Guide · Dan Latham · Updated 16 September 2026

UK GDPR for client-facing AI

Kuga provides platform terms, a privacy notice, and a DPA. The agency and the client still have to decide who is controller for the conversations on the client site, what the visitor is told, and what the agent is allowed to collect.

UK GDPR for client-facing AI

Roles, in plain terms

KUGA AI LTD is typically the processor for customer content processed to provide the service, and a controller for its own account, billing, and website data. The agency or the agency’s client is usually the controller for end-user conversations on a live deployment.

Do not copy this paragraph into a client contract without reading the current Privacy Policy and DPA. Those documents win.

What the visitor needs to see

The client site needs an honest notice that a conversation may be processed, stored, and reviewed. Do not hide a chat widget behind a privacy policy nobody can find from the widget itself.

Instructions and minimisation

Collect the fields the follow-up actually needs. Do not ask for special-category data unless the client has a lawful basis and a written instruction. Use Human Handover when the conversation leaves the approved script.

Read the DPA

Processor terms for the platform.

Privacy PolicyDPA

Security checklist for agency AIWhite-label AI, under your brandHow agencies should price client AIClient deployment checklist

Sell the service.

Keep the infrastructure.

Create an agency workspace