Privacy Policy
Last updated: 15 July 2026
Monshi is an AI receptionist service for UK small businesses, built by Archii Ltd. This policy explains what personal data we collect, why, and what rights you have — whether you're a business using Monshi, or someone who's called a business that uses Monshi.
We've tried to write this in plain English. Where we use a defined legal term, we explain it the first time it comes up.
1. Who we are
Monshi is a product of Archii Ltd, a company registered in England and Wales under company number 17285683 (incorporated 19 June 2026).
Registered office: 82A James Carter Road, Bury St Edmunds, IP28 7DE
Operating address: 104 Woodland Drive, Hove, BN3 6DE
Website: monshi.co.uk
For UK GDPR purposes, Archii Ltd is the data controller for the personal data described in this policy — meaning we decide how and why that data is processed — except where we're acting as a data processor on behalf of our business customers, which we explain in Section 4.
Monshi is a small company. We don't have a statutory requirement to appoint a formal Data Protection Officer at our current size, but we still want you to know exactly who's accountable. Our founder, Armin Sheibani, is personally responsible for data protection at Monshi and is the point of contact for any privacy question or concern.
Contact us about privacy:
Email: me@archii.co.uk (primary — goes straight to Armin)
General enquiries: hello@monshi.co.uk
Post: 104 Woodland Drive, Hove, BN3 6DE
2. What data we collect
We collect data from two different groups of people, in quite different ways. It's worth reading both parts even if you're only one of the two.
From business owners (our tenants)
If you sign up for Monshi to answer calls for your business, we collect:
Account and business information: your name, email address, business name, business category, opening hours, and the FAQs/answers you give us so Monshi can answer calls on your behalf.
Payment information: we don't currently take payments directly — this will apply once we add paid plans via Stripe. When that happens, Stripe handles your card details directly; we don't store full card numbers ourselves.
Usage data: how you use the Monshi portal — pages visited, settings changed, login times — so we can run and improve the service, and so we can help you if something goes wrong.
From callers to Monshi tenants
If you call a business that uses Monshi, our system (on behalf of that business) collects:
Your phone number (the one you're calling from).
A recording of the call.
A transcript of the call, generated automatically from the recording.
Anything you tell us during the call — for example, your name, what you're calling about, or any other details you choose to share with the AI receptionist.
We only collect what's needed to answer the call and pass on an accurate message to the business you're calling.
3. How we use your data
To provide the service. Answering calls, generating transcripts, storing your settings, and giving you (the tenant) access to your calls and account through the Monshi portal.
To improve the product. We look at aggregated, anonymised usage statistics — call volumes, response times, common question types — to make Monshi better. We do not use individual callers' recordings or transcripts to train AI models, and we don't hand caller-identifiable data to third parties for their own model training.
To communicate with tenants. Welcome emails, service updates, and important account or billing notices.
Marketing, only where you've opted in (see Section 4).
We do not sell personal data to third parties. Ever. That's not our business model and it never will be.
4. Our legal bases for processing (UK GDPR)
UK GDPR requires us to have a valid "legal basis" for every way we use personal data. Here's ours:
Contract — most of what we do for tenants (running the receptionist service, storing your settings, giving you access to calls) is necessary to perform the contract you entered into when you signed up.
Legitimate interests — we rely on this for things like fraud prevention, keeping the service secure, and general product improvement using aggregated data. Where we rely on this basis, we've thought about whether our interest is outweighed by your rights — for example, we don't use it to justify anything intrusive, and callers' individual call content is never used this way without the tenant's instruction.
Consent — for optional marketing communications only. We only send marketing emails to tenants who've actively opted in, and you can withdraw that consent at any time.
A note on callers' data specifically: when someone calls a Monshi tenant, the legal basis for handling that call belongs to the tenant business, not to Monshi. In data protection terms, the tenant is the data controller for their callers' data (they decide to use an AI receptionist and what it's for), and Monshi is the data processor (we process that data on their instructions, under contract, to deliver the service). If you're a caller with a question about how your data was used on a specific call, the tenant business is usually the right first point of contact — though we're always happy to help too (see Section 8).
5. Who we share data with
We use a small number of trusted service providers ("sub-processors") to run Monshi. We don't share data with anyone beyond what's needed to deliver the service.
Retell AI — powers the AI voice conversation (speech-to-text, response generation, text-to-speech). Based in the US. GDPR-compliant processing, Data Processing Agreement in place.
OpenAI (via Retell) — underlying language model that generates the AI's responses. Based in the US. Covered by Retell's DPA and OpenAI's own data protection commitments.
Telnyx — provides the phone numbers and routes calls. US company, with EU points-of-presence used where possible. Standard Contractual Clauses / vendor DPA.
Supabase — database hosting for tenant account data. US company, but our data is hosted in the EU-West-2 (London) region. Vendor DPA in place.
Vercel — hosts the Monshi website and portal. US company. Standard Contractual Clauses / vendor DPA.
Resend — sends transactional emails (welcome emails, notifications). US company, EU region used for Monshi's sending domain. Standard Contractual Clauses / vendor DPA.
GoDaddy — domain registration for monshi.co.uk. US company. Limited to domain registration data only.
If we add analytics tools such as Google Analytics in future, we'll name them here and update our cookie banner accordingly (see Section 9) — we haven't added any at the time of writing.
International transfers. Several of our providers are US companies. Where personal data leaves the UK, we rely on Standard Contractual Clauses (SCCs) — a standard set of data protection terms approved by regulators — and, where applicable, the UK–US Data Bridge, which has been in effect since October 2023 and allows personal data to be transferred to US organisations that have self-certified under the US Data Privacy Framework. We check that our providers have appropriate safeguards in place before we use them.
6. How long we keep data
We don't keep data longer than we need to:
Call recordings: 30 days by default. We plan to let tenants adjust this in their settings (coming soon) — right now, 30 days is the fixed retention period.
Call transcripts: 12 months.
Tenant account data: kept while your account is active, plus 90 days after cancellation (in case you want to come back or need a final export), then deleted — except where we're legally required to keep records longer, such as financial/tax records, which UK law requires us to retain for 7 years.
Marketing preferences: kept until you opt out, so we can honour your choice.
7. Your rights
Under UK GDPR, you have the right to:
Access the personal data we hold about you.
Rectification — ask us to correct inaccurate or incomplete data.
Erasure — ask us to delete your data ("right to be forgotten"), subject to legal exceptions (e.g. we can't delete financial records we're required to keep).
Restriction — ask us to limit how we use your data in certain circumstances.
Portability — get a copy of your data in a portable format, where technically feasible.
Object — object to processing based on legitimate interests or direct marketing.
Not be subject to solely automated decision-making that has legal or similarly significant effects on you, without human involvement. (Monshi's AI answers calls and takes messages — it doesn't make automated decisions about you that carry legal or similarly significant effects.)
How to exercise these rights: email me@archii.co.uk. We're building self-service tools into the tenant portal to handle these requests directly (coming soon) — until then, email is the fastest route and we'll respond within the timeframes UK GDPR requires.
Right to complain. If you're unhappy with how we've handled your data, we'd like the chance to sort it out directly first — but you also have the right to complain to the UK's data protection regulator, the Information Commissioner's Office (ICO), at ico.org.uk.
8. If you've called a business that uses Monshi
This section is specifically for callers — people who ring a business that uses Monshi, rather than the businesses themselves. Your situation is different from a tenant's: you didn't sign up for anything, so we want to be extra clear about what happens to your data.
What we collect during your call: your phone number, a recording of the call, an automatically generated transcript, and anything you choose to tell the AI receptionist (your name, reason for calling, or any other details).
How long we keep it: call recordings for 30 days, transcripts for 12 months (see Section 6 for the full picture).
Who's responsible: the business you called is the data controller for your call data — they decide to use Monshi and what happens with the message afterwards. Monshi (Archii Ltd) is the data processor — we handle the call on their behalf, following their instructions and our contract with them.
If you don't want your call handled by AI, or have any concern about how your call was recorded or handled, you can contact either:
The business you called directly — they can tell you how to reach a human, and can ask us to delete or restrict your call data.
Monshi directly at me@archii.co.uk — tell us the business you called and roughly when, and we'll help.
Recording notice. We take a belt-and-braces approach to making sure you know what's happening on the call:
Monshi's AI announces it at the start of the call. You'll hear something like: "This call may be handled by an AI assistant and may be recorded for quality and training purposes."
The business itself also discloses it — every Monshi tenant is contractually required to tell their customers (through signage, their website, or other channels) that calls may be answered by an AI receptionist and recorded.
We think both of these matter: the announcement gives you notice in the moment, and the business's own disclosure means you're not caught by surprise even before you dial. If you ever feel that wasn't clear on a specific call, we want to hear about it.
9. Cookies and tracking
Our website uses minimal cookies:
Session cookies for logging into the tenant portal — these are strictly necessary for the portal to work and don't track you across other sites.
No third-party trackers or advertising cookies on our marketing site today.
No cross-site tracking.
If we add analytics (such as Google Analytics) in future, we'll update this section and add a proper cookie consent banner before we do. As of the date at the top of this page, we haven't.
10. Security
We take reasonable technical and organisational steps to protect your data:
Encryption: data is encrypted in transit (TLS 1.2+) and at rest.
Access controls: at our current size, only Armin (founder) has administrative access to production data. As the team grows, access will be extended only on a need-to-know basis with proper access controls.
Ongoing review: we'll formalise and expand our security practices as the company scales — this is an area we expect to invest in as we grow.
Breach notification: if a personal data breach occurs that affects UK data subjects, we'll notify the ICO within 72 hours where required, and tell affected individuals without undue delay where the breach is likely to result in a risk to their rights and freedoms.
No system is 100% secure, but we design Monshi to minimise risk and to respond quickly if something goes wrong.
11. Children
Monshi is a business tool, built for business owners and the people who call them. It isn't directed at, or intended for use by, anyone under 18. We don't knowingly collect data from children as part of our core service.
12. Changes to this policy
We may update this policy as Monshi grows and changes. If we make a material change — something that meaningfully affects how we use your data — we'll email active tenants directly. For minor or non-material updates, we'll simply update this page.
Last updated: 15 July 2026
13. Contact us
Privacy questions (primary): me@archii.co.uk
General enquiries: hello@monshi.co.uk
Post: 104 Woodland Drive, Hove, BN3 6DE
Complaints to the regulator: ico.org.uk
archii Ltd is registered with the UK Information Commissioner's Office (ICO), registration number ZC198766.
