Legal

Privacy Policy

Effective date: 30 August 2026

1. Who we are

C14 Connect ("C14", "we", "us", "our") is a UK-focused AI lead capture, CRM and omnichannel communications platform. C14 helps service businesses ("Customers", "you" when we mean a business using C14) qualify website enquiries with an AI assistant ("Atlas"), organise them into a customer relationship management (CRM) system, and manage conversations across their website chat widget, Facebook Messenger and Instagram Direct Messages from one workspace.

This policy explains what personal data C14 collects and processes, why, and the rights available to the people it concerns. It applies to:

  • visitors to our own website at c14connect.co.uk;
  • people who sign up for and use a C14 account (Customers and their team members); and
  • people who interact with a C14 Customer's website chat widget, Facebook Page or Instagram account — referred to below as "End Users".

C14 Connect is a UK-based trading name, operated by its owner as a sole trader. C14 Connect is not a limited company or other incorporated entity, and does not have a company registration number. For the purposes of UK data protection law, the individual trading as C14 Connect is the controller or processor referred to throughout this policy — see Section 18 for how to contact us.

2. Controller and processor roles

Data protection law distinguishes between a controller (the organisation that decides why and how personal data is processed) and a processor(an organisation that processes personal data on a controller's instructions).

  • C14 is the controller for data about our own website visitors, and about Customers and their team members — account details, billing information, and how they use the C14 product itself.
  • C14 is a processor(and the Customer is the controller) for personal data belonging to a Customer's own End Users — for example, a message someone sends to a Customer's Facebook Page, Instagram account or website chat widget, and any CRM record a Customer creates about their own contacts. Section 14 below explains what this means in practice.

3. Information you give us directly

When you create or use a C14 account, we collect:

  • Account data — your name, email address and password (stored by our authentication provider, Supabase, using industry-standard password hashing — we never see or store your password in plain text), and the name of the business/organisation you set up.
  • Team and invitation data — if you invite a colleague to your workspace, we process their email address to send them an invitation.
  • Billing and subscription data— your subscription plan and status. Card payments are handled entirely by Stripe on Stripe's own hosted checkout and billing portal pages — C14's servers never receive or store your card number.
  • Business content you provide — information you add to configure Atlas (business knowledge, FAQs, services) and any content you upload or type while using the product.
  • Correspondence — if you contact us for support, we process what you send us in order to respond.

4. Information processed on behalf of our Customers

Where a Customer uses C14 to run their own communications, we process personal data about that Customer's End Users on the Customer's behalf and instructions, as their processor:

  • CRM and contact data— names, contact details and any other information a Customer chooses to record about their own customers/leads inside C14's CRM, including notes, tasks and activity history the Customer or Atlas creates.
  • Website widget conversations— messages exchanged between an End User and a Customer's embedded chat widget, including any contact details an End User provides through it (e.g. via a lead-capture form inside the chat).
  • Facebook Messenger and Instagram messages— the content of messages sent to and from a Customer's connected Facebook Page or Instagram professional account, timestamps, and metadata about any attachments (we record attachment type and a temporary link Meta provides; we do not download or store the media file itself).
  • Meta account and identifiers— the Facebook Page ID, linked Instagram professional account ID, and the message sender's platform-scoped identifier (a Page-Scoped ID or Instagram-Scoped ID). These identifiers are issued by Meta, are specific to the Customer's connected account, and are not a person's real name, phone number or global social media identity. Where Meta's API grants permission, we may also retrieve a sender's first name or username to display in the Customer's inbox.

5. Connecting Facebook and Instagram (OAuth)

When a Customer connects a Facebook Page or Instagram account, Meta issues C14 an access token authorising us to send and receive messages on the Customer's behalf, within the scope the Customer approves during Meta's own consent screen. That access token is encrypted before storage and is only ever decrypted at the moment it is needed to make an authorised call to Meta's API — we do not expose it to Customers, End Users, or any part of the product outside that transport layer. A Customer can revoke this access at any time by disconnecting the channel inside C14, or by removing C14's access from their own Facebook/Instagram account settings.

6. AI processing (Atlas)

Atlas, C14's AI assistant, is powered by OpenAI. To generate a reply or qualify a conversation, we send OpenAI the relevant conversation content (the End User's messages and, where useful, prior turns in that conversation) together with the Customer's own business context they have configured (such as services offered and FAQs). This is used solely to generate that response and to support lead qualification and CRM automation described below — it is not used by C14 to build advertising profiles.

7. Lead qualification and CRM creation

Based on a conversation, Atlas may determine that an enquiry looks like a genuine lead, extract details such as a name, contact method or the service being asked about, and create or update a CRM contact, task or follow-up for the Customer automatically. This automation exists to save the Customer time; a Customer's team can review, edit or delete any record Atlas creates.

8. Cookies and local storage

C14's own marketing website does not use analytics, advertising or tracking cookies. The technical storage we use is limited to what is strictly necessary to run the product:

  • Authentication cookies — when you sign in to a C14 account, our authentication provider (Supabase) sets essential session cookies so you stay signed in. These are required for the product to function and cannot be switched off while remaining signed in.
  • Chat widget local storage— the embeddable chat widget stores a randomly generated visitor/session identifier in your browser's local storage so that returning to the same website continues the same conversation, plus a small marker if you have dismissed the widget or it has already auto-opened once in your browsing session. None of this identifies you personally on its own.

9. Why we process this data (purposes)

  • to provide, operate and maintain the C14 product for our Customers;
  • to let Atlas answer, qualify and route conversations across the website widget, Messenger and Instagram;
  • to create and maintain CRM records, tasks and follow-ups on a Customer's behalf;
  • to authenticate users and secure accounts;
  • to process subscription billing and payments;
  • to communicate with account holders about their account, service changes or support requests;
  • to detect, investigate and prevent fraud, abuse or security incidents; and
  • to comply with our legal and regulatory obligations.

10. Our lawful bases (UK GDPR)

Under the UK General Data Protection Regulation and the Data Protection Act 2018, we rely on:

  • Contract(Article 6(1)(b)) — to provide the C14 service to account holders, and, on a Customer's behalf, to respond to an End User who has engaged with that Customer's business;
  • Legitimate interests(Article 6(1)(f)) — to run, secure and improve the product, and for a Customer's own legitimate interest in responding promptly to their enquiries — balanced against the interests and rights of the individuals concerned;
  • Legal obligation (Article 6(1)(c)) — for matters such as tax and accounting records; and
  • Consent(Article 6(1)(a)) — where a Customer or Meta's own platform requires it, for example the consent an End User gives Meta before messaging a business on Instagram or Messenger.

11. Who we share data with (processors and service providers)

We do not sell personal data. We share it only with the service providers who help us run C14, each acting under contractual obligations consistent with UK GDPR:

  • Supabase — database hosting and authentication.
  • OpenAI — AI processing that powers Atlas.
  • Stripe — subscription billing and payment processing.
  • Resend — transactional email delivery (e.g. welcome emails).
  • Meta Platforms, Inc. — the platform through which Facebook Messenger and Instagram messages are sent and received; Meta processes this data under its own terms as the platform operator.
  • Google (Places API)— used only when a Customer searches for prospective businesses to contact; this looks up publicly available business listing information and does not involve an End User's or Customer account holder's personal data.
  • Vercel — application hosting for our website and product infrastructure.

We may also disclose personal data where required by law, to enforce our terms, or to protect the rights, safety or property of C14, our Customers, or others.

12. International data transfers

Some of the service providers listed in Section 11 may process or store personal data outside the UK. Where that is the case, we rely on the appropriate UK data-transfer safeguards recognised under UK GDPR — such as an applicable UK adequacy regulation, the UK International Data Transfer Addendum, or equivalent standard contractual clauses — before that data is transferred.

13. Retention

We keep personal data for as long as reasonably necessary for the purposes described in this policy — for example, for as long as a Customer's account remains active, or as long as a Customer chooses to retain a particular CRM record or conversation. Some data (such as billing records) must be kept for longer to meet our legal and accounting obligations. When data is no longer needed, we delete or anonymise it.

14. If you are an End User of a C14 Customer

If you have messaged a business on their website chat widget, Facebook Page or Instagram account and that business uses C14, the business itself is the data controllerresponsible for your personal data — C14 processes it strictly on that business's instructions, as their processor. This means:

  • requests about your data (access, correction, deletion) should generally be directed to that business first; and
  • C14 will assist that business in responding to such a request, in line with our contract with them.

You can still contact us directly using the details in Section 18, and we will help direct your request appropriately.

15. Security

We apply technical and organisational measures designed to protect personal data, including encrypting access tokens for connected messaging channels at rest, restricting who can access production systems, and using reputable, established infrastructure providers. No method of transmission or storage is completely secure, but we work to protect personal data appropriate to the risk.

16. Your rights

Under UK GDPR, depending on the circumstances, you have the right to:

  • be informed about how your data is used;
  • access a copy of your personal data;
  • have inaccurate data corrected;
  • have your data erased in certain circumstances;
  • restrict or object to certain processing, including processing based on legitimate interests;
  • request your data in a portable format;
  • withdraw consent at any time where we rely on consent; and
  • lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk, though we would welcome the chance to resolve any concern directly first.

To exercise any of these rights, contact us using the details in Section 18.

17. Children

C14 is a business-to-business product and is not directed at children. We do not knowingly collect personal data from children, and Customers must not use C14 to knowingly do so either.

18. Contact us

If you have questions about this policy or how we handle personal data, contact us at privacy@c14connect.co.uk.

19. Changes to this policy

We may update this policy from time to time, for example as the product changes or to reflect legal requirements. We will update the effective date above when we do, and where changes are significant we will take reasonable steps to make that clear.