S4W — PRIVACY NOTICE
Version 1.0 · Effective from 3 September 2026. Superseded versions are available on request from hello@s4w.com.
S4W — PRIVACY NOTICE
Version 1.0 Supersedes: no previous version of this notice
This Privacy Notice is issued by S4W L.L.C-FZ ("S4W"), a company registered in the United Arab Emirates with licence number 2529741, whose registered address is Meydan Grandstand, 6th floor, Meydan Road, Nad Al Sheba, Dubai, U.A.E. S4W L.L.C-FZ is the controller or the processor of the Personal Data described in this notice, as set out in section 3. Dial Square Consultancy Ltd, a company registered in England and Wales with company number 17317079, whose registered address is 131 Finsbury Pavement, London, England, EC2A 1NT, is our representative in the United Kingdom under Article 27 of the UK GDPR.
This Privacy Notice sets out how we use, protect and share the Personal Data that we collect from you when you visit our website, when you engage us to perform Services, when we carry out automation work for the organisation you deal with, or when you interact with or contact us in any other way.
CONTENTS
- About this Privacy Notice
- Who are we?
- Our role: when we are a controller and when we are a processor
- Who are you?
- What types of Personal Data do we collect from you?
- How and why do we use your Personal Data?
- Our automation services
- Automated decision-making and artificial intelligence
- How can you manage your marketing preferences?
- What about cookies?
- Who do we share your Personal Data with?
- What happens if we share your Personal Data with organisations outside of the UK (and/or EEA)?
- How do we protect your Personal Data?
- How long do we keep your Personal Data for?
- What are your rights in relation to the Personal Data we hold?
- Contact us if you have a question or a complaint
- Updates to this Privacy Notice
- Third-party links
1. ABOUT THIS PRIVACY NOTICE
1.1 In this Privacy Notice, Personal Data means any information relating to an identified or identifiable living individual. We use the term "Personal Data" throughout; where you see the phrase "personal information" used elsewhere in our documents, it means the same thing.
1.2 This Privacy Notice covers our automation business. We design, build, integrate, deploy and operate bespoke artificial-intelligence and automation solutions for business clients — connecting a Client's existing systems together, moving records between them, generating documents and messages, and operating workflows that respond to events in the Client's business. That work is built and operated internally under the name "S4W Automation Studio"; that is an internal name for part of our business and not a separate company.
1.3 Section 7 (Our automation services) explains the parts that are specific to the work we perform for a Client.
1.4 This Privacy Notice is published at https://s4w.com/privacy. Our General Terms of Business are published at https://s4w.com/terms, our Data Processing Addendum (DPA) at https://s4w.com/dpa and our Cookies Notice at https://s4w.com/cookie-policy.
1.5 Client means a business which engages us to perform Services. Services, Deliverables, SOW, Agreement and Client Materials have the meanings given to them in our General Terms of Business: in summary, the Services are the work described in a statement of work (a SOW), the Deliverables are the automations and other items we build and deliver under it, the Client Materials are the data, records, system access and credentials the Client supplies to us for that purpose, and an Agreement is a SOW and those Terms read together.
2. WHO ARE WE?
2.1 The entity responsible for the processing described in this Privacy Notice is:
S4W L.L.C-FZ, a company registered in the United Arab Emirates, licence number 2529741, registered address Meydan Grandstand, 6th floor, Meydan Road, Nad Al Sheba, Dubai, U.A.E. (S4W, we, us or our).
2.2 S4W is the contracting party for the Services, and is the controller or processor as applicable in accordance with section 3. S4W also trades as YourCalls and YourCalls.ai, under which names it provides a separate self-service voice AI service; that service is governed by its own terms and its own privacy notice, and is not covered by this Privacy Notice.
2.3 Payment collection agent and merchant of record. Fees for the Services are collected on our behalf by Dial Square Consultancy Ltd, registered in England and Wales, company number 17317079, registered address 131 Finsbury Pavement, London, England, EC2A 1NT. Dial Square Consultancy Ltd is our payment collection agent and merchant of record, appointed under clause 1.5 of our General Terms of Business. It is not a reseller and it does not contract with you. Where a payment is collected through our payment provider, Dial Square Consultancy Ltd is the name that will appear on the invoice and on the card or bank statement. Dial Square Consultancy Ltd is not currently registered for VAT.
2.4 Our UK representative. S4W is established outside the United Kingdom and offers services to, and monitors the behaviour of, individuals in the United Kingdom. We have appointed Dial Square Consultancy Ltd, 131 Finsbury Pavement, London, England, EC2A 1NT, contactable at hello@s4w.com, as our representative in the United Kingdom under Article 27 of the UK GDPR. You may contact our UK representative on any matter relating to our processing of your Personal Data.
2.5 Our privacy contact. You can reach us on any privacy matter at hello@s4w.com, or by writing to us at the registered address in clause 2.1. We have assessed our processing against Article 37 of the UK GDPR and have concluded that we are not required to appoint a statutory Data Protection Officer.
2.6 You can contact us at the addresses above if you have any questions about this Privacy Notice, or if you would like to exercise any of your rights under data protection laws, which we set out in section 15.
3. OUR ROLE: WHEN WE ARE A CONTROLLER AND WHEN WE ARE A PROCESSOR
3.1 Data protection law distinguishes between a controller (who decides why and how Personal Data is used) and a processor (who uses Personal Data only on the controller's instructions). Our role differs depending on the data.
3.2 S4W acts as processor, on the Client's instructions, for: all Personal Data comprised in the Client Materials; all Personal Data which a Deliverable reads, creates, updates, generates or moves between systems in the course of the Services; and the record of what a Deliverable did.
3.3 S4W acts as an independent controller for: Client contact and relationship data, billing and payment data, support communications, website analytics and service administration data (such as IP addresses, device and browser information, sign-in times and configuration actions), and marketing data. Data that has been irreversibly anonymised and aggregated in accordance with the anonymisation provisions of our DPA is not Personal Data and falls outside this allocation of roles.
3.4 A Client's own customers, prospects, enquirers and contacts are data subjects for whom the Client is controller.
3.5 Where we act as processor, our processing is governed by our DPA with the relevant Client, published at https://s4w.com/dpa. Where we act as controller, this Privacy Notice describes what we do and why.
3.6 Where we act as processor, this Privacy Notice is provided for information. It does not replace the privacy information that the Client, as controller, is required to give you, and it does not change the Client's responsibility to give it.
4. WHO ARE YOU?
4.1 In this Privacy Notice, when we refer to you or your, we mean any individual whose Personal Data we process in connection with our website, the Services, our automation work, or when you interact with or contact us in any other way.
4.2 This includes:
(a) Website visitors, who browse or interact with our website or online content.
(b) Clients and their representatives, who engage us, who give us instructions, access or Client Materials on a Client's behalf, or who communicate with us about the Services.
(c) Marketing contacts, who sign up to receive updates, events or other marketing communications from us, or engage with our marketing campaigns.
(d) Suppliers, advisers and their personnel, whose contact details we hold in order to run our business.
(e) Other individuals who contact us, for example by email, phone or through our support channels, or whose Personal Data is provided to us in connection with the Services.
4.3 We also process Personal Data about the following individuals as a processor, on behalf of our Clients (see section 3). We are not the controller of this data:
(a) Our Clients' own customers, prospects and enquirers, whose Personal Data we process in the course of automation work (see section 7).
(b) Individuals who use a web page we operate for a Client, for example an online quotation page, whose details are collected through that page for the business named on it.
(c) A Client's own personnel, whose Personal Data is comprised in the Client Materials or is held in the systems a Deliverable operates on.
4.4 If you fall into more than one of these categories, this Privacy Notice applies to you in each relevant capacity.
5. WHAT TYPES OF PERSONAL DATA DO WE COLLECT FROM YOU?
5.1 Where we act as controller (see clause 3.3), we may collect, use, store and transfer different kinds of Personal Data about you, including:
(a) Contact and identity information, such as your name, job title, business email address and telephone number, where you engage us, act for a Client, or correspond with us about the Services, together with any identifiers used to authenticate you where you are given access to a system we operate.
(b) Billing and payment information, such as billing contact details, company name, billing address, tax or VAT identification number, invoice and transaction records, and limited card metadata (card brand, last four digits, expiry date, and a payment-method reference issued by our payment provider). Full card details are entered directly with our payment provider and are never held by us — see clause 11.4.
(c) Communication and support information, such as the content of emails, support tickets, contact form submissions, screenshots you send us and messages you send to us when you contact our team.
(d) Service administration and technical data, such as your IP address, device and browser information, sign-in times, pages visited and configuration actions, collected as part of operating and securing the systems on which we deliver the Services.
(e) Website analytics data, such as pages visited, session duration and click behaviour, collected on our website as described in section 10.
(f) Marketing preferences and engagement data, such as your contact details, communication preferences and consent and opt-out records, where you have signed up to receive marketing communications from us.
5.2 Where we act as processor (see clause 3.2), the Personal Data we handle on our Clients' instructions includes the categories set out in clauses 5.3 to 5.5. We do not decide what is given to us, or what a Deliverable encounters, in these categories.
5.3 Client Materials: the data, records, documents, content, exports, system access and credentials a Client supplies to us, or gives us access to, for the purposes of the Services, including any Personal Data comprised in them. We neither control nor inspect what a Client chooses to supply, and a Client's own free-text fields may contain anything its people have written there.
5.4 Records a Deliverable processes: the Personal Data which an automation reads, creates, updates, generates or moves between systems while it operates in the Client's business, together with the record of its execution — the events it processed, the actions it took and the payloads involved. Clause 7.2 sets out the categories this commonly includes.
5.5 Information collected through a web page we operate for a Client: where an engagement includes a client-facing or consumer-facing page, such as an online quotation page, the details the individual enters into it, the technical information collected with them (including the IP address and browser user-agent), any record of acceptance, and any payment transaction record described in clause 7.7.
5.6 Aggregated Data. We also collect, use and share Aggregated Data such as statistical or usage data for any purpose. Aggregated Data could be derived from your Personal Data but is not considered Personal Data in law as this data will not directly or indirectly reveal your identity. For example, we may aggregate usage data to calculate how often a particular step in an automation succeeds. However, if we combine or connect Aggregated Data with your Personal Data so that it can directly or indirectly identify you, we treat the combined data as Personal Data which will be used in accordance with this Privacy Notice.
5.7 AI model training. We do not use the Client Materials, or the records a Deliverable processes, to train AI models in identifiable form. We may use data derived from the performance of the Services once it has been irreversibly anonymised and aggregated so that no individual can be identified, as described in clause 8.1 of our General Terms of Business and the anonymisation provisions of our DPA. Content is sent to third-party AI providers in order to deliver the Services (see clause 11.3).
6. HOW AND WHY DO WE USE YOUR PERSONAL DATA?
6.1 How your information is collected
(a) When you interact with us. We collect Personal Data directly from you in the following circumstances:
- when you contact us via our website, submit an enquiry or contact form, or correspond with us by email or telephone;
- when your organisation engages us or manages an engagement with us, including during onboarding and discovery; and
- when you sign up to receive marketing communications from us or update your communication preferences.
(b) Automatically. We also collect certain technical and usage data automatically when you visit our website or use a system we operate, including your IP address, device and browser information, pages visited, session duration and click behaviour. See section 10 for what we use on our website and what device storage is involved.
(c) From third parties. We may receive Personal Data about you from the following third-party sources:
- from your employer or organisation, where a representative's details are provided on your behalf in connection with commissioning or managing an engagement with us;
- from our Clients, where they supply us with Client Materials or give us access to their own systems (in which case we act as processor — see section 3); and
- from our payment provider, which supplies us with transaction outcomes and limited card metadata.
(d) Automated technologies and cookies. As you interact with our website, we may automatically collect technical data about your equipment, browsing actions and patterns. Please see our Cookies Notice at https://s4w.com/cookie-policy and section 10 of this Privacy Notice for further details.
6.2 The legal bases we rely on
Data protection laws require us to have a legal basis for everything that we do with your Personal Data, falling under one of the following categories:
(a) Performance of a contract with you: where we need to perform a contract we are about to enter into or have entered into with you.
(b) Legitimate interests: we may use your Personal Data where it is necessary to conduct our business and pursue our legitimate interests, for example to prevent fraud and/or enable us to give you the best user experience. We make sure we consider and balance any potential impact on you and your rights (both positive and negative) before we process your Personal Data for our legitimate interests. We do not use your Personal Data for activities where our interests are overridden by the impact on you (unless we have your consent or are otherwise required or permitted to by law).
(c) Legal obligation: we may use your Personal Data where it is necessary for compliance with a legal obligation that we are subject to.
(d) Consent: we rely on consent principally where we have obtained your active agreement to use your Personal Data for a specified purpose, in relation to receiving marketing emails from us. Consent is also the basis on which non-essential cookies and similar device storage are used where required — see section 10.
Where we act as processor (see clause 3.2), the legal basis for the processing is a matter for our Client as controller, not for us.
6.3 Contact and identity information
| What do we do? | Why do we do it? | What is the legal basis? |
|---|---|---|
| Identify you when you visit our website or contact us for any reason. | So we can identify you, respond to your enquiry, and provide personalised services. | Legitimate interests: necessary for us to be able to communicate with you and manage our client relationships. |
| Send you service updates, project communications, and updates to this Privacy Notice and our Terms. | So we can keep you informed of any changes to our services, terms and data processing. | Legitimate interests: necessary for the effective provision of our products and services. Legal obligation where required by applicable law. |
| Send you information about our products and services. | So we can let you know about new AI solutions and services that we offer that you might be interested in. | Consent (for direct marketing to individuals). Legitimate interests: necessary to promote our business where permitted for B2B contacts under applicable law. |
| Send you surveys and respond to feedback and correspondence. | To understand how we are performing, gather views, and improve our services and your experience. | Legitimate interests: necessary to ensure we are providing the best service and to identify areas for improvement. |
| Create and manage the accounts and access credentials needed for any system or environment we operate for a Client, and authenticate the people who use it. | To control and record who has access to a Client's systems and data. | Performance of a contract. Legitimate interests: necessary for the provision of our services and for their security. |
| Onboard Clients and gather information about their business workflows, systems and integration requirements. | To design, build and deploy bespoke automation solutions that integrate with the Client's existing tools and workflows. | Performance of a contract. Legitimate interests: necessary to deliver effective and tailored solutions. |
| Provide support and respond to enquiries, including by accessing a system we operate for a Client where necessary to investigate a problem. | To resolve issues, assist with your requests and maintain service quality. | Legitimate interests: to maintain Client satisfaction and operational efficiency. Performance of a contract where support is part of contracted services. |
6.4 Billing and financial information
| What do we do? | Why do we do it? | What is the legal basis? |
|---|---|---|
| Take and process payments for the Services through our payment provider and our payment collection agent. | To facilitate payment for the Services we perform for you and to issue any refunds or corrections where necessary. | Performance of a contract with you. Legitimate interests: necessary to ensure that S4W is compensated for its services. |
| Record the time our personnel spend and the work performed on an engagement, and invoice the Fees set out in the SOW. | To calculate correctly what is owed under the SOW. | Performance of a contract with you. |
| Keep a record of our transactions with you. | For accounting, audit and financial reporting purposes. | Legal obligation. |
| Investigate and correct billing errors, including over-charges. | So that you are charged the correct amount and any error is put right. | Performance of a contract with you. Legitimate interests: necessary to run a fair and accurate billing process. |
| Analyse transaction data to improve our pricing and services. | To understand how our engagements are priced and delivered and to improve our commercial offering and service design. | Legitimate interests: necessary to improve our services and develop new ones. |
6.5 Website and service administration data
| What do we do? | Why do we do it? | What is the legal basis? |
|---|---|---|
| Identify you when you visit our website. | To provide you with the best possible user experience and to maintain site security. | Legitimate interests: necessary to provide the best user experience and protect our systems. |
| Monitor visitors to our website and analyse their use of it, and perform tests on our IT systems. | To protect our website and IT systems from fraud or cyberattacks, and to improve our website and services. | Legitimate interests: necessary to ensure our systems are secure and to protect against IT security incidents. Legal obligation where applicable. |
| Administer and protect our business and our website, including troubleshooting, data analysis, testing, system maintenance and hosting of data. | For running our business, provision of administration and IT services, network security, to prevent fraud and in the context of a business reorganisation or group restructuring exercise. | Legitimate interests: necessary to run our business and to provide effective and secure administration and IT services. Legal obligation where applicable. |
| Use aggregated and statistical usage data to improve our website, services, marketing and client experience. | To understand how our services are used, to develop them, to grow our business and to inform our marketing strategy. | Legitimate interests: necessary to enhance our business strategies and improve client satisfaction. |
| Monitor and maintain the security and performance of the systems, integrations and workflow infrastructure on which the Services run. | To keep the Services stable and to prevent unauthorised access or misuse. | Legitimate interests: necessary to protect our Clients and the individuals whose data they entrust to us. Legal obligation where applicable. |
6.6 Client data (where we act as processor)
The table below describes what we do with the Client Materials and with the records a Deliverable processes. For all of these activities we act as processor on the Client's documented instructions. The Client is the controller and is responsible for identifying its own legal basis, for giving privacy information to the individuals concerned, and for any notice or consent required before a message is sent or a conversation takes place.
| What do we do? | Why do we do it? | What is our role and the legal basis? |
|---|---|---|
| Connect the Client's systems together and move records between them as the Client has instructed. | To deliver the Services the Client has commissioned. | Processor, on the Client's instructions. The Client determines the legal basis. |
| Read, create, update and delete records in the systems the Client nominates (see clause 7.4), and hold the credentials needed to do so. | Because the automation cannot operate on the Client's data without them. | Processor, on the Client's instructions. |
| Generate documents, quotations, messages and other content from the Client's records, including by sending that content to a third-party AI provider (see clause 11.3). | To produce the output the Deliverable is built to produce. | Processor, on the Client's instructions. |
| Extract, summarise and classify information from the Client's records, messages and documents. | To give the Deliverable the information it needs to decide what to do next, and to give the Client a usable record. | Processor, on the Client's instructions. |
| Send messages, and where an engagement provides for it conduct voice or chat conversations, on the Client's behalf. | To deliver the Services the Client has commissioned. | Processor, on the Client's instructions. The Client is responsible for consent, sender identification and honouring opt-out requests. |
| Operate a client-facing or consumer-facing web page as part of an engagement, and store the information submitted through it. | Because the Client has commissioned that page as part of the automation. | Processor, on the Client's instructions. The Client named on the page is the controller — see clause 7.6. |
| Transmit Personal Data to third-party systems, webhooks or endpoints that the Client has nominated or configured. | Because the Client has instructed us to send its data to a destination it has chosen. | Processor, on the Client's instructions. The Client is responsible for the destination and for that recipient's handling of the data — see clause 11.6. |
| Retain the record of an automation's execution — the events it processed, the actions it took and the payloads involved. | So that the automation can be monitored, supported and audited, and so that what it did can be reconstructed. | Processor, on the Client's instructions — see section 14. |
Our own limited uses of that data are set out in clause 6.7.
6.7 Our own limited use of Client data
The table below states our role for each activity. Where we act as processor, we do so pursuant to the documented instructions recorded in our DPA and its security provisions. Where we act as controller, it is because we determine the purpose ourselves or because the law requires the processing of us directly.
| What do we do? | Why do we do it? | What is our role and the legal basis? |
|---|---|---|
| Measure the volume of work an engagement generates, including the number of records and events an automation processes. | To invoice the Client accurately and to size and support the engagement. | Controller. Performance of a contract with the Client. Legal obligation (accounting records). |
| Investigate and respond to security incidents affecting the systems we operate, including reviewing specific records where necessary. | To protect our Clients and the people whose data they entrust to us. | Processor, pursuant to the security provisions of our DPA. The Client remains the controller and determines the legal basis. |
| Investigate suspected fraud, abuse or breach of our General Terms of Business by a Client, including reviewing specific records where necessary. | To protect our other Clients and ourselves, and to enforce our contract. | Controller. Legitimate interests: protecting our other Clients and ourselves, and enforcing our contract. |
| Produce aggregated and statistical measures of the performance and reliability of the Services. | To monitor and improve the accuracy and reliability of what we build. | Processor, pursuant to the documented instruction in our DPA. We only use such measures where the underlying data has first been irreversibly anonymised in accordance with the anonymisation provisions of our DPA. |
| Respond to a lawful request from a court, regulator or law enforcement body. | Because we are required to. | Controller. Legal obligation. |
6.8 Marketing and communications information
| What do we do? | Why do we do it? | What is the legal basis? |
|---|---|---|
| Keep a record of your communication preferences, including your opt-ins and opt-outs. | So we can make sure that you only receive the communications from us that you would like to receive and so we can update our records if you change your mind. | Consent. Legitimate interests: necessary to promote our business where permitted for B2B contacts under applicable law. Legal obligation where required to evidence consent. |
| Send you marketing communications about S4W's own products and services. | To keep you informed of new offerings and developments that may be relevant to your business. | Consent (for direct marketing to individuals). Legitimate interests: necessary to promote our business where permitted for B2B contacts under applicable law. |
6.9 All Personal Data
| What do we do? | Why do we do it? | What is the legal basis? |
|---|---|---|
| Transfer Personal Data in connection with any merger, sale, transfer of assets, investment, acquisition, bankruptcy or similar corporate transaction. | To ensure the continued service and function and to protect and grow our business. | Legitimate interests: to ensure we can protect and grow our business. |
| Comply with legal and regulatory obligations, including tax, accounting, sanctions screening and applicable data protection laws. | So we can meet our legal responsibilities under applicable law, including UK GDPR, EU GDPR where applicable, and the law of the United Arab Emirates. | Legal obligation. |
| Retain Personal Data to establish, exercise or defend legal claims. | So we can protect our interests and those of our Clients. | Legitimate interests: to seek legal advice and protect ourselves, our Clients or others in legal proceedings. |
| Transfer Personal Data internationally, as described in section 12. | To enable us to operate our business and to use the specialist hosting, workflow and AI providers on which the Services depend. | Legitimate interests: necessary to operate our international business. Appropriate safeguards: the UK Addendum to the EU Standard Contractual Clauses, together with a transfer risk assessment where required. |
6.10 Other processing
In limited circumstances we may process any of the Personal Data we hold to the extent necessary to defend, establish and exercise legal claims or to comply with legal or regulatory obligations.
6.11 If you do not provide Personal Data
Where we need to collect Personal Data due to a legal or regulatory obligation, or for performance of a contract, and you do not provide that data when requested, we may not be able to perform the contract we have or are trying to enter into with you (for example, to perform the Services). We will notify you of this at the time.
7. OUR AUTOMATION SERVICES
7.1 We design, build and operate bespoke automation for business clients. This typically involves connecting a Client's existing systems together, moving records between them, generating documents and messages, and operating workflows that respond to events in the Client's business.
7.2 In the course of that work we process Personal Data about the Client's own customers and prospects. Depending on the engagement this may include: name, postal address and postcode, telephone number, email address, the content of messages and conversations, records of enquiries and their outcomes, quotation and order details including financial information, records of acceptance (including the typed name, IP address, browser user-agent and the wording the individual agreed to), and records held in the Client's own CRM or field-service system.
7.3 We act as processor for all of this data. The Client is the controller. We process it only on the Client's instructions and under a written data processing agreement. If you are a customer of one of our Clients and you wish to exercise your rights, please contact that business in the first instance; clause 15.3 also applies to you.
7.4 To deliver automation work we connect to, and transfer data into and out of, systems that the Client nominates. These commonly include Zoho, GoHighLevel, ServiceM8, InsTool, Google Sheets and Meta lead advertising. The same list is set out in our DPA, published at https://s4w.com/dpa, in the annex which records the systems a Client nominates, and the two lists are intended to be identical. We hold credentials for those systems on the Client's instruction, encrypted at rest.
7.5 Data processed in the course of automation work is held in a database dedicated to that work and separate from our other services. It is hosted in Ireland (see section 12).
7.6 Where we operate a client-facing or consumer-facing web page as part of an automation engagement (for example, an online quotation page), the Client whose business is named on that page is the controller for the information collected through it.
7.7 Payments collected on a Client's behalf. Where an automation includes an online payment or deposit step (for example, a deposit taken on a quotation page), the payment is taken through our payment provider's hosted checkout into a payment account held in the Client's own name. Card details are entered directly with that payment provider and are never received or stored by us. We hold only the transaction record — the amount, the status, the time and the provider's reference — linked to the enquiry or quotation it relates to. The Client whose business is named on the page is the controller for that payment, and we act as its processor.
8. AUTOMATED DECISION-MAKING AND ARTIFICIAL INTELLIGENCE
8.1 What our AI actually does. We want to be clear about the extent to which the Services are automated:
(a) once a Deliverable is deployed in a Client's business it operates automatically, on the events and on the schedule it is built to respond to, without a person reviewing each action it takes;
(b) documents, quotations, messages and replies produced by a Deliverable may be generated by a large language model rather than written by a person;
(c) information is extracted, summarised and classified from a Client's records, messages and documents by large language models, and those outputs are used to decide what the automation does next;
(d) where an engagement provides for voice or chat conversations, those conversations may be conducted end to end by an AI assistant. The assistant speaks or writes, asks questions, answers questions and decides what to say next, and a person is not involved unless the assistant transfers the conversation to one or the Client's configuration provides for it. Where a conversation is by voice, the audio is converted to text by an automated speech-to-text service and the assistant's replies are converted to speech by an automated text-to-speech service; and
(e) a classification or score produced for an enquiry or a conversation may determine, under rules configured by the Client, whether and when that person is contacted again by that Client.
8.2 AI output can be wrong. Documents, messages, extracted fields, summaries and classifications are generated automatically and are not verified by a person unless the Client chooses to review them.
8.3 Speaking to a person. If you are speaking or writing to an AI assistant and you would prefer to deal with a person, say so, and ask the assistant to transfer you or to arrange a call back. The business you are dealing with is responsible for providing a route to a human.
8.4 Article 22 position. We do not use Personal Data to make decisions that are based solely on automated processing which produce legal effects concerning you or similarly significantly affect you, within the meaning of applicable data protection laws. The automated classifications described in clause 8.1(e) determine whether a business follows up an enquiry or a conversation; they do not by themselves determine access to a product, a service, credit, employment or any other benefit, and any such decision is taken by the business concerned, not by us.
8.5 If we ever introduce automated decision-making, including profiling, that has legal or similarly significant effects, we will update this Privacy Notice and provide you with additional information about the logic involved, as well as the significance and envisaged consequences of such processing for you, and the rights you have in relation to it. Where a Client configures or deploys a Deliverable in a way that produces such effects, that Client is the controller and is responsible for the corresponding obligations.
9. HOW CAN YOU MANAGE YOUR MARKETING PREFERENCES?
9.1 Where you give us your details through a form on our website, we will tell you at the point of collection how we will use them and, where we need your consent to send you marketing, we will ask for it separately and clearly. Where the conditions for the "soft opt-in" are met, we may send you marketing about similar products and services on that basis, and every message will give you a way to stop.
9.2 You can opt out at any time by using the unsubscribe link in any marketing email, or by contacting us at hello@s4w.com.
9.3 We will always get your express consent before we share your Personal Data with any third party for their own direct marketing purposes.
9.4 Please note that if you opt out of receiving marketing communications, you will still receive service-related communications that are essential for administrative or customer service purposes, for example, updates to our terms with you, billing notices, and checking that your contact details are correct.
10. WHAT ABOUT COOKIES?
10.1 For information about the cookies and similar technologies we use and how to change your preferences, please see our Cookies Notice at https://s4w.com/cookie-policy.
10.2 So that you know what is actually in use today:
(a) our website uses Vercel Web Analytics, a privacy-focused, cookieless analytics service provided by Vercel Inc. (United States), to count page views and measure traffic. It does not set cookies and does not store identifiers on your device. You can decline it through the banner on our website;
(b) we do not use Google Analytics or Google Tag Manager;
(c) the contact page on our website embeds Google's appointment scheduling product so that you can book a meeting with us. That embed is served by Google, which will receive your IP address and the details you enter when you book; and
(d) a web page we operate as part of an automation engagement (for example, an online quotation page) may load web fonts from a third-party content delivery network, which discloses the visitor's IP address to the provider of that network. Where such a page writes anything to the visitor's device beyond what is strictly necessary to deliver it, obtaining any consent required under the Privacy and Electronic Communications Regulations, and displaying that business's own cookie and privacy information, is the responsibility of the Client named on the page.
11. WHO DO WE SHARE YOUR PERSONAL DATA WITH?
11.1 We share Personal Data with third parties who provide services to us or to our Clients. We require all third parties to respect the security of Personal Data and to treat it in accordance with the law. We instruct our service providers to process Personal Data only for specified purposes and in accordance with our instructions.
11.2 The categories of recipient we disclose Personal Data to are as follows:
(a) Infrastructure, hosting and database providers — who host our website, our databases and the systems on which the Services run, and run our background processing and queues.
(b) Identity and authentication providers — who authenticate access to the systems we operate and manage sign-in.
(c) Telephony and messaging providers — where an engagement provides for messages or conversations, the providers who carry those messages and calls.
(d) AI and language model providers — who run the language models that generate content, extractions, summaries and classifications and, where an engagement provides for voice conversations, orchestrate those conversations and convert speech to text and text to speech. See clause 11.3.
(e) Payment providers and our payment collection agent — see clause 11.4.
(f) Email, support and collaboration providers — who send our transactional and marketing email, hold our support tickets and host our internal collaboration.
(g) Workflow and event-processing providers — who run the durable workflow engine on which our automations execute. Event payloads processed by that engine can include the records and message content described in clause 7.2.
(h) Client-nominated business systems — the CRM, field-service, spreadsheet and advertising systems the Client nominates (see clause 7.4).
(i) Professional advisers, such as our tax advisers, legal advisers, auditors, insurers and accountants, where necessary for the establishment, exercise or defence of legal claims or to protect the rights or safety of our website, our services or us.
(j) Regulators, courts and law enforcement, where disclosure is required by law or in the context of an investigation, regulatory requirement, judicial proceeding, court order or legal process (including to law enforcement or competent authorities such as the police or HMRC).
(k) Parties to a corporate transaction, where information about our Clients, including Personal Data, may be disclosed as part of any merger, sale, transfer of our assets, investment, acquisition, bankruptcy, or similar event, including while engaging with our actual or potential investors.
(l) Error monitoring providers — who receive diagnostic information about errors in the systems we operate, which can include the IP address, request headers and identifier of the person who encountered the error. Record and message content is not intentionally sent to them; error diagnostics may nonetheless include fragments of request data.
(m) Analytics providers — who measure traffic to our website, as described in clause 10.2(a).
11.3 AI processing you should know about specifically. Because it is material, we state expressly that:
(a) the content a Deliverable processes — the records, messages and documents it reads, together with the prompts and responses exchanged with a model — is sent to third-party AI providers in order to generate, extract, summarise and classify. Where an automation is designed to use a model, there is no option to disable that;
(b) material a Client supplies for an assistant to draw its answers from, such as documents and web pages, is processed by a third-party AI provider for indexing and summarisation, where an engagement includes an assistant of that kind;
(c) where an engagement provides for voice conversations, the audio, and the transcript made from it, are processed by third-party speech-to-text, text-to-speech, voice orchestration and language model providers; and
(d) the AI providers engaged for a given engagement are identified, with their role and country, in the sub-processor annex to our DPA (see clause 11.5).
11.4 Payments. Where a Client pays by card, card details are entered directly with our payment provider and are never received or stored by us; we hold only the card brand, the last four digits, the expiry date and a payment-method reference issued by that provider. Our payment provider also receives your company name, email address, billing address and any tax or VAT identification number you give us. Fees are collected by Dial Square Consultancy Ltd as our payment collection agent and merchant of record (see clause 2.3), and Dial Square Consultancy Ltd is the name that appears on the invoice and on your statement.
11.5 Our full list of sub-processors. A complete, dated list of the sub-processors we engage, showing each one's role and country, is published as an annex to our DPA at https://s4w.com/dpa. We will notify the Client's nominated contact by email at least 30 days before a new sub-processor begins processing, and the Client may object within 15 days, as set out in the sub-processor provisions of the DPA.
11.6 Systems and integrations our Client chooses. Where a Client nominates a system, or configures an integration, a webhook or an outbound connection, we transmit Personal Data to the destination that Client has chosen. Those destinations are not our sub-processors: they are onward transfers directed by the controller. We do not control those recipients and the Client is responsible for them and for their handling of the data. We do not vet the destination itself.
11.7 We may provide anonymous or aggregated information to analytics providers to help us improve and optimise our services. We will only share this information in a form that does not directly or indirectly identify you.
12. WHAT HAPPENS IF WE SHARE YOUR PERSONAL DATA WITH ORGANISATIONS OUTSIDE OF THE UK (AND/OR EEA)?
12.1 Where your data is stored. The database and file storage for our automation work — including the Client Materials, the records a Deliverable processes and the records of its execution — are hosted in the European Economic Area (Ireland), in the Dublin region (eu-west-1) of Amazon Web Services, and are operated on that infrastructure by our database provider. Personal Data is also processed by the providers identified in the sub-processor annex to our DPA, some of which are outside the UK and the EEA — see clause 12.2.
12.2 Transfers that do take place. Notwithstanding clause 12.1, some processing necessarily takes place outside the UK and the EEA:
(a) the content a Deliverable processes — records, messages, documents and the prompts and responses exchanged with AI models — is processed by AI providers that are headquartered in, and process data in, the United States. This includes our language model providers, any speech-to-text, text-to-speech and voice orchestration provider engaged for a voice conversation, and the workflow engine that carries event payloads containing this content;
(b) support, collaboration, email and analytics providers may process contact details, correspondence and usage data outside the UK and the EEA;
(c) S4W is established in the United Arab Emirates, and our authorised personnel there may access Personal Data in order to operate, support and secure our services. The United Arab Emirates is not the subject of a UK adequacy decision;
(d) application hosting — our web application, our application programming interface and worker services are operated by providers established in the United States, and Personal Data is processed by them in the course of delivering the Services; and
(e) conversation records — where an engagement provides for voice or chat conversations, the audio, transcripts and conversation metadata may also be held by the voice or messaging provider concerned in the United States.
12.3 How we protect transfers. Where we transfer Personal Data outside of the UK and/or the European Economic Area (EEA), we will ensure that an adequate level of protection is afforded to it by implementing one of the following safeguards:
(a) the country has been deemed to provide an adequate level of protection for Personal Data by the UK and/or European Commission; or
(b) we use the UK Addendum to the EU Standard Contractual Clauses, issued by the Information Commissioner and approved for use in the UK, which gives Personal Data equivalent protection.
12.4 Where we rely on clause 12.3(b), we carry out a transfer risk assessment and apply supplementary measures where the assessment shows they are needed.
12.5 For more information about these safeguards, or to request a copy of the relevant transfer mechanism, please contact us at hello@s4w.com.
13. HOW DO WE PROTECT YOUR PERSONAL DATA?
13.1 We are committed to protecting individuals' Personal Data. We put in place appropriate technical and organisational measures to help protect the security of your Personal Data. However, you should be aware that no system is ever completely secure.
13.2 The measures we currently apply include:
(a) encryption in transit — data moving between you, our services and our providers is protected using industry-standard transport encryption;
(b) encryption at rest — our databases and file storage are encrypted at rest by our infrastructure providers;
(c) access controls — access to production systems is limited to personnel who need it for their role, and is granted through named accounts;
(d) separation — data processed in the course of automation work is held in a database dedicated to that work and separate from our other services, and access within it is scoped to the Client the data belongs to;
(e) encryption of stored secrets — credentials, API keys and integration secrets are encrypted at rest, and API keys are stored as one-way hashes rather than in plain text;
(f) input validation — requests to our services are validated against defined schemas before they are processed; and
(g) least privilege for Client systems — we hold only the credentials and permissions an automation needs in order to do what the Client has instructed, and we revoke them when the engagement ends.
13.3 What we do not claim. We do not currently hold ISO 27001, SOC 2 or equivalent certification, and we do not currently operate penetration testing, automated vulnerability scanning, multi-factor authentication, record-level access logging or automated anomaly detection. We will update this section as those measures are introduced.
13.4 Staff access to Client systems and data. A limited number of authorised S4W personnel are able to access the systems we operate for a Client and the data in them, including message content and the records an automation has processed, for support, troubleshooting and security purposes. Direct reads of individual records by authorised personnel are not individually logged.
13.5 We have procedures to deal with any suspected personal data breach. Where we act as processor, we will notify the Client concerned without undue delay after becoming aware of a personal data breach, and in any event in sufficient time to allow the Client to meet its own obligations under Article 33 of the UK GDPR. Where we act as controller, we will notify the Information Commissioner's Office and, where required, affected individuals, in accordance with our legal obligations.
14. HOW LONG DO WE KEEP YOUR PERSONAL DATA FOR?
14.1 We will only retain your Personal Data for as long as reasonably necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, regulatory, tax, accounting or reporting requirements. We may retain your Personal Data for a longer period in the event of a complaint or if we reasonably believe there is a prospect of litigation in respect of our relationship with you.
14.2 The periods we apply are set out below.
| Category of data | How long we keep it |
|---|---|
| Client contact and relationship data | For the duration of the engagement and for two years afterwards, under our own controller retention policy. Deleted within 60 days of a written deletion request, save to the extent we are required to keep it by law. |
| Billing, payment and transaction records | Six years from the end of the financial year to which they relate, to meet accounting and tax requirements. Card details are not held by us; we hold only card brand, last four digits, expiry date and a payment-method reference from our payment provider. |
| Client Materials | For the duration of the Agreement. Deleted 60 days after it expires or is terminated, in accordance with clause 13.5(e) of our General Terms of Business and the deletion provisions of our DPA, save to the extent retention is required by law. |
| Records a Deliverable has processed, and the record of its execution (the events processed, the actions taken and the payloads involved) | As for the Client Materials above. Where the Client instructs a shorter period for a particular automation, that period applies. |
| Information collected through a web page we operate for a Client | As for the Client Materials above. |
| Credentials for a Client's nominated systems | For the duration of the Agreement. Revoked and deleted when it expires or is terminated, or earlier on the Client's instruction. |
| Support tickets and correspondence | For the duration of the engagement and for two years afterwards, after which they are deleted under the manual deletion process described in clause 14.3. |
| Marketing contacts and preferences | Until you opt out or withdraw consent, after which we keep the minimum record necessary (your contact identifier and the fact that you opted out) so that we do not contact you again. |
| Website and server logs held by our hosting providers | For the period applied by the hosting provider concerned, which is typically no more than 30 days. |
14.3 How deletion happens. We do not currently operate an automated deletion or purge process. Deletion is carried out manually, on written request, under a documented internal process. We aim to complete a deletion request within 60 days of receiving it and of confirming the identity and authority of the person making it, in line with the deletion provisions of our DPA. That is a different commitment from the one-month time limit for responding to a data subject's rights request under clause 15.6, which is a statutory response period and applies to requests made to us as controller. Deleting a record in one system does not by itself delete the copies of it which an automation has written to another; a request to delete those copies should identify the systems it covers.
14.4 Where we hold data as processor, we act on the instructions of the Client who is the controller. Retention periods that a Client sets for its own engagement, and requests to delete data before the periods above, are matters for that Client to instruct us on.
14.5 Some of our providers keep their own copies of data for their own retention periods, and backups are overwritten on a rolling cycle. Personal Data may persist in our encrypted backups for up to 7 days after it has been deleted from the live system, after which those backups are overwritten. Backups are not used for any processing purpose.
15. WHAT ARE YOUR RIGHTS IN RELATION TO THE PERSONAL DATA WE HOLD?
15.1 You have a number of rights under data protection laws in relation to your Personal Data. You have the right to:
(a) Request access to your Personal Data (commonly known as a "subject access request"). This enables you to receive a copy of the Personal Data we hold about you and to check that we are lawfully processing it.
(b) Request correction of the Personal Data that we hold about you. This enables you to have any incomplete or inaccurate data we hold about you corrected, though we may need to verify the accuracy of the new data you provide to us.
(c) Request erasure of your Personal Data in certain circumstances. This enables you to ask us to delete or remove Personal Data where there is no good reason for us continuing to process it. You also have the right to ask us to delete or remove your Personal Data where you have successfully exercised your right to object to processing (see below), where we may have processed your information unlawfully or where we are required to erase your Personal Data to comply with local law. Note, however, that we may not always be able to comply with your request for erasure for specific legal reasons which will be notified to you, if applicable, at the time of your request.
(d) Object to processing of your Personal Data where we are relying on a legitimate interest (or those of a third party) as the legal basis for that particular use of your data (including carrying out profiling based on our legitimate interests). In some cases, we may demonstrate that we have compelling legitimate grounds to process your information which override your right to object.
(e) You also have the absolute right to object at any time to the processing of your Personal Data for direct marketing purposes.
(f) Request the transfer of your Personal Data to you or to a third party. We will provide to you, or a third party you have chosen, your Personal Data in a structured, commonly used, machine-readable format. Note that this right only applies to automated information which you initially provided consent for us to use or where we used the information to perform a contract with you.
(g) Withdraw consent at any time where we are relying on consent to process your Personal Data. However, this will not affect the lawfulness of any processing carried out before you withdraw your consent. If you withdraw your consent, we may not be able to provide certain products or services to you. We will advise you if this is the case at the time you withdraw your consent.
(h) Request restriction of processing of your Personal Data. This enables you to ask us to suspend the processing of your Personal Data in one of the following scenarios:
- if you want us to establish the data's accuracy;
- where our use of the data is unlawful but you do not want us to erase it;
- where you need us to hold the data even if we no longer require it as you need it to establish, exercise or defend legal claims; or
- you have objected to our use of your data but we need to verify whether we have overriding legitimate grounds to use it.
15.2 If you wish to exercise any of the rights set out above, please contact us at hello@s4w.com.
15.3 If your data is held by us on behalf of one of our Clients. Where we hold Personal Data as a processor (see section 3), we are not permitted to act on a request about that data without the controller's instruction. Please send your request to the business you dealt with, or whose name appears on the page or the message you received. If you send it to us, we will tell you so, help you identify the right business where we can, and pass your request to that business so that it can instruct us. We will then assist that business to respond to you. We are not permitted to disclose, amend or delete data held on a Client's behalf without that Client's instruction, except where the law requires us to act.
15.4 You will not have to pay a fee to access your Personal Data (or to exercise any of the other rights). However, we may charge a reasonable fee if your request is clearly unfounded, repetitive or excessive. Alternatively, we could refuse to comply with your request in these circumstances.
15.5 What we may need from you
We may need to request specific information from you to help us confirm your identity and ensure your right to access your Personal Data (or to exercise any of your other rights). This is a security measure to ensure that Personal Data is not disclosed to any person who has no right to receive it. We may also contact you to ask you for further information in relation to your request to speed up our response.
15.6 Time limit to respond
We try to respond to all legitimate requests within one month. Occasionally it could take us longer than a month if your request is particularly complex or you have made a number of requests. In this case, we will notify you and keep you updated.
This one-month period is the statutory period for responding to a request to exercise the rights set out in clause 15.1. It is a different thing from the 60-day period within which we aim to complete the deletion of data under clause 14.3, which is the operational period for carrying out a deletion once it has been agreed or instructed.
16. CONTACT US IF YOU HAVE A QUESTION OR A COMPLAINT
16.1 If you have a question or a complaint about how we handle your Personal Data, please contact us at hello@s4w.com, or write to us at the address in clause 2.1. You may also contact our UK representative (clause 2.4).
16.2 You have the right to make a complaint at any time to the relevant data protection regulator. In the UK this is the Information Commissioner's Office (ICO), www.ico.org.uk. If you are in the European Economic Area, you may complain to the supervisory authority in the country where you live or work, or where you believe the issue arose.
16.3 We would, however, appreciate the chance to deal with your concerns before you approach any regulator, so in the first instance please contact us at hello@s4w.com.
17. UPDATES TO THIS PRIVACY NOTICE
17.1 This is Version 1.0 of this Privacy Notice. It does not supersede a previous version of this notice.
17.2 We may update this Privacy Notice from time to time and we keep it under regular review. Each version carries a version number, an effective date and the date it was last updated.
17.3 Where we make a material change, we will notify each Client by email to the contact it has nominated, and by a notice on our website, before the change takes effect. Continuing to use our services after the effective date of a change means the updated Privacy Notice applies to you.
17.4 Superseded versions are archived and are available on request from hello@s4w.com.
18. THIRD-PARTY LINKS
18.1 Our website may include links to third-party websites, plug-ins and applications. Clicking on those links or enabling those connections may allow third parties to collect or share data about you. We do not control these third-party websites and are not responsible for their privacy statements. When you leave our website, we encourage you to read the privacy notice of every website you visit.