Legal

Privacy Policy

Last updated: 26 July 2026

1. Who we are & controller

This service is operated by AIstackuk ("AIstackuk", "we", "us", "our"), trading as AI Stack UK. AIstackuk is the data controller for personal data processed through this website and service. You can contact us at contact@aistackuk.com for any privacy question or to exercise your rights.

2. Categories of personal data we collect

  • Account data — email address, name, password hash, avatar, company (if provided).
  • Content data — documents you upload for analysis and the resulting audit outputs.
  • Usage & device data — analytics events, pages viewed, referrer, IP address, browser and device identifiers.
  • Support data — messages you send us by email or in-app.
  • Billing data — order and subscription metadata (customer ID, plan, status). Card details are handled by Paddle, not us — see section 5.

3. Purposes & legal bases

  • Providing the service (account creation, running audits, delivering reports) — legal basis: performance of a contract.
  • Security & fraud prevention (rate-limiting, abuse detection, logs) — legitimate interests.
  • Product improvement & analytics — legitimate interests, or consent where required by cookie law.
  • Customer support — performance of a contract / legitimate interests.
  • Billing, tax and accounting — legal obligation and contract performance (processed via Paddle, see section 5).
  • Marketing emails (where applicable) — consent, which you can withdraw at any time.

4. Zero data training

Documents you upload for contract review are strictly confidential and are never used to train AI models. Files are processed in-memory, PII is anonymised before being sent to the AI model, and files are purged after analysis.

5. Data sharing & subprocessors

We share personal data only with the following categories of recipients:

  • Paddle.com Market Ltd ("Paddle") — Merchant of Record and payment processor. All purchases and subscriptions are sold by Paddle as reseller. Paddle collects and processes your name, email, billing address, card / payment details, transaction data and tax information to complete the sale, handle refunds and comply with tax law. See Paddle's Privacy Notice and Buyer Terms.
  • Hosting & database — Cloudflare (edge hosting) and Supabase (managed Postgres, auth, storage).
  • AI processing — Lovable AI Gateway used for editorial features such as directory search assistance (no client documents are processed).
  • Email delivery — transactional email provider used to send account notifications from notify.aistackuk.com.
  • Analytics — Google Analytics 4 (aggregated usage metrics; IP anonymised).
  • Professional advisers — legal, accounting and tax advisers under confidentiality.
  • Authorities — where required by law, court order or to protect our rights.

We do not sell personal data. Some subprocessors are located outside the UK/EEA; transfers rely on adequacy decisions or Standard Contractual Clauses with additional safeguards.

6. Data retention

  • Account data — kept while your account is active and for up to 12 months after closure, then deleted or anonymised.
  • Uploaded documents — purged from processing memory immediately after analysis; generated audit reports are kept in your account until you delete them or close your account.
  • Billing records — retained for 7 years to meet UK tax and accounting obligations.
  • Support emails — up to 24 months from last contact.
  • Analytics events — up to 14 months in aggregated form.
  • Webhook / security logs — up to 12 months for fraud prevention and debugging.

7. Security measures

We apply appropriate technical and organisational measures, including: encryption in transit (TLS 1.2+) and at rest, row-level security on the database, least-privilege access controls, hashed passwords, signed webhook verification for payment events, PII anonymisation before AI processing, audit logging, and regular dependency and security scanning. No system is perfectly secure, but we work to protect your data and will notify you and the ICO of any personal data breach where required by law.

8. Your UK GDPR rights

You have the right to:

  • Access your personal data and receive a copy.
  • Rectify inaccurate or incomplete data.
  • Erase your data ("right to be forgotten").
  • Restrict or object to processing.
  • Data portability (structured, machine-readable format).
  • Withdraw consent at any time, where processing is based on consent.
  • Lodge a complaint with the UK Information Commissioner's Office (ico.org.uk).

To exercise any right, email contact@aistackuk.com. We will respond within one month.

9. Cookies

We use strictly necessary cookies (session, authentication, CSRF) plus optional analytics cookies you can accept or reject via the cookie banner. You can also manage cookies through your browser settings.

10. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be notified in-app or by email. The "Last updated" date at the top of this page always reflects the latest version.