← Back to site

Privacy Policy

Last updated: 26 June 2026

This Privacy Policy explains how OAW Solutions Limited (“Vallamo”, “we”, “us”) collects, uses and protects personal information when you visit our website, create an account, or use the Vallamo service (the “Service”). Depending on where you are, your data is protected by the UK GDPR and Data Protection Act 2018, the EU GDPR (for people in the EU and EEA), and the Swiss FADP (for people in Switzerland). If you are in the United States, see section 14.

1. Who we are

OAW Solutions Limited is registered in England and Wales (company number 17266481). For anything to do with your data, contact support@vallamo.com. Our representatives for the EU and elsewhere are listed in section 13.

2. Our two roles

It matters which of two situations applies to you:

This policy mainly covers the first situation. If you chatted with an assistant on another business’s channel, that business’s privacy policy governs your data and you should contact them; we will pass your request on to them where appropriate.

3. Information we collect

Health-related information. Because some businesses using Vallamo provide health or wellness services (such as clinics, medspas, dental or physiotherapy practices), a conversation may sometimes include information about a person’s health, treatments or appointments. This is “special category data” and is treated with extra care (see section 5).

4. How and why we use it, and our lawful bases

We use personal data to provide and operate the Service, set up and support your account, process bookings, deposits and hand-offs to your team, keep the Service secure, improve and troubleshoot it, communicate with you, and meet our legal obligations. Our lawful bases under UK and EU GDPR are typically performance of a contract, legitimate interests (running, securing and improving our business in ways you would reasonably expect), consent (for certain cookies and marketing), and legal obligation.

5. Special category (health) data

Where the assistant handles health-related information, we do so almost always as a processor on a business customer’s behalf. That business is responsible for having a valid Article 9 condition for this data, normally the individual’s explicit consent, and for telling its customers how their data is used. We process such data only on the customer’s documented instructions and apply additional safeguards: tighter access controls, encryption, and data isolation per business. Vallamo does not use health-related conversation content for its own purposes and does not use it to train third-party AI models.

6. AI processing and AI transparency

The assistant generates replies using a third-party large language model provider, currently Anthropic (Claude). Conversation content is sent to that provider to produce a response. We work only with providers offering appropriate security and data-protection terms, under contracts that prevent your data being used to train their models. A current list of our sub-processors is in section 7.

In line with the EU AI Act, the assistant tells people they are interacting with an AI at the start of a conversation, and a person can ask to be passed to your team at any time. The assistant answers only from the knowledge bank a business has approved, and says so when it is unsure rather than guessing.

7. Sharing your information and our sub-processors

We do not sell personal data. We share it only with service providers who help us run Vallamo, under written data-processing contracts; with booking and other systems you choose to connect; with professional advisers; and with authorities where the law requires. We may also share data in a business sale or reorganisation, subject to this policy. Our current sub-processors are:

We keep this list current and tell business customers before we add or change a sub-processor, as set out in our Data Processing Agreement.

8. International transfers

Several of the providers above are in the United States, so some personal data is transferred outside the UK and EEA. We protect those transfers with a lawful mechanism in every case: reliance on the provider’s certification under the EU-US Data Privacy Framework and its UK Extension where it holds one, and otherwise the Standard Contractual Clauses together with the UK International Data Transfer Addendum, supported by a transfer risk assessment. You can ask us for details of the safeguard used for a particular provider.

9. How long we keep it

We keep personal data only as long as needed for the purposes above, then delete or anonymise it. For conversation data handled on a customer’s behalf, the retention period is set by that customer. Account data is kept for the life of the account and a reasonable period afterwards to meet legal and accounting obligations.

10. Security

We use technical and organisational measures appropriate to the risk, including encryption in transit, isolation of each business’s data, access controls, and audit logging of changes. No system is perfectly secure, but we work to protect your information and to respond promptly to any incident.

11. Your rights and how to use them

Subject to UK, EU and Swiss data protection law, you have the right to access your data; to have it corrected or erased; to restrict or object to processing; to data portability; to withdraw consent where we rely on it; and not to be subject to a decision based solely on automated processing that has a legal or similarly significant effect (the assistant does not make such decisions, see section 15). To exercise any of these, email support@vallamo.com. We will verify your identity, respond within one month (extendable by two further months for complex requests, which we will tell you about), and we will not charge unless a request is manifestly unfounded or excessive.

If the request concerns a conversation on another business’s channel, we act as processor and will pass your request to that business and assist them in answering it. You can also complain to the ICO (ico.org.uk) in the UK, or to your local supervisory authority in the EEA or Switzerland, though we would welcome the chance to put things right first.

12. Cookies and similar technologies

Our website and dashboard use cookies and similar technologies. Some are strictly necessary (for example to keep you logged in or to run the chat); these do not require consent. Any analytics or marketing technologies are only set with your consent, which you give or refuse through our cookie banner and can change at any time. Our pages also load the Playfair Display typeface from Google Fonts, which shares your IP address with Google to deliver the font. Full details, including the specific cookies we use, are in our Cookie Policy.

13. EU, UK and Swiss users: our representatives

We are established in the United Kingdom, so for UK data protection law we act through our UK office above. Because we offer the Service to people in the EU and EEA without being established there, we have appointed an EU representative under Article 27 EU GDPR. The representative for the EU can be contacted at: eu.representative@vallamo.com and is located in The Hague, Netherlands. The representative for Switzerland can be contacted at: ch.representative@vallamo.com and is located in Lugano, Switzerland.

14. United States users

If you are in the US, additional rights may apply under laws such as the California Consumer Privacy Act (as amended by the CPRA) and similar state laws: to know, access, correct and delete your data, to opt out of “sale” or “sharing” (we do not sell personal data), and to non-discrimination for exercising these rights. Some states (including Washington and Nevada) also regulate consumer health data more broadly than federal law; where those apply, we and our business customers obtain the consents and provide the notices they require. To exercise US rights, contact support@vallamo.com.

15. Automated decision-making

The assistant holds conversations, answers questions and arranges bookings, but it does not make decisions that produce legal or similarly significant effects about a person without human involvement. Sensitive or significant matters are routed to your team.

16. Children

The Service is intended for businesses and is not directed at children. We do not knowingly collect children’s data through our own website.

17. Changes to this policy

We may update this policy from time to time. We will post the updated version here and change the “last updated” date; significant changes will be communicated where appropriate.

18. Contact

Questions about this policy or your personal data? Email support@vallamo.com.