GDPR & data protection

How CANDAI handles personal data from website assistants and the CRM — practical, not legal advice.

What data we process

When a visitor uses the bot, typical fields include name, phone, address, email (optional), product interest, answers used for qualification, consent flag, and any photos they upload. That data is stored in the CRM and may be emailed to the client company and to platform alert addresses.

Lawful basis

Enquiries are taken with clear consent language in the flow before submission. Clients remain responsible for how they use leads after delivery. CANDAI processes data to provide the platform and to support the client’s sales process.

Company isolation

Each client company only sees its own leads and customers in the CRM. Platform owners can administer the system; company users cannot access another firm’s data.

Retention & rights

Clients should only keep data as long as needed for sales and legal purposes. Data subject requests (access, erasure, correction) can be handled via the client and, where the data sits on CANDAI systems, via support@candai.co.uk.

Security basics

Access is login-controlled. Destructive actions such as permanent delete are restricted to the platform owner. Email delivery uses the configured SMTP account. When the CRM is hosted publicly, HTTPS and strong passwords are required.

Photos

Optional photos uploaded in the bot are stored against the lead to help the survey or sales call. They should not include unnecessary third-party personal data.

Contact us