Privacy Policy
Margot, by BrainLake · Effective date: 21 July 2026 · Last updated: 4 August 2026
This policy explains how Quartalyst Advisors Ltd, trading as Hi Margot ("we", "us", "our") collects, uses, shares and protects personal data when you visit hiMargot.ai, when you or your firm use Margot, our AI scheduling assistant, and when you correspond with Margot in the course of scheduling a meeting.
Quartalyst Advisors Ltd is a company registered in England and Wales (company number 16538182) with its registered office at 71–75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom. We process personal data in accordance with the UK General Data Protection Regulation and the Data Protection Act 2018 and, where it applies, the EU General Data Protection Regulation.
Contact for anything in this policy: privacy@hiMargot.ai.
1. Who this policy covers, and our role
This policy covers four groups of people. Our legal role differs between them.
| Who you are | What we process | Our role |
|---|---|---|
| A visitor to hiMargot.ai or a prospective client | Website usage data, enquiry and contact details | Controller |
| A user at a firm that has deployed Margot | Account details, preferences, email and calendar data connected to Margot | Processor, on behalf of your firm (the controller) |
| A firm administrator or billing contact | Account, contract and billing details | Controller |
| A meeting participant corresponding with Margot who has no Margot account | Your name, email address, availability and the content of scheduling emails | Processor, on behalf of the firm whose user added Margot to the thread |
Where Margot is deployed by a firm, that firm decides why and how its users' data is processed, and we process it under a data processing agreement with the firm. If you are a user at such a firm and want to exercise your data protection rights over service data, your firm is the primary point of contact; we will support any request you send to us directly and route it appropriately (see section 12).
For website visitors, enquiries, firm administrators and billing, we are the controller and this policy is the complete statement of how we handle your data.
2. What Margot is
Margot is a scheduling assistant. Each user at a client firm has an individual agent. The user copies the firm's Margot email address into an email thread, and Margot reads the thread, checks calendars, proposes times, coordinates with participants and books the meeting. Margot is scheduling only. Margot does not triage inboxes, draft non-scheduling correspondence, or manage tasks, and non-scheduling content in a thread is surfaced to the user rather than acted on.
3. Information we collect
Information you give us. Name, work email address, firm, and role when you create an account or your firm creates one for you; scheduling preferences you set on the web platform (working hours, preferred windows, meeting lengths, buffers, time zone, video provider, priority rules, event tags); instructions you send Margot by email; enquiries and correspondence with us; billing and contract details where you are the firm contact.
Information from your connected email and calendar. When you connect your Google or Microsoft account, Margot accesses, through our integration provider Nylas: email messages and threads in which Margot is a participant; your calendar events and free/busy information; and the events Margot creates, updates or cancels on your behalf. Section 4 sets out exactly what we access from Google and why.
Information about meeting participants. When a Margot user schedules a meeting with you, we process your name, email address, stated availability, and the content of the scheduling emails you exchange with Margot, whether or not you have a Margot account. Emails sent from a Margot address carry a footer identifying the assistant.
Information collected automatically. When you use the website or platform: IP address, device and browser information, and usage data collected via cookies and similar technologies (see section 14); service logs and diagnostic data generated when Margot operates.
We do not collect special category data and Margot has no need for it. If special category data appears incidentally in an email thread, it is handled under the same protections as all thread content and is not extracted, profiled or used.
4. Google user data
This section applies when you connect a Google account to Margot. It describes every Google OAuth scope Margot requests, and why. Each is the minimum necessary to operate the scheduling agent.
| Scope | What it allows | Why Margot needs it |
|---|---|---|
| gmail.readonly | Read email messages and threads where the scheduling agent is a participant | To understand scheduling requests, replies, confirmations and cancellations |
| gmail.send | Send emails on your behalf | To send meeting proposals, confirmations, nudges and reschedules |
| calendar.events | Read, create, update and delete calendar events | To create meeting holds, book confirmed meetings and cancel them |
| calendar.readonly | Read your calendar and free/busy information | To find times when you are available for proposed meetings |
We use Google user data solely to operate the scheduling agent for you: to read scheduling emails in order to classify intent, extract meeting requirements and identify participants; to query your calendar free/busy to find open time slots; to send proposal, confirmation, cancellation and nudge emails on your behalf; and to create, update and delete calendar events for the meetings you schedule. We do not use Google user data for any other purpose.
Limited Use Compliance Statement.The use of raw or derived user data received from Google Workspace APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is used only to provide and improve the scheduling service for the user who connected their account. Gmail data is never used to train a shared AI model — it may only be used to improve scheduling for that specific user's account. It is never transferred to third parties for the purpose of training AI models, never sold, and never used for advertising.
- We only use Google user data to provide and improve the user-facing scheduling features described in this policy.
- We do not transfer Google user data to third parties except as necessary to provide those features (to the sub-processors listed in section 8), for security purposes, to comply with applicable law, or as part of a merger, acquisition or sale of assets after obtaining explicit prior consent.
- We do not use Google user data for advertising, and we never transfer it to advertising platforms, data brokers or information resellers.
- We do not allow humans to read Google user data, except (a) with your explicit prior consent to view specific data, for example when you ask our support team to investigate an issue on a thread, (b) where the data has been aggregated and anonymised, (c) as necessary for security purposes such as investigating abuse, or (d) as necessary to comply with applicable law.
- Gmail data accessed via Google APIs is used only to improve scheduling for your individual account. It is never used to train a shared or general Margot model, in accordance with Google's API Services User Data Policy.
- Email content is submitted to AI providers (Anthropic, OpenAI, Cerebras) only for real-time inference and is never retained by them or sent to any provider for the purpose of training.
- We do not sell Google user data.
Revoking access.You can disconnect your Google account from Margot at any time in the Margot web platform, or revoke Margot's access directly from your Google Account security settings at myaccount.google.com/permissions. Revoking access stops all processing of your Google data, and the deletion timeline in section 10 then applies.
5. Microsoft user data
Where you connect a Microsoft account instead, Margot accesses the equivalent mail and calendar data through the same integration provider, for the same purposes and under the same retention and deletion commitments set out in this policy. Where your account is on our shared cloud infrastructure, scheduling data from your Microsoft-connected account may be used to improve Margot's general scheduling capabilities, as described in section 7. You can revoke access in the Margot web platform or from your Microsoft account settings.
6. How we use personal data, and the legal bases
| Purpose | Data used | Legal basis (UK/EU GDPR) |
|---|---|---|
| Operating the scheduling service: reading scheduling threads, checking calendars, proposing times, booking, rescheduling and cancelling meetings, applying your preferences and instructions | Connected email and calendar data, preferences, account data | Performance of a contract (Art. 6(1)(b)); for processing we perform on a firm's behalf, the firm's instructions under the data processing agreement |
| Coordinating with meeting participants who are not Margot users | Participant names, email addresses, availability, thread content | Legitimate interests (Art. 6(1)(f)): enabling the meeting you are already corresponding about, in a way you would reasonably expect from a human assistant on the same thread |
| Account administration, support, notifications to the user (checkpoints, booking confirmations, no-slot summaries) | Account data, service data | Performance of a contract |
| Billing and contract management with client firms | Firm contact and billing data | Performance of a contract; legal obligation for tax and accounting records |
| Service security: sender authentication (SPF/DKIM/DMARC) checks, abuse prevention, access controls, logging | Message metadata, service logs | Legitimate interests: keeping the service and its users secure |
| Improving the service | Aggregated and anonymised usage data; diagnostic data; for cloud-hosted accounts, scheduling email content and booking outcomes | Legitimate interests; we provide an opt-out for training use (see section 7). Gmail-sourced data is used only to improve the individual user's scheduling experience, not to train shared models, in accordance with the Limited Use requirements in section 4. Non-Google email data from cloud-hosted accounts may be used to improve general scheduling capabilities. |
| Responding to enquiries and marketing to prospective clients | Contact details, correspondence | Legitimate interests for B2B outreach; consent where required. You can opt out at any time |
| Complying with law and legal process | As required | Legal obligation (Art. 6(1)(c)) |
We do not use personal data for automated decision-making that produces legal or similarly significant effects. Margot decides which meeting time to propose; Margot never overrides the user, and material actions such as moving significant events are surfaced for the user's sign-off.
7. AI processing
Margot uses large language models to read scheduling threads and decide the next scheduling step. How this works matters, so we state it plainly:
- Margot runs in a private environment provisioned per client firm. Email and calendar content is submitted to the model solely to perform the scheduling task and is not retained by us in the model.
- We require that model endpoints used with Margot are configured so that submitted data is not used to train or improve the provider's models.
- Thread content cannot steer the agent outside scheduling. Non-scheduling content, including instructions addressed to Margot within a thread, is surfaced to the user and never acted on.
The large language model providers currently used are Anthropic (Claude), OpenAI (GPT-4o), and Cerebras. Each is used via their standard API, under terms that do not permit the provider to use submitted data to train or improve their models. Email content is submitted to these providers only to perform the scheduling task and is not retained by them.
Using scheduling data to improve Margot
Where Margot is hosted on our shared cloud infrastructure, we may use scheduling emails, participant responses, and booking outcomes from your account to train and improve AI scheduling capabilities. This applies to accounts on our standard hosted plans. Where Margot is deployed on your organisation's own servers, your data is processed entirely within your own environment and is never used for training.
The following conditions apply:
- Scheduling content only. Only emails processed by Margot as part of a scheduling conversation are used. Emails in your inbox that Margot was not copied on are never accessed for this purpose.
- Gmail data — personalised use only.Where your email account is provided by Google (Gmail), data accessed via Google APIs is used only to improve scheduling for your individual account. It is never used to train a shared or general Margot model, in accordance with Google's API Services User Data Policy.
- Non-Google email data.Where your email is provided by a non-Google provider (for example Microsoft Outlook), scheduling data from cloud-hosted accounts may be used to improve Margot's general scheduling capabilities across the product.
- No transfer to third-party AI providers for training. Scheduling emails are sent to AI providers (Anthropic, OpenAI, Cerebras) only for real-time inference. They are never sent to these providers for the purpose of training their models.
- Opt-out. You can opt out of training use at any time in account settings. On opt-out, your data is excluded from future training runs.
- Deletion. If you close your account, all data held for training purposes is deleted within 30 days.
8. Who we share personal data with
We share personal data only with the parties needed to run the service. We do not sell personal data, and we do not share it with advertising platforms, data brokers or information resellers.
| Recipient | Purpose | Location |
|---|---|---|
| Nylas | Email and calendar connectivity (Gmail and Outlook sync, send, event management) | [Confirm region under Nylas agreement] |
| Amazon Web Services | Cloud hosting of the Margot runtime and stored data | [Region, e.g. eu-west-2, London] |
| The client firm's designated LLM provider | Inference on the firm's own API keys, as described in section 7 | Per the firm's own agreement |
| Anthropic, OpenAI, Cerebras | Large language model inference for email intent classification and scheduling decisions. Email content is submitted for real-time inference only and is never retained or used for training by these providers. | United States (standard API) |
| [Analytics, error monitoring and support tooling to be listed] | Product analytics, diagnostics, customer support | [To be confirmed] |
| Professional advisers, insurers, auditors | Where reasonably necessary | UK |
| Authorities and courts | Where legally required | As required |
Within the service itself, data moves the way you would expect from a human assistant, and no further: internal coordination and shared availability stay within your firm's environment; side conversations and private notes go only to the meeting owner and are never exposed to other participants; and coordination is never visible across firm boundaries.
If Quartalyst Advisors Ltd is involved in a merger, acquisition or asset sale, personal data may be transferred as part of that transaction. For Google user data, any such transfer happens only after obtaining explicit prior consent, and the receiving party remains bound by the commitments in this policy.
A current sub-processor list is maintained at [hiMargot.ai/subprocessors] and firms are notified of changes under their data processing agreement.
9. International transfers
Margot's runtime and stored data are hosted with Amazon Web Services in [the United Kingdom / the EEA — confirm region]. Where any sub-processor processes personal data outside the UK or EEA, we rely on one of the lawful transfer mechanisms available under UK and EU law: UK adequacy regulations (including the UK-US Data Bridge where the recipient is certified), the UK International Data Transfer Agreement or Addendum, or the EU Standard Contractual Clauses, together with any supplementary measures needed. Details of the mechanism used for any given sub-processor are available on request.
10. How long we keep personal data
| Data | Retention |
|---|---|
| Email content and calendar data processed by Margot | Retained while your account connection is active, because Margot needs thread history and calendar state to manage ongoing, recurring and follow-on scheduling. Deleted from our active systems within 30 days of you disconnecting your account, revoking access, or your firm offboarding |
| Data retained for AI training (where applicable) | Scheduling emails and booking outcomes used for training on cloud-hosted accounts are deleted within 30 days of account closure, or immediately on opt-out for future training runs |
| Calendar events Margot has created | These live in your own calendar, which you and your firm control. They are unaffected by deletion of our copies |
| Account data and preferences | Life of the account, then deleted within 30 days of account closure |
| Service logs and diagnostic data | [90 days — confirm with engineering], except where needed longer for an active security investigation |
| Backups | Deleted data leaves backups on the normal rotation cycle, within [30] further days |
| Billing and contract records | 6 years from the end of the relevant tax year, as required by UK law |
| Enquiries and marketing contacts | Until you opt out, or 24 months after last meaningful contact |
Meeting participants who are not Margot users appear only within thread content and event data, and their data follows the retention of the thread owner's data above.
You can request deletion sooner at any time; see section 12.
11. Security
We protect personal data with measures appropriate to its sensitivity, including: encryption in transit (TLS) and at rest; OAuth-based connections to Google and Microsoft, so Margot never sees or stores your email password; a private, isolated environment per client firm; access to production data restricted to authorised personnel on a least-privilege basis, subject to the human-access limits in section 4; sender authentication (SPF, DKIM, DMARC) checks before Margot acts on any inbound email; and logging and monitoring of access to production systems.
No system is perfectly secure. If a personal data breach occurs that risks your rights and freedoms, we will notify the ICO, affected firms and, where required, affected individuals without undue delay and in accordance with law.
12. Your rights
Under UK and EU data protection law you have the right to: access the personal data we hold about you; have inaccurate data corrected; have data erased; restrict or object to processing, including any processing based on legitimate interests; data portability; and to withdraw consent at any time where processing is based on consent, without affecting processing before withdrawal.
To exercise any of these rights, email privacy@hiMargot.ai. We respond within one month.
Where we act as a processor for your firm, we may need to refer your request to your firm as controller, and we will tell you if so and support the request either way. If you are a meeting participant with no Margot account, the same address works: you can object to Margot processing your data for scheduling, and the simplest practical route is also open to you at any time, which is to reply to, or ignore, the thread as you would with any assistant.
You also have the right to complain to the Information Commissioner's Office at ico.org.uk or on 0303 123 1113, or to your local EU supervisory authority. We would appreciate the chance to resolve any concern first.
13. What Margot never does
These are design commitments, restated here because they are also privacy commitments: Margot acts only on scheduling; Margot never exposes side conversations or private notes to other participants; Margot never re-adds a dropped participant (with the sole exception of the person who originally added Margot to the thread); Margot acts on inbound email only when sender authentication passes; and every preference and rule the agent operates under is inspectable by the user, so Margot never runs rules the user cannot see.
14. Cookies and website analytics
hiMargot.ai uses strictly necessary cookies to make the site work, and, with your consent, analytics cookies to understand how the site is used. You can accept or decline non-essential cookies via the banner on first visit and change your choice at any time at [cookie settings link].
[Cookie table to be completed once the analytics stack is confirmed.]
15. Children
Margot is a workplace product for business users. It is not directed at children and we do not knowingly collect data from anyone under 18. If you believe a child has provided us data, contact privacy@hiMargot.ai and we will delete it.
16. Changes to this policy
We may update this policy from time to time. Material changes will be notified to client firms and flagged on this page, with the effective date above updated. Continued use of the service after the effective date constitutes acceptance, except where law requires fresh consent.
17. Contact
Quartalyst Advisors Ltd (trading as Hi Margot)71–75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom
Company number: 16538182
Email: privacy@hiMargot.ai