Skip to main content

Security, GDPR + Compliance

UK data centres only. AES-256 encryption at rest, TLS 1.3 in transit. Full Data Processing Agreement provided to every client. ICO registered. PECR compliant. The compliance details UK estate agencies need before signing up.

Data residency: UK only

All data processed and stored by Luxo AI — call recordings, transcripts, caller details, calendar bookings, and CRM data — is held exclusively in UK data centres. No data leaves the United Kingdom for any reason. Our telephony provider (Twilio) is configured to UK regions only. Our database infrastructure is hosted in UK regions only. Sub-processors (where applicable) are bound by the same UK-only residency requirement.

Encryption

  • At rest: AES-256 encryption on all stored data (call recordings, transcripts, dashboard data, customer records)
  • In transit: TLS 1.3 for all network traffic between client, Luxo infrastructure, and integrations
  • Key management: Encryption keys rotated quarterly; managed via cloud KMS with hardware security module backing

GDPR + UK data protection compliance

  • ICO Registration: 00013961957 (Information Commissioner's Office)
  • Data Processing Agreement (DPA): Full DPA provided to every client at onboarding
  • Lawful basis: Contract performance + legitimate interest, depending on the data type
  • Right to erasure: All client data purged within 30 days of cancellation or caller request
  • Data minimisation: Only the data needed to qualify the call and book the appointment is captured
  • Subject Access Requests (SAR): Supported via luxoai.agency@gmail.com
  • Breach notification: 72-hour ICO + client notification commitment per UK GDPR Article 33

PECR (Privacy and Electronic Communications Regulations)

Luxo AI does not initiate marketing calls. Ava only answers calls dialled into the agency's forwarded phone number. There is no outbound calling, no SMS marketing, no email marketing run from the Luxo platform. TPS (Telephone Preference Service) and CTPS compliance is therefore not applicable to call handling — Luxo is an inbound-only service.

Call recordings + caller consent

Calls are recorded by default for training, quality, and audit purposes. The agency configures their preferred caller consent disclosure at setup — standard estate-agency pattern: "Calls may be recorded for training and quality purposes."

Recordings are stored encrypted (AES-256), accessible only to authorised users of the agency's dashboard. Default retention: 12 months. Retention can be reduced on request. Callers may request recording deletion via the agency at any time.

Access controls

  • Per-user authentication on the dashboard (email + password + optional MFA)
  • Role-based access: admin, manager, agent — different visibility levels
  • Session timeouts: 60-minute idle logout
  • Audit logs for all data access and modification
  • Sub-processor access strictly limited via formal data processing arrangements

Infrastructure security

  • WAF (Web Application Firewall) + DDoS protection on all public endpoints (Vercel + Cloudflare)
  • Continuous vulnerability scanning + monthly patching cadence
  • Encrypted database backups with 30-day retention
  • Geo-redundant failover within UK regions
  • 99.9% uptime SLA target
  • Incident response runbook with 24/7 founder on-call

Want the full DPA before signing up?

Email luxoai.agency@gmail.com or book a walkthrough — we'll send the DPA + answer any compliance questions.

Book your demo →