Privacy Policy

BAYPILOT LTD - Privacy Policy for End-Users of Our Business Partners

Last updated: 19 December 2025

1. Who we are

BAYPILOT LTD ("BayPilot", "we", "us", "our") provides AI-powered telephone, booking, and customer communication services on behalf of independent garages, MOT centres, and similar automotive service providers (our "Business Partners").

For most of the personal information described below BayPilot acts as a "data processor" and handles your data strictly on your Business Partner's instructions. In a few narrower cases, such as service analytics, fraud prevention, and product improvement, we act as an independent "data controller".

Contact our Data Protection Officer (DPO) at contact@baypilot.io.

2. The legal framework we follow

We process personal data in accordance with:

  • the UK GDPR and Data Protection Act 2018, as amended by the Data (Use and Access) Act 2025;
  • the Privacy and Electronic Communications Regulations 2003 (PECR); and
  • any local data-protection laws that apply where the garage or workshop is located.

3. What data we collect and why

CategoryExamplesPurpose and lawful basis*
Call dataCaller ID, audio recording, transcribed text, call timestamp, unique call IDPerform the booking contract with your garage; legitimate interest in quality assurance and fraud prevention
Booking detailsName, vehicle registration, service or MOT type, requested date and time, notes about vehicle issues or access needsPerform the requested booking and help the workshop prepare for the vehicle visit
Payment or deposit infoLast 4 digits of card, Stripe or GoCardless token, fee amountPerform contract and comply with financial regulations
SMS and email logsConfirmation or reminder texts, sender, recipient, delivery statusPerform contract and support service monitoring
Device and usage dataIP address, browser type, cookies, interaction logsLegitimate interest in security and analytics; consent for non-essential cookies where required
Service analyticsCall duration, abandonment rate, booking conversionOur legitimate interest in improving and reporting on the service

*Where we rely on consent, for example for marketing messages, you can withdraw it at any time.

4. How we collect your data

  • You speak with our AI voice agent or one of our human fail-over staff.
  • You enter details into a Business Partner's online booking widget powered by BayPilot.
  • Garage staff add or amend your booking in the BayPilot dashboard.
  • Our payment partner, such as Stripe or GoCardless, processes any booking fee or deposit.

5. Who we share data with

RecipientReason
Your Business PartnerTo confirm, modify, or cancel your booking
Telecoms and cloud providersSecure call processing and hosting
Payment processorsCollection of deposits or booking fees
SMS gatewaysSending confirmations and reminders
Professional advisersCompliance and defence of legal claims
Regulators or law enforcementWhere legally required

All suppliers are bound by data-processing contracts that meet UK GDPR standards.

6. International transfers

Your data may be stored or accessed outside the UK or EU. Where that happens, we rely on appropriate safeguards such as:

  • UK International Data Transfer Agreements (IDTAs) or EU Standard Contractual Clauses;
  • UK Information Commissioner-approved certifications; or
  • adequacy decisions where available.

7. Data retention

Data typeDefault retention
Call recordings and transcripts90 days unless your garage's plan includes longer history
Caller and booking metadata12 months after the booking date
Payment tokens and invoices7 years for compliance purposes
SMS or email delivery logs12 months
Aggregated anonymised analyticsIndefinite

8. Security measures

  • Encryption in transit (TLS 1.2+) and at rest (AES-256).
  • Role-based access and multi-factor authentication for staff.
  • Penetration testing, monitoring, and incident-response processes aligned to ICO guidance.
  • Access controls designed to limit data to those who need it for support or operations.

9. Your rights

You can, at no cost:

  • access the personal data we hold;
  • rectify inaccurate or incomplete data;
  • erase data in certain circumstances;
  • restrict or object to processing;
  • port data to another provider;
  • withdraw consent where processing is consent-based; and
  • complain to the ICO (ico.org.uk) or your local data-protection authority.

To exercise any right, email contact@baypilot.io with enough information to identify you and the relevant booking.

10. Children

Our service is not intended for individuals under 16. If we learn that we have collected personal data from a child without verified parental consent, we will delete it promptly.

11. Changes to this policy

We may update this notice to reflect legal, technical, or business changes. Significant changes will be highlighted on the BayPilot website or notified to Business Partners for onward communication where appropriate.

12. Contact us

Questions, concerns, or requests?

Data Protection Officer

Email: contact@baypilot.io

Thank you for trusting BayPilot to power a smoother booking experience.