{ "html": "\n\n\n \n \n Privacy Policy — AutoAI Labs\n \n \n \n \n \n \n \n \n\n\n\n \n
\n\n \n
\n
\n
\n \n \n \n \n \n \n \n \n \n
\n

Loading Privacy Policy

\n

Fetching the latest version of our privacy policy.

\n
\n
\n
\n
\n
\n
\n
\n
\n\n \n
\n\n \n
\n
\n \n
\n \n \n \n \n \n
\n AutoAI Labs\n
\n\n \n\n \n\n \n
\n
\n\n \n
\n\n \n
\n
\n
\n \n \n \n UK GDPR Compliant\n
\n

Privacy Policy

\n
\n \n \n \n \n \n \n Last updated: 1 January 2025\n \n Version 1.0\n
\n

\n This Privacy Policy explains how AutoAI Labs Ltd collects, uses, stores, and protects your personal data when you visit our website or interact with our services. We are committed to transparency and to your rights under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. This document tells you exactly what data we hold, why we hold it, and how you can exercise your rights.\n

\n
\n
\n\n \n
\n\n \n \n\n \n \n\n \n
\n\n \n
\n
\n 01\n

Who We Are

\n
\n
\n

AutoAI Labs Ltd (\"we\", \"us\", \"our\") is the Data Controller responsible for your personal data. We are a UK-registered company providing AI-powered automation consulting and product development services to SMEs and technology founders.

\n
\n

Data Controller Details

\n
\n
\n
Registered Name
\n
AutoAI Labs Ltd
\n
\n
\n
Registered Address
\n
12 Innovation Quarter, Manchester, M1 7AB, United Kingdom
\n
\n
\n
Company Number
\n
14829374
\n
\n
\n
ICO Registration Number
\n
ZB487293
\n
\n
\n
Data Controller Email
\n
dpo@autoailabs.co.uk
\n
\n
\n
\n

If you have any questions about how we handle your personal data, you can contact us at any time using the details above or via the contact block at the end of this policy.

\n
\n
\n\n \n
\n
\n 02\n

What Data We Collect

\n
\n
\n

We collect personal data only when necessary and always with a clear purpose. The categories of personal data we may collect include:

\n

2.1 Data You Provide Directly

\n
    \n
  • Identity Data: Full name, job title, company name.
  • \n
  • Contact Data: Email address, phone number (if provided).
  • \n
  • Project Data: Any descriptions, requirements, or details you share about your project via our contact or enquiry forms.
  • \n
  • Communication Data: Records of correspondence between you and AutoAI Labs, including emails and chat messages.
  • \n
\n

2.2 Data Collected Automatically

\n
    \n
  • Usage Data: Pages visited, time on site, referring URLs, browser type, operating system, and device type, collected via our analytics platform.
  • \n
  • Technical Data: IP address (anonymised where possible), session identifiers, and approximate geolocation (country/city level only).
  • \n
  • Cookie Data: Data collected via cookies and similar tracking technologies — see Section 7 for full details.
  • \n
\n

2.3 Data We Do Not Collect

\n

We do not collect or process special category data (such as health, biometric, religious, or racial data), financial payment card data, or data relating to criminal convictions. We do not build individual user profiles for advertising purposes.

\n
\n
\n\n \n
\n
\n 03\n

How We Use Your Data

\n
\n
\n

We use personal data for the following purposes:

\n
\n \n \n \n \n \n \n \n \n \n \n \n \n \n \n \n \n \n \n \n \n \n \n \n \n \n \n \n \n \n \n \n \n \n \n \n \n \n \n \n \n
PurposeData UsedLegal Basis
Responding to your enquiry or contact form submissionIdentity, Contact, Project DataContractual necessity / Legitimate interest
Sending you information about our services you requestedIdentity, Contact DataConsent
Improving our website and user experienceUsage, Technical DataLegitimate interest
Analytics and performance measurementUsage, Cookie DataConsent (where required)
Legal compliance and record-keepingAll relevant categoriesLegal obligation
Preventing fraud and ensuring securityTechnical DataLegitimate interest
\n
\n
\n
\n\n \n \n\n \n
\n
\n 05\n

Data Retention

\n
\n
\n

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including any legal, accounting, or reporting requirements. Our standard retention periods are:

\n
\n \n \n \n \n \n \n \n \n \n \n \n \n \n \n \n \n \n \n \n \n \n \n \n \n \n \n \n \n \n \n \n \n \n \n \n
Data CategoryRetention PeriodReason
Enquiry and contact form data3 years from last contactLegitimate interest in potential re-engagement
Client project records7 years from project endLegal obligation (HMRC / Companies Act)
Marketing consent recordsUntil consent withdrawn + 1 yearDemonstrating compliance
Website analytics data26 months (anonymised)Legitimate interest / Consent
Cookie consent logs13 monthsLegal obligation
\n
\n

Once the relevant retention period expires, personal data is securely deleted or anonymised so that it can no longer be attributed to you.

\n
\n
\n\n \n
\n
\n 06\n

Third-Party Services

\n
\n
\n

We engage carefully selected third-party service providers (data processors) to help us operate our business. These providers only process your data on our instructions and are bound by data processing agreements (DPAs) that meet UK GDPR standards. Our key processors include:

\n
\n
\n
\n \n \n \n \n
\n
\n

Email Service Provider

\n

Used to send and manage transactional and marketing emails. Data transferred under Standard Contractual Clauses (SCCs).

\n Transactional Email\n
\n
\n
\n
\n \n \n \n
\n
\n

Web Analytics Platform

\n

Privacy-first analytics to understand website usage. IP addresses are anonymised. Data is not shared with third parties for advertising.

\n Analytics\n
\n
\n
\n
\n \n \n \n \n
\n
\n

CRM / Contact Management

\n

Used to manage client and prospect relationships, track communications, and store project-related notes securely.

\n CRM\n
\n
\n
\n
\n \n \n \n \n
\n
\n

Website Hosting Provider

\n

Our website is hosted on a secure, UK/EEA-based infrastructure. The hosting provider processes server logs containing technical data.

\n Hosting\n
\n
\n
\n

We do not sell, rent, or trade your personal data to third parties for their own marketing purposes. We will only disclose your data to authorities if required to do so by law.

\n
\n
\n\n \n
\n
\n 07\n

Cookies

\n
\n
\n

Our website uses cookies — small text files stored on your device — to improve functionality and understand how our site is used. We categorise cookies as follows:

\n
\n
\n Always Active\n

Strictly Necessary Cookies

\n
\n

These cookies are essential for the website to function and cannot be disabled. They do not store personally identifiable information. They are set in response to actions you take, such as setting your privacy preferences or filling in forms.

\n
\n
\n
\n Requires Consent\n

Analytics Cookies

\n
\n

These cookies allow us to count visits and traffic sources to measure and improve site performance. All data is aggregated and anonymised. We use these only with your consent.

\n
\n
\n
\n Requires Consent\n

Functional Cookies

\n
\n

These cookies enable enhanced functionality and personalisation — for example, remembering your preferences. They may be set by us or by third-party providers whose services we have added to our pages.

\n
\n
\n \n \n \n \n \n

You can manage your cookie preferences at any time by clicking the \"Manage Cookies\" button in our cookie banner or by adjusting your browser settings. Note that blocking all cookies may affect website functionality.

\n
\n
\n
\n\n \n
\n
\n 08\n

Your Rights Under UK GDPR

\n
\n
\n

As a data subject, you have the following rights under UK GDPR. We will respond to all legitimate requests within one calendar month.

\n
\n
\n
\n \n \n \n \n
\n

Right of Access

\n

Request a copy of the personal data we hold about you (Subject Access Request / SAR).

\n
\n
\n
\n \n \n \n
\n

Right to Rectification

\n

Request correction of inaccurate or incomplete personal data we hold about you.

\n
\n
\n
\n \n \n \n \n
\n

Right to Erasure

\n

Request deletion of your personal data where there is no compelling reason to continue processing (the \"right to be forgotten\").

\n
\n
\n
\n \n \n \n \n
\n

Right to Restriction

\n

Request that we restrict processing of your data in certain circumstances — for example, while the accuracy of data is contested.

\n
\n
\n
\n \n \n \n \n \n
\n

Right to Portability

\n

Receive your personal data in a structured, commonly used, machine-readable format and transfer it to another controller.

\n
\n
\n
\n \n \n \n \n \n
\n

Right to Object

\n

Object to processing based on legitimate interests or for direct marketing purposes (you have an absolute right to object to marketing).

\n
\n
\n
\n \n \n \n \n
\n

Automated Decision-Making

\n

Not to be subject to solely automated decisions — including profiling — that produce legal or similarly significant effects. We do not currently use automated decision-making.

\n
\n
\n
\n \n \n \n \n \n
\n

Right to Withdraw Consent

\n

Withdraw any consent given at any time. Withdrawal does not affect the lawfulness of processing carried out prior to withdrawal.

\n
\n
\n
\n

To exercise any of your rights, contact us at dpo@autoailabs.co.uk with your request. We may need to verify your identity before processing the request. There is no fee for most requests, unless they are manifestly unfounded or excessive.

\n
\n
\n
\n\n \n
\n
\n 09\n

International Transfers

\n
\n
\n

Some of our third-party processors may be based outside the UK or EEA. Where personal data is transferred internationally, we ensure adequate protections are in place through one of the following mechanisms:

\n
    \n
  • UK Adequacy Regulations: Transfer to countries recognised by the UK Government as providing an adequate level of data protection (e.g. EEA member states, Canada, Israel).
  • \n
  • Standard Contractual Clauses (SCCs): Use of UK International Data Transfer Agreements (IDTAs) or approved SCCs that bind the recipient to UK GDPR-equivalent protections.
  • \n
  • Binding Corporate Rules (BCRs): Where the recipient organisation has approved BCRs in place.
  • \n
\n

You can request details of the specific safeguards in place for any transfer by contacting us at dpo@autoailabs.co.uk.

\n
\n
\n\n \n
\n
\n 10\n

Data Security

\n
\n
\n

We take the security of your personal data seriously and implement appropriate technical and organisational measures to protect it against unauthorised access, loss, destruction, or alteration. Our security measures include:

\n
\n
\n \n \n \n \n TLS/SSL encryption for all data in transit\n
\n
\n \n \n \n \n Encryption at rest for stored personal data\n
\n
\n \n \n \n \n Role-based access controls and least-privilege principles\n
\n
\n \n \n \n \n \n \n Multi-factor authentication for internal system access\n
\n
\n \n \n \n \n Regular security reviews and vendor due diligence\n
\n
\n \n \n \n Data breach response procedures and ICO reporting protocols\n
\n
\n

While no system is 100% secure, we continuously review and improve our security measures. In the event of a personal data breach that is likely to result in risk to your rights and freedoms, we will notify the ICO within 72 hours and inform you without undue delay.

\n
\n
\n\n \n
\n
\n 11\n

Children's Data

\n
\n
\n

Our services are directed exclusively at business professionals and are not intended for use by individuals under the age of 18. We do not knowingly collect personal data from children.

\n

If you believe that a child has provided us with personal data without appropriate consent, please contact us immediately at dpo@autoailabs.co.uk and we will take prompt steps to delete that information.

\n
\n
\n\n \n
\n
\n 12\n

Changes to This Policy

\n
\n
\n

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make changes, we will:

\n
    \n
  • Update the \"Last updated\" date at the top of this page.
  • \n
  • Notify users of material changes via email (where we hold your contact details and the change significantly affects your rights).
  • \n
  • Maintain a version history so you can review what has changed.
  • \n
\n

We encourage you to review this policy periodically. Continued use of our website or services after any changes constitutes your acceptance of the updated policy.

\n
\n

Version History

\n
\n v1.0\n 1 January 2025\n Initial publication\n
\n
\n
\n
\n\n \n
\n
\n 13\n

Contact the Data Controller

\n
\n
\n

If you have any questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact our Data Controller directly:

\n
\n
\n\n \n
\n
\n
\n \n \n \n \n
\n
\n

Data Controller Contact Details

\n

For all data subject requests and privacy enquiries

\n
\n
\n\n
\n
\n Company\n AutoAI Labs Ltd\n
\n
\n Address\n 12 Innovation Quarter, Manchester, M1 7AB, United Kingdom\n
\n
\n ICO Registration\n ZB487293\n
\n
\n Data Controller Email\n dpo@autoailabs.co.uk\n
\n
\n Response Time\n Within 1 calendar month\n
\n
\n\n \n\n
\n \n \n \n \n \n

You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk or by calling 0303 123 1113. We would, however, appreciate the opportunity to address your concerns before you approach the ICO.

\n
\n
\n\n \n