Privacy Policy
Last updated 11 August 2026
A plain-English draft for early access — please have it reviewed by a solicitor / DPO before launch. This policy explains how we handle personal data about you and your Users. Where you feed us other people's personal data, you are the controller and we are your processor — see the DPA.
1. Who we are
DigitAIse is operated by AIME TECH UK LIMITED, England & Wales. We are the data controller for account and usage data. Contact / data requests: [email protected].
2. What we collect, why, and our lawful basis
| Data | Why | Lawful basis (UK GDPR) |
|---|---|---|
| Account: name, email, business name, hashed password | Create and run your account, authenticate, support | Contract |
| Content you upload or connect: documents (from which we extract transactions, suppliers, line-items and detect/flag personal data such as emails, phone numbers, IBANs), emails, calendar, reviews, social mentions, chat and voice content | To deliver the agents you enable | Contract |
| Connected-account tokens (Google/Microsoft/social), stored encrypted | To act on the sources you authorise | Contract / consent |
| Usage & technical: logs, AI-token metering, IP address | Run, secure and bill the Service; prevent abuse | Legitimate interests / legal obligation |
| Payment: billing details (card handled by Stripe — we do not store card numbers) | Take payment | Contract |
3. AI processing
To generate agent outputs, relevant content is sent to our AI provider (Anthropic) for that request. Document search uses embeddings generated on our own servers. AI-generated content is marked/disclosed. We do not sell your data or use your Customer Data to train third-party foundation models.
4. Where your data is hosted
Your data is hosted in the United Kingdom (data centre in London). Each customer's data lives in an isolated per-tenant database schema, with sensitive fields encrypted using a per-tenant key. Traffic is protected in transit (TLS) and routed via Cloudflare.
5. Sub-processors
We use the following providers to deliver the Service:
| Provider | Purpose |
|---|---|
| Anthropic | AI models (generating agent outputs) |
| Stripe | Payments & card processing |
| Brevo (Sendinblue) | Transactional & agent email delivery |
| Twilio | Voice (Aria) telephony |
| Meta | WhatsApp messaging (when enabled) |
| Cloudflare | Edge network / DDoS protection |
| OVHcloud | UK hosting infrastructure |
Some providers may process data outside the UK; where they do, appropriate safeguards (UK adequacy or standard contractual clauses) apply.
6. Retention
We keep Customer Data for as long as your account is active. On account deletion (or on request) we permanently remove your tenant's data and its uploaded files. Some limited records (e.g. billing, audit and security logs) may be retained for a longer period where required by law.
7. Your rights
Under UK GDPR you have the right to access, rectify, erase, restrict, object to, and port your personal data, and to withdraw consent. You can review and export much of your data from the in-app "My data" ledger, or contact us at [email protected]. You can also complain to the UK Information Commissioner's Office (ICO) at ico.org.uk.
8. Security
We use per-tenant isolation, encryption of sensitive data at rest and in transit, access controls, uploaded-file scanning, and audit logging. No system is perfectly secure, but we design for breach resistance and will notify you of a personal data breach as required by law.
9. Cookies
We use strictly-necessary cookies to keep you signed in and secure. We do not use advertising cookies.
10. Children
The Service is for business use and not directed at anyone under 18.
11. Changes & contact
We may update this policy and will post the new version here. Questions or requests: [email protected].
← Back to home · Terms · DPA