Privacy Policy
Last Updated: 25 June 2026
Effective from: 25 June 2026
This Privacy Policy explains how Max Smart Digital Ltd collects, uses, stores, protects and shares personal data when you use OttBot at www.maxsmartdigital.com and the connected OttBot products (Connect, Build, Vision, Data, and any product marked “Soon” once available). Your use of the Platform is also subject to our Product Terms.
Summary
- Who operates OttBot: Max Smart Digital Ltd, a company registered in England and Wales.
- What OttBot does: OttBot is a connected AI ecosystem for marketing and customer communication. Businesses use it to capture leads, hold customer conversations across channels, automate workflows, analyse media, and keep contact records in one place.
- What data we collect: Account and contact details, lead and enquiry details, payment references, content and media you upload to our products, conversation and message data, AI analysis outputs, device and usage data, marketing preferences and support messages.
- Controller vs processor: We are the controller for our own website visitors, leads, account holders and marketing. When you use OttBot to handle your own customers’ data, we act as your processor under your instructions.
- Where your data lives: Our CRM and contact records are held in OttBot Data, Max Smart Digital’s own platform. Hosting is on Microsoft Azure (UK) and card payments are processed by Stripe.
- AI: Our products use AI to generate replies, summaries, scores, recommendations and workflow actions. AI output can be wrong and should be reviewed by a human before you rely on it.
- Children: The Platform is for users aged 18 and over.
- Your rights: You can ask us to access, correct, delete, restrict, object to or port your personal data, or withdraw consent where consent applies.
1. Who We Are
OttBot is operated by Max Smart Digital Ltd. For UK data protection law, Max Smart Digital Ltd is the data controller for the personal data described in this Privacy Policy (except where we act as a processor for our business customers — see Section 7).
This Privacy Policy has been prepared in line with applicable UK data protection and privacy laws, including the UK GDPR, the Data Protection Act 2018, the Privacy and Electronic Communications Regulations 2003 (PECR), and the Data (Use and Access) Act 2025.
| Data controller | Max Smart Digital Ltd |
|---|---|
| Company number | 13244342 |
| Registered office | Brewhouse, Pilgrims Way, Boughton Aluph, Kent, TN25 4EX, United Kingdom |
| Website | www.maxsmartdigital.com |
| Privacy contact | contactus@maxsmartdigital.com · or use our contact form |
Data Protection Contact. We are not currently required to appoint a formal Data Protection Officer under the UK GDPR. For privacy questions, data protection rights requests or complaints, please contact our Data Protection Contact using the email above or the contact form.
2. When This Privacy Policy Applies
This Privacy Policy applies when you:
- visit www.maxsmartdigital.com or any OttBot product page;
- request a demo, submit an enquiry or sign up to our newsletter;
- create or manage an OttBot account;
- subscribe to or pay for an OttBot product;
- use OttBot Connect, Build, Vision or Data (or a product marked “Soon” once available);
- upload content or media to a product, or interact with an AI feature;
- are an end customer who messages a business that uses OttBot; or
- contact us for support, or otherwise interact with the Platform.
This Privacy Policy does not replace the Product Terms, which explain the rules for using the Platform, subscriptions, acceptable use and content.
3. Personal Data We Collect
3.1 Account and registration data
- first name and surname;
- business email address;
- company name and role;
- account creation date, login history and account activity;
- password, stored in encrypted or hashed form.
3.2 Lead, enquiry and newsletter data
- your name, work email and company;
- the product or problem you tell us you’re interested in;
- the message you send through our demo or contact form;
- newsletter sign-up details and your marketing consent (including the source and date of consent).
3.3 Payment and transaction data
- payment status and payment reference;
- transaction ID, amount and currency;
- transaction date and time;
- billing country or region where needed for pricing, tax, fraud prevention or compliance.
Important: Card payments are processed by Stripe. We do not store your full card number, CVV or full payment card details.
3.4 Content and media you upload
- files, video, images, documents and other media you upload to a product (for example to OttBot Vision);
- metadata such as file size, format, duration and upload time;
- thumbnails, still frames, transcripts, summaries or other outputs generated from your content;
- workflow configurations you build in OttBot Build.
3.5 Conversation and message data
When OttBot Connect powers a conversation, we process the messages exchanged across channels (such as your website chat, WhatsApp, Instagram, Messenger, SMS and email), together with timestamps, channel identifiers and routing information needed to deliver and continue the conversation.
3.6 People featured in uploaded content
Content you upload may contain personal data about you or other people, including faces, voices, names and other identifying information. If you upload content featuring another person, you are responsible for having a lawful basis (such as their consent) to upload it and have it processed by our AI systems. Please do not upload content containing special category information (see Section 5.2) unless you have the necessary permission and the upload complies with our Product Terms.
3.7 Technical, device and usage data
- device type, operating system and browser information;
- pages visited and features used;
- session duration and interaction patterns;
- referral source, such as the website or campaign that led you to OttBot;
- security logs, error logs and fraud-prevention signals.
3.8 Communications and support data
- messages, support tickets and correspondence;
- complaints, reports, feedback and enquiries;
- marketing preferences and opt-out records.
3.9 Safety and enforcement data
- content reports and moderation flags;
- account restrictions, suspensions or termination records;
- evidence preserved for legal, regulatory, safety or law-enforcement purposes.
4. How We Collect Personal Data
- Directly from you: when you request a demo, register, subscribe, make a payment, upload content, hold a conversation, contact us or change settings.
- Automatically: through cookies, analytics tools, server logs, security tools and device information (see Section 9).
- Through AI processing: when your content, conversations or data are processed to generate replies, summaries, scores, recommendations or workflow actions.
- From service providers: for example payment status from Stripe, hosting and security logs, and analytics reports.
- From our business customers: where a business that uses OttBot provides us with contact data about its own customers (here we act as a processor — see Section 7).
5. How and Why We Use Personal Data
We use personal data only where we have a lawful basis under UK (and, where it applies, EU) data protection law. The main lawful bases we rely on are set out below.
| Processing activity | Purpose | Lawful basis |
|---|---|---|
| Account creation & management | To create, maintain and secure your account. | Contract: Art. 6(1)(b). Legitimate interests for security: Art. 6(1)(f). |
| Demo requests, enquiries & sales | To respond to your enquiry, arrange a demo and follow up. | Legitimate interests: Art. 6(1)(f). Consent for newsletter sign-up: Art. 6(1)(a). |
| Service delivery (running OttBot products) | To provide the subscribed products, process your content and run the AI features you ask for. | Contract: Art. 6(1)(b). Legitimate interests for system operation and safety: Art. 6(1)(f). |
| Payment processing | To take payment, confirm transactions, prevent fraud and keep tax/accounting records. | Contract: Art. 6(1)(b). Legal obligation: Art. 6(1)(c). Legitimate interests: Art. 6(1)(f). |
| Processing Customer Data on your behalf | To store and process your contacts and conversations in OttBot Data and across the products you use. | Processor acting on the customer’s instructions; the customer is the controller (see Section 7). |
| AI features & automated analysis | To generate replies, summaries, scores, recommendations and workflow actions. | Contract: Art. 6(1)(b). Legitimate interests: Art. 6(1)(f). Consent where required. |
| Security, fraud & abuse prevention | To keep the Platform secure, detect abuse and protect accounts. | Legitimate interests: Art. 6(1)(f). Legal obligation where applicable: Art. 6(1)(c). |
| Product improvement & troubleshooting | To fix bugs, improve reliability, develop features and understand usage. | Legitimate interests: Art. 6(1)(f). |
| Analytics & performance measurement | To understand how the Platform is used and improve the experience. | Consent where required for cookies; legitimate interests for strictly necessary server-side analytics. |
| Marketing communications | To send updates or promotional messages where permitted. | Consent: Art. 6(1)(a), or the PECR soft opt-in where lawful. You can opt out at any time. |
| Legal claims & compliance | To comply with law, respond to regulators, enforce our terms and protect legal rights. | Legal obligation: Art. 6(1)(c). Legitimate interests: Art. 6(1)(f). |
5.1 Legitimate interests
Where we rely on legitimate interests, we balance our interests against your rights and freedoms. Our legitimate interests include operating and improving a connected AI ecosystem; keeping the Platform secure and reliable; preventing fraud and misuse; responding to enquiries and growing the business; and maintaining business, safety and legal records. The Data (Use and Access) Act 2025 recognises certain activities (such as direct marketing, network and information security, and intra-group transfers) as legitimate interests; where we rely on these, we still apply appropriate safeguards.
5.2 Special category data
We do not ask you to provide special category data (such as data revealing health, racial or ethnic origin, religious beliefs, political opinions or sexual orientation). However, content or conversations you upload may incidentally include or reveal it. Please do not upload this type of information unless you have the necessary permission and it complies with our Product Terms. Where special category data is processed, the relevant Article 9 condition may include explicit consent, data manifestly made public by the person, legal claims, substantial public interest, or another condition permitted by law. We may remove content where we believe continued processing is not appropriate or lawful.
6. AI Processing and Automated Analysis
6.1 What happens when AI processes your data
- we store your content and conversation data securely in cloud storage on Microsoft Azure;
- we may extract text, transcripts, frames, summaries or metadata;
- we submit relevant content, message, transcript, metadata or prompt information to our AI systems or AI service providers for processing;
- the AI generates outputs such as replies, summaries, scores, classifications, recommendations or workflow actions;
- we return the result to you, or act on it within a workflow you have configured.
6.2 AI training and model improvement
We do not use Customer Data to train our own or third-party general-purpose AI models unless we have a lawful basis and, where required, customer permission. Where our AI service providers offer settings to prevent prompts, content and uploaded data from being used to train their foundation models, we enable those settings. We may use anonymised or aggregated data to monitor performance, improve reliability, test features, debug issues and evaluate safety. If this ever changes in a way that materially affects how personal data is used, we will update this Privacy Policy and notify customers where required.
6.3 Human review
AI output is generated automatically by default. We may manually review content, account activity or AI outputs where content has been reported, automated systems flag a possible problem, we receive a legal or regulatory request, you contact us for support, or we investigate suspected fraud, abuse or a security issue. Human reviewers are subject to confidentiality obligations and access controls.
6.4 Automated decision-making
Our AI outputs are tools to assist you, not final decisions about you, and are intended to be reviewed by a human before you rely on them. We do not carry out solely automated decision-making that produces legal or similarly significant effects on individuals without an appropriate safeguard. Where the UK GDPR (as amended by the Data (Use and Access) Act 2025) or the EU GDPR gives you rights in relation to automated decisions, you can contact us to request human involvement, express your point of view or contest a decision. Where the EU AI Act applies to an AI feature, we provide the transparency information it requires (for example, letting people know when they are interacting with an AI system).
7. Controller and Processor Roles
7.1 When we are the controller
We are the controller for personal data about our website visitors, leads, prospects, account holders and the people we market to, for example the data you submit through our demo and newsletter forms, your account details and your billing records.
7.2 When we are a processor
When you use OttBot to communicate with, or hold records about, your own customers, contacts and end users, you are the controller of that personal data and we are your processor. We process it on your documented instructions to provide the service, and we make a Data Processing Agreement (DPA) available on request. As a processor we:
- only process Customer Data to provide and support the products you use;
- store it in OttBot Data and the connected products, hosted on Microsoft Azure;
- help you respond to data-subject requests and to security incidents;
- require our own sub-processors to meet equivalent data-protection obligations (see Section 11).
If you are an end customer of a business that uses OttBot and you want to exercise your rights over your data, please contact that business (the controller) in the first instance; we will support them in responding.
8. Children and Age Restrictions
The Platform is intended for business use and is restricted to users aged 18 and over. We do not knowingly collect personal data from anyone under 18. If you are under 18, you must not create an account, subscribe or otherwise use the Platform. If we discover that an account holder is under 18, we may suspend or terminate the account and delete associated data, while preserving information where required for legal or safety reasons.
9. Cookies and Similar Technologies
We use cookies and similar technologies (including tags, pixels, local storage and scripts) to operate and improve the Platform, as governed by PECR and UK data protection law.
| Type | Purpose | Control |
|---|---|---|
| Essential | Login, security, payment flow, fraud prevention and basic functionality. | Necessary — cannot usually be switched off. |
| Functional | Remember preferences (such as Flex Mode) and improve the experience. | Used where permitted and, where required, with consent. |
| Analytics / performance | Understand usage, performance, errors and conversion journeys. | Used only with consent where PECR requires it. |
| Marketing / tracking | Only used if we introduce advertising, retargeting or similar measurement. | Only with consent. Not required for the core Platform today. |
Where legally required, we will not set non-essential cookies or similar technologies unless you have given consent, and we treat a recognised opt-out preference signal (such as Global Privacy Control) as a valid choice where the law requires. You can manage cookies through our cookie banner or settings tool, where available, and your browser settings. Disabling essential cookies may prevent parts of the Platform from working.
10. Marketing Communications
We may send you service messages about your account, subscription, payment or changes to our terms. These are not marketing messages and may be necessary to provide the Platform.
We will send promotional emails only where we have your consent, or where PECR permits us to use the soft opt-in for similar products or services to existing customers. You can opt out of marketing at any time using the unsubscribe link in any marketing email, by updating your preferences, or by contacting us at contactus@maxsmartdigital.com or through our contact form.
11. How We Share Personal Data
We do not sell your personal data. We may share it with the following categories of recipients where necessary.
| Recipient / category | Reason for sharing |
|---|---|
| Cloud hosting & storage providers, including Microsoft Azure | Hosting, secure storage, backups, processing infrastructure and security. |
| OttBot Data (Max Smart Digital’s own CRM / contact-data platform) | The CRM and transactional record for the ecosystem — contacts, leads, deals and conversation records. |
| Payment providers, including Stripe | Payment processing, fraud prevention, receipts, disputes and tax/accounting records. |
| AI model, infrastructure or analysis providers, where used | Content, message, transcript, prompt or metadata processing needed to generate AI outputs. |
| Analytics & performance providers | Usage measurement, error reporting, performance monitoring and product improvement. |
| Security & fraud-prevention providers | Abuse prevention, account security and fraud detection. |
| Professional advisers | Legal, accounting, audit, tax, insurance and business advice. |
| Regulators, courts and law enforcement | Legal compliance, investigations, regulatory enquiries and legal claims. |
| Business buyers or successor organisations | Where we sell, merge, transfer or restructure all or part of our business, subject to appropriate safeguards. |
We require our sub-processors to meet appropriate data-protection and security standards and to act only on our (or our customers’) instructions. We may disclose personal data to authorities where required by law or where we reasonably believe disclosure is necessary to prevent serious harm, protect public safety, investigate crime, enforce our Product Terms or report suspected illegal content.
12. International Data Transfers
We are based in the UK. Some of our service providers may process personal data in the United States, the European Economic Area or other countries, which means your personal data may be transferred outside the UK. Where we transfer personal data internationally, we use appropriate safeguards where required, such as UK adequacy regulations, the UK International Data Transfer Agreement (IDTA), the UK Addendum to the EU Standard Contractual Clauses, EU Standard Contractual Clauses, or another transfer mechanism permitted by law. You can contact us for more information about the safeguards used.
13. How Long We Keep Personal Data
We keep personal data only for as long as reasonably necessary for the purposes in this Policy, including legal, accounting, safety, fraud-prevention and regulatory requirements.
| Data type | Retention period or criteria |
|---|---|
| Account data | For the life of the account and then until you request deletion, or after 3 years of inactivity, unless we must retain limited records for legal, fraud-prevention or dispute purposes. |
| Lead, enquiry & newsletter data | Until you unsubscribe or object, and then deleted or anonymised within a reasonable period, unless retained to demonstrate compliance. |
| Customer Data (processed on your behalf) | For the term of your subscription and any agreed retention window, then deleted or returned per your instructions and the DPA. |
| Uploaded content & AI outputs | While linked to an active account or workflow, then deleted or anonymised within a reasonable period, unless retained for legal, safety or technical reasons. |
| Payment & transaction records | Usually 6 years for UK tax, accounting and legal record-keeping. |
| Support & complaint records | Usually up to 6 years from closure, unless a shorter or longer period is appropriate. |
| Security & technical logs | Usually up to 12 months, unless needed longer for security, fraud prevention, legal claims or investigations. |
| Marketing preferences & opt-out records | As long as needed to respect your preferences and demonstrate compliance. |
| Anonymised or aggregated data | May be retained indefinitely because it no longer identifies you. |
When we no longer need personal data, we delete it, anonymise it or securely archive it where appropriate.
14. Security
We use appropriate technical and organisational measures to protect personal data against unauthorised access, loss, misuse, alteration or disclosure. These may include:
- encryption of data in transit and at rest where appropriate;
- secure cloud storage and role-based access controls;
- authentication and least-privilege access restrictions;
- logging, monitoring and security reviews;
- staff confidentiality and data-protection training;
- incident-response procedures and breach notification;
- supplier due diligence and data-processing agreements;
- data protection impact assessments where legally required or appropriate.
No online service can guarantee absolute security. If you believe your account or personal data has been compromised, please contact us immediately.
15. Your Data Protection Rights
Depending on the circumstances and the lawful basis for processing, you may have the following rights under UK data protection law and, where applicable, EU data protection law.
| Right | What it means |
|---|---|
| Access | Ask for a copy of the personal data we hold about you. |
| Rectification | Ask us to correct inaccurate or incomplete personal data. |
| Erasure | Ask us to delete your personal data where the legal conditions apply. |
| Restriction | Ask us to restrict how we use your personal data in certain circumstances. |
| Portability | Ask for certain data in a structured, commonly used, machine-readable format where processing is based on consent or contract and carried out by automated means. |
| Object | Object to processing based on legitimate interests, or to direct marketing (an absolute right). |
| Withdraw consent | Withdraw consent at any time where we rely on it. Withdrawal does not affect processing carried out beforehand. |
| Automated decision review | Ask for human involvement where an automated decision has legal or similarly significant effects. |
15.1 How to exercise your rights
To exercise your rights, contact us at contactus@maxsmartdigital.com or through our contact form, with the subject “Data Protection Rights Request”. Please include your name, account email address, the right you want to exercise and enough information for us to locate your data. We may need to verify your identity. We will usually respond within one month; if your request is complex or you have made several, we may extend this by up to two further months and will tell you. Your rights are not absolute — we may refuse or limit a request where the law allows.
15.2 Deleting your account or data
You may request deletion of your account or personal data using the contact details above. When we receive a valid deletion request, we will delete or anonymise personal data within 30 days unless we have a legal basis to retain it. Where we act as your processor, we delete or return Customer Data in line with your instructions and the DPA.
16. Privacy Complaints
If you have a complaint about how we use your personal data, please contact us first so we can try to resolve it — email contactus@maxsmartdigital.com or use our contact form with the subject “Privacy Complaint”. Please explain what has happened, what data is affected and the outcome you are seeking. We will acknowledge privacy complaints within 30 days and respond without undue delay.
16.1 Complaints to the ICO
You also have the right to complain to the UK Information Commissioner’s Office (ICO):
- Website: www.ico.org.uk
- Phone: 0303 123 1113
- Address: Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
If you are in the EU/EEA, you may also have the right to complain to your local data protection authority.
17. Users Outside the UK
17.1 EU/EEA users
If you are located in the EU/EEA, the EU GDPR may apply in some circumstances. You have additional rights under EU data protection law and may contact your local data protection authority. Where an AI feature falls within the scope of the EU AI Act, we provide the transparency information it requires. Where legally required, we will take steps to comply with applicable EU representative or other cross-border requirements.
17.2 United States users
If you are located in the United States, you may have privacy rights under applicable state privacy laws, depending on your state of residence and whether we meet the relevant thresholds. Applicable laws may include:
- California: California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), and the California Privacy Protection Agency (CPPA) regulations — including the rules on automated decision-making technology (ADMT), risk assessments and cybersecurity audits;
- Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA);
- other states with comprehensive privacy laws now in force, including Texas, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota and Maryland.
Depending on your state, you may have the right to know/access, correct, delete and port your personal information; to opt out of the sale of personal information, sharing for targeted advertising, and certain profiling or automated decision-making; not to be discriminated against for exercising your rights; and to appeal a denied request.
Sale and sharing. We do not sell personal information for monetary consideration. Some state laws define “sale”, “sharing” or “targeted advertising” broadly. We honour a recognised opt-out preference signal (such as Global Privacy Control). If you wish to opt out, contact us at contactus@maxsmartdigital.com or via our contact form with the subject “Do Not Sell or Share My Personal Information”.
Sensitive personal information. We only use sensitive personal information for purposes permitted by applicable law, including providing the Platform, detecting security incidents, ensuring quality, debugging and complying with legal obligations.
How to exercise your US rights. Contact us at contactus@maxsmartdigital.com or via our contact form with the subject “US Privacy Rights Request”, including your name, state of residence, the right you wish to exercise and enough information to locate your data. We will respond within the timeframe required by your state’s law (typically 45 days, extendable by a further 45 days where permitted). You may designate an authorised agent, subject to verification, and may appeal a denied request.
17.3 Other countries
If you are located outside the UK, EU/EEA or United States, you may have rights under your local privacy laws. Contact us with any questions about how your local rights apply.
18. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our Platform, technology, suppliers, legal requirements or operational practices. Where changes are material, we will take reasonable steps to notify registered users, such as by email, in-product notice or a prominent notice on the Platform. The updated Policy will show the new effective date, and we encourage you to review it periodically.
19. Contact Details
For privacy questions, rights requests, account deletion, privacy complaints or data protection enquiries, contact:
| Company | Max Smart Digital Ltd |
|---|---|
| Registered office | Brewhouse, Pilgrims Way, Boughton Aluph, Kent, TN25 4EX, United Kingdom |
| Company number | 13244342 |
| Privacy contact | contactus@maxsmartdigital.com |
| Website | www.maxsmartdigital.com |
Manage Your Privacy Rights
To raise a data protection complaint, use the button below. For a personal data rights request, to update your marketing preferences or to manage your cookie choices, get in touch and we'll help. We handle requests in line with UK GDPR, the Data Protection Act 2018, PECR and the Data (Use and Access) Act 2025.