us whether that be through the contact form on our website, through email, text, social media messaging, social media posting or any other communication that you send us.
- Name, email address, telephone numbers, and identities on third party systems that you use to cross authenticate onto our systems.
We process this data for the purposes of verifying your identity and communicating with you; replying to your queries, managing our business relationship, and keeping you informed about products and services you sign up for or expressly enquire about.
Our lawful ground for this processing is our legitimate interests which in this case are to reply to communications sent to us, to keep business records and administer our communication with you about our products and services, managing our commercial relationship, and technically administering our systems.
Connected accounts and Google user data
Some polite.ai features let a workspace administrator connect a third-party account — for example a Google account — so that AI voice agents can act on it during telephone calls: offering appointment times, booking appointments into a calendar, and recognising callers. This section explains how we handle data from connected Google accounts (“Google user data”); the same principles apply to other connected providers such as Microsoft.
We request only the granular OAuth permissions needed for the features you enable, and we access only the data those features require:
- Viewing and managing events on the calendars you select — to offer appointment times and create bookings.
- Reading your list of calendars — so you can choose which calendar receives bookings.
- Reading free/busy availability — to compute open appointment slots without reading the details of your events.
- Reading contacts — to recognise existing callers from their phone number.
- Creating contacts (only where you enable capture) — to save new callers to your address book.
- Your account email address — to label which account is connected.
We use Google user data solely to provide these features to your workspace. We do not sell it and do not use it for advertising. The use of raw or derived user data received from Workspace APIs adheres to the Google User Data Policy, including the Limited Use requirements: no Google user data — raw, aggregated or derived — is used to create, train or improve machine-learning or artificial-intelligence models, whether ours or anyone else’s.
Where an AI model handles a call, feature-scoped results — free appointment slots, a matched caller’s name, or (for tools you explicitly enable) the results of a specific event or contact lookup — are passed to the model transiently, solely to serve that request. We route this data to AI providers only for inference, under terms that do not permit them to use it for training, and we do not run models that learn from it. OAuth tokens themselves are never passed to any model or model provider.
We protect this sensitive data with the following mechanisms:
- All data moving between your browser, our services and Google is encrypted in transit using HTTPS/TLS.
- OAuth credentials are held by a dedicated credential-custody service, isolated from the rest of the platform. The long-lived refresh token is encrypted at rest with AES-256-GCM; short-lived access tokens are held in memory only and expire within an hour.
- Tokens are never exposed to your browser, to callers, to the AI models that handle calls, or to any third party. All requests to Google are made server-side, and agents can invoke only the narrow operations you have configured, authorised by opaque per-agent keys.
- During booking, the AI model receives only free/busy slots and the confirmation of the event it created — not the contents of your calendar.
- Access to systems holding this data is limited to authorised personnel with a business need, who must keep it confidential.
We keep Google account credentials only while the connection is active. If you disconnect the account in the dashboard we delete the stored tokens immediately and ask Google to revoke them; you can also revoke polite.ai’s access at any time from your Google account permissions page. Events booked by your agents live in your own calendar, not on our systems. You can ask us to delete any remaining data associated with a connection by emailing hello@aplisay.uk.
Data retention
We will only retain your personal data for as long as necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements.
Your legal rights
Under data protection laws you have rights in relation to your personal data that include the right to request access, correction, erasure, restriction, transfer, to object to processing, to portability of data and (where the lawful ground of processing is consent) to withdraw consent. You can see more about these rights at the ICO website.
If you wish to exercise any of the rights set out above, please email us at hello@aplisay.uk. You will not have to pay a fee to access your personal data (or to exercise any of the other rights), however, we may charge a reasonable fee if your request is clearly unfounded, repetitive or excessive or refuse to comply with your request in these circumstances.
We may need to request specific information from you to help us confirm your identity and ensure your right to access your personal data (or to exercise any of your other rights). This is a security measure to ensure that personal data is not disclosed to any person who has no right to receive it.
We may also contact you to ask you for further information in relation to your request to speed up our response. We try to respond to all legitimate requests within one month. Occasionally it may take us longer than a month if your request is particularly complex or you have made a number of requests. In this case, we will notify you. If you are not happy with any aspect of how we collect and use your data, you have the right to complain to the Information Commissioner’s Office (ICO), the UK supervisory authority for data protection issues (www.ico.org.uk). We should be grateful if you would contact us first if you do have a complaint so that we can try to resolve it for you.
Third party links
This website may include links to third-party websites, plug-ins and applications. Clicking on those links or otherwise connecting to those services may allow third parties to collect or share data about you. We do not control these third-party websites and are not responsible for their privacy statements. When you leave our website, we encourage you to read the privacy notice of every website you visit.
Acceptance of terms
By accessing and using this website, you agree to be bound by these Terms and Conditions of Use. If you do not agree with any part of these terms, you must not use the website. By accessing or using our website, you consent to the practices described in this policy.
Changes to terms
We reserve the right to modify or replace these terms at our sole discretion. It is your responsibility to check these terms periodically for changes. Your continued use of the website after the posting of any changes constitutes acceptance of those changes.
User conduct
You agree to use this website only for lawful purposes and in a manner consistent with all applicable local, national, and international laws and regulations.
Intellectual property
All content on this website, including but not limited to text, graphics, logos, images, audio clips, video clips, digital downloads, and data compilations, is the property of Aplisay Ltd or its content suppliers and protected by international copyright laws.
User-generated content
If you submit any material to this website, you grant Aplisay a perpetual, royalty-free, worldwide licence to use, reproduce, modify, adapt, publish, translate, create derivative works from, distribute, and display such material.
Limitation of liability
In no event shall Aplisay or its affiliates be liable for any direct, indirect, incidental, special, or consequential damages resulting from the use or inability to use this website.
Indemnity
You agree to indemnify and hold harmless Aplisay and its affiliates from any claims, actions, demands, damages, liabilities, costs, or expenses, including reasonable legal fees, arising out of or related to your use of the website or any violation of these terms.
Governing law
These terms are governed by and construed in accordance with the laws of the United Kingdom, without regard to its conflict of law principles.