Last updated 12 June 2026 · Sonadesk Ltd · company no. 17275185 · registered in England & Wales
Sonadesk ("we", "us") provides an AI front-desk platform for local businesses: websites, online booking, payments, messaging and an AI receptionist. This policy explains how personal data is handled.
1. Controller — for our own customers. When a business signs up to Sonadesk, we are the data controller for their account data (name, business details, email, phone, billing information, usage records).
2. Processor — for our customers' customers. When you book, enquire, chat, call or email a business that uses Sonadesk, that business is the data controller of your information; we process it on their instructions to deliver their service (bookings, reminders, quotes, invoices, certificates and customer records). Questions or rights requests about that data should go to the business you dealt with — we help them respond.
Our AI receptionist and assistants are powered by Anthropic's Claude models and Vapi (voice). Conversation content is processed to answer, capture enquiries and produce summaries for the business you contacted. We do not sell this data or use it to build advertising profiles.
Vercel (hosting), Supabase (database & authentication), Stripe (payments), Twilio (calls & SMS), Vapi (AI voice orchestration) together with Deepgram (speech-to-text) and ElevenLabs (text-to-speech), Anthropic (AI models), Resend and Twilio SendGrid (email), Google (calendar integration, where connected). Each is bound by data-processing terms. The full, current sub-processor list is maintained in our Data Processing Agreement.
We rely on contract (providing the service), legitimate interests (security, service messages, fraud prevention) and consent where required. Marketing texts and emails sent by businesses through Sonadesk require their customers' consent under PECR; every message carries an opt-out (reply STOP / unsubscribe link) and opt-outs are enforced automatically.
Account data is kept while the account is active and for a reasonable period after closure. Records with statutory retention duties (e.g. gas safety records, electrical certificates, financial records) are retained for their legal periods even after an erasure request, with contact details removed where possible.
Under UK GDPR you may request access, correction, erasure, restriction, portability, or object to processing. Businesses can export or erase their customers' data from their dashboard; account holders can export their data from their account page. Contact hayden@sonadesk.co.uk — and you may complain to the ICO (ico.org.uk).
We use essential cookies for login and an optional consent banner controls anything beyond that. Data is encrypted in transit, access is restricted, and actions are logged. Data is processed in the UK/EEA and the US under appropriate safeguards.
Contact: Sonadesk Ltd · hayden@sonadesk.co.uk · 07862 147467