Privacy Policy
What we collect, why we collect it, who we share it with, and what you can ask us to do about it.
Effective July 31, 2026
1. Who we are
BEDROCK AI LLC (“Bedrock AI”, “we”, “us”, “our”) is a Limited Liability Company registered in State of Texas, United States. We build and operate custom AI agents for businesses. This policy covers our website at www.getbedrockai.com and the services we provide to our clients.
Data controller and contact details:
BEDROCK AI LLC
4972 State Hwy 30
Huntsville, TX 77340, United States
Email: gage@getbedrockai.com
Phone: (936) 355-8233
2. Two different roles we play
It matters which of these applies to you, because your rights differ:
- When you visit this website or enquire about our services, we decide how your information is used. We are the controller and this policy governs directly.
- When you interact with an AI agent we operate for one of our clients — for example if you call a plumbing company that uses Bedrock AI — that client decides how your information is used. They are the controller and we are their processor. We handle your data on their instructions, and their privacy policy governs. We will pass any request you make to them.
3. Information we collect
Information you give us directly
| Where | What | Why |
|---|---|---|
| Contact form | Name, company, email address, business type, service interest, your message, and — both optional — a mobile number and your SMS consent choice | To reply to your enquiry and arrange an audit call, and, only if you ticked the consent box, to send you text messages. Stored in our own database — we do not pass enquiries to a third-party CRM |
| SMS consent record | Your mobile number, the date and time you consented, the exact disclosure you were shown and its version, and the page you were on | To evidence that you asked to be texted, as carriers and law require. Written only when you tick the box, and never altered afterwards |
| Phone and email | Whatever you choose to tell us, plus call records where applicable | To help you and keep a record of what was discussed |
| Becoming a client | Billing contact, business details and payment information handled by our payment processor | To provide and invoice for the service |
Information collected automatically
- Technical data — IP address, browser type and version, device type, operating system, referring page
- Usage data — pages visited, time on page, interactions with the site
- Cookies and similar technologies — see our Cookie Policy
- Error diagnostics — when something breaks, our error monitoring records what went wrong and the technical context around it
Information we process on behalf of clients
When operating agents for a client, we process call recordings and transcripts, SMS and chat conversation content, contact details of the client's customers, appointment details, and consent and opt-out status.
4. SMS and mobile data
Because this is the area people ask about most, it is set out separately:
- Your mobile number is collected on this website in one place only — the contact form — and it is optional there. We treat it as consent to text you only when you also tick the consent box yourself, which is never pre-ticked.
- When you do tick it, we store a record of the consent: the number, the time, the exact wording you agreed to, and the page. That record is append-only — we cannot edit or delete it — which is what makes it evidence rather than an assertion.
- We use it to send you the messages described in our SMS Messaging Policy and for nothing else.
- No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. All other categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties.
- We share it only with the messaging carrier and CRM platform strictly required to deliver those messages.
- Your opt-out status is stored and enforced at the platform level. Once you reply STOP, no system we operate can message you again unless you opt in again.
- We retain opt-out records even after you unsubscribe — specifically so that we can continue to honour your opt-out.
5. How we use your information
- To respond to enquiries and provide the services you request
- To arrange, conduct and follow up on audit calls
- To send text messages you have expressly consented to receive
- To operate, secure, monitor and improve our services
- To take payment and keep accounting records
- To comply with legal obligations, including messaging and consumer protection rules
- To detect and prevent fraud, abuse and security incidents
We do not sell your personal information, and we do not share it for cross-context behavioural advertising.
Legal bases (where GDPR or similar law applies)
- Consent — marketing text messages, non-essential cookies
- Contract — providing services you have engaged us for
- Legitimate interests — responding to enquiries, securing our systems, improving our services
- Legal obligation — tax, accounting and regulatory record-keeping
6. AI processing
Our service uses large language models to understand and generate conversation. When an agent handles a call or message, the content is processed by these models to produce a response. We use enterprise API arrangements with our model providers under which your content is not used to train their models. We do not use client conversation data to train models of our own.
Our agents identify themselves as an automated assistant when asked and do not claim to be a specific human being.
7. Who we share information with
We share personal information only with service providers who need it to run the service, each bound by contract to protect it and to use it only for the purpose we specify:
| Provider | Purpose |
|---|---|
| Twilio | Voice and SMS delivery |
| Neon | Managed database hosting |
| Railway | Application hosting |
| Sentry | Error monitoring and diagnostics |
| Large language model providers | Agent language understanding and generation |
We may also disclose information:
- To comply with law, legal process, or a lawful government request
- To enforce our Terms of Service or protect our rights, safety or property
- In connection with a merger, acquisition or sale of assets — in which case we will notify you before your information becomes subject to a different policy
8. How long we keep it
- Enquiries that do not become clients — up to 24 months, then deleted. Held in our own database, and deletable on request at any time before that
- Client account and conversation data — for the life of the agreement, then deleted or returned on request
- Billing and tax records — as long as tax law requires, typically seven years
- SMS opt-in and opt-out records — retained indefinitely, so that we can keep honouring an opt-out and can still show what an opt-in consisted of. These are the one category we cannot delete on request: they are the evidence that we were entitled to message you, and carrier and consumer protection rules require us to be able to produce them.
9. How we protect it
Traffic is encrypted in transit with TLS and data at rest is encrypted by our managed infrastructure providers. Client data is isolated at the database layer. Access to production systems is individually authenticated, limited to personnel who need it, and logged. Full detail is on our Security page.
No system is perfectly secure, and we will not claim otherwise. If a breach affects your information we will notify you and any relevant regulator as required by law, without undue delay.
10. Your rights
Depending on where you live, you may have the right to:
- Access the personal information we hold about you
- Correct information that is inaccurate
- Delete your personal information
- Port your data to another provider
- Opt out of marketing at any time
- Withdraw consent you previously gave
- Not be discriminated against for exercising any of these rights
To exercise any of these, email gage@getbedrockai.com. We will respond within 45 days (extendable once where permitted). We may need to verify your identity first — we will only ask for what is necessary to do so.
California residents: we do not sell or share personal information as those terms are defined under the CCPA/CPRA, and we have not done so in the preceding 12 months. You may designate an authorised agent to make a request on your behalf.
EEA/UK residents: you may lodge a complaint with your local supervisory authority. We would prefer you raise it with us first so we can try to put it right.
11. Children
Our services are for businesses and are not directed at anyone under 18. We do not knowingly collect personal information from children. If you believe a child has provided us information, contact us and we will delete it.
12. International transfers
We are based in the United States and process data there. If you are outside the US, your information will be transferred to and processed in the US, where data protection law may differ from your own. Where required, we rely on appropriate safeguards such as Standard Contractual Clauses.
13. Changes to this policy
We may update this policy from time to time. The effective date at the top reflects the latest version. If we make material changes to how we use your information, we will notify you by email or a prominent notice on this site before they take effect.
14. Contact us
Questions, requests or complaints about privacy:
BEDROCK AI LLC
4972 State Hwy 30
Huntsville, TX 77340
United States
Email: gage@getbedrockai.com
Phone: (936) 355-8233