Legal

Privacy Policy

Last updated 5 September 2026  ·  Version 1.0
AA Capital Ventures Ltd trading as FirstReach AI

This policy explains how we collect, use, share and protect personal data, and the rights you have over it. It is written to meet the requirements of the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations 2003 (PECR). Our terms of service are provided with your quote and form part of your contract with us.

The short version

  • We are a UK company. We run this website and we provide an AI receptionist service that answers phone calls and emails for businesses.
  • If you use this website or ask us for a demo, we are the "controller" of your personal data, and this policy explains what we do with it.
  • If you have phoned or emailed a business that uses FirstReach AI, that business is the controller. We handle your call or email on its behalf under a written contract. Section 10 explains exactly what happens to your data.
  • We do not sell personal data, and we do not use calls or emails to train AI models.
  • We use carefully selected providers, including Deepgram (speech recognition), Cartesia (speech synthesis), OpenAI (language models) and Twilio (telephony), under data-processing terms, and we host on Google Cloud in London.
  • You have rights over your data, including the right to see it and to have it deleted. Email team@firstreach.uk.

Who we are and how to contact us

AA Capital Ventures Ltd, trading as FirstReach AI ("FirstReach", "we", "us", "our"), is a private limited company registered in England and Wales under company number 16712258. Our registered office is 10 Belvedere Avenue, Ilford, England, IG5 0UE.

We are not required to appoint a statutory Data Protection Officer under Article 37 UK GDPR. We have instead appointed a data protection lead who is responsible for this policy and for handling requests and complaints. We review this position each year and will appoint a Data Protection Officer if our processing of health data for clinical clients reaches the scale at which Article 37 requires one. You can reach them by:

Where we process personal data on behalf of a business that uses our service, that business is the controller and we act as its processor. Section 10 explains what that means for you.

Who this policy covers

  • Website visitors: anyone who visits firstreach.uk or any page that links to this policy.
  • Prospective clients: people who request a demo, ask for a proposal or otherwise contact us about our services.
  • Client, supplier and partner contacts: the individuals we deal with at businesses we work with.
  • Callers and email correspondents: people who phone or email a business that uses FirstReach AI. Section 10 is written for you.

This policy does not cover the privacy practices of our clients, of third-party websites we link to, or of social media platforms on which we have a presence. Each of those has its own privacy notice.

The personal data we collect

3.1 Data you give us

  • Enquiry and demo requests: your name, business email address, business name, and anything else you choose to include, such as a phone number, job title or message.
  • Demo calls: if you ring our assistant so that we can demonstrate the service, the audio and a transcript of that call.
  • Client relationship data: contact details, role, correspondence, meeting notes, contract details, configuration preferences and billing information. We do not store payment card numbers. Payments are made by bank transfer. We do not take card payments, so no card processor receives your details.
  • Correspondence: emails, messages and call notes when you contact us.

3.2 Data collected automatically

When you visit the website, our hosting provider records standard server-log information: your IP address, browser type and version, device and operating system, the pages you request, the date and time, and the referring page. We use this to keep the website secure and to understand how it is used at an aggregate level. As at the date of this policy the website does not use analytics tools, advertising trackers or social media pixels. See section 5 for cookies.

3.3 Resources loaded from third parties

To display the website, your browser fetches fonts from Google Fonts (Google LLC and Google Ireland Limited) and script libraries from jsDelivr and Cloudflare's cdnjs service. When it does so, those providers receive your IP address and standard request headers so that they can deliver the file. We do not send them any other information about you, and their handling of that data is governed by their own privacy notices. We do not control it.

3.4 Data from other sources

When we prepare a demo or a proposal for a business, we may look at information that is already public, for example Companies House records, the business's own website and published price list, its social media pages and review sites, and professional networking profiles. We may also receive your details from a colleague or from someone who refers you to us.

3.5 Special category data

We do not ask website visitors or prospective clients for special category data (such as information about health, ethnic origin, religion, sexual orientation, political opinions, trade union membership, genetic or biometric data) or for criminal offence data. Please do not include this kind of information in enquiries. For information disclosed during calls or emails to our clients, see section 10.4.

How we use your data and our lawful bases

UK GDPR requires us to have a lawful basis for each purpose for which we use personal data. The table below sets out our purposes and the bases we rely on.

PurposeData usedLawful basis
Responding to enquiries, running demos and preparing proposalsEnquiry data, demo call data, public business informationTaking steps at your request before entering into a contract (Article 6(1)(b)); our legitimate interest in promoting and growing our business (Article 6(1)(f))
Providing our service to clients, including onboarding, configuration, support, account management and billingClient relationship data, correspondencePerformance of a contract (Article 6(1)(b)); legal obligation to keep accounting records (Article 6(1)(c))
Sending business contacts information about our servicesContact details, role, enquiry historyLegitimate interest in direct marketing to relevant business contacts (Article 6(1)(f)), subject to PECR, see below
Sending marketing by email where PECR requires consent, for example to sole traders and partnerships, or where you have ticked the box on our formContact detailsConsent (Article 6(1)(a)), which you can withdraw at any time
Operating, securing and improving the websiteServer-log dataLegitimate interest in keeping the website secure and available and in understanding how it is used (Article 6(1)(f))
Delivering fonts and code libraries from third-party content delivery networksIP address, request headersLegitimate interest in displaying the website quickly and reliably (Article 6(1)(f))
Complying with legal obligations, responding to lawful requests from authorities, and establishing, exercising or defending legal claimsAny of the above, as relevantLegal obligation (Article 6(1)(c)); legitimate interests (Article 6(1)(f))
Producing aggregated, anonymised statistics about demand for and use of our servicesDerived data that does not identify anyoneLegitimate interests (Article 6(1)(f)). Once data is anonymised it is no longer personal data.
Reorganising, selling or transferring all or part of our businessAny of the above, as relevantLegitimate interest in running and developing our business (Article 6(1)(f))

Legitimate interests. Where we rely on legitimate interests we have carried out a balancing test to make sure that our interests are not overridden by your rights and freedoms. You can ask us for a summary of that assessment, and you have the right to object at any time (see section 11).

Marketing. If you have enquired about our services, or your role at a business makes our services relevant to you, we may send you information about FirstReach AI by email or contact you by phone. Where PECR requires consent for electronic marketing, for example because you are a sole trader or an unincorporated partnership, we will only send it if you have consented, for example by ticking the box on our demo form. Every marketing email contains an unsubscribe link, and you can opt out at any time by emailing team@firstreach.uk. We check phone numbers against the Telephone Preference Service and the Corporate Telephone Preference Service before making unsolicited marketing calls.

Demo calls. A demo is a call you place to us: you ring our demo line and speak to the assistant yourself. We do not make automated calls out to you. The call is handled in the way described in section 10, using the same providers. You will be told at the start of the call that you are speaking with an automated assistant and that the call is recorded and transcribed. We use the recording and transcript only to run the demo, to follow up with you and to prepare any proposal you ask for.

Do you have to give us your data? You are under no statutory or contractual obligation to provide personal data to us. If you do not give us the details we ask for on the demo form or when preparing a proposal, we will not be able to respond to your enquiry or arrange a demo. Once your business is a client, we need the contact details of its nominated representatives in order to perform our contract with it.

Automated decision-making. We do not make decisions about you using solely automated means that produce legal effects or similarly significant effects on you.

Cookies and similar technologies

This section is our cookie policy for the purposes of PECR regulation 6.

As at the date of this policy, the website does not set any cookies and does not store identifiers in your browser's local storage. We do not use analytics, advertising, session-recording or social media tracking technologies. The demo form is submitted to Formspree, which processes it on its own servers; no Formspree script runs on our pages, and Formspree does not set cookies on our site. The third-party font and script services described in section 3.3 may receive your IP address, but they do not set cookies through our pages.

If we introduce cookies or similar technologies that are not strictly necessary for the website to work, we will update this section first and ask for your consent through a cookie banner before they are set. You can control cookies through your browser settings at any time; the ICO's guidance at ico.org.uk explains how.

Who we share your data with

We share personal data only where we need to, and only with organisations that are bound to protect it. We do not sell personal data or share it with third parties for their own advertising purposes.

  • Service providers who process data on our instructions (processors):
    • Website hosting and server logs: Cloudflare, Inc. (United States, with edge servers worldwide)
    • Form handling for demo requests: Formspree, Inc. (United States)
    • Email, documents and calendars: Google Workspace (Google Cloud EMEA Limited)
    • Speech recognition: Deepgram, Inc. (United States)
    • Speech synthesis: Cartesia, Inc. (United States)
    • Language model processing: OpenAI OpCo, LLC (United States), under a Data Processing Agreement signed in September 2026
    • Language model processing for AI visibility audits: Anthropic PBC (United States)
    • Telephony and messaging: Twilio Inc. (United States) and Twilio Ireland Limited
    • Team alerts, where a client chooses them: Telegram FZ-LLC (United Arab Emirates) and WhatsApp Ireland Limited (Meta)
    • Hosting of our voice and email platform: Google Cloud (Google Cloud EMEA Limited and Google LLC), London region
  • Professional advisers: our lawyers, accountants, insurers and auditors, where necessary for advice or to comply with our obligations.
  • Authorities: regulators, courts, law enforcement and other public bodies where we are required to by law, or where necessary to protect our rights or the rights of others.
  • Business transfers: a prospective buyer, investor or successor, under confidentiality obligations, in connection with a merger, acquisition, financing or sale of all or part of our business.
  • With your consent: in any other case where you have agreed.

The providers we use for the service itself are listed, with their roles and locations, in the sub-processor schedule to our data processing addendum, which we provide with your contract and keep up to date.

International transfers

Some of the providers listed above are located in the United States, and their processing of personal data involves a transfer outside the United Kingdom. We only make such transfers where one of the following applies:

  • the destination country, or the recipient organisation, is covered by UK adequacy regulations, which includes the European Economic Area and organisations in the United States that are certified under the UK Extension to the EU-US Data Privacy Framework; or
  • we have put in place the ICO's International Data Transfer Agreement, or the ICO's Addendum to the EU Standard Contractual Clauses, together with a transfer risk assessment and, where appropriate, supplementary measures such as encryption.

The font and script providers described in section 3.3 may also receive your IP address in the United States. Where a provider is outside the UK, our agreement with them relies on the UK International Data Transfer Addendum to the European Commission's Standard Contractual Clauses, or on another safeguard permitted by Article 46 UK GDPR. You can ask us which safeguard covers a particular provider, and for a copy of it, by contacting us using the details in section 1.

How long we keep your data

We keep personal data only for as long as we need it for the purposes described above, and then delete or anonymise it. Our standard retention periods are:

Type of dataHow long we keep it
Enquiries and demo requests that do not lead to a contract24 months from our last contact with you, then deleted
Demo call recordings and transcriptsKept only while we are dealing with your enquiry and any proposal you have asked for, then deleted. Sooner if you ask us to delete them
Client contracts, account records and correspondenceFor the duration of the contract and for 6 years after it ends, to deal with any questions or claims
Invoices and financial records6 years from the end of the financial year to which they relate, as required by HMRC
Marketing contact dataUntil you opt out, or 24 months after your last engagement with us. We keep a minimal suppression record so that we can honour your opt-out.
Website server logsKept for as long as our hosting provider retains them for security and diagnostics, then deleted
Records of complaints, disputes and legal claimsUntil the matter is closed and for 6 years afterwards
Data processed on behalf of our clientsAs instructed by the client; see section 10.5 for our defaults. The email service's working dashboard keeps conversation logs for 2 days and handled escalations for 30 days; platform logs are kept for 30 days without customer identifiers.

We may keep data for longer where the law requires it, or where it is needed for an ongoing legal claim, investigation or regulatory matter.

How we keep your data secure

We use appropriate technical and organisational measures to protect personal data against unauthorised access, loss, alteration and disclosure. These include encryption in transit and at rest, access controls with multi-factor authentication, the principle of least privilege, logging and monitoring, segregation of each client's data, and due diligence on every provider we use, including signed data-processing agreements. Our staff and contractors are bound by confidentiality obligations.

No system can be guaranteed to be completely secure. If we become aware of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the ICO within 72 hours as required by law and, where the risk is high, we will notify you directly. Where the breach concerns data we process for a client, we will notify that client without undue delay so that it can meet its own obligations. If you believe your data has been compromised, please contact us immediately at team@firstreach.uk.

If you have phoned or emailed a business that uses FirstReach AI

10.1 Who is responsible for your data

The business you contacted (our "client") decided to use an AI receptionist and decides how your call or email is handled and for what purposes. Under data protection law, it is the controller of your personal data. We process your data only on its behalf and on its documented instructions, as its processor, under a written contract that meets the requirements of Article 28 UK GDPR. The client's own privacy notice is the primary source of information about how it uses your data, and it should tell you that it uses an AI receptionist. We describe what we do below so that you can understand it fully.

10.2 What happens when you call

  • At the start of the call you are told that you are speaking to an automated assistant, that the call is transcribed and, where the business has enabled it, that it is recorded. You can ask to speak to a person at any time, and the assistant will transfer you to the client's nominated contact or take a message, depending on how the client has set it up.
  • Your voice is streamed in real time to our speech-recognition provider, Deepgram, which converts it to text. That text is sent to our language-model provider, OpenAI, which is used to understand what you are asking and to compose a reply. The reply is converted back to speech by our speech-synthesis provider, Cartesia, and played to you. The call itself is carried by Twilio. These providers act as our sub-processors under data-processing terms and process your data only to provide their service to us; every Deepgram request is opted out of model training and OpenAI does not train on API data. The position on training for each other provider is set out in our data processing addendum, which we provide on request.
  • To make, change or cancel an appointment, the assistant reads live availability from the client's booking or calendar system and writes the booking back to it, together with your name, contact details and the details of the appointment.
  • If the client has enabled it, your caller ID may be matched against the client's existing customer records so that you can be greeted by name and offered a convenient slot. This matching uses the client's records, and no separate profile is created by us.
  • We do not use your voice to identify you. No voiceprint or biometric profile is created.
  • Confirmation and reminder messages may be sent to you by SMS or email on the client's behalf.
  • The client receives a transcript or summary of the call so that its team knows what was discussed.

10.3 What happens when you email

Where a client uses our email service, we read incoming messages in the client's Gmail or Google Workspace mailbox with the client's authorisation, classify them, and draft and send replies from the client's address in the client's name. Bookings are written to the client's booking system, such as Phorest, and anything sensitive waits for a person at the client to approve it. The text of your email and the reply is processed by the same language-model provider described above, under the same restrictions. Bookings made by email are written to the client's calendar in the same way as bookings made by phone.

10.4 The data involved

The data we process on the client's behalf typically includes your name, phone number, email address, the content of what you say or write, and the details of any appointment. It also includes anything else you choose to tell the assistant. In some sectors that may include information about your health, for example an allergy, a patch-test result or a medical condition that is relevant to a treatment you are booking. We process such information only to the extent needed to handle your request, and only on the client's instructions. The client is responsible for ensuring that it has a lawful basis, and where relevant a condition under Article 9 UK GDPR, for processing that information.

10.5 Recording and retention

Every call is transcribed so that the assistant can understand you and so that the business can see what was discussed; the transcript and a summary are kept for the period below. The business also decides whether the audio of the call is recorded. In either case you are told at the start of the call. Businesses may record and keep records of calls for purposes such as evidencing a transaction, quality and training, and compliance. Where the Telecommunications (Lawful Business Practice) (Interception of Communications) Regulations 2000 apply, the announcement at the start of the call forms part of the reasonable efforts made to inform those who use the system.

Unless the client instructs us otherwise, our defaults are: call audio is not retained after the call unless recording is enabled; recordings, transcripts and call summaries are kept for the period agreed with that client and set out in our contract with them; and booking records live in the client's own systems under the client's retention periods. When our contract with a client ends, we return or delete the client's data in accordance with our contract.

10.6 Automated decision-making

The assistant does not make decisions about you that have legal or similarly significant effects. It offers appointment times based on the availability in the client's diary, and any booking, cancellation or other outcome can be reviewed and changed by a person at the client's business if you ask.

10.7 No AI training

We do not use the content of your calls or emails to train our own AI models, and Deepgram requests are opted out of model improvement and OpenAI does not train on API data; the position for each other provider is set out in our data processing addendum, which we provide on request.

10.8 Your rights

Because the client is the controller, requests to access, correct or delete your data, or to object to its processing, should be made to the client. We will help the client to respond. If you contact us directly, we will pass your request to the client within five business days and let you know that we have done so. To help us identify the right client, please tell us the name of the business and the phone number or email address you contacted.

10.9 Where your data goes

The transfer safeguards described in section 7 apply equally to data we process on behalf of clients.

Your rights

Under UK GDPR you have the following rights in relation to personal data of which we are the controller. Some rights apply only in certain circumstances.

  • Access: to be told whether we are processing your personal data and, if so, to receive a copy of it and certain information about how we use it.
  • Rectification: to have inaccurate data corrected and incomplete data completed.
  • Erasure: to have your data deleted in certain circumstances, for example where it is no longer needed for the purpose for which it was collected.
  • Restriction: to require us to limit how we use your data in certain circumstances, for example while a dispute about its accuracy is resolved.
  • Portability: to receive data you have provided to us in a structured, commonly used, machine-readable format, where we process it by automated means on the basis of consent or contract.
  • Objection: to object to processing based on our legitimate interests, and to object at any time to direct marketing. Where you object to direct marketing, we will stop.
  • Withdrawing consent: where we rely on consent, to withdraw it at any time. This does not affect processing carried out before you withdrew it.
  • Automated decisions: not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects, except in limited circumstances.

To exercise any of these rights, contact us using the details in section 1. We may need to verify your identity before responding. We will respond within one month, which we may extend by up to two further months where a request is complex, in which case we will tell you. We do not charge a fee unless a request is manifestly unfounded or excessive, in which case we may charge a reasonable fee or decline to act on it, and we will explain why.

Children

Our website and services are directed at businesses and are not intended for use by anyone under 18. We do not knowingly collect personal data from children through the website. Where a child calls or emails one of our clients, the data is processed on the client's instructions in the same way as any other caller's, and the client is responsible for any additional protections that apply.

Our website may contain links to other websites. We are not responsible for their content or their privacy practices, and we encourage you to read their privacy notices. Where we have a presence on social media platforms such as LinkedIn or Instagram, the platform's privacy notice applies to your use of that platform, and we may see information you share with us or post publicly there.

Changes to this policy

We review this policy regularly and will post any changes on this page with a new "last updated" date and version number. Where a change is material, we will notify our clients by email and, where appropriate, draw the change to the attention of website users. Earlier versions are available on request.

Complaints and the ICO

If you have a concern about how we handle your personal data, please contact us first using the details in section 1. We take complaints seriously and will do our best to resolve them.

You also have the right to complain to the UK supervisory authority, the Information Commissioner's Office: Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF; helpline 0303 123 1113; ico.org.uk/make-a-complaint.