Privacy Policy
Radically transparent data practices for our AI services, compliant with the EU AI Act and UK Data Act 2025.
Costero Group S.L (Intelligrail)
NIF/CIF: ESB72819527
Marbella, Spain
Last Updated
April 8, 2026
This Privacy Policy explains how Intelligrail ("we," "us," or "our") collects and processes personal data. We operate primarily under the EU General Data Protection Regulation (GDPR) and the Spanish LOPDGDD, while complying with the UK GDPR and the UK Data (Use and Access) Act 2025 for our clients and contacts in the United Kingdom.
1. Roles and Scope
As a Service Provider (Processor)
When we provide our AI Voice Receptionist to a clinic or business (the "Client"), we act as a Data Processor. The Client is the Data Controller.
As a Marketing Entity (Controller)
When we contact prospective clients for B2B outreach, we act as the Data Controller.
2. Lawful Basis for Processing
- B2B Outreach (UK): We rely on Legitimate Interest to contact corporate subscribers (Limited Companies/LLPs). We have conducted a Legitimate Interest Assessment (LIA) confirming that our outreach is professionally relevant and minimally intrusive.
- Service Delivery: We process data based on Contractual Necessity to fulfill our agreement with our clients.
- Inbound Enquiries: We process data based on your Consent when you fill out a form or call our demo line.
3. AI Transparency (Mandatory Disclosure)
In accordance with Article 50 of the EU AI Act and UK transparency guidelines:
Interaction Disclosure
Our AI Voice Receptionist identifies itself as an artificial intelligence system at the start of every interaction.
Purpose
The AI is used solely for administrative scheduling and inquiry management. It does not perform "high-risk" profiling or medical diagnosis.
Human Intervention
Users interacting with our AI have the right to request human intervention or to exit the automated flow at any time.
4. Data Residency & Transfers
- Location: All personal data is stored on secure servers located within the European Economic Area (EEA).
- UK-EU Transfer: Data flows between the UK and Spain are governed by the UK-EU Adequacy Decision, meaning your data is handled with an equivalent level of protection in Spain as it would be in the UK.
5. Data Retention
- Call Recordings: If enabled by the client, voice recordings are stored for 30 days before being permanently deleted or anonymized.
- Marketing Data: We keep contact details until you opt-out or for 2 years after the last point of contact.
6. Your Rights
Under both EU and UK law, you have the right to access, rectify, or erase your data.
- UK Specific Right: Pursuant to the UK Data (Use and Access) Act 2025, UK residents have the right to lodge a complaint regarding our data handling. We will acknowledge receipt of any data protection complaint within 30 days in accordance with the UK DUA Act 2025. complaints@intelligrail.com.
9. Information We Collect
Personal Information
We may collect personal details such as your name, email address, phone number, and billing information when you register for an account or contact us.
Usage Data
We automatically collect information about how you interact with our platform, including IP addresses, browser types, and pages visited, to improve our services.
Cookies & Tracking
We use cookies and similar tracking technologies to monitor activity on our service and store certain information. You can configure your browser to refuse all cookies.
10. How We Use Your Information
Service Delivery
To provide, maintain, and improve our AI services, process transactions, and send related information including confirmations and invoices.
Marketing & Communications
To send you promotional messages, marketing, advertising, and other information that may be of interest to you, based on your preferences.
Analytics & Improvement
To monitor and analyze trends, usage, and activities in connection with our services to improve user experience.
11. Third-Party Sharing
Service Providers
We may share your information with third-party vendors, consultants, and other service providers who need access to such information to carry out work on our behalf.
Legal Requirements
We may disclose your information if required to do so by law or in response to valid requests by public authorities.
12. Data Security
Security Measures
We implement appropriate technical and organizational security measures to protect your personal information from unauthorized access, alteration, disclosure, or destruction.
7. Regional Addendums
California (CCPA / CPRA)
If you are a California resident, you have the right to request access to your data, request deletion, and opt-out of the "sale" or "sharing" of your personal information. We do not sell your personal information. To exercise your rights, contact us at privacy@intelligrail.com.
Wyoming, USA (Jurisdiction)
For clients contracting with our US entity, these terms and our data practices are governed by the laws of the State of Wyoming, USA, including mandatory arbitration for dispute resolution where applicable.
8. Contact & Complaints
To exercise your rights or ask a question regarding our privacy practices, please contact our Data Protection Officer: