1. Who is responsible for your information?
London AI Company is the trading name of Imram Wojdak, a sole trader established in England. It is not currently an incorporated company. For the business activities described in this notice, Imram Wojdak is the controller: the person who decides why and how personal information is used.
Business address: 23 Lower Court Road, KT19 8SW, United Kingdom
Privacy contact: support@londonai.company
Website: londonai.company
You can contact us using these details about your information, your rights or a complaint.
2. What this notice covers
This notice covers people who visit our website, contact us, receive relevant business communications, purchase or discuss our services, represent our customers or suppliers, or use our support channels.
We also build and support operational analytics and automation systems for clients. Where we process personal information only on a client’s documented instructions, that client is normally the controller and we are its processor. The client’s privacy notice explains the purpose and legal basis for that use. Our written data-processing agreement with the client governs our work. If the client is itself a processor, the roles and authorisation chain are documented separately.
For example, we may be controller for a warehouse operator’s billing contact details, but processor for delivery records containing personal information that the operator asks us to analyse. We do not automatically become the controller of every record accessible through an integration.
3. Information we collect and where it comes from
Depending on your interaction, we collect:
Contact and professional information: your name, business email, telephone number if provided, role, organisation and relevant public business details.
Enquiries and communications: messages, meeting notes, project requirements, feedback, support correspondence and information you choose to give us. We do not record or automatically transcribe meetings under our standard enquiry process. If a particular engagement needs recording, we will explain the purpose, lawful basis, provider and retention before it starts and obtain consent where required.
Contract and transaction records: proposals, Orders, signatures or acceptance records, billing addresses, invoices, payment status, transaction references, correspondence about payments and disputes, and limited payment-method details made available by Stripe.
Technical and security information: information such as IP address, browser and device information, requested pages, timestamps and security logs produced when the website or our business systems are used. The information collected depends on the tools described in section 7.
Preferences and compliance records: marketing preferences, opt-outs, consent records where relevant, privacy requests and complaints.
We obtain information directly from you; from your organisation or an authorised colleague; from our service providers, including Stripe; and, for relevant business prospecting, from public company websites, business directories, Companies House and public professional profiles. We use professional details relevant to the proposed business contact. Where a specific external lead source is used, we record it and can explain where your details came from. We do not use bought personal-contact lists under our standard prospecting process.
When we obtain your personal information indirectly, we provide this notice within the required time: normally at first contact if sooner, and no later than one month after obtaining the information, subject to applicable legal exceptions. Where disclosure to another recipient is envisaged, the notice is provided no later than the first disclosure if that occurs sooner.
4. Why we use information and our lawful bases
Responding to an enquiry or preparing a proposal: we use relevant contact details, communications and requirements to understand and respond to your request. If you are personally the prospective contracting party, such as a sole trader, the basis is taking steps at your request before entering a contract. For a company employee or representative, the basis is our legitimate interest in responding to business enquiries and developing customer relationships.
Delivering and administering a contract: we use contact, project, billing and acceptance records to supply services, communicate, collect payments and provide support. Where the contract is with you personally, the basis is performance of that contract. For another organisation’s representatives, it is our legitimate interest in managing the business relationship and delivering the service.
Accounting and tax: we keep required transaction and business records to comply with our legal obligations, including applicable tax and accounting requirements.
Security, preventing misuse and handling disputes: we use relevant logs, communications and records for our legitimate interests in protecting systems, preventing fraud, investigating problems and establishing, exercising or defending legal claims. Where a specific legal duty applies, we also process what is necessary to comply with that duty.
Relevant business marketing: we may use professional contact details and public business information for our legitimate interest in offering relevant automation services to appropriate corporate business contacts, after considering their reasonable expectations and privacy interests. Where electronic-marketing rules require consent, we rely on valid consent or another applicable permission under those rules before sending. Legitimate interests alone does not override a requirement for consent.
Marketing preferences and objections: we retain the minimum information needed to respect an opt-out and prevent accidental re-contact, to meet our legal duties and our legitimate interest in maintaining an accurate suppression record.
Privacy requests and complaints: we use the information necessary to verify, investigate and respond in compliance with our legal obligations. We may retain a limited record to demonstrate our response and protect legal rights.
Where we rely on legitimate interests, we consider whether our purpose can be achieved in a less intrusive way and balance it against your interests and rights. You can ask about the assessment relevant to your information.
Where we rely on consent, you may withdraw it at any time using the relevant control or our contact details. Withdrawal does not affect processing that was lawful before withdrawal.
You do not have to make an enquiry or provide optional information. If you want us to respond, enter a contract or process a payment, we need the relevant contact, contractual and billing details; without them we may be unable to do so. We identify information required for a particular transaction when collecting it. Information required for statutory accounting or other legal duties must be retained as described below. Optional marketing choices are not a condition of buying our services.
5. Marketing choices
You may object to direct marketing at any time, without giving a reason, by using an unsubscribe option, replying to a message or contacting us. We will stop using your information for direct marketing, including related profiling. Opting out of marketing does not stop necessary messages about an existing contract, payment or security issue.
Public availability of an email address does not automatically mean that its owner has consented to marketing. We distinguish corporate business subscribers from sole traders and other subscribers protected by the electronic-marketing consent rules. A request for information is not blanket consent to unrelated promotions.
We keep a limited suppression record after an opt-out so that deleting a marketing record does not lead to you being added again accidentally.
6. Client data and AI services
Client workflows may involve names, business contacts, resident or customer correspondence, staff information, quotes, orders or invoices. The exact categories, people affected, purpose, access permissions, vendors and retention must be specified for the engagement. Clients should not send production records until the processing arrangements are agreed.
When acting as a processor, we use that information only on documented instructions or as required by applicable law. We do not use it for our own marketing or to train general-purpose AI models. Project-specific AI processing is limited to the agreed purpose and approved providers, with the necessary contractual and transfer safeguards.
An AI service may receive selected inputs and produce outputs in an agreed workflow. Provider retention, access and training settings must be checked before use. Client confidential data will not be submitted through an unapproved consumer AI account. Relevant provider details are supplied to the client in the processing schedule.
We do not make solely automated decisions about individuals that have legal or similarly significant effects as part of the business activities covered by this notice. A client considering such a workflow needs a separate assessment and appropriate notices and safeguards before deployment.
Our website is intended for business contacts, not children. This does not mean that client records can never contain children’s information. Health information, other special-category data, criminal-offence data and children’s information are outside the standard project scope unless specifically assessed and agreed with the necessary legal conditions and safeguards.
7. Who receives information?
We share relevant information only where needed for the purposes described in this notice, with:
- Providers of hosting, business email, file storage, scheduling, electronic signatures, accounting and support systems actually used by the business.
- Approved technical contractors and project providers, subject to appropriate confidentiality and data-processing requirements.
- Stripe and relevant payment-system participants for payment processing, fraud prevention, payment queries and related legal requirements.
- Professional advisers, insurers, authorities or courts where disclosure is necessary and lawful.
- A future operator of the business in the circumstances described in section 12.
Providers processing personal information for us must act under appropriate written processing terms. Some recipients, including professional advisers and Stripe for certain purposes, act as independent controllers with their own legal responsibilities. A provider is not automatically our processor for every activity.
Stripe is our payment provider. When you pay through a Stripe-hosted checkout or payment link, your payment details are entered directly with Stripe. We do not receive or store your full payment-card number or card security code through that setup. We receive information needed to identify and reconcile payments, such as contact and billing details, payment status, transaction references and limited payment-method information. Stripe may collect additional transaction, device and fraud-prevention information. Its role varies by activity, as explained in its Privacy Policy: Stripe Privacy Policy.
Website hosting: Vercel Inc. hosts this website and handles page requests, form submissions and operational logs. This includes technical information such as IP addresses and information you submit through the enquiry form. See the Vercel Privacy Notice.
Enquiry delivery: when form email delivery is enabled, Resend, operated by Plus Five Five, Inc., processes the contact details and message needed to deliver your enquiry to our inbox. Delivery failures may leave a copy in restricted hosting logs. See the Resend Privacy Policy. Business email and file-storage services also handle correspondence and records we need to respond to you or deliver an agreed project.
Providers used inside a client’s operational system are identified in that client’s data-processing schedule. They are agreed for the particular project, rather than automatically receiving website enquiries or client records.
We do not sell personal information, provide it to data brokers or disclose client records for unrelated advertising. A lawful transfer of the operating business is dealt with separately below.
8. International transfers
Our providers operate internationally. Vercel processes website data in the United States and through its global delivery and support infrastructure. Resend processes enquiry emails in the United States when email delivery is enabled. Stripe may process payment information in the United States, India and other countries in its global network. Overseas access can include support as well as server storage.
Vercel’s Privacy Notice describes its participation in the UK Extension to the EU–US Data Privacy Framework for covered transfers. Resend’s Data Processing Addendum provides EU Standard Contractual Clauses with the UK Addendum for relevant UK transfers. Stripe describes its use of adequacy decisions, Standard Contractual Clauses with the UK Addendum and, for eligible transfers to Stripe, LLC, the UK Extension to the Data Privacy Framework in its Privacy Policy.
For client projects, we agree the relevant providers, countries and transfer arrangements in the processing schedule before sharing data. Safeguards depend on the recipient, service and transfer involved; certification does not cover every activity automatically. Contact us for details of the arrangement relevant to your information and how to obtain a copy of applicable safeguards, with confidential information redacted where necessary.
10. How long we keep information
We keep information only for as long as it is reasonably needed for its purpose, including applicable legal requirements. Our standard periods are:
- Unsuccessful enquiries and prospective-client correspondence: up to 12 months after the last meaningful contact, unless you ask us to maintain a relevant ongoing discussion or a separate legal reason requires retention.
- Active marketing records: while the relevant consent or assessed legitimate interest remains valid, with a review at least annually and removal of stale contacts normally after 12 months without meaningful engagement.
- Opt-out records: the minimum identifier and objection details for as long as needed to ensure the objection continues to be respected. These records are not used to send marketing.
- Contracts, acceptance records and essential project or dispute correspondence: normally six years after the relevant contract ends or the matter is closed, where necessary to establish or defend legal rights. This is a business retention choice, not a rule that every project file must be kept for six years.
- Sole-trader tax and accounting records: at least five years after the 31 January filing deadline for the relevant tax year, and longer where a legal requirement or an ongoing enquiry requires it.
- Website runtime logs: Vercel’s current Hobby plan makes these available for one hour. If we retain a relevant incident record separately, we keep it only as long as needed to investigate, resolve the issue or meet a legal obligation.
- Email-delivery records: when Resend is enabled, its standard email retention is 30 days. Copies in our business inbox follow the enquiry or customer-record periods above. Stripe keeps payment records under its own legal and regulatory retention requirements, as described in its Privacy Policy.
- Personal data processed for clients: for the period and return or deletion process in the client’s written instructions and data-processing agreement; it is not automatically kept for the business-record periods above.
We may retain a limited, relevant record for longer where there is a genuine ongoing dispute, legal hold or statutory obligation. Access is restricted and the need for retention is reviewed. When information is no longer needed, we delete it or make it anonymous so that it no longer identifies a person. Replacing names with codes alone does not make information anonymous.
Residual copies may remain in recovery backups until the relevant backup expires or is overwritten. The period depends on the system’s recovery cycle and applicable legal requirements. These copies are restricted to recovery purposes; if a backup is restored, applicable deletion requests must be reapplied before records return to ordinary use. Client backup and deletion arrangements are set in the project’s data-processing agreement.
11. Security, your rights and complaints
We use technical and organisational measures appropriate to the information and risk. No system can guarantee absolute security. This does not remove our duty to apply appropriate safeguards or respond to an incident as required by law. If a breach requires notification to an affected person or regulator, we will make the required notification; when acting as a processor, we notify the relevant client without undue delay.
Subject to the applicable conditions and exemptions, you can request access to your information, correction, erasure, restriction, or portability; object to processing based on legitimate interests; and withdraw consent where processing relies on consent. The right to object to direct marketing is absolute. These rights do not always require deletion of records we must lawfully keep.
Contact support@londonai.company to exercise a right. You do not need to use a particular form or legal wording. We may ask for proportionate information to verify identity or authority. Requests are normally free. We respond without undue delay and ordinarily within one calendar month; any permitted extension, pause or fee will be explained and used only where the law allows.
Where the request concerns information we process for a client, we will direct it to the appropriate controller and assist as required. We will not use that arrangement to avoid responding to a request about information for which we are controller.
To raise a data-protection complaint, email support@londonai.company or write to our address above with a description of the concern. We accept complaints through other reasonable contact methods too. We acknowledge complaints within 30 days, investigate without undue delay, keep you informed and explain the outcome without undue delay. The complaint process does not replace the separate deadline for a rights request.
You can also complain to the Information Commissioner’s Office, the UK data-protection regulator, through https://ico.org.uk/make-a-complaint/. We encourage you to contact us first so that we can try to resolve the issue, but this does not prevent you from contacting the ICO or exercising your legal rights.
12. Changes to the business or this notice
London AI Company may later be operated by an incorporated company. If that happens, we will assess the lawful basis and safeguards for any transfer of personal information, identify the new controller where applicable and provide the information required by law. Client processing arrangements and authorisations will be updated where necessary.
The new operator may receive records reasonably necessary to continue the business for the relevant existing purposes, subject to the applicable legal requirements. We may retain limited records needed to meet our own tax, legal or dispute obligations and remain responsible for that retained information. This notice does not itself transfer a customer contract or release any person from existing liability.
We may update this notice as the business, tools or law change. We will show the new effective date and provide notice of material changes where required. If a new use requires consent or another legal step, publishing a revised policy is not a substitute for that step.