Privacy Policy
Last updated: 18 March 2026
NeverMissACall ("we", "our" or "the Company") is committed to protecting the privacy of users of our website and services. This Privacy Policy explains how we collect, use, store and protect your personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
1. Data Controller
The data controller for personal data collected through this website is NeverMissACall.
For any questions relating to data protection, please contact us at: hello@nevermissacall.pt
2. Personal Data We Collect
In connection with your use of our website and services, we may collect the following personal data:
- Name — provided via the contact form
- Email address — provided via the contact form
- Phone number — provided via the contact form (optional)
- Technical data — IP address and browser information, recorded automatically in hosting server logs
- Meeting booking data — when you book a meeting, we store your name, email and chosen time.
3. Purposes of Processing
Your personal data is processed for the following purposes:
- Responding to contact requests and providing information about our services
- Providing access to the AI receptionist (AI-powered voice assistant) live demo
- Scheduling meetings: we check availability against the founders' own Google/Microsoft calendars and you will receive a calendar invitation for the booked meeting.
- Sending marketing communications (only with your consent)
- Improving the website and user experience
- Complying with legal and regulatory obligations
4. Lawful Basis for Processing
We process your personal data on the following lawful bases under UK GDPR:
- Consent (Article 6(1)(a)) — when you submit the contact form
- Pre-contractual steps (Article 6(1)(b)) — when you request information about our services or a demonstration
- Legitimate interests (Article 6(1)(f)) — to ensure the security and proper functioning of the website
5. Data Sharing and Sub-processors
Your personal data may be shared with the following service providers (sub-processors), who act on our behalf and under our instructions:
- Supabase — database hosting and lead/account data storage (EU — Frankfurt, Germany)
- Vercel — website hosting (global edge network, primary region EU)
- Hetzner — voice-server infrastructure (EU — Germany)
- Google (Gemini API) — AI voice processing for inbound calls (EU and US regions per Google Cloud documentation; transfers covered by SCCs + UK Addendum)
- Resend — transactional email delivery (EU — Frankfurt)
- Stripe — payment processing for paid subscriptions (EU/US; UK Addendum + SCCs)
- Slack — internal operational notifications (USA), receiving first name and record identifiers (no sensitive contact data) under Standard Contractual Clauses.
We do not sell, rent or otherwise disclose your personal data to third parties for marketing purposes.
6. International Data Transfers
Personal data you provide is primarily processed within the European Union (Germany), under the EU adequacy decision recognised by the UK Adequacy Regulations 2021 — meaning UK data subjects benefit from essentially equivalent protection.
Where a sub-processor (notably Google for AI voice processing, or Stripe for payments) processes data outside the EU, transfers are covered by the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses (SCCs), as published by Stripe and Google in their respective Data Processing Agreements.
7. Voice Calls and AI Processing
Where you trial or subscribe to our AI receptionist service, inbound calls to your business line are routed via our voice infrastructure to Google's Gemini Live API for real-time speech-to-speech processing. Call audio is streamed (not stored long-term by Google) and a transcript and metadata are stored in our EU-based Supabase database for the duration of your contract.
If you are a clinic or business deploying our service to receive calls from your own patients or customers, you act as the data controller for that downstream personal data and we act as the processor. You must ensure your own privacy notice tells the caller that AI is used to handle inbound calls — UK ICO guidance requires this for automated decision-making and large-scale audio processing.
8. Retention Periods
Your personal data will be retained only for as long as necessary for the purposes for which it was collected:
- Lead data — retained for 24 months after last contact, unless a contractual relationship exists
- Browsing data — retained for 13 months
9. Your Rights
Under UK GDPR, you have the right to:
- Access — obtain confirmation of whether we are processing your data and access it
- Rectification — request correction of inaccurate or incomplete data
- Erasure— request deletion of your data ("right to be forgotten")
- Restriction — request restriction of processing in certain circumstances
- Portability — receive your data in a structured, machine-readable format
- Objection — object to processing of your data, including for direct marketing
- Withdraw consent — at any time, without affecting the lawfulness of processing carried out before withdrawal
To exercise any of these rights, please contact us at: hello@nevermissacall.pt
10. Complaints
If you believe that our processing of your personal data infringes UK GDPR, you have the right to lodge a complaint with the Information Commissioner's Office (ICO): ico.org.uk
11. Security
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, destruction or alteration, including encryption of data in transit (HTTPS) and at rest, and access controls.
12. Changes to This Policy
We reserve the right to update this Privacy Policy at any time. Any changes will be published on this page with a revised "last updated" date. We recommend checking this page periodically.