LEGAL
Privacy Policy
DRAFT — NOT YET LEGALLY REVIEWED
This policy is an accurate description of what the site currently does, but it has not been reviewed by a solicitor and contains placeholders. Have it checked and complete the bracketed fields before relying on it. Remove this notice once that is done.
This policy explains what personal data Neith AI Ltd (“Neith”, “we”, “us”) collects through aineith.com, why we collect it, and what rights you have over it. It covers this website only. It does not cover the Neith product itself, which is governed by the separate agreement we enter into with client institutions.
01Who we are
Neith AI Ltd is the data controller for personal data collected through this website.
| Controller | Neith AI Ltd |
| Registered office | [REGISTERED OFFICE ADDRESS] |
| Company number | [COMPANY NUMBER] |
| ICO registration | [ICO REGISTRATION NUMBER] |
| Contact | hello@aineith.com |
02What we collect
We collect personal data in one situation only: when you voluntarily submit the access request form. That form asks for four fields.
| DATA | WHY WE NEED IT |
|---|---|
| Full name | To address you correctly when we reply |
| Work email | To reply to your request |
| Institution | To confirm the enquiry is from an institution, since Neith is not offered to individuals |
| Role | To route the conversation to the right person and pitch it at the right level |
Our hosting provider also generates standard server logs, which may include your IP address, browser user-agent and the pages requested. These are generated automatically as a byproduct of serving the site and are used only for security and diagnostics.
We do not ask for, and you should not send us, any trade data, client information or other confidential material through this website.
03No cookies, no tracking
PLAIN STATEMENT
This website sets no cookies. It runs no analytics, no advertising pixels, no session recording and no cross-site tracking of any kind. There is no consent banner because there is nothing to consent to.
We think a company selling a control-and-evidence product should be able to say that without qualification, so we have built the site so that we can.
04Our lawful basis
We rely on legitimate interests under Article 6(1)(f) UK GDPR: responding to an unsolicited business enquiry that you initiated, in a business-to-business context, using business contact details you chose to give us.
We have assessed that this does not override your interests or rights, because the data is limited to professional contact details, you supplied it deliberately in order to be contacted, and you can ask us to stop at any time. Server logs are processed on the same basis, for network and information security.
We do not use your details for unrelated marketing, we do not add you to a newsletter, and we do not sell, rent or share your data with anyone for their own purposes.
05Who processes it
We keep the list of third parties deliberately short.
| PROCESSOR | PURPOSE AND LOCATION |
|---|---|
| Formspree | Receives and forwards access request form submissions. United States. Acts as our processor under its data processing terms. |
| [HOSTING PROVIDER] | Serves the website and generates server logs. [HOSTING REGION]. |
| Google Fonts | Serves the two typefaces used on this site from Google's CDN. Loading a font from that CDN transmits your IP address to Google. See section 6. |
We may also disclose personal data where we are required to do so by law, or to establish, exercise or defend legal claims.
06International transfers
Formspree and Google Fonts are located in the United States, so submitting the form or loading the site involves a transfer of personal data outside the UK. Those transfers are made under the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, or another approved transfer mechanism.
If you would rather not have your IP address transmitted to Google's font CDN, you can request the site with fonts blocked; the page is fully readable and functional without them. [OPTIONAL: self-hosting the two typefaces removes this transfer entirely and is a small change.]
07How long we keep it
- Access requests: retained for up to 24 months from your last contact with us, then deleted. If you tell us you are not interested, we delete your details promptly, keeping only a minimal suppression record so we do not contact you again by mistake.
- Server logs: retained for a short operational period, ordinarily no more than 90 days.
08Security
The site is served over TLS. Access request data is accessible only to the small number of people at Neith who need it in order to respond. We apply the same principle here that the product applies to trade data: collect the minimum, keep it only as long as it is useful, and be able to say exactly what happened to it.
09Your rights
Under UK GDPR you have the right to access your personal data, to have inaccurate data corrected, to have your data erased, to restrict or object to our processing of it, and to receive it in a portable format. Where we rely on legitimate interests, you have the right to object at any time.
To exercise any of these, email hello@aineith.com. We will respond within one month. There is no charge.
If you are unhappy with how we have handled your data, you can complain to the Information Commissioner's Office at ico.org.uk/make-a-complaint or on 0303 123 1113. We would appreciate the chance to put it right first.
10Changes to this policy
If we change this policy we will update the version number and date at the top of this page. Material changes affecting people whose data we already hold will be notified by email.
11Contact
Questions about this policy, or about anything else on this site: hello@aineith.com.