Cloudax Connect Privacy Policy
Cloudax Ltd
Last updated: 27 August 2026
1. Who We Are and What This Policy Covers
Cloudax Ltd (“Cloudax”, “we”, “us” or “our”) is a company incorporated in England and Wales under company number 14717183. Our registered office is at 167-169 Great Portland Street, 5th Floor, London, W1W 5PF.
This Privacy Policy explains how we handle Personal Data when you visit our website, create or use a Cloudax Connect account, communicate with us, or otherwise interact with Cloudax in connection with our conversational AI and contact-centre platform. It also explains our role when our business customers use Cloudax Connect to handle calls, chats, video sessions and other communications involving their own contacts.
This is a privacy notice, not a request for blanket consent. We rely on the lawful bases described below. Where we specifically ask for consent, you may withdraw it at any time without affecting processing that took place before withdrawal.
2. Our Roles
Cloudax is a controller when we decide why and how to process Personal Data about website visitors, prospective customers, account users, billing contacts, support contacts and people who communicate directly with us.
We may also act as an independent controller for limited service metadata that we need for billing, fraud and abuse prevention, security, regulatory compliance, legal claims and maintaining auditable business records. This may include Account identifiers, usage records, transaction references, security events and provider cost records, but does not permit us to use customer conversation content for unrelated purposes.
Cloudax generally acts as a processor for Customer Data that a business customer submits to or generates through Cloudax Connect, including contact lists, call recordings, transcripts and conversation content. The customer decides why the communication takes place, who is contacted, what the Agent does and whether recording is enabled. The customer is normally the controller, and our processing is governed by its instructions and applicable data processing terms.
If you received a call, chat, SMS, email or other communication from one of our customers, that customer's privacy notice applies. Please contact that customer first to exercise your rights. We will assist the customer as required by law.
3. Personal Data We Collect
Depending on how you interact with us, we may collect:
- Identity and contact data: name, business email, telephone number, job title, organisation, profile image and account identifiers.
- Account and authentication data: hashed or otherwise protected credentials, sign-in records, multi-factor authentication details, roles, permissions, preferences and acceptance records.
- Commercial and billing data: subscription, plan, usage, invoice, payment status, billing contact and transaction records. Payment providers process full payment-card details; we do not ordinarily store them.
- Technical and usage data: IP address, browser, operating system, device and session identifiers, timestamps, pages and features used, API activity, audit events, error logs, latency, token and message usage, call volumes and associated costs.
- Support and communications data: support tickets, correspondence, feedback, survey responses and information supplied to diagnose an issue.
- Integration data: integration settings, encrypted credentials or tokens, webhook activity and data exchanged with services you choose to connect.
- Customer Data processed on behalf of customers: names, phone numbers, contact lists, call and message metadata, audio, video, recordings, transcripts, summaries, Agent outputs, call outcomes and other content included in interactions.
- Configuration and knowledge data: prompts, scripts, call flows, documents, filenames, file metadata, processed document chunks, embeddings, knowledge bases and Agent settings.
Conversation content may contain special-category data, such as health information, or information about criminal allegations if a customer chooses to process it. The customer is responsible for establishing an applicable Article 9 or 10 condition and providing required notices. Account users should not submit such data unless it is necessary and authorised.
Please do not include special-category data, criminal-offence data, passwords, payment card details or other highly sensitive information in support requests, feedback or free-text forms unless we specifically request it through an appropriate channel. If such information is provided unexpectedly, we will limit access and use it only as necessary to address the request, protect legal rights or comply with law.
4. Where Personal Data Comes From
We collect Personal Data:
- directly from you when you register, configure the Platform, subscribe, contact us or use the Services;
- from your employer, organisation administrator or another user who invites you;
- automatically from your device, browser and use of the Platform;
- from customers that upload contacts or use the Platform to communicate with people;
- from integrations and services you or a customer choose to connect; and
- from service providers, payment providers, security partners and publicly available business sources where lawful.
Where information is required to create an Account, provide a paid Service, secure the Platform or comply with law, failing to provide it may mean we cannot provide the relevant Service.
5. How and Why We Use Personal Data
- Provide and administer the Services, including Accounts, authentication, calls, chats, Agents, integrations, storage, support and requested features. Our lawful bases are performance of a contract and our legitimate interests in supplying our business services.
- Bill and manage our commercial relationship, including metering, invoices, payments and account administration. Our lawful bases are performance of a contract, legal obligations and legitimate interests in being paid and keeping business records.
- Secure and operate the Platform, including access control, logging, troubleshooting, abuse detection, fraud prevention, backups and incident response. Our lawful bases are legitimate interests in protecting our systems, customers and users and, where applicable, legal obligations.
- Communicate with you about support, service notices, security, changes and requests. Our lawful bases are performance of a contract and legitimate interests in managing the service relationship.
- Improve and develop the Services using performance data, feedback and aggregated or anonymised insights. Our lawful basis is legitimate interests in understanding and improving our products. Identifiable Customer Data is used for model training only where the customer has expressly authorised that use.
- Market relevant business services to existing or prospective business contacts where permitted. Our lawful bases are legitimate interests or consent where PECR or other law requires it. You can opt out at any time.
- Comply with law and protect rights, including responding to lawful requests, establishing or defending legal claims, enforcing terms and supporting audits. Our lawful bases are legal obligations and legitimate interests in protecting Cloudax and others.
- Complete a corporate transaction, such as financing, reorganisation, merger or sale, subject to appropriate confidentiality. Our lawful basis is legitimate interests in operating and developing our business.
When Cloudax acts as processor, we process Customer Data to provide the Services on the customer's documented instructions, rather than relying on our own lawful basis.
Where we rely on legitimate interests, those interests include operating and securing a business service, preventing fraud, supporting customers, improving reliability and managing business relationships. We consider the necessity and impact of the processing and do not rely on those interests where your rights and freedoms override them. Contract is relied on only where processing is necessary for our contract with the individual concerned; for personnel using an employer's Account, we generally rely on legitimate interests instead.
6. AI Processing and Automated Decisions
Cloudax Connect uses AI models to transcribe and generate speech, interpret messages, retrieve knowledge, create summaries and responses, route interactions and perform actions configured by customers. AI outputs are probabilistic and may be inaccurate.
Cloudax does not use Account Personal Data to make solely automated decisions about individuals that produce legal or similarly significant effects. Customers may configure Agents or integrations that contribute to their own decisions. In that case, the customer is responsible for identifying the lawful basis, giving required information, implementing human review and providing any rights required by Articles 21 and 22 UK GDPR.
Customer Data is sent to selected AI and speech providers for routine inference only as needed to provide the configured feature. We do not use identifiable Customer Data to train general-purpose models for other customers unless the customer has expressly authorised that separate use and all applicable lawful-basis, transparency and special-category requirements have been satisfied. Customer authorisation is not treated as consent from an affected individual where the law requires that individual's consent.
7. Sharing Personal Data
We may share Personal Data with:
- cloud hosting, storage, database, networking, security and content-delivery providers;
- AI model, speech-to-text, text-to-speech, telephony, communications and email providers needed to deliver configured features;
- authentication, payment, billing, analytics, monitoring and customer-support providers;
- third-party integrations selected and directed by you or a customer;
- our professional advisers, auditors, insurers and financing providers under confidentiality duties;
- regulators, courts, law-enforcement bodies or other recipients where disclosure is legally required or necessary to protect rights and safety; and
- a prospective buyer, seller or transaction participant in connection with a business transfer, subject to appropriate safeguards.
Depending on the selected features and deployment, our core providers include Microsoft Azure for hosting, storage and communications; OpenAI for language processing and embeddings; Deepgram, ElevenLabs and Cartesia for speech processing; Trieve for knowledge retrieval; Stripe for billing and fraud prevention; Sentry for error and performance monitoring; Cloudflare for network security and bot prevention; Resend and Microsoft services for email, support and operational communications; and Cloudmersive for malware scanning where enabled. Providers and features may change. An up-to-date subprocessor list, including the relevant processing location where available, is available on request.
Customer-selected integrations are separate from our core providers. If a customer connects a CRM, calendar, identity provider, payment service, telephony carrier, observability collector, webhook, HTTP tool or MCP server, we disclose Customer Data to that destination on the customer's instructions. The destination's own terms, privacy practices, locations and retention periods apply after it receives the data.
We require processors to protect Personal Data and process it only for contracted purposes. We do not sell Personal Data or share it for third-party cross-context behavioural advertising.
8. International Transfers
The principal storage region for Customer Data depends on the customer's order, deployment and configured features and may be in the United Kingdom or European Economic Area. Some providers, including global AI, speech, communications, security and support providers, may process data in the United States or other countries. Data may therefore be accessed or routed internationally even where its primary storage is in the United Kingdom.
Where Personal Data is transferred from the UK to a country not covered by UK adequacy regulations, we use an approved safeguard where required, such as the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, and carry out a transfer risk assessment where required. For an eligible US recipient certified under the Data Privacy Framework, we may rely on the UK Extension to the EU-US Data Privacy Framework as an adequacy regulation. For restricted transfers from the EEA, we use an adequacy decision, the EU-US Data Privacy Framework where applicable, or another lawful safeguard such as the EU Standard Contractual Clauses. You may contact us for information about the mechanism relevant to your data.
9. Data Retention
We keep Personal Data only for as long as necessary for the purpose for which it was collected, including service, security, legal, accounting and dispute requirements. We consider the amount, nature, sensitivity and risk of the data when setting retention.
- Conversation data: recordings, transcripts and related records are retained for up to 12 months by default, unless the customer selects or agrees a different period.
- Modified Data Retention: eligible Enterprise customers may select a shorter 1, 3 or 6 month Cloudax retention period for interaction content. The paid benefit is shorter retention; identifiable Customer Data is not used for model training without express authorisation under our standard policy.
- Zero Data Retention: eligible Enterprise customers may arrange deletion of interaction content after an interaction completes. This covers recordings, transcripts, message bodies, summaries, extracted fields, memories, attachment objects and content-bearing tool or webhook payloads. Minimal usage, payment, timestamp, status, consent, security and audit records remain. Contacts, Agent configuration and knowledge bases are service configuration and are not interaction content.
- Documents and configurations: generally retained while the relevant Account or content remains active, then deleted according to our offboarding and backup cycle.
- Account and relationship data: retained while the Account is active and afterwards where reasonably needed for support, security, disputes and legal compliance.
- Financial and tax records: generally retained for six years after the relevant financial period, or longer where law requires.
- Security, access and operational logs: retained for shorter, risk-based periods unless needed to investigate an incident or meet a legal requirement.
- Aggregated or genuinely anonymised data: may be retained because it no longer identifies an individual.
These retention options do not delete data from customer-selected integrations, message recipients or statutory records, and do not accelerate deletion from disaster-recovery backups before their normal protected lifecycle. Data already disclosed to a customer-selected destination remains subject to that destination's retention practices.
Deletion from active systems may not immediately remove encrypted backup copies. Backups are protected, not used for ordinary processing and deleted or overwritten in the normal cycle.
10. Security
We use technical and organisational measures designed to provide security appropriate to the risk, including encryption in transit and at rest, role-based access controls, authentication safeguards, logging, monitoring, vulnerability management, backups, incident procedures, supplier controls and staff confidentiality and training.
No online service is completely secure. Account users are responsible for protecting credentials, configuring permissions appropriately and notifying us promptly of suspected compromise. If a Personal Data breach occurs, we will investigate and notify affected controllers, individuals or regulators where and within the period required by applicable law.
11. Cookies and Similar Technologies
We use cookies, browser storage and similar technologies. Strictly necessary technologies support authentication, security, network management and core functionality. Preference technologies remember choices. Analytics technologies, where enabled, help us understand use and performance. Marketing technologies may be used only where deployed and permitted.
We use non-essential technologies only with consent where PECR requires it. You can accept or reject non-essential categories through the cookie banner and can also clear browser storage or cookies. Rejecting non-essential technologies does not prevent core use, although some optional features may be affected. Necessary technologies cannot be disabled through the banner.
Technologies used by the Services may include:
- Consent preferences: remember whether you accepted or rejected optional technologies until you clear browser storage or change the preference.
- Authentication and security: maintain signed-in sessions, protect forms and detect abuse. Account sessions generally last up to seven days unless ended sooner; Cloudflare Turnstile and similar security technologies may set shorter-lived identifiers.
- Interface preferences: remember settings such as navigation state, generally for up to seven days or until browser storage is cleared.
- Chat functionality: maintain a chat visitor identifier, generally for up to 24 hours, and may retain local conversation state in the browser until it is cleared or replaced.
- Affiliate referral attribution: retain a signed first-touch referral code for up to 90 days where needed to administer the partner programme, attribute qualifying sign-ups and calculate commissions. This essential record remains when non-essential technologies are rejected.
- Marketing attribution: where you consent, remember campaign parameters, advertising click identifiers, referring pages and the first landing page for up to 90 days so we can understand how people find Cloudax.
Browser and device settings can also be used to remove stored information. Withdrawing consent does not affect storage or access that occurred lawfully before withdrawal. Technologies placed by a customer inside an embedded Agent or by a connected third-party service are controlled by that customer or provider and should be described in its own notice.
12. Marketing Communications
We may send service-related communications that are necessary to administer or secure your Account. Where lawful, we may separately send information about Cloudax products and services to business contacts. You may opt out of marketing at any time by using the unsubscribe link or contacting us. Opting out of marketing does not stop essential service messages.
13. Your Data Protection Rights
Depending on the circumstances and applicable law, you may have the right to:
- access your Personal Data and receive information about its processing;
- correct inaccurate or incomplete Personal Data;
- request erasure of Personal Data;
- restrict processing in certain circumstances;
- receive certain data in a structured, commonly used and machine-readable format and transmit it to another controller;
- object to processing based on legitimate interests and object at any time to direct marketing;
- withdraw consent at any time where processing relies on consent; and
- ask for human intervention and challenge a qualifying solely automated decision.
Rights are not absolute and exemptions may apply. We may ask for information needed to verify your identity and authority. There is normally no fee, but a reasonable fee may apply to manifestly unfounded or excessive requests. We normally respond within one month and will tell you if the law allows us to extend that period.
To exercise a right concerning data controlled by a Cloudax customer, contact that customer. For data Cloudax controls, email [email protected] with the subject “Data Protection Enquiry”.
14. Children and Vulnerable People
Cloudax Connect Accounts are intended for business users aged 18 or over. We do not knowingly allow children to create Accounts. The Platform may process communications involving children or vulnerable people on behalf of a customer where that customer has a lawful and appropriately safeguarded use case. In those circumstances, the customer is responsible for required notices, lawful bases, age-appropriate design, consent or authorisation, safeguarding and human oversight.
15. Complaints
You may make a data-protection complaint by emailing [email protected] with the subject “Data Protection Complaint” or by writing to the address in Section 17. We will acknowledge your complaint within 30 days, investigate it without undue delay, keep you appropriately informed, and explain the outcome and any action taken. Please provide enough information for us to understand the concern and identify the relevant data. You also have the right to complain to the UK Information Commissioner's Office:
Information Commissioner's Office
Website: ico.org.uk/make-a-complaint
Telephone: 0303 123 1113
If you are outside the UK, you may also have the right to complain to the data-protection authority in the country where you live or work or where the alleged infringement took place.
16. Changes to This Policy
We may update this Policy to reflect changes to our Services, processing or legal obligations. We will post the revised version and update the date above. If a change materially affects how we use Personal Data, we will provide an appropriate additional notice, such as an Account message or email, before the change takes effect where required.
17. Contact Us
For questions, concerns or requests about this Policy or Personal Data controlled by Cloudax, contact:
Cloudax Ltd
Data Protection Enquiry
167-169 Great Portland Street, 5th Floor
London, W1W 5PF
United Kingdom
Email: [email protected]
Company number: 14717183
Please also review our Terms of Service, which govern use of Cloudax Connect.