Legal

Privacy policy

How AIxprt collects, uses and protects personal data. Written in plain English; the short version is that we collect what we need to reply to you and to do the work, and nothing else.

Last updated 6 September 2026

1. Who we are

This policy is issued by AIxprt.ai (company number 00000000), registered office registered address, United Kingdom ("AIxprt", "we", "us"). For the purposes of UK data protection law we are the controller of the personal data described here. Contact: hello@aixprt.ai.

2. What we collect

We keep this deliberately small.

WhenWhatWhy
You contact us or request an auditName, work email, website, what you sell, market, your messageTo reply and to prepare the audit you asked for
You become a clientBusiness contact details, access you grant to your website, analytics, store and search tools, invoicesTo deliver the service and to bill you
You visit aixprt.aiServer logs (IP address, browser, pages, timestamps) held by our hosting provider; analytics only if you accept analytics cookies (see Cookies)Security, performance and understanding what content is useful
We prepare an audit or run the servicePublic information about your brand, and the answers AI assistants give about your brand — these concern your business, not individualsThe core of what we do

We do not collect special-category data, and we ask you not to send it to us. We do not buy marketing lists.

3. Lawful basis

  • Contract — replying to your enquiry, preparing an audit you requested, and delivering the service.
  • Legitimate interests — keeping the site secure, understanding how it is used, and contacting a business that has asked about our services. You can object at any time.
  • Consent — analytics cookies, and any marketing email. You can withdraw consent whenever you like.
  • Legal obligation — keeping accounting records.

4. How long we keep it

  • Enquiries and audit requests: 12 months after our last contact, unless you become a client.
  • Client records: for the length of the engagement and 6 years afterwards (UK accounting rules).
  • Access credentials you grant us: revoked when the engagement ends, and we will confirm that in writing.
  • Server logs: 30 days.

5. Who we share it with

We do not sell personal data. We share it only with providers who help us run the business, under written terms:

  • Vercel — website hosting (US, with EU/UK data-transfer safeguards).
  • Google — fonts served on this site, and Workspace email.
  • Our engineering and delivery partner (India) — processes client business data on our instructions under a data-processing agreement, with the UK International Data Transfer Addendum in place.
  • Accounting, payment and CRM tools we name in your engagement letter.

Where data leaves the UK or EEA we rely on the UK International Data Transfer Agreement/Addendum or an adequacy decision.

6. Your rights

Under UK GDPR you can ask us to: access the data we hold about you; correct it; delete it; restrict or object to how we use it; and receive a copy in a portable format. Email hello@aixprt.ai and we will respond within one month. You can also complain to the Information Commissioner's Office at ico.org.uk, though we'd appreciate the chance to fix things first.

7. Security

Access to client systems is granted by you, scoped to what the work needs, stored in a password manager with two-factor authentication, and revoked at the end of the engagement. Our dashboard is served over HTTPS with per-client logins.

8. Changes

If we change this policy in a way that matters, we will note the date at the top and, for clients, tell you by email. Questions: hello@aixprt.ai.