Privacy policy
How AIxprt collects, uses and protects personal data. Written in plain English; the short version is that we collect what we need to reply to you and to do the work, and nothing else.
1. Who we are
This policy is issued by AIxprt.ai (company number 00000000), registered office registered address, United Kingdom ("AIxprt", "we", "us"). For the purposes of UK data protection law we are the controller of the personal data described here. Contact: hello@aixprt.ai.
2. What we collect
We keep this deliberately small.
| When | What | Why |
|---|---|---|
| You contact us or request an audit | Name, work email, website, what you sell, market, your message | To reply and to prepare the audit you asked for |
| You become a client | Business contact details, access you grant to your website, analytics, store and search tools, invoices | To deliver the service and to bill you |
| You visit aixprt.ai | Server logs (IP address, browser, pages, timestamps) held by our hosting provider; analytics only if you accept analytics cookies (see Cookies) | Security, performance and understanding what content is useful |
| We prepare an audit or run the service | Public information about your brand, and the answers AI assistants give about your brand — these concern your business, not individuals | The core of what we do |
We do not collect special-category data, and we ask you not to send it to us. We do not buy marketing lists.
3. Lawful basis
- Contract — replying to your enquiry, preparing an audit you requested, and delivering the service.
- Legitimate interests — keeping the site secure, understanding how it is used, and contacting a business that has asked about our services. You can object at any time.
- Consent — analytics cookies, and any marketing email. You can withdraw consent whenever you like.
- Legal obligation — keeping accounting records.
4. How long we keep it
- Enquiries and audit requests: 12 months after our last contact, unless you become a client.
- Client records: for the length of the engagement and 6 years afterwards (UK accounting rules).
- Access credentials you grant us: revoked when the engagement ends, and we will confirm that in writing.
- Server logs: 30 days.
5. Who we share it with
We do not sell personal data. We share it only with providers who help us run the business, under written terms:
- Vercel — website hosting (US, with EU/UK data-transfer safeguards).
- Google — fonts served on this site, and Workspace email.
- Our engineering and delivery partner (India) — processes client business data on our instructions under a data-processing agreement, with the UK International Data Transfer Addendum in place.
- Accounting, payment and CRM tools we name in your engagement letter.
Where data leaves the UK or EEA we rely on the UK International Data Transfer Agreement/Addendum or an adequacy decision.
6. Your rights
Under UK GDPR you can ask us to: access the data we hold about you; correct it; delete it; restrict or object to how we use it; and receive a copy in a portable format. Email hello@aixprt.ai and we will respond within one month. You can also complain to the Information Commissioner's Office at ico.org.uk, though we'd appreciate the chance to fix things first.
7. Security
Access to client systems is granted by you, scoped to what the work needs, stored in a password manager with two-factor authentication, and revoked at the end of the engagement. Our dashboard is served over HTTPS with per-client logins.
8. Changes
If we change this policy in a way that matters, we will note the date at the top and, for clients, tell you by email. Questions: hello@aixprt.ai.