Privacy Policy

Last updated: 9th August 2026

Sonic Blue Tech Ltd ("Handled", "we", "us", "our"), company number 12789740, registered office The Old Dairy, Redhill, Surrey, RH1 5LN, is committed to protecting your privacy. This policy explains how we collect, use, and protect personal data.

This policy has two audiences, because Handled plays two different roles depending on who you are:

  • If you're a business subscribed to Handled (or considering subscribing), this policy explains what we do with your data as a data controller.

  • If you're someone chatting with a SalesBot or SupportBot widget on one of our clients' websites, the business you're talking to is the data controller of your data, and Handled processes it on their instructions as a data processor, under a separate Data Processing Agreement with that business. For questions about your data in that case, please contact the business directly. This policy explains our own role and safeguards as their processor.

1. Who we are

Sonic Blue Tech Ltd, trading as Handled. datasecurity@handled.support

2. What data we collect (as controller, from our subscribers)

  • Account information: name, email address, business name and details.

  • Billing information, processed via Stripe (we do not store full card details ourselves).

  • Usage data: how you use the dashboard, widget configuration, conversation volumes and categories, for the purpose of providing and billing the Services.

  • Communications you send us (e.g. support requests, sales enquiries handled via our own SalesBot/SupportBot widget).

3. What data we process (as processor, on behalf of our clients)

When a business uses SalesBot or SupportBot, personal data provided by their customers during a chat (such as name, contact details, and the conversation itself) is processed by us on that business's instructions. We do not use this data for our own purposes, and access to it is structurally isolated per business. No business can access another's data.

4. Legal basis for processing

  • Contract to provide the Services you've subscribed to.

  • Legitimate interests to maintain and improve the Services, prevent abuse, and communicate with you about your account.

  • Consent for optional communications, such as marketing, where required.

  • Legal obligation where we're required to retain or disclose data by law.

5. Who we share data with

  • Stripe, for payment processing.

  • HubSpot or Moonstride, where you've connected a CRM, to create records on your instruction.

  • Slack, where you've connected a workspace, to deliver escalation notices.

  • Anthropic, whose Claude models power the Services' AI capabilities.

  • Render, for application hosting.

  • Supabase, for database infrastructure.

  • SendGrid, for transactional email delivery.

We do not sell personal data.

6. International transfers

Some of our sub-processors (including Stripe, HubSpot, and Slack) may transfer data outside the UK as part of providing their services. Where this happens, we rely on the safeguards those providers have in place. Typically the UK International Data Transfer Agreement (IDTA) or equivalent standard contractual clauses published in their own terms to ensure data is protected to UK standards.

7. How long we keep data

We retain your account data for as long as your subscription is active, and for a limited period of 90 days afterwards to allow you to reactivate or export your data. Financial records relating to billing are retained for 6 years, in line with UK tax record-keeping requirements. Conversation data collected on your behalf as a processor is retained in line with each client's own instructions; where a client hasn't specified a period, we retain it for 12 months.

8. Security

We take the security of personal data seriously. Measures include:

  • Passwordless sign-in with short-lived, single-use, hashed login tokens.

  • Hashed, revocable session tokens. The server never stores anything that could be reversed to reveal the original, only a one-way hash.

  • Structural tenant isolation. Every business's data is scoped to their own account and can never be accessed by another business.

  • Encrypted storage of connected CRM and Slack credentials, using reversible encryption (distinct from the one-way hashing above, since these need to be usable to actually connect to your tools), never exposed to the browser.

  • Signature verification on payment webhooks, and constant-time comparison on sensitive tokens. Including our own admin data-export token to prevent common attack patterns.

9. Your rights

Under UK GDPR, you have the right to: access your personal data; have inaccurate data corrected; request erasure; restrict or object to processing; and data portability, in each case subject to applicable exemptions. To exercise these rights, contact us at datasecurity@handled.support. You also have the right to complain to the Information Commissioner's Office (ico.org.uk) if you believe we've mishandled your data.

10. Cookies

Our website uses cookies. See our separate Cookie Policy for detail. If you're a visitor to one of our clients' websites using a SalesBot or SupportBot widget, see the widget storage disclosure provided to that business for their own site.

11. Children

The Services are intended for business use and are not directed at children. We do not knowingly collect data from children.

12. Changes to this policy

We may update this policy from time to time; material changes will be notified where appropriate.

13. Contact

Sonic Blue Tech Ltd, The Old Dairy, Redhill, Surrey, RH1 5LN. hello@handled.support