Security & Data

Version 1.0 · Last updated: 9 August 2026 · Written for the person who has to sign this off.

If you are handing a chat assistant your customers' questions, your enquiries and a view of your calendar, you're entitled to know exactly what happens to all of it. This page is the technical answer, in plain English. The legal answer is in the Privacy Policy and the Terms.

Everything below is a description of how the product is actually built today. Where we haven't got something yet, it's in section 10 rather than quietly missing.

1 Encryption

2 Accounts and sign-in

3 Separation between businesses

Every business on Dave on Duty has its own separate data store: its own knowledge base, conversations, leads, bookings and settings. Every request is checked against the signed-in account before anything is read or written, so one customer cannot reach another's data by changing an id in a URL. Our own testing includes deliberately attempting exactly that.

Where a business connects WhatsApp or Messenger, the connection is verified against Meta and bound to that business, specifically so that someone pasting another company's page details cannot intercept their messages.

4 What the AI sees, and what it never does

5 What Dave is allowed to touch

The most reassuring thing about Dave's integrations is how narrow they are. He has no general access to your business — only the specific connections you switch on.

📅 Your calendar: read-only

A connected Google, Outlook or Calendly calendar is read through a read-only busy feed, for one purpose: hiding times you're already busy so Dave never offers a slot you can't do. Nothing is ever written to your calendar. Bookings are recorded in Dave's own system and emailed to you and the customer.

✉️ Email: two addresses only

Dave can email the business owner and the customer in the conversation. That's it. He has no ability to email an arbitrary address, so a visitor cannot use your assistant to send mail to someone else.

📦 Stock & orders: what you upload

On Dave Max he reads the product and order data you provide or the shop connection you authorise. He reads it to answer questions — he doesn't place orders, take payments or change your stock.

🌐 Your website: public pages

The initial scan and the weekly refresh read the public pages of your site, the same ones any visitor or search engine can see. Nothing behind a login.

If you'd like your widget locked to your own domain so the assistant only answers on your website, ask us and we'll set it — it's enforced server-side.

6 Payments

Card payments and subscriptions are handled by Stripe, a PCI-DSS Level 1 payment processor. Card numbers never reach our servers — we never see them, store them or transmit them, and changing a card or cancelling happens inside Stripe's own portal. We hold a customer reference and the plan you are on, nothing more.

We also never take money automatically. There is no card on file during your free trial, top-ups require your explicit approval each time, and no allowance is ever auto-charged.

7 Getting your data out, and deleting it

8 Application security

9 If something goes wrong

If a breach affects personal data and is likely to risk people's rights, we will report it to the ICO within 72 hours and tell affected customers without undue delay — including what happened, what data was involved and what we're doing about it. As a processor for your visitors' data, we tell you promptly so you can meet your own obligations, because that clock is yours, not ours.

We would rather write an awkward email than a quiet one.

10 What we haven't got yet

The honest bit

Security pages usually only list wins. Here is what a careful buyer should know we don't have, because you'd find out eventually and it's better you hear it from us:

11 Paperwork for your compliance file

12 Reporting a security problem

Found something? Please tell us before telling the internet, and we will not be difficult about it. Email support@daveonduty.co.uk with "SECURITY" in the subject, or use the details in our security.txt. We'll acknowledge, fix what needs fixing, and credit you if you'd like the credit.

Anything on this page you want explained further, or evidenced, ask — Help & support.