Legal

Privacy Policy

What we collect, why we collect it, who we share it with, and what you can ask us to do about it.

Effective July 31, 2026

Mobile information is never sold or shared for marketing. No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. All other categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties.

1. Who we are

BEDROCK AI LLC (“Bedrock AI”, “we”, “us”, “our”) is a Limited Liability Company registered in State of Texas, United States. We build and operate custom AI agents for businesses. This policy covers our website at www.getbedrockai.com and the services we provide to our clients.

Data controller and contact details:
BEDROCK AI LLC
4972 State Hwy 30
Huntsville, TX 77340, United States
Email: gage@getbedrockai.com
Phone: (936) 355-8233

2. Two different roles we play

It matters which of these applies to you, because your rights differ:

  • When you visit this website or enquire about our services, we decide how your information is used. We are the controller and this policy governs directly.
  • When you interact with an AI agent we operate for one of our clients — for example if you call a plumbing company that uses Bedrock AI — that client decides how your information is used. They are the controller and we are their processor. We handle your data on their instructions, and their privacy policy governs. We will pass any request you make to them.

3. Information we collect

Information you give us directly

WhereWhatWhy
Contact formName, company, email address, business type, service interest, your message, and — both optional — a mobile number and your SMS consent choiceTo reply to your enquiry and arrange an audit call, and, only if you ticked the consent box, to send you text messages. Stored in our own database — we do not pass enquiries to a third-party CRM
SMS consent recordYour mobile number, the date and time you consented, the exact disclosure you were shown and its version, and the page you were onTo evidence that you asked to be texted, as carriers and law require. Written only when you tick the box, and never altered afterwards
Phone and emailWhatever you choose to tell us, plus call records where applicableTo help you and keep a record of what was discussed
Becoming a clientBilling contact, business details and payment information handled by our payment processorTo provide and invoice for the service

Information collected automatically

  • Technical data — IP address, browser type and version, device type, operating system, referring page
  • Usage data — pages visited, time on page, interactions with the site
  • Cookies and similar technologies — see our Cookie Policy
  • Error diagnostics — when something breaks, our error monitoring records what went wrong and the technical context around it

Information we process on behalf of clients

When operating agents for a client, we process call recordings and transcripts, SMS and chat conversation content, contact details of the client's customers, appointment details, and consent and opt-out status.

4. SMS and mobile data

Because this is the area people ask about most, it is set out separately:

  • Your mobile number is collected on this website in one place only — the contact form — and it is optional there. We treat it as consent to text you only when you also tick the consent box yourself, which is never pre-ticked.
  • When you do tick it, we store a record of the consent: the number, the time, the exact wording you agreed to, and the page. That record is append-only — we cannot edit or delete it — which is what makes it evidence rather than an assertion.
  • We use it to send you the messages described in our SMS Messaging Policy and for nothing else.
  • No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. All other categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties.
  • We share it only with the messaging carrier and CRM platform strictly required to deliver those messages.
  • Your opt-out status is stored and enforced at the platform level. Once you reply STOP, no system we operate can message you again unless you opt in again.
  • We retain opt-out records even after you unsubscribe — specifically so that we can continue to honour your opt-out.

5. How we use your information

  • To respond to enquiries and provide the services you request
  • To arrange, conduct and follow up on audit calls
  • To send text messages you have expressly consented to receive
  • To operate, secure, monitor and improve our services
  • To take payment and keep accounting records
  • To comply with legal obligations, including messaging and consumer protection rules
  • To detect and prevent fraud, abuse and security incidents

We do not sell your personal information, and we do not share it for cross-context behavioural advertising.

Legal bases (where GDPR or similar law applies)

  • Consent — marketing text messages, non-essential cookies
  • Contract — providing services you have engaged us for
  • Legitimate interests — responding to enquiries, securing our systems, improving our services
  • Legal obligation — tax, accounting and regulatory record-keeping

6. AI processing

Our service uses large language models to understand and generate conversation. When an agent handles a call or message, the content is processed by these models to produce a response. We use enterprise API arrangements with our model providers under which your content is not used to train their models. We do not use client conversation data to train models of our own.

Our agents identify themselves as an automated assistant when asked and do not claim to be a specific human being.

7. Who we share information with

We share personal information only with service providers who need it to run the service, each bound by contract to protect it and to use it only for the purpose we specify:

ProviderPurpose
TwilioVoice and SMS delivery
NeonManaged database hosting
RailwayApplication hosting
SentryError monitoring and diagnostics
Large language model providersAgent language understanding and generation

We may also disclose information:

  • To comply with law, legal process, or a lawful government request
  • To enforce our Terms of Service or protect our rights, safety or property
  • In connection with a merger, acquisition or sale of assets — in which case we will notify you before your information becomes subject to a different policy

8. How long we keep it

  • Enquiries that do not become clients — up to 24 months, then deleted. Held in our own database, and deletable on request at any time before that
  • Client account and conversation data — for the life of the agreement, then deleted or returned on request
  • Billing and tax records — as long as tax law requires, typically seven years
  • SMS opt-in and opt-out records — retained indefinitely, so that we can keep honouring an opt-out and can still show what an opt-in consisted of. These are the one category we cannot delete on request: they are the evidence that we were entitled to message you, and carrier and consumer protection rules require us to be able to produce them.

9. How we protect it

Traffic is encrypted in transit with TLS and data at rest is encrypted by our managed infrastructure providers. Client data is isolated at the database layer. Access to production systems is individually authenticated, limited to personnel who need it, and logged. Full detail is on our Security page.

No system is perfectly secure, and we will not claim otherwise. If a breach affects your information we will notify you and any relevant regulator as required by law, without undue delay.

10. Your rights

Depending on where you live, you may have the right to:

  • Access the personal information we hold about you
  • Correct information that is inaccurate
  • Delete your personal information
  • Port your data to another provider
  • Opt out of marketing at any time
  • Withdraw consent you previously gave
  • Not be discriminated against for exercising any of these rights

To exercise any of these, email gage@getbedrockai.com. We will respond within 45 days (extendable once where permitted). We may need to verify your identity first — we will only ask for what is necessary to do so.

California residents: we do not sell or share personal information as those terms are defined under the CCPA/CPRA, and we have not done so in the preceding 12 months. You may designate an authorised agent to make a request on your behalf.

EEA/UK residents: you may lodge a complaint with your local supervisory authority. We would prefer you raise it with us first so we can try to put it right.

11. Children

Our services are for businesses and are not directed at anyone under 18. We do not knowingly collect personal information from children. If you believe a child has provided us information, contact us and we will delete it.

12. International transfers

We are based in the United States and process data there. If you are outside the US, your information will be transferred to and processed in the US, where data protection law may differ from your own. Where required, we rely on appropriate safeguards such as Standard Contractual Clauses.

13. Changes to this policy

We may update this policy from time to time. The effective date at the top reflects the latest version. If we make material changes to how we use your information, we will notify you by email or a prominent notice on this site before they take effect.

14. Contact us

Questions, requests or complaints about privacy:

BEDROCK AI LLC
4972 State Hwy 30
Huntsville, TX 77340
United States
Email: gage@getbedrockai.com
Phone: (936) 355-8233

BEDROCK AI LLC, 4972 State Hwy 30, Huntsville, TX 77340, United States. Telephone (936) 355-8233.