Skip to main content
EngageMinty Technology and AI Growth Partner
  • CRM
  • Solutions

    What do you need help with?

    Explore all solutions →
    AI & AutomationImprove workflows with practical AI and connected systems. Generate more leadsJoin up websites, search, advertising and follow-up. Respond fasterCapture missed opportunities while your team is busy. Convert more customersMake the next step clearer and easier. Save time and reduce costsRemove repetitive work with practical automation. Connect your systemsBring CRM, APIs and essential tools into one flow. Bespoke TechnologyBuild or connect the capability existing software cannot provide. Have a bigger idea? Partner with us →Selective long-term and Technical Co-Founder partnerships.
  • Industries

    Built around how your business works.

    Explore all industries →
    PlumbersCalls, quotes, bookings, follow-up and reviews. ElectriciansEnquiries, estimates, scheduling and follow-up. DentistsPatient enquiries, reminders and reputation. Aesthetic clinicsConsultations, booking, reminders and conversion. SalonsBookings, missed calls, reviews and reactivation.
  • Pricing
  • Client proof
  • Partner with us
Free Website Audit Get started
← Legal and policies

Privacy

Privacy Policy

Last updated: 1 September 2026

On this pageWho we areInformation collectedHow we use itOur data rolesAI processingSharing and transfersCommunicationsCookiesRetentionSecurityChildrenPublicityYour rightsContact

01

Who we are

ENGAGEMINTY LTD is a UK technology and AI growth partner. Our company number is 15450941 and our registered office is 27 Old Gloucester Street, London, United Kingdom, WC1N 3AX.

This policy explains how we collect, use, share, retain and protect personal information when you visit our website, contact us, apply for an opportunity, buy or use our services, participate in a portal or community, or otherwise interact with EngageMinty.

02

Information we may collect

Depending on your relationship with us, we may collect:

  • identity and contact information, including your name, email address, telephone number and location;
  • business information, role, employer, website, requirements and enquiry details;
  • appointments, messages, call records, recordings, support requests and communication preferences;
  • application, audit, research, project, service and customer-support information you provide;
  • account, login, profile, portal, learning-progress, community, post, comment and upload information;
  • contract, order, invoice, subscription and payment-status information;
  • wallet balances and top-ups, manual or automatic top-up settings, metered-usage deductions, transaction history, failed-payment and reactivation status, billing disputes, refunds and payment-support communications;
  • payment information processed by Stripe, including transaction identifiers, status, amount, currency, billing contact, card brand and limited payment-method details such as the last four digits. We do not receive or store complete card numbers or card security codes;
  • consent, opt-in, opt-out and suppression records;
  • IP address, device and browser details, activity and security logs, communications metadata and information used to prevent fraud or abuse; and
  • information generated through our CRM, websites, forms, calendars, communications, AI features, workflows and connected systems.

Information obtained from other sources

We may obtain professional or business contact information from public business websites, search results, company registers, professional networks and directories; reputable licensed business-data providers; referrals, partners and networking; and existing CRM records or previous enquiries.

Where information is collected indirectly, we record its source where reasonably possible, assess whether the intended use is lawful and fair, and provide privacy information when required. Bought data is not treated as automatically lawful: we assess its source, collection method, permitted uses, notices and suppression handling. We do not use unlawfully scraped information.

03

How and why we use information

We may use personal information to respond to enquiries; arrange appointments; assess applications; provide, secure, support and improve services; manage accounts, projects and customer relationships; administer contracts, subscriptions, payments and wallets; charge for metered usage; issue receipts and account records; investigate unusual usage; prevent fraud and abuse; resolve disputes; maintain records; and comply with legal or accounting obligations.

We may also use information to provide requested service communications, conduct proportionate business-to-business outreach, operate portals and communities, moderate content and enforce our Terms of Service and Acceptable Use Policy.

Our lawful bases may include taking steps before or performing a contract, our legitimate interests in operating and protecting our business and services, consent where required, and compliance with legal obligations. Where special-category information is involved, an additional lawful condition is required.

Calls and meeting recordings

We may record telephone calls, online meetings or support conversations for quality assurance, training, security, record-keeping and service improvement. We inform participants before or at the start of recording. Access is restricted to authorised people who need it for an identified purpose, and recordings are not used for unrelated marketing.

04

When we are controller or processor

EngageMinty is an independent controller for information used for our own account administration, enquiries, billing and wallet records, security and fraud prevention, abuse investigations, legal compliance, service communications and business operations.

A customer is normally the controller for contact, lead, employee, applicant, patient and other personal information it places in its CRM account or asks us to process through a customer service. EngageMinty normally acts as processor for that information, processing it to provide, secure, support and maintain the agreed service and according to the customer’s documented instructions.

Customers are responsible for their own privacy notices, lawful bases, consents, data accuracy, retention choices and responses to individual-rights requests. A Data Processing Agreement may apply. We may assist with rights requests, exports or deletion where included in the service or separately agreed.

Client-controlled health information

We do not ordinarily collect health information for our own business purposes. A healthcare or aesthetics customer may use an approved system for information for which it remains controller and EngageMinty acts as processor. Authorised support access occurs only when requested or otherwise permitted by the agreement and only to the extent reasonably necessary.

Customers must not store protected health information, special-category health data or other regulated medical information in an EngageMinty-supported system unless the configuration has been approved in writing and the required contractual, technical and organisational safeguards are active. Optional HIPAA-enabled configurations may be available to eligible United States healthcare customers following assessment, but availability of a feature does not by itself make an organisation or workflow compliant.

05

AI-assisted processing

We may process prompts, instructions, uploaded or connected information, conversation content, generated outputs, feedback and relevant usage logs to provide AI-enabled features. Uses may include summaries, drafting, audits, analysis, classification, recommendations, prospect research and scoring, chat or voice assistants, workflow support and service improvement.

Relevant information may be sent to approved AI providers acting under contractual and security controls. Customers must not submit personal information they are not authorised to process. EngageMinty does not use customer data to train general-purpose AI models without express agreement.

We may use limited de-identified or aggregated operational information to monitor reliability, security, usage and costs where individuals and customer confidential information are not identifiable. AI output may be retained with the relevant CRM record, workflow or project where needed to provide the service.

AI output may be incomplete or inaccurate. Significant decisions require meaningful review by a suitably authorised person who considers the relevant information critically and retains authority to change the outcome. AI features must not make solely automated decisions producing legal or similarly significant effects unless the use has been separately assessed and lawfully implemented.

Sensitive information and AI

Health information, biometric information, criminal-record information and other special-category personal data must not be submitted to general AI features unless the specific use has been approved and appropriate safeguards are active. Approval may require a documented assessment, suitable lawful basis and condition, contractual protections, restricted access and an appropriately configured provider. We may disable or restrict AI processing where the proposed use creates an unacceptable privacy, legal or security risk.

If EngageMinty is controller, an individual may contact us about a decision made or materially assisted by AI. If our customer is controller, the request should normally be directed to that customer.

06

Service providers, disclosure and international transfers

We do not sell personal information as a customer or marketing database. We may use vetted providers for hosting, CRM infrastructure, communications, AI processing, payments, security, analytics where enabled, document handling, accounting and professional support. Providers receive only information reasonably required for their function and must operate under appropriate contractual, confidentiality and security obligations.

Some providers or infrastructure may be outside the United Kingdom or the country where an individual is based. Where personal information is transferred internationally, we use an applicable lawful mechanism, such as adequacy regulations or approved contractual safeguards, with supplementary protections where required. We may change providers as our services develop while continuing to assess their function, access, location and safeguards. Contact us for further information about relevant provider categories and transfer safeguards.

Investigations and official requests

We may process account activity, logs, content, communications metadata and relevant stored information to investigate suspected fraud, abuse, security incidents or policy violations and may preserve relevant records during an investigation, legal hold or official request.

Reasonably necessary information may be disclosed to law enforcement, courts, regulators, emergency services, specialist reporting bodies, relevant hosting, communications or security providers, and professional advisers where legally required or reasonably necessary to protect people, rights, services or platform security. We assess apparent validity and scope where appropriate, limit disclosure to what is reasonably necessary and notify the affected customer where legally permitted and operationally safe. Notice may be withheld where it could breach law, prejudice an investigation or increase risk.

Business transactions

Relevant information may be disclosed or transferred during a genuine sale, merger, investment, financing, restructuring or transfer of all or part of our business or assets. Prospective parties and advisers receive only what is reasonably necessary under confidentiality and data-protection safeguards, with anonymisation, aggregation or redaction used during early due diligence where practical. A successor may continue compatible processing, and we will provide notice of a material controller change where required.

07

Service and marketing communications

We use contact information to respond to enquiries and provide requested account, appointment, project, security, billing and service communications. Permission to answer an enquiry or provide a service does not automatically create marketing consent.

Where consent is required, email, SMS and WhatsApp marketing choices are collected separately for the relevant channel. You may opt out of marketing at any time. We may retain minimal suppression information so that we continue to honour an opt-out.

For lawful UK business-to-business calling, we apply appropriate TPS, CTPS and internal suppression screening, identify the caller, provide a callable number and honour objections. Licensed business data is used only after appropriate source and permitted-use checks.

SMS and mobile information

If you opt in, we may use your mobile number for service-related messages described on our SMS opt-in page. Message frequency varies according to appointments, enquiries and service activity. Message and data rates may apply.

No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Sharing with subcontractors in support services, such as customer service, is permitted only as needed to provide those services on our behalf. All other categories exclude text-messaging originator opt-in data and consent; this information will not be shared with third parties.

Reply STOP to opt out or HELP for help. Read our SMS Terms.

08

Cookies and browser storage

We may use strictly necessary cookies or browser storage for security, session continuity, preferences, form operation, fraud prevention and essential website functionality. These technologies may operate without optional consent where legally permitted.

Analytics, advertising pixels, behavioural tracking and other non-essential technologies will not be enabled until they have been inventoried, documented and placed behind any required consent controls. Where consent is required, they remain disabled until you make an affirmative choice. Refusing optional tracking will not prevent access to ordinary website content or core services, and you will be able to revisit your choices.

Our notices and controls will reflect technologies actually in use rather than speculative future tools.

09

How long we keep information

We keep personal information only for as long as reasonably needed for its purpose, subject to legal, security, dispute and claim requirements.

  • Unsuccessful enquiries and leads are normally kept for up to 12 months after the last meaningful contact.
  • Call, meeting and support recordings are normally kept for no longer than 12 months.
  • Portal, profile, learning and community information is normally kept for up to 12 months after access ends; shared discussions may continue in anonymised form.
  • During an active service, customer-controlled CRM information remains available according to account configuration and customer instructions.
  • After voluntary termination, CRM account data may be deleted after 30 days. After non-payment, the account may be terminated and its data deleted after 14 days without payment or customer contact. Customers are responsible for exporting required data before access ends.
  • Backups may retain residual copies temporarily until overwritten through the normal cycle. Released telephone numbers, domains and third-party assets may not be recoverable.
  • Essential billing, wallet, contract, accounting, security, abuse and legal records are normally retained for up to six years after the relevant relationship or transaction.
  • Consent and suppression evidence may be retained for as long as needed to demonstrate consent or honour an opt-out.

A legal hold, dispute, fraud or security investigation, statutory obligation, or the establishment, exercise or defence of legal claims may justify longer retention of specific records. More specific notices or Data Processing Agreements may set different periods.

10

Security and personal-data incidents

We use proportionate technical and organisational safeguards designed to protect information against unauthorised access, alteration, disclosure, loss and destruction. Measures may include access controls, authentication, encryption where appropriate, backups, logging, monitoring, patching, provider assessment, confidentiality obligations and incident-response procedures. Access is limited to authorised people and providers who reasonably need it for their role.

No internet-connected system can be guaranteed completely secure. We investigate suspected personal-data incidents, take reasonable steps to contain and remediate them, preserve relevant evidence and assess risks to affected individuals. We notify regulators and affected individuals when required by law.

When acting as processor, we notify the affected customer without undue delay after becoming aware of a personal-data breach affecting customer-controlled information and provide reasonably available information to support its assessment. Customers and authorised users must protect credentials, use available security controls and notify us promptly of suspected compromise, loss or unauthorised access.

11

Children and younger founders

Our ordinary services, accounts and contracts are intended for people aged 18 or over. We do not knowingly offer ordinary services directly to children or intentionally collect children’s information for marketing.

A person under 18 may explore an appropriate founder, project or partnership route only through an authorised parent, guardian or other responsible adult. The adult must submit the enquiry, provide their own contact details and act as principal contact and contracting party. We collect only information about the younger person reasonably necessary to assess the project and do not request sensitive information unless genuinely necessary, specifically assessed and protected.

Guardian involvement does not automatically make every activity or agreement appropriate or enforceable. We may decline an opportunity or require further safeguards. If information about a child is submitted improperly, we may delete or restrict it and contact the responsible adult where appropriate.

12

Testimonials, case studies and publicity

We do not publicly use an identifiable customer’s or individual’s name, logo, photograph, testimonial, quotation, project details or results without explicit permission. Permission may be limited to approved wording, assets, channels and restrictions. One approval does not grant blanket permission, and materially changed wording, new performance claims, new quotations or additional identifiable information require fresh approval.

Permission may be withdrawn for future publicity. Withdrawal does not require recall of already printed or distributed material, immediate erasure of completed lawful historical publication, or control of independent third-party copies. Confidential or personal information outside the permission remains protected. Anonymous or aggregated examples are presented so that customers and individuals are not reasonably identifiable.

13

Your data-protection rights

Depending on the circumstances and applicable law, you may request access, correction, deletion, restriction, objection or transfer of your personal information. Where processing relies on consent, you may withdraw it at any time without affecting processing that was lawful before withdrawal.

We may request reasonable information to verify identity and authority. We respond within the period required by law and may extend it where legally permitted for complex or numerous requests. A request may be refused or limited where a legal exemption applies, but we explain the reason where permitted.

Where EngageMinty is controller, we handle the request directly. Where our customer is controller and we hold information as processor, you should normally contact that customer; we provide reasonable assistance according to the service and applicable Data Processing Agreement.

Information may still be retained where required for legal obligations, fraud prevention, disputes, suppression records or legal claims. You may complain to the UK Information Commissioner’s Office at ico.org.uk and, where applicable, another competent data-protection authority.

14

Contact us

Privacy requests: privacy@engageminty.com
General enquiries: hello@engageminty.com

Postal address: ENGAGEMINTY LTD, 27 Old Gloucester Street, London, United Kingdom, WC1N 3AX.

Changes to this policy

We may update this policy when our services, providers, legal obligations or processing activities change. We will publish the revised version with an updated date and provide additional notice where a change materially affects how we use personal information or where the law requires it.

EngageMinty

Technology and AI Growth Partner for growing businesses. CRM, automation, practical AI and growth services connected around the customer journey.

ExploreCRM foundationConnected servicesWays to work togetherHow the work moves
EngageMintyClient proofLegal and policieshello@engageminty.com
© 2026 EngageMinty. All rights reserved.Remote-first · UK and international