Privacy Policy

This policy explains what personal data Bit Robotics Ltd (company number 11680576, registered office 13 Freeland Park Wareham Road, Lytchett House, Poole, Dorset, England, BH16 6FA, United Kingdom), trading as Recalld, collects, why, and what rights you have over it. Bit Robotics Ltd is registered with the UK Information Commissioner's Office under reference ZC241638. For anything privacy-related, contact support@recalld.ai.

Our representative in the European Union under Article 27 of the EU GDPR is SKILL SOFTWARE SRL, Str. Sold. Er. Arhip Nicolae 12, Bl. 66, Sc. A, Et. 9, Ap. 39, Ploiești, Prahova, Romania, eu-representative@bitrobotics.co.uk. If you are in the EU, you and your supervisory authority may contact the representative on any matter concerning our processing of your data.

1. Two roles: controller and processor

We handle personal data in two distinct ways:

2. What we collect as controller

Who handles this data for us: OVHcloud (servers), Google Cloud (backups), Cloudflare (marketing website hosting and visit statistics), Stripe (payments), Resend (sends our emails to you, United States), Google (sign-in with Google, and Google Workspace for our own email and records) and Intuit QuickBooks (accounting). Each acts under a data processing agreement with us; US providers are covered by the transfer safeguards in section 7.

3. Why we process it (legal bases)

We do not sell personal data and we do not use it for advertising.

4. Retention and deletion

5. Your rights

Under UK and EU data protection law you can:

6. Memory content (where we are the processor)

7. International transfers

Our EU region infrastructure is hosted in the European Union and our US region infrastructure in the United States. As a UK company we access EU region data from the United Kingdom, which the European Commission has recognised as providing adequate protection. Some model providers process data in the United States or other countries outside the UK/EEA, and US region data is held in the United States by design. Where personal data of UK or EEA residents is transferred outside the UK/EEA, transfers are protected by the providers' data processing terms incorporating the EU Standard Contractual Clauses with the UK Addendum, or, where the provider is certified, the EU-US Data Privacy Framework and its UK Extension. Details per provider are on the sub-processor page.

8. Cookies

The dashboard uses strictly necessary cookies to keep you signed in. The marketing site sets no analytics or tracking cookies, which is why there is no cookie banner. Fonts and our own scripts are served from our own domain. The one outside script is Cloudflare Web Analytics (section 2): it loads from Cloudflare, the company that already hosts this site, and reports to our own domain.

9. Security

Data is encrypted in transit (TLS) and backups are encrypted at rest. Live servers sit in access-controlled datacentres. Access to production systems is limited to authorised personnel, all customer data access is scoped to your account at the database layer, and BYOK provider keys are stored encrypted and never exposed back through the API. If a breach affects your personal data we will notify you and the relevant authority as required by law, within 72 hours of becoming aware where the law requires it.

10. Changes to this policy

We will post any changes on this page and, for material changes, notify account holders by email or through the dashboard before they take effect.