Privacy Policy.
LAST UPDATED · AUGUST 2026
1. Introduction
AskAndBook ("we", "us", or "our") operates an AI-powered voice receptionist platform accessible at askandbook.app. This Privacy Policy explains how we collect, use, store, share, and protect information when you use our website, our platform, or when our AI voice agents interact with callers on behalf of businesses we serve.
We are committed to protecting personal information in accordance with the Protection of Personal Information Act, 2013 (POPIA) of South Africa, and — where they apply — the UK General Data Protection Regulation and the Data Protection Act 2018 for our United Kingdom customers, and the EU General Data Protection Regulation.
2. Information We Collect
We collect the following categories of information:
- Account & business information: Business name, contact name, email address, phone number, billing address, and subscription details when you sign up or contact us.
- Configuration data: Business hours, FAQs, services offered, booking preferences, and other settings you provide to configure your AI assistant.
- Call data: Recordings, transcripts, call duration, caller phone numbers, and timestamps for calls handled by our AI voice agents on your behalf.
- Lead & appointment data: Names, phone numbers, and notes captured by the AI during calls (e.g., booking requests, lead enquiries).
- Payment information: Subscription and billing data processed through Paystack (for South African customers) or through our Merchant of Record, Creem, operated by Armitage Labs OÜ (for customers outside South Africa). We do not store full card details on our servers.
- Usage & technical data: IP addresses, browser type, pages visited, and session information collected automatically when you use our website or platform.
3. How We Use Your Information
We use the information we collect to:
- Provide, operate, and maintain the AskAndBook platform and AI voice agent services.
- Configure and personalise AI voice agents for your business.
- Process payments and manage subscriptions.
- Send transactional communications (booking confirmations, call summaries, billing notices).
- Provide customer support and respond to enquiries.
- Monitor platform performance, security, and reliability.
- Comply with legal obligations and enforce our Terms of Service.
- Improve our services through aggregated, anonymised analytics (excluding Google user data — see Section 13).
We will not use your data for unsolicited marketing. Google user data is never used for marketing purposes (see Section 13).
4. Our Role as Data Processor
When businesses use the AskAndBook platform to deploy AI voice agents, AskAndBook acts as a data processor on behalf of those businesses. The business is the data controller and determines the purposes and means of processing personal data collected during calls (such as caller names, phone numbers, and booking details).
In this capacity, we process personal data only as instructed by the business customer, and solely for the purpose of providing the Service. Businesses remain responsible for:
- Establishing a lawful basis for collecting and processing caller data under POPIA, GDPR, or other applicable law.
- Ensuring callers are informed that their call may be handled by an AI and may be recorded.
- Responding to data subject requests from their own callers and customers.
Where AskAndBook collects data directly from platform users (business account holders) for the purposes of operating the Service, we act as a data controller in respect of that data.
5. Call Recording & Transcripts
Our AI voice agents handle inbound calls on behalf of businesses. When a call is processed:
- You are speaking to an automated system. Callers interact with an AI voice agent deployed by the business they have called. The business deploying the agent is responsible for ensuring callers are appropriately informed that their call is handled by an AI and is recorded and/or transcribed, in accordance with applicable law. The agent can also announce this itself at the very start of the call — that is a setting each business controls, and it is switched on by default for businesses based in the United Kingdom.
- Transcripts. A written transcript of the conversation is produced for every call and stored against the call record, so the business can see what was discussed.
- Audio recordings. Whether an audio recording of the call is also captured and stored depends on the call technology configured for that business. On some configurations we store a transcript and summary only, and no audio recording is retained in our systems. Where an audio recording is stored, it is subject to the same retention period as the rest of the call record.
- Who can access it. Recordings and transcripts are accessible to the business that owns the relevant phone line, and to AskAndBook staff where reasonably necessary to provide, support and secure the Service. They are not used for advertising or profiling. See Section 8 for our position on AI model training.
- How long we keep it. Call data is retained for the period configured by the business — 90 days by default. At the end of that period any audio recording is deleted and the transcript and summary are irreversibly redacted; a minimal log entry (number, date, time, duration, outcome) is kept for the business's billing and reporting. Section 10 sets this out in full.
- Payment details are not taken. The agent is instructed not to collect card numbers, PINs or bank details. Payment is arranged directly with the business.
- Deletion requests. Callers may request deletion of their call data by contacting the business directly, or by emailing us at support@askandbook.app and we will pass the request to the business we act for.
6. WhatsApp Conversations
When you enable the WhatsApp Post-Call Assistant add-on, AskAndBook (acting as a Meta-registered Independent Tech Provider for the WhatsApp Business Platform) facilitates WhatsApp messaging between your callers and your business. Messaging is routed through our Business Solution Provider, Twilio, to Meta's WhatsApp Business Platform, and delivered to the caller's WhatsApp account. Conversations are stored to provide the service. This includes message content, timestamps, and caller phone numbers. See Section 14 below for full details on Meta WhatsApp Business Platform data handling.
- Conversations are visible to your business team through the portal for customer management purposes.
- Message content is not routinely accessed by AskAndBook platform administrators. However, AskAndBook may access conversation data where reasonably necessary for platform maintenance, technical support, security investigations, dispute resolution, or compliance with legal obligations.
- Conversation data is treated with the same level of confidentiality as call recordings and transcripts.
- Conversations are subject to the same data retention period as your call logs (configurable in your settings, default 90 days).
- Callers can request deletion of their conversation data by contacting your business directly.
7. SMS Notifications
When you enable the SMS Notifications add-on, we send text messages to callers and your business team on your behalf. We store a record of each SMS sent, including the recipient phone number, message content, delivery status, and timestamp. These records are used for billing, delivery tracking, and troubleshooting. SMS notification logs are subject to the same data retention period as your call logs.
8. Third-Party Service Providers
We share data with trusted third-party providers solely to operate our platform. These include:
- AI voice & telephony infrastructure: Providers that handle call routing, phone number provisioning, voice synthesis, and speech-to-text processing. Certain call data (including audio) is transmitted to these providers to facilitate call delivery and generate real-time AI responses. These providers process data solely for this purpose and are bound by strict confidentiality and data processing obligations.
- AI language & voice processing: We use OpenAI and ElevenLabs to power the conversational intelligence and speech capabilities of our AI voice and messaging agents. Call audio and text content is processed by these providers to generate responses in real time. Separately, after every call an extract of the transcript (up to the first 6,000 characters) is sent to OpenAI to work out the caller's sentiment and produce the short call summary the business sees in its portal. Such processing is carried out under data processing agreements that restrict use of the data to delivering the service to us. Google user data is never sent to AI or language model providers (see the Google User Data section below).
- Payment processing: Paystack processes subscription payments for South African customers. For customers outside South Africa, our Merchant of Record, Creem (operated by Armitage Labs OÜ, Estonia), processes payments, invoicing, and tax as the seller of record. We do not store full card details on our servers.
- Cloud hosting & database infrastructure: Providers hosting our application and data on secure cloud infrastructure.
- Transactional email: Providers used to send booking confirmations, call summaries, and account notifications.
- Session & caching services: Providers used to maintain call session state and platform performance.
We do not sell, rent, or trade your personal information to third parties for marketing purposes. All third-party providers are bound by confidentiality obligations and data processing agreements, and may only process data as instructed by us.
AI model training: We do not use call recordings, transcripts, messages or any other personal data processed on behalf of a business to train, fine-tune or improve our own AI models, and we do not sell or license that data to anyone else for that purpose. On our providers: OpenAI's business API terms state that content submitted through it is not used to develop or improve its models. We record each provider's stated position on model training in the sub-processor register described below, and business customers can request it. Where we publish operational statistics about the platform, they are derived from aggregated, anonymised information from which no individual and no business can be identified.
Sub-processor list: We maintain a register of the sub-processors we use, recording what each one does, what data it handles, the region it operates in, and the legal mechanism relied on for any transfer of data outside the customer's country. Business customers can request the current register at any time by emailing support@askandbook.app. Under our Data Processing Agreement we give business customers at least 30 days' notice before adding or replacing a sub-processor, and they may object on reasonable data protection grounds.
Data breach notification: In the event of a security breach that compromises personal data, we will notify affected customers and the relevant supervisory authority in accordance with the timeframes and requirements set out in applicable data protection law (including POPIA and GDPR where relevant).
9. Data Storage & Security
Your data is stored on secure cloud infrastructure. We implement industry-standard security measures including:
- Transport Layer Security (TLS/HTTPS) for all data in transit.
- Encryption at rest, provided and managed by our database and storage providers, covering everything we hold including call recordings. On top of that, WhatsApp sender credentials are separately encrypted by our own application before they are stored, and portal passwords are stored only as one-way hashes — we cannot read them back.
- Role-based access controls limiting production data access to authorised personnel only.
- Regular security reviews and monitoring.
While we take all reasonable precautions, no method of transmission or storage is 100% secure. We encourage you to use strong passwords and report any suspected security issues to support@askandbook.app.
10. Data Retention
Retention is configurable by each business. Every business sets how long its call data is kept, in its portal settings. The default is 90 days, and that is also the default we apply for United Kingdom customers. A business can shorten or extend it to suit its own obligations. Beyond that period we retain data only where we have a legal reason to.
When the period ends, what happens is not identical for everything, so it is worth being precise:
- Call recordings and voicemail audio: Deleted. On some configurations no audio recording is stored in the first place — see Section 5.
- Call transcripts and summaries: Irreversibly redacted. The text is overwritten and cannot be recovered by us or by the business.
- The call log entry itself: Kept, but only as the telephone number, date, time, duration, outcome and cost. That is what the business's billing and usage reports are built from, so we do not remove it. Nothing of what was said remains.
- WhatsApp conversations and messages, and SMS notification logs: Deleted.
- Bookings, leads & enquiries: Not covered by the retention period. They are the business's own record of its appointments and customers, and are kept until the business asks us to delete them or the account closes. A business can cancel a booking itself in its portal; deletion of a booking, lead or enquiry record is by request to us.
- Account & settings data: Retained for the duration of the subscription, plus 30 days after cancellation.
- Billing records: Retained for 7 years as required by South African financial regulations.
Deletion runs automatically on a daily schedule and needs no action from anyone. Where a business's AI agent is provided by a voice provider that keeps its own copy of the conversation, we set that provider's retention to the same period when the agent is set up, so its copy expires alongside ours.
Copies held in our database provider's routine backups are not edited individually; they expire with the backup that contains them, on a rolling window managed by that provider of no more than 35 days.
On termination, business customers may ask us to return or delete the data we hold on their behalf. Data written at a business's instruction into systems it controls — its own Google Calendar, Google Sheets or CRM — remains in those systems and is not deleted by us.
11. Your Rights
Depending on your jurisdiction, you have the following rights regarding your personal data:
- Right of access: Request a copy of the personal information we hold about you.
- Right to correction: Request correction of inaccurate or incomplete information.
- Right to deletion: Request deletion of your personal information, subject to legal retention obligations.
- Right to data portability: Request your data in a structured, commonly used format.
- Right to object: Object to processing of your data in certain circumstances.
- Right to withdraw consent: Where processing is based on consent, you may withdraw it at any time.
To exercise any of these rights, email support@askandbook.app. We will respond within 30 days. If you are unhappy with how we have handled your request, you can complain to us — see the next section.
Where we act as a data processor for a business (see Section 4), requests about call data are usually best directed to that business, which decides how the data is used. If you contact us instead, we will pass your request to them and tell you we have done so.
12. Complaints
If you think we have handled your personal information incorrectly, or you are unhappy with how we responded to a request to exercise your rights, you have the right to complain to us. We would rather hear from you and put it right.
How to complain
Email support@askandbook.app with the word "Complaint" in the subject line. Tell us what happened, when, and what you would like us to do. You do not need to use any particular form of words or cite any legislation. If you need to make your complaint another way — for example because of a disability or accessibility need — tell us and we will accommodate it.
What happens next
- We acknowledge your complaint within 30 days of receiving it.
- We investigate without undue delay, making whatever enquiries are appropriate.
- We keep you informed of progress, and of the outcome once we reach it.
- If your complaint concerns data we handle on behalf of a business customer, we will tell you that, and coordinate with that business — which is the data controller for that information.
If you are still not satisfied
You can complain to a data protection regulator. You do not have to complain to us first, and complaining to us does not remove your right to go to a regulator.
- United Kingdom: the Information Commissioner's Office (ICO) — ico.org.uk/make-a-complaint, or call the ICO helpline on 0303 123 1113.
- South Africa: the Information Regulator — inforegulator.org.za.
- Elsewhere: your local data protection authority.
13. Google User Data
AskAndBook integrates with Google services to provide booking and productivity features on behalf of business users. When you connect your Google account, we access the following data depending on which integrations you enable:
- Google Drive (Sheets): We create and write to Google Spreadsheets in your Google Drive to log bookings, leads, and (for real estate businesses) property listings. We only access files that AskAndBook itself creates — we cannot see or access your other Google Drive files.
- Google Calendar — Events: When a caller books an appointment through your AI agent, we create a calendar event on a calendar you select. While the permissions we request allow access to events on calendars you own, AskAndBook only creates new booking events and checks availability — we do not read, modify, or delete your existing calendar events.
- Google Calendar — Availability: Before creating a booking, we check your calendar availability (free/busy status) to prevent double-bookings. We can see whether a time slot is free or busy, but we cannot read the details of your existing events.
- Google Calendar — Calendar list: We read the list of calendars associated with your Google account so you can choose which calendar to use for bookings. This is read-only.
How we use Google data
Google user data is used solely to provide the AskAndBook booking and logging features you have enabled. Specifically:
- We do not use Google user data for advertising, marketing, or profiling purposes.
- We do not sell, rent, or share Google user data with third parties except as strictly necessary to provide the Service (e.g., our secure cloud database stores calendar event references).
- We do not use Google user data to train machine learning or AI models.
- Google OAuth access tokens and refresh tokens are stored in our access-controlled database and used only to make the calendar and spreadsheet updates you have authorised.
Google API Services User Data Policy
AskAndBook's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Revoking access
You can disconnect your Google account at any time from the Integrations page in your AskAndBook portal. You can also revoke AskAndBook's access from your Google Account permissions page. When access is revoked, AskAndBook will no longer be able to create calendar events or write to Google Sheets on your behalf. Any data previously written to your Google Sheets or Calendar remains in your Google account and is not affected.
14. Meta WhatsApp Business Platform Data
AskAndBook is registered with Meta as an Independent Tech Provider for the WhatsApp Business Platform. When your business enables the WhatsApp Post-Call Assistant add-on, you authorise AskAndBook to manage WhatsApp messaging on your behalf. This section explains what data flows through Meta's WhatsApp Business Platform and how we handle it.
What WhatsApp data we access
- Sender and recipient phone numbers for each WhatsApp conversation routed through your business's WhatsApp Business Account.
- Message content (template messages we send to your callers, and free-form replies they send back within the 24-hour service window).
- Message timestamps, delivery status, and read receipts where available.
- Your business profile information (display name, description, business category, address, contact email) submitted during sender registration with Meta.
- Authorisation tokens issued by Meta when you complete Embedded Signup, allowing AskAndBook to act as your authorised Tech Provider.
Permissions we use
- whatsapp_business_messaging — required to send template messages to your callers and to receive free-form replies.
- whatsapp_business_management — required to create and submit message templates for Meta approval, manage your business's WhatsApp sender phone numbers, and configure your WhatsApp Business Account on your behalf.
How we use Meta WhatsApp data
WhatsApp data is used solely to provide the AskAndBook WhatsApp Post-Call Assistant service you have enabled. Specifically:
- We do not use WhatsApp data for advertising, marketing, or profiling purposes.
- We do not sell, rent, or share WhatsApp data with third parties except as strictly necessary to provide the Service (e.g., our secure cloud database stores conversation records, and Twilio acts as our Business Solution Provider routing messages between your customers and Meta's WhatsApp servers).
- We do not use WhatsApp data to train machine learning or AI models.
- Meta authorisation tokens are stored encrypted in our database and used only to perform the integrations described above.
Service infrastructure
WhatsApp messaging functionality is provided by the Meta WhatsApp Business Platform. AskAndBook accesses Meta's WhatsApp APIs through our Business Solution Provider, Twilio, which provides the underlying message routing infrastructure. Both Twilio and Meta act as data processors in this flow, bound by their respective data processing agreements with us.
How we obtain access
You authorise AskAndBook to manage your WhatsApp Business Account through Meta's Embedded Signup flow. During Embedded Signup, you log in with your Facebook account, select or create a Meta Business Portfolio, and create a WhatsApp Business Account that grants AskAndBook (acting as your Tech Provider) the permissions listed above. AskAndBook does not store your Facebook account credentials — Meta handles authentication directly and issues us a scoped authorisation token for your business only.
Revoking access
You can disconnect AskAndBook from your WhatsApp Business Account at any time:
- From your AskAndBook portal: Settings → Add-ons → WhatsApp → Disable.
- From Meta Business Manager: Business Settings → Apps → AskAndBook → Remove.
When access is revoked, AskAndBook will no longer be able to send or receive WhatsApp messages on your behalf. Any data previously sent through Meta's WhatsApp servers remains in Meta's systems and is governed by Meta's WhatsApp Business Policy.
WhatsApp Business Platform compliance
AskAndBook's use and transfer of information received from Meta's WhatsApp Business Platform adheres to Meta's WhatsApp Business Solution Terms and Meta's Platform Terms.
15. Cookies and similar technologies
Essential cookies. Our website uses essential cookies for authentication, session management, security, and to remember your cookie choices. These are required for the site to work and are set without asking, as the law permits.
Analytics and advertising cookies. With permission, we also use third-party cookies and similar technologies to understand how our website is used and to measure the effectiveness of our advertising:
- Google Analytics — how visitors find and move through the site.
- Microsoft Clarity — aggregated usage analytics and session replay, so we can see where the site is confusing.
- Meta Pixel and Conversions API — measuring which of our advertisements lead to sign-ups, and showing our advertisements to relevant audiences on Meta's platforms. Where you complete a sign-up or a demo, we may also send Meta a hashed (irreversibly scrambled) copy of your email address and phone number so it can match the conversion to the advertisement you clicked. We never send Meta your details in readable form.
Your choice. If you are in the United Kingdom, the European Economic Area, or Switzerland, none of the analytics or advertising technologies above are loaded until you accept them on the banner shown when you first visit. If you decline, only essential cookies are used and no data is sent to Google, Microsoft, or Meta — including from our servers. Outside those regions these technologies load by default; you can prevent them by blocking cookies in your browser settings, though some parts of the platform may then not work correctly. You can change your choice at any time by clearing this site's cookies in your browser and reloading the page.
16. Children's Privacy
Our services are not directed to individuals under the age of 18. We do not knowingly collect personal information from minors. If you believe a minor has provided us with personal information, please contact us and we will delete it promptly.
17. International Data Transfers
AskAndBook is a South African company, and some of our service providers process data in other countries — principally the United States and the European Union. Where personal data moves across borders, we put an appropriate legal safeguard in place. We maintain a record of which safeguard applies to each provider, and business customers can request it (see Section 8).
United Kingdom customers
The United Kingdom has not made adequacy regulations covering South Africa. That means personal data reaching us from a UK business is a "restricted transfer" under the UK GDPR and needs a safeguard of its own.
- We enter into the International Data Transfer Agreement (IDTA) issued by the UK Information Commissioner with each UK business customer, as part of our Data Processing Agreement. It is available on request, and we will provide the information a UK customer needs for its own transfer risk assessment.
- Several of our United States providers are certified under the UK Extension to the EU–US Data Privacy Framework (the "UK–US Data Bridge"), which the UK recognises as providing an adequate level of protection. Where a provider is not certified, we rely instead on standard contractual clauses together with the UK Addendum or the IDTA.
- We review these mechanisms at least annually, and whenever a provider's certification status changes.
Other customers
For South African customers, transfers outside South Africa are made in accordance with POPIA. For customers elsewhere, we rely on the safeguards recognised by the applicable law of that jurisdiction — typically standard contractual clauses or an adequacy decision.
Government access requests
If a public authority makes a legally binding request for personal data we process on behalf of a business, we will notify that business unless we are legally prohibited from doing so, challenge any request that appears unlawful or excessive, and disclose only the minimum the law requires.
18. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email to registered users or by a prominent notice on our website. The "Last updated" date at the top of this page reflects the most recent revision. Continued use of the platform after changes constitutes acceptance of the updated policy.
19. Contact Us
For privacy-related enquiries and requests, please contact us at the address below. To make a complaint, see Section 12.
AskAndBook
Email: support@askandbook.app
Website: askandbook.app