checkmAIt
Home How It Works Privacy Terms GDPR
Privacy Policy

What we hold, why we hold it, and how to get it back

This policy explains what personal information checkmAIt collects, what we do with it, who we share it with, and the choices you have. It covers this website, our own business communications, and the AI systems we build and operate for our clients, including the phone calls and text messages those systems handle.

Last updated: 7 September 2026 Version 1.0 Applies to thecheckmait.com
Contents
  1. 01Who we are
  2. 02Our two roles
  3. 03What we collect
  4. 04SMS and text messaging
  5. 05Phone calls and AI voice agents
  6. 06Why we use it
  7. 07Who we share it with
  8. 08International transfers
  9. 09How long we keep it
  10. 10How we protect it
  11. 11Your rights
  12. 12Cookies
  13. 13Children
  14. 14Changes to this policy
  15. 15How to contact us
Section 01

Who we are

checkmAIt builds and operates bespoke AI systems for businesses: voice agents that answer the phone, messaging and follow-up systems, dashboards, and internal tools. Most of our clients are estate agencies and property businesses.

checkmAIt is a brand owned and operated by JMT Media Limited, a company registered in England and Wales with company number 16015121. Our registered office is 38 Pinfold Close, Repton, Derby, DE65 6FR, United Kingdom. In this policy, "we", "us" and "our" mean JMT Media Limited trading as checkmAIt.

You may see the name JMT Media Limited on contracts, invoices, card statements and telecoms records even though you deal with us as checkmAIt. They are the same business. JMT Media Limited is the legal entity accountable for everything described in this policy.

Trading namecheckmAIt
Owned and operated byJMT Media Limited
Privacy contactprivacy@thecheckmait.com
Section 02

Our two roles

Data protection law distinguishes between the party that decides why personal information is used and the party that handles it on someone else's instructions. checkmAIt is sometimes one and sometimes the other, and it matters because it changes who you should contact.

Role one · Controller

Our own website and clients

When you visit this website, book a call with us, email us, or become a checkmAIt client, we decide what we collect and why. This policy governs that information in full, and we answer requests about it directly.

Role two · Processor

Systems we run for clients

When our AI systems answer a call, send a message or update a record for a client, we act on that client's instructions. The client is the controller and their own privacy policy governs that information. We handle it only to deliver the service they have asked for.

If you spoke to an AI assistant, received a message, or made an enquiry with a business that uses checkmAIt, that business holds your information and decides how it is used. Contact them first. If you cannot reach them, or you are not sure who they are, email us at privacy@thecheckmait.com and we will identify the business and pass your request on.

Section 03

What we collect

Information you give us

  • Your name, business name, email address and phone number when you book a call, complete a form, or contact us.
  • What you tell us about your business during an enquiry, a discovery call, or the course of a project.
  • Billing details when you become a client. Card numbers are entered directly with our payment provider and never reach our systems.
  • Anything you choose to include in an email, message or call with us.

Information we collect automatically

  • Standard web log data when you visit this site: IP address, browser and device type, pages viewed, and the site or advert you arrived from.
  • Aggregate analytics about how the site is used, so we can see which pages work and which do not.

Information our systems handle for clients

  • Contact details of the people who call, message or enquire with our clients: name, phone number, email address, and the property or enquiry the contact relates to.
  • Call recordings, call transcripts and message history, where the client has enabled them and where the law and this policy allow.
  • Records of what happened: when a call came in, whether it was answered, what was booked, what follow-up was sent.

We do not seek out special category information such as health, ethnicity, religion, political opinions or biometric data, and our systems are not designed to collect it. We ask clients not to route it through the systems we build.

Section 04

SMS and text messaging

This section covers text messages sent by checkmAIt and by the systems we operate for our clients.

No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Information sharing with subcontractors who provide support services, such as the messaging platforms and customer service tools that make the service work, is permitted solely for that purpose. All other use case categories exclude text messaging originator opt-in data and consent, and that information is never shared with any third party.

How consent is obtained

We and our clients only send text messages to people who have opted in to receive them. Consent is collected at the point of contact: on a web form or landing page that states clearly that you will receive text messages, by you sending an enquiry or a message to the number first, by you providing your number during a phone call and agreeing to be contacted by text, or through an existing customer relationship where you gave your number for that purpose. Consent is recorded with a timestamp and the source, and it is never bought, rented, or shared from another business.

What the messages are about

Messages relate to the enquiry or the service you have asked about: replying to your enquiry, confirming or rescheduling an appointment, sending property or service information you requested, following up on a conversation, and account or service notifications. We do not send unrelated marketing on behalf of anyone else.

How to stop them

  • Reply STOP to any message to opt out. You will receive one confirmation message and then no further messages from that number.
  • Reply HELP for assistance, or contact us at privacy@thecheckmait.com.
  • Opting out is honoured automatically and immediately. You can opt back in at any time by messaging the number again or asking the business to re-enable messages.

Frequency and cost

  • Message frequency varies and depends on your conversation. Most people receive a small number of messages tied to a specific enquiry rather than an ongoing campaign.
  • Message and data rates may apply. Your mobile carrier's standard charges apply to messages you send and receive.
  • Carriers are not liable for delayed or undelivered messages.

Automation

Messages may be drafted or sent automatically by an AI system rather than typed by a person. A person can and does take over the conversation where it needs one. If you would rather speak to a human at any point, say so in your reply and we will pass the conversation to one.

Section 05

Phone calls and AI voice agents

Some of the systems we build answer or place phone calls using an AI voice agent. Where that happens:

  • The agent identifies the business it is calling on behalf of at the start of the call.
  • Where a call is recorded, you are told at the start of the call, and you can ask for the call not to be recorded or ask to speak to a person instead.
  • Recordings and transcripts are held only for as long as the client needs them, and are configured to delete automatically on a schedule rather than being kept indefinitely.
  • Where the platform supports it, we switch on redaction so that names, numbers and addresses are stripped out of stored transcripts.
  • We do not use call recordings or transcripts to train AI models, and our AI providers are contractually barred from training their models on data sent through their business interfaces.

Call recording law varies by country and by state. Our clients are responsible for the notice and consent requirements that apply where they operate, and we configure the announcement and recording settings to match.

Section 06

Why we use it

We use personal information for these purposes, and no others:

  • To answer you. Responding to enquiries, booking and running calls, and sending you what you asked for. Our basis is your consent, or the steps needed to enter a contract with you.
  • To deliver the service. Building, running, monitoring and supporting the systems our clients pay for. Our basis is the contract with the client, and we act on their instructions.
  • To run the business. Invoicing, accounting, record keeping and legal obligations. Our basis is legal obligation and our legitimate interest in running a business properly.
  • To improve what we build. Understanding how systems perform in aggregate so we can make them work better. Our basis is legitimate interest, and we use aggregated or de-identified data wherever it will do the job.
  • To keep things secure. Detecting and preventing fraud, abuse and misuse. Our basis is legitimate interest.

Where we rely on consent, you can withdraw it at any time and we will stop. Withdrawing consent does not affect anything we did before you withdrew it.

We do not sell personal information, and we never have. We do not share it with data brokers, and we do not use it for advertising unrelated to the enquiry it came from.

Section 07

Who we share it with

We share personal information in four situations only.

  • With the client the enquiry belongs to. If you contacted a business that uses our systems, your information goes to that business. That is the point of the service.
  • With the platforms that run the service. Hosting, telephony and messaging, AI models, databases, CRM, calendars, payments and support tools. They act on our instructions under contract and cannot use the data for their own purposes. How we choose them is set out below and in our GDPR statement.
  • With professional advisers, such as accountants and lawyers, where they need it and are bound by confidentiality.
  • Where the law requires it, or to establish, exercise or defend legal claims, or to protect someone's safety.

If checkmAIt is ever sold or merged, personal information may transfer as part of that business. Anyone receiving it would be bound by this policy or one at least as protective, and we would tell you before anything changed.

How we choose our providers

We do not hand personal data to a platform because it is convenient. Before a provider joins our stack we check that it offers a written data processing agreement, that it holds recognised independent security certification, that it has a lawful basis for any transfer of data out of the UK and EEA, and that it publishes its own list of sub-processors so the chain does not go dark one layer down. We review that list, we re-check it periodically, and we drop providers that fall short. The GDPR statement explains this in more detail, and clients can request the full register of platforms we use with links to each provider's own documents.

Section 08

International transfers

JMT Media Limited is established in the United Kingdom and is subject to the UK GDPR. Where we handle the personal data of people in the EEA, the EU GDPR applies to that processing and we comply with it.

We work with clients in the UK, Europe, the United States and Asia, and some of the platforms we use are based outside the country you live in. Where personal information moves across borders, we make sure it is covered by an approved safeguard before it goes: Standard Contractual Clauses with the UK Addendum or International Data Transfer Agreement, the EU-US Data Privacy Framework where the provider is certified, or an adequacy decision covering the destination country.

Where a client needs their data to stay physically within a particular region, we can usually configure the stack to do that, including running the same AI models through EU-hosted infrastructure. Ask us and we will tell you exactly what is possible for your setup.

Section 09

How long we keep it

  • Enquiries that do not become clients: up to 24 months, then deleted.
  • Client records and project files: for the life of the relationship and 6 years afterwards, which is the period we may need them for tax, accounting and legal purposes.
  • Call recordings and transcripts: for the window the client sets, configured to delete automatically. Where no window is set, we default to a short one rather than keeping them.
  • Message history: for as long as the client needs it to service the conversation, then deleted on their schedule.
  • Opt-out records: kept indefinitely, because we need them to make sure we never message you again.
  • Website logs and analytics: up to 26 months in aggregate form.

Where we act as processor, the client's retention schedule takes precedence and we delete or return their data when the contract ends.

Section 10

How we protect it

  • Data is encrypted in transit, and at rest on the platforms we use.
  • Credentials live in a password manager with per-person access. They are not shared, emailed or kept in files.
  • Access is limited to the people working on a given build, and it is removed when someone leaves the project.
  • We collect the minimum the system needs to work, and we switch on redaction and automatic deletion wherever a platform offers them.
  • Every platform in our stack is chosen partly on its security posture, and we re-check that posture rather than assuming it holds.

No system is perfectly secure, and we will not pretend otherwise. If a breach occurs that is likely to put anyone at risk, we will notify the relevant regulator within 72 hours of becoming aware of it, notify affected clients without undue delay, and tell you what happened and what to do about it.

Section 11

Your rights

Depending on where you live, you have some or all of the following rights over your personal information:

  • Access. Get a copy of what we hold about you.
  • Correction. Have anything inaccurate or incomplete put right.
  • Deletion. Ask us to erase it, where there is no overriding reason to keep it.
  • Restriction. Ask us to pause using it while a dispute is sorted out.
  • Objection. Object to us using it on the basis of legitimate interest, and object to direct marketing at any time with no reason needed.
  • Portability. Receive it in a machine-readable format, or have it sent to someone else.
  • Withdraw consent. At any time, for anything we do on the basis of consent.
  • Human review. Ask for a person to review a decision made about you by an automated system.

To exercise any of these, email privacy@thecheckmait.com. We will respond within 30 days. There is no charge. We may ask you to confirm your identity first, so that we do not hand your information to somebody else.

If the information sits in a system we run for a client, we will pass your request to that client and support them in answering it, because the decision is legally theirs to make.

Section 12

Cookies

This site uses a small number of cookies and similar technologies: those strictly necessary for the site to function, basic analytics so we can see which pages are read, and the booking widget we use to schedule calls, which sets its own cookies when you open it.

You can block or delete cookies in your browser settings. Blocking the necessary ones may stop parts of the site working. We do not use advertising cookies to build profiles of you across other websites.

Section 13

Children

Our services are for businesses. They are not directed at children, and we do not knowingly collect information about anyone under 16. If you believe a child's information has reached us, tell us and we will delete it.

Section 14

Changes to this policy

We update this policy when what we do changes, or when the law does. The date at the top of the page always shows the current version. If a change materially affects your rights, we will tell affected clients directly rather than relying on you to notice.

Section 15

How to contact us

For anything in this policy, including access, deletion and opt-out requests, email us. A person reads that inbox.

Emailprivacy@thecheckmait.com
Postal address38 Pinfold Close, Repton,
Derby, DE65 6FR, United Kingdom
Response timeWithin 30 days

If you are in the UK and you are not satisfied with how we have handled your information, you can complain to the Information Commissioner's Office at ico.org.uk or on 0303 123 1113. If you are in the EEA, you can complain to your national data protection authority. We would rather you came to us first so we can put it right.

Related

Our GDPR position, in one page

The GDPR statement sets out how responsibility is split between you, us and the platforms underneath, how we vet every processor and sub-processor before it touches client data, and what we commit to as a processor.

Clients can request the full platform data register, which lists every platform in the stack with links to each provider's own data processing agreement, transfer basis and security audits. Email privacy@thecheckmait.com and we will send it.

checkmAIt
Home How It Works Privacy Policy Terms GDPR Contact

© 2026 checkmAIt. All rights reserved.