We act as your processor
You decide why and how your customers are contacted. We process their data only on your instructions, to confirm the job you sent.
AnyoneIn talks to your customers on your behalf, so it has to be trustworthy on the doorstep and in the data centre. Here's exactly how it handles their data, how the agent behaves, and what's still on the roadmap.
Last reviewed: · Pending legal review
Your order system sends a job. AnyoneIn contacts the customer through two subprocessors, reads the reply, and sends the outcome back. That's the whole journey.
What we ask your system for
What we never need
The agent never asks customers for payment or personal details, on any channel.
You decide why and how your customers are contacted. We process their data only on your instructions, to confirm the job you sent.
Our data processing agreement covers the subprocessors, regions, retention and security measures on this page. Request it
Only the fields needed to confirm a visit. On a call, the agent reads out the first line of the address at most, and only if the customer asks.
Choose how long jobs, messages and call transcripts are kept. Planned default: transcripts deleted after 90 days Assumption
The service runs on Google Cloud in London (europe-west2). EU hosting in Belgium (europe-west1) is available on request.
TLS on every connection, including the webhooks we send you. Data at rest is encrypted by Google Cloud's storage encryption.
These are the only subprocessors that handle your customers' data. We'll tell you before we add or change one.
| Subprocessor | What for | Data it handles | Region |
|---|---|---|---|
| Google CloudCloud Run, storage, Secret Manager | Hosting the service, the job store and the customer page | Everything in a job, and its conversation | London, UKeurope-west2 |
| Google CloudGemini, speech | Reading replies, running the call conversation, the voice and speech recognition | Message text, call audio as it streams, the job details it needs | Google CloudProcessing region set out in the DPA |
| Telecoms providerMessaging and voice · named in the DPA | Sending texts and WhatsApp messages, placing and receiving calls | Mobile number, message content, call audio in transit | Provider networkTransfers covered by the provider’s DPA |
| Google WorkspaceGmail | Sending confirmation emails and receiving replies | Email address, message content | Google WorkspaceData regions set out in the DPA |
We don't use your customers' data to train AI models. Processing regions and international transfer terms are confirmed in the DPA before a pilot starts.
They’re written into the agent’s instructions and apply to every message and every turn of every call.
The first thing the customer hears is who's calling and that it's an automated assistant. Ask it whether it's a robot and it says yes, then carries on.
No order details until it knows it's speaking to the customer or someone in their household. It never reads out the full address, phone number or email: only the first line, and only if they ask where.
A reply is only ever treated as a reply. If it contains instructions to change the rules, reveal its instructions or act for someone else, the agent ignores them and carries on confirming.
Ask for a person, sound unhappy, or raise something it can't handle (damage, refunds, a complaint, a price) and it hands over to your team. It never invents facts, prices or promises, and automated replies are capped so it can't get stuck in a loop.
Calls are transcribed so your team can see exactly what was said, in the console, next to every outcome. The customer is told through your privacy notice. The call audio itself isn't stored.
Before launch A spoken line about the transcript, added to the call opening.
Checking someone will be in for an order they've placed is a service message. Selling to them is marketing. AnyoneIn keeps the two apart.
Service
Sent by email, text and phone call as part of fulfilling the order.
Marketing · upsells coming soon
These are the PECR rules. Read the ICO's guidance on direct marketing (opens in a new tab).
Texts and calls go out between 9am and 8pm, UK time. Emails between 7am and 9pm. An unanswered call gets one retry, a few hours later, and that's it.
Texts and calls Email
Reply STOP to a text, say "stop calling me" on the phone, or ask by email: the plan ends on every channel and the agent confirms it won't message again.
Every call is placed for one specific job and the agent speaks the moment it connects. If a machine answers, it leaves a short voicemail. Customers can ring the number back and reach the same agent. We follow Ofcom's persistent misuse policy (opens in a new tab).
Signed in both directions, rate limited, with secrets out of the code and a service account that can only do its job.
Every event we send carries an HMAC-SHA256 signature of the body. Verify it with your secret before you trust it.
X-AnyoneIn-Signature: sha256=9f2c…e41a
Links in emails and texts are signed, so they can't be guessed or altered. Opening one never changes anything, because mail scanners open links on their own.
Every inbound text and call webhook carries the provider’s signature, and it’s verified. Anything that fails is rejected and logged.
Sliding-window limits per IP address on creating confirmations, verification and the lead forms, so nobody can use the service to flood phones.
API keys, signing keys and provider tokens live in Google Secret Manager, never in code, images or config files.
The service runs as its own service account, with access only to the storage and secrets it uses.
strict-transport-security: max-age=31536000;
includeSubDomains
content-security-policy: default-src 'self';
script-src 'self'; frame-ancestors 'none';
object-src 'none'; base-uri 'self'
x-frame-options: DENY
x-content-type-options: nosniff
referrer-policy: strict-origin-when-cross-origin
permissions-policy: camera=(), microphone=(),
geolocation=()
A strict content security policy and security headers on every response. No third-party scripts on this site or the customer page.
We don't hold any security certifications today. When that changes, it'll change here first, with the certificate to back it.
SAML and Google sign-in for the ops console.
Who looked at, changed or exported what, and when.
An independent audit of our security controls. Not certified.
A certified information security management system. Not certified.
In the meantime, we'll answer your security questionnaire and walk your IT team through the architecture.
The data processing agreement, the subprocessor list and answers to your security questionnaire, before you commit to anything.
Last reviewed: · Pending legal review. This page describes the service today and isn't legal advice.