UK GDPR Compliant

Privacy Policy

Last updated: 1 January 2025 Version 1.0

This Privacy Policy explains how AutoAI Labs Ltd collects, uses, stores, and protects your personal data when you visit our website or interact with our services. We are committed to transparency and to your rights under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. This document tells you exactly what data we hold, why we hold it, and how you can exercise your rights.

01

Who We Are

AutoAI Labs Ltd ("we", "us", "our") is the Data Controller responsible for your personal data. We are a UK-registered company providing AI-powered automation consulting and product development services to SMEs and technology founders.

Data Controller Details

Registered Name
AutoAI Labs Ltd
Registered Address
5 Chatteris Close, Luton, England, LU4 9QP
Company Number
16563465
ICO Registration Number
ZB487293
Data Controller Email
dpo@autoailabs.co.uk

If you have any questions about how we handle your personal data, you can contact us at any time using the details above or via the contact block at the end of this policy.

02

What Data We Collect

We collect personal data only when necessary and always with a clear purpose. The categories of personal data we may collect include:

2.1 Data You Provide Directly

  • Identity Data: Full name, job title, company name.
  • Contact Data: Email address, phone number (if provided).
  • Project Data: Any descriptions, requirements, or details you share about your project via our contact or enquiry forms.
  • Communication Data: Records of correspondence between you and AutoAI Labs, including emails and chat messages.

2.2 Data Collected Automatically

  • Usage Data: Pages visited, time on site, referring URLs, browser type, operating system, and device type, collected via our analytics platform.
  • Technical Data: IP address (anonymised where possible), session identifiers, and approximate geolocation (country/city level only).
  • Cookie Data: Data collected via cookies and similar tracking technologies — see Section 7 for full details.

2.3 Data We Do Not Collect

We do not collect or process special category data (such as health, biometric, religious, or racial data), financial payment card data, or data relating to criminal convictions. We do not build individual user profiles for advertising purposes.

03

How We Use Your Data

We use personal data for the following purposes:

Purpose Data Used Legal Basis
Responding to your enquiry or contact form submission Identity, Contact, Project Data Contractual necessity / Legitimate interest
Sending you information about our services you requested Identity, Contact Data Consent
Improving our website and user experience Usage, Technical Data Legitimate interest
Analytics and performance measurement Usage, Cookie Data Consent (where required)
Legal compliance and record-keeping All relevant categories Legal obligation
Preventing fraud and ensuring security Technical Data Legitimate interest
05

Data Retention

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including any legal, accounting, or reporting requirements. Our standard retention periods are:

Data Category Retention Period Reason
Enquiry and contact form data 3 years from last contact Legitimate interest in potential re-engagement
Client project records 7 years from project end Legal obligation (HMRC / Companies Act)
Marketing consent records Until consent withdrawn + 1 year Demonstrating compliance
Website analytics data 26 months (anonymised) Legitimate interest / Consent
Cookie consent logs 13 months Legal obligation

Once the relevant retention period expires, personal data is securely deleted or anonymised so that it can no longer be attributed to you.

06

Third-Party Services

We engage carefully selected third-party service providers (data processors) to help us operate our business. These providers only process your data on our instructions and are bound by data processing agreements (DPAs) that meet UK GDPR standards. Our key processors include:

Email Service Provider

Used to send and manage transactional and marketing emails. Data transferred under Standard Contractual Clauses (SCCs).

Transactional Email

Web Analytics Platform

Privacy-first analytics to understand website usage. IP addresses are anonymised. Data is not shared with third parties for advertising.

Analytics

CRM / Contact Management

Used to manage client and prospect relationships, track communications, and store project-related notes securely.

CRM

Website Hosting Provider

Our website is hosted on a secure, UK/EEA-based infrastructure. The hosting provider processes server logs containing technical data.

Hosting

We do not sell, rent, or trade your personal data to third parties for their own marketing purposes. We will only disclose your data to authorities if required to do so by law.

07

Cookies

Our website uses cookies — small text files stored on your device — to improve functionality and understand how our site is used. We categorise cookies as follows:

08

Your Rights Under UK GDPR

As a data subject, you have the following rights under UK GDPR. We will respond to all legitimate requests within one calendar month.

Right of Access

Request a copy of the personal data we hold about you (Subject Access Request / SAR).

Right to Rectification

Request correction of inaccurate or incomplete personal data we hold about you.

Right to Erasure

Request deletion of your personal data where there is no compelling reason to continue processing (the "right to be forgotten").

Right to Restriction

Request that we restrict processing of your data in certain circumstances — for example, while the accuracy of data is contested.

Right to Portability

Receive your personal data in a structured, commonly used, machine-readable format and transfer it to another controller.

Right to Object

Object to processing based on legitimate interests or for direct marketing purposes (you have an absolute right to object to marketing).

Automated Decision-Making

Not to be subject to solely automated decisions — including profiling — that produce legal or similarly significant effects. We do not currently use automated decision-making.

Right to Withdraw Consent

Withdraw any consent given at any time. Withdrawal does not affect the lawfulness of processing carried out prior to withdrawal.

To exercise any of your rights, contact us at dpo@autoailabs.co.uk with your request. We may need to verify your identity before processing the request. There is no fee for most requests, unless they are manifestly unfounded or excessive.

09

International Transfers

Some of our third-party processors may be based outside the UK or EEA. Where personal data is transferred internationally, we ensure adequate protections are in place through one of the following mechanisms:

  • UK Adequacy Regulations: Transfer to countries recognised by the UK Government as providing an adequate level of data protection (e.g. EEA member states, Canada, Israel).
  • Standard Contractual Clauses (SCCs): Use of UK International Data Transfer Agreements (IDTAs) or approved SCCs that bind the recipient to UK GDPR-equivalent protections.
  • Binding Corporate Rules (BCRs): Where the recipient organisation has approved BCRs in place.

You can request details of the specific safeguards in place for any transfer by contacting us at dpo@autoailabs.co.uk.

10

Data Security

We take the security of your personal data seriously and implement appropriate technical and organisational measures to protect it against unauthorised access, loss, destruction, or alteration. Our security measures include:

TLS/SSL encryption for all data in transit
Encryption at rest for stored personal data
Role-based access controls and least-privilege principles
Multi-factor authentication for internal system access
Regular security reviews and vendor due diligence
Data breach response procedures and ICO reporting protocols

While no system is 100% secure, we continuously review and improve our security measures. In the event of a personal data breach that is likely to result in risk to your rights and freedoms, we will notify the ICO within 72 hours and inform you without undue delay.

11

Children's Data

Our services are directed exclusively at business professionals and are not intended for use by individuals under the age of 18. We do not knowingly collect personal data from children.

If you believe that a child has provided us with personal data without appropriate consent, please contact us immediately at dpo@autoailabs.co.uk and we will take prompt steps to delete that information.

12

Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make changes, we will:

  • Update the "Last updated" date at the top of this page.
  • Notify users of material changes via email (where we hold your contact details and the change significantly affects your rights).
  • Maintain a version history so you can review what has changed.

We encourage you to review this policy periodically. Continued use of our website or services after any changes constitutes your acceptance of the updated policy.

Version History

v1.0 1 January 2025 Initial publication
13

Contact the Data Controller

If you have any questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact our Data Controller directly:

Data Controller Contact Details

For all data subject requests and privacy enquiries

Company AutoAI Labs Ltd
Address 5 Chatteris Close, Luton, England, LU4 9QP
ICO Registration ZB487293
Data Controller Email dpo@autoailabs.co.uk
Response Time Within 1 calendar month

You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk or by calling 0303 123 1113. We would, however, appreciate the opportunity to address your concerns before you approach the ICO.