Privacy, in plain terms.
We collect the minimum, we say what it is for, and you can opt out of any of it. Here is the whole thing — no fine-print maze.
Last updated · August 2026
Terms →Who we are
NPC Protocol is a design and AI-services studio. This policy covers this website and the services we run for you. Reach us at hello@npcprotocol.com. This site and these services are operated by NPC Protocol.
What we collect
Three things, and nothing we won't name. (1) What you give us — name, email, phone, business details, and whatever you type into a form or message. (2) Voice and call data — calls through our AI front-desk are transcribed, and we delete the raw audio rather than keep it. (3) AI lead qualification — for prospects, AI may score a lead on fit, budget, and timeline and pass the qualified ones into a CRM. We also keep basic server logs (address, time, page). We do not run tracking cookies or profiling analytics, and we never sell your data.
How we use it
To deliver what you asked for — build your site, run your front-desk, qualify your leads, or report on visibility — to answer you, and to keep the site and services secure. We don't use it for unrelated marketing to you without telling you first, and we don't sell it.
The AI front-desk
Our assistant is automated, not a person, and it says so to every caller. It tells each caller that it is an automated assistant and that the call is being recorded. Calls are transcribed for the task at hand — answering, booking, hand-off — and we delete the raw audio rather than retain it. Where the front-desk serves your customers, you are the controller of their data and we act as your processor under our Data Processing Addendum.
AI qualification & automated decisions
When we qualify a lead, AI assesses it on a small set of factors — fit, stated budget, and timeline — and flags the strong ones. That is automated decision-making. It does not produce a legal or similarly significant effect on you on its own; a human reviews anything that matters before any action is taken. Want to know how a decision about you was made, or want a human to look at it? Email us and we will.
Lawful bases
We process your data on a small number of clear bases: performance of the contract between us (delivering the service); our legitimate interests (running a secure, working service and protecting against abuse); consent, where the law needs it; and legal obligation. We name the basis for each use in our agreements, and we don't lean on 'legitimate interests' where consent is the honest answer.
Who it goes to
A small set of processors run the machinery: a third-party AI voice platform, a telephony service for phone numbers, a language-model provider for text, and our hosting. Each acts on our behalf under a Data Processing Addendum with the safeguards the law requires — they can't use your data for their own purposes, and we don't resell it.
Your rights
You can ask what we hold about you, ask us to correct it, ask us to delete it, ask how a decision was made, and opt out of certain uses. In the UK these rights come from UK GDPR, and you also have the right to complain to the Information Commissioner's Office (ICO). For US residents, the applicable state privacy law applies — including California. To exercise any of these, email hello@npcprotocol.com and a human reads it.
International transfers
We're based in the UAE and serve the US and UK. The UAE is not a jurisdiction the UK treats as adequate, so for UK data we move it under a UK International Data Transfer Agreement (or the UK Addendum to the EU Standard Contractual Clauses). That is the actual safeguard in place, not a promise.
Retention
Raw call audio: deleted after transcription, not retained. Call transcripts and lead records: kept for the length of your engagement, then deleted or anonymised within 30 days. Server logs: 30 days. If the law requires us to keep something longer, we do — and only for that reason.
Security
We use reasonable technical and organisational measures to protect your data. No system is 100% secure and we don't promise otherwise — but we work to keep it safe and to tell you quickly if something goes wrong.
Cookies & your off switch
We don't use tracking cookies or non-essential analytics, so there's nothing to 'consent' to by default. If we ever add optional, non-essential tracking, you'll get a real choice — and clearing cookies in your browser turns off anything we do store. That's your off switch, and it works.
Sensitive information
Forms, emails, and calls can sometimes carry sensitive information — health, finances, or details about someone else. If that happens, we treat it as confidential, use it only for the service you asked for, and we'll delete it on request. We don't build profiles around it.
Children
Our services are for businesses and the customers of those businesses. We do not knowingly collect personal data from children under 13. If a child has sent us data, tell us and we will delete it.
Changes
If this policy changes in a way that matters, we update this page and refresh the date at the top. It's short, so keep reading.
The full paperwork
This page is the short version. The detailed agreements — our Master Services Agreement, the Data Processing Addendum, and the AI Voice Services Schedule — sit alongside it.