Full Legal Protection Pack
Version 1.0 — Effective 30 March 2026
Product Name: Katy AI Operations Assistant
Operator / Data Controller: Sebastian Fletcher, trading as Gitwix
Contact: admin@gitwix.com
Jurisdiction: England & Wales
Version: 1.0 — Effective Date: 30 March 2026
Last Updated: March 2026
By accessing or using the Katy AI Operations Assistant platform (“the Service”, “the Platform”), including any web-based interface, API endpoint, voice assistant functionality, or associated tooling, you (“the User”, “you”) agree to be legally bound by these Terms of Service (“Terms”). If you do not agree to these Terms in their entirety, you must immediately cease use of the Service.
These Terms constitute a legally binding agreement between you and Sebastian Fletcher, trading as Gitwix (“we”, “us”, “the Operator”). Use of the Service by any individual or organisation constitutes unconditional acceptance.
The Service is intended solely for use by:
You represent and warrant that:
The Service is designed exclusively for the following purposes:
Any use outside of the above purposes is expressly prohibited without prior written consent from the Operator.
You must not, under any circumstances, use the Service to:
You are fully responsible for:
The Operator reserves the right to suspend or terminate accounts where misuse, abuse, or violation of these Terms is suspected or confirmed.
The Katy AI Operations Assistant is an AI-powered tool designed to assist — not replace — human judgement in business decisions. You acknowledge and agree that:
All intellectual property rights in the Service, including software, AI models, interfaces, branding, and documentation, are owned exclusively by the Operator or its licensors. These Terms do not transfer any intellectual property rights to you.
You retain ownership of data you input into the Service, subject to the licence granted below. You grant the Operator a limited, non-exclusive licence to process your input data solely for the purpose of delivering the Service to you.
The Operator does not claim ownership of contact data processed through the Service.
The Service is provided on a commercially reasonable best-effort basis. The Operator does not guarantee:
Planned maintenance will be communicated where reasonably practicable. The Operator accepts no liability for losses arising from downtime, technical failures, or third-party service interruptions (including Vercel, Supabase, or telecommunications providers).
To the fullest extent permitted by applicable law:
Nothing in these Terms limits liability for death or personal injury caused by negligence, fraud, or fraudulent misrepresentation, or any liability that cannot be excluded under applicable law.
You agree to indemnify, defend, and hold harmless the Operator and its affiliates, directors, employees, and agents from and against any claims, liabilities, damages, losses, and expenses (including reasonable legal fees) arising out of or in connection with:
The Operator reserves the right to:
Continued use of the Service following notification of changes constitutes acceptance of the revised Terms. It is your responsibility to review these Terms periodically.
The Operator may suspend or terminate your access immediately and without notice if:
Upon termination, your right to use the Service ceases immediately. Provisions that by their nature should survive termination (including intellectual property, limitation of liability, and indemnification clauses) shall continue to apply.
These Terms are governed by and construed in accordance with the laws of England and Wales. Any disputes arising from or relating to these Terms or the Service shall be subject to the exclusive jurisdiction of the courts of England and Wales.
Sebastian Fletcher, trading as Gitwix (“we”, “us”), is the data controller for personal data processed through the Katy AI Operations Assistant platform. We are committed to handling personal data responsibly and in compliance with UK GDPR (UK General Data Protection Regulation) and the Data Protection Act 2018.
Contact for data protection enquiries: admin@gitwix.com
| Data Category | Legal Basis | Detail |
|---|---|---|
| Operator account data | Contract (Art. 6(1)(b)) | Necessary to provide the Service |
| Contact call data | Legitimate interests (Art. 6(1)(f)) / Consent | Outreach screening; consent obtained by Operator |
| Voice recordings | Explicit consent (Art. 9 where applicable) | Obtained prior to call commencement |
| AI summaries | Legitimate interests (Art. 6(1)(f)) | Assessment purposes |
| Technical/usage data | Legitimate interests (Art. 6(1)(f)) | Platform security and improvement |
| Marketing communications | Consent (Art. 6(1)(a)) | Opt-in only |
Where the Service processes special category data (e.g., health information, ethnicity, or other protected characteristics inadvertently revealed during a call), processing is limited to what is strictly necessary and will only proceed under Article 9(2)(b) (employment law obligations) or explicit consent.
Personal data is used for the following purposes:
We do not use personal data for:
We use the following third-party sub-processors. By using the Service, you acknowledge and accept their involvement:
| Processor | Purpose | Location | Safeguard |
|---|---|---|---|
| Vercel Inc. | Application hosting and deployment | USA | EU-US Data Privacy Framework |
| Supabase Inc. | Database and authentication | USA (AWS) | Standard Contractual Clauses |
| OpenAI / AI provider | AI processing and transcription | USA | Standard Contractual Clauses |
| Twilio Inc. | Voice call infrastructure | USA | Standard Contractual Clauses |
| ElevenLabs Inc. | Voice AI generation and processing | USA | Standard Contractual Clauses |
| Anthropic PBC | AI language processing and analysis | USA | Standard Contractual Clauses |
| Microsoft Corporation | Email and calendar integration (Graph API) | USA/EU | EU-US Data Privacy Framework |
| Stripe Inc. | Payment processing | USA | EU-US Data Privacy Framework |
We will notify you of material changes to sub-processors. We require all sub-processors to maintain appropriate security standards and process data only on our documented instructions.
We may also disclose data to:
Some of our sub-processors are located outside the UK/EEA. Where data is transferred internationally, we rely on one or more of the following safeguards:
| Data Type | Retention Period |
|---|---|
| Operator account data | Duration of account + 2 years |
| Contact call recordings | 90 days, unless longer retention is required by law |
| Transcriptions and AI summaries | 12 months from creation |
| Usage and technical logs | 6 months |
| Billing records | 7 years (legal requirement) |
You may request earlier deletion subject to our legal obligations.
Under UK GDPR, individuals have the following rights:
To exercise any of these rights, please contact: admin@gitwix.com. We will respond within one calendar month. Where requests are complex or numerous, we may extend this by a further two months with prior notice.
If you are dissatisfied with how we have handled your data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO): www.ico.org.uk | Helpline: 0303 123 1113.
We implement the following technical and organisational measures to protect personal data:
In the event of a personal data breach that is likely to result in a risk to individuals' rights and freedoms, we will notify the ICO within 72 hours of becoming aware and inform affected individuals without undue delay where required.
“Hello. You are about to speak with Katy, an AI-powered operations assistant operated on behalf of [Operator Company Name]. This call may be recorded and transcribed for assessment purposes. Your responses will be reviewed by the team at [Operator Company Name]. By continuing this call, you consent to this processing. If you do not consent, you may end the call at any time and request an alternative assessment method by contacting [Operator contact details]. For full details of how your data is handled, please visit https://app.gitwix.com/privacy.”
What we collect during this call:
How it is used:
Your rights:
Retention: Call recordings and transcripts are retained for 90 days following your assessment, after which they are permanently deleted.
No sale of data: Your data will never be sold or shared with third parties outside of the business process.
Operators using the Service are contractually required to:
The Katy AI platform is configured by default with a compliant AI disclosure greeting that identifies the caller as an AI assistant at the commencement of every call. This default behaviour is designed to satisfy the transparency requirements of the EU AI Act and UK telecommunications regulations.
The default pre-call disclosure reads: "Hi, this is Katy, an AI assistant calling on behalf of [Company Name]."
Deployers (business customers) have the ability to modify or disable this AI disclosure greeting through the Platform's Settings interface. The Platform presents an explicit, unskippable legal warning when a Deployer attempts to disable this feature, requiring the Deployer to acknowledge and accept full legal liability before proceeding.
The Operator (Gitwix) accepts no responsibility, liability, or legal obligation arising from a Deployer's decision to modify, disable, or remove the default AI disclosure greeting. By disabling this compliance feature, the Deployer assumes all legal, regulatory, and financial risk associated with non-disclosure, including but not limited to fines, enforcement actions, or civil claims under the EU AI Act, GDPR, TCPA, FCC regulations, UK Ofcom rules, or any equivalent legislation in any jurisdiction.
Gitwix strongly recommends that all Deployers maintain the AI disclosure greeting in its default enabled state. Deployers who choose to disable it warrant that they have obtained independent legal advice confirming that their specific use case, jurisdiction, and consent framework do not require such disclosure.
This Acceptable Use Policy forms part of the Terms of Service and sets out specific standards of behaviour required from all users. Violation of this AUP may result in immediate account suspension without refund.
In addition to prohibitions in the Terms of Service, the following are expressly prohibited:
If you discover a security vulnerability in the Service, please report it confidentially to admin@gitwix.com before any public disclosure.
Disclosure Timeline:
We request that you do not publicly disclose the vulnerability until we have had reasonable time to remediate. We will not take legal action against security researchers acting in good faith under this policy.
This Data Processing Agreement supplements the Terms of Service and applies where the Operator processes personal data on behalf of business customers acting as data controllers.
The business customer is the Data Controller. Sebastian Fletcher, trading as Gitwix, is the Data Processor when processing contact personal data on the customer's behalf.
The Operator will only process personal data on documented instructions from the Controller, except where required by law. If the Operator believes an instruction violates UK GDPR, it will promptly notify the Controller.
The Operator commits to:
The Controller has the right, on reasonable notice (minimum 30 days except in genuine emergencies), to audit the Operator's data processing activities, either directly or through an appointed third party, no more than once per calendar year.
The Katy AI Operations Assistant uses AI to assist with outreach processes. As operator and users of AI in business decisions, both the Service provider and business customers must comply with:
The Operator commits to:
Business customers must:
| Obligation | Who | Requirement |
|---|---|---|
| Pre-call consent | Operator | Must play/display consent notice before every AI call |
| Privacy Notice link | Operator | Must provide link before assessment |
| Human review | Operator | All AI output must be reviewed by a human before hiring decisions |
| Data retention | Both | Contact data deleted per schedule in Privacy Notice |
| Data subject requests | Both | Respond within 30 days |
| Breach notification to ICO | Operator (Gitwix) | Within 72 hours |
| Breach notification to customer | Operator (Gitwix) | Within 48 hours |
| Sub-processor notification | Operator (Gitwix) | Prior to engaging new processors |
| Equality Act compliance | Business customer | Must conduct equality impact assessment |
| Contact alternative option | Business customer | Must offer non-AI alternative assessment |
This document was prepared for Katy AI Operations Assistant, operated by Sebastian Fletcher (Gitwix). All sections should be reviewed by a qualified UK solicitor with experience in data protection and employment law.
Powered by Katy AI