Trust, transparency and control

Privacy should beunderstood—not assumed.

This notice explains what personal information SafetyOfAI Limited may collect, why we use it, how we protect it and the choices available to you.

Effective 30 July 2026UK GDPR alignedVersion 1.0
Read the policy
Data stewardship vault Protected state
Collect MinimallyUse LawfullyProtect Deliberately

Privacy at a glance

Four commitments govern how we handle information.

01

Purpose limited

We use personal information only for clear, stated business purposes.

02

Data minimised

We ask only for information reasonably needed to respond or work with you.

03

Human accountable

We do not use this website to make solely automated decisions about people.

04

Rights respected

You can ask about your information or raise a concern directly with us.

01

Who we are

SafetyOfAI Limited is responsible for this website.

SafetyOfAI Limited is the data controller for personal information covered by this notice. This means we decide why and how that information is used.

We are a UK company based in Nottingham. This notice applies to visitors to this website, people who contact us, prospective clients, clients and professional contacts. It does not replace any more specific privacy terms provided as part of a client engagement.

Privacy contactSafetyOfAI Limited

Nottingham · United Kingdom

hello@safetyofai.com
02

What we collect

We collect information in proportion to the relationship.

Depending on how you interact with us, this may include:

  • Identity

    Your name, role and organisation.

  • Contact

    Your business email address, telephone number and correspondence preferences.

  • Enquiry

    Information you choose to include when contacting us or requesting a conversation.

  • Engagement

    Records needed to scope, manage or deliver an agreed service.

  • Technical

    Basic device, browser, IP, request and security information generated when this website is accessed.

Please do not send special category information, confidential employee information or sensitive operational data through a general website enquiry. Where an engagement requires sensitive material, we will establish an appropriate and controlled route.

03

Purposes and lawful bases

Every use must have a purpose and a lawful basis.

We use personal information only where data protection law allows us to do so. The basis depends on the purpose and context.

InformationWhy we use itLawful basis
Enquiry and contact information

To respond to questions, arrange conversations and understand potential requirements.

Legitimate interests; or steps requested before entering a contract.

Client and engagement information

To scope, deliver and administer SafetyOfAI services, including HDRS-related work.

Contract; legitimate interests; and legal obligation where applicable.

Business relationship records

To maintain professional relationships, follow up requested discussions and keep accurate records.

Legitimate interests.

Technical and security information

To operate, protect and understand the performance of this website.

Legitimate interests in service reliability, security and fraud prevention.

Marketing preferences

To send updates or briefings where requested or otherwise lawfully permitted.

Consent or legitimate interests, subject to applicable electronic marketing rules.

No website profiling

We do not use this website to make decisions that produce legal or similarly significant effects through solely automated processing. We do not sell personal information.

04

Sharing and international transfers

Access is limited to what is necessary.

We may share information with carefully selected service providers that support hosting, security, communications, professional advice or business administration. They may use the information only for the agreed purpose and under appropriate confidentiality and data protection obligations.

We may also disclose information where required by law, to protect legal rights, or in connection with a genuine corporate transaction subject to appropriate safeguards.

Some providers may process information outside the United Kingdom. Where this occurs, we use an applicable lawful transfer mechanism and assess appropriate protection, such as UK adequacy regulations or approved contractual safeguards.

05

Retention and security

We keep information only for as long as it remains justified.

Retention depends on the nature of the information, the relationship, legal requirements and whether it may be needed to establish, exercise or defend legal claims.

General enquiriesUp to 24 months

Unless a relationship develops or earlier deletion is appropriate.

Client recordsNormally 7 years

After the relevant engagement, where required for contractual, tax or legal records.

Marketing preferencesUntil withdrawn

With limited suppression information retained where needed to honour an objection.

Security recordsRisk dependent

For the shortest period reasonably needed to maintain and investigate service security.

We use proportionate technical and organisational measures intended to protect information against accidental loss, unauthorised access, alteration or disclosure. No method of transmission or storage is completely secure, so protection is continuously reviewed rather than treated as a guarantee.

06

Your information rights

You remain entitled to understand and challenge our use.

Depending on the circumstances, UK data protection law provides the following rights. They are not all absolute, and we may need to verify your identity before responding.

01

Access

Ask for a copy of personal information we hold about you.

02

Correction

Ask us to correct information that is inaccurate or incomplete.

03

Erasure

Ask us to delete information where there is no lawful reason to retain it.

04

Restriction

Ask us to limit how we use information in certain circumstances.

05

Objection

Object to processing based on legitimate interests or direct marketing.

06

Portability

Receive certain information in a structured, commonly used format.

07

Withdraw consent

Withdraw consent at any time where consent is our lawful basis.

To exercise a right, email hello@safetyofai.com. We normally respond within one month, subject to the extensions and exemptions permitted by law.

07

Cookies and similar technologies

We do not treat silence as consent.

This website may use strictly necessary storage or access technologies required for security, authentication, load balancing or core operation. These do not require consent where a legal exception applies, but we still aim to explain their use.

We do not currently set optional advertising or behavioural tracking cookies. If optional analytics or similar technologies are introduced, we will update this notice and provide an appropriate consent control before they are activated where consent is required.

08

Children and external services

This website is intended for professional audiences.

Our services and website are not directed to children, and we do not knowingly seek personal information from them. If you believe a child has provided information to us, please contact us so we can assess and address it.

Links to external websites are provided for convenience. Their privacy practices are controlled by their respective operators, and you should review their notices separately.

09

Questions and complaints

Raise a concern directly and we will investigate it.

Email hello@safetyofai.com with the subject “Data protection complaint.” We will acknowledge a complaint within 30 days, investigate it without undue delay, keep you appropriately informed and explain the outcome.

You also have the right to complain to the UK Information Commissioner’s Office. We would value the opportunity to address your concern first, but contacting us does not remove that right.

Policy governance

We will keep this notice accurate as SafetyOfAI evolves.

We review this notice periodically and when our processing changes. Material changes will be communicated appropriately before a new use begins. The effective date at the top identifies the current version.

Privacy is operational

Trust should be designed into every decision system.

SafetyOfAI applies the same principle to AI governance: important safeguards must exist in practice, not simply on paper.

Explore our approach