Privacy Policy
How we handle the personal data of people who call or message a number powered by team.help.
Effective date: 11 July 2026
1. Who we are
team.help is operated by Samurai Computing Ltd, a company registered in England and Wales (company number 03316294) with its registered office at 67 Hoo Road, Meppershall, Shefford, Bedfordshire, SG17 5LP, United Kingdom. Our registration with the Information Commissioner's Office is in progress; the registration number will be published here once issued.
For privacy questions or to exercise your rights, contact us at help@team.help.
When you call or message a business that uses team.help, the business is the controller of your personal data and Samurai Computing Ltd acts as the business's processor for the call. Samurai Computing Ltd is the controller for the limited purposes of operating, securing, and improving the team.help service itself.
2. The information we collect
When you call or message a number powered by team.help we collect and process:
- Your telephone number (Caller Line Identification or CLI), including where it is withheld.
- The name you give us during the call or message.
- Details you share about your enquiry, and any booking history with the business you have contacted.
- The full audio recording of the call.
- An AI-generated written transcript of what was said.
- Call and message metadata: time, duration, outcome, and which business was contacted.
Data we receive when a business connects a calendar to team.help
When the business owner connects their Google Calendar, Microsoft 365 / Exchange, Apple iCloud, or other CalDAV calendar to team.help via the Settings page, we receive:
- The OAuth refresh token (for Google and Microsoft) or the app-specific password (for iCloud and CalDAV), stored encrypted at rest.
- The email address of the connected account.
- For each event in the forward sync window: event ID, start and end times, summary (title), location, free/busy status, all-day flag, ETag, and the list of calendars the event belongs to.
- Attendee email addresses where present on events the business owner has access to.
We do not access any other Google or Microsoft account data. We do not access email, contacts, files, or any data outside the calendars the business owner has explicitly connected.
3. How we use it, and our legal basis
- To answer your enquiry, take your booking and answer your questions - necessary to perform our contract with you (UK GDPR Article 6(1)(b)).
- To keep records of the call for quality, dispute resolution, and fraud prevention - our legitimate interests and the business's legitimate interests in running a reliable service (Article 6(1)(f)).
- To improve the team.help service, including monitoring and tuning the underlying AI models - our legitimate interests in providing an accurate, safe, and reliable service (Article 6(1)(f)).
- To send you a booking confirmation, reminder, or callback by SMS or WhatsApp - only where you have given consent during the call, or where the soft opt-in under regulation 22(3) of the Privacy and Electronic Communications Regulations 2003 applies (existing customer relationship, similar service, easy opt-out in every message). See section 9.
- To comply with our legal obligations - for example responding to lawful requests from regulators (Article 6(1)(c)).
- To sync the business owner's calendar with the booking system - the AI receptionist must know when the business is unavailable so it does not double-book, and must create an event on the owner's calendar when a customer books an appointment. This is necessary to perform the service the business has signed up for (UK GDPR Article 6(1)(b)).
4. Speaking with an AI
Calls answered by team.help are handled by artificial intelligence, not a human receptionist. The AI identifies itself as an AI at the start of every call so you know who you are speaking to. Your speech is converted to text and processed by a Large Language Model (LLM) which generates the AI's spoken response. The audio of the call, the transcript, and any structured data extracted from the call (such as your name and enquiry details) are stored as set out in this policy.
You can ask to be transferred to a human, end the call, or use one of the alternative contact methods set out in section 12 at any time.
5. Recording and use for training
Calls are recorded and transcribed for the purposes set out in section 3. This includes using anonymised or pseudonymised excerpts to monitor the quality of the AI and to improve its accuracy. Calendar data is excluded from this - calendar events, attendees, locations, and any other data obtained from a connected Google Calendar, Microsoft 365, iCloud, or CalDAV account is never used to train, fine-tune, or otherwise develop AI or machine-learning models, and is never shared with our AI subprocessors for that purpose.
We do not use your voice to clone or synthesise speech, and we do not sell your voice or transcript to third parties.
If you do not want your call to be recorded, please end the call and use one of the alternative contact methods in section 12.
6. Who we share information with
We share the personal data described in section 2 with:
- The business you have contacted, so it can respond to your enquiry or fulfil your booking.
- The business's own systems, where the business has integrated one with team.help (for example a booking system or helpdesk). That system processes your booking on the business's instructions.
- Our UK telephony carrier, which delivers the call.
- Our UK and EU based hosting and infrastructure providers, which run the team.help service under written agreements that meet UK GDPR Article 28.
- Our self-hosted Nango calendar-sync server, which runs on our own infrastructure alongside the rest of team.help. Nango holds the OAuth refresh tokens for the business owner's Google and Microsoft calendars and proxies the calls team.help makes to those providers. It is part of our infrastructure, not a third-party service. iCloud and CalDAV credentials do not pass through Nango - they are encrypted and stored directly in team.help's database.
- Twilio, our telephony and WhatsApp Business Solution Provider, which delivers calls and messages between you and the business.
- Our AI subprocessors, which perform the speech recognition and language understanding that let the AI receptionist hold a conversation:
- Groq, Inc. (United States) - speech-to-text for call and WhatsApp audio, and the language model that drives the assistant's replies on SMS and WhatsApp.
- ElevenLabs, Inc. (United States) - the conversational voice used on telephone calls.
We will also disclose information where we are required to do so by law, by a regulator, or to protect the rights, property, or safety of any person.
7. Where we process your data
team.help stores your personal data in the United Kingdom and the European Economic Area. Our databases, recordings, and hosting are located there, and your data is not stored outside the UK or EEA.
Two parts of the service involve a transfer to the United States. The content of a call or message is sent to our AI subprocessors in section 6 (Groq and ElevenLabs) so the assistant can understand you and reply, and the resulting text is returned to us in the UK. These are transfers for processing only - neither provider retains your data as its own, and neither uses it to train its models.
Groq retains nothing. We have enabled Zero Data Retention across our Groq organisation, so the audio and text we send for speech recognition and language understanding are not logged or stored by Groq at all. They are processed in memory to produce the response and then discarded.
Our safeguard for these transfers under Article 46 of the UK GDPR is the European Commission's Standard Contractual Clauses together with the UK Addendum (version B1.0, issued by the Information Commissioner under section 119A of the Data Protection Act 2018), incorporated into our data processing agreement with each provider. ElevenLabs is additionally certified under the EU-US Data Privacy Framework and its UK Extension. We review these safeguards periodically. You can ask us for details of the safeguards in place by emailing help@team.help.
Calendar data is excluded from this. It is processed only in the UK and EEA and is never sent to our AI subprocessors.
8. How long we keep it
- Call audio recordings: 90 days from the date of the call.
- AI transcripts and call metadata: 12 months from the date of the call.
- Booking records (your name, telephone number, and booking history): for as long as the business requires them to run its business and comply with its own legal obligations, typically 6 years.
- Records relating to a complaint, dispute, or legal claim: until the matter is resolved and any limitation period has expired.
- Calendar data: held only while the business owner's connection is active. When they disconnect a calendar from the Settings page, we delete the OAuth refresh token (or app-specific password) within 24 hours and all derived busy/free records within 30 days.
9. Marketing and reminders by SMS and WhatsApp
We will only send you a confirmation, reminder, or callback message by SMS or WhatsApp where:
- You have asked us to during the call, or
- You are an existing customer of the business and the message relates to a similar service, in line with the soft opt-in under PECR.
Every message tells you who it is from and how to opt out (typically by replying STOP). You can opt out at any time and we will stop sending messages without affecting your right to receive transactional information about an existing booking.
WhatsApp messages are sent from the business's own WhatsApp Business number, not from team.help. Business-initiated WhatsApp messages use message templates that Meta has reviewed and approved in advance.
10. WhatsApp
A business using team.help may choose to connect its own WhatsApp Business Account so that it can answer enquiries and send booking confirmations over WhatsApp. Connecting is optional and is done by the business owner, not by you.
What happens when a business connects WhatsApp
The business owner completes Meta's WhatsApp Embedded Signup from the team.help admin portal. They sign in with their own Facebook account and choose the WhatsApp Business Account and telephone number they want to use. From that process team.help receives only two identifiers - the WhatsApp Business Account ID and the telephone number ID - which we store so we can route the business's messages. team.help never receives or stores a Meta access token, and we do not read the business's Facebook profile, pages, adverts, or contacts.
How your messages are handled
If you message a business on WhatsApp, or it messages you:
- Your WhatsApp telephone number, your message content, and any media you send are processed so the AI receptionist can understand and answer you, exactly as described in sections 2 to 5 for calls.
- Messages are carried by Twilio, our WhatsApp Business Solution Provider, which delivers them between team.help and WhatsApp. Twilio acts as our processor under a written agreement.
- Messages also pass through Meta Platforms Ireland Limited, which operates WhatsApp. Meta processes them as a controller under its own WhatsApp privacy policy, which we do not control. WhatsApp messages are end-to-end encrypted in transit between devices; once a message is delivered to a business it is processed by that business and by us on its behalf.
- WhatsApp message content and metadata are kept on the same basis as AI transcripts and call metadata in section 8 - 12 months from the date of the message.
- We do not use your WhatsApp messages for advertising, we do not sell them, and we do not use them to train generalised AI models.
The business's data
We use the WhatsApp Business Account identifiers described above only to operate the messaging features the business owner has enabled - routing messages, and creating and managing the message templates that business sends. We do not transfer them to anyone other than Twilio for that purpose, or as required by law. If the business owner disconnects WhatsApp, we stop sending and delete the stored identifiers within 30 days.
11. Your rights
Under UK GDPR you have the right to:
- Be told what personal data we hold about you and ask for a copy (right of access).
- Have inaccurate data corrected (rectification).
- Ask us to delete your personal data, including the audio recording of a specific call (erasure).
- Restrict or object to our processing.
- Receive your data in a portable format.
- Withdraw consent at any time, where we are relying on consent.
To exercise any of these rights, email help@team.help. We will respond within one month.
If you are unhappy with how we have handled your data you can complain to the Information Commissioner's Office at ico.org.uk or on 0303 123 1113. We would appreciate the chance to put things right first.
Business owners can disconnect a connected calendar at any time from their Settings page in the team.help admin portal. Disconnecting revokes our access to the calendar, deletes the stored credential, and removes all derived data within the period set out in section 8.
12. Accessibility and alternative contact methods
In line with our obligations under the Equality Act 2010, the business you are contacting provides alternative ways to get in touch if you cannot or do not wish to use the AI receptionist:
- Email the business directly, or email us at help@team.help.
- Ask the AI to transfer you to a human, or call back during the business's staffed hours.
- Contact the business through its other published channels.
13. Security
We use appropriate technical and organisational measures to protect personal data, including encryption in transit and at rest, access controls, audit logging, and regular review of our subprocessors. No system is perfectly secure; if we suffer a personal data breach that is likely to result in a risk to your rights and freedoms we will notify the ICO within 72 hours and, where required, notify you directly.
14. Cookies
The team.help website uses only strictly necessary cookies and equivalent local storage to remember your theme and colour preferences and to keep you signed in to the business admin area. We do not use advertising or analytics cookies that require your consent.
15. Changes to this policy
We may update this policy from time to time. The "Effective date" at the top tells you when it last changed. If we make a material change we will give you reasonable notice before it takes effect.
16. Google API Services compliance
team.help's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- We use Google user data (calendar events) only to provide the calendar-sync features the business owner has explicitly enabled.
- We do not transfer Google user data to others except as necessary to provide or improve those user-facing features, or as required by law.
- We do not use Google user data for serving advertisements.
- We do not allow humans to read Google user data, except with the user's affirmative agreement for specific support cases, to comply with applicable law, or where the data has been aggregated and anonymised.
- We do not use Google user data to train, fine-tune, or otherwise develop generalised AI or machine-learning models.
17. Contact
Samurai Computing Ltd
67 Hoo Road, Meppershall, Shefford, Bedfordshire, SG17 5LP, United Kingdom
Email: help@team.help