Privacy Policy
Last updated: 15 June 2026
Who we are
JustSay is operated by GetSilk Ltd (Company No. 17273512), a company incorporated in England and Wales.
- Trading name: JustSay
- Website: justsay.uk
- Data protection contact: privacy@getsilk.co.uk
- ICO registration number: ZC112305
JustSay provides a feedback collection and review management service for businesses. We collect customer feedback via WhatsApp, use artificial intelligence to analyse sentiment and generate review drafts, and provide businesses with operational intelligence through a real-time dashboard.
How this policy applies
This privacy policy explains how we handle personal data in two contexts:
- Clients — if you are a business using JustSay, this policy covers how we handle your account information and business data.
- Customers — if you are an individual (such as a hotel guest, restaurant diner, patient, or member) who has received a WhatsApp message from JustSay after using a business's services, this policy explains how your feedback and personal data is processed.
What data we collect
From Clients (businesses using JustSay)
When a business subscribes to JustSay, we collect:
- Business name, address, and contact details
- Primary contact name and email address
- Dashboard user email addresses
- Google Business Profile and TripAdvisor URLs
- Payment information (processed securely via our payment provider — we do not store card details directly)
- Service configuration preferences (themes, trigger timing, recovery window settings)
From Customers (individuals giving feedback)
When a Client uses JustSay, we process the following customer data on behalf of that Client:
- Customer name
- Customer mobile phone number
- Room number, booking reference, or equivalent identifier
- Checkout date, appointment date, or visit date
- WhatsApp messages sent and received (including voice notes and text replies)
- Voice note audio recordings
- Transcriptions of voice notes
- AI-generated sentiment scores and theme analysis
- AI-generated review drafts
- Whether the customer approved, edited, or declined their review
Is providing your data a requirement? Provision of your personal data to JustSay is not a statutory or contractual requirement, and you are not obliged to provide it. Your data is shared with us by the business you visited. If they choose not to share it, or if you ask them not to, you will simply not receive a feedback request. There are no adverse consequences for you.
Why not consent?
We considered using consent as the lawful basis but concluded that it would be inappropriate for this processing. Consent must be freely given, specific, informed, and unambiguous — and must be withdrawable at any time. The nature of post-visit feedback collection means that: (a) requiring opt-in at booking would significantly reduce the contactable population, undermining the representative value of the feedback; (b) implementation across different booking channels (online, OTA, walk-in) would be inconsistent; and (c) the processing is low-risk and customer control is maintained throughout (see safeguards below). Legitimate interest, with robust safeguards, provides a more appropriate and proportionate legal basis.
How customer data flows through our system
When a customer uses a partner business's services, the following happens:
- The business's operational system sends us the customer's name, phone number, booking reference, and visit date.
- We send the customer a WhatsApp message on behalf of the business, inviting them to share feedback.
- If the customer replies (by voice note or text), their response is processed by our AI systems to generate a sentiment score, identify operational themes, and draft a review.
- The customer receives the draft review and can approve it as-is, request edits, or simply not respond.
- A service recovery window applies to every conversation. During this window, the business has the opportunity to review the feedback and, if necessary, resolve any issues directly with the customer before any review is published.
- If the customer approves their review and the service recovery window has passed, they receive a link to publish the review on Google, TripAdvisor, or another review platform. The customer must take active action to publish — we never publish reviews without explicit customer approval.
- The business sees operational theme data, sentiment trends, and conversation details on their dashboard.
Customers are never obligated to respond. If a customer does not reply to the WhatsApp message, no further messages are sent and no data beyond their name and phone number is retained (subject to the retention periods below).
Safeguards protecting customers
We have implemented the following safeguards to protect customer rights and freedoms:
- Participation is entirely voluntary. Customers choose whether to reply. No follow-up messages, no chasing, no pressure.
- Customer controls publication. No review is ever published without explicit customer approval. The customer reviews and may edit every draft before deciding whether to publish.
- Service recovery protects the customer. If a customer reports a negative experience, the business is alerted and given time to resolve the issue before any review is published. This actively benefits the customer.
- Minimal data, short retention. Voice note audio is deleted within 7 days. All personal data is deleted within 12 months. Only anonymised statistics are retained long-term.
- Transparency. The WhatsApp message includes a clear statement about how feedback will be used, with a link to this privacy policy. Partner businesses also include a disclosure clause in their booking terms.
- Easy opt-out. Any customer can request deletion of their data by emailing privacy@getsilk.co.uk. We respond within 30 days.
- No sensitive data. We do not collect or process special category data. Feedback is about the business experience, not the customer's personal life, health, or beliefs.
- No automated decisions with legal effect. AI is used for transcription, sentiment analysis, and review drafting. None of these outputs produce a legal or similarly significant effect on the customer. The customer always has final say.
Sub-processors
We use the following third-party services to deliver JustSay:
| Provider | Purpose | Location | Data processed |
|---|---|---|---|
| 360dialog GmbH | WhatsApp Business API messaging | Germany (EU) | Customer phone numbers, message content |
| OpenAI, Inc. | Voice note transcription | United States | Voice note audio files |
| Anthropic, Inc. | Sentiment analysis, theme extraction, review generation | United States | Transcribed text, customer feedback |
| Cloudflare, Inc. | Application hosting, database, CDN | Global (primary: EU/UK) | All application data |
| Resend, Inc. | Transactional email delivery | United States | Client contact email addresses, alert content |
| Stripe, Inc. | Payment processing (where applicable) | United States | Client payment details (not customer data) |
| GoCardless Ltd | Payment processing (where applicable) | United Kingdom | Client payment details (not customer data) |
Both OpenAI and Anthropic have confirmed that data submitted via their APIs is not used to train their models.
International data transfers
Some of the data we process is transferred outside the United Kingdom:
- Voice note transcription is processed by OpenAI in the United States.
- Sentiment analysis and review generation is processed by Anthropic in the United States.
- Email delivery is processed by Resend in the United States.
- WhatsApp messaging is routed through 360dialog in Germany, covered by UK adequacy regulations for the EU/EEA.
Transfers to the United States are protected by the UK International Data Transfer Agreement (UK IDTA) or the EU Standard Contractual Clauses supplemented by the UK International Data Transfer Addendum, as applicable, incorporated into our agreements with each provider. We have conducted transfer risk assessments for each transfer.
Details of our international transfer mechanisms are available on request by contacting privacy@getsilk.co.uk.
How long we keep data
| Data type | Retention period | Reason |
|---|---|---|
| Voice note audio files | 7 days from receipt | Deleted once transcription is confirmed. Minimises storage of raw audio. |
| Raw conversation data (transcripts, messages, customer phone numbers, customer names) | 12 months from conversation date | GDPR-defensible retention period. Businesses rarely need to revisit individual conversations beyond a year. |
| Derived and aggregated data (sentiment scores, theme breakdowns, response rates, published review records) | Permanently (anonymised, no personal data) | Anonymised operational data providing long-term value — year-on-year comparisons, seasonal patterns, trend analysis. Retained after account closure as it contains no personally identifiable information. |
| Client account data (business details, user accounts, configuration) | Life of Client account, plus 6 years after termination | Compliance with limitation periods under English law and HMRC record-keeping requirements. |
When a Client cancels their account
- We offer a full data export before the account closes.
- Within 30 days of cancellation, all customer personal data is permanently deleted — conversations, transcripts, phone numbers, names, voice notes, dashboard accounts, and configuration.
- We retain anonymised aggregate statistics permanently. These contain no business name, no customer data, and no personally identifiable information.
Your rights
If you are a Customer
Under the UK GDPR, you have the right to:
- Access — request a copy of the personal data we hold about you.
- Rectification — request correction of inaccurate data.
- Erasure — request deletion of your personal data. We will remove your name, phone number, transcripts, and any associated feedback within 30 days. Any review you have already published on Google or TripAdvisor is controlled by that platform and must be removed there directly.
- Restriction — request that we limit how we process your data.
- Objection — object to our processing of your data on legitimate interest grounds. We will cease processing unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms.
- Portability — request your data in a machine-readable format.
- Withdraw consent — where processing is based on consent (note: our primary lawful basis for customer data is legitimate interest, not consent).
How to exercise your rights: Email privacy@getsilk.co.uk with your name and the business you visited. We will respond within 30 days. We may ask for information to verify your identity before fulfilling a request.
If you are a Client
You have the same rights as above in relation to your own personal data (contact details, account information). Additionally, you may exercise rights on behalf of your customers to the extent you are their data controller — please contact us at privacy@getsilk.co.uk.
Data security
We take the following measures to protect personal data:
- All data is encrypted in transit (TLS 1.2 or above) and at rest.
- Database access is restricted to authenticated and authorised users only, with role-based permissions.
- Dashboard access uses magic-link authentication — no passwords are stored.
- Voice note audio is automatically and permanently deleted after 7 days.
- Idempotent message processing prevents duplicate data creation.
- Sub-processor access is limited to the minimum data required for their function.
- We regularly review access controls and security practices.
Cookies
Strictly necessary cookies: Our Dashboard uses essential functional cookies (session cookies and authentication tokens) required for it to function. These cookies do not require consent.
Analytics cookies: We may use analytics tools to understand how visitors use our website. If we do, these cookies will only be set with your consent, and you will be presented with a choice when you first visit. You can withdraw consent at any time by clearing your cookies or using the cookie preferences link in our website footer.
We do not use advertising cookies, tracking pixels, or share browsing data with third parties for marketing purposes.
Children
JustSay is a business-to-business service. We do not knowingly collect or process personal data from anyone under the age of 18. If a customer is under 18 and has provided feedback, a parent or guardian may contact us to request deletion.
Changes to this policy
We may update this privacy policy from time to time. If we make material changes that affect how we process your data, we will notify affected parties by email (Clients) or by updating the policy on our website (Customers). We encourage you to review this policy periodically.
The "last updated" date at the top of this policy indicates when the most recent changes were made.
How to contact us
For any questions about this privacy policy or how we handle your data:
- Email: privacy@getsilk.co.uk
- Website: justsay.uk
How to complain
If you are unhappy with how we have handled your data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):
- Website: ico.org.uk
- Telephone: 0303 123 1113
- Address: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
We would appreciate the opportunity to address your concerns before you contact the ICO. Please email privacy@getsilk.co.uk in the first instance.
Lawful basis summary
| Processing activity | Lawful basis | GDPR Article |
|---|---|---|
| Providing the Service to Clients | Contract | 6(1)(b) |
| Client account data and billing | Contract | 6(1)(b) |
| Processing customer feedback on behalf of Clients | Legitimate interest | 6(1)(f) |
| Sending WhatsApp messages to customers | Legitimate interest | 6(1)(f) |
| Service recovery alerts to Client staff | Contract | 6(1)(b) |
| Retaining anonymised aggregate statistics | Legitimate interest | 6(1)(f) |
| Processing payments via Stripe or GoCardless | Contract | 6(1)(b) |