Privacy Policy
Last updated: 8 September 2026
This notice explains how Data Privacy and Data Security Services Limited, trading as Smart Flow AI (“we”, “us” or “our”), collects and uses personal data through smartflowai.uk, enquiries, proposal requests, our client portal and AI assistants, and our business relationships. It explains your choices and how to exercise your rights or make a complaint.
We apply the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations 2003 (PECR), as amended, including relevant changes made by the Data (Use and Access) Act 2025. Other applicable laws, including EU data protection law where relevant to our Cyprus activities, may also apply.
1. Data Controller and contact details
Data Privacy and Data Security Services Limited is the Data Controller for the activities described in this notice. Smart Flow AI is its trading name. A controller decides why and how personal data is used.
- UK operating address: 124 City Road, London, EC1V 2NX, United Kingdom.
- Cyprus operating address: Apostolou Pavlou, Vasilika Center Block 1, Shop 1, 8046, Paphos, Cyprus.
- Email: info@smartflowai.uk.
- Website: Contact Smart Flow AI.
Where a client instructs us to handle personal data solely on its behalf, that client may be the controller and we may act as its processor under a separate agreement. The client’s privacy notice then explains that processing. We remain responsible for our own controller activities, such as managing business contacts and our website.
2. Data Protection Officer
Data Privacy Services is our appointed Data Protection Officer (DPO). You can contact the DPO directly about this notice, your rights or a data protection concern at info@dataprivacyservices.co.uk. You can also write to our UK operating address, marked “For the attention of the DPO”.
3. Personal data we collect and where it comes from
- Enquiries and callbacks: your name, email address, business name, telephone number, preferred contact time and the message you provide.
- Proposal requests: your selected service, requirements, timeframe, organisation, role, contact details, additional context and any supporting document. Documents can contain personal data about you or other people.
- Client relationships: business contact information, account and membership details, project information, support requests, replies and communications. Account authentication and access records are also processed.
- AI interactions: questions, relevant recent conversation context and generated answers. Information you type may include personal data even though we ask you to avoid it.
- Technical information: network address, browser and device information, request times, website activity, security logs and cookie preferences, depending on the functions used and choices made.
- Compliance records: consent choices, proposal consent wording and timestamps, rights requests, complaints, correspondence and records needed to meet legal obligations.
Most information comes directly from you. Business contacts and project details may also be supplied by your employer, an authorised colleague, a client or a professional adviser. Technical data is generated when your browser communicates with our systems and providers. Where information is obtained indirectly, we provide privacy information as required by law.
Only supply information you are entitled to share. Please avoid passwords, API keys, financial account credentials, unnecessary confidential information, health information or other special-category data, and criminal-offence information. We do not request these through public forms or chat. If a project requires such data, appropriate arrangements and additional legal conditions must be agreed before it is shared.
4. Purposes and lawful bases
We identify a lawful basis for each purpose; the basis depends on the activity and relationship.
- Responding to website enquiries, callbacks and proposal forms: consent where the form asks for your agreement to process the submission. You can use the contact details above to discuss an alternative way to communicate.
- Taking steps towards or performing a contract with you personally: Article 6(1)(b), where processing is objectively necessary for that contract or for steps you request before entering it.
- Managing organisational client and supplier relationships: legitimate interests under Article 6(1)(f), specifically communicating with business representatives, administering projects and providing agreed services. A contract with your employer does not, by itself, make contract the lawful basis for your personal data.
- Optional AI assistance and portal messages submitted using a consent box: consent under Article 6(1)(a) for that interaction, including transmission to the AI provider where explained. Separate account administration and security activities rely on their own stated bases.
- Website and account security, abuse prevention, diagnostics and proportionate usage limits: legitimate interests in protecting our systems, users and service availability, balanced against your rights.
- Accounting, legal and regulatory duties and handling statutory rights and complaints: legal obligation under Article 6(1)(c), where a specific obligation applies. Establishing, exercising or defending legal claims may rely on legitimate interests and, where relevant, additional legal conditions.
- Optional cookies and similar technologies: consent where PECR requires it. Strictly necessary technologies may operate without consent where a legal exemption applies. Our Cookie Policy provides further detail.
We do not treat submitting a proposal, asking for support or chatting with the assistant as agreement to receive marketing. If we introduce optional marketing, we will provide a separate choice and the applicable privacy information. Any electronic marketing must also meet PECR requirements.
5. Your choices, required fields and withdrawing consent
Required fields identify the information needed to process a particular request. Supporting documents and fields marked optional are voluntary. If essential information is not supplied, we may be unable to answer, prepare a proposal or provide the requested service. There is no obligation to use the AI assistants.
You may withdraw consent at any time by contacting us or the DPO. For optional cookies, use Cookie settings. To stop further AI interactions, stop sending questions; use Clear chat to remove the visitor conversation from the current browser view. Clearing a chat is not a request to delete any information already processed by a provider.
Withdrawal does not affect the lawfulness of earlier processing. If a different lawful purpose requires us to retain some information, such as a legal obligation or an existing legal claim, we will explain that purpose and basis. We do not retrospectively switch the basis simply to disregard your withdrawal.
6. AI assistants
Our public AI service assistant uses the published Service Catalogue to answer questions and suggest proposal links. It does not have access to private client projects, uploaded proposal documents or account records. The client-portal AI assistant answers questions submitted through that portal.
When you consent and send a question, the question and relevant conversation context are transmitted from our server to OpenAI through its API. We keep the API credential on the server. AI answers may be inaccurate; a consultant should confirm any proposal, commitment or advice before you rely on it.
The visitor chatbot does not save conversation text in the WordPress database. Its browser conversation is held in the current page view and is cleared when you clear the chat or leave that view. Limited technical usage counters are maintained for abuse prevention. Portal questions, replies and any exchange you send to a consultant may be retained in portal or support records according to their purpose.
The API requests are configured with response storage disabled. This does not mean that OpenAI retains no data: its standard API abuse-monitoring logs may contain content and are generally retained for up to 30 days, subject to its applicable exceptions and legal requirements. OpenAI states that API content is not used for model training by default unless the customer opts in. See OpenAI API data controls.
These website assistants provide information; they do not make decisions about you that produce legal or similarly significant effects, approve purchases, determine eligibility or submit requests on your behalf. If we introduce such decision-making, we will provide the required information and safeguards before doing so.
7. Uploaded documents and proposal notifications
A proposal may include an optional supporting document. Accepted formats and size limits are shown on the form. The file is stored privately with the proposal and is available to authorised site administrators. It is also attached to the proposal notification sent to our business inbox, so a copy may exist in email systems and backups.
Uploading a file does not make it public or send it to the public chatbot for analysis. Please remove irrelevant personal data before uploading. If a document concerns other people, ensure there is a lawful reason to share it and that they receive appropriate privacy information. Contact us for a suitable transfer method if material is particularly sensitive.
8. Who receives personal data
Access is limited by the purpose of the activity. Recipients may include authorised staff and consultants, the DPO, and providers supporting the website and our business operations.
- Hostinger: website hosting and associated infrastructure; configured email services carry website notifications.
- OpenAI: processing AI questions and relevant context to generate answers, as explained above.
- Microsoft services: client collaboration, documents or project workspaces where these are used for your engagement and access has been arranged.
- Website, security, maintenance and consent-management providers: where needed to operate and protect the website. Relevant cookies and embedded services are described in the Cookie Policy.
- Professional advisers, regulators and competent authorities: where necessary for advice, legal obligations or legitimate legal claims.
Providers acting as processors must be governed by appropriate data-processing terms. Some recipients act as independent controllers for their own lawful purposes. We do not sell personal data. We do not publish your proposal or supporting file. Links to external websites lead to services with their own privacy notices.
9. International processing and transfers
We operate in the UK and Cyprus and use providers whose infrastructure, support teams or subprocessors may be outside the UK, including in the European Economic Area and the United States. The location depends on the provider and the account configuration. This notice should not be read as a promise that all data remains in the UK.
Before a restricted international transfer is made, applicable UK transfer requirements must be satisfied. The mechanism may be UK adequacy regulations, where applicable, or appropriate contractual safeguards such as the UK International Data Transfer Agreement or the UK Addendum to the European Commission’s standard contractual clauses, together with the required data protection test and any additional protections. A provider’s general statement about compliance is not itself a substitute for these arrangements.
Contact our DPO for information about the countries and safeguards relevant to your processing and to request a copy or explanation of the applicable safeguards, subject to necessary redactions. Where EU law also applies, the corresponding EU transfer requirements must be addressed.
10. Retention and deletion
We retain personal data only for as long as needed for the purpose for which it was collected, taking account of legal obligations, contractual requirements, security needs and legal claims. Retention is determined using the following criteria rather than one universal period:
- Enquiries, callbacks and unsuccessful proposals: whether the enquiry is still active, whether reasonable follow-up is expected, and whether an unresolved dispute or obligation requires a record.
- Client and project records: the duration of the relationship, ongoing support requirements, applicable accounting or other statutory duties, and relevant limitation periods for claims.
- Documents: their continuing relevance to the associated proposal or project. Copies in email and backups must be considered alongside the website copy.
- Accounts: whether access remains authorised and whether particular records are needed after access is removed.
- Consent, rights and complaint records: the need to evidence the choice or response and demonstrate compliance.
- Security and technical records: the time needed to investigate misuse, protect systems and resolve incidents. Visitor-chat network usage counters expire after an hour without a further counted request; daily usage totals contain no chat text.
- AI data: the browser, portal and provider arrangements described in section 6.
When information is no longer required, it should be securely deleted or irreversibly anonymised. Backup copies may remain until overwritten under the relevant backup cycle and should not be restored to ordinary use after deletion except where necessary and lawful. Ask the DPO about the retention applicable to a particular record or request deletion; legal exceptions may apply.
11. Cookies and similar technologies
Read our built-in Cookie Policy (UK) for information about cookies, related technologies, their purposes and available controls. Use the website’s Cookie settings control or the consent-management section of that policy to review or change your choices.
Rejecting optional cookies should not prevent access to essential website functions, although particular embedded features may not work. Browser settings can also block or delete cookies. Consent to an enquiry or AI chat is separate from your cookie choices. The cookie inventory must be kept up to date as website features change.
12. Security and confidentiality
Measures used on this site include HTTPS, access-controlled portal and proposal records, server-side API credentials, file-type and size validation, and limits on automated requests. Security also depends on appropriate permissions, maintenance and staff handling. No online service or email transmission can be guaranteed completely secure.
Keep your account credentials private, use appropriate account protection and contact us promptly if you suspect unauthorised access. We assess personal-data incidents and notify the regulator and affected people when the law requires it.
13. Your data protection rights
Depending on the circumstances and lawful basis, you may request access to your personal data, correction of inaccurate or incomplete information, erasure, restriction of processing, or portability of qualifying information. You may withdraw consent and have applicable protections in relation to significant solely automated decisions. These rights are not absolute; we will explain any lawful restriction.
Your right to object: you may object to processing based on legitimate interests because of your particular situation. We must stop unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or processing is necessary for legal claims. You have an absolute right to object to use of your personal data for direct marketing, including related profiling.
Contact info@dataprivacyservices.co.uk or info@smartflowai.uk to exercise a right. No special wording or paid service is required. We may request proportionate information to verify identity or clarify a request, but will not ask for unnecessary identification.
We normally respond without undue delay and within one month, applying the relevant statutory rules on when time begins and any permitted pause for clarification. Where an extension is legally permitted because of complexity or the number of requests, it may be up to a further two months; we will explain it within the initial period. Requests are normally free. Any lawful refusal or fee will be explained, along with your complaint options.
14. Your right to complain
You have the right to complain about our handling of your personal data, and the right to complain to the Information Commissioner’s Office (ICO).
To complain to us, email the DPO at info@dataprivacyservices.co.uk, email info@smartflowai.uk, or write to our UK address marked “Data protection complaint”. Describe what happened, approximately when, and the outcome you seek. We can help you raise a complaint and will consider reasonable accessibility adjustments; you do not need to use a prescribed form.
We will acknowledge your complaint within 30 days of receipt, make appropriate enquiries, keep you informed of progress and communicate the outcome without undue delay. A complaint and a request to exercise a data right may be handled together, but their distinct legal obligations and response periods still apply.
You may complain to the ICO at any time; you do not have to obtain our permission or wait for us to agree with your concern. The ICO generally recommends giving the organisation an opportunity to respond first.
- Online: Make a complaint to the ICO.
- Telephone: 0303 123 1113.
- Post: Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF, United Kingdom.
This does not limit any right to seek a judicial remedy or compensation where the legal conditions are met. Where another supervisory authority has jurisdiction, including for relevant EU processing, your rights to approach that authority are also unaffected.
15. Children and changes to this notice
Our services are directed at business users and are not designed for children. Please contact the DPO if you believe a child’s data has been supplied so that we can assess and respond appropriately.
We review this notice when our services, processing or legal requirements change. The published version will show its revision date. Where a material change affects you, or a new purpose requires further information or consent, we will provide the relevant information before starting that processing.
