Legal
Privacy
How New Era AI Ltd handles personal data across this website and our platforms: what we collect, why, who we share it with, and your rights under UK GDPR.
Last updated 28 September 2026
New Era AI Ltd (company number 13167322), based in Llanelli, Carmarthenshire, Wales, is the data controller for personal data collected through this website, through the platforms we operate, and through our commercial relationships. This page explains what that means in practice.
Our platforms
The same controller and the same rules apply to each of these. A product login does not create a separate privacy notice.
- This website (neweraai.ai): enquiries, booking, chat, assessments, and cookies.
- Rank One (rankone.neweraai.ai): account login and the ranking / AI-search visibility work you run there.
- Echo One (echoone.neweraai.ai): voice accounts, call audio, transcripts, and write-back into your CRM.
- Appointment Engine (appointment-engine.ai): booking accounts, diary slots, reminders, and attendee details.
- Nexus One: the AI CRM and sales engine, built on HighLevel. Pipeline, contacts, nurture sequences, and reporting.
- Consultancy client portal: where clients sign in to follow an engagement: project files, tasks, messages, and deliverables.
- Admin console on this site: staff access to our own ops tools. It is not a public product.
What we collect
- Contact details you give us. Name, email address, phone number and whatever you choose to tell us about your business when you get in touch, book, chat, or complete an assessment.
- Account data. If you sign in to Rank One, Echo One, Appointment Engine, the consultancy client portal, or the admin console, we hold the identity used to create that account. When you choose Sign in with Google, that includes the Google fields listed under Google user data.
- Correspondence. Emails, call notes, chat transcripts and messages exchanged during an enquiry or an engagement, including follow-up we send from HighLevel when contacting you.
- Call recordings and transcripts on Echo One, including the public voice demo. Detail is under voice demo calls below. Production Echo One calls follow the engagement, not the demo retention period.
- Booking and diary data on Appointment Engine: names, contact details, requested slots, reminders, and outcomes.
- CRM and pipeline data on Nexus One (HighLevel): contacts, stages, notes, sequences, and reporting fields written from the channels you connected, including Echo One write-back.
- Rank One workspace data. The sites, queries, and visibility work you run in that product, plus the account used to open it. If you connect your own Google Search Console or Google Analytics property, that includes the read-only performance data described under Google user data.
- Client portal files and messages. Documents, tasks, and conversation you or we put in the consultancy portal during an engagement.
- Basic technical data. Standard server logs, which include IP address and user agent, retained for security and diagnostics.
We do not run advertising trackers on this site and we do not build behavioural profiles of visitors.
Why we process it
- To respond to you. Lawful basis: legitimate interests, or steps taken at your request prior to entering a contract.
- To run the product you signed into. Lawful basis: performance of a contract, or steps taken at your request prior to entering one.
- To deliver an engagement. Lawful basis: performance of a contract.
- To keep records we are required to keep. Lawful basis: legal obligation.
- To keep the site and platforms secure. Lawful basis: legitimate interests.
Voice demo calls: recording and transcription
If you use the Echo One voice demo, the call is recorded and transcribed. This is worth stating plainly rather than burying, because it is the one place on this site where we capture your voice.
- What is captured. The audio of the call and a text transcript of it, plus the time, duration and the browser origin the call came from. If you tell the agent your name, company or phone number during the call, that ends up in the transcript because you said it.
- Why. To review how the agent handled the conversation and improve it, and to answer you properly if you book a consultation and want to go through the call. That is the only use. Demo recordings are not used for marketing, are not sold, and are not used to train a public model.
- Lawful basis. Consent. The demo page tells you the call is recorded before you press start, and pressing start is the consent. Not pressing it means no recording exists.
- Who processes it. Vapi, our voice infrastructure provider, which carries the call and produces the transcript, and the speech and language model providers behind it. They act on our instructions.
- How long. 90 days, then deleted. If a call led to a consultation, the notes we make from it follow the enquiry retention period below rather than the recording one.
- Deleting one. Email us with roughly when you called and we will find and delete that call. You do not need an account and you do not need to explain why.
Calls to our published phone number are a separate matter: outside office hours the line is answered by our own AI receptionist, which captures a message and books a callback. If a call to that line is recorded you are told at the start of it.
Production Echo One accounts are not the public demo. Recordings and transcripts there are kept for the life of the engagement and then follow the paid-engagement retention period below, unless we have agreed a shorter period with you in writing.
Google user data: access, use, sharing, and protection
We receive Google user data in two separate ways, and they are worth keeping apart because different data is involved and it goes to different places. The first is signing in with Google. The second is connecting your own Google Search Console and Google Analytics properties to Rank One so it can report on them. This section states what we access, how we use it, who we share it with, how we protect it, and how long we keep it. Rank One (rankone.neweraai.ai) and this website are operated by New Era AI Ltd.
What we access, and the scopes we ask for
- Signing in with Google (
openid,email, and basic profile). Your name, email address, profile photo if the Google account has one, and the Google user id. If you connect Google inside Nexus One, Appointment Engine, or another HighLevel-backed product, we may also receive the calendar or contact fields you authorize on the consent screen, so we can offer real diary slots or keep a contact record in sync. - Connecting Search Console to Rank One (
.../auth/webmasters.readonly, “See and download your Google Search Console data”). The list of properties your Google account can access, so you can pick the one to connect, and the search performance rows for the property you chose: search queries, pages, clicks, impressions, click-through rate, and average position, plus URL inspection results for pages on that property. - Connecting Analytics to Rank One (
.../auth/analytics.readonly, “See and download your Google Analytics data”). Your GA4 property and data stream details, so Rank One can match the right property to the site you connected, and the traffic reports it runs against that property: sessions, users, landing pages, and referral sources, including which AI assistants and search engines sent those visits.
Both Rank One scopes are read-only. We deliberately do not request any scope that would let us write to, submit to, or change your Search Console or Analytics account, and Rank One is not capable of doing so. Where a client has not connected their own Google account, we access only the properties that client has explicitly granted our Google service account access to, and nothing else.
How we use it
Sign-in data is used to authenticate your account on Rank One, Echo One, Appointment Engine, the consultancy client portal, and the admin console. Search Console and Analytics data is used for one thing: producing the reporting you opened Rank One for, on the site you connected. That means keyword and page performance, quick wins, keyword cannibalisation, index coverage, and which AI assistants and search sources send you traffic. It is shown back only to the account that connected it. We do not use Google user data for advertising, for retargeting, for credit scoring, or to train AI models.
Who we share, transfer, or disclose Google user data to
We do not transfer or disclose Google user data to third parties for purposes other than the ones described in this policy. What follows is the complete list of parties that receive any Google user data from us, and each is bound by a written data processing agreement to act only on our instructions.
- Your Search Console and Analytics data is not shared with any third party at all. Rank One fetches it from Google’s APIs, stores it in our own database on infrastructure we control, and displays it back to you. It is not sent to Clerk, to HighLevel, or to any other company.
- In particular, it is never sent to an AI or large language model provider. Rank One does query AI assistants such as ChatGPT, Perplexity, Gemini, and Claude to check whether a brand is cited in their answers, but those queries contain only public search terms. Your Search Console and Analytics data is never included in them and is never used as training or prompt data.
- Clerk, Inc. (United States) receives sign-in data only: your Google name, email address, profile photo, and Google user id. Clerk operates the Sign in with Google flow on our behalf and holds the resulting account identity so you can sign in. It receives no Search Console or Analytics data.
- HighLevel Inc. (GoHighLevel / LeadConnector, United States) receives your Google name and email address, and, where you have connected a Google account inside Nexus One or Appointment Engine, the calendar or contact fields you authorized there. It holds the CRM, booking, and messaging spine behind those products and this website’s chat and contact forms. It receives no Search Console or Analytics data.
- Our hosting and email infrastructure providers, which store or transmit the systems and the mail that carry this data. They have no independent right to access or use it, and we will name the specific provider involved in your account or engagement if you ask.
Beyond those providers, we share, transfer, or disclose Google user data in only two circumstances: where the law or a valid legal process requires it, and in a merger, acquisition, or sale of the business, in which case affected users are notified before their data becomes subject to a different privacy policy.
We do not sell Google user data. We do not transfer or disclose it to advertisers, advertising networks, data brokers, information resellers, analytics providers, or any other third party for their own purposes. We do not transfer or disclose it for targeted, personalized, retargeted, or interest-based advertising. We do not use or transfer it to determine credit-worthiness or for lending purposes. We do not use Google user data from Sign in with Google, Google Search Console, or Google Analytics to develop, improve, or train non-personalized or generalized AI or machine-learning models. Google Workspace APIs are not used to develop, improve, or train non-personalized AI or machine-learning models. We do not pass that data to any third party for that purpose. No human reads Google user data except where you have explicitly asked us to, where it is necessary for security purposes or to comply with applicable law, or where the data has been aggregated and anonymized.
Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
How we protect Google user data
Security procedures are in place to protect the confidentiality of your Google user data, including sensitive data. Sensitive data here means the Google account identity used when you sign in (name, email address, profile photo, and Google user id) and the Search Console and Analytics data you connect to Rank One (search queries, pages, clicks, impressions, positions, URL inspection results, sessions, users, landing pages, and referral sources).
We use encryption to protect your information. Google user data is encrypted in transit with TLS whenever it moves between your browser, our servers, and Google’s APIs. The token that lets Rank One re-read your Search Console and Analytics data is encrypted at rest in our database. Sign-in tokens held for your account are encrypted at rest by our authentication provider, Clerk. We never see or store your Google password. Sign-in, and the Search Console or Analytics connection, both happen on Google’s own consent screen.
Access to stored Google user data is limited to the account that connected it, and to the staff and systems that need it to provide the feature you asked for or to keep that service secure. Search Console and Analytics access is read-only. Those results are not sent to advertising networks, data brokers, or AI providers.
Storing, keeping, and deleting Google user data
Google user data is kept only for as long as the account it belongs to stays open and the connection remains in place. The protections above, including encryption in transit and encryption of stored tokens, apply for that whole period.
You can revoke our access at any time, either by disconnecting the property inside Rank One or from your Google account permissions page. Either one stops all further access immediately. The Google user data we already hold, including the stored Search Console and Analytics results and the encrypted token, is deleted within 30 days of you disconnecting, closing your account, or asking us to erase it. To ask, email info@neweraai.ai. You do not need to give a reason.
How long we keep it
Enquiry correspondence is kept for up to 24 months from last contact unless you ask us to remove it sooner. Records relating to a paid engagement, including consultancy portal files and production Echo One recordings tied to that work, are kept for six years after the end of the relationship, in line with UK accounting and limitation requirements. Account records stay for as long as the account is open, then follow the same engagement or enquiry period. Server logs are kept for 90 days, as are voice demo recordings and their transcripts.
Who else touches it
We use named processors to run the platforms. Each is bound by a data processing agreement and acts on our instructions.
- Clerk, Inc. Authentication, including Sign in with Google, for Rank One, Echo One, Appointment Engine, the consultancy client portal, and the admin console.
- HighLevel Inc. (GoHighLevel / LeadConnector). CRM, chat, and booking spine. Nexus One is built on it. Contact details from this website, Appointment Engine bookings, Echo One write-back, and the messages we send when contacting you are processed there.
- Vapi. Voice infrastructure for Echo One calls and the public demo. It carries the audio and produces the transcript.
- Hosting and email providers. They store or carry the systems and the mail we send. We will name the specific provider for your engagement if you ask.
Client data is never used to train public models. Where an engagement involves AI tooling, we use business or enterprise tiers with contractual commitments to that effect, and we agree data-handling boundaries with you in writing before anything is built.
We do not sell personal data, and we do not share it with third parties for their own marketing.
International transfers
Clerk and HighLevel operate outside the UK, as do some hosting, email, and voice providers. Where that is the case, transfers are made under the UK International Data Transfer Agreement or an adequacy decision. We will tell you which providers are involved in your engagement if you ask.
Cookies
This website asks before it sets anything that is not strictly necessary. Analytics and the chat widget stay off until you allow them. The full list, durations, and how to change your choice are on the cookie policy. We do not use advertising or cross-site tracking cookies. Product logins (Rank One, Echo One, Appointment Engine, the consultancy client portal, and the admin console) set their own essential session cookies so you stay signed in.
Your rights
Under UK GDPR you have the right to:
- Ask what we hold about you, and receive a copy.
- Have inaccurate data corrected.
- Have data erased where we have no overriding reason to keep it.
- Restrict or object to processing based on legitimate interests.
- Receive your data in a portable format.
- Complain to the Information Commissioner’s Office.
To exercise any of these, email info@neweraai.ai. We will respond within one month. If you are not satisfied with our response you can complain to the ICO at ico.org.uk.
Changes
If this page changes materially, the “last updated” date at the top will change with it. This version was published on 28 September 2026.