Privacy Policy
Last updated: 8 September 2026
1. Who we are
PixelNest AI is a trading name of Ash Parsa Limited, a company registered in England and Wales under company number 10408871, with its registered office at Flat 2 Kew House, 84 North Road, Brentford, England, TW8 0GJ.
In this policy, "PixelNest", "we", "us" and "our" refer to Ash Parsa Limited. "You" refers to the person reading this policy, whether you are a visitor to our website, a client business, or an individual whose data we process on a client's behalf.
For any question about this policy or about how your data is handled, contact us at info@pixelnest.ai.
2. What PixelNest does
PixelNest AI builds and operates AI messaging and voice systems for businesses, principally estate agencies and property developers. Our services include AI agents that hold conversations with a client's contacts over WhatsApp, AI voice agents that place and receive calls, automated lead reactivation campaigns, and integrations with a client's CRM.
This means we handle personal data in two different roles, and the distinction matters for your rights.
3. Controller and processor: which applies to you
Where we act as a data processor. When we operate an AI agent on behalf of a client business, that client decides what the agent is for, who it contacts, and what happens to the resulting data. The client is the data controller. We are the data processor, acting on their documented instructions under a data processing agreement.
If you received a WhatsApp message or a call from an AI agent we operate, the business whose name appeared in that conversation is the controller of your data. You may exercise your rights against them directly, or contact us and we will pass your request to them without undue delay.
By way of example, we act as processor for Cloud Nine Consulting, S.L. (trading as Cloud Nine Spain), which remains the data controller for enquiry data arising from messaging channels we operate on its behalf.
Where we act as a data controller. We are the controller for data about our own website visitors, prospective clients, client contacts and account administrators, and for business records such as contracts, invoices and correspondence.
4. Data we process on behalf of clients
Depending on the services a client has engaged us for, this may include:
- Contact identifiers: name, phone number, email address, WhatsApp profile name
- Message content: the full text of conversations between the AI agent and the contact, including inbound messages, agent responses, and any media exchanged
- Voice call data: call audio, transcripts generated from that audio, call duration and outcome
- Conversation metadata: timestamps, delivery and read status, language, message template used
- Enquiry data supplied by the contact: property requirements, budget range, location preferences, timescales
- CRM record data synchronised to or from the client's system, including lead status and history
- Technical data: message and session identifiers, phone number identifiers, error and delivery logs
We do not deliberately collect special category data. AI agents are configured not to solicit it. Because conversations are open-ended, a contact may volunteer such information unprompted. Where this occurs it is retained only as part of the conversation record and is not used for profiling or segmentation.
5. Lawful basis
As processor, the lawful basis for processing is determined by the client controller. Clients are contractually required to confirm they hold a valid basis, typically consent or legitimate interests, before any contact list is provided to us.
Opt-in. In addition, before any contact list is loaded into our systems, each client must obtain, and be able to evidence on request, opt-in from every contact to receive messages from that business on WhatsApp, in line with Meta's WhatsApp Business Messaging Policy. Clients confirm this to us in writing under their service agreement and we rely on that confirmation contractually. Where a client cannot evidence opt-in for a contact, that contact must not be included, and we suspend messaging to any list where opt-in is called into question.
As controller of our own data, we rely on:
- Contract, to deliver services to clients and administer accounts
- Legitimate interests, to operate and secure our website, improve service reliability, and communicate with business contacts about services they have enquired about
- Consent, for marketing communications where required, withdrawable at any time
- Legal obligation, for tax, accounting and statutory record keeping
6. WhatsApp Business Platform data
Our Meta application. The application we use to deliver WhatsApp services is PixelNest Messaging, Meta App ID 907370241744815, owned and operated by Ash Parsa Limited trading as PixelNest AI.
Where a client engages us to operate WhatsApp services, that client grants PixelNest Messaging access to their WhatsApp Business Account through Meta's authorisation process. This access is granted by the client, is limited to that client's own account and phone numbers, and can be revoked by them at any time from their Meta Business settings.
Platform Data. Information we receive from Meta or the WhatsApp Business Platform is "Platform Data" as that term is used in Meta's Platform Terms. This includes message content, phone numbers and profile names, message template records, and delivery, read and quality status data.
We access and use Platform Data solely to deliver the contracted service to the client it belongs to: sending and receiving messages, managing message templates, and reading delivery and quality status.
We do not, in relation to Platform Data:
- sell, licence, rent or otherwise transfer it to any third party for value
- transfer or make it available to data brokers, information brokers, ad networks, advertising or monetisation partners, or analytics or measurement products or services
- use it for advertising, ad targeting, audience building or any advertising-related purpose
- use it to train, fine-tune or improve any general-purpose AI or machine learning model
- attempt to re-identify de-identified or anonymised data, or combine Platform Data with data obtained from other sources, including data brokers or publicly scraped datasets
- use one client's Platform Data to benefit another client or for our own purposes
Deletion of Platform Data. We delete Platform Data when a client revokes PixelNest Messaging's access to their WhatsApp Business Account, when the engagement with that client ends, when Meta or the client instructs us to delete it, or when it is no longer needed for the permitted purpose for which it was received, whichever occurs first. Deletion from live systems is completed within 30 days, and deleted data persists only in encrypted backups until the 30 day backup cycle completes. Statutory records we are required to keep, such as invoices, do not contain Platform Data.
Platform Data is handled in accordance with Meta's Platform Terms, the Developer Policies and the WhatsApp Business Messaging Policy.
7. AI processing and disclosure
Conversations are generated by large language models. Message content and call transcripts are transmitted to our AI subprocessors to produce responses. We engage these providers under terms that prohibit training their models on our clients' data.
AI agents we operate always identify themselves as automated systems. This is a fixed characteristic of our agents and cannot be disabled or instructed away by a client. AI agents do not make decisions producing legal or similarly significant effects. Their function is to converse, qualify enquiries and route them to human staff at the client business.
8. Client separation
Each client's data is logically separated. Access controls are applied per client account, and our systems are configured so that data belonging to one client is not accessible to, or used in the service of, another.
9. Subprocessors
We use the following subprocessors. The specific providers engaged depend on which services a client has contracted.
| Purpose | Provider | Location |
|---|---|---|
| Messaging platform | Meta Platforms Ireland Ltd (WhatsApp Business Platform) | Ireland |
| Database and backend hosting | Supabase | European Union |
| Workflow orchestration | n8n | European Union |
| Website hosting | Lovable (Lovable Labs Incorporated) | United States / European Union |
| Business email, documents and internal CRM records | Google Ireland Ltd (Google Workspace) | European Union |
| Language model processing | Anthropic PBC | United States |
| Language model routing | OpenRouter, Inc. | United States |
| Voice agent infrastructure | VAPI | United States |
| Speech to text | Deepgram, Inc. | United States |
| Text to speech | ElevenLabs, Inc. | United States |
We also engage general IT, hosting, backup, security and technical support providers who may incidentally access personal data in the course of maintaining our systems. All such providers are engaged under written terms imposing confidentiality and data protection obligations equivalent to those in this policy.
A current subprocessor list is maintained and provided to clients on request. Clients are notified before a new subprocessor is added and may object on reasonable data protection grounds.
10. International transfers
From the EEA to the United Kingdom. The European Commission has adopted an adequacy decision for the United Kingdom, renewed in December 2025 and running until December 2031. Personal data may therefore be transferred from the EEA to us in the UK without additional safeguards such as standard contractual clauses. Our EU and Spanish clients need take no further steps for this transfer.
From the UK and EEA to the United States. Some of our AI subprocessors are established in the United States. These transfers are made under the European Commission's Standard Contractual Clauses together with the UK International Data Transfer Addendum, or, where the provider is certified under the EU-US Data Privacy Framework and its UK Extension, under that framework. We carry out and document a transfer risk assessment, referred to in UK legislation as a data protection test, for each such transfer, and apply supplementary technical and organisational measures including encryption in transit and contractual restrictions on onward disclosure.
Transfer documentation is available to clients on request.
11. Retention
- Conversation records and message content: 24 months from the date of the last message
- Call audio: 30 days, after which transcripts only are retained for 24 months
- Contact records: for the duration of the client engagement
- Campaign and reporting data: 24 months
- On termination of a client engagement: all client data is deleted or returned within 30 days, subject to any legal retention requirement
- Our own business records: six years, in line with UK statutory requirements
- Security and audit logs: 12 months
- Website analytics: 14 months
Clients may agree shorter or longer retention periods in their service agreement, which take precedence over the periods above.
Backups are encrypted and cycled on a rolling 30 day basis. Data deleted from live systems may persist in backups until that cycle completes. Restored backups are re-processed to remove data subject to a deletion request.
12. How to request deletion of your data
You can ask us to delete your data directly. You do not need to contact anyone else first, and you do not need an account with us.
Email info@pixelnest.ai with the subject line "Data deletion request", including:
- The phone number, WhatsApp number or email address concerned
- The name of the business you were in contact with, if you know it
- The approximate date of the conversation, if you know it
What happens next. We acknowledge every request within three working days and complete it within 30 days. We will:
- Delete the personal data we hold about you in our systems, including contact records, WhatsApp conversation history and media, voice call audio and transcripts, enquiry data, and campaign and delivery logs.
- Delete any Platform Data received from Meta or the WhatsApp Business Platform relating to you.
- Suppress your number so you are not contacted again in any future campaign.
- Where the data was processed on behalf of a client business acting as controller, pass your request to that business without undue delay and confirm to you that we have done so.
- Send you written confirmation once the deletion is complete.
Deletion is free of charge. Data removed from live systems may remain in encrypted backups until the rolling 30 day backup cycle completes, after which it is permanently gone; restored backups are re-processed to remove data subject to a deletion request. The only records we keep are invoices, contracts and accounting records required by UK law for six years, and security logs kept for 12 months, neither of which contain conversation content.
If you would prefer to remove our application's access yourself, or want the full step-by-step route, see our Data Deletion Instructions.
13. Your rights
Under UK GDPR and EU GDPR you have the right to access your data, to have inaccurate data corrected, to request erasure, to restrict or object to processing, to data portability, and to withdraw consent where processing relies on it.
Write to info@pixelnest.ai for any of these and we will respond within one month. Where we act only as processor, we will also pass your request to the client business that acts as controller, and you may contact them directly as well if you wish.
You may lodge a complaint with the UK Information Commissioner's Office at ico.org.uk, with the Agencia Española de Protección de Datos at aepd.es, or with the supervisory authority in your country of residence.
To stop receiving messages from an AI agent, reply STOP or BAJA to any WhatsApp message, or state during a call that you do not wish to be contacted. Opt-outs are actioned immediately and the number is suppressed from all future campaigns.
14. Security
We apply access controls on a least-privilege basis, encryption in transit and at rest, credential rotation, audit logging of system access, and separation of production from development environments. Access to client data is limited to personnel who require it to deliver the service.
No system is completely secure. We maintain an incident response process and will notify affected clients without undue delay, and in any event within 24 hours of becoming aware of a personal data breach, so they can meet their own notification obligations.
15. Website
Our website uses cookies for essential operation and, where you consent, for analytics. You can manage your preferences through the cookie banner or your browser settings.
Enquiry forms collect the contact details you provide, used only to respond to your enquiry and to communicate with you about our services. This data is retained for 24 months from your last contact with us.
16. Children
Our services are not directed at children. We do not knowingly process the data of anyone under 16. If you believe we hold such data, contact us and we will delete it.
17. Changes
We may update this policy to reflect changes in our services or legal obligations. Material changes affecting clients will be notified directly. The date at the top shows when this version took effect.
18. Contact
Ash Parsa Limited, trading as PixelNest AI Company number 10408871 (England and Wales) Registered office: Flat 2 Kew House, 84 North Road, Brentford, England, TW8 0GJ Email: info@pixelnest.ai Website: www.pixelnest.ai
