Privacy Policy

dAIsy | meetdaisy.co.uk
JAM AI Ltd | Company No. 16845508
33 Great George, Leeds, LS1 3AJ

Last updated: September 2026

[email protected]

1. Who we are

This Privacy Policy explains how JAM AI Limited, trading through the dAIsy brand, collects, uses, shares and protects personal information.

In this Privacy Policy, references to "JAM AI", "dAIsy", "we", "us" or "our" mean JAM AI Limited.

JAM AI Limited is registered with the UK Information Commissioner's Office (ICO) as a data controller. Our current ICO registration reference is available on request from [email protected].

2. Scope of this Privacy Policy

This Privacy Policy applies when JAM AI acts as a data controller, including where you:

      visit a dAIsy website;

      enquire about dAIsy;

      start a dAIsy trial;

      purchase a dAIsy subscription;

      administer a business account;

      contact our team;

      receive communications directly from JAM AI;

      attend a dAIsy event or demonstration; or

      otherwise interact directly with JAM AI.

 

There is an important distinction where a business uses dAIsy to process information about its own customers, prospects, employees or other contacts, or where dAIsy is accessed through a reseller or agency partner ("Partner").

In those circumstances, the dAIsy business customer (or, where relevant, the Partner's end client) will normally be the data controller and JAM AI will normally act as its data processor or sub-processor.

If you are an individual whose information has been entered into dAIsy by one of our customers or a Partner's client, you should normally contact that business first regarding how and why your information is being used.


3. Information we may collect

Depending on how you interact with us, we may collect the following categories of information.

Identity and contact information

      name;

      business name;

      job title;

      email address;

      telephone number;

      business address; and

      account-contact information.

Account information

      account identifiers;

      authorised-user details;

      package or subscription information;

      account settings;

      support history;

      login and security information; and

      activity associated with your dAIsy account.

Billing and transaction information

      billing address;

      subscription level;

      invoice information;

      payment status;

      transaction references;

      VAT information; and

      limited payment-related information provided to us by our payment processor.

 

JAM AI does not normally need to store complete payment-card details itself. Card-payment information is processed by specialist payment providers such as Stripe.

Communications

We may process communications you send to us, including emails, support requests, website enquiries, messages, telephone enquiries, feedback and other correspondence.

Technical and usage information

      IP address;

      browser type;

      device information;

      operating system;

      pages visited;

      date and time information;

      referral source;

      login activity;

      security logs; and

      information about interaction with dAIsy.

Marketing information

      marketing preferences;

      communications opened or clicked;

      event attendance;

      enquiries;

      interests in dAIsy services; and

      whether you have opted out of marketing.

Customer-service data

Where you contact us for support, we may process information reasonably necessary to investigate and resolve the issue.


4. Information processed through customer and Partner dAIsy accounts

Our customers, and businesses who access dAIsy through a Partner, may use dAIsy to collect and manage personal information relating to their own business. Depending on that use, this may include:

      names;

      telephone numbers;

      email addresses;

      addresses;

      website enquiries;

      form submissions;

      appointment information;

      booking details;

      CRM records;

      communications;

      chatbot conversations;

      marketing preferences;

      notes;

      tags;

      customer-history information;

      survey responses; and

      other information selected by the customer.

 

For this information, the customer (or, where dAIsy is accessed through a Partner, the relevant end client) will normally decide why and how the information is processed and will normally be the controller. JAM AI will normally act only on documented instructions as processor or sub-processor, subject to applicable law and the dAIsy Data Processing Terms.

Our contractual data-processing obligations to business customers and Partners are set out in the dAIsy Terms of Service.


5. How we obtain information

We may receive personal information:

      directly from you;

      when you create or administer an account;

      when you complete a form;

      when you start a trial;

      when you subscribe;

      when you contact us;

      when you use a dAIsy website;

      from other authorised users at your organisation;

      from a Partner through whom you access dAIsy;

      from payment providers;

      from service providers;

      from publicly available business sources;

      from referrals or introductions; or

      through technologies used to operate and secure our websites and services.

6. How we use personal information

We may use personal information to:

      provide dAIsy;

      create and administer accounts;

      provide trials;

      process subscriptions and payments;

      deliver onboarding;

      provide customer support;

      communicate with customers and Partners;

      manage our commercial relationships;

      operate and secure our websites;

      monitor performance and security;

      prevent fraud and misuse;

      improve our services;

      maintain business records;

      comply with legal obligations;

      resolve disputes;

      enforce our contractual rights; and

      market dAIsy where legally permitted.

 

We do not use personal information for purposes that are incompatible with the purpose for which it was collected unless permitted by law.

7. Our lawful bases

Under UK data-protection law, we must have a lawful basis for processing personal information when we act as controller. Depending on the circumstances, we may rely on:

Contract

We may rely on contract where processing is necessary to enter into or perform a contract with you personally, for example where you subscribe as an individual or sole trader. Where you act as a contact or authorised user for a company or other organisation, we will normally rely on legitimate interests rather than contract for account administration and relationship management.

Legitimate interests

We may process information where necessary for our legitimate business interests, provided those interests are not overridden by your rights. These interests may include administering business customer and Partner accounts and authorised users, managing customer relationships, operating and improving dAIsy, securing our systems, preventing fraud, maintaining records, analysing business performance, developing our services and marketing relevant business services where permitted. Where we rely on legitimate interests, we consider whether those interests are necessary and balanced against the rights and freedoms of the individuals concerned.

Legal obligation

We may process information where necessary to comply with tax, accounting, regulatory, court or other legal obligations.

Consent

Where the law requires consent, we may rely on your consent. You may withdraw consent at any time, although withdrawal does not affect processing carried out lawfully before withdrawal.

8. Business marketing

dAIsy is a business-to-business service. We may send relevant business marketing communications where permitted by law. Where consent is required, we will seek consent. Where legitimate interests or another lawful basis may lawfully be used for B2B marketing, we may rely on that basis where appropriate.

You can opt out of marketing at any time by using an unsubscribe option provided in the communication or contacting us at [email protected]. We will maintain appropriate suppression records so that marketing preferences can be respected.

9. Cookies and similar technologies

Our websites may use cookies and similar technologies to operate securely, remember preferences, understand website usage and, where applicable, support marketing. Some cookies are necessary for the website or service to function.

Where consent is legally required for non-essential cookies, those cookies are only used after the relevant consent has been obtained through the cookie banner or preference centre available on our websites.

You can also manage cookies through your browser settings, although disabling certain cookies may affect functionality.

10. Payments

Subscription payments may be processed by third-party payment providers, including Stripe. Payment providers process payment information under their own security and privacy arrangements.

JAM AI may receive transaction information such as:

      payment status;

      payment reference;

      billing information;

      subscription details;

      partial card information, such as the last digits of a payment card; and

      information required to manage refunds, disputes or failed payments.

 

We do not need to receive or store your full payment-card number in order to provide dAIsy.

11. Artificial intelligence

dAIsy includes AI-enabled functionality. Where AI functionality processes personal information on behalf of a dAIsy customer, JAM AI will normally process that information as the customer's (or Partner's end client's) processor.

AI functionality may rely on specialist third-party providers. JAM AI does not use personal information processed through dAIsy to train general-purpose or foundation AI models operated by JAM AI or by third-party AI providers. Where a third-party AI provider is engaged as a sub-processor, JAM AI requires, so far as reasonably achievable through its contract with that provider, that personal information is used only to deliver the requested functionality and not for that provider's own model training.

Customers are responsible for deciding what information they provide to AI functionality and should avoid entering unnecessary confidential, sensitive or personal information.

AI providers, models and capabilities may change from time to time.

12. Who we share information with

We may disclose personal information to third parties where reasonably necessary to operate dAIsy or our business. These may include providers of:

      underlying software infrastructure;

      cloud hosting;

      database and storage services;

      communications;

      email;

      SMS;

      telephony;

      artificial intelligence;

      payment processing;

      cyber-security;

      analytics;

      customer support;

      accounting;

      professional advice; and

      business integrations.

 

We may also disclose information: where required by law; in response to a valid legal request; to protect our rights or security; to investigate fraud or unlawful activity; to a Partner through whom you access dAIsy, to the extent reasonably necessary to operate that relationship; or as part of a genuine merger, sale, acquisition, restructuring or transfer of the dAIsy business.

We do not sell personal information in the ordinary meaning of selling personal data to data brokers for their own unrelated purposes.

13. Underlying platform and infrastructure

dAIsy is provided by JAM AI Limited and uses third-party software and infrastructure to deliver elements of the Service. In particular, dAIsy uses software and infrastructure provided by HighLevel, Inc. (also known as GoHighLevel or HighLevel).

Where HighLevel or another provider processes personal data on behalf of JAM AI in connection with Customer data, that provider may act as a sub-processor under appropriate contractual arrangements.

JAM AI may also use other providers for services such as cloud hosting, communications, email, SMS, telephony, artificial intelligence, payment processing, analytics, security and integrations. The providers used may change from time to time as the Service develops.

HighLevel and other independent third-party providers may also process certain information for their own purposes where they act as separate controllers. Where that occurs, their own privacy information will apply to that processing.

14. International transfers

Some of our service providers may process information outside the United Kingdom. Where UK data-protection law treats a transfer as a restricted international transfer, we will use an appropriate lawful transfer mechanism or safeguard where required, which may include UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to approved Standard Contractual Clauses, or another lawful transfer mechanism recognised under UK data-protection law.

dAIsy is currently offered primarily to customers based in the United Kingdom. If we offer dAIsy to organisations based in the European Economic Area, Switzerland or elsewhere, we will take any additional steps required by the law applicable to those customers, including appointing an EU representative under Article 27 of the EU GDPR where required.

You can request further information about the safeguards relevant to a particular transfer by contacting [email protected].

15. Data security

We take reasonable technical and organisational measures designed to protect personal information against unauthorised access, accidental loss, misuse, alteration, unauthorised disclosure and destruction, including access controls, authentication, encryption, secure infrastructure, monitoring, backups, vulnerability management, logging and appropriate organisational procedures.

No internet-based service can guarantee absolute security. Customers also have responsibilities for protecting their own dAIsy accounts, including controlling access and protecting passwords and authentication methods.

16. Data retention

We retain personal information only for as long as reasonably necessary for the purpose for which it was collected, including to meet legal, accounting, tax, security and contractual requirements. Retention periods vary depending on the type of information.

For customer account data processed through dAIsy following cancellation or termination:

      access normally ends when the paid subscription period ends;

      account data may be retained for up to 90 days for recovery, reactivation or orderly deletion; and

      after that period, data may be permanently deleted and unrecoverable.

 

Some information may be removed sooner. In particular, telephone numbers and associated telecommunications registrations may be released or deleted within shorter periods imposed by underlying providers.

Certain records may be retained for longer where required for legal, tax, accounting, fraud-prevention, security or dispute-resolution purposes. Backup copies may also remain for a limited period before being overwritten or deleted through normal backup cycles.

17. Your data-protection rights

Depending on the circumstances, UK data-protection law may give you the right to:

      request access to personal information we hold about you;

      ask us to correct inaccurate information;

      ask us to delete information;

      ask us to restrict processing;

      object to certain processing;

      receive certain information in a portable format;

      withdraw consent where processing is based on consent; and

      object to direct marketing. You have an absolute right to object to our use of your personal information for direct marketing.

 

These rights are subject to legal conditions and exemptions. To exercise a right relating to information for which JAM AI is controller, contact [email protected]. We may need to verify your identity before completing a request.

18. If your information is held by one of our customers or partners

If your information appears in dAIsy because you are a customer, prospect, employee or other contact of one of our business customers, or of a client introduced through a Partner, that business will normally be the controller.

You should generally contact that business first if you wish to access your information, correct your information, request deletion, object to marketing, withdraw consent or exercise another data-protection right. JAM AI will provide reasonable assistance to the relevant customer or Partner where required under data-protection law.

19. Automated processing

dAIsy may enable customers to create workflows, automations and AI-assisted processes. JAM AI does not normally determine the purposes for which an individual customer's automation is used. Customers are responsible for ensuring that their use of automated processing complies with applicable law.

Where solely automated processing produces legal or similarly significant effects on an individual, additional requirements may apply under UK data-protection law.

20. Children

dAIsy is a business service and is not intended to be purchased or used by children. Our customers are responsible for ensuring that any processing of children's personal information through dAIsy is lawful and appropriately safeguarded.

21. Special-category information

dAIsy is not designed specifically for storing or processing special-category personal information or criminal-offence information. Customers should not use dAIsy to process such information unless the processing is necessary, they have an appropriate lawful basis and condition under applicable law, appropriate safeguards are in place and their use of the Service is suitable for that processing.

22. Complaints

If you have a concern about how JAM AI uses your personal information, you can make a data-protection complaint to us at [email protected]. We will acknowledge a data-protection complaint within 30 days, take appropriate steps to investigate it, keep you informed where appropriate and provide our outcome without unnecessary or unjustifiable delay. You do not have to complain to us before contacting the ICO, although giving us the opportunity to resolve the issue may be helpful.

You also have the right to complain to the UK's data-protection regulator, the Information Commissioner's Office (ICO). The ICO can be contacted at Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF, by telephone on 0303 123 1113, or through ico.org.uk.

23. Data protection contact

JAM AI has a designated contact for data-protection enquiries and complaints. This contact is not described as a Data Protection Officer unless JAM AI formally appoints one in accordance with applicable law. Data-protection enquiries should be sent to [email protected].

24. Third-party websites and integrations

dAIsy and our websites may contain links to or integrate with third-party websites and services. Those organisations may process information under their own privacy policies. JAM AI is not responsible for the privacy practices of independent third parties where they act as separate controllers. You should review the relevant third party's privacy information where appropriate.

25. Business transfers

If JAM AI or the dAIsy business is sold, merged, reorganised or transferred, personal information may be transferred as part of that transaction where lawful. Any recipient will be required to process the information in accordance with applicable data-protection law.

26. Changes to this Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in dAIsy, our business, our service providers, applicable law or our processing activities. The latest version will be published through the dAIsy website. Where a change is material, we may provide additional notice where appropriate.

27. Contact us

For questions about this Privacy Policy or JAM AI's use of personal information, contact:

 

JAM AI Limited

Company number: 16845508

Registered office: 33 Great George Street, Leeds, England, LS1 3AJ

Email: [email protected]

dAIsy