Last updated: 7 October 2026
This notice explains what personal data Autopilot collects, why we collect it, who we share it with, how long we keep it and what rights you have. It covers:
- visitors to our website (autopilotbusiness.co.uk), and people who email, call or message us;
- the businesses we contact about our services;
- our business clients;
- people who apply to work with us, including applicants in Kenya; and
- the data we handle on behalf of our clients.
1. Who we are
Autopilot (also shown as AutopilotBusiness) is a trading name of Ecom Giant Retail Limited, a company registered in England and Wales, company number 15545138. Registered office: 704 Skylines Plaza, Alencon Link, Basingstoke RG21 7AY, United Kingdom.
For the personal data described in this notice, Ecom Giant Retail Limited is the controller, which means we decide how and why it's used. The exception is the data we handle for our clients (see section 10).
- Email: [email protected] (please put "Privacy" in the subject line)
- Phone: 0118 230 5432
- Post: Ecom Giant Retail Limited, 704 Skylines Plaza, Alencon Link, Basingstoke RG21 7AY, United Kingdom
- ICO registration number: ZB948188
- Data protection officer: we don't have to appoint one. Calvin Odoi, Director, is responsible for data protection.
2. The short version
- If you email, call or message us, we get what you tell us, and we use it to reply.
- Our website platform, HighLevel, records visits to our site (a random visitor ID, the pages you view, how you arrived and your approximate country). See section 4 and our Cookie notice.
- We contact some UK businesses by email and phone to offer our services. Section 5 explains what we hold, where we got it and how to make us stop. You can object at any time.
- If you apply for a job or freelance role with us, section 8 explains what we collect, who sees it and how long we keep it. Please don't send us ID documents, certificates or sensitive information unless we ask for them.
- Some of our team and providers are outside the UK, including in Kenya and the United States. Section 13 explains how we protect your data.
- We never sell personal data.
- You can ask to see, correct or delete your data, or complain, by emailing [email protected].
3. If you email, call or message us
- What we get: your name, email address or phone number, and anything else you choose to tell us (for example your business name and what you need).
- Why: to reply to you and, if you ask, to arrange a call, a trial or a proposal.
- Lawful basis: taking steps at your request before entering into a contract (UK GDPR Article 6(1)(b)) if you're asking about becoming a client. Otherwise, our legitimate interests in answering enquiries (Article 6(1)(f)).
- Where it's held: in our Google Workspace email account and, where we follow up, in our HighLevel CRM.
- How long: 12 months after our last contact with you, unless you become a client (section 7).
4. When you visit our website
Our website is built and hosted on HighLevel (HighLevel, Inc., also trading as LeadConnector). HighLevel's hosting runs behind Cloudflare, which protects the site and speeds it up. Our Cookie notice lists every cookie and similar technology in detail.
| What | Who | What it collects | Why | Lawful basis |
|---|---|---|---|---|
| Visitor statistics and enquiry linking | HighLevel, as our processor | A random visitor ID (the msgsndr_id cookie, kept for 1 year), the pages you view, how you arrived (the referring site and any campaign tags in the link), your approximate country (from your IP address), time on page and how far you scroll. A history of your visits is kept in your browser's local storage. |
To show us how many people visit which pages and where they came from. If you later fill in a form or book a call on our site, HighLevel links your earlier visits to that enquiry in our CRM. | Our legitimate interests in understanding how our site is used and linking visits to enquiries you choose to make (Article 6(1)(f)). You can object at any time (see below). |
| Security | Cloudflare, for HighLevel | Your IP address, browser details and a short-lived security cookie (__cf_bm, 30 minutes) |
To tell real visitors apart from bots and block attacks | Legitimate interests in keeping the site secure (Article 6(1)(f)). This cookie is strictly necessary. |
| Page-speed measurement | Cloudflare Web Analytics, as part of HighLevel's hosting | Page-load timings, the page address and your browser type. No cookie or local storage. | To measure how fast pages load | Legitimate interests in running a fast, working website (Article 6(1)(f)) |
| Web fonts | Google Fonts | Your IP address and browser details, when your browser downloads the site's fonts. No cookie. | To show the site in its intended typefaces | Legitimate interests (Article 6(1)(f)) |
| Server logs | HighLevel and Cloudflare | IP address, date and time, page requested, browser type | To run and secure the service | Legitimate interests (Article 6(1)(f)) |
Please note: HighLevel sets the msgsndr_id cookie and some browser storage when a page loads, before you make a choice on our cookie banner, and keeps them whichever option you choose. We can't switch this off in HighLevel's settings. You can object at any time by emailing [email protected], or avoid it by blocking cookies and site data for autopilotbusiness.co.uk in your browser (the site still works). Our Cookie notice explains more.
- HighLevel acts as our processor under a data processing agreement. HighLevel's terms also allow it to de-identify or aggregate data to provide and improve its own services.
- How long: the
msgsndr_idcookie lasts 1 year and the Cloudflare cookie 30 minutes. The local-storage history stays in your browser until you clear it. Visitor records in our HighLevel account are kept for 12 months. - We don't use Google Analytics, the Meta (Facebook) Pixel, advertising cookies or other marketing trackers on our website. If we ever add our own analytics or marketing cookies, they'll only run if you choose "Accept all" on our cookie banner.
5. People we contact for marketing
We contact some UK businesses, by email and by phone, to offer our services. This section explains what we hold about the people at those businesses (for example the owner or manager), where we got it, and how to make us stop. Our sales team includes people based in Kenya.
- What we hold: the business name; its business email address (a general address such as info@, not a personal one) and business phone number; the name and role of the owner or manager, where the business or the local press has published it; one short factual note about the business (for example a recent opening or award); the company's details from Companies House; where and when we found each detail; and a record of our emails and calls and any replies.
- Where we get it: publicly published business contact details and names from the business's own website, local press, the business's listing on CrossFit.com (for CrossFit affiliates), and Companies House (to check that the business is a company and who runs it). We don't buy contact lists, and we don't use personal social-media profiles to add to what we hold.
- Why and lawful basis: business-to-business direct marketing, based on our legitimate interests in offering our services to businesses that are likely to benefit from them (UK GDPR Article 6(1)(f)). We have carried out a legitimate interests assessment, and you can ask us for a copy.
- How we contact you (PECR):
- We only send marketing emails to limited companies, LLPs and similar organisations, not to sole traders or partnerships unless they've agreed to hear from us. Every email says who we are and gives a simple way to opt out.
- Before calling, we screen numbers against the Telephone Preference Service (TPS), the Corporate Telephone Preference Service (CTPS) and our own "do not contact" list. Our callers give their name, say they're calling for Autopilot, and tell you at the start of every call that it's recorded.
- Who sees it: our sales team, including Kenya-based staff and independent sales consultants, and the providers that hold it for us (Google Workspace, and HighLevel, which also runs our calling system). See sections 12 and 13.
- How long: if you don't reply, we delete your details 12 months after our last contact. If you reply, we treat the conversation as an enquiry (section 3).
Recording of sales calls
- We record our sales calls. At the start of every call, our caller tells you that the call is recorded.
- What we record: the audio of the call, plus the number called, the date and time, and who made the call.
- Why: to train our sales team and check the quality of our calls, to make sure calls follow UK calling rules, and to keep a record of what was said and agreed (for example if you ask us to stop contacting you, or if there's a later disagreement or complaint).
- Lawful basis: our legitimate interests in training, quality, compliance and resolving disputes (UK GDPR Article 6(1)(f)). You can object at any time.
- If you don't want to be recorded: tell the caller and they'll end the call. You can still contact us by email.
- Who can listen: only the people who need to, for training, quality checks or dealing with a complaint or dispute.
- How long: we delete recordings 6 months after the call, unless we need one for a complaint or dispute, in which case we keep it until that's resolved.
Your right to object: you can object to us using your details for direct marketing at any time, free of charge. Reply "unsubscribe" to any of our emails, tell the person who calls you, or email [email protected]. We'll stop contacting you by email and by phone.
We act on objections within 2 working days. So that we never contact you again, even if we later find your details somewhere else, we keep a minimal record on our "do not contact" list (the business name, email address, web domain, phone number, the date and what you told us). We keep that record for as long as we carry out direct marketing.
6. If you book a call or fill in a form
Where our website offers a booking calendar or enquiry form, it runs on HighLevel.
- What we collect: your name, email address, phone number, business name, the time you choose and anything you type into the form. HighLevel also links your earlier visits to our website to your enquiry (section 4).
- Why: to arrange and hold the call, send confirmations and reminders by email or text, and follow up afterwards.
- Lawful basis: taking steps at your request before a contract (Article 6(1)(b)), and our legitimate interests in following up enquiries (Article 6(1)(f)).
- Marketing: booking a call doesn't sign you up to marketing.
- Where it's held: in our HighLevel CRM. Texts are sent through HighLevel's messaging service, which uses Twilio.
- How long: 12 months after our last contact with you, unless you become a client (section 7).
7. If you start a trial or become a client
- What we collect: your name, job title, business name and address, email address, phone number, billing details, your agreement to our terms, notes from our calls with you, records of what we've done for you, and the messages between us.
- Access to your accounts: to deliver the service we need access to your business accounts, for example Google Business Profile, Facebook, Instagram, TikTok, YouTube and your booking system. Where possible we ask you to add [email protected] as a manager or partner rather than sharing passwords. We never ask for passwords by plain email.
- Content: photos, video and other content you share with us, so we can edit and post it for you.
- Payments: card payments will be handled by Stripe, through HighLevel, which we're setting up now. Until it's live, we'll agree with you how you pay. We never see or store your full card number: we see the card type, the last four digits, the expiry date and your payment history. Stripe processes payments for us and is also an independent controller for its own fraud checks and legal obligations, under its own privacy policy (stripe.com/gb/privacy).
- Why: to set up and run the service, take payments, handle support and complaints, and keep accounts.
- Lawful basis: performing our contract with you (Article 6(1)(b)). Where our contract is with your company rather than you personally, our legitimate interests in running the contract with your business (Article 6(1)(f)). Also our legal obligations, for example tax and accounting records (Article 6(1)(c)), and our legitimate interests in running and protecting our business, for example preventing fraud and defending legal claims (Article 6(1)(f)).
- How long: contract and financial records are kept for 6 years after the contract ends. When the contract ends we promptly remove our access to your accounts and return or delete your content and account data, unless you ask us to keep it or the law requires us to.
8. Job and freelance applicants
This section applies if you apply to work with us, including applicants in Kenya. We currently recruit for two kinds of role:
- Salaried sales representatives based in Kenya. The successful applicant is employed by our Employer of Record, Two Max Group Limited (Nairobi, Kenya), and works for Autopilot.
- Independent sales consultants based in Kenya. This is a commission-only, freelance engagement contracted directly with Ecom Giant Retail Limited. It is not employment.
For both, Ecom Giant Retail Limited is the controller of your application.
What we collect
- Your CV, covering note, contact details (name, email address, phone number, town or area), and your answers to any screening questions.
- Our screening notes and scores, notes from interviews and from any mock sales call, and our decision.
- Interview recordings, only if you agree (see below).
- References, only if you reach the final stage and we ask for them.
What we don't want at the application stage
- Please don't send copies of diplomas, degree certificates, transcripts, KCSE certificates or result slips, national ID cards or passports, your KRA PIN, or photos of yourself. We don't need them to assess your application. If you send them anyway, we'll delete them (normally within 7 days) and keep only a note that they were received.
- Please don't include your ID number on your CV.
- We don't ask for sensitive information, such as your health, religion, ethnic or tribal origin, political views, sexual orientation, biometric data or trade union membership, or for information about criminal convictions. Please leave it out of your CV and messages. If you send it, we won't use it and will delete it.
- Education records such as certificates and transcripts aren't "special category" data, but they often contain more than we need, which is why we don't keep them.
- At the final offer stage, we may need to check your identity, right to work, qualifications or (for consultants) your KRA PIN. We'll ask you to show or send the documents then. Once we've checked them, we record that they were verified and delete our copies, unless the law requires us to keep them (for example, for consultants, tax records).
Where we get it: from you, and from the job boards you apply through (for example LinkedIn, MyJobMag or BrighterMonday). Those job boards also handle your data under their own privacy policies.
Why we use it, and our lawful basis
- To assess your application, interview you and decide whether to offer you the role. Lawful basis: taking steps at your request before entering into a contract (UK GDPR Article 6(1)(b)), and our legitimate interests in recruiting the right people (Article 6(1)(f)).
- To consider you for other suitable Autopilot roles. We may consider your application for other suitable roles with us, and tell you about them while we still hold your data. For example, once we've chosen who to hire for the salaried role, we may tell applicants who weren't selected about our freelance consultant role. It's up to you whether to apply, and it won't affect any other application. Lawful basis: our legitimate interests in filling our roles with suitable people who have already shown interest in working with us (Article 6(1)(f)). You can ask us not to do this at any time.
- To keep a record of our decision and deal with any questions or complaints. Lawful basis: our legitimate interests (Article 6(1)(f)).
Do you have to give us this information? No, but we can't consider your application without a CV and a way to contact you.
Interviews and recordings: interviews are held on Google Meet. We'll tell you beforehand if we'd like to record an interview, and we only record it if you agree. If you say no, we won't record, and it won't count against you.
AI tools: we use AI tools, including our AI assistant (Grok Bot), to help us organise, summarise and score applications against the criteria in our job advert. Our founder personally reviews the results and makes every shortlisting and hiring decision, including every decision not to take an application further. We don't make decisions about you by automated means alone.
Who sees it
- Only the people involved in the hiring decision (Calvin Odoi and our hiring team).
- Two Max Group Limited (salaried role only): if you're shortlisted or selected for the salaried role, we share your CV and contact details with Two Max, as the prospective employer, for checks and to prepare your offer. Two Max acts on our instructions until you accept an offer, then becomes your employer and the controller of your employment data. Two Max deletes data of shortlisted applicants who aren't hired within 30 days of our decision.
- The providers that hold the data for us: Google Workspace (email, documents and Google Meet), HighLevel (our CRM) and our AI assistant (Grok Bot). They act as our processors.
Where it's held: your application is sent from Kenya to us in the UK and stored with our providers, including in the United States. If you're shortlisted for the salaried role, it's sent back to Two Max in Kenya. See section 13.
How long we keep it
- If you're not selected: we delete your application, notes and scores 6 months after the hiring decision for the role you applied for. For the salaried role, that's 6 months after we choose who to hire (or after the role closes). For the freelance role, it's 6 months after we tell you our decision.
- If you'd like us to keep you on file for future roles, we'll ask for your agreement, and keep your details for no more than 12 months. You can change your mind at any time.
- Interview recordings: deleted 90 days after the interview.
- Documents we didn't ask for (for example certificates or ID copies): deleted, normally within 7 days.
- If you're hired for the salaried role: Two Max, as your employer, gives you its own employee privacy information. We keep only what we need to manage your work with us.
- If you're engaged as an independent consultant: your consultant agreement explains how we use your data, including payment and tax records.
Kenyan law: if you're in Kenya, Kenya's Data Protection Act 2019 also applies. It gives you rights to be told how your data is used, to access it, to object to its use, and to have false or misleading data corrected or deleted. You can complain to Kenya's Office of the Data Protection Commissioner (odpc.go.ke), as well as to us or the UK ICO (section 17).
9. Independent sales consultants we work with
If we engage you as an independent sales consultant, your consultant agreement explains how we use your personal data. In short, we hold your name and contact details, ID or passport details, KRA PIN, M-Pesa or bank details, invoices and payment records, recordings of calls made through our calling system (HighLevel's phone system), and performance data. We use it to manage the agreement and pay you (contract), keep tax and accounting records (legal obligation), and check compliance with UK calling and data protection law (legitimate interests). We pay through M-Pesa or Wise. Tax and payment records are kept for 6 years after the agreement ends.
10. Our clients' customers (where we act for our clients)
Our services send texts, reply to reviews, manage messages and post on social media on behalf of our business clients. Where a client's plan includes them, our AI website chat and AI phone answering features also respond to the client's customers. For example:
- a missed-call text-back sends a text to someone who called the client's business;
- a review reply responds publicly to a review left for the client on Google;
- reminder and win-back texts go to the client's customers; and
- social posts can include photos or videos that the client gives us.
For that data, our client is the controller and we are their processor. We only use it to provide the service to that client, on their written instructions, under a data processing agreement in our client terms (UK GDPR Article 28). We use HighLevel and its providers (for example Twilio for texts and calls, and OpenAI for AI features) as sub-processors, with our client's authorisation. We don't use our clients' customers' data for our own marketing, and we don't sell it.
If you're a customer of one of our clients, please read that business's privacy notice and contact them first. If you contact us, we'll pass your request to the right client promptly.
11. Use of AI
- In the services we provide to clients: we use AI tools to draft replies to Google reviews and messages, answer chats and calls where a client's plan includes it, and enhance photos and edit video for social posts. Replies to 4 and 5-star reviews may be posted automatically, in a style the client has approved. Reviews of 1 to 3 stars go to the business owner first. We deliver these services through HighLevel, including its built-in AI features, which use AI providers including OpenAI, in the United States.
- In running our own business: we use our AI assistant (Grok Bot) to help draft emails and documents, research businesses' publicly published information (section 5), organise applications (section 8) and organise our work. It acts as our processor and processes data in the United States. A person checks anything sent in our name before it goes out.
- We don't use AI, or any other automated process, to make decisions about individuals that have legal or similarly significant effects.
12. Who we share personal data with
We don't sell personal data. We share it only with the people and providers we need, who act on our instructions, and where the law requires.
| Who | What they do for us | Where |
|---|---|---|
| HighLevel, Inc. / LeadConnector LLC (our processor) | Website hosting, visitor statistics, our CRM, booking calendar and forms, text messages, AI features, and our calling system, which our sales team (including in Kenya) uses to make and record sales calls. HighLevel's own providers include Twilio (texts and calls), Google Cloud and Amazon Web Services (storage), OpenAI (AI features) and its support team in India. | USA, India |
| Cloudflare, Inc. | Security, delivery and page-speed measurement for the website, as part of HighLevel's hosting | USA and global network |
| Google (Google Workspace, including Google Meet; Google Fonts) | Business email, documents and storage, video interviews and any recordings (as our processor); web fonts | USA and other countries |
| Two Max Group Limited | Employer of Record for our salaried sales staff in Kenya: receives shortlisted and selected applicants' CVs and contact details (section 8) | Kenya |
| Our staff and independent sales consultants, including in Kenya | Contacting businesses on our behalf (section 5) and supporting our sales | UK, Kenya |
| Stripe (coming soon) | Card payments, as our payment processor. Also an independent controller for its own fraud checks. | USA and other countries |
| Wise and M-Pesa (Safaricom) | Paying our independent sales consultants (section 9) | UK, EU, Kenya and other countries |
| Our AI assistant (Grok Bot) | Helping run our business (section 11), as our processor | USA |
| Job boards (for example LinkedIn, MyJobMag, BrighterMonday) | Advertising our roles and passing applications to us | Kenya and other countries |
| Accountants and professional advisers | Accounts, tax and legal advice | UK and, for Kenyan advice, Kenya |
We may also disclose personal data if the law requires it, to protect our rights or someone's safety, or to a buyer if our business is ever sold.
13. Transfers outside the UK
Some of our providers, and some of our team, are outside the UK. When personal data leaves the UK, we make sure it stays protected by using appropriate safeguards such as the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU standard contractual clauses, or adequacy regulations where they apply (for example, the UK Extension to the EU-US Data Privacy Framework, for US providers certified under it).
- United States: HighLevel, Google, Cloudflare, Stripe, our AI assistant and other US providers. We rely on adequacy regulations where they apply to the provider, or otherwise on the IDTA or UK Addendum in the provider's data processing terms.
- India and other countries where our providers work (for example HighLevel's support team): covered by our providers' contractual safeguards (the IDTA or UK Addendum).
- Kenya: there are no UK adequacy regulations for Kenya.
- Two Max Group Limited: we sign the UK IDTA with Two Max, and carry out a transfer risk assessment, before we send any applicant's details.
- Independent sales consultants: we sign the UK IDTA with each consultant, and carry out a transfer risk assessment, before they get access to any data.
- Access is through our own systems, with individual logins and only the access each person needs. We don't allow copies on personal devices, and we remove access when someone leaves.
- Kenya's Data Protection Act 2019 also protects the data.
You can ask us for more information about these safeguards, or a copy of them, by emailing [email protected].
14. How long we keep personal data
| Data | How long |
|---|---|
| Email, phone, booking and form enquiries from people who don't become clients | 12 months after our last contact |
| Businesses we contact for marketing that don't reply | 12 months after our last contact |
| "Do not contact" list entries | For as long as we carry out direct marketing |
| Sales call recordings | 6 months after the call (longer only for a complaint or dispute, until resolved) |
| Client contract and financial records | 6 years after the contract ends |
| Client account access, content and account data | Removed, returned or deleted promptly when the contract ends |
| Applications from people we don't select | 6 months after the hiring decision for the role (up to 12 months if you agree to stay on file) |
| Interview recordings | 90 days after the interview |
| Certificates, ID copies or other documents we didn't ask for | Deleted, normally within 7 days (we keep only a note that they were received) |
| Documents checked at offer stage | Copies deleted once checked (we keep a note that they were verified) |
| Independent consultants' tax and payment records | 6 years after the agreement ends |
| Website visitor records | 12 months (the msgsndr_id cookie lasts 1 year in your browser unless you clear it) |
We may keep data for longer if we need it for a complaint or legal claim, or if the law requires it.
15. How we keep data secure
We use reputable providers. Two-step login is required on our business systems, and access is limited to what each person's role needs. We don't send passwords by plain email, and we remove access when someone leaves. Applicant data is kept only in our hiring folder and our CRM, not in personal copies.
16. Your rights
Under UK data protection law you have the right to:
- access the personal data we hold about you and get a copy;
- have inaccurate data corrected;
- have your data deleted in some circumstances;
- restrict how we use it in some circumstances;
- data portability: receive data you gave us in a common electronic format, or have it sent to someone else, where we rely on consent or a contract;
- object to our use of your data where we rely on legitimate interests; and
- withdraw consent at any time, where we rely on consent (this doesn't affect what we did before).
You have an absolute right to object to direct marketing. If you object, we'll stop.
To use any of these rights, email [email protected] or write to us at the address in section 1. We'll reply within one month. For complex requests this can be extended by up to two further months, and we'll tell you if so. We may need to check your identity first. There's normally no charge.
If you're in Kenya, you also have the rights described in section 8.
17. Complaints
If you're unhappy with how we've handled your personal data, please tell us. You can complain by email to [email protected] (please put "Privacy complaint" in the subject line), by post to the address in section 1, or by telling anyone you deal with at Autopilot, who will pass it on.
We will:
- acknowledge your complaint within 30 days of receiving it;
- look into it and keep you updated; and
- tell you the outcome without undue delay.
You also have the right to complain to the Information Commissioner's Office (ICO), the UK data protection regulator: ico.org.uk/make-a-complaint, or call 0303 123 1113. If you're in Kenya, you can also contact or complain to Kenya's Office of the Data Protection Commissioner (odpc.go.ke).
18. Cookies
Our website uses a small number of cookies and similar technologies, mostly set by our website platform, HighLevel, and by Cloudflare. These include HighLevel's msgsndr_id visitor-ID cookie, which is set before you make a choice on our cookie banner (see section 4). Our Cookie notice lists them all and explains how to control them. If we ever add our own analytics or marketing cookies, they'll only run if you choose "Accept all" on our cookie banner.
19. Children
Our website and services are for businesses, and our roles are for adults. We don't knowingly collect children's personal data for our own purposes. Some of our clients' customers may be under 18 (for example junior gym members). Where we handle their data for a client, the client is the controller (section 10).
20. Changes to this notice
We'll update this notice when our services or the law change, and change the "Last updated" date above. If a change significantly affects how we use data we already hold about you, we'll tell you directly where we can.