LIGHTNING
LIGHTNING BUSINESS SOLUTIONS · UNITED KINGDOM

Privacy Policy

Greyline Technologies Limited, company 16673047, trading as Lightning Business Solutions.

Privacy Policy

Privacy & Data Protection Policy

Document Reference: GTL-POL-001-v3

Effective Date: 1st January 2025

Data Controller: Greyline Technologies Limited (t/a Lightning Business Solutions)

1. Introduction and Scope

Greyline Technologies Limited, trading as Lightning Business Solutions and Imogen Grace ("the Company", "we", "us", or "our"), respects your privacy and is committed to protecting your personal data. This comprehensive privacy policy aims to give you information on how we collect and process your personal data through your use of our websites, our digital assistant products (including "Imogen Grace"), our consultancy services, and any data you may provide through this website or during the provision of our services.

This policy applies to all data subjects, including but not limited to:

  • Commercial Clients: Small to medium enterprises (SMEs) utilizing our automation services.
  • Public Sector Partners: Government bodies, local authorities, NHS trusts, and educational institutions.
  • End Users: Individuals who interact with our systems (e.g., callers engaging with our AI receptionists).
  • Visitors: Users of our website and digital platforms.

This policy adheres strictly to the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 (DPA 2018), and the Privacy and Electronic Communications Regulations (PECR).

2. Definitions & Interpretation

In this Policy, the following terms shall have the following meanings:

  • "Personal Data" means any information relating to an identified or identifiable living individual.
  • "Processing" means any operation performed on personal data, such as collection, recording, storage, adaptation, or destruction.
  • "AI System" refers to our proprietary and third-party artificial intelligence models, including Large Language Models (LLMs) and Voice Synthesis engines used in the "Imogen Grace" product.
  • "Voice Data" refers to audio recordings, transcripts, and biometric voice markers processed during telephone interactions.

3. Identity of the Data Controller

Greyline Technologies Limited is the Controller and is responsible for your personal data.

Full Legal Name: Greyline Technologies Limited
Company Number: 16673047
Registered Office: 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom
Data Protection Officer (DPO) Contact: [email protected]

4. The Data We Collect About You

We may collect, use, store, and transfer different kinds of personal data about you which we have grouped together follows:

  • Identity Data: First name, maiden name, last name, username or similar identifier, marital status, title, date of birth, and gender.
  • Contact Data: Billing address, delivery address, email address, and telephone numbers.
  • Financial Data: Bank account and payment card details (Note: We do not store full credit card numbers; these are processed via secure PCI-DSS compliant payment gateways).
  • Transaction Data: Details about payments to and from you and other details of products and services you have purchased from us.
  • Technical Data: Internet protocol (IP) address, your login data, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform, and other technology on the devices you use to access this website.
  • Profile Data: Your username and password, purchases or orders made by you, your interests, preferences, feedback, and survey responses.
  • Usage Data: Information about how you use our website, products, and services, including interaction logs with our AI agents.
  • Marketing and Communications Data: Your preferences in receiving marketing from us and our third parties and your communication preferences.

5. Voice Data & AI Processing (Imogen Grace)

A core component of our service involves the use of Artificial Intelligence to process voice interactions. This section specifically addresses data processed via the "Imogen Grace" digital assistant.

5.1. Collection of Voice Data

When an individual interacts with our telephone systems, we collect audio recordings of the conversation. This is necessary for:

  • Real-time transcription (Speech-to-Text).
  • Intent analysis (Understanding the purpose of the call).
  • Service fulfilment (Booking appointments, taking messages).
  • Quality assurance and system training.

5.2. Automated Decision Making & Profiling

Our systems use automated logic to route calls, categorize urgency, and schedule appointments. While these decisions are automated, they do not produce legal effects concerning the data subject. However, we maintain Human-in-the-Loop (HITL) oversight protocols where flagged interactions are reviewed by authorised personnel to ensure accuracy and fairness.

5.3. Transparency

We do not attempt to mislead users regarding the nature of our digital assistants. While "Imogen Grace" is designed to sound natural and conversational, it is a software product. Where required by law or ethical guidelines, we disclose the automated nature of the interaction.

6. How Your Personal Data is Collected

We use different methods to collect data from and about you including through:

  • Direct interactions: You may give us your Identity, Contact and Financial Data by filling in forms or by corresponding with us by post, phone, email or otherwise. This includes personal data you provide when you:
    • Apply for our products or services;
    • Create an account on our website;
    • Subscribe to our service or publications;
    • Request marketing to be sent to you;
    • Enter a competition, promotion or survey; or
    • Give us feedback or contact us.
  • Automated technologies or interactions: As you interact with our website, we will automatically collect Technical Data about your equipment, browsing actions and patterns. We collect this personal data by using cookies, server logs and other similar technologies.
  • Third parties or publicly available sources: We will receive personal data about you from various third parties and public sources as set out below:
    • Technical Data from analytics providers such as Google;
    • Contact, Financial and Transaction Data from providers of technical, payment and delivery services;
    • Identity and Contact Data from data brokers or aggregators;
    • Identity and Contact Data from publicly available sources such as Companies House and the Electoral Register based inside the UK.

7. Purposes & Legal Basis for Processing

We have set out below, in a table format, a description of all the ways we plan to use your personal data, and which of the legal bases we rely on to do so. We have also identified what our legitimate interests are where appropriate.

Purpose/Activity Type of Data Lawful Basis for Processing
To register you as a new customer Identity, Contact Performance of a contract with you
To process and deliver your order including: (a) Manage payments, fees and charges (b) Collect and recover money owed to us Identity, Contact, Financial, Transaction, Marketing and Communications (a) Performance of a contract with you
(b) Necessary for our legitimate interests (to recover debts due to us)
To process voice interactions via Imogen Grace (Digital Assistant) Voice Data, Identity, Usage (a) Performance of a contract (Client)
(b) Legitimate Interest (End User service delivery)
To manage our relationship with you which will include: (a) Notifying you about changes to our terms or privacy policy (b) Asking you to leave a review or take a survey Identity, Contact, Profile, Marketing and Communications (a) Performance of a contract with you
(b) Necessary to comply with a legal obligation
(c) Necessary for our legitimate interests (to keep our records updated and to study how customers use our products/services)

8. Disclosure of Data (Sub-Processors)

To provide our advanced automation services, we may share your personal data with specific third parties known as Sub-Processors. We require all third parties to respect the security of your personal data and to treat it in accordance with the law.

We use the following categories of Sub-Processors:

  • Cloud Infrastructure Providers: (e.g., Amazon Web Services, Google Cloud Platform) for secure data hosting.
  • Telephony & Voice Carriers: (e.g., Twilio, Bland.ai) for processing telephone signals and voice data.
  • AI & Machine Learning Providers: (e.g., OpenAI, ElevenLabs) for natural language processing and synthesis. Data sent to these providers is anonymised where possible and processed under strict data processing agreements.
  • Workflow Automation Tools: (e.g., n8n, Make) for routing data between your calendar, CRM, and our systems.
  • Professional Advisers: Acting as processors or joint controllers including lawyers, bankers, auditors and insurers based in the United Kingdom who provide consultancy, banking, legal, insurance and accounting services.
  • HM Revenue & Customs, Regulators and other Authorities: Acting as processors or joint controllers based in the United Kingdom who require reporting of processing activities in certain circumstances.

9. International Data Transfers

Many of our external third parties (specifically AI and Telephony providers) are based outside the United Kingdom so their processing of your personal data will involve a transfer of data outside the UK.

Whenever we transfer your personal data out of the UK, we ensure a similar degree of protection is afforded to it by ensuring at least one of the following safeguards is implemented:

  • We will only transfer your personal data to countries that have been deemed to provide an adequate level of protection for personal data by the UK Government (Adequacy Regulations).
  • Where we use certain service providers, we may use specific contracts approved for use in the UK which give personal data the same protection it has in the UK (International Data Transfer Agreement or IDTA).
  • For US-based providers, we ensure they participate in the UK-US Data Bridge (extension to the EU-US Data Privacy Framework) or rely on Standard Contractual Clauses (SCCs) with robust Transfer Impact Assessments (TIAs).

10. Data Security & Encryption

We have put in place appropriate security measures to prevent your personal data from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. In addition, we limit access to your personal data to those employees, agents, contractors and other third parties who have a business need to know. They will only process your personal data on our instructions and they are subject to a duty of confidentiality.

Our security measures include:

  • Encryption at Rest: All databases and file storage systems are encrypted using AES-256 standards.
  • Encryption in Transit: All data transmission occurs via Secure Socket Layer (SSL) / Transport Layer Security (TLS) 1.2 or higher.
  • Access Control: Multi-Factor Authentication (MFA) is enforced for all administrative access.
  • Regular Audits: We conduct vulnerability assessments on our infrastructure.

11. Data Retention Policy

We will only retain your personal data for as long as reasonably necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, regulatory, tax, accounting or reporting requirements.

  • Client Account Data: Retained for the duration of the contract plus 6 years (for tax and legal claims limitation periods).
  • Voice Recordings & Transcripts: Retained for a default period of 90 days for quality assurance and training, after which they are securely deleted or anonymised, unless a different retention period is agreed in the specific Client Service Agreement.
  • Marketing Data: Retained until you withdraw consent or for a period of 24 months of inactivity.

12. Your Legal Rights

Under certain circumstances, you have rights under data protection laws in relation to your personal data:

  • Request access to your personal data (commonly known as a "data subject access request").
  • Request correction of the personal data that we hold about you.
  • Request erasure of your personal data.
  • Object to processing of your personal data where we are relying on a legitimate interest.
  • Request restriction of processing of your personal data.
  • Request the transfer of your personal data to you or to a third party.
  • Withdraw consent at any time where we are relying on consent to process your personal data.

If you wish to exercise any of the rights set out above, please contact the Data Protection Officer at [email protected].

13. Public Sector & Government Contracts

When Greyline Technologies Limited acts as a supplier to Public Sector bodies (including Local Authorities, NHS Trusts, and Central Government departments), we operate as a Data Processor. In such instances:

  • We process data strictly in accordance with the Data Controller's (the Public Body's) written instructions.
  • We adhere to the specific security standards required by the Government Security Classifications Policy (e.g., OFFICIAL).
  • We assist the Public Body in fulfilling their obligations under the Freedom of Information Act 2000 (FOIA).
  • Specific contract clauses regarding data processing take precedence over this general policy where applicable.

© 2025 Greyline Technologies Limited. All rights reserved.
Registered in England & Wales No. 16673047.