Skip to content
EdgeAudit ← Back to home
Privacy

Privacy policy

Last updated: 19 July 2026

The short version — what dentists, solicitors and B&B owners ask us most:

Full legal version below.

This Privacy Policy explains how EdgeAudit (operated as a UK sole trader based in the North-West of Northern Ireland — contact hello@edgeaudit.app) collects, uses, and protects information about you when you use our AI voice receptionist service and this website.

1. What we collect

From clients (businesses)

From callers (people who phone your business)

From website visitors

2. How we use it

3. Who we share it with

EdgeAudit is a small Northern Irish operation. The only third parties we share data with are the infrastructure providers strictly necessary to deliver the service:

Anthropic is the conversational AI on every client line. We also keep our own internal test and demo assistants, some of which run on other AI language models (currently Google's Gemini, OpenAI and xAI) while we compare them. These are our own numbers, not client lines, and no client's calls are routed through them. If we ever changed the AI provider on a live client line we'd tell that client in advance, as their DPA requires.

We don't sell your data. We don't share it with advertisers. We don't have advertisers.

4. How long we keep it

5. Your rights (UK / EU GDPR)

You have the right to access, rectify, erase, restrict and port your data, and to object to processing. Email hello@edgeaudit.app with "GDPR request" in the subject and we'll respond within 30 days.

6. Security

All data is encrypted in transit (TLS 1.3) and at rest. Access is restricted to the operator through private, credential-protected accounts on a least-privilege basis.

7. Data storage and international transfers

By default, call audio, transcripts and metadata are stored by our voice orchestration provider (Vapi.ai) on their infrastructure. Underlying AI providers (Anthropic, Deepgram, ElevenLabs) may process data in the United States. Where personal data is transferred outside the UK we rely on an appropriate UK GDPR Chapter V safeguard for each transfer — the UK Extension to the EU-US Data Privacy Framework where that provider is certified, otherwise the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses.

For healthcare and legal clients who require it, we can configure your specific deployment to use UK/EU-only data residency and to exclude particular providers from your conversation data. This is set up per-client at onboarding and documented in your Data Processing Agreement (DPA). If data residency is a regulatory requirement for you, please raise this on the discovery call so we can confirm the configuration in writing before you sign.

8. Cookies

This website uses no cookies. Cloudflare Web Analytics is cookie-free. If we add any in future, we'll display a consent banner before they're set.

9. Changes

We may update this policy as the service evolves. Material changes will be emailed to active customers. The "Last updated" date at the top tracks revisions.

10. Contact

Questions, requests or complaints: hello@edgeaudit.app.

If you're unhappy with how we've handled a request, you can complain to the UK Information Commissioner's Office at ico.org.uk.

WhatsApp Stephen