Business AI
Legal centre

UK Pilot · Privacy

Privacy Notice

Version 1.1 · Effective 27 September 2026

Pilot identity notice. Business AI is currently an invitation-only UK Pilot. The service provider's legal/trading name, geographic establishment address and direct contact email have not yet been configured for public display. Paid public launch must remain blocked until those details are published.

1. Who is responsible for your information?

For account administration, billing, service security, operational logging and Pilot support, the Business AI operator shown above acts as controller. For customer enquiry data processed for a subscribing business, that business is normally the controller and the Business AI operator acts as its processor under the Data Processing Agreement.

2. Information and sources

Depending on the features used, Business AI may handle account email/authentication records; business profile and configuration information; customer names, contact details and enquiry messages; leads, actions and booking requests; approved Business Knowledge files and extracted facts; marketing drafts, images, publication records and connected social-account identifiers; billing/subscription metadata; security/audit events; and Pilot feedback.

Information is obtained from account users and customers directly, from authorised business users, from connected providers such as Stripe and Meta when those features are used, and from technical/security events generated while the service operates. Raw payment-card information should not be entered into Business AI; Stripe handles card processing in supported checkout flows.

3. Why controller data is used

PurposeTypical lawful basis
Provide and administer accounts, subscriptions and requested features.Contract or steps taken at your request before a contract.
Secure the service, prevent abuse, investigate faults and maintain proportionate audit records.Legitimate interests in operating and protecting the service.
Manage billing, accounting and records required by law.Contract and/or legal obligation.
Respond to support, privacy and legal requests.Contract, legitimate interests and/or legal obligation depending on the request.

4. Customer enquiries

When a person uses a business's public Business AI enquiry page, their message and any contact details they provide are collected for that business. The business determines the purpose and lawful basis for that customer relationship. Business AI processes the information to generate responses, capture enquiries, create leads/actions/bookings where configured, support human handover and make information available to authorised members of that business.

If you are a customer contacting a business, requests about access, correction, deletion, restriction or objection should normally be made to that business first. Business AI provides technical tools to help the business respond.

5. AI processing and automated decisions

Customer messages and relevant approved business context may be sent to an AI provider to generate an enquiry response or marketing content. Business AI is designed to support human review and handover and is not intended to make solely automated decisions that have legal or similarly significant effects on people.

6. Recipients and service providers

Business AI uses providers for hosting, database/authentication/storage, AI processing, billing and optional social publishing. The current provider list and purposes are in the Sub-processor Notice. Access is limited to what is needed for the relevant service.

7. International transfers

Some providers may process information outside the UK. Where a restricted transfer occurs, the operator must use an available UK transfer mechanism where required and assess the transfer in line with current ICO guidance. Information on applicable safeguards can be requested using the contact email shown above.

8. Retention

The Pilot currently exposes business-configurable review settings, with defaults of 365 days for lead-data review and 730 days for audit-record review. These are review periods, not automatic deletion promises. Account, billing, security, legal and support records are retained only for as long as reasonably needed for their purpose or a legal requirement. At the end of processor services, customer data is handled under the DPA.

9. Security

The Pilot uses authenticated tenant membership, role-based access, database row-level security, server-side secrets, private file storage, audit logging and encryption for supported social tokens. No online system can guarantee absolute security, and users must also protect their accounts and devices.

10. Your rights

Depending on the circumstances and lawful basis, UK data-protection law may give you rights of access, rectification, erasure, restriction, objection and data portability, plus rights relating to automated decision-making.

Your right to object. Where the Business AI operator relies on legitimate interests for processing your personal information, you can object to that processing. Direct-marketing objections must be respected where applicable. Use the contact email shown above; customer-enquiry objections should normally be sent to the relevant business controller.

11. Complaints

You can raise a privacy concern using the contact email shown above. You also have the right to complain to the Information Commissioner's Office (ICO). For customer-enquiry data, contacting the relevant business first may allow it to resolve the request quickly.

12. Storage on your device

Business AI uses essential browser storage for authentication and requested app functions. The current Pilot does not intentionally deploy advertising or behavioural-tracking technologies. See the Storage & Cookie Notice.

13. Changes

Material changes are versioned. Where appropriate, account users are shown the new version and asked to acknowledge or accept it before continuing.

Business AI Pilot · Version 1.1 · Last updated 27 September 2026. This pack describes the current Pilot and is not independent legal certification.