Privacy and Cookie Notice
This notice explains how personal information is handled when you use the TillTech website and its interactive features.
Last reviewed: 26 August 2026
1. Who we are
The controller for the processing described in this notice is TILLTECH SYSTEMS LTD, registered in England and Wales under company number 10026658. Our registered office is 22 St. John Street, Newport Pagnell, Buckinghamshire, England, MK16 8HJ.
For privacy enquiries or to exercise a data protection right, email customerrelations@till.tech or write to us at the registered address above.
2. Information we handle
Depending on how you use the website, we handle the following categories of information:
- Enquiries, demonstrations, support, and newsletters: information you enter into our forms, such as your name, business, contact details, postcode, requirements, preferred appointment times, support category and priority, and the content of your message. These forms are submitted to HubSpot. The submission also includes the page title and page address without its query string or fragment. If you have allowed analytics and a HubSpot tracking token is already present, that token may also accompany the submission.
- AI-assisted tools: messages, prompts, business names, website addresses, the page path, generated responses, and a server-issued session identifier when you use chat or report-generation features.
- Speech and language features: audio you choose to record, speech transcripts, text selected for text-to-speech, visible interface text sent for translation after you explicitly select Greek, and your saved language choice. Chat, form-entry, and generated-report regions are excluded from automatic page translation.
- Usage and device information: consent choices, browser preferences, pages and interactions where optional analytics is enabled, and ordinary request information such as IP address, browser or user-agent information, timestamps, and security or diagnostic events.
- Regional access checks: the server uses an incoming network address transiently to infer an approximate ISO country code and decide whether the requested part of the site is available from that region. For a blocked request, the application logs the country code and requested path, not the raw address. Privacy, Terms, and Contact remain available so the decision can be reviewed.
Please avoid entering payment-card details, passwords, special-category information, or other confidential material into website forms or AI chat unless TillTech specifically asks you to use an approved channel for it.
3. AI chat, speech, and translation
Tilly is an automated AI assistant, not a human. Chat messages and limited context are sent through the TillTech website to a separately configured AI service so it can generate a response. Server-side conversation records may be retained in Google Cloud Storage and imported into TillTech's restricted content-management system; newly written transcript fields in that system are encrypted at rest. Authorised administrators may access transcripts for support, service quality, and security purposes.
A signed, HttpOnly chat-session cookie links requests to a session and expires after seven days unless it is cleared sooner. A copy of chat messages may also be held in your browser's local storage so a conversation can be restored. When the current widget next loads, it restores only messages from your current local calendar day and discards older browser-stored messages. Clearing the chat or your browser data removes that browser copy, but does not itself delete a server-side record.
If you use microphone transcription, the uploaded audio is sent through the website server to Google Cloud Speech-to-Text. Temporary server upload files are deleted after the request finishes; the resulting text may become part of your chat. Text-to-speech sends response text to Google Cloud Text-to-Speech. When you explicitly select Greek, visible page-interface text is sent through the TillTech server to Google Cloud Translation; chat, form-entry, and generated-report regions are excluded. A saved Greek preference may reapply that choice on a later visit. Do not activate these features if you do not want that content processed by those services.
4. Why we use information and our legal bases
| Purpose | Legal basis, depending on context |
|---|---|
| Replying to enquiries, arranging demonstrations, and providing requested support | Taking steps at your request before a contract, performing a contract, and our legitimate interests in customer service and operating our business |
| Providing chat, reports, speech, translation, video, and preference features | Performing a requested service and our legitimate interests in making the website useful; consent where required for an optional third-party feature |
| Sending newsletters and measuring optional website analytics | Consent, which you may withdraw; other direct-marketing rules may also apply to existing customer relationships |
| Protecting the website, preventing abuse, diagnosing faults, and meeting legal requirements | Our legitimate interests in security and service reliability, and compliance with legal obligations |
| Applying and reviewing regional access controls based on an approximate country inferred from network information | Our legitimate interests in protecting the service and managing where it is offered, balanced against the availability of this notice and a human review route |
Where we rely on legitimate interests, we consider the need for the processing, its impact on individuals, and available safeguards. You are not required to provide information through the website, but we may be unable to respond or provide a requested feature without the information it needs.
6. Retention and security
Except for the browser and session periods described above, retention depends on why the record is needed. TillTech keeps personal information only for as long as necessary to respond to or document an enquiry, provide support, administer a customer or supplier relationship, maintain service security, resolve disputes, or meet accounting and other legal obligations. We consider the sensitivity, volume, risk, and whether information can be deleted or anonymised when setting each period.
The implementation includes access controls for administrative conversation records, encryption of newly written CMS transcript fields, signed chat sessions, request limits, and restricted production transport and browser-security settings. No system can be guaranteed completely secure. Please contact us promptly if you believe information sent through this website has been compromised.
8. Your data protection rights
Depending on the circumstances, UK data-protection law may give you rights to access, correct, erase, or restrict personal information; object to processing; receive certain information in a portable format; and withdraw consent without affecting earlier lawful processing. Some rights have conditions and exemptions.
Contact us using the details in section 1. We may need enough information to verify your identity and locate the relevant records. You can also complain to the UK Information Commissioner's Office through the ICO complaints service. We would appreciate the opportunity to address your concern first.
You can object to processing based on legitimate interests, including a regional access decision, by contacting us. You can withdraw analytics consent through Privacy settings on this page and unsubscribe from marketing using the link in a message or by contacting us; withdrawal does not affect earlier lawful processing.
9. Changes to this notice
We may update this notice when website functionality, suppliers, or legal requirements change. The review date at the top identifies the version displayed. Material changes should be communicated through an appropriate website or direct notice where required.
This website notice should be read alongside our Terms of Service where they apply.