Privacy Policy
This privacy policy explains what personal information Software and AI Services Ltd (“we”, “us”, “our”) collects, why we collect it, what we do with it, and the rights you have under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
We are the data controller for the information described below. If you have any questions or want to exercise your rights, please contact us at privacy@softwareandaiservices.co.uk.
Information we collect
We collect personal information from you in three main ways:
- When you contact us — via our contact form, by email, phone or messaging. We collect your name, email address, and any phone number, company name and message content you choose to provide.
- When we work together — as a client, contractor or supplier. We collect the professional contact details, project information and any correspondence needed to deliver the engagement, and where relevant, billing information.
- When you visit this website — a small amount of technical information is collected automatically, such as your device type, browser, approximate location (from your IP address) and the pages you visit, as described in our Cookie Policy.
Lawful basis for processing
We only process your personal data where we have a lawful basis under UK GDPR Article 6:
- Consent — for non-essential cookies and any direct marketing (see our Cookie Policy).
- Contract — where processing is necessary to enter into or perform a contract with you or your organisation.
- Legitimate interests — for responding to enquiries, running and improving our business, and keeping our systems secure. We balance these interests against your rights and freedoms.
- Legal obligation — where we are required by law to keep records (for example, accounting and tax obligations).
How we use your information
- To reply to enquiries and discuss potential work.
- To deliver services under a contract with you or your organisation.
- To send project-related communication, invoices and administrative correspondence.
- To keep our website, systems and data secure and to detect misuse.
- To comply with our legal and regulatory obligations.
We do not sell your personal information to anyone, and we do not use it for automated decision-making that has a significant effect on you.
Who we share your information with
We share personal data only with the following categories of recipients, and only where necessary:
- Service providers we use to run our business — for example, hosting providers (Heart Internet), cloud infrastructure (AWS), issue tracking and support tooling (Atlassian), email and productivity tools, payment providers, and professional advisors (accountants, solicitors). Each acts as a processor or independent controller under a written agreement.
- Regulators, law enforcement or courts where we are required to by law.
- A successor entity in the event of a sale, merger or restructuring of our business, subject to appropriate confidentiality and data-protection obligations.
International transfers
Some of our service providers process personal data outside the UK. Where they do, we rely on UK-recognised transfer mechanisms — such as UK Adequacy Regulations, the UK Addendum to the EU Standard Contractual Clauses, or the UK International Data Transfer Agreement — to keep your data protected to UK standards.
How long we keep it
We keep personal data only for as long as we need it:
- Enquiries that do not lead to work: up to 24 months, then deleted.
- Client and project records: for the duration of the engagement and for a further 6 years to meet legal, accounting and tax obligations.
- Website analytics and logs: retained only for the period described in our Cookie Policy.
When the retention period expires, we securely delete or anonymise the data.
How we protect your information
We operate our systems in line with our Information Security Policy, which is aligned to ISO/IEC 27001 principles. Measures include encryption in transit (TLS), encryption at rest for sensitive stores, role-based access control, principle of least privilege, immutable audit logging on regulated systems, and formal incident response.
Your rights
Under UK GDPR you have the right to:
- Be informed about how we use your data (this policy).
- Access a copy of the personal data we hold about you.
- Rectify data that is inaccurate or incomplete.
- Erase your data (“right to be forgotten”) where the legal basis for holding it no longer applies.
- Restrict or object to processing.
- Data portability — receive your data in a portable format.
- Withdraw consent at any time, where consent is the lawful basis.
- Complain to the Information Commissioner’s Office (ICO) at ico.org.uk or 0303 123 1113.
To exercise any of these rights, email privacy@softwareandaiservices.co.uk. We will respond within one month of receiving a valid request.
Changes to this policy
We may update this policy from time to time. The “last updated” date at the bottom of this page always reflects the most recent version. Material changes will be flagged on our website.
Software and AI Services Ltd is registered in Northern Ireland, company number NI732919. Registered office: 98 Larne Road, Ballyclare, Northern Ireland, BT39 9UD. Policy last updated: August 2026.