Skip to main content
    Cloudax
    Partners
    Sign inLet's Talk

    Company › Legal

    Your data,
    handled with care.

    How we collect, use, and protect personal data, in plain English, written to UK GDPR standards.

    Privacy by design, not afterthought.

    Built to the compliance posture regulated buyers require.

    Cloudax Ltd ("we", "our", "us", "Cloudax") is committed to protecting and respecting your privacy. This policy explains how we collect, use, store and share personal data in accordance with the UK GDPR, the Data Protection Act 2018, and, where applicable, the EU GDPR.

    It covers everything we do that involves personal data about you, including:

    • Your use of this website (cloud.ax) and its sub-domains.
    • Interactive demos and trials you run (including live call demonstrations and the phone-number box on the homepage), which place an automated call to a number you provide.
    • Contact, consultation, booking and careers enquiries.
    • Communications between you and our team by email, phone or meeting.

    Cloudax Ltd is the data controller for personal data collected through this website. If you use the Cloudax Connect platform under a separate customer agreement, that agreement (not this policy) governs how we process personal data as your processor.

    Four commitments we hold ourselves to.

    01

    Only what we need

    We collect the minimum data required to answer your enquiry, run your demo, or keep the site secure. Nothing more, nothing speculative.

    02

    Clear, consented use

    Every use of your data has a lawful basis under UK/EU GDPR: consent where it should be, legitimate interest only where it genuinely applies.

    03

    Carefully selected processors

    A small number of contracted sub-processors help run the site, deliver demos and secure our infrastructure, all bound by written agreements.

    04

    Your rights, honoured

    Access, correction, erasure, portability, withdrawal of consent: all exercisable at any time by emailing us. We respond within a month.

    The data we hold, and why.

    We only collect what we need. The exact data depends on how you interact with us.

    Contact & enquiry data

    Identity & contact

    First name, last name, email address and phone number you submit through Contact, Book a Consultation, careers or demo forms.

    Company context

    Company name, website URL, role, country and any free-text message you add.

    Live AI demo data

    Call inputs

    The UK phone number you submit, your name, and, if provided, your email and company website URL.

    Call content

    Audio of the call with the AI agent (both sides), a full text transcript, AI-generated summary, sentiment and call metadata (duration, timestamps, outcome).

    Website context

    Publicly accessible content fetched from the website URL you provide (via Jina AI Reader or a direct HTTPS request) so the AI can tailor the conversation to your business.

    Routing telemetry

    SIP signalling data, carrier information and call status: the technical breadcrumbs needed to place and supervise the call.

    Technical & security data

    Device & network

    IP address, approximate location, browser type/version, device type, operating system, referring URL.

    Bot-detection signals

    Short-lived Cloudflare Turnstile tokens on demo forms, designed not to use tracking cookies and to minimise personal data.

    Rate-limit counters

    In-memory IP and phone-number counters retained for up to one hour, so the same person can't trigger unlimited demo calls.

    Server logs

    Request metadata (method, path, status code, timestamp, IP) written to security and operational logs.

    Website analytics

    Aggregate usage

    Subject to your cookie preferences, we collect anonymised analytics to understand how people use the site.

    Your choice

    See our Cookies Policy for the full list and how to change your preferences at any time.

    Seven purposes. No more.

    Every use is tied to a lawful basis under UK and EU GDPR.

    Delivering the demo you requested

    Placing the call, reading your website to personalise the script, recording and transcribing the call, and handling follow-up messages or retries.

    Responding to you

    Replying to enquiries, scheduling meetings, answering platform questions, and sending quotes or proposals.

    Sales and business development

    Contacting you after a demo by phone, email or LinkedIn to discuss your experience and, where relevant, present Cloudax Connect. You can opt out any time.

    Service quality and product improvement

    Reviewing recordings and transcripts to find bugs, tune the AI agent, and improve voice quality, latency, routing and safety.

    Security, anti-fraud and abuse prevention

    Detecting automated traffic, enforcing rate limits, blocking misuse of the demo, and investigating incidents.

    Legal and regulatory compliance

    Record-keeping, responding to lawful requests from authorities, and enforcing our Terms & Conditions.

    Aggregated analytics

    Producing non-identifying statistics about how people use our website and demos.

    We don't sell your data. Ever.

    Cloudax does not sell personal data. Our UKAS-accredited ISO 27001 information-security programme keeps that promise operational (not just marketing) with encryption in transit and at rest, least-privilege access, and independent penetration testing.

    ISO 27001

    UKAS-accredited

    TLS

    Encryption in transit

    Least-privilege

    Access by default

    Annual

    Independent pen-test

    Who we share data with.

    A small, carefully selected set of processors, all bound by written contracts that require appropriate security and limit processing to our instructions.

    Cloud hosting & CDN

    Our infrastructure provider & Cloudflare

    Content delivery, WAF protection, and Cloudflare Turnstile for bot detection on demo forms.

    Website analytics

    Microsoft Clarity

    Session replay and heatmap analytics that help us understand how visitors use the site. Only loads if you accept non-essential cookies in our cookie banner, and Microsoft does not use this data for advertising.

    Voice platform & telephony

    Cloudax's voice stack

    We place the outbound demo call ourselves, over SIP, through regulated UK carriers, using specialist sub-processors for speech-to-text, voice synthesis and streaming the conversation to the AI.

    Website reader

    Jina AI Reader

    Fetches the public contents of any website URL you supply so the AI agent can personalise the call. If Jina is unavailable we fall back to a direct HTTPS fetch from our server.

    Notification & productivity

    Microsoft 365

    Outlook, Teams and Bookings for customer communication and scheduling.

    Internal webhook

    Power Automate sends a short record of each demo request (name, phone, email, website) to our Teams workspace so we can follow up.

    Analytics

    Aggregated usage only

    Strictly subject to your cookie preferences. See our Cookies Policy for the complete list.

    Professional advisers & authorities

    Legal, accounting & insurance

    Our lawyers, accountants, auditors and insurers, where necessary.

    Authorities

    If required by law, court order or to protect our rights or the safety of others.

    What you can ask us to do.

    To exercise any right, email [email protected]. We respond within one month.

    Access

    Request a copy of the personal data we hold about you.

    Rectification

    Ask us to correct inaccurate or incomplete data.

    Erasure

    Request deletion of your data (the “right to be forgotten”) where applicable.

    Restriction & objection

    Restrict or object to our processing, including profiling activities.

    Portability

    Receive your data in a structured, commonly used, machine-readable format.

    Withdraw consent

    Withdraw consent at any time, without affecting processing carried out before withdrawal.

    Automated decisions

    Not be subject to decisions based solely on automated processing that produce legal or similarly significant effects. Our demos are informational; they do not do this.

    The legal ground for every use of your data.

    Plus the specific consent you give when triggering a live AI demo.

    Demo consent: what you agree to

    When you submit your number through the homepage hero or any other interactive demo, you expressly consent to:

    • Cloudax placing an automated voice call from an AI agent to the number you provide.
    • The call beingrecorded, transcribed and analysed by Cloudax and our voice, speech-to-text and AI sub-processors, so we can operate the demo, produce a summary, and improve the service.
    • Cloudax retaining your name, phone, email (if supplied), company website (if supplied), the contents of any website we fetch to personalise the script, the call recording, transcript, summary and related metadata.
    • Cloudax contacting you after the demo (by phone, SMS, email or messaging) to follow up. We will stop on request.

    You confirm that:

    • You own the phone number you submit, or you have the number holder's authority to receive an automated AI call on it.
    • You are at least 18 years old.
    • You understand the call is with an AI agent, not a human.

    You can withdraw consent at any time by emailing [email protected]. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

    Lawful bases under UK / EU GDPR

    • Consent (Article 6(1)(a)):demo calls, sales follow-up after a demo, non-essential cookies, and marketing communications.
    • Contract (Article 6(1)(b)):taking steps at your request to provide information, quotes or demos prior to entering into a contract, and performing any contract you sign with us.
    • Legitimate interests (Article 6(1)(f)):running and securing our website, preventing fraud and demo abuse, keeping the platform stable, and responding to business enquiries from corporate contacts. Your rights will always override where they apply.
    • Legal obligation (Article 6(1)(c)):meeting tax, accounting, safeguarding and regulatory duties.

    How we keep data safe, and for how long.

    International transfers, security controls and retention windows: documented, not assumed.

    International data transfers

    We are based in the United Kingdom and host production infrastructure in the UK or EEA wherever practical. Some sub-processors (notably Cloudflare, Microsoft and certain AI services) may process data in countries outside the UK, including the United States. Where that happens we rely on appropriate safeguards (UK/EU adequacy regulations where they exist, the UK International Data Transfer Addendum, or the EU Standard Contractual Clauses) together with supplementary measures such as encryption in transit and access controls.

    Data security

    We operate a UKAS-accredited ISO 27001 certified information-security programme with technical and organisational measures designed to protect personal data against unauthorised or unlawful processing, accidental loss, destruction or damage:

    • Encryption of data in transit (TLS) and at rest.
    • Role-based access control and least-privilege by default.
    • Centralised logging, monitoring and alerting.
    • Annual independent penetration testing.
    • Regular backups, disaster-recovery testing and change management.
    • Security training and background checks for our people.

    Data retention

    We keep personal data for as long as we genuinely need it, and no longer than is proportionate. In practice:

    • Records of your interactions with us: demo submissions, enquiries, meeting notes and email exchanges are held in our internal business systems (CRM, mailbox, collaboration tools) for as long as the relationship or enquiry is relevant. Individual records may be retained indefinitely as part of normal record-keeping, but we will not actively re-use them once they stop being relevant to a live or realistic future conversation.
    • Demo call recordings and transcripts: typically removed once they're no longer useful for support, quality review or debugging.
    • Careers applications: retained for as long as the role is open, plus a reasonable period afterwards; longer only if you've asked us to keep your details on file.
    • Rate-limit counters and short-lived security tokens: kept in memory for up to one hour.
    • Server and security logs: typically 90 days, longer if needed for an incident investigation or legal reason.
    • Accounting and tax records: at least six years, as required by UK law.

    You can ask us to delete your data at any time. We will delete or anonymise it in the systems we control and stop relying on it for any further contact. Where the data is embedded in ongoing correspondence or held by third-party tools, we'll remove it as far as reasonably possible as part of normal record-management.

    Cookies

    Our website uses a small number of essential and (with your consent) analytics cookies. See our Cookies Policy for the full list and how to change your preferences at any time.

    Accountability baked in.

    Children

    Cloudax is a B2B service. Our website, demos and communications are not directed at children under 16, and we do not knowingly collect personal data from children.

    Changes to this policy

    We may update this Privacy Policy in response to changing legal, technical or business developments. Material changes are reflected in the Last Updated date and, where appropriate, brought to your attention directly.

    Complaints

    You have the right to lodge a complaint with the ICO, the UK supervisory authority for data protection. We'd appreciate the chance to address concerns first, so please contact us in the first instance.

    Privacy isn't a checkbox. It's the contract.

    We hold ourselves to the same standards our regulated enterprise customers hold us to, because without trust in how we handle data, none of the rest of the platform matters.

    Cloudax Ltd is registered in England & Wales, Company No. 14717183.

    Last updated: 22nd April 2026

    Exercise a right or ask a question.

    For any data-protection matter (access, correction, erasure, withdrawal of consent, or a general question), email us. We respond within one month.

    [email protected]

    Cloudax Ltd · Registered in England & Wales, Company No. 14717183

    See how Cloudax's more human AI can transform your business

    No commitment, free consultation included

    Let's Talk
    CloudaxCyber Essentials certifiedCyber Essentials Plus certifiedISO 27001 certified

    Find us

    167-169 Great Portland St.
    London W1W 5PF

    1 Hardman Square
    Manchester M3 3EB

    +44 333 011 1190
    [email protected]

    Solutions

    • Connect
    • Inbound
    • Outbound
    • Chat

    Use cases

    • Property
    • Legal
    • Finance
    • BPOs
    • Utilities & Energy
    • Automotive
    • Travel & Hospitality
    • E-commerce & Retail

    Company

    • About Us
    • Careers
    • Case Studies
    • News
    • Press
    • Contact
    • Security
    • Brand

    Legal

    • Privacy Policy
    • Terms & Conditions
    • Cookies Policy
    • Accessibility Statement
    • Modern Slavery Statement
    • Anti-Bribery Statement
    • Code of Conduct
    • Environmental & Sustainability Policy
    © 2026 Cloudax Ltd. All rights reserved. Cloudax® is a registered trade mark.