Legal
Privacy Policy
Last updated 11 August 2026.
1. Who we are
Camigo provides AI-assisted customer messaging and verification software to businesses. We are Camigo Ltd, registered in England & Wales under company number 17397233, registered office 492 Harrow Road, London W9 3QA. You can reach us at hello@camigo.ai. Our ICO registration is [to be completed — application in progress].
2. Two different roles
Which one applies to you changes who is responsible for your data.
| Situation | Our role |
|---|---|
| You visit camigo.ai, enquire, or sign up as a customer | Controller. We decide how your data is used and this policy governs it. |
| You are a customer of a business that uses Camigo, and you message them | Processor. That business is the controller. We handle your messages only on their instructions — contact them first, and we will support them in answering you. |
3. What we collect
If you are our customer
- Account details: name, business name, email, phone number, and a password stored only as a hash.
- Billing details: billing address, VAT number, plan and invoice history. Card details are handled by Stripe and never stored by us.
- Usage data: conversation volumes, feature use, log and diagnostic data, IP address.
If you message a business that uses Camigo
- The content of your messages and the replies sent to you.
- Your channel identifier — WhatsApp number, Instagram or Facebook handle, or email address — and display name where the channel provides one.
- Timestamps and message metadata needed to deliver and thread the conversation.
If you are verified through Camigo Verify
- The phone number or email address being verified, the channel used, and whether the code was delivered and entered.
- We do not retain the code itself after the verification completes or expires.
Please don't send card numbers, passwords or identity-document numbers over messaging. Camigo is designed never to ask for them.
4. Why we use it, and our lawful basis
| Purpose | Lawful basis |
|---|---|
| Providing the service — receiving, routing and answering messages, sending verification codes | Performance of a contract |
| Billing, invoicing and collecting payment | Contract; legal obligation |
| Security, fraud prevention and abuse monitoring | Legitimate interests |
| Improving reliability and answer quality | Legitimate interests |
| Marketing emails to business contacts | Legitimate interests, with an unsubscribe link in every message |
| Meeting accounting, tax and legal duties | Legal obligation |
5. AI processing
Camigo uses large language models supplied by Anthropic to draft replies. Message content is sent to Anthropic's API for that purpose under a commercial agreement. We do not use your conversations, or your customers' conversations, to train third-party foundation models, and our agreement with Anthropic does not permit them to be used for that purpose either.
Camigo identifies itself as an AI and does not pretend to be a human. Businesses using Camigo can read every conversation and take over at any point.
6. Who we share it with
| Sub-processor | What for | Where |
|---|---|---|
| Anthropic | AI processing of message content | USA / EU |
| Meta Platforms | WhatsApp, Instagram and Facebook message delivery | USA / EU |
| Stripe | Payments and subscription billing | USA / EU |
| Railway | Application hosting and database | [region to be confirmed] |
| Netlify | Website hosting | USA / global CDN |
| Speech and telephony providers | Voice calls and verification | [to be completed] |
We do not sell personal data and we do not share it with advertisers.
7. International transfers
Where personal data goes outside the UK or EEA, we rely on the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, or on an adequacy decision where one is in force.
8. How long we keep it
- Conversation content: for as long as the business's account is active, then deleted within [30/90 days — to be confirmed] of closure. Businesses can set a shorter period.
- Verification records: [to be confirmed]. Codes themselves are not retained past expiry.
- Account and billing records: six years, to meet UK accounting and tax requirements.
- Security and diagnostic logs: [90 days — to be confirmed].
9. Your rights
Under UK GDPR you can ask for access to your data, correction, erasure, restriction, objection, or portability. Where we rely on consent you can withdraw it at any time. Email hello@camigo.ai and we'll respond within one month. If you're a customer of a business that uses Camigo, please contact that business — they control your data.
You can also complain to the Information Commissioner's Office at ico.org.uk.
10. Security
Data is encrypted in transit with TLS. Channel access tokens and other credentials are encrypted at rest. Access to production is limited to those who need it and is logged. We will notify affected businesses, and the ICO where required, within 72 hours of becoming aware of a reportable breach.
11. Cookies
This site uses only what is strictly necessary to serve the page. If we add analytics or advertising cookies later we'll ask for your consent first and update this policy.
12. Children
Camigo is a business tool, not directed at children, and we do not knowingly collect data from anyone under 16.
13. Changes
If we make a material change we'll email account holders and update the date at the top.