Who We Are
AutoAI Labs Ltd ("we", "us", "our") is the Data Controller responsible for your personal data. We are a UK-registered company providing AI-powered automation consulting and product development services to SMEs and technology founders.
Data Controller Details
- Registered Name
- AutoAI Labs Ltd
- Registered Address
- 5 Chatteris Close, Luton, England, LU4 9QP
- Company Number
- 16563465
- ICO Registration Number
- ZB487293
- Data Controller Email
- dpo@autoailabs.co.uk
If you have any questions about how we handle your personal data, you can contact us at any time using the details above or via the contact block at the end of this policy.
What Data We Collect
We collect personal data only when necessary and always with a clear purpose. The categories of personal data we may collect include:
2.1 Data You Provide Directly
- Identity Data: Full name, job title, company name.
- Contact Data: Email address, phone number (if provided).
- Project Data: Any descriptions, requirements, or details you share about your project via our contact or enquiry forms.
- Communication Data: Records of correspondence between you and AutoAI Labs, including emails and chat messages.
2.2 Data Collected Automatically
- Usage Data: Pages visited, time on site, referring URLs, browser type, operating system, and device type, collected via our analytics platform.
- Technical Data: IP address (anonymised where possible), session identifiers, and approximate geolocation (country/city level only).
- Cookie Data: Data collected via cookies and similar tracking technologies â see Section 7 for full details.
2.3 Data We Do Not Collect
We do not collect or process special category data (such as health, biometric, religious, or racial data), financial payment card data, or data relating to criminal convictions. We do not build individual user profiles for advertising purposes.
How We Use Your Data
We use personal data for the following purposes:
| Purpose | Data Used | Legal Basis |
|---|---|---|
| Responding to your enquiry or contact form submission | Identity, Contact, Project Data | Contractual necessity / Legitimate interest |
| Sending you information about our services you requested | Identity, Contact Data | Consent |
| Improving our website and user experience | Usage, Technical Data | Legitimate interest |
| Analytics and performance measurement | Usage, Cookie Data | Consent (where required) |
| Legal compliance and record-keeping | All relevant categories | Legal obligation |
| Preventing fraud and ensuring security | Technical Data | Legitimate interest |
Legal Basis for Processing
Under UK GDPR, we must have a valid legal basis for every processing activity. We rely on the following bases:
Consent
Where you have given us clear, specific, informed, and unambiguous consent â for example, opting in to marketing emails or accepting non-essential cookies.
Contractual Necessity
Where processing is necessary to fulfil a contract with you or to take steps at your request before entering a contract â for example, responding to a project enquiry.
Legitimate Interest
Where we have a genuine and proportionate business reason â such as improving our services, preventing fraud, or responding to your direct communications â that doesn't override your rights.
Legal Obligation
Where processing is required to comply with applicable UK law â for example, retaining financial records under HMRC requirements.
You have the right to withdraw consent at any time without affecting the lawfulness of processing carried out before withdrawal. To withdraw consent, contact us at dpo@autoailabs.co.uk.
Data Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including any legal, accounting, or reporting requirements. Our standard retention periods are:
| Data Category | Retention Period | Reason |
|---|---|---|
| Enquiry and contact form data | 3 years from last contact | Legitimate interest in potential re-engagement |
| Client project records | 7 years from project end | Legal obligation (HMRC / Companies Act) |
| Marketing consent records | Until consent withdrawn + 1 year | Demonstrating compliance |
| Website analytics data | 26 months (anonymised) | Legitimate interest / Consent |
| Cookie consent logs | 13 months | Legal obligation |
Once the relevant retention period expires, personal data is securely deleted or anonymised so that it can no longer be attributed to you.
Third-Party Services
We engage carefully selected third-party service providers (data processors) to help us operate our business. These providers only process your data on our instructions and are bound by data processing agreements (DPAs) that meet UK GDPR standards. Our key processors include:
Email Service Provider
Used to send and manage transactional and marketing emails. Data transferred under Standard Contractual Clauses (SCCs).
Transactional EmailWeb Analytics Platform
Privacy-first analytics to understand website usage. IP addresses are anonymised. Data is not shared with third parties for advertising.
AnalyticsCRM / Contact Management
Used to manage client and prospect relationships, track communications, and store project-related notes securely.
CRMWebsite Hosting Provider
Our website is hosted on a secure, UK/EEA-based infrastructure. The hosting provider processes server logs containing technical data.
HostingWe do not sell, rent, or trade your personal data to third parties for their own marketing purposes. We will only disclose your data to authorities if required to do so by law.
Cookies
Our website uses cookies â small text files stored on your device â to improve functionality and understand how our site is used. We categorise cookies as follows:
Your Rights Under UK GDPR
As a data subject, you have the following rights under UK GDPR. We will respond to all legitimate requests within one calendar month.
Right of Access
Request a copy of the personal data we hold about you (Subject Access Request / SAR).
Right to Rectification
Request correction of inaccurate or incomplete personal data we hold about you.
Right to Erasure
Request deletion of your personal data where there is no compelling reason to continue processing (the "right to be forgotten").
Right to Restriction
Request that we restrict processing of your data in certain circumstances â for example, while the accuracy of data is contested.
Right to Portability
Receive your personal data in a structured, commonly used, machine-readable format and transfer it to another controller.
Right to Object
Object to processing based on legitimate interests or for direct marketing purposes (you have an absolute right to object to marketing).
Automated Decision-Making
Not to be subject to solely automated decisions â including profiling â that produce legal or similarly significant effects. We do not currently use automated decision-making.
Right to Withdraw Consent
Withdraw any consent given at any time. Withdrawal does not affect the lawfulness of processing carried out prior to withdrawal.
To exercise any of your rights, contact us at dpo@autoailabs.co.uk with your request. We may need to verify your identity before processing the request. There is no fee for most requests, unless they are manifestly unfounded or excessive.
International Transfers
Some of our third-party processors may be based outside the UK or EEA. Where personal data is transferred internationally, we ensure adequate protections are in place through one of the following mechanisms:
- UK Adequacy Regulations: Transfer to countries recognised by the UK Government as providing an adequate level of data protection (e.g. EEA member states, Canada, Israel).
- Standard Contractual Clauses (SCCs): Use of UK International Data Transfer Agreements (IDTAs) or approved SCCs that bind the recipient to UK GDPR-equivalent protections.
- Binding Corporate Rules (BCRs): Where the recipient organisation has approved BCRs in place.
You can request details of the specific safeguards in place for any transfer by contacting us at dpo@autoailabs.co.uk.
Data Security
We take the security of your personal data seriously and implement appropriate technical and organisational measures to protect it against unauthorised access, loss, destruction, or alteration. Our security measures include:
While no system is 100% secure, we continuously review and improve our security measures. In the event of a personal data breach that is likely to result in risk to your rights and freedoms, we will notify the ICO within 72 hours and inform you without undue delay.
Children's Data
Our services are directed exclusively at business professionals and are not intended for use by individuals under the age of 18. We do not knowingly collect personal data from children.
If you believe that a child has provided us with personal data without appropriate consent, please contact us immediately at dpo@autoailabs.co.uk and we will take prompt steps to delete that information.
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make changes, we will:
- Update the "Last updated" date at the top of this page.
- Notify users of material changes via email (where we hold your contact details and the change significantly affects your rights).
- Maintain a version history so you can review what has changed.
We encourage you to review this policy periodically. Continued use of our website or services after any changes constitutes your acceptance of the updated policy.
Version History
Contact the Data Controller
If you have any questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact our Data Controller directly:
Data Controller Contact Details
For all data subject requests and privacy enquiries
You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk or by calling 0303 123 1113. We would, however, appreciate the opportunity to address your concerns before you approach the ICO.