Privacy notice
What we collect and why.
Updated 29 July 2026
Pre-launch draft — not approved for live caller data. This notice, the installed providers and the retention settings require professional legal review before Managed Overflow is activated.
1. Who controls your information
Roltaire Ltd, registered in England and Wales under company number 17363420, is the controller for enquiries about Roltaire. Registered office: Roltaire, Town End, Gildersome, United Kingdom, LS27 7HF. Email: hello@roltaire.com.
For managed call and automation services supplied to a business client, that client normally decides why caller information is used and is the controller. Roltaire acts as its processor under the data processing schedule in our Terms. Roltaire remains a controller for its own billing, security and legal records.
2. Information and where it comes from
- From you: contact details, enquiry content, quote information, account details and messages you send.
- From a client or its call provider: the caller's phone number, business called, call status, time, service identifier and delivery status.
- From a virtual-assistant call: the phone number, approved callback details, conversation content, structured brief and outcome. Audio must be processed in real time for the assistant to respond and may be transiently converted to text by the configured provider. Recording files and retained transcript artefacts are disabled unless the caller is told at the start and the client has expressly enabled them.
- From our systems and providers: checkout and billing records, account identifiers, login events, device and request information, service usage and security logs.
Please do not send health information, payment-card details or other sensitive information by text. If a caller volunteers sensitive information, the client controller determines the lawful handling and Roltaire follows its documented instructions.
3. Purposes and lawful bases
- Enquiries and quotes: to respond and take requested steps before a contract.
- Contracts, accounts and billing: to perform the contract and meet accounting, tax and legal obligations.
- Website and service security: for our legitimate interests in preventing abuse, investigating failures and operating reliable services.
- Managed call and automation services: on the client controller's documented instructions, to conduct a disclosed virtual-assistant conversation, deliver an approved callback brief and operational alerts, prevent duplicates and provide the client with the resulting service record.
- Legal claims and compliance: to meet legal obligations and for our legitimate interests in establishing, exercising or defending legal rights.
Roltaire does not use caller or callback-brief information for its own marketing. If Roltaire introduces optional marketing, it will provide a separate choice and honour applicable consent and opt-out rules.
4. AI, recordings and automated decisions
A named assistant introduces itself naturally as the business's virtual assistant at the start. Managed Overflow gathers only the client-approved information needed for a human callback and does not quote, diagnose, take payment or make a booking. It does not make solely automated decisions that have legal or similarly significant effects on callers. A person at the business remains responsible for material decisions.
Live speech processing is necessary for the assistant to conduct the call. Stored call recordings and retained transcript artefacts are off by default. If a client enables either for a documented purpose, callers are told at the start, the client identifies a lawful basis and retention period, and the applicable caller notice is updated before use. Caller data is not used to train a general AI model unless a separate lawful arrangement and notice expressly permit it.
5. Who receives it
Information is shared only as needed with the business you called and configured providers: Vercel for hosting, Neon for database and account authentication, Vapi for voice automation, Twilio or the connected carrier for calls and messages, Upstash for short-lived deduplication where configured, and Stripe for payment and billing. Professional advisers, insurers, courts or regulators may receive information where reasonably necessary or legally required.
Stripe handles payment information under its own privacy terms. For client call services, the active providers and any recording are confirmed in the client's service configuration before activation.
6. International transfers
Some configured providers may process information outside the UK. Before a restricted transfer, the responsible controller must use applicable UK adequacy regulations, the UK International Data Transfer Agreement or Addendum, or another lawful safeguard and complete any required transfer assessment. Email hello@roltaire.com to ask about the safeguard used for Roltaire's processing or how to obtain a copy.
7. How long information is kept
- Unsuccessful sales enquiries: up to 12 months after the last meaningful contact.
- Contracts, invoices, payment records and core service records: up to six years after the contract or relevant accounting period ends, unless a dispute or law requires longer.
- Portal account and operational service data: for the service term, then deleted or returned under the contract, normally within 30 days plus the documented backup cycle.
- One-way keyed hashes used for call deduplication and safety quotas: normally 24 hours.
- Application security and failure logs: normally up to 90 days, or longer only where needed to investigate an incident or legal claim.
- Stored call recordings and retained transcript artefacts: not created by default. If enabled, the caller notice and client service configuration state the specific period.
Telephone, messaging and hosting providers may retain their own network or security records under their legal obligations and published policies. Roltaire reviews configured retention before activating a client service and does not keep identifiable information merely in case it becomes useful.
8. Your choices and rights
Depending on the processing, you may ask for access, correction, deletion, restriction or portability, and may object to processing based on legitimate interests. You have the right to object to processing based on legitimate interests. Where processing relies on consent, you may withdraw it at any time without affecting earlier lawful processing.
For information handled for a business you called, contact that business as controller; Roltaire will assist it. For Roltaire's own records, email hello@roltaire.com. We may need to verify your identity and will normally respond within one month.
You can complain to the UK Information Commissioner's Office at ico.org.uk. Please contact us first if you would like us to try to resolve the issue.
9. Whether information is required
You do not have to make an enquiry or continue a virtual-assistant call. Information marked as required during account creation or checkout is needed to provide the account, take payment or enter the contract; without it, we may be unable to provide that service.
10. Cookies, security and changes
The current Roltaire site does not set analytics or advertising cookies. Essential hosting and security systems may process request data without using marketing cookies. We will update this notice before introducing analytics or materially changing how information is used.
Roltaire uses proportionate access controls, encryption in transit, restricted service credentials, data minimisation, backups and security testing. No internet service is risk-free; please email us promptly if you believe information has been misused.