Consent Notice (widget wording)
Version 2.4 - Effective 2026-07-19 - Change log Template document: review by a qualified data-protection lawyer or DPO before commercial reliance. Not legal advice.
This notice documents the consent wording the Whistle widget actually presents to visitors and how each consent is recorded. Contact details are collected through a conversational capture flow: the message composer is replaced by one slim structured field at a time (name, then phone or email as needed). Answers post straight to the EU backend and never enter the history the AI sees. The privacy policy linked in the widget is always the client's (the controller's) policy, configured per client.
Tier 1: early contact capture (optional, skippable)
Shortly after the visitor's first message, the assistant may ask for a name and phone number in case the conversation is cut off. Submitting a field is the consent act: the visitor gives consent by the affirmative act of sending their details, with this statement displayed directly beneath the input:
"By continuing you agree [business] may store these details to handle your enquiry, per the privacy policy. Stored securely in the EU."
The step is entirely skippable ("Skip for now"). If the visitor skips, no personal details are stored and the conversation simply continues.
Tier 2: booking and hand-off capture
Before a booking or callback is arranged, the same conversational capture collects the remaining contact details, with the same consent statement shown beneath the input while contact details are being collected. At the email step, the visitor instead sees:
"We'll only use this to confirm your booking."
together with a separate, optional, unticked marketing checkbox:
"Optionally, keep me updated with helpful information"
Keeping marketing separate and opt-in means any future marketing rests on its own consent, as UK PECR and the EU ePrivacy Directive require. The flow completes without the marketing opt-in; it never completes without the visitor having actively submitted their details beneath the consent statement.
Service follow-up emails
If a visitor submits contact details under the consent above but does not complete a booking, the client may enable follow-up emails inviting the visitor to pick a time. These messages concern only the visitor's own enquiry: at most three are ever sent (the client configures one to three; the default is one), all within 7 days of the enquiry, spaced at least 48 hours apart by default, containing no marketing content. The final message always states that it is the last. They are service communications under the consent already given for handling the enquiry, not direct marketing; any marketing still requires the separate opt-in above. Each send is recorded against the lead (followUpStage, followUpSentAt) and in the audit log.
AI disclosure
Disclosure that the visitor is talking to an AI does not depend on the model's behaviour. The widget displays, by design:
- a persistent "AI assistant" label in the conversation header, visible for the whole conversation and shown before any message can be typed (the home panel is navigation only and carries no AI interaction);
- a static disclosure line pinned at the top of the conversation, shown before the visitor types anything, carrying the client's configured disclosure (
noAdviceDisclaimer), by default:
"I'm an AI assistant and can't give legal or professional advice, I just help get you booked in with the team."
The same disclosure is also instructed through the assistant's configuration so the AI describes itself accurately in conversation. This meets EU AI Act Article 50 (transparency for AI systems interacting with people, applying from 2 August 2026): clear disclosure at the latest at the time of first interaction. Clients must not remove or obscure it, per the Acceptable Use Policy.
How consent is recorded
- Each consent is recorded against the lead with a timestamp and the
consentPolicyVersionin force at the time. - The
consentPolicyVersionvalue in a client's configuration must reference the version of this document (currently 2.4), so every recorded consent maps to the exact wording shown. - Consent can be withdrawn at any time: see the Data Subject Requests procedure. Withdrawal does not affect the lawfulness of processing before withdrawal.
Related: Privacy Policy, Cookie Notice, AI Transparency Notice.
This document is a GDPR-aligned template and must be reviewed by a qualified data-protection lawyer or DPO before commercial reliance. It is not legal advice.