Skip to content
InnovAIte

Information & terms

InnovAIte Privacy Notice

What the website enquiry form does today, and the information that must be completed before services go live.

Last updated: · Version 1.0

Who is responsible

InnovAIte is independently developed by Charles Oluko. The exact legal operator, public business address and designated data-protection contact have not yet been confirmed for this notice. No company registration or ICO registration claim is made here.

Roles need to be assessed for each activity. Deciding the purposes and essential means of processing makes an organisation a controller; acting only on another controller’s documented instructions generally makes it a processor. The actual activity, not just a contract label, determines the role.

Website enquiries

The form collects your name, email address, enquiry type, message, an optional product name, a generated enquiry reference and the submitting page path. Recognised campaign labels in a page link may accompany the enquiry to identify the promotion that led to it. Advertising click identifiers are excluded and campaign cookies are not saved.

Messages are used to respond to enquiries and discuss the requested work. The server uses connection information for a short-lived abuse limit. Please do not include credentials, confidential client records or sensitive personal information in the first message.

The current implementation sends enquiries through Resend when email delivery is configured. It does not maintain a separate enquiry database or include message contents in application error logs. Production hosting, mailbox arrangements, provider locations and retention still need confirmation.

Submitting an enquiry does not subscribe you to marketing. No newsletter, advertising pixel or visitor-analytics integration has been added to this version.

Information used during an engagement

Depending on the agreed work, information may include business contact details, roles and departments, correspondence, authorised operational documents and datasets, observations, meeting recordings or transcripts, technical and security records, and information needed for quotes, contracts and invoices.

The engagement must specify purposes, permitted information, its sources, who can access it, recording arrangements, providers, retention, transfers and the client’s and InnovAIte’s responsibilities. Staff or stakeholder information supplied by a client may require privacy information to be provided to those individuals as well.

Purposes may include delivering the agreed Discovery or development work, communicating with stakeholders, administering the engagement, protecting systems and meeting applicable legal obligations. Sharing evidence for an engagement does not itself authorise unrelated marketing, publication or model training.

Lawful bases and sensitive information

The purpose-by-purpose lawful-basis assessment is outstanding. The completed notice must identify the actual basis for each activity, any legitimate interests relied on, and where providing information is a contractual or legal requirement and what happens if it is not provided.

A general list of possible bases is not a substitute for that assessment. Where consent is used, it must be an appropriate and valid choice. Special-category and criminal-offence data require additional legal assessment and conditions before processing, not simply a standard confidentiality agreement.

AI and human oversight

Discovery is designed to use approved AI assistance under a named human operator. Material client-facing findings require evidence and human review.

Standard Discovery is not designed to make solely automated decisions about individuals with legal or similarly significant effects. A future change would require a separate assessment and updated information and safeguards before processing begins.

Providers, sharing and international transfers

Subject to the engagement, authorised providers may support hosting, storage, communications, AI analysis, transcription, document processing or security. Professional advisers and accounting or payment providers may need information for their specific functions. Information may also need disclosure where required by law or to establish, exercise or defend legal rights.

The actual production provider list and controller/processor arrangements are still being finalised. Those details, provider data-use conditions and any required client authorisations must be settled before client evidence is sent to a service.

Overseas processing requires assessment of whether a restricted transfer occurs and the relevant adequacy arrangement or other applicable lawful mechanism. The completed notice must explain actual transfer arrangements and how to obtain information about applicable safeguards.

Retention and security

Actual retention periods and their starting points remain to be confirmed for enquiries, email, logs, source evidence, recordings, transcripts, outputs, contracts and backups. Information should not be kept indefinitely on the chance it might become useful.

The engagement must define return, deletion and any justified further retention. Relevant derived copies also need to be included in deletion planning.

Controls must be appropriate to the data and processing risks. Engagement requirements include restricted access, approved processing routes and client-safe outputs; their implementation needs verification before evidence is processed. No claim of security certification or absolute protection is made.

Your rights

Depending on the circumstances, your rights may include access, correction, erasure, restriction, objection, portability and safeguards relating to certain automated decisions. The rights are not absolute and depend on the processing and applicable law.

Where processing relies on consent, you may withdraw it without affecting the lawfulness of processing before withdrawal. You may object to use of your personal information for direct marketing.

Use the contact below to ask about your information or exercise a right. Identity checks may be needed to protect your information. If InnovAIte acts as a processor for the relevant activity, the request may need to be coordinated with the client controller.

Cookies and updates

The separate Cookie Notice describes this website version and the checks still needed for its production configuration. No optional tracking has been introduced by these pages.

This notice will be updated as the operator, services and actual processing arrangements are finalised. The date and version above identify this draft; they do not indicate legal approval.

Contact and complaints

For now, send privacy questions to hello@innovaite.co.uk. The designated privacy contact and public business address still need confirmation.

You may also complain to the Information Commissioner’s Office where applicable. You do not have to contact InnovAIte before approaching the ICO.

Read the Cookie Notice.