Privacy Policy
Version 2.5 · Last updated: 26 August 2026 · A real change, in your favour: card numbers, bank details, passwords and National Insurance numbers typed into a chat are now removed automatically before the message is stored, emailed or sent to the AI. Section 5 explains what is caught and, honestly, what is not.
1 Who this policy is for
Dave on Duty provides AI chat assistants that businesses put on their own websites. That means two very different groups of people read this page, and the answers differ:
You chatted with an assistant
You typed a message to a chat bubble on some business's website — a dentist, a salon, a garage. Sections 2–17 are for you. The short answer: your conversation belongs to that business, we hold it for them, and you can ask either of us to delete it.
You run a business that uses Dave
You have a Dave on Duty account. Section 18 is for you, and it matters: for your visitors' data you are the controller and we act on your instructions.
This policy covers the daveonduty.com website, the customer portal, and the assistants we host on our customers' sites. It does not cover our customers' own websites, which have their own privacy policies.
2 Who is responsible for your data
Data-protection law splits responsibility into two roles, and being clear about which one we hold is the most important thing on this page.
- For conversations on a customer's website — the business you were talking to is the controller. It decides what its assistant knows, what it asks for, and what happens to the leads and bookings that result. Dave on Duty is that business's processor: we hold and process the data on their instructions and for no purpose of our own.
- For our own website, our customer accounts and our billing — Dave on Duty is the controller, and this policy is our notice to you.
In practice: if you want a chat with a dentist deleted, you can ask us and we will act, but the dentist is the one whose decision it ultimately is, and we may pass your request to them.
3 What we collect
When you chat with an assistant
- Your messages, and the assistant's replies.
- Anything you choose to tell it — typically your name, email address and sometimes a phone number, when you ask to book something or be contacted. The assistant asks for these only when they are needed to do the thing you asked for.
- Booking details — the service, date and time, plus any details the business needs (for a restaurant, the number of people; for a garage, the vehicle).
- A random session id stored in your browser so the assistant remembers the thread you're in. It contains nothing about you.
- Your IP address, used at the moment of the request to stop abuse and rate-limit flooding, and appearing in ordinary server logs. We do not store it against your conversation.
- Optional feedback — if you tap 👍 or 👎 on an answer, we record that, the question and the answer, so the business can improve what its assistant knows.
When you use our own website
- Anonymous visit counts — see section 8, which explains exactly how we do this without storing your IP address or setting a cookie.
- Support messages — if you use the form on our support page: your name, email, the topic you picked and your message. If you are signed in, your business name, plan and account status come with it so we don't have to ask who you are.
When you have a Dave on Duty account
- Account details — email address, business name, website address, optionally a phone number, and your password stored only as a strong scrypt hash that cannot be reversed. Nobody here can read your password, including us.
- What you build — the information you give your assistant: notes, uploaded documents, policies, services, opening hours and your answers to the most-asked-questions pack.
- Billing records — plan, status, invoices and payment history. Card numbers never reach our servers; Stripe holds those.
We do not use advertising cookies, we do not track you across other websites, and we neither buy nor sell personal data.
4 Why we use it, and our legal basis
Under UK GDPR every use of personal data needs a lawful basis. Ours, in full:
| What we do | Why | Lawful basis |
|---|---|---|
| Answer your questions and carry out what you asked for — booking, enquiry, quote | It's the service you're using | Legitimate interests of the business you contacted (and ours in operating the service) |
| Pass leads, bookings and enquiries to the business | That's the point of the assistant | Legitimate interests |
| Send you a confirmation email | You asked for the booking | Performance of a contract with you, or legitimate interests |
| Show a business the questions its assistant couldn't answer | So the next person gets a proper answer | Legitimate interests — service improvement |
| Ask you for a review after an appointment, where the business has switched it on | Feedback for the business | Legitimate interests / soft opt-in, with an opt-out in every message |
| Rate-limiting, abuse prevention, security logs | Keeping the service up and safe | Legitimate interests |
| Run your Dave on Duty account and bill you | You're our customer | Performance of a contract |
| Keep invoices and accounting records | HMRC requires it | Legal obligation |
| Count visits to our own website | To know which pages are useful | Legitimate interests (no cookies, no identification — see section 8) |
Where we rely on legitimate interests, we have weighed them against your rights and concluded the processing is what you would reasonably expect. You can object at any time (section 14) and we will stop unless we have compelling grounds not to.
5 How the AI handles your messages
To write a reply, your message is sent to Claude, an AI model operated by Anthropic, via Anthropic's API, together with the business's own information. Three things worth knowing:
- Under Anthropic's API terms, data submitted this way is not used to train their models.
- Each assistant answers only from its own business's information. One business's data is never visible to another business's assistant, and never mixed.
- The assistant is built to answer only from what the business has given it and to say plainly when it doesn't know, rather than to guess. It is not given access to anything about you beyond the conversation you are having.
Please don't type anything into a chat window you wouldn't be comfortable emailing to the business — it reaches them either way, and a chat assistant is not the place for medical details, card numbers or passwords.
If you do it anyway, we catch the worst of it automatically. Before a message is saved, before it is emailed to the business, and before it is sent to the AI, it is scanned for payment card numbers, bank sort codes and account numbers, card security codes, passwords and PINs, and National Insurance numbers. Anything found is replaced with a note saying it was removed. The original is never written to our disk, never reaches the business's inbox, and never leaves our server — so there is nothing for us to go back and delete later, and nothing sitting in an export.
Being straight about the limits: this is a safety net for the details people most often paste by mistake, not a guarantee that every sensitive thing is caught. It cannot recognise something written out in ordinary prose — a health condition described in a sentence, for instance — so the advice above still stands. If you have shared something sensitive that survived it, tell us and we will remove it.
6 Automated decisions and profiling
The law gives you a particular right not to have decisions that seriously affect you made purely by a machine — being turned down for credit by an algorithm, say. That right never comes into play here, because we make no decisions of that kind about you. To be concrete: the assistant answers questions and takes bookings. It does not price you individually, score you, assess your creditworthiness, accept or reject you as a customer, or decide anything a human at the business could not simply overrule. A booking it takes is a request on the business's own booking list, and a person there can change or cancel it.
We do not build advertising or behavioural profiles of anyone, on our site or on our customers' sites.
7 Cookies and storage
We set no advertising or analytics cookies. UK law (PECR) requires consent for non-essential cookies, and we don't use any — which is why you have never had to dismiss a cookie banner here. Everything we do store is strictly necessary for something you asked for:
| Name | Type | What it's for | How long |
|---|---|---|---|
| wd_session | Cookie | Keeps you signed in to your Dave on Duty account. HttpOnly and Secure, so scripts can't read it. | 30 minutes without activity, or when you close the browser or sign out |
| wd_sid_* | localStorage | A random id so an assistant remembers the conversation you're in on that site. Contains nothing about you. | Until you clear your browser storage |
| dod-currency | localStorage | Remembers whether you asked to see our prices in pounds or dollars, so the switch stays where you put it. | Until you clear it |
| dod_noanalytics | localStorage | Set only if you opt out of our visit counting — it's the flag that keeps you out. | Until you clear it |
| wd_demo_ask | sessionStorage | Holds a question you typed on our demo page just long enough to carry it across the page load, so you don't have to type it twice. | Deleted the moment it is used, and when you close the tab |
Our web fonts are served by Google Fonts, which means Google receives the IP address of visitors to our own website as part of delivering them. That is the only third party that sees anything as you browse this site.
8 How we count website visits
We wanted to know which pages are useful without following anyone around the internet, so we built the counting ourselves rather than adding Google Analytics. Here is exactly what happens, because "privacy friendly analytics" is a phrase that deserves proof:
- No cookie is set and no script of any third party is involved.
- Your IP address is never stored. At the moment of the request it is combined with your browser's user-agent and a secret that we rotate every day, and hashed into a short id. We keep the id, not the ingredients.
- That id lets us tell "one person read three pages" from "three people read one page" for a single day. Because the secret changes daily, the same visitor tomorrow is a completely different id, so nothing can be joined up over time and nothing can be traced back to you.
- We honour your browser's Do Not Track setting — if it's on, we count nothing.
- You can opt out permanently by setting
dod_noanalyticsin your browser's local storage for this site. - None of this runs on our customers' websites. The assistant embedded on a dentist's site does no analytics at all.
9 Who else processes data (our sub-processors)
We keep this list short deliberately, and we update this page before adding anyone to it. If you are a business customer, this is the sub-processor list your own privacy notice needs.
| Who | What they do for us | Where |
|---|---|---|
| Anthropic | Generates the assistant's replies (Claude API). Does not use submitted data to train models. | USA |
| Render | Hosting, and the encrypted-at-rest disks the data sits on. | EU / USA |
| Stripe | Card payments and subscriptions. Card numbers never reach our servers. | EU / USA |
| Namecheap Private Email | Delivers transactional email — confirmations, enquiries, account notices. | USA |
| Google Fonts | Serves the fonts on our own website; receives visitors' IP addresses. | EU / USA |
| Meta | Only if a business connects WhatsApp or Messenger. Off unless chosen. | EU / USA |
We never sell personal data. Not to anyone, at any price, in any form — not conversations, not contact details, not aggregated extracts of either. Beyond the processors listed above, who only ever act on our instructions, we do not share it: no advertisers, no data brokers, no "partners".
10 Transfers outside the UK
Some of the providers above operate in the United States. When personal data leaves the UK it has to travel under a legal safeguard, and ours is the standard one: a contract, in wording the UK regulator has approved, that binds the provider to protect the data as if it had never left. Every provider we use publishes those terms and we rely on them rather than inventing our own — which is part of why we chose established providers in the first place. The formal names, if you need them for your own records: the provider's standard contractual clauses plus the UK International Data Transfer Addendum.
11 How long we keep things
| What | How long | Why that long |
|---|---|---|
| Live conversation memory | Expires automatically after a couple of hours of inactivity | It only exists so the assistant can follow the thread |
| Chat transcripts | The most recent 2,000 per business; older ones are overwritten automatically | So the business can check answer quality without an ever-growing archive |
| Leads, bookings, enquiries | Until the business deletes them, or 90 days after it closes its account | They are the business's own customer records |
| A closed customer account's data | 90 days, then deleted | Long enough to come back or take a copy; short enough not to hoard |
| Support messages | 2 years | So we can see the history if you write to us again |
| Website visit counts | Rolling recent window, then overwritten | Aggregate numbers only; the daily ids are useless after a day anyway |
| Invoices and accounting records | 6 years | Required by UK tax law — we cannot delete these on request |
Ask us to delete something sooner and we will, unless the law requires us to keep it (the last row).
12 How we keep it safe
- Everything travels over HTTPS/TLS, and stored data sits on encrypted-at-rest infrastructure at our hosting provider.
- Each business's data is kept in its own separate store, and every request is checked against the signed-in account before anything is read.
- Passwords are stored as scrypt hashes — we never see or hold the password itself. Sign-in is rate-limited and locks out after repeated failures, and you can end every active session from your account.
- Access to customer data is limited to what running the service requires.
- We publish a security.txt so researchers can report a problem to us directly, and we would rather hear it from them than from a customer.
If a breach ever affects your personal data and is likely to risk your rights, we will tell the ICO within 72 hours and tell you without undue delay. We would rather write an awkward email than a quiet one.
13 Emails we send on a business's behalf
Some emails come from us but on behalf of the business you contacted: booking confirmations, reschedules, cancellations, enquiry follow-ups, and — if the business switched it on — a single review request a few hours after an appointment. For those:
- The business decides whether to use them, and their details appear on them; replies go to them.
- Review requests are deliberately restrained: one per booking, never a chase, never the same person twice within 90 days, and every one carries an opt-out.
- We never add you to a marketing list, and we never email you about Dave on Duty because you happened to chat with one of our customers' assistants.
14 Your rights
Under UK GDPR you have the following rights. They are free to exercise, and we will not ask you to justify yourself:
- Access — a copy of the personal data we hold about you.
- Rectification — correction of anything wrong.
- Erasure — deletion, where we have no overriding reason or legal duty to keep it.
- Restriction — tell us to hold it but stop using it while something is sorted out.
- Portability — a machine-readable copy, or transfer to someone else. Business customers can do this themselves at any moment from Plan & billing → Download all my data.
- Objection — object to processing based on legitimate interests, including any profiling.
- Objection to direct marketing — absolute, and instantly honoured. No "are you sure?"
- Withdraw consent, where we relied on consent, without affecting what happened before.
15 How to exercise them
Email support@daveonduty.co.uk and say what you want. A human reads it. We respond within one month as the law requires, and usually within a couple of working days because there is rarely a reason to wait.
We may ask you to confirm your identity before acting — not to obstruct you, but because handing someone's conversation history to whoever asks for it would be the real privacy failure. If your request concerns a conversation you had with one of our customers' assistants, we will act and, where appropriate, pass the request to that business, because they are the controller (section 2).
16 Complaints
If you think we have handled your data badly, please tell us first — most things are a misunderstanding we can fix the same day. You also have the right to complain to the UK's data protection regulator, the Information Commissioner's Office (ico.org.uk), and you do not need our permission or agreement to do so.
17 Children
Our service is aimed at businesses and their adult customers, and is not directed at children under 16. We do not knowingly collect children's data. If a child has sent information to one of our assistants, tell us and we will delete it.
18 If you are a business customer
This section is for the people who use Dave to run their business.
- Your visitors' data is yours. You are the controller and we are your processor. We act on your instructions and use your data for nothing of our own — no training, no analytics products, no resale, ever.
- A data-processing agreement covering the Article 28 requirements is already in force — it's Annex A of the Terms, and it applies to every customer automatically without you having to ask. Need it as a separate countersigned document for your compliance file? Email us and we will send it the same day.
- The technical detail your IT or compliance person will ask for — encryption, sign-in security, separation between businesses, what the assistant can and cannot touch — is on the Security & Data page, including an honest list of what we don't have yet.
- The sub-processor list in section 9 is the one to reproduce in your own privacy notice. We will update this page before we ever add to it.
- Take your data whenever you want — Plan & billing → Download all my data gives you one JSON file with your settings, knowledge sources, conversations, leads, bookings and enquiries. No ticket, no wait, no export fee.
- Tell your own visitors. You need to mention the chat assistant in your website's privacy policy — ask us and we will send you wording you can paste in.
- Please don't put special-category data through chat (detailed health records, for example) beyond what a visitor volunteers in ordinary conversation. The assistant isn't built for it and your obligations around it are heavier.
19 If you are in the United States
Dave on Duty is run from the United Kingdom, and everything above applies to you exactly as written. UK and European data-protection law is stricter than most American privacy law, so the simplest way to put it is this: we hold your data to the higher standard wherever you live, rather than dropping to the local minimum. This section says what that means in the language US state privacy laws use.
- We do not sell your personal information, and we do not share it for cross-context behavioural advertising. We haven't in the past twelve months and we have no plans to. There is no advertising business here to sell it to — the money comes from businesses paying a monthly fee, and that is the whole model.
- Your data is stored and processed in the UK, the EU and the United States, by the providers listed in section 9. If you are in the US, your data will normally cross to the UK or EU at some point — that is where our systems live, and it is protected there by law that is generally stronger than the US equivalent.
- Your rights. California's CCPA/CPRA and the equivalent laws in Colorado, Connecticut, Virginia, Texas, Oregon, Montana, Delaware and the rest give residents of those states the right to know what is held, get a copy, correct it, delete it, and opt out of sale, sharing and targeted advertising. Section 14 already gives everyone those rights, whichever state you are in and whether or not your state has passed a law yet. We are not going to check your postcode before deciding how to treat you.
- Sensitive information. We do not ask for it and do not use it to work out anything about you. If a visitor volunteers something sensitive in a conversation, it is used to answer them and nothing else — see section 5.
- You will not be treated worse for asking. No degraded service, no different price, no hassle for exercising any right in this policy.
- Someone can act for you. An authorised agent may make a request on your behalf; we will ask for reasonable proof that you asked them to, for the reason given in section 15.
- If we say no, you can appeal. Reply to the same email and a person — not a form — reviews the decision and answers within 45 days. If you are still unhappy you can complain to your state's Attorney General, and you do not need our agreement to do that.
- Opt-out signals. Browser signals such as Global Privacy Control are respected, though in practice there is nothing for one to switch off: we do not sell or share data, and section 8 explains that our website analytics are our own, cookie-free and never linked to an individual.
- Children. The service is not directed at children and we do not knowingly collect data from anyone under 13, or under 16 (section 17). Tell us if it has happened and we will delete it.
- US business customers. For your visitors' data we are a service provider and processor, not an independent controller — we use it only to run the service for you, never for our own purposes, and we do not sell or share it. The processing terms in Annex A of the Terms already apply to you; email us if your compliance file needs them restated with US statutory wording.
To exercise any of this, use the same route as everyone else: support@daveonduty.co.uk. There is no separate US privacy portal, because there is no separate US standard here.
20 Changes to this policy
We update the version number and date at the top whenever this changes, and keep a note of what the previous version was, so you can tell that something moved. If a change materially affects how we handle personal data, we email account holders before it takes effect rather than quietly editing the page.
21 Contact
Privacy questions, data requests, complaints, or just wanting something explained in plainer English: support@daveonduty.co.uk, or via the Help & support page. There's no privacy-team inbox that nobody reads — it's the same address as everything else, and a person answers it.
