Vlok Privacy Policy

Last updated: 1 August 2026

This Privacy Policy explains how Vlok Ltd (“Vlok”, “we”, “us” or “our”) collects, uses, shares and protects personal data in connection with:

This Privacy Policy applies to:

The Service is intended primarily for business clients and adult callers. It is not designed as a service directed at children.

1. Who we are

Vlok Ltd is a company registered in England and Wales.

Registered office:
The Oval
57 New Walk
Leicester
England
LE1 7EA

For privacy and data-protection enquiries, contact:

Email: support@vlok.ai

2. Our data-protection roles

Our role under data-protection law depends on why and how particular personal data is processed.

2.1 Where Vlok acts as a processor

When Vlok handles caller, guest and booking information to provide the Service for a restaurant or hospitality client:

In these circumstances, Vlok processes personal data on the client’s documented instructions and in accordance with the applicable Data Processing Agreement.

The client determines matters such as:

2.2 Where Vlok acts as an independent controller

Vlok acts as an independent controller where it decides the purposes and essential means of processing for its own business activities.

This may include processing for:

Vlok may therefore act as a processor and an independent controller in relation to different processing activities involving the same service.

Contractual descriptions do not override the roles determined by applicable data-protection law.

3. Personal data we collect

The personal data we process depends on how a person interacts with Vlok and the relevant restaurant.

3.1 Caller and guest information

We may process:

3.2 Call and communications information

We may process:

Call audio is not routinely retained unless call recording has been specifically enabled or is required for a particular feature, investigation or agreed service.

Where call audio is stored, callers will be provided with appropriate information where required.

3.3 Client and authorised-user information

We may process:

We do not normally receive full bank-account or card details where payments are handled directly by a regulated payment provider. We may receive payment references, mandate status and transaction information.

3.4 Website, enquiry and demonstration information

When someone uses our website, submits an enquiry or uses a demonstration, we may process:

We may use essential technologies required to operate, secure and maintain the website. We do not use this policy to authorise non-essential advertising cookies or consumer behavioural advertising.

3.5 Client materials and business information

Clients may provide:

General restaurant information is not usually personal data. It may become personal data where it identifies an employee, owner or other individual.

4. How we obtain personal data

We may receive personal data:

A caller may provide information about another guest. The caller should only provide information that is reasonably necessary to make or manage the booking.

5. How we use personal data when acting as a processor

When acting on behalf of a client, we may process personal data to:

The relevant client is responsible for identifying its lawful basis for this processing and providing required privacy information.

6. How we use personal data when acting as controller

Where Vlok acts as an independent controller, we may use personal data for the following purposes.

6.1 Client account and contract management

We use client and authorised-user information to:

6.2 Billing and financial administration

We use information to:

6.3 Customer service

We may use information to:

6.4 Security, fraud prevention and misuse monitoring

We may process personal data to:

6.5 Manual review of interactions

Authorised Vlok employees and contractors may manually review selected call transcripts, interaction records and, where enabled, call audio.

Manual review may be carried out for:

Access is limited to personnel who require it for their role and who are subject to confidentiality and security requirements.

We aim to limit the information displayed during review and may mask, remove or reduce direct identifiers where reasonably practicable.

6.6 AI development, training and improvement

Vlok may use eligible call transcripts, interaction records, booking-flow information, corrections and feedback to:

For this activity, Vlok may act as an independent controller because Vlok determines the separate purpose of developing and improving its technology.

Before using data for general AI development, Vlok may take steps including:

Pseudonymised information remains personal data where it can still be linked to an individual using additional information.

We do not use allergy information, health information or other special-category personal data to train or improve general Vlok AI models.

Where technically practicable, such information will be filtered, removed, masked or excluded before a dataset is used for general model training.

Information may still be processed temporarily to:

6.7 Analytics and service development

We may use service and interaction data to:

Where information has been genuinely anonymised so that no person is identifiable or reasonably re-identifiable, it is no longer personal data. We may retain and use such anonymised information indefinitely.

7. Special-category information

Some information provided during a restaurant interaction may constitute special-category personal data.

This may include:

Special-category information receives additional protection.

7.1 How special-category information is used

We may process this information to:

When Vlok processes this information on behalf of a restaurant, the restaurant is responsible for identifying the applicable lawful basis and special-category condition.

Vlok does not independently verify restaurant allergen or ingredient information.

The restaurant is responsible for:

The Service may direct a caller to restaurant staff rather than provide a definitive automated answer.

7.2 Exclusion from general AI training

We do not intentionally use allergy, medical or other special-category personal data to train general Vlok AI models.

We use technical and organisational measures designed to identify and remove this information from general training datasets where reasonably practicable.

No automated filtering method is guaranteed to identify every sensitive statement. Access controls, dataset review and incident procedures are therefore also used where appropriate.

8. Our lawful bases

The lawful basis depends on the particular activity.

8.1 Processor activities

Where Vlok acts as a processor, the relevant client determines the lawful basis for the underlying processing.

Vlok processes the information under its contract and Data Processing Agreement with that client.

8.2 Contract

We may rely on contractual necessity where processing is required to:

Where the client is a company, we may instead rely on legitimate interests to process the details of its employees and representatives.

8.3 Legitimate interests

We may rely on our legitimate interests where necessary and where those interests are not overridden by an individual’s rights.

Our legitimate interests may include:

When relying on legitimate interests for AI training or development, we consider factors including:

We may decide not to use particular data where the impact on an individual outweighs our interests.

8.4 Legal obligations

We may process personal data where necessary to:

8.5 Legal claims

We may process and retain information where necessary to establish, exercise or defend legal claims.

8.6 Consent

We may rely on consent where required for a particular optional activity.

Where we rely on consent, it may be withdrawn at any time. Withdrawal does not affect processing carried out before consent was withdrawn.

9. Third-party AI, telecommunications and infrastructure providers

We use service providers to operate and develop the Service.

These currently include:

9.1 OpenAI

OpenAI technology may be used for AI language processing, generating responses, classifying requests and supporting service or model-development functions.

Depending on the particular service configuration, relevant interaction content may be transmitted to OpenAI for processing.

9.2 Twilio

Twilio may be used for:

9.3 ElevenLabs

ElevenLabs may be used for:

9.4 Other providers

We may also use providers of:

Providers may change as the Service develops.

Where a provider processes personal data on our behalf, we require appropriate contractual, confidentiality, security and data-protection commitments.

Where possible and appropriate, we configure third-party AI providers so that submitted content is not used by the provider to train its general models.

However, provider-specific handling may depend on:

We assess relevant provider terms and safeguards before using providers for material personal-data processing.

10. Who we share personal data with

We may share personal data with:

We only share information where reasonably necessary for the relevant purpose or where required by law.

Where a business sale, merger, investment or restructuring is being considered, information may be disclosed under appropriate confidentiality restrictions.

11. International transfers

Some of our providers may process personal data outside the United Kingdom.

The countries and service locations used by Vlok may change as providers, infrastructure and business requirements develop.

Where a transfer is a restricted transfer under UK data-protection law, we will use an applicable transfer mechanism where required, which may include:

Where required, we may assess the laws and practices of the destination country and implement supplementary contractual, organisational or technical safeguards.

Individuals may contact us for further information about safeguards applicable to relevant transfers.

12. Data retention

We retain personal data for no longer than we reasonably need it for the relevant purposes, including service delivery, AI development, security, dispute handling and legal compliance.

The periods below are maximum or typical periods. Information may be deleted sooner where it is no longer required.

We may retain information longer where:

12.1 Call transcripts and interaction logs

Call transcripts and identifiable interaction logs may generally be retained for up to 24 months for:

Selected transcripts required for a documented dispute, safety investigation, legal claim or serious service issue may be retained for up to six years after the relevant matter is closed or the contractual relationship ends, where reasonably necessary.

12.2 AI development datasets

Eligible personal data selected for AI development may be retained for up to five years where Vlok has documented an ongoing development, testing, safety or evaluation purpose.

Before or during this period, Vlok will seek to remove direct identifiers and exclude known special-category information where reasonably practicable.

Datasets will be reviewed periodically. Data that is no longer reasonably required will be deleted or further anonymised.

Genuinely anonymised AI-development and statistical data may be retained indefinitely.

12.3 Call audio

Where call audio is stored, it will generally be retained for no longer than 12 months, unless:

12.4 Booking and guest records

Booking and guest records may be retained for the duration of the client relationship and for up to 24 months afterwards for:

Records relevant to a legal claim, payment issue or regulatory matter may be retained for up to six years or longer where legally required.

12.5 Allergy and special-category information

Identifiable allergy, health and other special-category information will be retained only for as long as reasonably required to:

Unless a longer period is required for a specific incident or lawful client instruction, we aim not to retain this information in identifiable transcripts or operational records for longer than 12 months.

It is excluded from general AI-training datasets.

12.6 SMS and communications records

SMS delivery records and communication logs may be retained for up to 24 months.

Support correspondence and complaint records may be retained for up to six years after the matter is closed where reasonably necessary to maintain business records or defend claims.

12.7 Client account and contract records

Client account, contract, onboarding and acceptance records may be retained for the duration of the relationship and for up to six years afterwards.

12.8 Billing and accounting records

Invoices, payment records and accounting information may be retained for up to six years after the end of the relevant financial year, or longer where required by applicable tax or accounting law.

12.9 Security records

Security, access and audit logs may be retained for up to 24 months.

Records relating to confirmed or suspected fraud, abuse, unauthorised access or security incidents may be retained for up to six years after the incident is resolved.

12.10 Backups

Information may remain in encrypted or access-restricted backups for a limited period after deletion from active systems.

Backups are overwritten or deleted according to our backup cycle and are not ordinarily restored except for disaster recovery, security or legal requirements.

13. Security

We use technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or unauthorised access.

Measures may include:

No internet, telecommunications or AI system can be guaranteed to be completely secure.

Clients and authorised users are responsible for maintaining the confidentiality of their login credentials and notifying Vlok promptly of suspected unauthorised access.

14. Automated processing and decision-making

The Service uses AI and automated processing to:

Booking outcomes may depend on:

The Service is not intended to make solely automated decisions that produce legal or similarly significant effects on individuals.

A person may request staff assistance or contact the relevant restaurant where:

15. Children’s personal data

The Service is not directed at children and is intended to be used primarily by adults arranging restaurant bookings.

A booking may include information about a child, such as:

Callers should not provide more information about a child than is reasonably necessary.

We do not knowingly use children’s personal data or children’s special-category data for general AI training.

Where we become aware that unnecessary children’s information has been collected, we may delete, restrict or minimise it.

16. Individual rights

Depending on the circumstances and applicable law, individuals may have the right to:

These rights are not absolute and may be subject to legal exceptions.

16.1 Requests concerning restaurant booking data

Where Vlok processes booking or caller data solely on behalf of a restaurant, the individual should normally contact that restaurant directly.

Vlok will assist the restaurant in responding where required by the Data Processing Agreement and applicable law.

To help identify the relevant client, a person contacting Vlok should provide:

16.2 Requests concerning Vlok-controlled data

Where Vlok acts as controller, individuals may contact:

support@vlok.ai

We may need to verify identity before responding.

16.3 Objections to AI training and improvement

Individuals may object to Vlok using their identifiable personal data for AI development or training where that processing is based on legitimate interests.

We will assess the objection and stop the relevant processing unless:

Where reasonably possible, we may instead remove identifiers, exclude the interaction from future training use or convert the information into an anonymised form.

17. Complaints

Individuals may contact us first so that we can investigate a privacy concern.

They also have the right to complain to the UK Information Commissioner’s Office.

Contacting Vlok first is not a requirement before making a complaint to the Information Commissioner.

18. Data breaches

Vlok maintains procedures designed to identify, investigate, contain and respond to personal data breaches.

Where Vlok acts as a processor, we will notify the relevant client without undue delay after becoming aware of a personal data breach affecting that client’s data.

Where Vlok acts as a controller, we will notify affected individuals and the Information Commissioner where required by law.

19. Data Processing Agreement

Where Vlok processes personal data on behalf of a client, that processing is governed by a separate Data Processing Agreement or Data Processing Schedule forming part of the contract between Vlok and the client.

The Data Processing Agreement covers matters including:

This Privacy Policy does not replace the Data Processing Agreement.

20. Client responsibilities

Restaurants and hospitality clients acting as controllers are responsible for:

Vlok may provide an automated disclosure stating that a caller is interacting with an AI system and that the interaction may be transcribed or processed.

Clients must not disable or circumvent disclosures required for legal, safety or transparency purposes.

21. Business transfers

If Vlok is involved in a merger, acquisition, investment, restructuring, financing, sale of assets or similar transaction, personal data may be disclosed to relevant parties and advisers subject to appropriate confidentiality and data-protection safeguards.

Personal data may be transferred to a successor organisation where permitted by law.

22. Changes to this Privacy Policy

We may update this Privacy Policy to reflect:

We will publish the revised version and update the “last updated” date.

Where a change materially affects how we use personal data, we will provide additional notice where required or appropriate.

A change to this Privacy Policy does not remove any rights that individuals have under applicable law.

23. Contact us

For privacy or data-protection enquiries, contact:

Vlok Ltd
The Oval
57 New Walk
Leicester
England
LE1 7EA

Email: support@vlok.ai