1. Introduction
This Privacy Policy explains how Fela Awolaja-Edwards, trading as Monoscope, collects, uses, and protects personal data as a data processor for our business customers (merchants) and their customers (callers).
- Data Processor: Fela Awolaja-Edwards, trading as Monoscope, 98 Rufford Tower, Lexden Road, Ealing, London, W3 9NF
- Contact: [email protected]
- ICO Registration Number: To be added once registration is complete
This policy complies with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
2. Our Role in Data Processing
Merchant data (direct relationship). The merchant is the Data Controller and Monoscope is the Data Processor. Merchants provide business data directly, and we process it only on their instructions to provide the AI receptionist and website services.
Caller data (indirect relationship).Our AI receptionist collects personal data from callers on behalf of merchants. The merchant is the Data Controller, Monoscope is the Data Processor, and the data subjects are the merchant's customers. Merchants retain full ownership and control over caller data.
3. Data We Collect
From merchants:
- Business name, address, and contact details
- Menu and product data
- Payment and billing information
From callers during AI receptionist interactions:
- Names, when provided
- Phone numbers, for callbacks and confirmations
- Order, booking, or enquiry details
- Special requirements such as allergies, dietary restrictions, or delivery instructions
- Call recordings and transcripts (see Section 5)
4. Lawful Basis for Processing
- Merchant data: Performance of a contract (Article 6(1)(b) UK GDPR). We process merchant data to perform our contractual obligations under the Monoscope service agreement.
- Caller data: Performance of a contract (Article 6(1)(b) UK GDPR). We process caller data on behalf of merchants to fulfil their contracts with their customers, such as taking bookings or processing orders.
5. Call Recording and Transcription
All calls answered by the Monoscope AI receptionist are recorded and transcribed.
Callers are notified at the start of each call. UK law (Privacy and Electronic Communications Regulations / Investigatory Powers Act) requires notification of call recording.
Call recordings are used for:
- Accuracy of bookings and orders
- Quality assurance and service improvement
- Dispute resolution
- Training and model refinement, using anonymised data only
Call recordings and transcripts are retained for 12 months unless legal requirements mandate longer retention.
Switcher statements
If you upload a "switcher statement" (a recent merchant invoice from your current transaction processor, or a business bank statement) via our quote form or Telegram, we use it solely to compare your current card processing rates and prepare your savings quote.
Statements are:
- Stored on Monoscope's own UK-based system, encrypted at rest with AES-256
- Never shared with third parties for marketing purposes
- Automatically and permanently deleted after 90 days
Upload is entirely optional: the quote form works without a statement, and you may withdraw consent at any time by contacting [email protected].
6. Sub-Processors
- AI processing. AI receptionist processing is performed within the United Kingdom on infrastructure controlled by Monoscope. Personal data is not transferred outside the United Kingdom for this purpose.
- Payment processing (Dojo). Card payment data is processed by Dojo (a trading name of Paymentsense Limited), which acts as an independent data controller/processor for payment transactions and has its own GDPR compliance regime and privacy policy. Monoscope does not control or access payment card data; this flows directly between the caller, the merchant, and Dojo. See dojo.tech/legal.
- Hosting and email (website only). The Monoscope marketing website is hosted by a cloud hosting provider, and transactional email relating to quotes and receipts is sent through an email delivery provider. Both act as processors under their own contracts and data processing terms. Neither processes AI receptionist call data.
- Other sub-processors. We do not engage additional sub-processors without prior written consent from merchants. Any changes will be notified 30 days in advance.
7. Data Security
We implement appropriate technical and organisational measures:
- Technical: encryption of data at rest and in transit (TLS 1.3), multi-factor authentication for admin access, regular security patches and updates, access logging and monitoring
- Organisational: access controls on a least-privilege basis, regular security audits, incident response procedures
8. Your Rights (for Merchants)
- Right of access (Article 15): request confirmation of whether we process your data and a copy of it
- Right to rectification (Article 16): request correction of inaccurate or incomplete data
- Right to erasure (Article 17): request deletion of your data, subject to legal retention requirements
- Right to restriction of processing (Article 18): request that we restrict processing in certain circumstances
- Right to data portability (Article 20): request your data in a structured, commonly used format
- Right to object (Article 21): object to processing based on legitimate interests
- Right to complain (Article 77):complain to the Information Commissioner's Office at ico.org.uk, 0303 123 1113, or Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
9. Caller Rights
Callers' data is controlled by the merchant. Callers should exercise their GDPR rights (access, correction, deletion, objection, and so on) by contacting the merchant directly. Monoscope will cooperate with merchants to fulfil legitimate data subject requests from callers.
10. Data Retention
- Merchant business data: 36 months after contract termination
- Caller records (names, phone numbers): 12 months after last interaction
- Call recordings and transcripts: 12 months
- Transaction logs: 12 months
- Account records: 36 months after contract termination
Longer retention may apply if required by law (for example tax, anti-money laundering, or dispute resolution).
11. International Data Transfers
We do not transfer personal data outside the UK. All processing occurs on UK-based infrastructure.
12. Data Breaches
If a personal data breach occurs that poses a risk to your rights and freedoms, we will notify you without undue delay and within 72 hours of becoming aware of the breach. We will also notify the ICO where required.
13. Children's Data
Our services are not intended for individuals under 18 years old. We do not knowingly collect personal data from children. If we discover we have collected such data, we will delete it immediately.
14. Cookies and Analytics
The Monoscope website does not set cookies and does not use tracking or analytics cookies. No personal data is collected through the website other than what you submit through the prospect and quote forms.
15. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify merchants of material changes by email and by updating the "Last updated" date on this page. Continued use of our services after changes constitutes acceptance of the updated policy.