The Voice AI Company
Back to home
LEGAL

Terms of Service.

These terms govern your subscription to and use of services provided by Philip Lougher Ltd, trading as The Voice AI Company.

Last updated: 19 August 2026

1. Acceptance of Terms

By subscribing to our services, paying any associated fees, signing an order form, or accessing the platform, you ("Customer") agree to be bound by these Terms of Service. These terms, any applicable order form and the Data Processing Addendum in Schedule 1 constitute a legally binding agreement between you and Philip Lougher Ltd, trading as The Voice AI Company ("Provider", "we", "us", or "our").

2. Services Provided

We provide custom artificial intelligence voice agent solutions, including setup, hosting, and month-to-month maintenance. The specific scope of your voice agent's capabilities will be outlined during your onboarding process.

3. Payment and Subscription Terms

Billing

Services are billed on a month-to-month, recurring subscription basis. Payment is processed upfront prior to the commencement of each billing cycle.

Currency

All fees are charged in GBP (£) unless otherwise stated.

Included AI Call Allowance

Each subscription includes the amount of AI call-handling time stated in the applicable plan, proposal, order form, or other written agreement (the "Included Allowance") for each billing cycle. Included Allowance is measured in AI-handled call minutes, resets at the start of each paid billing cycle, and is not refundable, transferable, redeemable for cash, or carried forward unless we agree otherwise in writing.

Usage Notifications and Allowance Reached

We may provide usage notifications at approximately 50%, 80%, and 95% of the Included Allowance through the dashboard, email, or another agreed channel. These notifications are a courtesy and are not a guarantee that usage will not reach the Included Allowance. The Customer remains responsible for monitoring usage in the dashboard.

We do not apply automatic overage charges. When the Included Allowance is reached, AI call handling may pause for the remainder of that billing cycle. Where a human fallback destination has been configured and is available, new calls will be routed to that destination rather than to the AI agent. The availability of any fallback route depends on the Customer maintaining an accurate, working destination number or phone system.

Additional AI Capacity

The Customer may choose to purchase additional AI call-handling time for the current billing cycle ("Additional AI Capacity") where offered. Additional AI Capacity is optional, prepaid, and activated only after payment has been successfully received. It applies only to the current billing cycle, is non-refundable and non-transferable once activated, and does not change the price or Included Allowance of the Customer's recurring subscription unless we agree otherwise in writing.

Cancellations

You may cancel your subscription at any time. Cancellations will take effect at the end of your current paid billing cycle. We do not provide refunds or credits for partial months of service.

Failed Payments

If a payment fails, we reserve the right to pause or suspend your voice agent until the balance is settled.

4. AI Performance and Limitations

Accuracy

While we strive for high-quality interactions, artificial intelligence systems can occasionally generate unpredictable, inaccurate, or unintended responses ("hallucinations"). The Provider is not liable for business losses, damages, or reputational harm resulting from the AI's spoken outputs.

Third-Party Infrastructure

Our services rely on third-party APIs, such as language models and telephony providers. We do not guarantee 100% uptime and are not responsible for service interruptions caused by these underlying network outages.

5. Intellectual Property

Provider IP

We retain all rights, title, and ownership of the underlying AI orchestration infrastructure, code, prompts, and proprietary methodologies used to build and host the agent.

Customer IP

You retain all ownership rights to the specific business data, customer lists, and proprietary knowledge base materials you provide to us to train your voice agent.

6. Data Protection and Privacy

Each party will comply with applicable data protection laws, including the UK GDPR, the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations 2003 where applicable.

For personal data processed through the voice agent and customer dashboard on the Customer's behalf, the Customer will normally act as controller and the Provider will act as processor. The Customer determines the purposes of the processing and is responsible for identifying an appropriate lawful basis, providing privacy information to callers and giving the Provider lawful documented instructions.

The Provider will process that personal data only to provide the agreed services and in accordance with the Data Processing Addendum in Schedule 1. The Provider remains responsible for its own obligations as a processor. Consent is not assumed to be the Customer's only available lawful basis.

The Provider acts as an independent controller for personal data it uses for its own legitimate business purposes, including customer account administration, billing, fraud prevention, service security and compliance with legal obligations. Further information is available in our Privacy and Cookie Policy.

7. Limitation of Liability

To the maximum extent permitted by law, the Provider's total liability for any claims arising out of or related to this agreement shall not exceed the total amount paid by the Customer to the Provider in the one (1) month immediately preceding the event giving rise to the claim.

8. Termination

We reserve the right to terminate or suspend your access to the service immediately, without prior notice, for conduct that we believe violates these Terms or is harmful to other users of us, our partners, or third-party infrastructure providers.

9. Governing Law

These Terms shall be governed by and construed in accordance with the laws of England and Wales. Any disputes arising under these Terms shall be subject to the exclusive jurisdiction of the courts of England and Wales.

Schedule 1: Data Processing Addendum

This Data Processing Addendum ("DPA") forms part of the agreement between the Customer and the Provider. It applies whenever the Provider processes personal data on behalf of the Customer in connection with the services.

In this DPA, "Controller", "Processor", "Data Subject", "Personal Data", "Personal Data Breach", "Process" and "Processing" have the meanings given in applicable data protection law. "Customer Personal Data" means personal data processed by the Provider on behalf of the Customer.

A. Roles and documented instructions

The parties acknowledge that the Customer is the Controller and the Provider is the Processor of Customer Personal Data, unless an applicable order form records a different arrangement for a specific processing activity.

The Provider will process Customer Personal Data only on the Customer's documented instructions, including the instructions contained in the agreement, an order form, the configured operation of the services and other written instructions agreed by the parties. The Provider may also process Customer Personal Data where required by UK law and will inform the Customer before doing so unless the law prohibits that notice.

If the Provider reasonably believes that an instruction infringes applicable data protection law, it will inform the Customer and may suspend the affected processing while the parties resolve the issue.

B. Customer responsibilities

The Customer is responsible for ensuring that its instructions are lawful, that it has an appropriate lawful basis for the processing and that callers and other Data Subjects receive the privacy information required by law. Where calls are recorded or transcribed, the Customer will ensure that callers are clearly informed about the recording, transcription, purposes, retention and relevant rights.

The Customer will not instruct the Provider to process special category or criminal offence data unless the parties have documented the processing and the Customer has identified all additional lawful conditions and safeguards required by law.

C. Confidentiality and security

The Provider will ensure that people authorised to process Customer Personal Data are subject to appropriate confidentiality obligations. The Provider will implement appropriate technical and organisational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.

Those measures will be proportionate to the nature of the processing and the risks to individuals. They may include authenticated access, tenant-based access controls, encryption provided by relevant infrastructure providers, transport-layer encryption, signed webhook verification, restricted administrative access, backup and recovery arrangements and procedures for managing security incidents.

D. Sub-processors

The Customer gives the Provider general written authorisation to use the sub-processors listed in the processing details below and any optional provider identified in an order form or other written deployment record. The Provider will place data protection terms with each sub-processor that provide an equivalent level of protection for Customer Personal Data as required by applicable law.

The Provider will give reasonable notice of a material change to its sub-processors where that change affects the Customer's processing. The Customer may object on reasonable data protection grounds. The parties will work in good faith to resolve the objection and, if it cannot be resolved, either party may terminate the affected service.

The Provider remains responsible to the Customer for the performance of its sub-processors' data protection obligations to the extent required by applicable law.

E. International transfers

The Provider will not make, or knowingly permit, a restricted transfer of Customer Personal Data outside the UK unless the transfer is covered by UK adequacy regulations, an applicable exception or appropriate safeguards recognised under UK data protection law.

Where required, those safeguards may include the UK International Data Transfer Agreement, the UK International Data Transfer Addendum to the European Commission Standard Contractual Clauses or another valid transfer mechanism. The Provider will make relevant transfer information available to the Customer on reasonable request.

F. Individual rights and assistance

Taking account of the nature of the processing, the Provider will provide reasonable assistance to help the Customer respond to requests by Data Subjects to exercise their rights. If the Provider receives a request relating to Customer Personal Data, it will direct the request to the Customer unless legally required to respond itself.

The Provider will also provide reasonable assistance with the Customer's security, breach notification, Data Protection Impact Assessment and regulatory consultation obligations, taking account of the nature of the processing and the information available to the Provider.

G. Personal data breaches

The Provider will notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data. The notice will include available information reasonably required to help the Customer assess the incident and meet its notification obligations. Information may be provided in phases as it becomes available.

The Provider will take reasonable steps to contain, investigate and mitigate the effects of the breach. Notification is not an admission of fault or liability.

H. Information and audits

The Provider will make available information reasonably necessary to demonstrate compliance with this DPA. The Customer may request a reasonable audit of relevant processing where documentary information is insufficient, subject to reasonable notice, confidentiality, security protections and arrangements that avoid unnecessary disruption.

I. Retention, return and deletion

The Provider will retain Customer Personal Data only for the period agreed in the order form, deployment record or other documented instruction, or for as long as reasonably necessary to provide the services. The parties will agree appropriate retention periods for recordings, transcripts, call metadata, integration outputs and diagnostic records before live processing begins.

On termination or expiry of the services, the Provider will, at the Customer's choice, delete or return Customer Personal Data and delete remaining copies unless UK law requires continued storage. Data held in protected backups may be deleted through the Provider's ordinary backup cycle, provided it remains protected and is not used for another purpose.

J. Processing details

Subject matter and purpose

Provision of AI-assisted telephone answering, enquiry handling, appointment support, call routing, call analysis, customer reporting, integrations and the secure customer dashboard described in the agreement.

Duration

For the duration of the services and the agreed retention period, subject to any lawful requirement to retain particular records for longer.

Categories of Data Subjects

People who call or receive calls from the Customer, the Customer's prospective and existing customers, authorised dashboard users and other people whose information is provided through the services.

Types of Personal Data

Names, telephone numbers, email addresses, postal addresses, call audio, transcripts, summaries, enquiry and appointment details, call timestamps and duration, communication preferences, agent interaction data and technical or account information required to provide the services.

Processing activities

Collection, recording, transmission, transcription, organisation, storage, retrieval, display, analysis, communication through approved integrations, restriction, deletion and other processing necessary to provide the agreed services.

K. Current sub-processors

Retell AI, Inc.

Voice agent operation, telephony orchestration, speech processing, transcription, call analysis and recording services, together with its authorised infrastructure, language-model, voice and telephony providers.

Supabase, Inc.

Database hosting, authentication, access controls and related platform services.

Netlify, Inc.

Application hosting, server-side functions, network delivery and operational infrastructure.

Optional integrations

Google Sheets, SMS providers, workflow platforms and other customer-requested integrations will process Customer Personal Data only where enabled for the applicable deployment. The relevant provider and purpose will be recorded in the order form, deployment record or another written notice before use.

The Voice AI Company

Intelligent conversations. Better business.

info@thevoiceaicompany.com Terms of Service Privacy Policy The Voice AI Company is a trading name of Philip Lougher Ltd © 2026 The Voice AI Company