Privacy Policy

Last updated: 15 June 2026

Who we are

JustSay is operated by GetSilk Ltd (Company No. 17273512), a company incorporated in England and Wales.

JustSay provides a feedback collection and review management service for businesses. We collect customer feedback via WhatsApp, use artificial intelligence to analyse sentiment and generate review drafts, and provide businesses with operational intelligence through a real-time dashboard.

Data Protection Officer: JustSay is not required to appoint a Data Protection Officer under Article 37 of the UK GDPR, as our core activities do not involve regular and systematic monitoring of data subjects on a large scale, nor do we process special category data on a large scale. Our data protection contact (above) handles all data protection queries.

How this policy applies

This privacy policy explains how we handle personal data in two contexts:

  1. Clients — if you are a business using JustSay, this policy covers how we handle your account information and business data.
  2. Customers — if you are an individual (such as a hotel guest, restaurant diner, patient, or member) who has received a WhatsApp message from JustSay after using a business's services, this policy explains how your feedback and personal data is processed.

What data we collect

From Clients (businesses using JustSay)

When a business subscribes to JustSay, we collect:

Lawful basis: Contract — this data is necessary to provide the service the Client has subscribed to (Article 6(1)(b) UK GDPR).

From Customers (individuals giving feedback)

When a Client uses JustSay, we process the following customer data on behalf of that Client:

Data controller: The business you visited (our Client) is the data controller for your personal data. JustSay processes this data on the Client's behalf as data processor under Article 28 UK GDPR. We are not the data controller for your feedback data.

Is providing your data a requirement? Provision of your personal data to JustSay is not a statutory or contractual requirement, and you are not obliged to provide it. Your data is shared with us by the business you visited. If they choose not to share it, or if you ask them not to, you will simply not receive a feedback request. There are no adverse consequences for you.

Lawful basis: Legitimate interest — the Client has a legitimate interest in collecting customer feedback to improve its service and manage its online reputation (Article 6(1)(f) UK GDPR). We have carried out a Legitimate Interest Assessment which is available on request. A summary of the balancing test is set out in our safeguards section below.

Why not consent?

We considered using consent as the lawful basis but concluded that it would be inappropriate for this processing. Consent must be freely given, specific, informed, and unambiguous — and must be withdrawable at any time. The nature of post-visit feedback collection means that: (a) requiring opt-in at booking would significantly reduce the contactable population, undermining the representative value of the feedback; (b) implementation across different booking channels (online, OTA, walk-in) would be inconsistent; and (c) the processing is low-risk and customer control is maintained throughout (see safeguards below). Legitimate interest, with robust safeguards, provides a more appropriate and proportionate legal basis.


How customer data flows through our system

When a customer uses a partner business's services, the following happens:

  1. The business's operational system sends us the customer's name, phone number, booking reference, and visit date.
  2. We send the customer a WhatsApp message on behalf of the business, inviting them to share feedback.
  3. If the customer replies (by voice note or text), their response is processed by our AI systems to generate a sentiment score, identify operational themes, and draft a review.
  4. The customer receives the draft review and can approve it as-is, request edits, or simply not respond.
  5. A service recovery window applies to every conversation. During this window, the business has the opportunity to review the feedback and, if necessary, resolve any issues directly with the customer before any review is published.
  6. If the customer approves their review and the service recovery window has passed, they receive a link to publish the review on Google, TripAdvisor, or another review platform. The customer must take active action to publish — we never publish reviews without explicit customer approval.
  7. The business sees operational theme data, sentiment trends, and conversation details on their dashboard.

Customers are never obligated to respond. If a customer does not reply to the WhatsApp message, no further messages are sent and no data beyond their name and phone number is retained (subject to the retention periods below).


Safeguards protecting customers

We have implemented the following safeguards to protect customer rights and freedoms:


Sub-processors

We use the following third-party services to deliver JustSay:

Provider Purpose Location Data processed
360dialog GmbHWhatsApp Business API messagingGermany (EU)Customer phone numbers, message content
OpenAI, Inc.Voice note transcriptionUnited StatesVoice note audio files
Anthropic, Inc.Sentiment analysis, theme extraction, review generationUnited StatesTranscribed text, customer feedback
Cloudflare, Inc.Application hosting, database, CDNGlobal (primary: EU/UK)All application data
Resend, Inc.Transactional email deliveryUnited StatesClient contact email addresses, alert content
Stripe, Inc.Payment processing (where applicable)United StatesClient payment details (not customer data)
GoCardless LtdPayment processing (where applicable)United KingdomClient payment details (not customer data)

Both OpenAI and Anthropic have confirmed that data submitted via their APIs is not used to train their models.


International data transfers

Some of the data we process is transferred outside the United Kingdom:

Transfers to the United States are protected by the UK International Data Transfer Agreement (UK IDTA) or the EU Standard Contractual Clauses supplemented by the UK International Data Transfer Addendum, as applicable, incorporated into our agreements with each provider. We have conducted transfer risk assessments for each transfer.

Details of our international transfer mechanisms are available on request by contacting privacy@getsilk.co.uk.


How long we keep data

Data type Retention period Reason
Voice note audio files 7 days from receipt Deleted once transcription is confirmed. Minimises storage of raw audio.
Raw conversation data (transcripts, messages, customer phone numbers, customer names) 12 months from conversation date GDPR-defensible retention period. Businesses rarely need to revisit individual conversations beyond a year.
Derived and aggregated data (sentiment scores, theme breakdowns, response rates, published review records) Permanently (anonymised, no personal data) Anonymised operational data providing long-term value — year-on-year comparisons, seasonal patterns, trend analysis. Retained after account closure as it contains no personally identifiable information.
Client account data (business details, user accounts, configuration) Life of Client account, plus 6 years after termination Compliance with limitation periods under English law and HMRC record-keeping requirements.

When a Client cancels their account


Your rights

If you are a Customer

Under the UK GDPR, you have the right to:

How to exercise your rights: Email privacy@getsilk.co.uk with your name and the business you visited. We will respond within 30 days. We may ask for information to verify your identity before fulfilling a request.

If you are a Client

You have the same rights as above in relation to your own personal data (contact details, account information). Additionally, you may exercise rights on behalf of your customers to the extent you are their data controller — please contact us at privacy@getsilk.co.uk.


Data security

We take the following measures to protect personal data:


Cookies

Strictly necessary cookies: Our Dashboard uses essential functional cookies (session cookies and authentication tokens) required for it to function. These cookies do not require consent.

Analytics cookies: We may use analytics tools to understand how visitors use our website. If we do, these cookies will only be set with your consent, and you will be presented with a choice when you first visit. You can withdraw consent at any time by clearing your cookies or using the cookie preferences link in our website footer.

We do not use advertising cookies, tracking pixels, or share browsing data with third parties for marketing purposes.


Children

JustSay is a business-to-business service. We do not knowingly collect or process personal data from anyone under the age of 18. If a customer is under 18 and has provided feedback, a parent or guardian may contact us to request deletion.


Changes to this policy

We may update this privacy policy from time to time. If we make material changes that affect how we process your data, we will notify affected parties by email (Clients) or by updating the policy on our website (Customers). We encourage you to review this policy periodically.

The "last updated" date at the top of this policy indicates when the most recent changes were made.


How to contact us

For any questions about this privacy policy or how we handle your data:


How to complain

If you are unhappy with how we have handled your data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):

We would appreciate the opportunity to address your concerns before you contact the ICO. Please email privacy@getsilk.co.uk in the first instance.


Lawful basis summary

Processing activity Lawful basis GDPR Article
Providing the Service to ClientsContract6(1)(b)
Client account data and billingContract6(1)(b)
Processing customer feedback on behalf of ClientsLegitimate interest6(1)(f)
Sending WhatsApp messages to customersLegitimate interest6(1)(f)
Service recovery alerts to Client staffContract6(1)(b)
Retaining anonymised aggregate statisticsLegitimate interest6(1)(f)
Processing payments via Stripe or GoCardlessContract6(1)(b)