Legal
Privacy Policy
What we do with personal data: yours, your customers’, and the people who talk to your assistant.
Start here
The short version.
- We do not sell your data. We never have and there is no version of our business that would.
- Conversations are not used to train AI models, ours or anyone else’s.
- Everything we store is hosted in the UK. AI answers are generated in the US, under zero-retention terms.
- If you chatted with an assistant on a business’s website, that business decides what happens to your messages, not us.
- Questions, or want your data: [email protected].
The rest of this page is the detail. We have written it to be read rather than to be legally impenetrable, and we have been specific where most policies are vague, particularly about the AI, and about people who never signed up for anything.
Which part of this applies to you
Holp Ltd (“Holp”, “we”, “us”) is a UK company that makes an AI assistant businesses put on their own websites. That means three different kinds of people end up on this page, and they need different answers.
| You are… | What that means here | Go to |
|---|---|---|
| Someone who chatted with an assistant on a business’s website | You typed a question into a chat box and Holp answered. We handled your message on behalf of that business, and they decide what happens to it, not us. | If you chatted with a Holp assistant |
| A Holp customer | You have an account with us. We decide how your account data is handled, so we are responsible for it directly. | If you have a Holp account |
| Just browsing this website | You are reading holp.ai. We collect very little, and nothing without your say-so. | If you are browsing this site |
Why the difference matters
Data protection law splits responsibility in two, and almost every question about who to contact comes down to which side something falls on.
- A controller decides why and how personal data is used. They answer to you for it.
- A processor handles data on a controller’s instructions, and cannot decide to do something else with it.
For your Holp account, we are the controller. For conversations on a customer’s website, that customer is the controller and Holp is the processor. So if you chatted with an assistant on a shop’s website and you want your messages deleted, that shop is the right place to ask, and we will act on their instruction. We explain how to reach us anyway if you get stuck.
For website visitors
If you chatted with a Holp assistant
This section is for you if you asked a question in a chat box on some business’s website and Holp answered it. Most privacy policies ignore you completely. You are the person with the least information and the most reason to want it, so we have put you first.
Who is responsible for what you typed
The business whose website you were on. They chose to use Holp, they decide what the assistant knows, how long conversations are kept, and who on their team reads them. They are the controller. We hold the messages for them and act on their instructions.
If you want to see, correct or delete what you sent, ask that business. Their own privacy notice should say how. If you cannot find a way to contact them, or they do not respond, email us at [email protected], and although we cannot decide for them, we can point you to the right place and we will chase them.
What Holp receives when you use the chat
| What | Why it exists |
|---|---|
| The messages you type | To work out what you are asking and answer it. This is the whole point of the assistant. |
| The assistant’s replies | So the business can see what was said, and improve answers that went wrong. |
| Anything you volunteer: your name, email, phone number, order number | Only if you type it, or fill in a contact form the assistant offers you. |
| The page you were on | So the assistant can give an answer relevant to what you were looking at. |
| Basic technical information such as approximate location from your IP address, browser and device type | To keep the service running, stop abuse, and show the chat correctly on your screen. |
| Your language | So it can reply in the language you wrote in. |
A word of advice
Please do not type anything into a chat box that you would not put in an email. That means no card numbers, no passwords, no NHS numbers, nothing about your health, and nothing you would be upset to see stored. This is not us dodging responsibility: a chat window is not a secure form, on any website, with any provider. If a business needs sensitive details from you, they should ask for them somewhere built for it.
If you do type something sensitive by accident, tell the business and ask them to delete that conversation. They can.
What we do not do with it
- We do not sell it. Not to anyone, ever.
- We do not use it for advertising, and we do not pass it to advertising networks.
- We do not use it to train AI models. Not ours, and not the AI providers’ (see how the AI works).
- We do not build a profile of you across the different websites that use Holp. A conversation on one customer’s site is not linked to a conversation on another’s.
Is a machine making decisions about you?
No. The assistant answers questions from information the business has published. It does not decide whether you get a loan, a job, a refund or a service, and nothing it does produces a legal or similarly significant effect on you. If a conversation needs a real decision, it hands over to a person.
How long your conversation is kept
Until the business deletes it, or closes their Holp account. They control that. When an account is closed we delete its conversations from our live systems within 30 days, and from backups within 90 days.
For customers
If you have a Holp account
Here we are the controller. This is what we hold about you and your team, and why we are allowed to.
What we collect
- Account details: name, work email, job title, business name, and password (stored hashed, never in readable form).
- Billing information: billing address, plan, invoices and payment history. Card details are handled by our payment provider and never reach our servers.
- What you upload: the website content, PDFs and knowledge you give the assistant to learn from.
- Usage data: conversation volumes, which features you use, error logs.
- Support conversations: emails and messages you send us.
Why we are allowed to hold it
Every use of personal data needs a lawful basis. Here is ours, per purpose, rather than a vague list.
| What we do | Lawful basis | Notes |
|---|---|---|
| Run your account and provide the service | Performance of a contract | We cannot give you the product without this. |
| Take payment and chase unpaid invoices | Performance of a contract | |
| Answer your support requests | Performance of a contract | |
| Keep the service secure, prevent abuse, fix faults | Legitimate interests | Our interest in a working, un-abused service. You can object (see your rights). |
| Improve the product using aggregated usage patterns | Legitimate interests | Aggregated and stripped of anything identifying. Never the content of your visitors’ conversations. |
| Email you about your account and service changes | Performance of a contract | These are not marketing and you cannot unsubscribe from them while you hold an account. |
| Send marketing about Holp to existing customers | Legitimate interests | Unsubscribe in any email, or email us. We stop immediately. |
| Send marketing to people who are not customers | Consent | Only where you have asked for it. |
| Keep records for tax, accounting and legal claims | Legal obligation |
What you are responsible for
Worth saying plainly, because it catches people out. When your assistant talks to visitors on your website, you are the controller of those conversations, not us. That means it is on you to:
- Mention the chat in your own privacy notice, and say that a processor handles it.
- Have a lawful basis for the conversations and any leads you capture.
- Answer requests from your visitors about their data. We will help you find and delete it.
- Not upload personal data into the assistant’s knowledge that has no business being there.
We can only act on your instructions for that data. If a visitor asks us directly, we will refer them to you. The data processing agreement sets that relationship out in full, as UK GDPR Article 28 requires.
The AI part
How the AI works, and what it does with what you type
This is the question everybody actually wants answered, and most privacy policies skirt it. So, directly:
Your conversations are not used to train AI models. Not by Holp, and not by the AI providers we use. We hold zero data retention terms with our AI providers, which means the content we send them is not stored on their systems after the answer is returned, and is not used to improve their models.
Which AI providers we use
Holp does not build its own language model. We send the question, the relevant part of the business’s published content, and the recent conversation to one of two providers, which returns an answer:
| Provider | Where | What it receives |
|---|---|---|
| OpenAI | United States | The visitor’s message, relevant content from the business’s own knowledge, and recent turns of that conversation. |
| Anthropic | United States | The same. |
Customers on the newer widget can choose which of the two answers their visitors, in the assistant’s Advanced settings. The classic widget uses the platform default.
What is sent, and what is not
- Sent: the message, the relevant knowledge the business has given the assistant, and the recent conversation so the answer makes sense in context.
- Not sent: your account details, billing information, or anything from other customers’ workspaces.
The assistant can still get things wrong
Holp is built to answer only from what a business has actually published, and to say it does not know rather than guess. That is a deliberate design choice and it holds up well, but no AI system is perfect. An answer from an assistant is not professional, legal, medical or financial advice, and a business’s own terms take precedence over anything a chat window says.
Who else touches your data
We use a small number of suppliers to run the service. Each one is bound by a contract that limits them to our instructions, and none of them may use your data for their own purposes.
The ones that carry your content are named below. The rest are described by what they do, because naming every piece of infrastructure on a public page tells our competitors more than it tells you.
| Supplier | What they do | Where | What they can see |
|---|---|---|---|
| Amazon Web Services | Cloud hosting and databases, in the London region (eu-west-2) | United Kingdom | Everything stored in the platform, at rest |
| OpenAI | Generates the assistant’s answers | United States | Message content and the knowledge passages used to answer it, in the moment, under zero-retention terms |
| Anthropic | Generates the assistant’s answers, as the alternative model provider | United States | The same, on the same terms |
| Stripe | Payments and subscriptions | Ireland and United States | Billing details. Card numbers never reach Holp. |
| Google Analytics | Website analytics | United States | Usage of holp.ai only, and only if you accept analytics cookies. Never the product. |
| A search index provider | Finds the right passage of your knowledge to answer from | United States | Your knowledge content and the embeddings built from it, stored |
| A content extraction provider | Reads the pages and PDFs you add to an assistant’s knowledge | Germany | The web addresses and documents you submit |
| Two web search providers | Look something up on the web when an assistant needs to, one as backup for the other | United States | The search query, which is derived from the conversation |
| A location lookup provider | Turns a shortened IP address into a town and country | Germany | A shortened IP address only. We cut the last part off before it is stored or sent, so it points at a network rather than a device. |
| An email delivery provider | Sends our transactional email | United States | Your email address, and the content of the emails we send you |
| A bot protection provider | The bot check on our public forms and free tools | United States | Your IP address and browser signals, at the moment you submit |
| An error monitoring provider | Technical diagnostics when something breaks | United States | Diagnostic data, which can incidentally include an identifier |
| Optional “sign in with Google” | United States | Your name, email address and Google account ID, but only if you choose that route |
Customers get the full list. Every sub-processor is named in the data processing agreement, along with what each one does and where it is, which is what UK GDPR requires of us and what your procurement team will ask for. We will tell customers before we add or change any of them.
Not every supplier sees every conversation. The web search tools are only involved when an assistant needs to look something up, and Google is only involved if you sign in that way.
Other times we may share data
- If the law requires it: a court order, or a lawful request from a regulator or the police. We check that requests are valid rather than simply complying.
- To establish or defend legal claims.
- If Holp is sold or merges, data would transfer with the business, and you would be told beforehand.
We do not sell personal data, and we do not share it for advertising. There is no version of our business model that involves it.
Sending data outside the UK
Everything Holp stores in the platform is hosted in the United Kingdom. The suppliers listed above as being elsewhere are the exceptions: message content goes to OpenAI or Anthropic in the United States for as long as it takes to generate an answer, your knowledge content is indexed in the United States, and the pages and documents you add are read in Germany.
For transfers to the United States we rely on the UK International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses, together with checks on the safeguards each provider has in place. If you have seen a privacy policy citing “Standard Contractual Clauses” on their own for a UK business, that is the EU mechanism, and UK transfers need the IDTA or the Addendum.
How long we keep things, and how we protect them
| What | How long | Why |
|---|---|---|
| Visitor conversations and captured leads | Until the customer deletes them or closes their account | The customer decides. We act on their instruction. |
| Data after an account closes | Removed from live systems within 30 days, and from backups within 90 days | |
| Account and profile details | For the life of the account, then deleted | |
| Billing records and invoices | 6 years after the end of the relationship | UK tax and accounting law requires it |
| Support emails | 3 years | So we can pick up a thread later |
| Security and error logs | 12 months | Investigating incidents and abuse |
| Marketing consents and opt-outs | Kept indefinitely | So we do not email someone who has told us to stop |
| Website analytics | As set out in the cookie policy |
Keeping it safe
We take security seriously, and we would rather describe it concretely than say “industry standard”:
- Data is encrypted in transit, and encrypted at rest in our databases.
- Passwords are stored hashed. Nobody at Holp can read yours.
- Access to production data is limited to the people who need it, and is logged.
- Each customer’s workspace is separated. One customer cannot see another’s conversations or knowledge.
- Card details never touch our servers.
No system is completely secure, and anyone who tells you otherwise is selling something. If a breach happens that puts your rights at risk, we will tell the ICO within 72 hours of becoming aware of it, and tell you without undue delay where the risk to you is high.
Your rights
Under UK data protection law you can ask us to do the following. All of them are free, and we answer within one month.
| Right | What it means in practice |
|---|---|
| Be informed | Know what we hold and why. That is what this page is for. |
| Access | Get a copy of the personal data we hold about you. |
| Rectification | Have anything wrong corrected. |
| Erasure | Have data deleted, where we have no overriding reason to keep it. |
| Restriction | Have us pause using your data while something is being sorted out. |
| Object | Tell us to stop processing based on legitimate interests. For marketing, this is absolute, so we stop, no questions. |
| Portability | Get data you gave us in a machine-readable format, or have it sent elsewhere. |
| Withdraw consent | Where we relied on consent, take it back at any time. It does not undo what was lawful beforehand. |
| Not be subject to automated decisions | We do not make decisions about you by automated means that have legal or similarly significant effects. See how the AI works. |
Email [email protected]. We may need to check who you are before we hand over personal data, which protects you, not us.
If you chatted with an assistant on a business’s website, send your request to that business rather than to us. They hold the decision. We will help them find and action it, and if you cannot get anywhere, tell us and we will chase.
If you are not happy
Come to us first and give us the chance to put it right. If we do not, you can complain to the Information Commissioner’s Office, the UK regulator, at ico.org.uk or on 0303 123 1113. You can complain to them without coming to us first.
Children
Holp is a product sold to businesses and is not aimed at children. We do not knowingly collect personal data from children under 13. If you believe a child has given us personal data, email [email protected] and we will delete it.
If you run a website that children use and you have a Holp assistant on it, the responsibility for age-appropriate design sits with you as the controller. The ICO’s Children’s code is the guidance to read.
Browsing this website, and cookies
If you are just reading holp.ai and have not signed up for anything, we collect very little.
- Analytics: only if you accept analytics cookies. We use Google Analytics to see which pages get read. If you decline, none of it runs.
- Server logs: IP address, browser and pages requested, kept briefly for security and to diagnose faults. Lawful basis: legitimate interests in a secure, working website.
- Forms you fill in: the contact form, and our free tools. Only what you type.
Our free tools
The answerability check, sitemap extractor, sitemap validator and robots.txt checker read publicly available pages on a website address you give us. They do not require an account.
Cookies
Every cookie this site can set is listed in our cookie policy, including what it does and how long it lasts. In short: one necessary cookie remembering your consent choice, and Google Analytics only if you accept it. No advertising cookies at all. Change your mind any time with Manage cookies in the footer.
Who we are, and how to reach us
| Company | Holp Ltd, registered in England and Wales, company number 16582223 |
| Registered office | Unit 20b Yarrow Mill, Yarrow Road, Chorley, England, PR6 0LP |
| Privacy enquiries | [email protected] |
| General enquiries | [email protected] |
Changes to this policy
We will update this page when the way we handle data changes. The date at the top tells you when it last changed. If a change materially affects you, we will email account holders rather than rely on you noticing.
Last updated: 24 August 2026.
Related
- Data processing agreement: the Article 28 terms for customers
- Cookie policy: every cookie this site sets
- Answerability check: see what your own site can answer
- All resources