Legal
Privacy Policy
What we collect, why we collect it, and what you can tell us to do with it. If anything here is unclear, email us and we'll explain it properly.
Version 1.0 · Last updated 9 September 2026 · Applies to leonardopower.com and to the services we run for our clients
1. Who we are
Leonardo Power is a trading name of Leonardo da Vinci Ltd, a company registered in England and Wales under company number 15428163, with its registered office at 97 Ashcombe Road, Dorking, England, RH4 1LW.
For the information described in this notice, we are the data controller — we decide what is collected and why. The one big exception is set out in section 6.
You can reach us about anything on this page:
- Email hello@leonardopower.com
- Phone +44 20 4572 2164
- Post: Data Protection, Leonardo da Vinci Ltd, 97 Ashcombe Road, Dorking, RH4 1LW
We are registered with the Information Commissioner's Office under reference ZB763905.
We are not required to appoint a Data Protection Officer, and we haven't. Questions go to the address above and are answered by a director.
2. The short version
If you fill in a form on this site, your details go into our CRM so we can reply and quote. If you ask our demo to ring you, we record that call and send you the recording.
We advertise on Google, Facebook, Instagram and TikTok. Those platforms only get to recognise your browser if you say yes to advertising cookies — and the tags that do it are not loaded at all until you do.
We don't sell your personal information, and we never will. You can ask to see what we hold, have it corrected, or have it deleted, and we'll do it within a month.
3. What we collect
When you just look at the site
Our host records the usual server information — your IP address, the pages requested, the time, your browser and device type, and the site that sent you. This happens for every website and is how a server works out what to send you and spots attacks.
The typefaces on this site are served by Google Fonts, which means Google receives your IP address when the fonts load. This happens before any cookie choice, because it is part of drawing the page. If that concerns you, we can self-host the fonts for a client site on request.
When you fill in the “Start a project” form
Your name, business name, email address, phone number if you give one, what you told us you need, and anything you write in the message box.
When you ask the demo to ring you
Your name, business name, mobile number, email address, and the question you told us your customers ask most. We text a code to that number to check it is yours before anything rings. We then create a recording, a transcript and a written summary of the call, and email them to you. See section 5.
When you book a call
Our booking diary is run by LeadConnector (HighLevel). Whatever you type into it — name, email, phone, the slot you pick — goes to them and into our CRM.
When you talk to the assistant on this site
Everything typed into the assistant window is stored against your record so nobody has to ask you the same question twice. Please don't type anything into it you wouldn't put in an email.
When you become a client
Contact details for you and the people at your business we deal with, billing details, the content and material you send us for the build, the logins we need to do the work, and our correspondence with you.
What we don't collect
We don't ask for special category data — health, ethnicity, beliefs, biometrics, sexuality — and you shouldn't send it to us.
No card details are typed into this website. Paying takes you to a secure checkout hosted by our payment provider, where Stripe handles the card. We receive confirmation that it worked, the last four digits and the expiry date — never the full number.
4. Why, and our lawful basis
UK GDPR says we need a lawful reason for each use. Here they are, in full.
| What we do | Why | Lawful basis |
|---|---|---|
| Answer your enquiry and quote | You asked us to | Legitimate interests — responding to someone who contacted us about our services. Before a contract, and at your request. |
| Ring you with the demo, and record it | To show you what the product does, and to send you the recording | Consent — you tick the box and confirm a code we text you. Withdraw it any time and we delete the recording. |
| Deliver the service you've bought | Building the site, training the voice, running the CRM, hosting and support | Performance of a contract |
| Invoice you and keep the books | We have to | Legal obligation — HMRC requires records to be kept for six years |
| Send you service messages | Downtime, renewals, changes to a live site | Performance of a contract |
| Send marketing email to businesses | To tell you about what we do | Legitimate interests where you are a business contact and we've dealt with you, or consent otherwise. Every message has an unsubscribe link that works. |
| Measure how the site performs | To find the pages that aren't working | Consent — analytics cookies, off by default |
| Advertise on Google, Meta and TikTok | To reach people like you, and to stop paying to show you the same ad twice | Consent — advertising cookies, off by default |
| Keep the site up and defend it | Security, abuse, fraud, backups | Legitimate interests — running a service that stays up |
Where we rely on legitimate interests, we've weighed our interest against your rights and concluded it's what you'd reasonably expect. You can object — see section 11 — and we'll stop unless we have compelling grounds not to.
5. The AI receptionist and call recording
This is the part of our business people ask about most, so it gets its own section.
The demo call to your mobile
When you ask our demo to ring you, an automated voice — not a person — calls the number you gave and answers as though it worked for your business. That call is recorded and transcribed, and the recording, transcript and a short summary are emailed to you and saved against your record.
You are told this before the call, by ticking the consent box. The assistant also identifies itself as automated at the start of the call. We ring the number once. If you want the recording and transcript deleted, email us and we'll delete them, usually the same working day.
Calls answered by an assistant we've built for a client
If you have rung a business whose phone is answered by an assistant we built, that call may be recorded, transcribed and summarised into that business's CRM. In that situation the business you rang is the data controller, not us — we run the system on their instructions. Ask them for their privacy notice, or contact us and we will pass your request on.
What the assistant is, plainly
It is software. It can be wrong. It works from information the business has given it about prices, services and availability, and it is instructed to hand over to a human when it doesn't know. Nothing it says is legal, medical or financial advice, and it must not be used for emergencies — if it's an emergency, call 999.
We build and run the voice and the transcription ourselves. Your calls are not sent to somebody else's AI service to be interpreted, and we do not use recordings or transcripts to train AI models — ours or anyone else's.
What we buy is the ground it stands on. The system runs on Google Cloud, which is also where recordings and transcripts are stored, and calls reach the public telephone network through a licensed carrier. Both are our processors: they hold the data on our instructions, they don't use it for their own purposes, and Google's cloud terms prohibit it being used to train Google's models.
6. When the data isn't ours
Most of what our systems hold is not our data at all — it belongs to our clients, and it is about their customers.
When we run a website, an assistant and a CRM for a client, that client is the controller and we are their processor. We only act on their written instructions, we don't use their customers' data for our own purposes, and our contract with them contains the data processing terms UK GDPR Article 28 requires.
If you are a customer of one of our clients and want to see or delete what is held about you, ask that business directly. If you contact us instead, we'll tell them and help them answer you, but we cannot make that decision for them.
7. Cookies and advertising
We advertise on Google Ads, Meta (Facebook and Instagram) and TikTok. To measure whether those ads work, and to avoid paying to show the same ad to someone who has already been here, those platforms need to recognise your browser.
Nothing that does this loads until you consent. No pixel, no tag, no advertising cookie. If you choose “Reject all”, the code is never fetched at all — not merely switched off. If you accept, we use Google Consent Mode so your choice travels with the tag.
We may build audiences on those platforms from people who have visited this site, and we may upload business contact details to create similar audiences. We never upload special category data, and we never sell your data to them or anyone else.
The full list of cookies, what each one does and how long it lasts is in our cookie policy. You can at any time.
9. Sending data outside the UK
Several of the suppliers above are in the United States. When your information goes there, we rely on one of the safeguards UK law allows:
- the UK–US Data Bridge, where the supplier is certified under the UK extension to the EU–US Data Privacy Framework; or
- the International Data Transfer Addendum to the European Commission's standard contractual clauses, backed by a transfer risk assessment.
Ask us and we'll tell you which applies to a given supplier and send you a copy of the relevant terms.
Call recordings and transcripts are stored on Google Cloud in the United States, and the CRM is US-hosted too. We're telling you plainly because most notices bury it. The transfer is covered by the safeguards above, and it puts your data on the same footing as Google Workspace, Microsoft 365 and most business software already in use around you.
If your business is one of the ones that has to keep personal data inside the UK or the EU, tell us before we build. It changes which tools we can use, and it is much easier to design in than to retrofit.
10. How long we keep it
| What | How long |
|---|---|
| An enquiry that never becomes a client | 24 months from your last contact with us, then deleted |
| Demo call recordings and transcripts | 90 days, then deleted — or immediately, if you ask |
| Client records and project files | For the life of the contract, then 6 years |
| Invoices and accounting records | 6 years after the end of the tax year, because HMRC says so |
| Server and security logs | Up to 12 months |
| Your cookie choice | 12 months, then we ask again |
| Marketing suppression list (people who opted out) | Indefinitely — it's the only way to keep not contacting you |
11. Your rights
Under UK GDPR you can ask us to:
- Show you what we hold about you, and give you a copy
- Correct anything that's wrong
- Delete it, where we don't have a reason to keep it
- Stop or limit what we're doing with it
- Hand it over to you or another provider in a portable format
- Object to processing based on legitimate interests
- Stop marketing — this one is absolute, no reasons needed, and we act on it immediately
- Withdraw consent you previously gave, without affecting what was done before you withdrew it
Email hello@leonardopower.com. It's free, and we answer within one month. We may ask you to confirm who you are first — not to be difficult, but because handing your data to someone pretending to be you would be worse.
We don't make decisions about you by automated means that produce a legal or similarly significant effect.
12. Security
The site is served over HTTPS. Access to the CRM is limited to people who need it and protected by two-factor authentication. Credentials for our suppliers are held in a password manager, never in the code, and never in the browser — the form on this site posts to our own server, which holds the keys.
No system is perfect. If we ever have a breach that is likely to put your rights at risk, we'll tell the ICO within 72 hours and tell you without undue delay.
13. Complaints
Tell us first and give us the chance to fix it — hello@leonardopower.com.
If we don't put it right, you can complain to the Information Commissioner's Office, the UK's data protection regulator: ico.org.uk/make-a-complaint, or 0303 123 1113. Complaining to them doesn't cost anything and doesn't affect any other right you have.
14. Changes
When we change this notice we'll change the version number and date at the top. If the change actually affects you — a new supplier seeing your data, a new purpose — we'll tell clients by email rather than quietly updating the page.