⚠️ DRAFT — not legal advice. Template for review by a qualified England & Wales / UK data-protection adviser before publication. Complete every [bracketed] placeholder. Scope: this policy covers personal data of website visitors and enquirers. When gptagent processes data on behalf of a business customer (e.g. call recordings, transcripts, and the personal data of that customer’s callers), gptagent acts as a processor under the customer agreement and a Data Processing Agreement (DPA) — that processing is governed by those documents, not this policy.

Privacy Policy

Last updated: [DATE]

1. Who we are (Data Controller)

UPSCLD LLP (trading as “gptagent”), a limited liability partnership registered in England and Wales (LLP number OC453110), registered office 3rd Floor Suite, 207 Regent Street, London, England, W1B 3HH, is the data controller for the personal data described in this policy.

We process personal data in accordance with the UK GDPR and the Data Protection Act 2018.

2. Personal data we collect

We do not intentionally collect special-category data through the website. Please do not send us sensitive personal data via enquiry forms.

3. Why we use it, and our lawful basis (UK GDPR Art. 6)

PurposeLawful basis
Respond to your enquiry; arrange and run a pilot/discovery callSteps at your request prior to a contract / legitimate interests (responding to enquiries)
Operate, secure, and improve the websiteLegitimate interests (running and protecting our site)
Analytics and audience measurementConsent (for non-essential/analytics cookies)
Any marketing communicationsConsent
Comply with legal obligations; establish/defend legal claimsLegal obligation / legitimate interests

Where we rely on legitimate interests, we have assessed that they are not overridden by your rights. Where we rely on consent, you may withdraw it at any time (this does not affect earlier processing).

4. Who we share it with (processors & recipients)

We use trusted third parties who process personal data on our behalf under appropriate contracts, including:

We do not sell your personal data.

5. International transfers

Some of our providers are located outside the UK (including the United States). Where personal data is transferred outside the UK, we rely on appropriate safeguards under UK data-protection law — such as UK adequacy regulations, the International Data Transfer Agreement (IDTA), or the EU Standard Contractual Clauses with the UK Addendum — together with additional measures where needed.

6. Retention

We keep personal data only as long as necessary for the purposes above:

7. Your rights

Under UK GDPR you have the right to: access your data; request rectification; request erasure; restrict or object to processing; request portability; and withdraw consent. To exercise any right, contact privacy@gptagent.ai. We will respond within the statutory time limit and may need to verify your identity.

You also have the right to complain to the UK supervisory authority, the Information Commissioner’s Office (ICO) — ico.org.uk — though we’d appreciate the chance to address your concern first.

8. Security

We use appropriate technical and organisational measures to protect personal data. No method of transmission or storage is completely secure, but we work to protect your information and to notify you and the ICO of any qualifying breach as required.

9. Children

The website is intended for business users and is not directed at children under 18. We do not knowingly collect their personal data.

10. Changes

We may update this policy from time to time; the “Last updated” date reflects the current version. Material changes will be highlighted where appropriate.

11. Contact

Data protection queries: privacy@gptagent.aiUPSCLD LLP, 3rd Floor Suite, 207 Regent Street, London, England, W1B 3HH.