Legal
Privacy Policy
1. Who we are
FrontDesq is an AI-powered voice receptionist service for small and medium businesses. This Privacy Policy is published by FRONTDESQ LTD (Company No. 17302785), registered in England and Wales, with its registered office at 128 City Road, London, United Kingdom, EC1V 2NX.
We operate the website at frontdesq.co and the FrontDesq SaaS platform (together, the "Service").
When we say "FrontDesq", "we", "us", or "our" in this policy, we mean FRONTDESQ LTD.
If you have any questions about this policy, please contact us at privacy@frontdesq.co.
2. Who this policy applies to
This policy covers four different groups of people, because what we collect and why differs depending on who you are:
Website visitors: anyone who browses frontdesq.co without requesting a demo or creating an account.
Demo call users: anyone who provides their phone number to receive a one-time AI demo call from FrontDesq.
Business customers: businesses and sole traders who create a FrontDesq account, subscribe to a plan, and use FrontDesq to manage their own inbound calls.
End callers: individuals who call a business that uses FrontDesq to handle its inbound calls. These callers are customers or contacts of our business customers, not of FrontDesq directly. When we answer calls on behalf of a business customer, we generally act as a data processor following that business's instructions, not as a controller in our own right. The business customer is responsible for ensuring their callers are informed appropriately.
This policy describes both our activities as a controller (where we determine how and why personal data is used) and our activities as a processor (where we handle caller data on behalf of our business customers).
3. Information we collect and why
3.1 Website visitors
When you visit frontdesq.co, we collect:
- Technical data: IP address, browser type and version, device type, operating system, referring URL, pages visited, and time of visit. We use this for security monitoring, fraud prevention, and to understand how our website is used.
- Contact form submissions: If you use a contact form or chat widget, we collect the name, email address, and message content you provide, in order to respond to your enquiry.
- Cookies and tracking: We use cookies and similar technologies for analytics and to understand how visitors use our site. See Section 9 for more detail on cookies.
Lawful basis (UK GDPR): Legitimate interests, understanding how our website performs, preventing abuse, and improving our service.
3.2 Demo call users
When you enter your phone number on our website and request a demo call, you are providing consent to receive one automated AI call from FrontDesq at that number. We collect:
- Phone number provided at the point of request.
- Timestamp, IP address, and page version at the time of submission, to maintain a record of your consent.
- Consent record: The exact wording of the notice you agreed to and the time you agreed to it.
- Call metadata: Call duration, connection status, and outcome.
- Call recording and transcript: The demo call may be recorded and transcribed. This will be disclosed to you before you submit your number and again at the start of the call. We use demo call recordings, transcripts, metadata, and consent records to provide the demo, maintain evidence of your request, prevent abuse, troubleshoot technical issues, and assess call quality. Where we use demo call data for service improvement, we aim to use aggregated, de-identified, or limited review data wherever reasonably possible. We do not use demo call recordings or transcripts to train AI models without separate, clearly disclosed authorisation.
- Any information you provide during the call: If you share your name, business name, or other details during the conversation, we may retain those as part of the demo interaction record.
Purpose: To deliver the one-time demo call you requested, to maintain a record of your consent, and to assess and improve the quality of our AI receptionist.
Lawful basis (UK GDPR): Consent, as you expressly requested the call and were presented with a clear notice before submitting your number. For security logging, fraud prevention, and aggregate service improvement: legitimate interests.
Important: demo calls are a one-time evaluation tool. Requesting a demo call does not create a subscription, add you to an ongoing marketing list, or authorise further automated calls. If you wish to receive follow-up communications from FrontDesq, we will obtain your separate consent.
3.3 Business customers
When a business creates a FrontDesq account and subscribes to a plan, we collect:
- Account data: Business name, contact name, email address, phone number, business address, and industry.
- Login credentials: Email address and hashed password (we do not store plaintext passwords).
- Subscription and billing records: Plan type, billing cycle, payment status, invoices, and billing history. Payment card details are handled directly by our payment processors and are not stored by us.
- Service configuration: Settings, call scripts, business hours, integration preferences, and any custom instructions you configure for your AI receptionist.
- Support interactions: Any messages or records created when you contact our support team.
- Usage data: Aggregate information about how you use the platform, such as call volumes and feature usage, used for billing, capacity planning, and product improvement.
Purposes: Providing and managing your subscription, processing payments, delivering customer support, maintaining account security, and improving our service.
Lawful basis (UK GDPR): Contract performance, processing necessary to fulfil your subscription agreement with us. Legitimate interests, covering security, fraud prevention, and aggregate service improvement analytics.
3.4 Caller data processed on behalf of business customers
When FrontDesq answers inbound calls on behalf of a subscribed business, the callers to that business may share:
- Name, phone number, and sometimes address or location
- Details about the reason for their call (job requests, appointment needs, enquiry details)
- Preferred times, callback preferences, and other scheduling information
- Any other information they volunteer during the call
In this context, FrontDesq acts as a data processor on behalf of the business customer, who is the data controller. The business customer determines what information their AI receptionist should collect, how it is used, and what follow-up actions are taken, and the business customer is responsible for identifying the lawful basis for collecting, recording, transcribing, storing, and using caller information. FrontDesq processes caller data on the business customer's configuration and instructions.
Business customers are responsible for giving callers appropriate notice that they are speaking with an AI, that calls may be recorded or transcribed, and that their information will be handled in accordance with the business's own privacy obligations. Business customers must ensure that their use of FrontDesq, including any follow-up messages sent to callers, complies with applicable privacy, telecommunications, marketing, and consumer laws in the jurisdictions where they operate.
FrontDesq does not use caller data collected in this capacity for its own marketing purposes, and does not use identifiable caller conversation data to train AI models without explicit separate authorisation and a clear lawful basis.
Call recording and transcription rules vary by jurisdiction, and business customers are responsible for configuring FrontDesq in a way that complies with the laws that apply to their business and callers.
Where business customers use FrontDesq to send follow-up messages to their own callers or leads, the business customer is responsible for ensuring those messages are lawful, including ensuring that any required consent, sender identification, and unsubscribe mechanism are in place.
A note on sensitive information: FrontDesq is a business communication automation tool. It is not designed to handle emergency calls or to provide medical, legal, financial, or other professional advice. Business customers must not configure FrontDesq to collect sensitive personal information (such as health information, financial details, or domestic safety information) unless they have a clearly identified lawful basis, appropriate caller notices, and appropriate safeguards in place.
4. Demo calls: what happens when you request one
This section explains in detail what happens when you submit your number for a FrontDesq demo call, because we know this is the part most people want to understand clearly.
Before the call: By entering your phone number and submitting the request form, you are consenting to receive one automated AI call from FrontDesq at that number. The notice displayed at the point of submission describes this clearly. We log your consent, including the timestamp, your IP address, and the exact wording you agreed to, so that there is a clear record.
During the call: You will be speaking with Amy, FrontDesq's AI receptionist. The call will be clearly identified as an AI call. The call may be recorded and transcribed. Call recording and transcription are used to provide the demo, assess call quality, troubleshoot technical issues, prevent abuse, and improve the FrontDesq service in the limited way described in Section 3.2.
After the call: A brief summary of the call outcome may be generated. We retain the call recording, transcript, and metadata for up to 90 days, after which they are deleted or anonymised from our active systems, subject to backup, legal, security, and provider-retention requirements. Your phone number and consent record are retained for a reasonable period as part of our compliance records (see Section 8).
What we will not do: We will not add your number to an ongoing telemarketing list, make further automated calls to you without separate consent, or share your number with third parties for their marketing purposes.
5. How we use your information
| Purpose | Who it applies to | Lawful basis |
|---|---|---|
| Deliver the demo call you requested | Demo call users | Consent |
| Create and maintain your account | Business customers | Contract |
| Process subscription payments | Business customers | Contract |
| Provide customer support | Business customers | Contract / Legitimate interests |
| Deliver the AI receptionist service | Business customers, end callers (as processor) | Contract (with business customer); business customer's lawful basis for caller data |
| Maintain call recordings and transcripts for quality assurance | Demo call users, end callers (as processor) | Consent (demo); business customer's lawful basis (operational) |
| Monitor website performance and security | Website visitors | Legitimate interests |
| Fraud prevention and abuse detection | All groups | Legitimate interests |
| Comply with legal obligations | All groups | Legal obligation |
| Service improvement analytics (aggregate, non-identifiable) | All groups | Legitimate interests |
| Send transactional communications (invoices, service updates, downtime notices) | Business customers | Contract / Legitimate interests |
| Send optional marketing communications about FrontDesq updates and offers | Business customers (with opt-in) | Consent |
We do not sell personal data to third parties. We do not use personal data for automated profiling that produces legal or similarly significant effects on individuals without human review.
AI and automated decisions: FrontDesq does not use AI to make decisions that produce legal or similarly significant effects about individuals. The AI receptionist may help collect information, create summaries, categorise enquiries, and assist business customers with handling calls, but business customers remain responsible for reviewing and acting on that information. No automated decision made by FrontDesq is final or binding on any individual without human review by the relevant business customer.
6. Legal bases under UK GDPR
For users in the United Kingdom, we are required to identify a lawful basis for each processing activity. The primary bases we rely on are:
Consent: where you have actively agreed to a specific use of your data, such as requesting a demo call or signing up to receive marketing emails. You may withdraw consent at any time without affecting the lawfulness of processing before withdrawal.
Contract performance: where processing is necessary to provide the service you have subscribed to, including account management, billing, and delivering the AI receptionist.
Legitimate interests: where we have a genuine business reason to process data and that interest is not overridden by your privacy rights. We rely on this for website analytics, security monitoring, fraud prevention, and aggregate product improvement. We have assessed these interests and consider them proportionate.
Legal obligation: where we are required to retain or share data to comply with a legal requirement, such as tax records or a valid court order.
7. Australian privacy disclosures
FrontDesq collects and handles personal information in connection with its services to businesses and individuals in Australia. This section provides additional information for individuals in Australia and is designed to support transparent handling of personal information in line with Australian privacy expectations.
What information we collect and why: As described in Section 3 above.
How we collect it: Directly from you when you visit our website, request a demo call, create an account, or contact us. Indirectly through usage of our service.
Overseas disclosure: FrontDesq uses a number of third-party infrastructure and AI service providers. These providers may store or access personal information outside Australia, including in the United States, the European Union, and the United Kingdom. See Section 10 for details of our subprocessors and the countries involved.
Where Australian privacy law applies, we take reasonable steps to ensure that overseas recipients handle personal information in a manner consistent with the Australian Privacy Principles, including through contractual arrangements with our providers where appropriate.
Access and correction: If you are an individual in Australia and wish to access or correct personal information we hold about you, please contact us at privacy@frontdesq.co. We will respond within a reasonable timeframe.
Complaints: If you have a concern about how we have handled your personal information and you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
8. Data retention
We do not keep your data for longer than necessary. The following periods apply by category:
| Category | Retention period |
|---|---|
| Demo call recordings and transcripts | 90 days from the date of the call |
| Demo call consent records (number, timestamp, IP, consent text) | 3 years from the date of the call, or longer if required by law |
| Business customer account data | Duration of active subscription, plus 3 years after closure |
| Billing and payment records | 7 years (UK tax and accounting obligations) |
| Customer support correspondence | 3 years from closure of the interaction |
| Call recordings and transcripts processed for business customers | As configured by the business customer (typically 30–90 days unless the customer has enabled longer retention) |
| Website logs and analytics data | Up to 26 months in aggregated form |
| Security and fraud monitoring logs | Up to 12 months |
When data is no longer required, we delete or anonymise it securely. If you request deletion of your data before the end of the applicable retention period and we are not legally required to retain it, we will delete it promptly.
9. Cookies and tracking
Our website uses cookies and similar technologies. We use:
- Strictly necessary cookies: Required for the site to function (e.g., session management). These are always active.
- Analytics cookies: Help us understand how visitors use our site (Google Analytics). Where possible, we use aggregate or de-identified reporting. You can decline these by blocking cookies for our site in your browser settings.
- Product analytics and session replay: We use Microsoft Clarity to see how pages are used, through heatmaps and recordings of on-page activity such as scrolling, clicks and navigation. We mask what you type into our forms, so your name, business name, phone number and email address are not captured in a recording. We use this to find where the site is confusing or broken, not to identify individual visitors.
You can control cookies through your browser settings. Disabling cookies may affect the functionality of certain parts of our website. This section reflects the cookies and tools we actually deploy. If you see a discrepancy, please contact us at privacy@frontdesq.co.
10. Sharing and subprocessors
We use trusted third-party providers to help us operate and deliver FrontDesq. These providers may process personal information for hosting, database storage, telephony, AI voice processing, speech-to-text, text-to-speech, email delivery, analytics, payments, security, and customer support. Where required, we put appropriate contractual safeguards in place with providers that process personal information on our behalf. We may update our provider list from time to time as our service evolves.
Key providers we use or may use to deliver the Service include:
| Provider | Function | Main provider location / possible processing region |
|---|---|---|
| Telnyx | Telephony and voice media (inbound call delivery, speech processing) | United States |
| Anthropic (Claude) | AI language model that powers the call conversation | United States |
| Supabase | Database and data storage | Australia or other configured project region |
| Fly.io / Railway | Application hosting and infrastructure | United States / EU |
| Vercel | Website hosting | United States / EU |
| Resend | Transactional email delivery | United States |
| Google Analytics | Website analytics | United States |
| Microsoft Clarity | Product analytics, heatmaps and session replay | United States |
| Cal.com | Demo call scheduling (name, email, phone and business name you enter when booking) | United States |
| Stripe | Payment processing | United States |
| Zadarma | Outbound calling infrastructure | EU |
We do not share personal data with third parties for their own marketing purposes.
We may disclose personal data if required to do so by law, regulation, court order, or in connection with the enforcement of our legal rights.
If FrontDesq is involved in a merger, acquisition, or sale of assets, personal data may be transferred as part of that transaction. We will notify affected individuals if this occurs and their data is affected.
11. International data transfers
FrontDesq is a UK-registered company serving customers in Australia and the UK. Our infrastructure and AI service providers are primarily based in the United States, with some capacity in the EU.
For UK users: Where personal data is transferred outside the UK to countries not covered by an adequacy decision, we rely on the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses, as appropriate, combined with a data protection test where required.
For Australian users: Where personal information is disclosed overseas, including to US-based AI and telephony providers, we take reasonable steps to ensure it is handled consistently with the Australian Privacy Principles. Where technically feasible, we aim to store core operational data in an appropriately configured project region.
You may contact us at privacy@frontdesq.co to request further information about the specific safeguards in place for international transfers.
12. Security
We take appropriate technical and organisational measures to protect personal data against unauthorised access, loss, destruction, or alteration. These include:
- Encryption of data in transit (TLS) and at rest where applicable
- Access controls and least-privilege principles for staff and systems
- Logging and monitoring of access to systems holding personal data
- Secure credential storage (hashed passwords; no plaintext storage)
- Incident response procedures
We select subprocessors with strong security practices and require them to maintain appropriate technical and organisational safeguards.
No system is completely immune to risk. In the event of a personal data breach that is likely to result in high risk to individuals, we will notify affected individuals and relevant supervisory authorities as required by applicable law.
13. Your rights (UK users)
If you are in the UK, you have the following rights under UK GDPR:
- Access: Request a copy of the personal data we hold about you.
- Correction: Ask us to correct inaccurate or incomplete data.
- Erasure: Ask us to delete your data where there is no legitimate reason to continue processing it.
- Restriction: Ask us to restrict processing of your data in certain circumstances.
- Objection: Object to processing based on legitimate interests.
- Portability: Receive your data in a structured, machine-readable format in certain circumstances.
- Withdraw consent: Where processing is based on consent, withdraw it at any time without affecting prior processing.
To exercise any of these rights, contact us at privacy@frontdesq.co. We will respond within one calendar month. If we are unable to act on your request, we will explain why.
If you are not satisfied with our response, you have the right to complain to the Information Commissioner's Office (ICO) at ico.org.uk or by calling 0303 123 1113.
14. Your rights (Australian users)
If you are in Australia, you have the right to:
- Access personal information we hold about you (APP 12).
- Correct personal information that is inaccurate, out of date, incomplete, irrelevant, or misleading (APP 13).
- Complain about how we have handled your personal information.
Contact us at privacy@frontdesq.co. We aim to respond within 30 days.
If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au or by calling 1300 363 992.
15. Marketing communications
FrontDesq may send marketing communications to business customers and prospects who have opted in to receive them (such as product updates, new features, or offers). We will always identify ourselves as the sender and provide a clear, easy way to unsubscribe. You can unsubscribe at any time by clicking the unsubscribe link in any marketing email or by contacting us at privacy@frontdesq.co.
Requesting a demo call does not constitute consent to receive ongoing marketing communications.
Transactional communications, such as subscription confirmations, invoices, password reset emails, and service notices, are sent as necessary to fulfil your subscription agreement and are not affected by marketing opt-out preferences.
For Australian recipients: Commercial electronic messages (including email, SMS, and similar messages) are only sent where required consent exists. All such messages will identify FrontDesq as the sender, include valid contact details, and include a clear and functional unsubscribe mechanism. Unsubscribe requests will be honoured within 5 business days, in line with obligations under the Spam Act 2003 (Cth) and ACMA guidance.
16. Children
FrontDesq is a business-to-business service. We do not knowingly collect personal data from individuals under the age of 18. If you believe a minor has submitted data to us, please contact us and we will delete it promptly.
17. Changes to this policy
We may update this policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons. We will update the "Last updated" date at the top of this page and, where changes are material, we will notify business customers directly by email.
We encourage you to review this policy periodically.
18. Contact us
FRONTDESQ LTD Company No. 17302785 Registered in England and Wales Registered office: 128 City Road, London, United Kingdom, EC1V 2NX
Privacy enquiries: privacy@frontdesq.co General contact: hello@frontdesq.co
This Privacy Policy was last updated in July 2026. If you have any concerns about how we handle your personal information, we welcome the opportunity to address them, please reach out to us before raising a formal complaint.