Purpose limited
We use personal information only for clear, stated business purposes.
Trust, transparency and control
This notice explains what personal information SafetyOfAI Limited may collect, why we use it, how we protect it and the choices available to you.
Read the policy ↓Privacy at a glance
We use personal information only for clear, stated business purposes.
We ask only for information reasonably needed to respond or work with you.
We do not use this website to make solely automated decisions about people.
You can ask about your information or raise a concern directly with us.
Who we are
SafetyOfAI Limited is the data controller for personal information covered by this notice. This means we decide why and how that information is used.
We are a UK company based in Nottingham. This notice applies to visitors to this website, people who contact us, prospective clients, clients and professional contacts. It does not replace any more specific privacy terms provided as part of a client engagement.
What we collect
Depending on how you interact with us, this may include:
Your name, role and organisation.
Your business email address, telephone number and correspondence preferences.
Information you choose to include when contacting us or requesting a conversation.
Records needed to scope, manage or deliver an agreed service.
Basic device, browser, IP, request and security information generated when this website is accessed.
Please do not send special category information, confidential employee information or sensitive operational data through a general website enquiry. Where an engagement requires sensitive material, we will establish an appropriate and controlled route.
Purposes and lawful bases
We use personal information only where data protection law allows us to do so. The basis depends on the purpose and context.
To respond to questions, arrange conversations and understand potential requirements.
Legitimate interests; or steps requested before entering a contract.
To scope, deliver and administer SafetyOfAI services, including HDRS-related work.
Contract; legitimate interests; and legal obligation where applicable.
To maintain professional relationships, follow up requested discussions and keep accurate records.
Legitimate interests.
To operate, protect and understand the performance of this website.
Legitimate interests in service reliability, security and fraud prevention.
To send updates or briefings where requested or otherwise lawfully permitted.
Consent or legitimate interests, subject to applicable electronic marketing rules.
We do not use this website to make decisions that produce legal or similarly significant effects through solely automated processing. We do not sell personal information.
Retention and security
Retention depends on the nature of the information, the relationship, legal requirements and whether it may be needed to establish, exercise or defend legal claims.
Unless a relationship develops or earlier deletion is appropriate.
After the relevant engagement, where required for contractual, tax or legal records.
With limited suppression information retained where needed to honour an objection.
For the shortest period reasonably needed to maintain and investigate service security.
We use proportionate technical and organisational measures intended to protect information against accidental loss, unauthorised access, alteration or disclosure. No method of transmission or storage is completely secure, so protection is continuously reviewed rather than treated as a guarantee.
Your information rights
Depending on the circumstances, UK data protection law provides the following rights. They are not all absolute, and we may need to verify your identity before responding.
Ask for a copy of personal information we hold about you.
Ask us to correct information that is inaccurate or incomplete.
Ask us to delete information where there is no lawful reason to retain it.
Ask us to limit how we use information in certain circumstances.
Object to processing based on legitimate interests or direct marketing.
Receive certain information in a structured, commonly used format.
Withdraw consent at any time where consent is our lawful basis.
To exercise a right, email hello@safetyofai.com. We normally respond within one month, subject to the extensions and exemptions permitted by law.
Children and external services
Our services and website are not directed to children, and we do not knowingly seek personal information from them. If you believe a child has provided information to us, please contact us so we can assess and address it.
Links to external websites are provided for convenience. Their privacy practices are controlled by their respective operators, and you should review their notices separately.
Questions and complaints
Email hello@safetyofai.com with the subject “Data protection complaint.” We will acknowledge a complaint within 30 days, investigate it without undue delay, keep you appropriately informed and explain the outcome.
You also have the right to complain to the UK Information Commissioner’s Office. We would value the opportunity to address your concern first, but contacting us does not remove that right.
We review this notice periodically and when our processing changes. Material changes will be communicated appropriately before a new use begins. The effective date at the top identifies the current version.
Privacy is operational
SafetyOfAI applies the same principle to AI governance: important safeguards must exist in practice, not simply on paper.
Explore our approach ↗