Skip to main content
Legal

Privacy Policy

Last updated: 2 September 2026

Draft pending legal review. This policy is written to the requirements of the EU GDPR, the UK GDPR and the US state privacy statutes, and it accurately describes what this website does today. It has not been reviewed by a qualified adviser, and the items in [square brackets] must be completed before publication. Aigenflow AI does not claim certification under GDPR, SOC 2, ISO 27001, HIPAA or PCI DSS — this document describes practices, not certification.

The short version

  • This website has one form. We only get what you type into it.
  • We use it to reply to you. That is all.
  • We set no cookies and run no analytics or advertising trackers.
  • We have never sold or shared personal data, and we do not.
  • We do not use your enquiry to train AI models.
  • You can ask us to delete everything we hold about you at any time, by emailing hello@aigenflow.net.

1. Who we are

Aigenflow AI (“we”, “us”) operates the website at aigenflow.net. We are the data controller for the personal data described here — meaning we decide why and how it is processed.

[To complete: registered legal entity name, company registration number, registered address, and the country of establishment.]

[To complete if applicable: if we are established outside the EU or UK but offer services to people in them, GDPR Article 27 / UK GDPR Article 27 requires an appointed representative in the EU and/or UK. Name and address them here, or record advice confirming no representative is required.]

We have not appointed a Data Protection Officer. Our processing is not large-scale, is not systematic monitoring, and does not involve special-category data, so Article 37 does not require one. Privacy questions go to hello@aigenflow.net.

2. What we collect

The website has a single contact form. We receive what you type into it, and nothing else. There is no account system, no tracking, and no profile building.

Personal data collected, why, the legal basis, and how long it is kept
DataWhyLegal basisKept for
NameTo address you correctly in our replyConsent, and our legitimate interest in responding to enquiries24 months from last contact
Email addressTo reply to your enquiryConsent, and our legitimate interest in responding to enquiries24 months from last contact
Company name (optional)To understand the context of your enquiryConsent24 months from last contact
Phone number (optional)To reply by phone if you preferConsent24 months from last contact
Service of interestTo route your enquiry and prepare for the conversationConsent24 months from last contact
Your project descriptionTo understand what you need and whether we can helpConsent, and our legitimate interest in responding to enquiries24 months from last contact
Budget and timeline (optional)To scope realistically before we speakConsent24 months from last contact
IP addressRate limiting, to stop the form being abusedLegitimate interest in protecting the service from abuseHeld in memory only, for up to 10 minutes. Never stored with your enquiry.

We do not collect special-category data (health, race, religion, political opinions, biometrics, sexual orientation, trade union membership) and ask you not to include it in your message. We do not collect government identifiers, financial account details or precise geolocation.

Providing this data is voluntary. It is not a statutory or contractual requirement — but without an email address we cannot reply to you.

3. Why we process it, and our legal basis

We use your enquiry solely to respond to it and, if it leads somewhere, to discuss the work with you. We do not use it for marketing lists, we do not enrich it with data from other sources, and we do not use it to train AI models.

Under the GDPR and UK GDPR we rely on two bases, set out per field in the table above:

  • Consent (Article 6(1)(a)) — you tick the box on the form. You can withdraw it at any time.
  • Legitimate interests (Article 6(1)(f)) — responding to a business enquiry addressed to us, and protecting the form from automated abuse. We have considered your interests and rights against ours: you initiated the contact, the data is minimal and business-related, and the processing is what you would expect. You can object at any time.

4. Cookies and tracking

This website sets no cookies. It uses no local storage for tracking, no analytics, no advertising pixels, no session recording and no fingerprinting. It loads no third-party fonts, scripts or embeds at runtime — the fonts are served from our own domain.

That is why you are not seeing a cookie banner: there is nothing to consent to. If we introduce analytics or any other tracking technology in future, we will publish a cookie policy, update this page, and — where consent is required — ask for it before anything is set.

We honour Global Privacy Control (GPC) signals. Since we do not sell or share personal data or run targeted advertising, there is currently nothing for a GPC signal to switch off, but the commitment stands if that ever changes.

5. Who else sees your data

We do not sell your personal data, rent it, or share it for anyone else’s marketing. The only organisations that receive it are the service providers we use to run the site and reply to you. Each acts as our processor under a written agreement, may only use the data to provide their service, and may not use it for their own purposes.

Service providers that may receive personal data
ProviderWhat they doWhat they receiveStatus
Vercel Inc.United States, with global edge deliveryWebsite hosting and delivery; runs the contact endpointAll traffic, including enquiry contents in transit, and server logsIn use
Resend (Plus Five Five, Inc.)United StatesDelivers enquiry notifications to our inboxThe full contents of your enquiryIn use once configured
Cloudflare, Inc.United States, with global edge processingTurnstile bot check on the contact formYour IP address and a challenge token. No enquiry content.Not currently in use
CRM or automation platformDepends on the platform chosenReceives a copy of enquiries so they can be trackedName, email, company, phone, service, budget, timeline, messageNot currently in use

[To complete: confirm the final list of providers before launch, sign a Data Processing Agreement with each one, and update this table if any is added, removed or replaced.]

We may also disclose personal data where we are legally required to — for example in response to a valid court order — or to establish, exercise or defend legal claims. If the business is ever sold or merged, your data may transfer to the acquirer, and we will tell you before that happens.

6. International transfers

Our providers are based in the United States. If you are in the EEA, the UK or Switzerland, that means your data is transferred outside your jurisdiction.

These transfers are protected by:

  • the EU–US Data Privacy Framework (and its UK Extension and Swiss Extension) where the provider is certified under it, and
  • the European Commission’s Standard Contractual Clauses, with the UK International Data Transfer Addendum where the UK GDPR applies, together with a transfer risk assessment.

You can ask us for a copy of the safeguards that apply to a specific transfer by emailing hello@aigenflow.net.

[To complete: verify each provider’s current DPF certification status and execute SCCs where it does not apply. DPF certification can be checked on the official Data Privacy Framework list and lapses if not renewed.]

7. How long we keep it

We keep enquiry correspondence for 24 months from our last contact with you, then delete it. That period lets us pick up a conversation that resumes months later and keeps a reasonable record of business correspondence, without holding data indefinitely.

If an enquiry becomes a client engagement, the data moves into our client records and is kept for as long as the relationship lasts plus any period required by tax, accounting or limitation law.

Your IP address is used for rate limiting and held in server memory for up to ten minutes. It is never written to storage alongside your enquiry.

[To complete: confirm the 24-month period suits the business, and record how deletion is actually carried out in the email provider and any CRM — a stated retention period that nobody enforces is worse than no statement at all.]

8. How we protect it

The site is served over HTTPS with HTTP Strict Transport Security. Form submissions are validated and rate limited on the server, and input is sanitised before it is used. Credentials for email and any connected service are held server-side and are never exposed to your browser. Access to the enquiry inbox is limited to people who need it.

No system is perfectly secure and we do not claim otherwise. If a breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours where the GDPR requires it, and will tell you directly where the risk is high.

9. Your rights

These rights apply to everyone who contacts us, wherever you live. We extend them globally rather than only to residents of jurisdictions that mandate them.

Rights available to everyone
RightWhat it means
AccessAsk what personal data we hold about you and get a copy.
CorrectionHave inaccurate or incomplete data about you corrected.
DeletionAsk us to delete your data. We will, unless we are legally required to keep it.
PortabilityReceive your data in a structured, machine-readable format.
ObjectionObject to processing based on our legitimate interests.
RestrictionAsk us to pause processing while a dispute about accuracy or basis is resolved.
Withdraw consentWithdraw consent at any time. This does not affect processing that already happened lawfully.
ComplainComplain to your data protection authority. You do not have to contact us first.

How to exercise them: email hello@aigenflow.net. We will respond within one month (GDPR) or 45 days (US state laws), and will tell you if we need an extension and why. There is no charge unless a request is manifestly unfounded or excessive.

Verification: we will usually verify you by replying to the email address the enquiry came from. We will not ask you to create an account or supply identity documents for a routine request. If we genuinely cannot verify you, we will explain why rather than simply refusing.

10. If you are in the EEA, the UK or Switzerland

The GDPR, UK GDPR and Swiss FADP give you the rights listed above, plus the right to lodge a complaint with a supervisory authority in the country where you live, work, or where you think the issue occurred. You do not have to contact us first, though we would prefer the chance to put things right.

  • UK — Information Commissioner’s Office, ico.org.uk
  • EEA — your national data protection authority; the European Data Protection Board publishes the list
  • Switzerland — Federal Data Protection and Information Commissioner

We do not carry out automated decision-making that produces legal or similarly significant effects, so Article 22 does not apply.

11. If you are in the United States

This section applies if you are a resident of a US state with a comprehensive privacy law — including California (CCPA as amended by the CPRA), Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana and other states as their statutes take effect.

What we collect, in statutory terms

In the last 12 months we have collected the following categories of personal information, all of it directly from you through the contact form:

  • Identifiers — name, email address, phone number, IP address
  • Commercial information — company name, service interest, project description, budget and timeline
  • Internet or other electronic network activity — IP address, used transiently for rate limiting

We do not collect biometric information, precise geolocation, government identifiers, financial account information, health information, or any other category of sensitive personal information. Because we collect no sensitive personal information, there is nothing for a “limit the use of my sensitive personal information” request to act on.

Selling and sharing

We do not sell personal information, and we do not share it for cross-context behavioural advertising. We have not done so in the preceding 12 months, and we do not do so with the personal information of minors under 16. That is why you will not find a “Do Not Sell or Share My Personal Information” link on this site — there is nothing to opt out of.

Your rights

  • Know / access — what we collect, why, who receives it, and a copy
  • Delete — subject to legal retention exceptions
  • Correct — inaccurate personal information
  • Opt out — of sale, sharing, targeted advertising and profiling. We do none of these.
  • Non-discrimination — we will never charge you more, give you worse service, or refuse to deal with you because you exercised a right
  • Authorised agent — you may use one; we will ask for proof of their authority

Appeals. If we refuse a request, you may appeal by replying to our decision with the word “appeal”. We will review it and respond within 45 days with a written explanation. If we deny the appeal, we will tell you how to complain to your state Attorney General. Virginia, Colorado, Connecticut and several other states require this route, and we offer it to every US resident.

Notice at collection. The contact form links to this policy, which serves as the notice at or before the point of collection required by the CCPA.

12. Children’s data

This site is a business service and is not directed at children. We do not knowingly collect personal data from anyone under 16, and we have no actual knowledge of having sold or shared the personal information of anyone under 16. If you believe a child has sent us personal data, email hello@aigenflow.net and we will delete it.

13. Automated decisions and AI

Enquiries are read by a person. There is no automated decision-making that produces legal or similarly significant effects, and no profiling.

No AI model is used anywhere on this website. Nothing you type into the contact form is sent to an AI provider, and your enquiry is never used as training data. The services we describe on this site are what we build for clients — they are not features running on this site.

If we add an AI feature here in future, we will update this policy before switching it on and say exactly what it does with your data.

14. Changes to this policy

If we change this policy we will update the date at the top. Where a change materially affects how we use data we already hold, we will contact you directly where we are able to, and — where the law requires it — ask for fresh consent rather than relying on the old one.

15. Contact and complaints

For anything in this policy, including any request about your data, email hello@aigenflow.net.

If you are not satisfied with our response you can complain to your data protection authority or state Attorney General, as set out in sections 10 and 11. You are not required to contact us first.