Privacy Policy
Last updated: 2 September 2026
The short version
- This website has one form. We only get what you type into it.
- We use it to reply to you. That is all.
- We set no cookies and run no analytics or advertising trackers.
- We have never sold or shared personal data, and we do not.
- We do not use your enquiry to train AI models.
- You can ask us to delete everything we hold about you at any time, by emailing hello@aigenflow.net.
1. Who we are
Aigenflow AI (“we”, “us”) operates the website at aigenflow.net. We are the data controller for the personal data described here — meaning we decide why and how it is processed.
[To complete: registered legal entity name, company registration number, registered address, and the country of establishment.]
[To complete if applicable: if we are established outside the EU or UK but offer services to people in them, GDPR Article 27 / UK GDPR Article 27 requires an appointed representative in the EU and/or UK. Name and address them here, or record advice confirming no representative is required.]
We have not appointed a Data Protection Officer. Our processing is not large-scale, is not systematic monitoring, and does not involve special-category data, so Article 37 does not require one. Privacy questions go to hello@aigenflow.net.
2. What we collect
The website has a single contact form. We receive what you type into it, and nothing else. There is no account system, no tracking, and no profile building.
| Data | Why | Legal basis | Kept for |
|---|---|---|---|
| Name | To address you correctly in our reply | Consent, and our legitimate interest in responding to enquiries | 24 months from last contact |
| Email address | To reply to your enquiry | Consent, and our legitimate interest in responding to enquiries | 24 months from last contact |
| Company name (optional) | To understand the context of your enquiry | Consent | 24 months from last contact |
| Phone number (optional) | To reply by phone if you prefer | Consent | 24 months from last contact |
| Service of interest | To route your enquiry and prepare for the conversation | Consent | 24 months from last contact |
| Your project description | To understand what you need and whether we can help | Consent, and our legitimate interest in responding to enquiries | 24 months from last contact |
| Budget and timeline (optional) | To scope realistically before we speak | Consent | 24 months from last contact |
| IP address | Rate limiting, to stop the form being abused | Legitimate interest in protecting the service from abuse | Held in memory only, for up to 10 minutes. Never stored with your enquiry. |
We do not collect special-category data (health, race, religion, political opinions, biometrics, sexual orientation, trade union membership) and ask you not to include it in your message. We do not collect government identifiers, financial account details or precise geolocation.
Providing this data is voluntary. It is not a statutory or contractual requirement — but without an email address we cannot reply to you.
3. Why we process it, and our legal basis
We use your enquiry solely to respond to it and, if it leads somewhere, to discuss the work with you. We do not use it for marketing lists, we do not enrich it with data from other sources, and we do not use it to train AI models.
Under the GDPR and UK GDPR we rely on two bases, set out per field in the table above:
- Consent (Article 6(1)(a)) — you tick the box on the form. You can withdraw it at any time.
- Legitimate interests (Article 6(1)(f)) — responding to a business enquiry addressed to us, and protecting the form from automated abuse. We have considered your interests and rights against ours: you initiated the contact, the data is minimal and business-related, and the processing is what you would expect. You can object at any time.
4. Cookies and tracking
This website sets no cookies. It uses no local storage for tracking, no analytics, no advertising pixels, no session recording and no fingerprinting. It loads no third-party fonts, scripts or embeds at runtime — the fonts are served from our own domain.
That is why you are not seeing a cookie banner: there is nothing to consent to. If we introduce analytics or any other tracking technology in future, we will publish a cookie policy, update this page, and — where consent is required — ask for it before anything is set.
We honour Global Privacy Control (GPC) signals. Since we do not sell or share personal data or run targeted advertising, there is currently nothing for a GPC signal to switch off, but the commitment stands if that ever changes.
5. Who else sees your data
We do not sell your personal data, rent it, or share it for anyone else’s marketing. The only organisations that receive it are the service providers we use to run the site and reply to you. Each acts as our processor under a written agreement, may only use the data to provide their service, and may not use it for their own purposes.
| Provider | What they do | What they receive | Status |
|---|---|---|---|
| Vercel Inc.United States, with global edge delivery | Website hosting and delivery; runs the contact endpoint | All traffic, including enquiry contents in transit, and server logs | In use |
| Resend (Plus Five Five, Inc.)United States | Delivers enquiry notifications to our inbox | The full contents of your enquiry | In use once configured |
| Cloudflare, Inc.United States, with global edge processing | Turnstile bot check on the contact form | Your IP address and a challenge token. No enquiry content. | Not currently in use |
| CRM or automation platformDepends on the platform chosen | Receives a copy of enquiries so they can be tracked | Name, email, company, phone, service, budget, timeline, message | Not currently in use |
[To complete: confirm the final list of providers before launch, sign a Data Processing Agreement with each one, and update this table if any is added, removed or replaced.]
We may also disclose personal data where we are legally required to — for example in response to a valid court order — or to establish, exercise or defend legal claims. If the business is ever sold or merged, your data may transfer to the acquirer, and we will tell you before that happens.
6. International transfers
Our providers are based in the United States. If you are in the EEA, the UK or Switzerland, that means your data is transferred outside your jurisdiction.
These transfers are protected by:
- the EU–US Data Privacy Framework (and its UK Extension and Swiss Extension) where the provider is certified under it, and
- the European Commission’s Standard Contractual Clauses, with the UK International Data Transfer Addendum where the UK GDPR applies, together with a transfer risk assessment.
You can ask us for a copy of the safeguards that apply to a specific transfer by emailing hello@aigenflow.net.
[To complete: verify each provider’s current DPF certification status and execute SCCs where it does not apply. DPF certification can be checked on the official Data Privacy Framework list and lapses if not renewed.]
7. How long we keep it
We keep enquiry correspondence for 24 months from our last contact with you, then delete it. That period lets us pick up a conversation that resumes months later and keeps a reasonable record of business correspondence, without holding data indefinitely.
If an enquiry becomes a client engagement, the data moves into our client records and is kept for as long as the relationship lasts plus any period required by tax, accounting or limitation law.
Your IP address is used for rate limiting and held in server memory for up to ten minutes. It is never written to storage alongside your enquiry.
[To complete: confirm the 24-month period suits the business, and record how deletion is actually carried out in the email provider and any CRM — a stated retention period that nobody enforces is worse than no statement at all.]
8. How we protect it
The site is served over HTTPS with HTTP Strict Transport Security. Form submissions are validated and rate limited on the server, and input is sanitised before it is used. Credentials for email and any connected service are held server-side and are never exposed to your browser. Access to the enquiry inbox is limited to people who need it.
No system is perfectly secure and we do not claim otherwise. If a breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours where the GDPR requires it, and will tell you directly where the risk is high.
9. Your rights
These rights apply to everyone who contacts us, wherever you live. We extend them globally rather than only to residents of jurisdictions that mandate them.
| Right | What it means |
|---|---|
| Access | Ask what personal data we hold about you and get a copy. |
| Correction | Have inaccurate or incomplete data about you corrected. |
| Deletion | Ask us to delete your data. We will, unless we are legally required to keep it. |
| Portability | Receive your data in a structured, machine-readable format. |
| Objection | Object to processing based on our legitimate interests. |
| Restriction | Ask us to pause processing while a dispute about accuracy or basis is resolved. |
| Withdraw consent | Withdraw consent at any time. This does not affect processing that already happened lawfully. |
| Complain | Complain to your data protection authority. You do not have to contact us first. |
How to exercise them: email hello@aigenflow.net. We will respond within one month (GDPR) or 45 days (US state laws), and will tell you if we need an extension and why. There is no charge unless a request is manifestly unfounded or excessive.
Verification: we will usually verify you by replying to the email address the enquiry came from. We will not ask you to create an account or supply identity documents for a routine request. If we genuinely cannot verify you, we will explain why rather than simply refusing.
10. If you are in the EEA, the UK or Switzerland
The GDPR, UK GDPR and Swiss FADP give you the rights listed above, plus the right to lodge a complaint with a supervisory authority in the country where you live, work, or where you think the issue occurred. You do not have to contact us first, though we would prefer the chance to put things right.
- UK — Information Commissioner’s Office, ico.org.uk
- EEA — your national data protection authority; the European Data Protection Board publishes the list
- Switzerland — Federal Data Protection and Information Commissioner
We do not carry out automated decision-making that produces legal or similarly significant effects, so Article 22 does not apply.
11. If you are in the United States
This section applies if you are a resident of a US state with a comprehensive privacy law — including California (CCPA as amended by the CPRA), Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana and other states as their statutes take effect.
What we collect, in statutory terms
In the last 12 months we have collected the following categories of personal information, all of it directly from you through the contact form:
- Identifiers — name, email address, phone number, IP address
- Commercial information — company name, service interest, project description, budget and timeline
- Internet or other electronic network activity — IP address, used transiently for rate limiting
We do not collect biometric information, precise geolocation, government identifiers, financial account information, health information, or any other category of sensitive personal information. Because we collect no sensitive personal information, there is nothing for a “limit the use of my sensitive personal information” request to act on.
Selling and sharing
We do not sell personal information, and we do not share it for cross-context behavioural advertising. We have not done so in the preceding 12 months, and we do not do so with the personal information of minors under 16. That is why you will not find a “Do Not Sell or Share My Personal Information” link on this site — there is nothing to opt out of.
Your rights
- Know / access — what we collect, why, who receives it, and a copy
- Delete — subject to legal retention exceptions
- Correct — inaccurate personal information
- Opt out — of sale, sharing, targeted advertising and profiling. We do none of these.
- Non-discrimination — we will never charge you more, give you worse service, or refuse to deal with you because you exercised a right
- Authorised agent — you may use one; we will ask for proof of their authority
Appeals. If we refuse a request, you may appeal by replying to our decision with the word “appeal”. We will review it and respond within 45 days with a written explanation. If we deny the appeal, we will tell you how to complain to your state Attorney General. Virginia, Colorado, Connecticut and several other states require this route, and we offer it to every US resident.
Notice at collection. The contact form links to this policy, which serves as the notice at or before the point of collection required by the CCPA.
12. Children’s data
This site is a business service and is not directed at children. We do not knowingly collect personal data from anyone under 16, and we have no actual knowledge of having sold or shared the personal information of anyone under 16. If you believe a child has sent us personal data, email hello@aigenflow.net and we will delete it.
13. Automated decisions and AI
Enquiries are read by a person. There is no automated decision-making that produces legal or similarly significant effects, and no profiling.
No AI model is used anywhere on this website. Nothing you type into the contact form is sent to an AI provider, and your enquiry is never used as training data. The services we describe on this site are what we build for clients — they are not features running on this site.
If we add an AI feature here in future, we will update this policy before switching it on and say exactly what it does with your data.
14. Changes to this policy
If we change this policy we will update the date at the top. Where a change materially affects how we use data we already hold, we will contact you directly where we are able to, and — where the law requires it — ask for fresh consent rather than relying on the old one.
15. Contact and complaints
For anything in this policy, including any request about your data, email hello@aigenflow.net.
If you are not satisfied with our response you can complain to your data protection authority or state Attorney General, as set out in sections 10 and 11. You are not required to contact us first.