Privacy Policy

How SONTI LTD collects, uses, shares and protects personal data on the Knotie-AI Pro platform — including prompts, uploads and generated media.

Effective date: 14 September 2026 · Privacy v2.1

1. Introduction

Knotie-AI Pro is operated by SONTI LTD, a company registered in England and Wales ("we", "us", "our"). This Privacy Policy explains what personal data we collect, how we use it, who we share it with, and the rights you have — under the UK GDPR, the EU GDPR and the Data Protection Act 2018.

Our platform lets partners (agencies and resellers) build, brand and resell AI products and services to their own customers: voice and chat AI agents, workflow automations, an AI API and MCP gateway, CRM, websites, hosted servers with one-click app deployments, and a generative media studio for creating images, video and audio.

The Service is built on top of one or more third-party AI model providers and cloud infrastructure providers. We describe those providers by category in this policy rather than by name. A list of our subprocessors is available on request and will be published; write to [email protected] to ask for the current list.

By accessing or using the platform you agree to this Privacy Policy. If you do not agree with any part of it, please do not use the Service.

2. Our Role: Controller and Processor

Which role we play depends on whose data it is.

  • We are the controller of the personal data of partners and of customers we serve directly — account details, contact details, billing data, authentication data, platform usage and support correspondence.
  • We are a processor of the personal data that a partner’s customers and end users put into the Service — CRM contacts, call recipients, chat participants, uploaded media, prompts and generated outputs. The partner is the controller of that data and we process it on the partner’s documented instructions in order to provide the Service.
  • Our providers are processors and subprocessors — with one honest exception. Where we pass data to an AI model provider, a hosting provider or another supplier so that a feature can work, that supplier acts as our processor or subprocessor under written terms, handling your content on our instructions for generation, hosting and delivery. The exception is that some providers retain limited inputs and outputs for their own abuse-detection, safety and legal-compliance purposes, under their own terms; for that limited purpose they act as independent controllers rather than on our instructions. The subprocessor list we make available on request and will publish identifies which providers do this.
  • Partners are responsible for establishing their own lawful basis, providing privacy notices to their customers and end users, and obtaining any consents required — including consent for recording calls and for the use of a person’s likeness or voice.

3. Information We Collect

We collect the following categories of information:

3.1 Account Information

  • Partner (agency) details: name, email, business details, billing information
  • Customer details: name, email, business details, assigned products and agents
  • Authentication data, including passwords (hashed), passkey credentials and multi-factor settings
  • Credentials for third-party and BYOA services, server root/SSH access and CRM connection tokens — stored encrypted

3.2 Service and Interaction Data

  • Voice recordings and transcriptions from interactions with voice AI agents
  • Chat messages and conversation data from chat agents and automations
  • CRM data and contact records processed on behalf of partners
  • Agent, automation and workflow configuration data
  • Generative media inputs: prompts, uploaded or referenced images, video, audio and documents, character and persona training material, and the settings chosen for each generation
  • Generative media outputs: the images, video, audio, character models, storyboards and films produced, and their moderation status
  • Gateway and MCP request and response metadata (token counts, tool calls, timestamps, model or capability used)
  • Provisioning and operational metadata for servers and deployed applications
  • Call and message metadata (duration, timestamps, status)
  • The billing and audit trail for every generation and every call: what was requested, which capability served it, what it cost, and what happened to it

3.3 Analytics and Usage Data

  • Performance metrics for AI agents and generations
  • Conversation analytics (sentiment, topics, key moments) where the partner enables them
  • Platform usage statistics and feature utilisation

3.4 Technical Information

  • Device information (type, operating system, browser)
  • IP address and approximate location derived from it
  • Log data, error reports and security events
  • Cookies and similar technologies (section 12)

4. How We Use Your Information, and Our Lawful Bases

4.1 Purposes

  • To provide, operate and maintain the platform and the products you enable
  • To run generations and agent workflows you request, and to keep your media library working
  • To provision, operate and secure infrastructure, integrations and deployed applications
  • To meter usage, take payment, prevent billing errors and answer billing queries
  • To moderate content and prevent abuse, fraud and misuse of the Service and of our providers
  • To provide support and respond to your requests
  • To send service, security and administrative messages, and marketing where you have consented
  • To analyse usage in aggregate, improve service quality and develop new features
  • To comply with legal, tax and regulatory obligations, and to establish, exercise or defend legal claims

4.2 Lawful Bases

  • Contract — providing the Service you have signed up for, taking payment, and supporting you
  • Legitimate interests — securing the platform, preventing abuse and fraud, keeping accurate billing and audit records, improving the Service, and direct marketing to business contacts (we balance these against your rights, and you can object)
  • Legal obligation — accounting and tax records, responding to lawful requests, and reporting illegal content
  • Consent — optional cookies, marketing emails where consent is required, and any processing we specifically ask you to agree to. You can withdraw consent at any time
  • Where we act as a processor for a partner, the lawful basis for the underlying processing is the partner’s responsibility, and we act on their instructions

5. AI-Specific Disclosures

Because the Service is built on AI, some things deserve to be said plainly rather than buried.

  • We do not train on your content. We do not use your inputs, prompts, references or outputs to train, fine-tune or improve general-purpose AI models, for our benefit or anyone else’s, and we do not sell or licence them for that purpose. We contract with our providers on terms intended to achieve the same result.
  • One exception: training you ask for. Where you deliberately submit your own images or material to train a character, persona or style model, we train that model on exactly that material. The model is private to your account and used only on your instructions. You must hold the rights and consents for that material.
  • Where your content goes. Prompts, uploads and outputs are transmitted to the AI model provider selected to serve that request, and to the storage and infrastructure providers that hold and deliver them. They act on our instructions for generation, hosting and delivery, except that some providers retain limited inputs and outputs for their own abuse-detection, safety and legal-compliance purposes under their own terms, acting as independent controllers for that limited purpose. The subprocessor list identifies which ones.
  • Provider routing. For any given request we may route the work to whichever provider offers the best available combination of price, quality and availability at that time. Providers change their availability, pricing and content policies, and we may substitute one for another.
  • Content moderation. Automated moderation runs on inputs and outputs. Content may be refused, blocked or removed where it breaches our terms, a provider policy or the law.
  • Human review is the exception. Our staff do not routinely read your prompts, look at your media or listen to your recordings. A person reviews content only where you ask us to (for example, a support request you raise), where an automated system flags a suspected serious breach or security incident, or where the law requires it. Access is restricted, logged and limited to what is necessary.
  • Programmatic submission. Content can reach the Service through the interface or programmatically, through our API, MCP tools, the in-portal director agent or your own agents. Where the interface asks you to confirm you hold the necessary rights and consents, we record that confirmation. Where content arrives programmatically there may be no on-screen step — use of those surfaces is itself the account holder’s confirmation, and the account holder remains the owner of, and accountable for, all inputs and outputs on the account.
  • We keep prompts and outputs. See section 9 for what we retain and for how long, and why.
  • Outputs are not guaranteed. AI output may be inaccurate or unsuitable. You review it before you use it.

6. Data Sharing and Disclosure

We do not sell your personal data. We share it only as follows:

6.1 Partner and Customer Relationship

  • Partners can see their own customers’ product, agent and infrastructure configuration, usage and analytics
  • Customer data is segregated and accessible only to the partner that manages that customer
  • Partners are responsible for obtaining the consents and giving the notices their customers require

6.2 Providers and Subprocessors

To deliver the Service we share data with the following categories of provider. We do not name individual vendors in this policy; the current list of subprocessors is available on request and will be published.

  • AI model providers — language, speech, image, video and audio generation
  • Cloud, hosting, server and storage providers
  • CRM platforms and workflow automation tooling
  • Payment processors
  • Email delivery and telephony providers
  • Analytics, logging, monitoring and observability providers
  • Customer support tooling

7. Your Keys and Credentials

We store API keys, provider credentials, server access details and connection tokens in encrypted form and never share them with unauthorised parties. For BYOA products you connect your own provider accounts, and data processed through them is governed by that provider’s terms as well as this policy. Each provider has its own privacy policy, and we recommend reviewing the policies of any provider you connect.

8. Data Security

We implement appropriate technical and organisational measures to protect your data:

  • Data is encrypted in transit using TLS
  • Sensitive data — including recordings, chat data, media, API keys and server credentials — is encrypted at rest
  • Access to production data is restricted to authorised personnel and is logged
  • We carry out security reviews and maintain incident response procedures
  • Tenant data is segregated so that one partner cannot reach another partner’s data

8.1 No System Is Perfectly Secure

While we work hard to protect your information, no method of transmission or storage is completely secure. You are responsible for the security of your own credentials, devices and deployed applications. If we become aware of a personal data breach affecting you, we will notify you and the relevant supervisory authority as required by law.

9. Data Retention

We keep data for as long as we need it for the purposes set out in this policy, and no longer, except where the law requires otherwise.

  • Account information — for as long as the account is active, and up to 12 months after it closes. Where a partner asks us to delete their account, sections 9.2 and 9.3 apply instead and the account is anonymised 30 days after we approve the request
  • Uploads and generated media — while the account is active, then deleted within 90 days of account closure, or within 90 days of a verified deletion request. Generated media that is not pinned or saved may expire sooner, according to the retention period published in the product
  • Records of prompts, references, settings and outputs, and the billing and audit trail for each generation — retained for up to 12 months after closure, longer only where the law requires it or a legal hold applies, and then deleted or anonymised
  • Backups holding that data — purged within 90 days after the period above ends
  • Aggregate usage and billing records visible to a partner — kept for the statutory accounting periods that apply to them
  • Voice recordings, transcriptions and chat data — according to your retention settings, typically 30 to 90 days by default, and in every case removed or replaced with placeholders when a partner account is anonymised under sections 9.2 and 9.3
  • CRM and contact data — per the partner’s configuration, for as long as needed to provide the Service
  • Server and deployed-application data — until the instance is deprovisioned or the account is terminated
  • Analytics data — up to 12 months in identifiable form, and in aggregated form after that
  • Technical and security logs — typically 30 to 90 days

9.1 Deletion

You may ask us to delete specific content or your account data at any time. The schedule above applies from the date we verify the request: uploads and generated media go within 90 days, the underlying records and billing trail within 12 months, and the backups holding them within 90 days after that. Deletion is subject to any legal hold and to the billing and audit records we are required to keep. Where deletion is not possible we anonymise the data instead.

9.2 Deleting a Partner Account

A partner can ask us to delete their whole account from Partner Settings → Danger zone, using the “Request account deletion” action. You confirm the request in the product, we show you a reference id beginning “GDPR-” and email you a copy of it, and a member of our team reviews the request. We may decline a request — for example while there is an unpaid balance on the account or an open legal dispute — and if we do, we tell you why.

Once we approve the request, your account enters a 30-day period before anonymisation. We email you the date it will happen on, and send one reminder seven days before it. Your access carries on as normal during those 30 days, so that you can:

  • Download all of your data — the “Download my data” action produces a single JSON file covering your account and profile, your team, your customers and their onboarding records, your agents and phone numbers, your campaigns, prospects and call records, your knowledge bases, your invoices, receipts and credit history, your email and audit logs, and your analytics. Passwords, API keys and other credentials are never included in it
  • Withdraw the request — at any time before anonymisation starts, which puts the account back to normal

9.3 What Anonymisation Does, and What Survives It

When the 30 days are up we anonymise your data across our systems rather than dropping records we are required to keep. Your profile, contact details, login credentials, branding, domains and stored third-party credentials; your customers’ names, email addresses, phone numbers and portal logins; your prospects and campaign contacts; your call records, transcripts, recording references and call analysis; the rows held in our analytics warehouse; and your uploaded documents, media and website assets are removed or replaced with placeholders.

Records we have to keep for legal and financial reasons are retained for the statutory period, with personal identifiers removed where the law allows: invoices and receipts, payment records, credit and telephony ledgers, audit and consent records, and telecoms regulatory records. Financial records are kept for six years, the statutory accounting retention period in the UK; the rest for as long as the law requiring them says.

Two other things happen at the same time. Any subscription still live on the account is cancelled at anonymisation, so that an erased account is never charged again. And your email address is added permanently to our marketing suppression list — as soon as the request is approved — so that we never send marketing to it again, even if that address is later used to sign up. The suppression list holds a one-way hash of the address rather than the address itself.

Anonymisation cannot be reversed. Once it has run we cannot restore the account, its customers or its content, and the request can no longer be withdrawn — so please export anything you want to keep during the 30 days.

10. International Data Transfers

We and our providers operate internationally, and your content and personal data may be transferred to, stored in and processed in countries outside the United Kingdom and the European Economic Area — including where a generation is routed to a model provider hosted elsewhere.

Where we make such a transfer we put appropriate safeguards in place: an adequacy decision where one applies, or the UK International Data Transfer Agreement or Addendum, or the EU Standard Contractual Clauses, plus any additional measures the transfer requires. You can ask us for details of the safeguards applying to a particular transfer.

11. Your Rights and Choices

Depending on where you live, you have some or all of the following rights over your personal data:

  • Access — obtain a copy of the personal data we hold about you
  • Rectification — correct inaccurate or incomplete information
  • Erasure — ask us to delete your personal data; partners can start this themselves from Partner Settings (see sections 9.2 and 9.3)
  • Restriction — ask us to limit how we process your data
  • Objection — object to processing based on our legitimate interests, and to direct marketing at any time
  • Portability — receive your data in a structured, commonly used, machine-readable format
  • Withdraw consent — where processing is based on consent, without affecting processing already carried out
  • Automated decisions — we do not make decisions producing legal or similarly significant effects about you by automated means alone

11.1 How to Exercise Them

Write to [email protected]. We will respond within one month, and may ask you to verify your identity first. There is no charge unless a request is manifestly unfounded or excessive.

If your data was put into the Service by a partner (that is, we act as processor), we will refer your request to that partner, who is the controller, and support them in answering it.

If you are unhappy with how we have handled your data you may complain to the UK Information Commissioner’s Office at ico.org.uk, or to your local supervisory authority. We would appreciate the chance to resolve it first.

11.2 Erasing a Whole Partner Account

Partners do not have to write to us to exercise the right to erasure over their account — it is built into the product. Partner Settings → Danger zone holds “Download my data” and “Request account deletion”. Sections 9.2 and 9.3 set out the whole process: the reference id, our review, the 30-day period in which you can download your data or withdraw the request, the anonymisation that follows, and the records we keep afterwards.

A customer of a partner exercises their rights with that partner, not with us: the partner is the controller of that data and we act as processor. When a partner’s account is anonymised, the personal data we hold for their customers is anonymised with it, subject to the same legal and financial retention exceptions.

The right to object to direct marketing is honoured permanently. An address added to our marketing suppression list stays on it, and signing up again later does not lift the suppression.

12. Cookies and Tracking

We use cookies and similar technologies:

  • Essential cookies — required for sign-in, security and the platform to function; these cannot be switched off
  • Analytical cookies — help us understand how the platform is used
  • Functional cookies — remember preferences and settings
  • Marketing cookies — used to measure and deliver relevant advertising, set only with consent

13. Children’s Privacy

The Service is not intended for anyone under 18, and we do not knowingly collect personal data from children. Accounts must be held by adults.

You must not upload or reference images, video or audio of a minor for likeness, persona or character-training features. If we learn that we hold personal data of a child, or media of a minor submitted for those features, we will delete it promptly and may suspend the account.

14. Changes to This Policy

We may update this Privacy Policy at any time — for example when we add features, change providers, or when the law changes.

We will tell you about material changes by email to the address on your account, or by an in-product notice, before they take effect. The updated policy applies from its effective date, which is shown at the top of this page.

**Where a change introduces processing that requires your consent under data protection law, we will ask you for that consent separately — we will not treat your continued use of the Service as consent.**

The current version is always available at the published URL. Previous versions are available on request.

15. Contact Information

This policy is issued by SONTI LTD, a company registered in England and Wales, operating Knotie-AI Pro.

For privacy questions, to exercise your rights, or to request our current subprocessor list, write to [email protected]. For general support, write to [email protected]. To report abuse or a rights infringement, write to [email protected].