Privacy Policy
This Privacy Policy explains how Lion’s Point Ltd ("Relai", "we", "us") collects, uses, shares and protects personal data in connection with the Relai website at relaioffice.com and the Relai AI SDR platform (together, the "Service"). It applies to visitors to our website, to the individuals at our business customers, and to the individuals whose personal data those customers process using Relai.
1. Who we are
The Service is provided by Lion’s Point Ltd, a company registered in England and Wales under company number 14468027, with its registered office at 8 Rosary Gardens, London SW7 4NT, United Kingdom. For the purposes of UK GDPR and, where applicable, EU GDPR, our contact point for data protection matters is privacy@relaioffice.com.
2. Our two roles: controller and processor
Relai handles personal data in two distinct capacities, and different parts of this policy apply to each:
- As a controller. When we decide why and how personal data is processed — for example, data about our website visitors, prospective customers, the individual users at our customers, and billing contacts — we act as the controller. Sections 3 and 5–15 describe this processing.
- As a processor. When our business customers use Relai to process personal data about their own leads and contacts (the "Customer Data"), the customer is the controller and Relai is the processor, acting only on that customer's instructions. That relationship is governed by our Data Processing Agreement; Section 4 summarises it.
3. Personal data we collect (as controller)
- Account data: name, work email, password (stored only as a salted hash), company, role, and user preferences.
- Billing data: billing contact details, plan, and transaction records. Card details are collected and stored by our payment processor (Stripe), not by us.
- Usage & technical data: log data, IP address, device and browser information, feature usage and diagnostic events, used to operate, secure and improve the Service.
- Communications: messages you send us (support, sales, feedback) and records of those interactions.
- Website & cookie data: see Section 12.
4. Customer Data we process (as processor)
When a customer connects their systems and uses Relai to work their leads, we process personal data on their behalf. Depending on the channels and integrations the customer enables, this may include:
- Contact and CRM records (names, email addresses, phone numbers, lead and deal information, notes);
- The content of conversations Relai handles or drafts across WhatsApp, email and telephone, including message text, call audio and call transcripts;
- Calendar events and meeting details;
- Any personal data the customer or their contacts choose to include in those communications.
We process Customer Data only to provide the Service and only on the customer's documented instructions, as set out in the Data Processing Agreement. The customer is responsible for establishing a lawful basis for their processing and for honouring the rights of their contacts.
5. How we use personal data, and our legal bases
Where we act as controller, we rely on the following legal bases under UK/EU GDPR:
| Purpose | Legal basis |
|---|---|
| Providing, operating and supporting the Service; managing accounts | Performance of a contract |
| Billing, collecting payments and preventing fraud | Performance of a contract; legitimate interests; legal obligation |
| Securing the Service, monitoring for abuse, and keeping logs | Legitimate interests (security) |
| Improving and developing the Service (aggregated/usage analysis) | Legitimate interests |
| Sending service and transactional messages | Performance of a contract; legitimate interests |
| Marketing to prospective and existing customers | Consent, or legitimate interests where permitted |
| Complying with law and responding to lawful requests | Legal obligation |
You can object to processing based on legitimate interests, and withdraw consent at any time, as described in Section 11.
6. AI processing
Relai uses large language models to read context and generate messages, insights and summaries. To do this, relevant content — such as a lead's message and the surrounding conversation and CRM context — is sent to our AI subprocessor (Anthropic) for processing and a response is returned. Under Anthropic's commercial terms, data submitted through their API is not used to train their models. Relai does not use Customer Data to train any third party's models. AI outputs may contain errors; the Service is designed to keep a human in control of important actions, and customers remain responsible for reviewing AI output before it is relied upon.
7. Sharing and subprocessors
We do not sell personal data. We share it only with the service providers ("subprocessors") that help us run the Service, each under a contract that requires appropriate protection. The subprocessors we currently rely on are:
| Subprocessor | Purpose | Data involved | Location |
|---|---|---|---|
| Anthropic, PBC | AI conversation, drafting & insight generation | Message and lead context submitted for processing | USA |
| HubSpot, Inc. | CRM connectivity (the customer's system of record) | Contact & CRM records | USA / EU |
| 360dialog GmbH | WhatsApp Business Platform provider (BSP) | WhatsApp messages, phone numbers | Germany (EU) |
| Meta Platforms | WhatsApp message delivery | WhatsApp messages, phone numbers | EU / USA |
| Twilio Inc. | Telephony, call recording & transcription (Voice Intelligence) | Call audio, transcripts, phone numbers | USA |
| Aurinko, Inc. | Unified email & calendar connectivity (when enabled) | Email content, calendar events | USA |
| Google LLC | Gmail & Google Calendar (when a customer connects them) | Email & calendar content | USA / EU |
| Microsoft Corp. | Outlook / Microsoft 365 (when a customer connects them) | Email & calendar content | USA / EU |
| Stripe, Inc. | Subscription billing & payment processing | Billing contact and transaction data (card data held by Stripe) | USA / Ireland |
| Amazon Web Services (AWS) | Application hosting, storage & backups | All processed data, at rest | UK / EU |
This list is indicative and may change as the Service evolves; the current list of subprocessors is available on request at privacy@relaioffice.com. We may also disclose personal data where required by law, to enforce our terms, or in connection with a corporate transaction, subject to appropriate safeguards.
7a. Google user data and Limited Use
When a customer connects a Google account, Relai requests only the minimum access it needs: to send email on the user's behalf (the gmail.send scope) and to read and manage their calendar (the calendar scope). Relai does not read the contents of your Gmail inbox — we do not request gmail.readonly or any other mailbox-reading scope. Replies from a lead are captured only when the lead replies to a message Relai sent, via a dedicated reply address, never by scanning your mailbox.
Relai's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular: we use Google user data only to provide and improve the user-facing features described above; we do not transfer or sell it to third parties except as necessary to provide the Service or as required by law; we do not use it for advertising; we do not allow humans to read it except with your explicit consent, for security or legal reasons, or where the data has been aggregated and anonymised; and we do not use Google user data to develop, improve or train generalised artificial-intelligence or machine-learning models.
8. International transfers
Some of our subprocessors are located outside the UK/EEA, including in the United States. Where personal data is transferred outside the UK/EEA, we rely on appropriate safeguards — such as the UK International Data Transfer Agreement or Addendum, the EU Standard Contractual Clauses, and/or reliance on the EU–US Data Privacy Framework where a provider is certified — together with additional measures where needed. You can request more information about the safeguards in place at privacy@relaioffice.com.
9. Data retention
We keep personal data only for as long as necessary for the purposes described in this policy, or as required by law. Account and billing records are retained for the life of the account and for a reasonable period afterwards to meet legal and accounting obligations. Customer Data is retained and deleted in accordance with the customer's instructions and the Data Processing Agreement; on termination we delete or return Customer Data as set out there. Specific retention periods should be confirmed with your solicitor.
10. Security
We take appropriate technical and organisational measures to protect personal data, including encryption in transit, role-based access controls, hashed passwords and audit logging. Our Security Overview describes these measures in more detail. No system is perfectly secure, and we cannot guarantee absolute security.
11. Your rights
Subject to conditions and exemptions under UK/EU GDPR, you have the right to: access your personal data; have it corrected or erased; restrict or object to its processing; data portability; and to withdraw consent where processing is based on consent. To exercise any of these rights in respect of data for which Relai is the controller, contact privacy@relaioffice.com. Where Relai processes data as a processor on a customer's behalf, please direct your request to that customer (the controller); we will assist them as required by the Data Processing Agreement.
12. Cookies
Our website uses only the cookies strictly necessary to operate it and, where you consent, a limited set of analytics cookies to understand usage. You can control non-essential cookies through the cookie banner and your browser settings. Where you accept analytics cookies via our cookie banner, we use Google Analytics and Microsoft Clarity to understand how the site is used; you can decline these at any time. We do not use third-party advertising cookies.
13. Children
The Service is a business tool and is not directed to children. We do not knowingly collect personal data from anyone under 16.
14. Changes to this policy
We may update this policy from time to time. We will post the updated version here with a new "last updated" date and, where changes are material, take reasonable steps to notify you.
15. Contact and complaints
For any privacy question or request, contact privacy@relaioffice.com or write to us at 8 Rosary Gardens, London SW7 4NT, United Kingdom. If you are in the UK and are unhappy with how we have handled your data, you have the right to complain to the Information Commissioner's Office (ICO) at ico.org.uk. If you are in the EEA, you may complain to your local supervisory authority.