Auxilia Front Desk

Legal

Privacy Policy

Last updated: 24 July 2026

1. Who we are

Auxilia Front Desk ("Auxilia", "we", "us", "our") provides automated customer-support services via WhatsApp, Instagram and website chat for small businesses. We act as the data controller for personal data processed through our platform.

Contact us at: [email protected]

2. What data we collect

When you or your customers interact with our automated messaging service, we may process the following categories of personal data:

  • Customer names
  • Phone numbers (including WhatsApp numbers)
  • WhatsApp messages and conversation history
  • Voice notes sent via WhatsApp
  • Images and media shared in conversations
  • Booking enquiries and appointment details
  • Technical data (IP addresses, device identifiers, timestamps)

3. How we use your data

We process personal data for the following purposes:

  • Providing automated customer-support and enquiry-handling services
  • Processing and confirming bookings and appointments
  • Sending automated reminders and follow-up messages
  • Improving the accuracy and quality of automated responses
  • Complying with legal obligations

Our lawful basis for processing is legitimate interests (providing the contracted service) and, where required, consent.

4. Third-party processors

To deliver our services, your data may be processed by the following third-party sub-processors:

  • Meta (WhatsApp Business API) — for message delivery and management
  • Make (formerly Integromat) — for workflow automation
  • OpenAI — for AI-powered response generation
  • Connected booking or email services — as configured for your business

All processors are contractually required to handle data securely and in accordance with applicable data protection law.

5. Data retention

We retain personal data only for as long as necessary to provide our services or as required by law. Conversation data is typically retained for up to 12 months unless a shorter period is requested or a longer period is legally required. You may request deletion at any time (see Section 7).

6. Data security

We implement appropriate technical and organisational measures to protect personal data against unauthorised access, loss, destruction or alteration. Access to personal data is restricted to authorised personnel only.

7. Your rights (UK GDPR)

Under UK GDPR, you have the right to:

  • Access — request a copy of the personal data we hold about you
  • Rectification — request correction of inaccurate or incomplete data
  • Erasure — request deletion of your personal data
  • Restriction — request that we limit how we use your data
  • Portability — receive your data in a structured, machine-readable format
  • Object — object to processing based on legitimate interests

To exercise any of these rights, email us at [email protected]. We will respond within 30 days. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO).

8. Data transfers

Some of our sub-processors may process data outside the UK or EEA. Where this occurs, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses or adequacy decisions, in accordance with UK GDPR requirements.

9. We do not sell your data

We do not sell, rent or trade personal data to third parties for marketing or any other commercial purpose.

10. Changes to this policy

We may update this Privacy Policy from time to time. The "Last updated" date at the top of this page will reflect any changes. Continued use of our services after an update constitutes acceptance of the revised policy.

11. Contact us

For any privacy-related questions or to exercise your rights, please contact us at: [email protected]