Privacy Policy
Last updated: June 2025
1. Who We Are
SCG Bot Services is operated by Squid Consultancy Group Limited, a company registered in Scotland (Company No. SC846551) with its registered office at 8 Cecil Street, Glasgow G12 8RQ, United Kingdom. We are the data controller for the personal data we collect through the Service.
Data Protection Contact: contact@squidconsultancy.com
2. What Data We Collect
We collect the following categories of personal data:
- Account Information: email address, company name, hashed password.
- Billing Information: payment details processed securely by Stripe. We do not store your full card number.
- Usage Data: API call logs (endpoint, timestamp, token count), bot configurations, training data you provide.
- Technical Data: IP address, browser type, device information, and cookies necessary for the Service to function.
- Communications: messages you send through our contact form or support channels.
3. How We Use Your Data
We use your personal data for the following purposes:
- To provide, maintain, and improve the Service (contract performance).
- To process payments and manage subscriptions (contract performance).
- To communicate with you about your account, updates, and support (legitimate interest).
- To monitor usage for security, fraud prevention, and abuse detection (legitimate interest).
- To comply with legal obligations (legal obligation).
4. Legal Basis for Processing (UK GDPR)
We process your data under the following legal bases:
- Contract: Processing necessary to fulfil our agreement with you when you register and use the Service.
- Legitimate Interest: Processing necessary for our legitimate business interests, such as product improvement, analytics, and security.
- Legal Obligation: Processing required to comply with applicable UK law.
- Consent: Where explicitly given, for example for marketing communications.
5. Data Sharing
We may share your personal data with:
- Stripe: for secure payment processing.
- Hosting providers (Vercel, Hostinger): for infrastructure and database services.
- AI model providers: anonymised query data to generate chatbot responses. No personal data is shared with model providers.
- Law enforcement or regulators: if required by law or to protect our legal rights.
We do not sell your personal data to third parties.
6. Data Retention
We retain your account data for as long as your account is active. API logs are retained for 90 days. If you delete your account, we will remove your personal data within 30 days, except where retention is required by law (e.g. billing records for tax purposes, which are retained for 7 years).
7. Data Security
We implement appropriate technical and organisational measures to protect your personal data, including:
- Passwords hashed with bcrypt.
- All data transmitted over HTTPS/TLS.
- API keys are unique per account and can be rotated.
- Database access restricted by IP and credentials.
- Regular security reviews and updates.
8. Your Rights (UK GDPR)
Under the UK GDPR, you have the right to:
- Access: Request a copy of the personal data we hold about you.
- Rectification: Request correction of inaccurate data.
- Erasure: Request deletion of your personal data ("right to be forgotten").
- Restriction: Request that we limit processing of your data.
- Portability: Request your data in a structured, machine-readable format.
- Objection: Object to processing based on legitimate interest.
To exercise any of these rights, contact us at contact@squidconsultancy.com. We will respond within 30 days.
9. Cookies
We use essential cookies required for the Service to function (e.g. authentication tokens stored in localStorage). We do not use third-party tracking or advertising cookies.
10. International Transfers
Your data may be processed by hosting providers located outside the UK. Where this occurs, we ensure appropriate safeguards are in place (e.g. Standard Contractual Clauses) in accordance with UK GDPR requirements.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will post any changes on this page with a revised "Last updated" date. Material changes will be communicated via email or a notice on the Service.
12. Complaints
If you are not satisfied with how we handle your personal data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO): ico.org.uk
13. Contact
For privacy-related enquiries:
- Email: contact@squidconsultancy.com
- Phone: +(44) 7752-106224
- Address: 8 Cecil Street, Glasgow G12 8RQ, United Kingdom