This policy explains how BioAgent (operated by Intelligent Labs Ltd) collects, uses, stores and protects personal data — including data processed through the BioAgent AI receptionist service (operating as Stacy) and Meta platform integrations (Instagram and Facebook).
BioAgent is an AI receptionist and messaging automation service operated by Intelligent Labs Ltd — a UK registered company. BioAgent provides AI-powered receptionist, call handling, and social media DM automation services to businesses across the UK, UAE, and Saudi Arabia.
Intelligent Labs Ltd is the data controller for personal data collected through our website and the data processor for personal data collected on behalf of our business clients through the BioAgent platform.
| Detail | Information |
|---|---|
| Service / Brand name | BioAgent |
| Legal entity | Intelligent Labs Ltd |
| Company number | 17250096 |
| Registered in | England & Wales |
| Registered address | The Warehouse, 53 Ormrod St, Bury, BL9 7HF |
| info@intelligent-labs.co.uk | |
| Website | intelligent-labs.co.uk |
When you visit our website we may collect:
When a business signs up for BioAgent services we collect:
When an end user interacts with a BioAgent-powered service on behalf of one of our business clients, the following data may be collected on behalf of that client:
Important: When BioAgent is deployed for a business client, that business is the Data Controller for their customers' data. Intelligent Labs Ltd acts as the Data Processor. The client's own privacy policy also applies to their customers' data.
BioAgent's DM Automation service connects to a business client's Instagram Business account and/or Facebook Page via Meta's official APIs. Conversations are handled by Stacy — BioAgent's AI receptionist. When a user sends a Direct Message to that business account, Stacy (powered by BioAgent):
BioAgent connects directly to Meta's official APIs — the Instagram Graph API and the Messenger Platform API — via secure webhooks. We do not use third party intermediary platforms to access Meta data. All data received from Meta is processed directly by BioAgent's systems in compliance with Meta's Platform Terms and Developer Policies.
When processing Instagram and Facebook DMs on behalf of a business client, we receive and process the following data from Meta:
| Data type | Source | Purpose | Retention |
|---|---|---|---|
| Subscriber ID (unique Meta user identifier) | Meta webhook payload | Identify the user across the conversation | 30 days maximum |
| First name and last name | Meta webhook payload | Personalise responses | 30 days maximum |
| Message content | Meta webhook payload | Generate AI responses | 30 days maximum |
| Timestamp | Meta webhook payload | Conversation management | 30 days maximum |
| Channel type (Instagram/Facebook) | Meta webhook payload | Route responses correctly | 30 days maximum |
Users who interact with a BioAgent-powered Instagram or Facebook account (including conversations with Stacy, BioAgent's AI receptionist) can opt out of automated messaging at any time by sending any of the following keywords in a Direct Message:
Upon receiving any of these keywords the system will immediately cease all automated responses, send a single confirmation message — "You've been unsubscribed from automated messages. Reply START to opt back in." — and add the user to an opted-out list. No further automated messages will be sent unless the user actively opts back in.
Users can opt back in at any time by sending START. Upon receipt of START the system will resume automated responses and send a welcome confirmation message.
Opt-out requests are processed immediately and automatically — no human intervention is required.
Use of Instagram and Facebook is also subject to Meta's own Privacy Policy, available at facebook.com/privacy/policy. Intelligent Labs Ltd operates within Meta's Platform Terms and Developer Policies at all times.
In compliance with Meta's Messenger Platform policy, BioAgent only sends automated responses within the 24-hour messaging window following a user-initiated message. We do not send unsolicited messages outside of this window.
BioAgent does not send messages outside the standard 24-hour messaging window.
BioAgent's DM automation service operates under the persona name Stacy — an AI receptionist. Stacy is not a human. When a user asks whether they are speaking to a real person or an AI, Stacy is configured to identify itself as a AI assistant and will never claim to be human.
Stacy responds on behalf of the business whose account the user has contacted. The business is responsible for informing their customers that automated AI responses may be used when contacting their social media accounts.
If a user wishes to speak to a human representative, Stacy will offer to connect them with the business team during business hours.
BioAgent operates an automated nightly data cleanup process that permanently deletes all Instagram and Facebook DM conversation history older than 30 days from our systems. This process runs automatically every night without manual intervention.
This means:
Note that the business client's own CRM may retain a summary of the booking or enquiry outcome (name, phone number, treatment interest) for their own legitimate business purposes and in accordance with their own data retention policy.
BioAgent uses secure HTTPS webhooks to receive data from Meta's platforms. All webhook endpoints are:
Any request that fails webhook validation is rejected immediately and logged.
BioAgent's AI persona Stacy is configured to offer human handoff in the following situations:
During business hours, human handoff connects the user with the business client's team directly. Outside business hours, the user is informed of business hours and offered a callback.
BioAgent's Meta integration is strictly prohibited from being used for:
Business clients who use BioAgent agree in writing (via our Service Agreement) that they will not attempt to use the platform for any prohibited purpose. Intelligent Labs Ltd reserves the right to immediately suspend access for any client found to be in breach of these restrictions.
We use personal data for the following purposes:
We do not use personal data for automated decision-making that produces legal or similarly significant effects on individuals.
We rely on the following legal bases under UK GDPR Article 6:
| Processing activity | Legal basis |
|---|---|
| Responding to website enquiries | Legitimate interests (Article 6(1)(f)) |
| Delivering BioAgent services to business clients | Contract performance (Article 6(1)(b)) |
| Processing end user data on behalf of business clients | Legitimate interests of the data controller (our client) (Article 6(1)(f)) |
| Instagram and Facebook DM automation | Legitimate interests — the user initiated the conversation by contacting the business (Article 6(1)(f)) |
| Legal and compliance obligations | Legal obligation (Article 6(1)(c)) |
We use the following third party platforms to deliver our services. Each is subject to a data processing agreement or operates under equivalent safeguards:
| Platform | Purpose | Data shared | Location |
|---|---|---|---|
| Retell AI | Voice AI engine | Call audio, transcripts | USA (SCCs in place) |
| Make.com | Workflow automation | Conversation data, booking details | EU |
| HubSpot | CRM | Contact name, phone, enquiry details | USA (SCCs in place) |
| Stripe | Payment processing | Payment data (processed by Stripe directly) | USA (SCCs in place) |
| Zoho Mail | Email communications | Email content | EU |
| Netlify | Website hosting | Contact form submissions | USA (SCCs in place) |
| Anthropic (Claude API) | AI language model | Conversation text (processed in real time) | USA (SCCs in place) |
| Meta (Instagram/Facebook) | DM platform | Message content, subscriber ID | USA (SCCs in place) |
We do not sell personal data to any third party. We do not share personal data for marketing or advertising purposes.
| Data type | Retention period | Reason |
|---|---|---|
| Website contact form submissions | 12 months | To manage and respond to enquiries |
| Instagram / Facebook DM conversation history | 30 days maximum — automatically deleted by nightly cleanup process | Conversation context only. An automated nightly process checks all records and permanently deletes any conversation history older than 30 days. This is automatic and requires no manual intervention. |
| Call recordings and transcripts | 90 days maximum | Quality assurance and dispute resolution |
| CRM contact records (client data) | Duration of client contract + 30 days | Service delivery |
| Business client account data | Duration of contract + 7 years | Legal and financial compliance |
| Payment records | 7 years | HMRC legal requirement |
On termination of a client contract, all end user personal data held on behalf of that client is deleted within 30 days of the termination date.
Under UK GDPR you have the following rights in relation to your personal data:
To exercise any of these rights please contact us at info@intelligent-labs.co.uk. We will respond within 30 days. There is no charge for reasonable requests.
If you are not satisfied with our response you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk or by calling 0303 123 1113.
Our website uses minimal cookies. We do not use advertising cookies, tracking pixels, or third party analytics cookies that identify individual users.
Standard session cookies may be set by our hosting provider (Netlify) for security and performance purposes. These do not contain personal data and expire when you close your browser.
Our contact forms use Netlify Forms which may set a session cookie for spam prevention. This cookie does not track you across other websites.
Our services are not directed at children under the age of 18. We do not knowingly collect personal data from children.
Where a BioAgent-powered AI agent detects that a caller or DM sender may be under 18, the agent is configured to decline to book treatments requiring minimum age compliance and to direct the individual to contact the business directly during business hours.
If you believe we have inadvertently collected data from a child please contact us immediately at info@intelligent-labs.co.uk and we will delete it promptly.
Some of our third party service providers are based outside the UK and EEA. Where personal data is transferred internationally we ensure appropriate safeguards are in place including:
All international transfers are documented and assessed under our Transfer Impact Assessment process.
We take the security of personal data seriously. Our technical and organisational measures include:
In the event of a personal data breach we will notify affected clients within 48 hours and the ICO within 72 hours where required by UK GDPR Article 33.
Our full Information Security Policy is available on request.
We may update this Privacy Policy from time to time to reflect changes in our services, technology, or legal requirements. When we make significant changes we will update the "Last updated" date at the top of this page.
We encourage you to review this policy periodically. Continued use of our services following any update constitutes acceptance of the revised policy.
For any questions about this Privacy Policy, to exercise your data rights, or to report a data protection concern please contact us: