Skip to main content

Privacy Policy

Last updated: 10 April 2025

1. Who we are

Luxo AI Ltd (“Luxo AI”, “we”, “our”) provides an AI-powered receptionist service for UK estate agents. Our registered address and data controller contact is: privacy@luxo.ai.

2. Data we collect

  • Account data — name, email, phone number, agency name when you sign up.
  • Call data — transcripts, recordings, and AI-generated summaries of calls handled by Ava on your behalf.
  • Lead data — information collected from callers (name, contact details, property requirements) as part of the qualification process.
  • Usage data — how you interact with the Luxo AI dashboard, pages visited, features used.
  • Payment data — processed securely via Stripe. We do not store card details.
  • Marketing enquiries — name and email if you submit a contact or demo request form.

3. How we use your data

  • To provide and operate the Luxo AI service.
  • To transcribe and summarise calls made through your Luxo AI number.
  • To qualify and score inbound property enquiries on your behalf.
  • To book viewings into your connected Google Calendar.
  • To send you service notifications, call summaries, and lead alerts.
  • To improve AI accuracy and service quality (anonymised, aggregated data only).
  • To comply with legal obligations.

4. Legal basis for processing (UK GDPR)

  • Contract — processing necessary to perform our service agreement with you.
  • Legitimate interests — service improvement, fraud prevention, security.
  • Consent — marketing communications (you may withdraw at any time).
  • Legal obligation — where required by law.

Call recording consent: Ava informs callers at the start of each call that the conversation may be recorded and summarised. This satisfies the consent requirement under UK GDPR and the Investigatory Powers Act 2016.

5. Data storage and security

All personal data is stored in UK-based data centres. Data is encrypted at rest (AES-256) and in transit (TLS 1.2+). We use Supabase (PostgreSQL) with row-level security policies. Access is restricted to authorised personnel only.

6. Data retention

  • Call transcripts and recordings: 12 months from call date, then deleted.
  • Lead and account data: retained for the duration of your subscription + 90 days after cancellation.
  • Payment records: 7 years (legal requirement).

7. Third-party processors

We use the following sub-processors:

  • Vapi — AI voice infrastructure (call handling)
  • Supabase — database and authentication
  • Stripe — payment processing
  • Google — Calendar integration (with your authorisation)
  • Vercel — web hosting
  • n8n — workflow automation

All processors are bound by Data Processing Agreements and comply with UK GDPR.

8. Your rights

Under UK GDPR you have the right to:

  • Access your personal data
  • Correct inaccurate data
  • Request deletion (“right to be forgotten”)
  • Object to processing
  • Data portability
  • Withdraw consent at any time

To exercise any right, email privacy@luxo.ai. We will respond within 30 days. You also have the right to lodge a complaint with the Information Commissioner’s Office (ICO).

9. Cookies

We use essential cookies for authentication and session management. Analytics cookies (Vercel Analytics) collect anonymised usage data with no personally identifiable information. You may disable non-essential cookies in your browser settings.

10. Changes to this policy

We may update this policy periodically. Material changes will be notified by email. Continued use of the service after changes constitutes acceptance.

11. Contact

For privacy-related queries: privacy@luxo.ai
For general enquiries: hello@luxo.ai