Install BuzzConnekt

Add to home screen for quick access.

Legal

BuzzConnekt AI Privacy Notice

Effective date: 24 July 2026Last updated: 24 July 2026

1. About this Privacy Notice

This Privacy Notice explains how BuzzConnekt Business Solutions Ltd collects, uses, stores and shares personal data.

BuzzConnekt provides an artificial-intelligence-powered communications platform. Our services include the AI front desk agent known as Maya, which may answer and route telephone calls, record and transcribe conversations, collect messages, send communications, qualify enquiries and book appointments on behalf of our business customers.

This Privacy Notice applies to:

  • Visitors to our website.
  • Prospective customers.
  • BuzzConnekt account holders and authorised users.
  • People who contact BuzzConnekt for support or other enquiries.
  • Recipients of BuzzConnekt’s own business marketing.
  • People who call or receive communications from a business using BuzzConnekt, to the extent that BuzzConnekt processes their data.
  • Other individuals whose personal data is supplied to us through a customer account, integration or authorised campaign.

We process personal data in accordance with applicable UK data-protection law, including:

  • The UK General Data Protection Regulation.
  • The Data Protection Act 2018.
  • The Data (Use and Access) Act 2025.
  • The Privacy and Electronic Communications Regulations 2003.
  • Other applicable telecommunications, consumer-protection and electronic-marketing laws.

2. Who we are

BuzzConnekt is operated by:

BuzzConnekt Business Solutions Ltd
Company number: 16030199
Registered in England and Wales
Registered office: 211 Bell Avenue, Romford, England, RM3 7DB

BuzzConnekt has not appointed a formal Data Protection Officer. Privacy matters are handled by our Privacy Lead through the contact details above. We keep the need to appoint a formal Data Protection Officer under review as our services and processing activities develop.

In this Privacy Notice, “BuzzConnekt”, “we”, “us” and “our” refer to BuzzConnekt Business Solutions Ltd.

3. When BuzzConnekt is a controller and when we are a processor

Data-protection law distinguishes between a controller, which decides why and how personal data is processed, and a processor, which processes personal data on a controller’s instructions.

BuzzConnekt may act in both roles.

3.1 When we act as a controller

BuzzConnekt acts as a controller when we decide why and how personal data is used. This normally includes personal data relating to:

  • Website visitors.
  • Prospective customers.
  • Customers and authorised account users.
  • Billing and subscription administration.
  • Customer-support enquiries.
  • Platform security and fraud prevention.
  • BuzzConnekt’s own business marketing.
  • Legal, regulatory and accounting obligations.
  • The management and defence of legal claims.
  • Business analytics based on account, usage or appropriately aggregated data.

This Privacy Notice explains how we process personal data in that controller role.

3.2 When we act as a processor

BuzzConnekt normally acts as a processor when Maya handles calls, messages, appointments, leads or other communications on behalf of one of our business customers.

In those circumstances:

  • The business using BuzzConnekt is normally the controller.
  • The customer decides why the personal data is collected and how it should be used.
  • The customer is responsible for identifying an appropriate lawful basis.
  • The customer is responsible for providing callers and other individuals with appropriate privacy information.
  • BuzzConnekt processes the personal data only on the customer’s documented instructions, except where the law requires otherwise.
  • Our processing is governed by a Data Processing Addendum forming part of our agreement with the customer.
  • We assist the customer with data-protection rights, security incidents, impact assessments and other compliance obligations where required.

If you have contacted a business that uses BuzzConnekt and want to exercise your rights concerning that interaction, you should normally contact that business first.

You may also contact us at privacy@buzzconnekt.net. Where we are acting as a processor, we will refer the request to the relevant customer and assist them as required.

3.3 Processing for our own purposes

We do not automatically become a controller merely because personal data passes through our systems.

However, BuzzConnekt may act as a controller for limited processing connected with:

  • Platform and network security.
  • Preventing fraud, misuse and unlawful activity.
  • Investigating security incidents.
  • Maintaining legally required records.
  • Protecting our legal rights.
  • Complying with lawful regulatory or law-enforcement requests.

We do not use identifiable customer call recordings or transcripts for our own direct marketing.

We may use aggregated or appropriately de-identified service metrics to measure matters such as system performance, call completion rates, service reliability and feature usage.

We will not use identifiable call content to train a general-purpose artificial-intelligence model for our own independent purposes unless that use is separately disclosed, contractually permitted and supported by an appropriate lawful basis.

4. Personal data we collect

The personal data we collect depends on how you interact with BuzzConnekt.

4.1 Website and device information

We may collect:

  • Internet Protocol address.
  • Browser type and version.
  • Device type and operating system.
  • Time zone and approximate location derived from an IP address.
  • Pages viewed and actions taken.
  • Referral source.
  • Session and diagnostic information.
  • Cookie identifiers and consent choices.
  • Security and access logs.

4.2 Enquiry and prospective-customer information

When you request information, contact us or book a demonstration, we may collect:

  • Name.
  • Business name.
  • Job title or role.
  • Email address.
  • Telephone number.
  • Industry and business requirements.
  • Information contained in your enquiry.
  • Demonstration and sales-call records.
  • Marketing preferences.

4.3 Customer and authorised-user information

When a customer creates or manages an account, we may collect:

  • Name.
  • Business name and trading name.
  • Company number, where relevant.
  • Business address.
  • Job title or role.
  • Email address.
  • Telephone number.
  • Login details and authentication information.
  • Account permissions.
  • Subscription plan.
  • Customer-support correspondence.
  • Service settings and preferences.
  • Records of acceptance of our contractual documents.
  • Records of customer instructions and compliance confirmations.

4.4 Service configuration information

Customers may provide information used to configure Maya and other BuzzConnekt services, including:

  • Business descriptions.
  • Opening hours.
  • Staff and department details.
  • Frequently asked questions.
  • Call-routing instructions.
  • Appointment types.
  • Escalation rules.
  • Telephone numbers.
  • Email addresses.
  • Knowledge-base material.
  • Scripts and greetings.
  • Calendar and customer-relationship-management settings.
  • Emergency or out-of-hours procedures.

Some of this information may contain personal data relating to staff members, contractors or other individuals.

4.5 Billing and transaction information

We may collect:

  • Billing name and address.
  • Subscription information.
  • Payment status.
  • Invoice and transaction history.
  • The last digits and expiry information associated with a payment method, where supplied by our payment provider.
  • Tax and accounting information.
  • Records of refunds, credits and payment disputes.

Full payment-card details are processed by our payment provider. BuzzConnekt does not normally receive or store complete payment-card numbers.

4.6 Usage and operational information

We may collect:

  • Call volumes.
  • Call duration.
  • Message volumes.
  • Appointment volumes.
  • Features used.
  • Numbers allocated to an account.
  • Account activity.
  • Error and diagnostic information.
  • Audit logs.
  • Security events.
  • Service-performance information.
  • Support and troubleshooting records.

4.7 Call, message and appointment data

When BuzzConnekt processes communications on behalf of a customer, the personal data may include:

  • Caller or recipient telephone number.
  • Calling number and destination number.
  • Date, time and duration of the communication.
  • Call audio.
  • Call transcript.
  • Call summary.
  • Name and contact details supplied during the interaction.
  • Reason for contacting the business.
  • Enquiry details.
  • Appointment details.
  • Message content.
  • Email or SMS content.
  • Call-routing outcome.
  • Customer-service notes.
  • Consent, objection and opt-out information.
  • Information imported from or written to connected calendars, booking systems or customer-relationship-management platforms.

For outbound campaigns, customers may also supply:

  • Lead names.
  • Telephone numbers.
  • Email addresses.
  • Business details.
  • Lead source.
  • Campaign history.
  • Consent evidence.
  • Marketing preferences.
  • Suppression and do-not-contact information.

4.8 Special-category and criminal-offence information

Telephone conversations can be unpredictable. A caller may disclose sensitive information, even where BuzzConnekt or the customer did not specifically request it.

Call data may therefore occasionally include:

  • Health or disability information.
  • Racial or ethnic origin.
  • Religious or philosophical beliefs.
  • Political opinions.
  • Trade-union membership.
  • Genetic or biometric information.
  • Information about a person’s sex life or sexual orientation.
  • Allegations, investigations, convictions or other criminal-offence information.

BuzzConnekt does not seek to collect this information for its own marketing purposes.

Where we process this information on behalf of a customer:

  • The customer is responsible for identifying an Article 6 lawful basis.
  • The customer is responsible for identifying an applicable Article 9 condition for special-category information.
  • The customer is responsible for satisfying the additional requirements applicable to criminal-offence information.
  • We process it only on documented instructions and subject to the Data Processing Addendum.
  • We apply access controls, data-minimisation, retention and security measures appropriate to the risk.

Customers must configure their service to avoid collecting sensitive information that is unnecessary for their purpose.

Customers must not use BuzzConnekt to collect or make decisions using sensitive information unless they have completed the appropriate legal assessment and implemented the required safeguards.

4.9 Children’s information

Our website, subscriptions and business accounts are not intended for children.

However, a child may telephone or communicate with a business that uses BuzzConnekt. In that situation, BuzzConnekt may process the child’s personal data on behalf of the business customer.

Customers are responsible for determining whether their services may be used by children and for implementing:

  • Age-appropriate privacy information.
  • Appropriate lawful bases.
  • Data-minimisation controls.
  • Suitable safeguarding and escalation procedures.
  • Parental or guardian involvement where legally required.

5. Where we obtain personal data

We may obtain personal data from:

  • You directly.
  • Your employer or the business through which you use BuzzConnekt.
  • An account owner or account administrator.
  • A caller or communication recipient.
  • A BuzzConnekt customer.
  • Connected calendars, booking systems, email systems or customer-relationship-management platforms.
  • Payment and billing providers.
  • Telephony and messaging providers.
  • Security, identity-verification and fraud-prevention providers.
  • Business directories and publicly available professional sources.
  • Referral partners or resellers.
  • Public corporate records.
  • Other parties where you have authorised the disclosure.

Where a customer uploads contact or lead information, the customer is responsible for ensuring that it has obtained and shared the information lawfully.

6. Information you must provide

Some personal data is required so that we can enter into or perform our contract with you.

For example, we normally need:

  • Your identity and business contact details.
  • Account and login information.
  • Billing information.
  • The service instructions needed to configure your account.

If you do not provide required information, we may be unable to:

  • Create your account.
  • Supply the service.
  • Process payment.
  • Provide support.
  • Maintain account security.
  • Meet our legal obligations.

Providing information for BuzzConnekt’s own marketing is optional. Refusing marketing does not prevent you from using the service.

7. How we use personal data when we are the controller

7.1 Creating and managing accounts

Purpose:
To register customers, administer accounts, authenticate users, configure the service and provide contracted features.
Personal data:
Identity, business contact, account, configuration, usage and subscription information.
Lawful basis:
Performance of a contract or taking steps at your request before entering into a contract.

Where an authorised user is not personally party to the customer contract, we normally rely on our legitimate interests in administering the business customer’s account and providing secure access to authorised personnel.

7.2 Processing subscriptions and payments

Purpose:
To process payments, issue invoices, administer subscriptions, manage failed payments and maintain financial records.
Personal data:
Identity, contact, billing, subscription and transaction information.
Lawful basis:
Performance of a contract and compliance with legal obligations.

7.3 Responding to enquiries and providing support

Purpose:
To respond to questions, arrange demonstrations, investigate issues, troubleshoot the service and provide customer support.
Personal data:
Identity, contact, account, technical, usage and support information.
Lawful basis:
Performance of a contract, taking steps before entering a contract, and our legitimate interests in providing effective support and operating our business.

7.4 Service communications

Purpose:
To send information about billing, account security, service changes, maintenance, incidents and contractual matters.
Personal data:
Identity, contact, account and subscription information.
Lawful basis:
Performance of a contract, compliance with legal obligations and our legitimate interests in administering and protecting the service.

Service communications are not marketing and may continue even where you have opted out of promotional messages.

7.5 Security, fraud prevention and misuse monitoring

Purpose:
To authenticate users, secure accounts, protect our systems, detect fraud, investigate misuse, prevent unlawful activity and enforce our terms.
Personal data:
Account, technical, device, usage, communications metadata, security and audit information.
Lawful basis:
Our legitimate interests in protecting BuzzConnekt, our customers, callers and the public; and compliance with legal obligations where applicable.

7.6 Service measurement and development

Purpose:
To measure performance, diagnose problems, understand feature use, improve reliability and develop the service.
Personal data:
Account, technical, usage, diagnostic and appropriately aggregated or de-identified information.
Lawful basis:
Our legitimate interests in maintaining and improving a reliable and competitive service.

We seek to minimise the use of identifiable personal data for this purpose. We do not use identifiable call content for independent product development unless the processing is separately disclosed and appropriately authorised.

7.7 BuzzConnekt marketing

Purpose:
To send relevant information about BuzzConnekt services, features, offers and events.
Personal data:
Name, business contact details, role, organisation, marketing preferences and engagement information.
Lawful basis:
Consent where required, or our legitimate interests in promoting BuzzConnekt to relevant business contacts where the law permits.

Our electronic-marketing approach depends on the type of recipient:

  • For individuals, sole traders and certain partnerships, we will obtain consent unless another lawful PECR exception, such as a valid soft opt-in, applies.
  • For employees and representatives of limited companies and other corporate subscribers, PECR may not require consent for business email marketing. However, UK GDPR still applies where we use personal data.
  • We provide an unsubscribe method in marketing communications.
  • We respect objections and opt-out requests.
  • We maintain suppression information so that we do not contact people who have opted out.
  • We do not require marketing consent as a condition of purchasing the service.

7.8 Legal, regulatory and accounting requirements

Purpose:
To maintain business records, comply with tax and accounting law, respond to regulators and lawful authorities, and establish, exercise or defend legal claims.
Personal data:
Identity, contact, account, billing, transaction, usage, support and communications information.
Lawful basis:
Compliance with legal obligations and our legitimate interests in protecting and enforcing our legal rights.

7.9 Business transfers

Purpose:
To evaluate or complete a merger, acquisition, restructuring, investment, financing or sale of all or part of our business.
Personal data:
Relevant customer, account, contract, billing, employee-contact and usage information.
Lawful basis:
Our legitimate interests in managing and developing our business.

Any recipient will be subject to appropriate confidentiality and data-protection obligations.

8. Our legitimate interests

Where we rely on legitimate interests, those interests may include:

  • Operating and administering BuzzConnekt.
  • Providing secure access to authorised users.
  • Protecting customers, callers and our systems.
  • Preventing fraud, abuse and unlawful activity.
  • Responding to business enquiries.
  • Maintaining and improving service reliability.
  • Understanding the use of our services.
  • Promoting relevant services to suitable corporate contacts.
  • Managing business relationships.
  • Recovering debts.
  • Protecting and enforcing legal rights.
  • Supporting a potential business transaction.

Before relying on legitimate interests, we consider:

  • Whether the processing has a legitimate purpose.
  • Whether the processing is necessary.
  • The reasonable expectations of the individuals concerned.
  • The nature and sensitivity of the information.
  • The possible impact on individuals.
  • Whether less intrusive alternatives are available.
  • What safeguards can reduce the impact.

You may contact us for more information about a legitimate-interests assessment relevant to your personal data.

9. Artificial intelligence, call recording and automated processing

9.1 Maya is an artificial-intelligence system

Maya is an automated artificial-intelligence assistant and is not a human front desk agent.

Customers using Maya must ensure that callers are given an appropriate notice explaining that they are interacting with an automated assistant.

9.2 Recording and transcription

Depending on the customer’s configuration and purpose, calls may be:

  • Connected through our telephony providers.
  • Recorded.
  • Transcribed.
  • Summarised.
  • Analysed to determine the caller’s request.
  • Used to create messages, appointments or customer-service records.

Where a call is recorded or transcribed, callers should be informed at or near the start of the call.

The customer is normally responsible for:

  • Deciding whether recording is necessary.
  • Establishing a lawful basis.
  • Providing the appropriate call notice.
  • Determining the retention period.
  • Ensuring that the recording complies with sector-specific requirements.
  • Providing a human-escalation route where appropriate.

9.3 Voice information

A voice recording is personal data where an individual can be identified from it.

BuzzConnekt does not use voice recordings for biometric identification or voiceprint matching unless that functionality has been separately agreed, legally assessed and clearly disclosed.

9.4 How Maya processes communications

Maya may use several technologies to process a communication, including:

  • Telephony.
  • Speech recognition.
  • Language-model processing.
  • Text-to-speech generation.
  • Call routing.
  • Messaging.
  • Calendar or booking integrations.
  • Customer-relationship-management integrations.

Relevant information may be sent to service providers supporting those functions, subject to contractual and security safeguards.

9.5 Automated decisions

BuzzConnekt does not currently use personal data in its standard service to make solely automated decisions that produce legal or similarly significant effects about individuals.

Maya is designed to:

  • Answer routine questions.
  • Collect information.
  • Route communications.
  • Record messages.
  • Arrange appointments.
  • Perform administrative workflows.

Maya is not intended to make final decisions concerning matters such as:

  • Credit eligibility.
  • Insurance eligibility.
  • Employment.
  • Tenancy eligibility.
  • Medical treatment.
  • Legal rights.
  • Access to essential services.

Customers must not configure BuzzConnekt to make solely automated decisions with legal or similarly significant effects unless they have:

  • Confirmed that the processing is lawful.
  • Completed an appropriate Data Protection Impact Assessment.
  • Provided meaningful information about the processing.
  • Implemented appropriate human review.
  • Allowed individuals to express their view and challenge the outcome.
  • Implemented all other safeguards required by law.

10. Who we share personal data with

We may share personal data with carefully selected service providers and other recipients where necessary.

The categories include:

10.1 Hosting and infrastructure providers

Providers that host our website, application, databases, files, backups and related infrastructure.

10.2 Telephony and messaging providers

Providers that connect telephone calls, allocate or manage telephone numbers and deliver SMS or other communications.

10.3 Artificial-intelligence and speech providers

Providers supporting:

  • Speech-to-text processing.
  • Language understanding.
  • Response generation.
  • Text-to-speech output.
  • Call summarisation.

10.4 Database and storage providers

Providers used to store account information, service configurations, recordings, transcripts, messages and system data.

10.5 Payment providers

Providers that process subscription payments, refunds and payment-related fraud checks.

10.6 Email and notification providers

Providers used to deliver service emails, account alerts, messages and other notifications.

10.7 Calendar, booking and integration providers

Providers that enable appointments, calendar synchronisation and connections with customer-relationship-management or business systems.

10.8 Analytics, monitoring and security providers

Providers used for service analytics, performance monitoring, error detection, security and fraud prevention.

Non-essential website analytics are used only where an appropriate consent or legal exception applies.

10.9 Professional advisers

Accountants, auditors, insurers, legal advisers and other professional advisers where reasonably necessary.

10.10 Authorities and legal recipients

Courts, regulators, law-enforcement agencies, tax authorities and other public bodies where disclosure is required or permitted by law.

10.11 Business transaction recipients

Potential buyers, investors, lenders and professional advisers involved in a genuine merger, acquisition, restructuring, financing or sale.

We do not sell personal data.

Our current service providers are identified in the BuzzConnekt Subprocessor List, which is available through the legal section of our website.

The Subprocessor List includes information about:

  • The provider.
  • The service supplied.
  • The types of personal data involved.
  • The principal processing location.
  • Relevant international-transfer arrangements.

Customers will be informed of material changes to subprocessors in accordance with our Data Processing Addendum.

11. International transfers

Some providers supporting BuzzConnekt may process personal data outside the United Kingdom.

Where personal data is subject to a restricted international transfer, we use an appropriate transfer mechanism. Depending on the recipient and destination, this may include:

  • UK adequacy regulations.
  • The UK Extension to the EU–US Data Privacy Framework, where the recipient is certified and the transfer is covered.
  • The UK International Data Transfer Agreement.
  • The UK Addendum to the European Commission’s Standard Contractual Clauses.
  • Another transfer mechanism permitted by UK data-protection law.

Where required, we assess whether the destination provides protection that is not materially lower than the protection available under UK data-protection law. We may implement additional contractual, organisational or technical safeguards where necessary.

You may request further information about the safeguards applying to your personal data by contacting privacy@buzzconnekt.net.

Commercially sensitive information and information affecting the rights of other parties may be redacted where legally permitted.

12. How long we retain personal data

We retain personal data only for as long as reasonably necessary for the purpose for which it was collected, including legal, accounting, security and contractual requirements.

Our normal retention periods are as follows.

12.1 Prospective-customer and sales enquiries

We normally retain sales enquiries and demonstration records for up to 24 months after the most recent meaningful interaction, unless:

  • You ask us to delete the information.
  • You object to further processing.
  • A longer period is necessary for a legal claim.
  • You become a customer.

12.2 Customer account information

We normally retain account and service-configuration information:

  • For the duration of the customer account.
  • For up to 12 months after the account closes.

Some information may be retained for longer where necessary for security, disputes, fraud prevention or legal obligations.

12.3 Call recordings, transcripts and communications data

Where BuzzConnekt acts as a processor, call recordings, transcripts, messages and appointment information are retained for the period selected or instructed by the customer, subject to the customer agreement and Data Processing Addendum.

When the retention period expires, the information is deleted or anonymised unless:

  • A legal hold applies.
  • Retention is required by law.
  • The customer lawfully instructs us otherwise.

12.4 Billing, accounting and tax information

We normally retain invoices, transaction records and tax information for six years after the end of the relevant financial year or business relationship, where required for accounting, tax and legal purposes.

12.5 Customer-support records

We normally retain customer-support correspondence for up to 24 months after the matter is closed.

We may retain particular records for longer where they are relevant to a continuing dispute, security incident or legal claim.

12.6 Security and audit logs

Security, authentication and audit information is retained for a period determined by:

  • The nature of the log.
  • The security risk.
  • Fraud-prevention requirements.
  • Contractual obligations.
  • Legal and regulatory requirements.

We periodically review these periods and avoid retaining identifiable log data for longer than necessary.

12.7 Marketing information

We retain marketing information until:

  • You unsubscribe.
  • You withdraw consent.
  • You object to direct marketing.
  • We decide the information is no longer current or useful.

When you opt out, we may retain limited suppression information, such as your email address or telephone number, for as long as necessary to ensure that we continue to respect your choice.

12.8 Backups

Deleted personal data may remain temporarily in secured backups until those backups are overwritten through our documented backup cycle.

Backup data is isolated from ordinary operational use and is restored only where necessary for disaster recovery, security or business continuity.

If a backup is restored, applicable deletion instructions and retention controls are reapplied.

13. How we protect personal data

We use technical and organisational measures designed to protect personal data against:

  • Unauthorised access.
  • Accidental loss.
  • Unlawful use.
  • Unauthorised alteration.
  • Unauthorised disclosure.
  • Destruction.

Depending on the nature and risk of the processing, our measures may include:

  • Encryption in transit.
  • Encryption at rest where supported and appropriate.
  • Authentication controls.
  • Multi-factor authentication for relevant systems.
  • Role-based access.
  • Least-privilege access.
  • Logging and monitoring.
  • Secure software-development practices.
  • Vulnerability and patch management.
  • Backup and recovery controls.
  • Vendor due diligence.
  • Confidentiality obligations.
  • Incident-response procedures.
  • Staff training.
  • Periodic review of access permissions.

No system can be guaranteed to be completely secure. We continuously review our security controls in light of the nature of the information and the risks involved.

13.1 Personal data breaches

Where BuzzConnekt acts as a controller, we will:

  • Investigate suspected personal data breaches.
  • Assess the likely risk to individuals.
  • Notify the Information Commissioner without undue delay and, where feasible, within 72 hours where notification is legally required.
  • Inform affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms.
  • Maintain appropriate breach records.

Where BuzzConnekt acts as a processor, we will notify the relevant customer without undue delay after becoming aware of a personal data breach affecting customer data and will provide reasonable assistance in accordance with our Data Processing Addendum.

14. Your data-protection rights

Your rights depend on the circumstances, the type of personal data and the lawful basis being used.

Where BuzzConnekt is the controller, your rights may include the following.

14.1 Right to be informed

You have the right to receive clear information about how we collect and use your personal data.

14.2 Right of access

You may ask:

  • Whether we process your personal data.
  • For a copy of the personal data.
  • For supporting information about the processing.

14.3 Right to rectification

You may ask us to correct inaccurate personal data or complete information that is incomplete.

14.4 Right to erasure

You may ask us to delete personal data in certain circumstances.

The right to erasure is not absolute. We may retain information where processing remains necessary for a lawful reason, such as compliance with a legal obligation or the establishment, exercise or defence of legal claims.

14.5 Right to restrict processing

You may ask us to restrict the use of your personal data in certain circumstances, including while an accuracy or objection issue is being considered.

14.6 Right to data portability

Where processing is based on consent or contract and carried out by automated means, you may have the right to receive personal data you provided in a structured, commonly used and machine-readable format.

You may also ask us to transmit it to another controller where technically feasible.

14.7 Right to withdraw consent

Where we rely on consent, you may withdraw it at any time.

Withdrawal does not affect the lawfulness of processing that took place before consent was withdrawn.

14.8 Rights relating to automated decisions

Where applicable, you may have rights concerning solely automated decisions producing legal or similarly significant effects, including rights to appropriate safeguards and human intervention.

BuzzConnekt’s standard service does not currently make these decisions about individuals.

15. Your right to object

You have the right to object at any time to the use of your personal data for direct marketing.

Where you object to direct marketing, we will stop using your personal data for that purpose.

You may use the unsubscribe option in a marketing communication or contact us at privacy@buzzconnekt.net.

You may also object to processing based on legitimate interests.

Where you object to legitimate-interests processing, we will stop processing the personal data unless:

  • We demonstrate compelling legitimate grounds that override your interests, rights and freedoms; or
  • Processing is required for the establishment, exercise or defence of legal claims.

16. How to exercise your rights

To exercise a data-protection right, contact:

privacy@buzzconnekt.net

You may also write to:

Privacy Lead
BuzzConnekt Business Solutions Ltd
211 Bell Avenue
Romford
England
RM3 7DB

Please provide enough information to help us identify:

  • Who you are.
  • The right you wish to exercise.
  • The relevant account, interaction or communication.
  • The information concerned.

We may ask for reasonable evidence of identity or authority where necessary to protect personal data against unauthorised disclosure.

We normally respond without undue delay and within one month.

Where permitted by law:

  • We may extend the response period by up to two further months if a request is complex or you have made several requests.
  • We will tell you within the initial one-month period if an extension is needed and explain why.

Where reasonable clarification is required to identify the information requested, the response period may pause until the clarification is received.

Exercising your rights is normally free.

We may charge a reasonable fee or refuse to act where a request is manifestly unfounded or excessive, including because it is repetitive. Where we refuse a request, we will explain our decision and tell you about your right to complain.

Where BuzzConnekt is processing personal data on behalf of a customer, we will normally refer the request to the customer and assist them in responding.

17. Data-protection complaints

You have the right to complain if you believe that BuzzConnekt has not handled your personal data in accordance with data-protection law.

You may submit a data-protection complaint electronically by emailing:

privacy@buzzconnekt.net

You may also send your complaint by post to:

Privacy Lead
BuzzConnekt Business Solutions Ltd
211 Bell Avenue
Romford
England
RM3 7DB

Please include:

  • Your name and contact details.
  • A description of the concern.
  • The relevant dates.
  • The account, telephone number or interaction concerned, where applicable.
  • Copies of relevant correspondence or evidence.
  • The outcome you are seeking.

We will:

  • Acknowledge your complaint within 30 days.
  • Take appropriate steps to investigate it.
  • Request further information where reasonably necessary.
  • Keep you informed where the investigation cannot be concluded promptly.
  • Communicate the outcome without undue delay.
  • Explain any action we have taken or intend to take.
  • Inform you of your right to complain to the Information Commissioner.

You may complain directly to the Information Commissioner’s Office at any time. You do not have to complete BuzzConnekt’s complaint process first.

The Information Commissioner’s Office can be contacted through its official website or on 0303 123 1113.

18. Cookies and similar technologies

Our website uses cookies and similar technologies.

These may include:

  • Strictly necessary technologies.
  • Security and authentication technologies.
  • Preference and functionality technologies.
  • Statistical or analytics technologies.
  • Marketing technologies.

Strictly necessary technologies may be used without consent where the law permits.

We do not place or access non-essential cookies or similar technologies requiring consent until you have made an affirmative choice through our consent controls.

Where a statutory exception permits a limited use without consent, we will apply the conditions of that exception, including an accessible objection mechanism where required.

Our cookie controls allow you to:

  • Accept non-essential technologies.
  • Reject non-essential technologies.
  • Choose categories.
  • Change or withdraw your preference.

Rejecting non-essential cookies should be as easy as accepting them.

You can review or change your current choice at any time using the control below or via the link in the site footer.

More information about the technologies we use, their purposes, providers and durations is available in our Cookie Notice, accessible through our website footer and cookie settings.

19. Direct marketing on behalf of customers

A customer may use BuzzConnekt to communicate with its own leads, customers or business contacts.

In that situation, the customer is normally responsible for:

  • Determining whether the communication is direct marketing.
  • Identifying the lawful basis.
  • Obtaining valid consent where required.
  • Complying with PECR.
  • Screening against applicable preference services and suppression lists.
  • Maintaining consent and lead-source evidence.
  • Identifying itself during communications.
  • Providing a valid opt-out method.
  • Respecting objections and do-not-contact requests.
  • Ensuring that automated-call requirements are met.
  • Ensuring that campaign scripts comply with sector-specific rules.

BuzzConnekt may provide technical tools to support these obligations, but those tools do not replace the customer’s legal responsibilities.

We may suspend or restrict campaigns where we reasonably believe that:

  • Contact information was obtained unlawfully.
  • Required consent is missing.
  • A campaign breaches PECR or other law.
  • Communications are misleading, harmful or abusive.
  • Opt-out requests are not being respected.
  • The customer’s use creates an unacceptable compliance or reputational risk.

20. Third-party websites and integrations

BuzzConnekt may contain links to third-party websites or connect with third-party platforms.

Those organisations may act as independent controllers and have their own privacy notices.

BuzzConnekt is not responsible for the privacy practices of an independent third party. Customers and users should review the privacy information supplied by each connected provider.

Connecting an integration may allow information to move between BuzzConnekt and the third-party service in accordance with the customer’s instructions.

21. Changes to this Privacy Notice

We may update this Privacy Notice to reflect:

  • Changes to our services.
  • Changes to our suppliers or processing activities.
  • Changes to data-protection law.
  • Changes to regulatory guidance.
  • Security or operational developments.

When we make changes, we will update the “Last updated” date.

Where a change is material, we may also notify customers through:

  • Email.
  • An account notification.
  • A dashboard message.
  • Another appropriate communication.

A previous version may be made available on request where reasonably practicable.

22. Contact us

For privacy questions, rights requests or data-protection complaints, contact:

Privacy Lead
BuzzConnekt Business Solutions Ltd
211 Bell Avenue
Romford
England
RM3 7DB
Company number: 16030199
Registered in England and Wales