Who we are
Ringmere is an AI phone receptionist for UK service businesses, operated by Peoplely Ltd (company no. 16386277), registered office 71-75 Shelton Street, London, England, WC2H 9JQ, and registered with the UK Information Commissioner’s Office (registration ZC192829). For call data processed on behalf of a business customer, that business is the data controller and Ringmere (Peoplely Ltd) acts as a data processor.
What we process
Account details for business customers, and, on their behalf, caller phone numbers, names, booking details and call transcripts (plus, where the business chooses to enable call recording, audio recordings), needed to answer calls and make bookings.
Why
To answer calls, book appointments, capture enquiries, prevent spam/fraud, and provide the dashboard and support. Callers are told at the start of a call that it is handled by an automated assistant, and that it may be recorded where the business has enabled call recording.
Who we share data with
We use a small number of vetted sub-processors to run the service, and none of them may use your data for their own purposes, for advertising, or to train general-purpose AI models: Twilio (telephony, SMS/WhatsApp, call recording), OpenAI (real-time voice AI and transcription), Google (Calendar API, for businesses that connect their calendar), Resend (transactional email), Stripe (billing), Fly.io (hosting and database), Cloudflare R2 (encrypted offsite backup storage, EU jurisdiction), Sentry (error monitoring), Meta (WhatsApp Business Platform, for businesses that connect WhatsApp), Google Ads (conversion measurement on our own sign-up), and, for hotels that connect a channel manager, Beds24 or Cloudbeds (the guest name, phone, email and stay dates needed to hold the room), and for food businesses only, postcodes.io (delivery-radius lookup). Each of them is covered by a data-processing agreement: Twilio, Google, Resend, Stripe, Fly.io, Cloudflare, Sentry, Meta, Beds24 and Cloudbeds incorporate one into the terms we have accepted, and our agreement with OpenAI is executed. We do not sell personal data to anyone. Our current sub-processor list is available on request.
Where data is processed
Your data is stored in the UK (Fly.io, London region), with backups held in the EU (Cloudflare R2, EU jurisdiction) and encrypted at rest and in transit. Some of the sub-processors above process data outside the UK: OpenAI, Resend, Stripe and Sentry operate from the United States, and Google, Twilio and Cloudflare operate globally. Those transfers rely on UK GDPR transfer safeguards (the UK International Data Transfer Addendum or Standard Contractual Clauses) under each provider’s data-processing agreement. If your organisation needs processing restricted to a particular region, contact info@ringmere.com before you go live so we can tell you what is currently possible.
How we protect it
Data is hosted in the UK (Fly.io, London region), encrypted in transit with TLS and at rest. Sensitive credentials, including Google Calendar refresh tokens, are separately encrypted with AES-256-GCM and are never exposed to the browser or to our AI provider. Every business account is tenant-isolated, so access is enforced per authenticated owner on every request, and internal access to personal data is limited to what is needed for support, security or legal purposes.
Google Calendar data
When a business connects Google Calendar, Ringmere requests two scopes: calendar.readonly, to check free/busy availability, and calendar.events, to create, update or cancel the bookings it makes on the business’s behalf. We do not read or store the content of unrelated calendar events. Availability and booking details derived from your calendar are shared with OpenAI, our voice AI provider, only so it can quote available times and confirm bookings during a live call; OpenAI never receives your Google account, credentials or refresh token, and does not use this data to train its models. We do not use Google user data for advertising or sell it. The use of raw or derived user data received from Google Workspace APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. If a business disconnects Google Calendar, its stored token is deleted immediately.
Cookies and advertising
This website works without cookies. For visitors in the UK and Europe, no advertising cookie is set unless you accept the optional measurement cookie in the banner; if you decline, Google may still receive an aggregated, cookieless signal that a sign-up happened. For visitors elsewhere, where no consent banner is required, measurement is on by default. The cookie lets Google Ads tell us which of our adverts led to a sign-up; it does not identify you to us and is not used to follow you around other websites. You can change your mind by clearing this site's data in your browser. The signed-in app carries the same measurement tag on the same terms, so that a sign-up can be matched to the advert that led to it; apart from that it uses only the cookies needed to keep you signed in.
Your rights
Under UK GDPR you can request access, correction, deletion, restriction or portability of your data. Business customers can action caller requests from the platform. Email info@ringmere.com to exercise your rights.
Retention
Call data is retained only as long as needed for the service and your configured retention period, then deleted.
Contact
For any privacy question or request, contact info@ringmere.com.
Last updated 25 July 2026. This is a plain-English summary; contact info@ringmere.com for our full policy or a Data Processing Agreement.