Skip to content
Bletchley
ProductIntegrationApplications
Login
Terms of ServicePrivacy PolicyData Processing AgreementCookie Policy

BLETCHLEY

Bletchley platform

Privacy Policy

On this page

  1. 1. Who we are, and what this policy covers
  2. 2. The personal data we collect
  3. 3. Why we use personal data
  4. 4. Our commitments when we handle data for a customer
  5. 5. Who we disclose personal data to
  6. 6. Transfers between countries
  7. 7. How long we keep personal data
  8. 8. Cookies and similar technologies
  9. 9. Marketing
  10. 10. Your rights
  11. 11. Automated decisions
  12. 12. Security
  13. 13. Changes to this policy
  14. 14. Contact
On this page+
  1. 1. Who we are, and what this policy covers
  2. 2. The personal data we collect
  3. 3. Why we use personal data
  4. 4. Our commitments when we handle data for a customer
  5. 5. Who we disclose personal data to
  6. 6. Transfers between countries
  7. 7. How long we keep personal data
  8. 8. Cookies and similar technologies
  9. 9. Marketing
  10. 10. Your rights
  11. 11. Automated decisions
  12. 12. Security
  13. 13. Changes to this policy
  14. 14. Contact

1. Who we are, and what this policy covers

Bletchley Consulting Services Limited, a company incorporated in Hong Kong SAR, operates the Bletchley platform. The platform lets a business run a data-backed conversational service for its own customers, across messaging, voice and its own website. We operate internationally, and this policy applies wherever we make the platform available.

This policy explains what we do with personal data that we handle in our own right. It does not explain what our business customers do with personal data on their own account. Which of those you are asking about determines who you should approach.

We handle personal data in our own right, as a controller or data user, when you visit our websites, correspond with us, open or administer an account, attend an event we host, interact with a demonstration or recruitment assistant that we operate ourselves, or apply to work with us. Everything in this policy applies to that data.

We handle personal data on behalf of our customers, as a processor acting only on their instructions, when a business runs its own conversational service on the Bletchley platform and the people it serves interact with that service. The business decides what data is collected, what the service is for and how long the data is kept. Our obligations are fixed by our contract with that business, including our data processing agreement, and not by this policy. If you interacted with a conversational service on a company's website or messaging channel and you want to see, correct or delete your data, please contact that company. We assist our customers in responding to such requests, as our contract with them requires.

Section 4 sets out the commitments we make when we handle data on our customers' behalf. It describes what we do and do not do with that data. It does not describe how the platform is built.

2. The personal data we collect

2.1 Data you give us

When you register or administer an account, we collect your name, work email address, telephone number, job title, employer, login credentials and the workspace membership and access details associated with you. Where you purchase Credits or services under an order form, we also collect billing contact details, Credit purchases and usage recorded on the account, order-form and invoice details, payment and refund records, and tax identifiers where these are required.

To activate a Free Trial, you must provide and verify an email address and a mobile number. We collect those details and the associated verification and trial-eligibility records to verify your contact details, prevent duplicate Free Trials and prevent abuse. Providing and verifying both details is mandatory for the Free Trial; if you do not do so, we cannot activate it. The retention rules for these records are set out in section 7, recipients in section 5 and your access and correction rights in section 10.

When you contact us, we collect the content of your enquiry or support request, our correspondence with you, notes of meetings and demonstrations and, where you have agreed to it, a recording or transcript of a call.

When you interact with a demonstration or recruitment assistant that we operate, we collect what you type or say to it, together with any contact details you choose to provide.

When you take part in our referral programme, we record that you made a referral and, where you lawfully provide them, the business contact details of the person you referred. We tell that person who referred them.

When you apply for a role with us, we collect your application, curriculum vitae, work history, information about your right to work, and our interview notes.

When you register for an event, we collect your registration details and any dietary or access requirements you volunteer.

2.2 Data we collect automatically

When you use the platform we collect your internet protocol address and the approximate location derived from it, device and browser characteristics, operating system, referring and exit pages, the pages you view and links you select, session duration, cookie and similar identifiers, and in-product events. For signed-in users we also keep an audit log of administrative actions taken in the console, which is how an account holder can see who changed what. Our marketing website’s use of cookies and browser storage is described in the Cookie Policy.

2.3 Data from other sources

We obtain business contact and company information from public sources, from business data providers, from partners and resellers who refer prospects to us, and from the partner directories in which we are listed. We may also receive information from analytics and advertising platforms about how people found us.

2.4 Data we ask you not to send us

Please do not send us government identity numbers, payment card numbers, health information or other sensitive personal data through our website forms, our support channels or an assistant we operate. We do not need it. If you send it anyway we will delete it once we have dealt with your request. Different and stricter rules apply to data our customers load into the platform, and those are in section 4.

3. Why we use personal data

We use personal data to provide, administer and secure the platform and your account; to bill you, account for usage, collect what is owed and keep the statutory financial records we are required to keep; to provide support, investigate faults and respond to incidents; to protect the platform and our customers against fraud, abuse and security threats, and to enforce our terms; to measure reliability and improve the platform; to market our products to businesses and business contacts; to run events, surveys and research; to recruit; and to deal with legal claims, regulatory enquiries, corporate transactions and our own legal obligations.

We use the email address and mobile number provided for the Free Trial, and associated verification records, to verify control of those contact details, check whether a Free Trial has already been claimed, and detect and prevent duplicate trials and abuse.

Where the European or United Kingdom General Data Protection Regulation applies to our processing, we rely on the following legal bases. We rely on the performance of our contract with you to provide the platform, administer your account and take payment. We rely on our legitimate interests to secure the platform, prevent abuse, measure and improve the service, market to business contacts, and pursue or defend claims; where we rely on legitimate interests we have considered whether those interests are overridden by your rights, and you may object at any time. We rely on your consent for non-essential cookies, for certain marketing and for recording where consent is required, and you may withdraw that consent at any time without affecting processing already carried out. We rely on compliance with a legal obligation for tax, accounting and regulatory record-keeping and for responding to lawful requests.

Where other privacy laws apply, we use personal data only for the purposes for which it was collected or a directly related purpose, and we obtain consent where that law requires it.

We also produce aggregated statistics about how the platform is used, such as volumes of activity, response times and the rate at which questions are answered or passed to a person. Once aggregated and de-identified this information is no longer personal data, and we use and retain it for research, benchmarking and product development. It is never published in a form that identifies a customer or an individual.

4. Our commitments when we handle data for a customer

The commitments below are contractual. They sit in our data processing agreement with each customer and we publish them here because they are what people most often ask about.

4.1 We act only on instructions

We process a customer's data only to operate and support the service that customer runs, on that customer's instructions, and as required by law. We do not use it for our own purposes. We do not vet, screen or monitor what a customer supplies or how it uses the service, beyond what is necessary to operate, support and secure the platform and to act on a report of misuse. Each customer is responsible for the lawfulness of the data it supplies and of the service it runs.

4.2 Answers come from the customer's own data

A service answers from the data the customer supplies or connects, and is designed to say that information is unavailable, or to pass the person to a human being, rather than to supply an answer it has no data for. We do not warrant that any answer is correct; the accuracy of an answer depends on the accuracy of the customer's own data.

4.3 Data is never used to train models

A customer's data, and the answers generated from it, are never used to train, fine-tune or otherwise improve any general-purpose or foundation model, in any form. We contractually prohibit every provider of model inference we engage from doing so, and where such a provider offers processing without retention of the data submitted to it, we use that option.

4.4 Data we do not accept

Customers must not supply government identity numbers, passport numbers, full payment card numbers, bank account credentials, biometric templates or free-text clinical remarks. Automated checks cover full payment card numbers and government identity numbers. Where those numbers are detected in an uploaded file or data source, the upload or ingestion is rejected. Where detected in a message to a service, the numbers are masked before the message is stored or sent to a model provider. These checks do not provide automatic detection or masking of every prohibited category. Our terms require customers not to supply prohibited data and require a separate written agreement before sensitive, special category, health or cardholder data is processed at all.

4.5 Personal records are answered only to the person they concern

General business information, such as prices, opening hours, availability and policies, is answered to anyone who asks. Information about an individual, such as that person's own booking, balance or history, is answered only where the platform has verified that it is dealing with that person, either because the channel itself proves control of a telephone number or account the business already holds, or because a one-time code has been confirmed. We do not identify people by inference or on a balance of probabilities. Where identity cannot be verified, the information is withheld.

4.6 Personal records are not routed through consumer assistants

A customer may administer its service through a general-purpose assistant provided by a third party. Where it does, that assistant receives configuration and summary information only. It does not receive the underlying records about individuals. Those records reach the platform only by authenticated upload or an authenticated connection.

4.7 An objection is recorded against the person, not the channel

If someone asks a service to stop contacting them, that objection is recorded against the person rather than the channel it arrived on, and is honoured across that business customer's workspace. Where the same person uses another channel, the objection follows them wherever the platform can match them by telephone number or email address. The record is kept for as long as necessary to honour it, and is not erased or overridden when records are later merged or re-imported.

4.8 Customers are kept separate

Each customer's data is held separately from every other customer's. No customer's data is used to answer another customer's enquiries, and nothing learned while operating one customer's service is applied to another's.

4.9 Records of conversations

We keep a record of what a service was asked, what it answered and which of the customer's data sources the answer drew on, so that the customer can review and improve its own service and can show what an answer was based on. Retention is set out in section 7, and a customer may configure a shorter period.

5. Who we disclose personal data to

We disclose personal data to the following categories of recipient: providers of infrastructure, hosting, database and backup services; providers of machine learning and language model inference; the operators of the messaging, voice and application surfaces on which our customers run their services; providers of payment, invoicing and tax services; providers of the business tools we operate on, including customer relationship management, support, email delivery, analytics and error monitoring; our professional advisers, including legal, accounting, audit and insurance; a buyer, investor or successor in connection with a merger, financing, reorganisation, insolvency or sale of assets; public authorities, courts and regulators where we are required to disclose, or where disclosure is necessary to establish or defend legal claims or to protect the rights, safety or property of any person; and any third party you or our customer directs us to share with.

For Free Trial verification and eligibility, we disclose the information needed for those purposes only to email delivery providers; SMS or WhatsApp message delivery and verification providers; and cloud hosting and database providers.

We do not sell personal data, and we do not disclose personal data to third parties for their own marketing purposes.

The identity of the subprocessors we engage to deliver the platform, what each of them processes and where, is disclosed to our customers under our data processing agreement, which also provides for notice before a new subprocessor is engaged. We treat our supply chain as confidential and do not publish it. No customer is asked to accept a subprocessor it has not been told about.

6. Transfers between countries

We are established in Hong Kong and operate internationally. Personal data may be transferred to, processed in and stored in countries other than the one in which it was collected, including countries whose data protection laws differ from those of your own. Where a customer's agreement provides for processing in a specified region, we process that customer's data accordingly.

Where we transfer personal data from the European Economic Area, the United Kingdom or Switzerland to a country that has not been found to provide an adequate level of protection, we rely on the European Commission's standard contractual clauses, or the United Kingdom's international data transfer addendum, together with an assessment of the risks of the transfer and additional measures where those are required.

Where we transfer personal data out of Hong Kong, we apply contractual protections modelled on the model contractual clauses recommended by the Privacy Commissioner for Personal Data, and we tell each customer which categories of recipient are involved so that it can meet its own obligations as a data user.

Where we transfer personal data out of Singapore or another market whose law imposes a comparable standard, we take steps to ensure that the data continues to receive protection at least comparable to that required by that law.

Where the law of a market requires us to appoint a local representative for data protection purposes, we do so. Requests may be sent to info@bletchley.cc and will be directed to that representative where one is appointed.

7. How long we keep personal data

Account and workspace records are kept for the life of the account and for 12 months after it is closed, then deleted.

The following specific periods apply to Free Trial verification and eligibility records instead of the general account-record period above. Records needed only to complete or troubleshoot contact verification, including codes, attempts and delivery status, are retained for 90 days from the verification attempt, then deleted.

The minimum record needed to prevent duplicate Free Trials consists of a non-reversible keyed hash of the verified email address and mobile number, plus trial-claimed status and date. It is retained for 3 years from the date the Free Trial was granted, including after account closure, then deleted. This record is used only to check trial eligibility and prevent abuse, not for marketing or profiling.

Data supplied or connected by a customer, and anything we derive from it in order to operate that customer's service, is kept while that customer's account remains open, subject to the shorter retention periods described in this policy or configured by the customer. On termination it is available for export for 30 days and is then deleted or returned within a further 30 days, other than copies held in backups that expire on their ordinary cycle and data we are required by law to retain.

Records of conversations are kept for a rolling 24 months, or for the shorter period a customer configures, and are deleted on termination in accordance with the paragraph above.

The automated rejection and masking of detected full payment card numbers and government identity numbers is described in section 4.4.

Security and audit logs are kept for 12 months.

Billing, tax and statutory financial records are kept for seven years.

Marketing contact data is kept until you opt out, or after 24 months without engagement. Where you opt out we keep a suppression record indefinitely, because keeping it is how we avoid contacting you again.

Records of an objection to contact are kept indefinitely, for the same reason.

Recruitment data is kept for six months after a decision, or for 12 months where you consent to us keeping it for future roles.

Our marketing website does not currently use analytics trackers. Its use of cookies and browser storage is set out in the Cookie Policy.

We may keep personal data for longer where we are required to do so by law, or where it is necessary to establish, exercise or defend a legal claim.

8. Cookies and similar technologies

Our marketing website no longer saves pricing selections. It does not currently set cookies or use analytics, advertising or cross-site tracking technologies. A browser used with the former pricing-selection feature may still contain an old session-storage item; the website no longer reads or updates it. The Cookie Policy explains that historical item and how to remove it. That policy covers the marketing website, not the signed-in Bletchley platform or websites operated by our customers.

There are no optional tracking choices to manage on the marketing website at present. If we introduce tracking that requires consent, it will remain off until you opt in, and we will provide a way to refuse it and withdraw consent as easily as you gave it. Continuing to browse will not count as consent.

9. Marketing

We market to businesses and to business contacts. Before we use your personal data in direct marketing we tell you what kinds of data we will use and what we will market, and we obtain your consent where the law that applies to you requires it. In practice we use your name, work email address, telephone number, employer and job title to tell you about the Bletchley platform and related services by email, telephone and business messaging.

You can stop marketing at any time, free of charge, by using the unsubscribe link in any message or by writing to info@bletchley.cc. We act on such a request promptly and keep a record of it so that we do not contact you again.

We do not provide your personal data to any third party for that third party's own direct marketing.

Invoices, security notices, incident notifications, service announcements and notices of changes to our terms or to this policy are not marketing. While you hold an account you cannot opt out of them.

10. Your rights

Wherever you are, you may ask us for a copy of the personal data we hold about you, ask us to correct it if it is wrong, ask us to delete it, object to our use of it for marketing, and complain about how we have handled it. Write to info@bletchley.cc. We will verify your identity before acting and may ask for information in order to do so. We do not charge for most requests, and we will tell you in advance if a fee is permitted and payable.

Where the European or United Kingdom General Data Protection Regulation applies, you also have the right to restriction of processing, to data portability, to object to processing based on our legitimate interests, and to withdraw a consent you have given. We respond within one month, which we may extend by a further two months for complex requests, telling you if we do. You may complain to your national supervisory authority.

Where Hong Kong law applies, you may make a data access request and a data correction request, and we will respond within 40 days. You may complain to the Office of the Privacy Commissioner for Personal Data. These rights include access to and correction of the personal data we hold for Free Trial verification and eligibility. Requests may be sent to info@bletchley.cc.

Where Singapore law applies, you may request access to and correction of your personal data and may withdraw your consent on reasonable notice. We generally respond within 30 days and will tell you if we need longer. Withdrawing consent may mean that we can no longer provide a service to you.

Where the privacy law of a United States state applies, you may request to know, access, correct, delete and receive a portable copy of your personal information, opt out of any sale or sharing of it and of targeted advertising, limit the use of sensitive personal information, and appeal a decision we make on your request. We do not discriminate against anyone for exercising these rights.

Where you are in another market and local law gives you rights beyond those above, we honour them.

If your request concerns personal data we process on behalf of one of our business customers, we will tell you so, direct you to that customer where we are lawfully able to identify them, and assist them in responding to you.

11. Automated decisions

A service built on the platform generates answers and can create records such as bookings and requests. We do not use it to make decisions about you that produce legal or similarly significant effects without human involvement, and our terms prohibit our customers from doing so. If you believe an automated response has affected you unfairly, contact the business you were dealing with, or write to us at info@bletchley.cc.

12. Security

We maintain administrative, physical and technical measures appropriate to the data we hold. These include encryption of data in transit and at rest, access control on least-privilege principles, separation of each customer's data from every other customer's, logging and audit trails, change management, vulnerability management, screening and training of personnel, and an incident response plan that covers incidents specific to artificial intelligence systems, such as the unauthorised entry of personal data into a model or abnormal model output.

No system is completely secure. Where a breach of security affects personal data we hold, we notify the affected customer without undue delay and in any event within 72 hours of becoming aware of it, and we notify individuals and regulators where the law requires it or where it is otherwise appropriate. We notify even where the law that applies to us does not yet compel us to.

If you believe you have found a vulnerability, please write to info@bletchley.cc. Please do not test the security of the platform in any other way.

13. Changes to this policy

We may update this policy. Where a change is material we notify account holders by email or within the console before it takes effect. Continuing to use our websites or the platform after a change takes effect means that you accept the updated policy.

14. Contact

For any question about this policy, to exercise a right, to report a concern or to reach our data protection officer, write to info@bletchley.cc.

You may also complain to the data protection authority in your own market. In Hong Kong this is the Office of the Privacy Commissioner for Personal Data.

Back to top
Bletchley
Terms of ServicePrivacy PolicyData Processing AgreementCookie PolicyAffiliation and Partnership

© 2026 Bletchley Consulting Services Limited. All Rights Reserved.