Privacy Policy
This privacy notice explains how IntegriAI Limited (“we”, “us”, or “our”) uses and protects your personal data. We are committed to protecting your privacy, maintaining transparency, and ensuring your data is processed securely and lawfully.
You can contact our voluntarily appointed Data Protection Officer at privacy@integriai.co.uk if you have any concerns or wish to exercise your data protection rights.
If you prefer, you can write to us at:
IntegriAI Limited
86-90 Paul Street, London, EC2A 4NE
If you are an EU data subject, you can contact our EU Representative at eurep@fifthsquare.eu. Our EU Representative complies with obligations under GDPR Article 27 and is established in the Republic of Ireland. Please note that this is a third-party representative who will process your data solely for compliance purposes.
Our Promises
At IntegriAI, we recognise that your personal data belongs to you — not us. As such, we make the following commitments:
- We will always be transparent and open about how we collect, use, and store your personal data.
- We only collect data that is relevant and necessary for our stated business purposes.
- Your data will only be stored on secure systems that meet recognised compliance and security standards.
- We respect your rights as outlined below and will respond to all data protection requests promptly.
- Any third parties we share data with are legally required to protect it and use it only for legitimate business purposes.
- We only process or share your data where we have a lawful basis to do so — such as fulfilling our contractual obligations, legitimate business interests, or compliance with legal requirements.
Your Rights
You have the following rights under data protection law:
- Access – Request a copy of the personal information we hold about you.
- Rectification – Ask us to correct or update personal data that is inaccurate or incomplete.
- Erasure – Request that we delete personal data we hold about you (“right to be forgotten”).
- Restriction – Ask us to restrict how we process your personal data.
- Objection – Object to our processing of your personal data, including for direct marketing purposes.
- Portability – Request that we transfer your personal data to another controller, where technically feasible.
- Withdrawal of Consent – Withdraw consent where processing is based on your consent.
If you wish to exercise any of these rights, contact us at privacy@integriai.co.uk.
If you are dissatisfied with our response, you have the right to lodge a complaint with the Information Commissioner’s Office (ICO): https://ico.org.uk/concerns/
How We Collect Your Data
We collect data in several ways, including:
- Access – Request a copy of the personal information we hold about you.
- Through our services: when we deliver AI governance, advisory, or technology solutions to clients.
- Referrals or business relationships: through our network, partners, or resellers.
- Public sources: including publicly available company or regulatory data relevant to AI governance, compliance, or technology.
What Data We Collect
Depending on your relationship with IntegriAI, we may collect:
- Personal contact details: name, email address, phone number, job title, organisation, and country.
- Professional details: your role, company, or industry interests related to AI governance or technology.
- Communications: emails, call notes, meeting summaries, or other correspondence.
- Usage data: analytics on how you use our website, forms, or digital services (via cookies or tracking technologies).
We aim to minimise the data we collect and retain only what is necessary for our services or legal obligations.
How We Process and Store Your Data
Data is securely processed and stored on encrypted cloud services, including Microsoft Azure, Microsoft 365, and HubSpot. These services meet international compliance standards such as ISO 27001, SOC 2, and GDPR adequacy requirements.
We may use Large Language Models (LLMs) or AI tools to help us analyse anonymised or pseudonymised data for service improvement and automation.
Your data may be processed in the UK, EEA, or other jurisdictions with adequate data protection safeguards. Where data is transferred outside the UK or EEA, we ensure protection through International Data Transfer Agreements (IDTAs), Addendums, or Standard Contractual Clauses (SCCs).
Legal Basis for Processing
We process your data under one or more of the following legal bases:
- Contractual Obligation – to perform a contract with you or your employer.
- Legitimate Interest – to develop and promote our AI governance, advisory, and technology services responsibly.
- Legal Obligation – to comply with applicable laws and regulations.
- Consent – where you have explicitly agreed to receive marketing or participate in surveys.
Third Parties and Data Sharing
We may share your personal data with trusted partners, service providers, or subcontractors who assist us in delivering our services. These include:
- Marketing and analytics platforms (e.g., HubSpot).
- Cloud and IT infrastructure providers (e.g., Microsoft).
- External consultants or auditors bound by confidentiality agreements.
We do not sell your personal data to third parties.
Our website may include links to external sites or social media platforms. We are not responsible for the privacy practices of those sites.
In the event of a merger, acquisition, or asset sale, your personal data may be transferred in accordance with data protection law, and you will be notified beforehand.
Data Retention
We retain personal data only as long as necessary for the purpose it was collected. Typical retention periods are:
- Prospect or marketing data: 36 months from last interaction.
- Client data: 36 months after service completion.
- Supplier or partner data: 36 months after last contact.
Data is reviewed annually each October to ensure accuracy and necessity.
Marketing and Communications
Every marketing email we send includes an unsubscribe option. You may also contact us at privacy@integriai.co to:
- Opt out of marketing communications
- Request access or deletion of your data
When data is deleted, we retain a minimal record (name and email) on a suppression list to ensure no further contact.
Legal Compliance
We comply with the UK Data Protection Act 2018, UK GDPR, and the EU GDPR where applicable. Our supervisory authority is the Information Commissioner’s Office (ICO) in the UK.
Due to our international work, we cannot guarantee compliance with every local law outside the UK, but we strive to uphold global best practices in data protection and AI governance.
This Privacy Policy is reviewed regularly and was last updated in October 2025.
The most current version will always be available at www.integriai.co/privacy.