Security and data protection
This page summarises how Pikul AI handles data, at the level of detail an IT or compliance reviewer usually wants: what the service does, who owns the data, where it is stored and processed, and the security measures around it. If you need more than what's here, email us and you'll get the answer in writing.
The service is provided by R P PIKUL Ltd, trading as Pikul Agency and Pikul.AI, a company registered in England and Wales under company number 10568899, with its registered office at Craven House, 40-44 Uxbridge Road, Ealing, London W5 2BS. We are registered with the Information Commissioner's Office, reference ZC192233. Data protection contact: rafal@pikul.agency.
What the service does with data
Pikul AI is an AI receptionist. It answers your business's enquiries over WhatsApp, web chat, Instagram and Facebook messages, SMS and email, qualifies them and books appointments. It answers only from information you approve, collects the minimum needed to book (name, contact details, enquiry topic), and hands anything sensitive or uncertain to your team.
Administrative use only. The assistant books, reminds, answers general questions and routes enquiries. It never gives clinical, legal or financial advice. For healthcare clients it is configured not to discuss conditions or symptoms: it books the appointment and leaves the medicine to your clinicians.
Who owns the data
You do, 100%. You are the data controller; Pikul Agency and our platform providers act strictly as processors under a written data processing agreement, provided before go-live. On exit, your data is exported to you and then deleted, at your choice, within 30 days.
Where data lives
- Platform data (contacts, conversations, appointments) is stored in the EU: Google Cloud in Poland and dedicated servers in Germany.
- AI inference (generating replies) is processed by leading AI providers (Anthropic, OpenAI, Google) and may take place in the US, safeguarded by Standard Contractual Clauses and the UK International Data Transfer Addendum.
- Message transport runs through the channel providers (for example Meta for WhatsApp and Twilio for SMS), in the EU and US under the same safeguards.
- The full sub-processor table, with purposes and locations, is Annex A of our data processing agreement, available on request.
Security measures
- Access to client data is restricted to named individuals, with multi-factor authentication on every system and least-privilege permissions.
- Your data is never used to train public AI models. The assistant answers only from the knowledge base you approve.
- Breach notification: we notify you without undue delay, and in any case within 48 hours of becoming aware, with the information you need for your own regulatory duties. The platform operates under the GDPR 72-hour authority notification duty.
Compliance posture
- Built for UK GDPR: controller and processor roles set out in a written Article 28 agreement, with data subject requests forwarded to you within 5 working days.
- Health-adjacent enquiries are treated as sensitive by design: minimum collection, no symptom probing, instant human handover, and transcripts handled as enquiry data, not clinical records.
- PECR-compliant outbound: the assistant sends service messages (confirmations, reminders); marketing goes out only with consent or soft opt-in.
- Data retention follows your policy: the system is configured to your retention periods, not ours.
Certifications, stated plainly
We are a specialist boutique, not a 200-person vendor, and we'd rather tell you exactly what is and isn't certified than have you find out in an audit. No ISO 27001 or SOC 2 certificates are held at platform level today (they are on the vendor's roadmap); the platform serves a Fortune 500 European company in production. If your governance requires a deployment-scoped external security test, we can commission one as part of your project.
Questions
Email rafal@pikul.agency. You'll get answers in writing, and anything we can't do, we'll say so.