Data Protection Policy

Ambitions Web Ltd (trading as Ambitions AI and CXSolved.AI) -- Company No. 15387454

Updated: 9 April 2026

1. Introduction

Ambitions Web Ltd (trading as Ambitions AI and CXSolved.AI) is dedicated to protecting personal data and respecting privacy. This Data Protection Policy outlines how we handle personal data in compliance with the UK General Data Protection Regulation (UK GDPR) and relevant US data protection laws. We take privacy seriously, leveraging advanced technology -- including our proprietary AI tools -- to deliver secure, cutting-edge services like AI voice assistants for customer service and sales.

2. Scope

This policy covers all services operated by Ambitions Web Ltd across both its Ambitions AI and CXSolved.AI brands, including AI voice and conversation systems operated on behalf of clients. In these cases, Ambitions Web Ltd acts as a data processor, processing personal data under the instruction of the client as data controller. It covers collection, processing, storage, sharing, and security. All employees, freelancers, and contractors must follow this policy.

3. Data We Collect

We collect and process:

  • Website Leads: Names and business email addresses.
  • Client Data: Names, email addresses, phone numbers, and home addresses (as provided by clients).
  • End-User Conversation Data: Where we operate AI voice or conversation systems on behalf of clients, end users of those systems (i.e., the client's customers) may share personal data during interactions -- such as names, addresses, and booking details. This data is processed solely on behalf of and under the instruction of the client, and is not used for any other purpose.
  • No Sensitive Data: We don't collect highly sensitive personal data (e.g., health or financial details) unless explicitly required and agreed.

4. Data Collection and Storage

Collection: Data is gathered via website forms with user consent, or provided by clients under their lawful basis. End-user conversation data is collected solely through systems operated on behalf of clients, under their instruction.

Storage: Data is securely stored in:

  • GoHighLevel: Our cloud-based CRM for client data management.
  • Amazon Web Services (AWS): Where we host our proprietary AI tools, designed to enhance and optimise interactions between GoHighLevel and RetellAI.
  • RetellAI: For real-time AI voice processing.
  • Supabase: For secure storage of AI conversation data.
  • Make.com: For workflow automation linking systems.

Retention: Our own client data (e.g., business emails) is kept indefinitely. Data processed for clients -- including end-user conversation data -- is retained for up to six months, then securely deleted, unless clients instruct otherwise.

5. Data Security Measures

We protect personal data with:

  • Access Controls: Limited to authorised personnel.
  • Encryption: TLS 1.2+ in transit, AES-256 at rest across GoHighLevel, AWS, RetellAI, and Supabase.
  • Password Security: Hashed and encrypted per industry standards.
  • Two-Factor Authentication (2FA): Enabled across all our systems.
  • Advanced Infrastructure: Our proprietary AI tools on AWS are built with rigorous security protocols.
  • Audits: Regular reviews of systems and sub-processors for vulnerabilities.
  • Software Updates: Immediate patching and anti-malware defences.

6. Data Breach Response

If a breach occurs:

  • We investigate and assess its scope promptly.
  • We notify the client (controller) within 24 hours with details and mitigation steps.
  • We assist the client in notifying affected individuals or the ICO as instructed, acting independently only if legally required, with immediate client notice.
  • We implement fixes to prevent recurrence.

7. Data Subject Rights

Under UK GDPR and US laws, individuals can access, correct, or delete their data, request portability or withdraw consent. Submit requests to our Data Protection Officer (DPO), Nicholas Burrage, at hello@theambitionsagency.com -- we respond within 7 days. Clients handle their customers' requests, and we assist with data from our systems as needed.

8. Legal Basis for Processing

  • Our Leads: Consent via website forms.
  • Client Data: Processed under client instructions (as controller), assuming their lawful basis (e.g., consent or legitimate interest). We don't process data beyond agreed purposes.
  • End-User Conversation Data: Processed under client instructions as data processor. We do not determine the purpose or means of processing this data.

9. International Data Transfers

Data may transfer to the US via GoHighLevel, Make.com, RetellAI, Supabase, and our AWS-hosted AI tools. These transfers comply with the UK-US Data Bridge (effective October 2023), ensuring UK GDPR standards. No EU GDPR processing occurs, as we don't operate in the EU.

10. Sub-Processors

We use the following sub-processors:

  • GoHighLevel: CRM and storage.
  • Make.com: Workflow automation.
  • RetellAI: AI voice functionality.
  • Supabase: AI conversation storage.
  • AWS: Hosting our proprietary AI tools.

Where we operate AI voice or conversation systems for clients, relevant sub-processors (including RetellAI and Supabase) handle end-user conversation data on our behalf, under appropriate data processing agreements. Clients are notified of sub-processor changes per our agreements, with no data used for AI training unless explicitly permitted by the client.

11. Cookies and Tracking

We use Google and Facebook cookies for analytics on our sites. A cookie policy informs users and secures consent for non-essential cookies, adjustable via settings.

12. ICO Registration

Ambitions Web Ltd is registered with the Information Commissioner's Office (ICO) -- the UK's independent body for data rights and information privacy. This registration reflects our legal responsibilities under UK GDPR.

Registration number: ZB804022
View our ICO registration

13. Policy Updates and Compliance

We review this policy as needed to stay compliant with evolving laws and best practices. Updates are shared with stakeholders.

14. Contact Information

Nicholas Burrage (Data Protection Officer)
80 Magdalen Road, Exeter, Devon, EX2 4TT
Email: hello@theambitionsagency.com
Phone: 01752 830000