Skip to content
AgentLane

Privacy Policy

Last updated: 1 August 2026

AgentLane ("we", "us", or "our") provides AI-powered communication automation services to businesses and agencies. This Privacy Policy explains how we collect, use, store, and protect personal data when you use our services, interact with our AI agents, or visit our website.

We act as a data processor under the UK General Data Protection Regulation (UK GDPR) and the EU General Data Protection Regulation (EU GDPR) for the personal data we process on behalf of our business clients. Our clients (aesthetics clinics, dental practices, home service businesses, and their agencies) act as the data controllers for their own customer data.

1. Who We Are

Controller / Processor: AgentLane Role: Data Processor (for end-customer data) / Data Controller (for website visitors and agency partners) ICO Registration Number: To be added once registered with the ICO. Registered Address: To be added once a registered address is confirmed. Contact Email: privacy@agentlane.agency

2. What Data We Process

2.1 End-Customer Data (Processed on behalf of our clients)

When a customer of one of our clients interacts with our AI agent (e.g., via SMS or phone), we process:

  • Phone numbers (caller ID / SMS sender)
  • Message content (SMS text, call transcripts)
  • Appointment details (requested dates, times, services)
  • Names (if provided by the customer during conversation)
  • Conversation metadata (timestamps, message direction, delivery status)

Legal basis: Legitimate interest (facilitating business communication and appointment booking) and, where required, consent (opt-in via START keyword or explicit booking request).

2.2 Agency Partner Data

When you apply to become an agency partner or interact with us commercially, we collect:

  • Name and job title
  • Business email address
  • Company name and registration number
  • Phone number
  • Billing information (processed via Stripe)
  • Communication history (emails, call notes)

Legal basis: Contractual necessity and legitimate interest (business relationship management).

2.3 Website Visitor Data

When you visit agentlane.agency, we collect:

  • IP address (anonymised where possible)
  • Browser type and version
  • Device information
  • Pages visited and time spent
  • Referral source
  • Cookie data (see our Cookie Policy)

Legal basis: Legitimate interest (website security, performance optimisation) and consent (for non-essential cookies).

3. How We Use Your Data

3.1 End-Customer Data

We use this data solely to:

  • Receive and send SMS messages on behalf of our clients
  • Generate AI-powered responses using large language models
  • Create, modify, or cancel appointments via integrated calendar systems
  • Escalate complex enquiries to the business owner
  • Generate anonymised performance reports for our agency partners

We do NOT use end-customer data to:

  • Train our own AI models
  • Sell or share with third parties for marketing
  • Profile individuals for purposes unrelated to the client's business
  • Retain beyond the stated retention period

3.2 Agency Partner Data

We use this data to:

  • Manage partner accounts and onboarding
  • Process monthly commission payments and invoices
  • Provide technical support and account management
  • Send service updates and partner communications
  • Meet legal and regulatory obligations

3.3 Website Visitor Data

We use this data to:

  • Ensure website security and prevent fraud
  • Analyse traffic patterns and improve user experience
  • Respond to enquiries submitted via contact forms

4. Data Sharing and Sub-Processors

We use the following sub-processors to deliver our services. All sub-processors are bound by data processing agreements that meet or exceed UK/EU GDPR standards.

Sub-Processor Purpose Location GDPR Safeguards
Supabase Database hosting, data storage EU (Ireland — eu-west-1) EU Standard Contractual Clauses
Twilio SMS/MMS delivery, phone number management US (with EU data residency options) EU Standard Contractual Clauses
Anthropic (Claude) AI response generation US EU Standard Contractual Clauses, zero retention policy
Cal.com Appointment scheduling and calendar integration EU / US EU Standard Contractual Clauses
Stripe Payment processing for agency partners US EU Standard Contractual Clauses, PCI-DSS compliant
Vercel Website hosting and edge delivery EU / US EU Standard Contractual Clauses

Important notes:

  • All end-customer conversational data is stored exclusively in the European Union (Ireland) via Supabase.
  • Message content sent to Anthropic for AI processing is not retained by Anthropic for model training and is deleted immediately after the response is generated (Anthropic's zero-retention API policy).
  • We do not transfer EU/UK personal data to jurisdictions without adequate GDPR safeguards.

5. Data Retention

Data Category Retention Period Rationale
SMS/Call conversation data 12 months from date of creation Operational necessity, dispute resolution, service optimisation
Appointment records 12 months from appointment date Booking verification, no-show analysis
Agency partner contact/billing data Duration of contract + 7 years Tax and legal compliance
Website analytics (anonymised) 26 months Traffic analysis and site improvement
Failed message logs 90 days Troubleshooting and delivery verification

Automated deletion: We run automated purge workflows to permanently delete data that exceeds the retention periods above. Data is deleted from both active databases and backups within 30 days of the retention expiry.

6. Your Rights Under GDPR

If you are an individual whose data we process (e.g., a customer of one of our clients), you have the following rights:

6.1 Right to Access

You can request a copy of all personal data we hold about you. We will provide this within 30 days, free of charge for the first request.

6.2 Right to Rectification

If any data we hold about you is inaccurate or incomplete, you can request correction.

6.3 Right to Erasure ("Right to be Forgotten")

You can request deletion of your personal data. We will comply within 30 days unless we have a legal obligation to retain it (e.g., tax records).

How to request deletion: Text STOP to any AI agent number, or email privacy@agentlane.agency with your phone number and the business you interacted with.

6.4 Right to Restrict Processing

You can request that we limit how we use your data while a dispute is resolved.

6.5 Right to Data Portability

You can request your data in a structured, machine-readable format (CSV or JSON).

6.6 Right to Object

You can object to processing based on legitimate interest. We will cease processing unless we demonstrate compelling legal grounds.

6.7 Right to Withdraw Consent

Where processing is based on consent, you can withdraw it at any time by texting STOP or contacting us. Withdrawal does not affect the lawfulness of processing before withdrawal.

6.8 Right to Complain

If you are unhappy with how we handle your data, you can complain to:

  • UK: Information Commissioner's Office (ICO) — www.ico.org.uk
  • EU: Your local Data Protection Authority

7. Security Measures

We implement the following technical and organisational measures:

  • Encryption at rest: All data in Supabase is encrypted using AES-256
  • Encryption in transit: All API communications use TLS 1.3
  • Access control: Role-based access to n8n and Supabase; 2FA enforced on all admin accounts
  • Audit logging: All database access and workflow executions are logged
  • Network isolation: n8n instance and database communicate via private networking where possible
  • Regular backups: Encrypted backups retained for 30 days, then purged
  • Incident response: 72-hour internal breach notification procedure; 72-hour regulatory notification where required by GDPR Article 33

8. International Data Transfers

Primary storage: All end-customer data is stored in the European Union (Ireland, eu-west-1).

Transfers to the US: Some sub-processors (Twilio, Anthropic, Stripe) are US-based. We ensure GDPR-compliant transfers through:

  • EU Standard Contractual Clauses (SCCs)
  • Adequacy decisions where applicable (e.g., EU-US Data Privacy Framework for certified providers)
  • Zero-retention policies for AI processing (Anthropic)

We do not transfer data to jurisdictions without adequate GDPR safeguards.

9. Children's Privacy

Our services are not directed at children under 16. We do not knowingly process data from children. If you believe we have processed a child's data, contact us immediately for deletion.

10. Changes to This Policy

We may update this Privacy Policy to reflect changes in our practices or legal requirements. We will notify agency partners of material changes via email. For end-customers, the latest version will always be available at agentlane.agency/privacy.

Material changes will be notified 30 days in advance.

11. Contact Us

For privacy-related questions, data subject requests, or DPA inquiries:

Email: privacy@agentlane.agency Response time: Within 48 hours Postal address: To be added once a registered address is confirmed.

For agencies requesting a signed Data Processing Agreement (DPA), please email dpa@agentlane.agency.


This Privacy Policy is designed to comply with UK GDPR, EU GDPR, and the Data Protection Act 2018. It does not constitute legal advice. We recommend consulting a qualified data protection solicitor for final review before publication.