01
Who we are
ENGAGEMINTY LTD is a UK technology and AI growth partner. Our company number is 15450941 and our registered office is 27 Old Gloucester Street, London, United Kingdom, WC1N 3AX.
This policy explains how we collect, use, share, retain and protect personal information when you visit our website, contact us, apply for an opportunity, buy or use our services, participate in a portal or community, or otherwise interact with EngageMinty.
02
Information we may collect
Depending on your relationship with us, we may collect:
- identity and contact information, including your name, email address, telephone number and location;
- business information, role, employer, website, requirements and enquiry details;
- appointments, messages, call records, recordings, support requests and communication preferences;
- application, audit, research, project, service and customer-support information you provide;
- account, login, profile, portal, learning-progress, community, post, comment and upload information;
- contract, order, invoice, subscription and payment-status information;
- wallet balances and top-ups, manual or automatic top-up settings, metered-usage deductions, transaction history, failed-payment and reactivation status, billing disputes, refunds and payment-support communications;
- payment information processed by Stripe, including transaction identifiers, status, amount, currency, billing contact, card brand and limited payment-method details such as the last four digits. We do not receive or store complete card numbers or card security codes;
- consent, opt-in, opt-out and suppression records;
- IP address, device and browser details, activity and security logs, communications metadata and information used to prevent fraud or abuse; and
- information generated through our CRM, websites, forms, calendars, communications, AI features, workflows and connected systems.
Information obtained from other sources
We may obtain professional or business contact information from public business websites, search results, company registers, professional networks and directories; reputable licensed business-data providers; referrals, partners and networking; and existing CRM records or previous enquiries.
Where information is collected indirectly, we record its source where reasonably possible, assess whether the intended use is lawful and fair, and provide privacy information when required. Bought data is not treated as automatically lawful: we assess its source, collection method, permitted uses, notices and suppression handling. We do not use unlawfully scraped information.
03
How and why we use information
We may use personal information to respond to enquiries; arrange appointments; assess applications; provide, secure, support and improve services; manage accounts, projects and customer relationships; administer contracts, subscriptions, payments and wallets; charge for metered usage; issue receipts and account records; investigate unusual usage; prevent fraud and abuse; resolve disputes; maintain records; and comply with legal or accounting obligations.
We may also use information to provide requested service communications, conduct proportionate business-to-business outreach, operate portals and communities, moderate content and enforce our Terms of Service and Acceptable Use Policy.
Our lawful bases may include taking steps before or performing a contract, our legitimate interests in operating and protecting our business and services, consent where required, and compliance with legal obligations. Where special-category information is involved, an additional lawful condition is required.
Calls and meeting recordings
We may record telephone calls, online meetings or support conversations for quality assurance, training, security, record-keeping and service improvement. We inform participants before or at the start of recording. Access is restricted to authorised people who need it for an identified purpose, and recordings are not used for unrelated marketing.
04
When we are controller or processor
EngageMinty is an independent controller for information used for our own account administration, enquiries, billing and wallet records, security and fraud prevention, abuse investigations, legal compliance, service communications and business operations.
A customer is normally the controller for contact, lead, employee, applicant, patient and other personal information it places in its CRM account or asks us to process through a customer service. EngageMinty normally acts as processor for that information, processing it to provide, secure, support and maintain the agreed service and according to the customer’s documented instructions.
Customers are responsible for their own privacy notices, lawful bases, consents, data accuracy, retention choices and responses to individual-rights requests. A Data Processing Agreement may apply. We may assist with rights requests, exports or deletion where included in the service or separately agreed.
Client-controlled health information
We do not ordinarily collect health information for our own business purposes. A healthcare or aesthetics customer may use an approved system for information for which it remains controller and EngageMinty acts as processor. Authorised support access occurs only when requested or otherwise permitted by the agreement and only to the extent reasonably necessary.
Customers must not store protected health information, special-category health data or other regulated medical information in an EngageMinty-supported system unless the configuration has been approved in writing and the required contractual, technical and organisational safeguards are active. Optional HIPAA-enabled configurations may be available to eligible United States healthcare customers following assessment, but availability of a feature does not by itself make an organisation or workflow compliant.
05
AI-assisted processing
We may process prompts, instructions, uploaded or connected information, conversation content, generated outputs, feedback and relevant usage logs to provide AI-enabled features. Uses may include summaries, drafting, audits, analysis, classification, recommendations, prospect research and scoring, chat or voice assistants, workflow support and service improvement.
Relevant information may be sent to approved AI providers acting under contractual and security controls. Customers must not submit personal information they are not authorised to process. EngageMinty does not use customer data to train general-purpose AI models without express agreement.
We may use limited de-identified or aggregated operational information to monitor reliability, security, usage and costs where individuals and customer confidential information are not identifiable. AI output may be retained with the relevant CRM record, workflow or project where needed to provide the service.
AI output may be incomplete or inaccurate. Significant decisions require meaningful review by a suitably authorised person who considers the relevant information critically and retains authority to change the outcome. AI features must not make solely automated decisions producing legal or similarly significant effects unless the use has been separately assessed and lawfully implemented.
Sensitive information and AI
Health information, biometric information, criminal-record information and other special-category personal data must not be submitted to general AI features unless the specific use has been approved and appropriate safeguards are active. Approval may require a documented assessment, suitable lawful basis and condition, contractual protections, restricted access and an appropriately configured provider. We may disable or restrict AI processing where the proposed use creates an unacceptable privacy, legal or security risk.
If EngageMinty is controller, an individual may contact us about a decision made or materially assisted by AI. If our customer is controller, the request should normally be directed to that customer.
07
Service and marketing communications
We use contact information to respond to enquiries and provide requested account, appointment, project, security, billing and service communications. Permission to answer an enquiry or provide a service does not automatically create marketing consent.
Where consent is required, email, SMS and WhatsApp marketing choices are collected separately for the relevant channel. You may opt out of marketing at any time. We may retain minimal suppression information so that we continue to honour an opt-out.
For lawful UK business-to-business calling, we apply appropriate TPS, CTPS and internal suppression screening, identify the caller, provide a callable number and honour objections. Licensed business data is used only after appropriate source and permitted-use checks.
SMS and mobile information
If you opt in, we may use your mobile number for service-related messages described on our SMS opt-in page. Message frequency varies according to appointments, enquiries and service activity. Message and data rates may apply.
No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Sharing with subcontractors in support services, such as customer service, is permitted only as needed to provide those services on our behalf. All other categories exclude text-messaging originator opt-in data and consent; this information will not be shared with third parties.
Reply STOP to opt out or HELP for help. Read our SMS Terms.
09
How long we keep information
We keep personal information only for as long as reasonably needed for its purpose, subject to legal, security, dispute and claim requirements.
- Unsuccessful enquiries and leads are normally kept for up to 12 months after the last meaningful contact.
- Call, meeting and support recordings are normally kept for no longer than 12 months.
- Portal, profile, learning and community information is normally kept for up to 12 months after access ends; shared discussions may continue in anonymised form.
- During an active service, customer-controlled CRM information remains available according to account configuration and customer instructions.
- After voluntary termination, CRM account data may be deleted after 30 days. After non-payment, the account may be terminated and its data deleted after 14 days without payment or customer contact. Customers are responsible for exporting required data before access ends.
- Backups may retain residual copies temporarily until overwritten through the normal cycle. Released telephone numbers, domains and third-party assets may not be recoverable.
- Essential billing, wallet, contract, accounting, security, abuse and legal records are normally retained for up to six years after the relevant relationship or transaction.
- Consent and suppression evidence may be retained for as long as needed to demonstrate consent or honour an opt-out.
A legal hold, dispute, fraud or security investigation, statutory obligation, or the establishment, exercise or defence of legal claims may justify longer retention of specific records. More specific notices or Data Processing Agreements may set different periods.
10
Security and personal-data incidents
We use proportionate technical and organisational safeguards designed to protect information against unauthorised access, alteration, disclosure, loss and destruction. Measures may include access controls, authentication, encryption where appropriate, backups, logging, monitoring, patching, provider assessment, confidentiality obligations and incident-response procedures. Access is limited to authorised people and providers who reasonably need it for their role.
No internet-connected system can be guaranteed completely secure. We investigate suspected personal-data incidents, take reasonable steps to contain and remediate them, preserve relevant evidence and assess risks to affected individuals. We notify regulators and affected individuals when required by law.
When acting as processor, we notify the affected customer without undue delay after becoming aware of a personal-data breach affecting customer-controlled information and provide reasonably available information to support its assessment. Customers and authorised users must protect credentials, use available security controls and notify us promptly of suspected compromise, loss or unauthorised access.
11
Children and younger founders
Our ordinary services, accounts and contracts are intended for people aged 18 or over. We do not knowingly offer ordinary services directly to children or intentionally collect children’s information for marketing.
A person under 18 may explore an appropriate founder, project or partnership route only through an authorised parent, guardian or other responsible adult. The adult must submit the enquiry, provide their own contact details and act as principal contact and contracting party. We collect only information about the younger person reasonably necessary to assess the project and do not request sensitive information unless genuinely necessary, specifically assessed and protected.
Guardian involvement does not automatically make every activity or agreement appropriate or enforceable. We may decline an opportunity or require further safeguards. If information about a child is submitted improperly, we may delete or restrict it and contact the responsible adult where appropriate.
12
Testimonials, case studies and publicity
We do not publicly use an identifiable customer’s or individual’s name, logo, photograph, testimonial, quotation, project details or results without explicit permission. Permission may be limited to approved wording, assets, channels and restrictions. One approval does not grant blanket permission, and materially changed wording, new performance claims, new quotations or additional identifiable information require fresh approval.
Permission may be withdrawn for future publicity. Withdrawal does not require recall of already printed or distributed material, immediate erasure of completed lawful historical publication, or control of independent third-party copies. Confidential or personal information outside the permission remains protected. Anonymous or aggregated examples are presented so that customers and individuals are not reasonably identifiable.
13
Your data-protection rights
Depending on the circumstances and applicable law, you may request access, correction, deletion, restriction, objection or transfer of your personal information. Where processing relies on consent, you may withdraw it at any time without affecting processing that was lawful before withdrawal.
We may request reasonable information to verify identity and authority. We respond within the period required by law and may extend it where legally permitted for complex or numerous requests. A request may be refused or limited where a legal exemption applies, but we explain the reason where permitted.
Where EngageMinty is controller, we handle the request directly. Where our customer is controller and we hold information as processor, you should normally contact that customer; we provide reasonable assistance according to the service and applicable Data Processing Agreement.
Information may still be retained where required for legal obligations, fraud prevention, disputes, suppression records or legal claims. You may complain to the UK Information Commissioner’s Office at ico.org.uk and, where applicable, another competent data-protection authority.
14
Contact us
Privacy requests: privacy@engageminty.com
General enquiries: hello@engageminty.com
Postal address: ENGAGEMINTY LTD, 27 Old Gloucester Street, London, United Kingdom, WC1N 3AX.
Changes to this policy
We may update this policy when our services, providers, legal obligations or processing activities change. We will publish the revised version with an updated date and provide additional notice where a change materially affects how we use personal information or where the law requires it.