Summary
This summary is not a substitute for the full policy below, but it covers the points people ask about most.
- Cloei builds AI systems that talk to customers on behalf of businesses. Most of the time we are handling data for one of those businesses, not for ourselves. If you received a message from a Cloei-powered assistant, the business named in that message is normally the one responsible for your data.
- You will always be told when you are speaking to an AI. Our assistants identify themselves as automated at the start of a conversation and will not claim to be human if asked.
- We do not sell personal data. Our AI providers are not permitted to train their models on data processed through Cloei. We do use de-identified conversation data — stripped so that individuals can no longer reasonably be identified — to improve our platform. Section 9 explains how.
- You can ask us to stop marketing to you at any time, and you have rights over the data we hold about you as a controller — set out in section 21.
- Questions or complaints: support@cloei.ai. We will acknowledge any data protection complaint within 30 days.
1. About this policy
CLOEI AI LIMITED (“Cloei”, “we”, “us”, “our”) provides AI-powered conversational technology that businesses use to communicate with their customers and prospective customers.
This policy explains how we handle personal data when you:
- visit cloei.ai;
- contact us, request a demonstration, or deal with us as a customer, supplier or partner;
- interact with an AI assistant powered by Cloei on behalf of another business; or
- are included in data one of our business customers provides to us.
Because Cloei sits between businesses and their customers, our role changes depending on the situation. Sometimes we decide how personal data is used (controller); more often, we act on a business customer’s instructions (processor). Section 4 explains which applies when, and why it matters to you.
This policy is governed by the UK GDPR, the Data Protection Act 2018 as amended by the Data (Use and Access) Act 2025, and the Privacy and Electronic Communications Regulations 2003 (PECR).
2. Who we are
CLOEI AI LIMITED
| Company number | 16688827 |
|---|---|
| Registered office | Reedham House, 31 King Street West, Manchester, M3 2PJ, United Kingdom |
| ICO registration | ZC240937 |
| Website | cloei.ai |
| Privacy contact | support@cloei.ai |
We have not appointed a statutory Data Protection Officer, as we are not required to under Article 37 UK GDPR. Responsibility for data protection sits with our directors, and privacy queries are handled through the contact address above.
Cloei’s services are provided in the United Kingdom and we have not appointed a representative under Article 27 UK GDPR.
3. What Cloei does
Cloei provides AI systems that hold natural-language conversations with customers on behalf of businesses, across channels including WhatsApp, SMS and RCS, web chat, social messaging and email.
Depending on how a business configures Cloei, our technology may:
- answer enquiries and understand what a customer is asking for;
- collect information a customer chooses to provide;
- qualify enquiries and assess whether a customer is likely to be eligible for a product or service;
- provide information, options, quotes or recommendations;
- arrange appointments or callbacks;
- help customers through an application or enquiry process;
- follow up on incomplete journeys;
- hand the conversation to a human agent; and
- pass conversation outcomes and information back to the business’s own systems.
We work with businesses in regulated and enquiry-led sectors, including motor finance, insurance and warranties, travel, and lead generation. What we process, and why, therefore varies significantly between one deployment and the next.
4. Controller or processor
When we are the controller
We decide how personal data is used — and this policy applies in full — when you:
- visit cloei.ai or contact us through it;
- submit an enquiry or request a demonstration;
- deal with our sales, support or delivery teams;
- are a contact at a customer, supplier, partner or prospective customer;
- subscribe to our marketing; or
- are recorded in our own business contact records.
We also act as controller for security, fraud prevention, legal compliance, and defending legal claims.
When we are the processor
When a business uses Cloei to communicate with its own customers, that business decides what data we receive, what we do with it, which communications happen, and how long the data is kept. In that situation the business is the controller and we act on its documented instructions under a written contract that meets Article 28 UK GDPR.
What this means for you: if you received a message from a Cloei-powered assistant and want to know why you were contacted, ask to be removed, or exercise your data protection rights, the fastest route is normally the business named in that message. You can still contact us at support@cloei.ai — we will either help directly or pass your request to the relevant business and support them in responding.
5. Talking to a Cloei AI assistant
Because this is central to what we do, we set it out separately.
- Disclosure. Cloei assistants identify themselves as automated at the outset of a conversation. If you ask whether you are speaking to a person, the assistant will tell you it is an AI. We require this of every deployment as a condition of using our platform.
- Human handover. You can ask to speak to a human at any point. Where the business has enabled it, the conversation will be transferred; where it has not, you will be told how to reach a person.
- Recording and retention. Conversations are recorded and stored so the business can service your enquiry, meet its own regulatory record-keeping obligations, and check the quality of the service.
- What you should not send. Please do not send payment card details, passwords, or sensitive information that has not been asked for. If a service genuinely needs sensitive information, you will be told why.
- Accuracy. AI systems can occasionally produce inaccurate or incomplete responses. Nothing an assistant tells you overrides the terms, quotes or decisions issued by the business you are dealing with.
6. Information we may process
Identity and contact. Name, title, date of birth where a service requires it, customer or account reference, email address, phone number, postal address, messaging account identifier, and communication preferences.
Business contact. Where you deal with us professionally: employer, job title, business contact details, department, your requirements, and our correspondence and commercial history with you.
Conversation data. Messages sent and received, questions and answers, conversation history and context, timestamps, channel, AI-generated responses, human agent responses, expressed preferences, outcomes, and callback or appointment requests.
Data supplied by our business customers. Customer and prospect records, contact details, account identifiers, prior enquiry history, products held, application data, lead source, and previous communications.
Technical data. IP address, browser and device type, operating system, approximate location derived from IP, system and access logs, security events, and diagnostic and performance data.
7. Where we get personal data
Directly from you; from your use of cloei.ai; from conversations with our assistants; from businesses using the Cloei platform; from integrations with our customers’ CRM, telephony and marketing systems; from messaging and telecommunications providers; from our own suppliers acting on our behalf; and, for business-to-business purposes only, from publicly available sources such as company websites, Companies House and professional networks.
Where a business supplies personal data to us, that business is responsible for having a lawful basis to do so and for telling the people concerned. Where we obtain business contact data indirectly and act as controller, we provide the information required by Article 14 UK GDPR at or before the point we first contact you.
8. How we use personal data
To deliver our services — operating the platform, running conversations, understanding intent, generating responses, collecting information, qualifying enquiries, arranging callbacks, transferring to human agents, maintaining conversation context, integrating with client systems, and recording outcomes.
To run our business — responding to enquiries, arranging demonstrations, providing support, administering accounts and contracts, managing suppliers, invoicing, and keeping business records.
To improve Cloei — analysing how the platform performs, developing features, testing and evaluating our AI systems, diagnosing errors, and improving reliability, conversation quality and security. Section 9 explains what data is used for this and how it is de-identified first.
To keep our systems secure and prevent fraud — authentication, monitoring, detecting suspicious activity, investigating incidents, and protecting our customers and users.
To meet legal and regulatory obligations — complying with law, responding to lawful requests, cooperating with regulators and law enforcement, keeping records, and establishing or defending legal claims.
9. AI models, providers and training
Our AI providers
We use third-party large language model providers, currently OpenAI and Anthropic, to power conversation understanding and response generation.
Training
- We do not permit our AI providers to train their models on personal data processed through Cloei. We use these providers under enterprise or API terms that exclude customer data from model training.
- We do not train our own models on identifiable personal data, unless a business customer specifically instructs us to for their own deployment, under a written agreement.
- We do use de-identified conversation data to improve the Cloei platform. Before conversation data is used for this purpose, it is processed so that individuals can no longer reasonably be identified. Once de-identified, it may be combined with data from other businesses using Cloei and used to improve conversation quality, accuracy and reliability across the platform.
How we de-identify
Direct identifiers such as names, contact details, account references and dates of birth are removed. Free-text content is scanned and redacted to remove identifying detail. The process is designed to be irreversible: we do not retain a key allowing de-identified records to be linked back to an individual.
De-identification takes place within 30 days of a conversation ending. After that point, only the de-identified version is retained for platform improvement.
Data minimisation
We limit what is sent to AI providers to what the relevant service needs, and we configure retention with those providers according to our contractual and data protection arrangements.
We may add or change AI providers as our technology develops. Where we do, we will apply equivalent contractual protections and update the list in section 13.
10. Automated decision-making and profiling
Some Cloei deployments involve profiling — for example, assessing from a conversation whether an enquiry is likely to meet a business’s eligibility criteria, or prioritising enquiries for follow-up.
UK law changed on 5 February 2026. Articles 22A to 22D of the UK GDPR now permit solely automated decisions with legal or similarly significant effects in a wider range of circumstances than before, provided appropriate safeguards are in place. Stricter conditions continue to apply where such a decision is based, entirely or partly, on special category data.
Our position:
- Cloei is designed to inform decisions, not to make them alone. Where a Cloei conversation feeds into a significant decision — such as whether a finance or insurance application proceeds — that decision is normally taken by the business, with meaningful human involvement.
- Where a business configures Cloei so that a significant decision is made without meaningful human involvement, that business is responsible as controller for the safeguards required by Article 22C: telling you the decision was made, letting you make representations, providing human intervention on request, and letting you contest the outcome. Our contracts require customers to implement these.
- If you believe an automated decision has been made about you through a Cloei-powered service, contact the business concerned, or contact us at support@cloei.ai and we will identify the responsible business and pass your request on.
11. Lawful bases
Where we act as controller, we rely on:
| Basis | Typical use |
|---|---|
| Contract | Providing services to you or your organisation; steps taken at your request before entering a contract |
| Legitimate interests | Operating and developing Cloei; responding to business enquiries; managing customer and supplier relationships; B2B marketing; system security and fraud prevention; business analytics; record-keeping; establishing or defending legal claims |
| Consent | Electronic direct marketing where PECR requires it; any non-essential cookies we introduce |
| Legal obligation | Tax, accounting, corporate and regulatory record-keeping; responding to lawful requests |
| Recognised legitimate interests | Certain limited purposes now listed in Schedule 4 UK GDPR, such as disclosure to a regulator, where these apply |
You can ask us for our legitimate interests assessment for any of the purposes above by emailing support@cloei.ai.
Where we act as processor, the lawful basis is determined by the business customer, not by us. This includes the de-identification described in section 9, which we carry out on the customer’s instruction. Once data is de-identified it is no longer personal data and data protection law does not apply to its further use.
12. Marketing
We may send you information about Cloei’s products, features, events, research and related services.
If you are a business contact, we generally rely on legitimate interests, and on the fact that PECR permits electronic marketing to certain corporate subscribers. If PECR requires your consent, we will obtain it before sending marketing by email, SMS or messaging app.
Soft opt-in. Where you have bought a service from us or negotiated to, and we obtained your details in that context, we may market our own similar products and services to you without fresh consent, provided we gave you a chance to opt out at the time and give you one in every message.
Opting out. You can stop marketing at any time by using the unsubscribe link or opt-out instruction in any message, replying STOP where the channel supports it, or emailing support@cloei.ai. We will keep a minimal suppression record so your preference continues to be honoured.
Opting out of marketing does not stop service, transactional, contractual or legally required communications.
13. Who we share personal data with
We do not sell personal data.
We share personal data with the following recipients, under written contracts requiring appropriate security and confidentiality:
| Recipient | Purpose | Processing location |
|---|---|---|
| Amazon Web Services | Cloud hosting and infrastructure | EU |
| MongoDB Atlas | Database infrastructure | EU |
| Twilio | Messaging and telephony infrastructure | EU |
| OpenAI | AI language model services | EU |
| Anthropic | AI language model services | EU |
| Meta Platforms / WhatsApp Business | Messaging channel | EU |
| Microsoft 365 | Email and business productivity | UK / EU |
| Novem | IT and technology support services | UK |
We also use business tools such as internal messaging and knowledge management systems. Personal data processed on behalf of our business customers is not transferred into those systems.
We also share personal data with:
- Our business customers, where you have communicated through Cloei on their behalf — conversation records and outcomes are provided to them.
- Professional advisers — lawyers, accountants, auditors, insurers and security advisers, where necessary.
- Regulators, courts, law enforcement and other authorities, where required by law or necessary to protect our rights.
- Prospective purchasers, investors or lenders, if Cloei or part of our business is sold, merged, financed or reorganised, subject to confidentiality protections.
Changes to our providers
Where we act as processor, we will give our business customers reasonable advance notice of new or replacement sub-processors so they can raise objections under their contract with us.
14. International transfers
The providers supporting Cloei process personal data within the United Kingdom or the European Economic Area. Transfers to the EEA are covered by UK adequacy regulations, so no additional transfer mechanism is required.
If we introduce a provider that processes personal data in a country not covered by UK adequacy regulations, we will ensure an appropriate transfer mechanism is in place — the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or another lawful mechanism — together with a transfer risk assessment where required, and we will update this policy.
You can request details of the safeguards applying to a specific transfer by emailing support@cloei.ai.
15. Security and data breaches
We use technical and organisational measures appropriate to the risk, including: access controls and role-based permissions; multi-factor authentication; encryption in transit and at rest; secure cloud infrastructure; logging and monitoring; supplier due diligence; secure development practices; data minimisation; incident response procedures; and confidentiality obligations on staff and contractors.
If a personal data breach occurs, we will notify the ICO within 72 hours where the law requires it, and notify affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms. Where we act as processor, we will notify the affected business customer without undue delay so it can meet its own obligations.
No internet-based service can be guaranteed absolutely secure. We review our controls as our platform develops.
16. How long we keep personal data
We keep personal data only as long as necessary. Where we act as processor, retention is set by the business customer’s instructions. Where we act as controller, our periods are:
| Data | Retention |
|---|---|
| Website enquiry and demo request data | 24 months from last contact |
| Business contact and CRM records | 24 months from last meaningful interaction, then review |
| Customer contract and account records | Duration of contract plus 6 years (limitation period) |
| Accounting and tax records | 6 years from the end of the relevant accounting period |
| Marketing suppression records | Indefinitely, minimal data only, to honour your opt-out |
| Conversation records from our own demonstrations and trials | 6 months |
| Conversation records processed for a business customer | As instructed by that customer |
| System, access and security logs | 12 months |
| Records relating to a dispute or claim | Until resolved, plus any applicable limitation period |
When we no longer need identifiable data, we delete it or de-identify it as described in section 9. De-identified and aggregated data may be kept indefinitely for analytics and product development.
17. Cookies
cloei.ai does not currently use advertising or behavioural tracking cookies. We use only cookies and similar technologies that are strictly necessary for the site to function and to keep it secure.
If we introduce analytics, tag management or other non-essential technologies, we will update this policy and our cookie information. Where consent is required, these will not be set until you have given it. Note that certain low-risk analytics and functionality cookies were brought within a statutory exemption from the PECR consent requirement in February 2026; where we rely on that exemption, we will say so and still offer you a way to object.
18. Sensitive information and customers in vulnerable circumstances
Some sectors we work in — motor finance, insurance and warranties among them — involve customers who may be in financially difficult circumstances, and conversations in which people sometimes volunteer sensitive information such as health or financial hardship details.
- We seek to minimise the processing of special category data and expect customers to configure their deployments so that it is not collected unnecessarily.
- Where special category data is processed, the relevant controller must identify both an Article 6 lawful basis and an Article 9 condition.
- Our de-identification process described in section 9 is designed to remove sensitive detail from conversation data before it is used for platform improvement.
- Our contracts require business customers operating in regulated sectors to configure their services consistently with their own regulatory obligations, including the FCA’s Consumer Duty and its expectations around customers with characteristics of vulnerability. Where a conversation indicates possible vulnerability, deployments should be configured to route the customer to appropriate human support.
19. Children
Our website and our direct services are aimed at businesses and are not intended for children. We do not knowingly collect children’s data through cloei.ai for marketing purposes.
Where a business customer’s own service involves people under 18, that customer is responsible for the lawful basis, the age assurance approach and the safeguards, including the data protection by design expectations for children’s services introduced by the Data (Use and Access) Act 2025. We process such data only on that customer’s documented instructions.
20. Third-party websites
Our website and communications may link to third-party sites and services. We are not responsible for their privacy practices. Review their own privacy information before providing personal data to them.
21. Your rights
Where we are the controller, you may have the right to:
- Access — obtain confirmation that we process your data and a copy of it.
- Rectification — have inaccurate or incomplete data corrected.
- Erasure — have data deleted where there is no lawful reason to continue processing it.
- Restriction — limit how we use your data in certain circumstances.
- Objection — object to processing based on legitimate interests. You have an absolute right to object to direct marketing.
- Portability — receive data you provided to us in a structured, commonly used, machine-readable format, or have it sent to another organisation.
- Withdraw consent — at any time, where we rely on consent. This does not affect processing carried out before withdrawal.
- Rights relating to automated decisions — see section 10.
These rights are subject to legal exemptions. They do not extend to de-identified data, which can no longer be linked to you.
22. How to exercise your rights
Email support@cloei.ai with enough detail for us to identify you and understand what you are asking for. We may need to verify your identity.
Timescales. We respond within one month. Under Article 12A UK GDPR, that period does not begin until we have the information we reasonably need to identify you and to clarify the request, and it can be extended by up to two further months for complex or numerous requests — we will tell you if that happens. We conduct a reasonable and proportionate search for the data you have asked for.
If your request relates to data we process for a business customer, we will tell you and either refer you to that business or assist it in responding.
There is normally no charge, though we may charge a reasonable fee or refuse to act where a request is manifestly unfounded or excessive.
23. Complaints
Complain to us first. Section 164A of the Data Protection Act 2018 requires us to make it straightforward to complain about how we handle personal data, and to deal with complaints properly.
- Use our data protection complaints form at cloei.ai/legal/data-complaint, or email support@cloei.ai.
- We will acknowledge your complaint within 30 days of receiving it.
- We will take appropriate steps to respond without undue delay, keep you updated on progress, and tell you the outcome.
Complain to the regulator. If you remain dissatisfied, you can complain to the Information Commissioner’s Office:
Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Helpline: 0303 123 1113 · ico.org.uk
Our ICO registration number is ZC240937.
24. Changes to this policy
We will update this policy as our services, channels, providers and legal obligations change. The current version is always published at cloei.ai. Where a change materially affects how we use personal data, we will take appropriate steps to bring it to the attention of affected individuals.
| Version | Date | Summary |
|---|---|---|
| 1.0 | 9 September 2026 | Initial publication |
25. Contact us
CLOEI AI LIMITED
Reedham House, 31 King Street West, Manchester, M3 2PJ, United Kingdom
Email: support@cloei.ai
Company number: 16688827
ICO registration: ZC240937
Website: cloei.ai