Legal
Privacy Policy
Last updated: July 2026
1. Introduction
INTELLIGENCE AI LTD ("we", "us", "our") is a company registered in the United Kingdom under company number 17356575, with its registered address at 128 City Road, London, United Kingdom, EC1V 2NX. We are the data controller responsible for the personal data you provide to us or that we collect in connection with your use of our website, our no-code automation platform, and related services. We process personal data in compliance with the retained UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
This Privacy Policy is designed to give you a clear understanding of what personal data we collect, why we collect it, the legal basis for processing it, how we use it, who we share it with, and the rights and choices available to you. The policy applies whether you are browsing our website, contacting our team, creating an account, or purchasing a platform plan.
We may update this policy from time to time. When we do, the latest version will be published on this page, along with its "Last updated" date. We encourage you to review this policy periodically.
2. Data We Collect
We collect personal data that you provide to us directly, that we generate when you use our platform, and that we receive from third-party services you choose to connect. This section explains each category in detail.
2.1 Information you provide directly
You may provide us with the following information:
- Contact details: your name, business email address, phone number, and postal address when you complete a contact form, sign up for an account, or communicate with our support team.
- Business information: your company name, job title, business sector, and the process, workflow, or automation requirements you share with us during onboarding or support discussions.
- Payment details: your billing name, billing address, country, and VAT number where applicable. Card numbers are entered directly into Stripe's secure hosted checkout and are not transmitted to or stored by us.
- Communication records: emails, messages, call notes, and other records of your interactions with our team, including support requests and feedback.
2.2 Platform and account data
When you create and use an account, we collect data needed to operate the platform:
- Account data: login credentials (stored in encrypted form), account preferences, and billing history.
- Workflow configuration data: the structure of workflows, triggers, actions, conditions, approvals, and connected service names you configure on the platform.
- Integration data: the names of third-party services you connect, API tokens or authentication details supplied by you, and the data flows you choose to enable. We do not access data stored in connected services beyond what is necessary to execute the workflows you configure.
- Usage and analytics data: logins, feature usage, workflow executions, error logs, and other operational information used to keep the platform running and to improve its performance.
2.3 Technical and cookie data
When you visit our website, we automatically collect technical information such as your IP address, browser type and version, operating system, device information, referring URLs, pages viewed, and the dates and times of your visits. Some of this data is collected through cookies and similar technologies. For more information, please see our Cookie Policy.
2.4 Data from third-party sources
If you choose to connect third-party services (for example, a CRM, messaging tool, spreadsheet, or calendar) to your workflows, we process data from those services only to the extent that you configure and authorize. We do not collect, store, or use that data for purposes outside of the workflows you have created.
3. Legal Basis for Processing
Data protection law requires us to have a lawful basis for processing your personal data. The table below explains the legal bases we rely on and the activities to which they apply.
3.1 Contractual necessity (Article 6(1)(b) UK GDPR)
We process your name, contact details, account information, payment confirmation, and platform configuration data in order to set up and manage your account, provide access to the platform, deliver the package you purchased, and fulfil our obligations under our terms and conditions.
3.2 Legitimate interests (Article 6(1)(f) UK GDPR)
We rely on legitimate interests to respond to enquiries, provide customer support, improve our website and platform, detect and prevent fraud or misuse, keep our systems secure, and operate and grow our business in a responsible way. Where we rely on legitimate interests, we carefully balance those interests against your rights and freedoms.
3.3 Consent (Article 6(1)(a) UK GDPR)
We rely on consent for optional cookies and for any marketing communications we may send, where applicable. You can withdraw your consent at any time by contacting us or, for cookies, through your browser settings or the cookie banner on our website.
3.4 Legal obligation (Article 6(1)(c) UK GDPR)
We may process your personal data where necessary to comply with applicable laws, including tax, accounting, anti-fraud, and regulatory obligations. This includes retaining transaction records for the period required by UK law.
3.5 Vital interests and public task
We do not generally rely on vital interests or public task as a basis for processing. If this changes for a specific and exceptional reason, we will inform you at the time.
4. How We Use Your Data
We use personal data only for lawful and clearly defined purposes. The main purposes are set out below. Where more than one purpose applies, we only use the minimum data necessary for that purpose.
4.1 To provide and manage the Platform
- Create and administer your Account
- Enable access to the features included in your Plan
- Store and execute the workflows and integrations you configure
- Provide technical support and respond to operational enquiries
4.2 To process transactions and payments
- Verify, process, and confirm your purchases
- Communicate with Stripe for payment authorisation, refunds, and fraud prevention
- Issue invoices, receipts, and VAT documentation where applicable
- Manage billing disputes and account payment queries
4.3 To communicate with you
- Respond to enquiries submitted through our website or support channels
- Send transactional emails such as confirmations, security alerts, and updates affecting your Account
- Provide product updates, tips, and relevant service information where you have agreed to receive them
4.4 To improve and secure the Platform
- Monitor platform performance, reliability, and usage trends
- Detect, prevent, and investigate fraud, abuse, unauthorised access, or security incidents
- Develop new features, fix bugs, and carry out testing and quality assurance
4.5 To comply with legal obligations
- Maintain accounting and tax records required by UK law
- Respond to lawful requests from courts, regulators, or government authorities
- Enforce our Terms & Conditions and other legal rights
4.6 Lawful-basis reminder
Activities in sections 4.1, 4.2, and 4.5 are normally carried out under contractual necessity or legal obligation. Activities in section 4.3 and 4.4 rely on legitimate interests where they are not necessary for a contract. Marketing communications rely on consent where required. See Section 3 for more detail.
5. Payment Processing via Stripe
All payments on our website are processed by Stripe, Inc., a PCI DSS Level 1 certified payment processor. We use Stripe so that your payment details are handled with bank-grade security and in compliance with the highest payment industry standards.
5.1 Card data we do not collect
When you make a purchase, your card details are entered directly into Stripe's secure hosted checkout (Stripe Elements or Stripe Checkout) and are transmitted to Stripe, not to us. We never receive, view, store, or process your full card number, CVC, or card expiry date. Stripe provides us only with the information we need to confirm and support your Order.
5.2 Payment data we do receive
- Payment status (for example, authorised, successful, refunded, or failed)
- Transaction amount, currency, and timestamp
- Billing name and billing address (for invoicing, VAT, and customer records)
- The last four digits of the card and card brand (so we can help identify transactions in support queries)
- Stripe customer or payment identifier (to link transactions to your Account)
5.3 Stripe's role as data controller
For the card and payment processing data you enter into Stripe's checkout, Stripe acts as an independent data controller. Stripe's own privacy practices are described in its privacy policy available at stripe.com/privacy. We recommend reviewing Stripe's privacy policy before making a payment.
5.4 Fraud prevention
Stripe may use fraud-prevention technologies, including device fingerprinting and transaction risk scoring, to protect you and us against unauthorised payments. These checks are performed by Stripe in accordance with Stripe's own terms and privacy policy.
6. Data Sharing
We do not sell, rent, or trade your personal data. We share personal data only with selected third parties who help us operate, secure, and improve the Platform and our business, or where we are required by law to do so. Each recipient receives only the data they need to perform their role and is required to keep it secure.
6.1 Categories of recipients
- Payment processors: Stripe, for processing payments, refunds, and fraud prevention.
- Cloud and infrastructure providers: providers that host our website, Platform, databases, backups, and related infrastructure.
- Communication and support tools: email delivery, customer relationship management (CRM), and help-desk providers used to manage enquiries and support your Account.
- Analytics providers: providers that help us understand how visitors use our website and Platform, so that we can improve performance and user experience.
- Professional advisers: accountants, auditors, insurers, and legal advisers who support our business on a confidential basis.
- Regulators and authorities: courts, tax authorities, law enforcement, and other bodies where disclosure is required by law or to protect our legal rights.
6.2 Third parties connected through your workflows
When you configure a workflow to send or receive data from a third-party service (for example, a CRM, messaging app, spreadsheet, or email provider), that data is shared with the third party in accordance with your instructions and the third party's terms. We are not responsible for how those third parties process such data.
6.3 Safeguards
Where we share personal data with third parties that process it on our behalf, we use written contracts that require them to keep the data secure, use it only for the agreed purpose, and comply with UK data protection law.
7. International Data Transfers
Some of our service providers, including Stripe, may process personal data outside the United Kingdom or the European Economic Area (EEA). Where we transfer personal data internationally, we ensure that an appropriate safeguard is in place in accordance with UK data protection law.
These safeguards may include:
- The UK International Data Transfer Agreement (IDTA) or UK Addendum to the EU Standard Contractual Clauses
- EU Standard Contractual Clauses approved by the European Commission
- Transfers to countries that the UK Secretary of State has recognised as providing an adequate level of protection for personal data
- Other mechanisms permitted under UK GDPR for specific, limited transfers, where applicable
You can contact us if you would like more information about the specific safeguards we use.
8. Data Retention
We retain personal data only for as long as necessary to fulfil the purposes for which we collected it, including to provide the Platform, respond to enquiries, resolve disputes, enforce our agreements, and meet our legal, tax, and regulatory obligations.
8.1 Retention periods
- Account and platform data: retained for as long as your Account remains active, plus a reasonable period afterwards to resolve outstanding matters, enforce our terms, or respond to legal requests.
- Transaction and billing data: retained for the period required under UK tax and accounting law (typically six years).
- Communication records: retained for as long as needed to provide support, resolve disputes, and maintain records of our relationship with you.
- Marketing data: retained until you withdraw your consent or opt out, or until we determine it is no longer relevant.
- Website analytics and log data: typically retained for up to 26 months, unless longer retention is needed for security, debugging, or legal purposes.
8.2 Deletion and anonymisation
When personal data is no longer needed, we securely delete or anonymise it so that it cannot be linked back to you. Some data may be retained in aggregated or anonymised form for analytical or operational purposes.
9. Your Rights
Under UK GDPR and the Data Protection Act 2018, you have the following rights in relation to your personal data. These rights are not absolute and may be limited in certain circumstances, for example where we need to comply with a legal obligation or where processing is necessary for the establishment, exercise, or defence of legal claims.
9.1 Right to access
You have the right to request confirmation of whether we process your personal data and, if so, to obtain a copy of that data and information about how and why it is being used.
9.2 Right to rectification
You have the right to request that we correct inaccurate or incomplete personal data. We encourage you to keep your Account information up to date to help us provide the Platform accurately.
9.3 Right to erasure ("right to be forgotten")
You have the right to request that we delete your personal data in certain circumstances, for example where the data is no longer necessary for the purpose for which it was collected. We may need to retain some data where required by law or for legitimate legal purposes, such as tax or accounting records.
9.4 Right to restrict processing
You can ask us to restrict the processing of your personal data in specific situations, for example while we verify the accuracy of data you dispute, or where you object to our processing based on legitimate interests.
9.5 Right to data portability
Where our processing is based on your consent or is necessary for the performance of a contract and is carried out by automated means, you have the right to receive your personal data in a structured, commonly used, machine-readable format, and to request that we transfer it directly to another controller where technically feasible.
9.6 Right to object
You have the right to object to processing based on legitimate interests, including profiling. You can also object to direct marketing at any time. If you object to marketing, we will stop sending you marketing communications as soon as possible.
9.7 Right to withdraw consent
Where we rely on your consent to process your personal data, you have the right to withdraw that consent at any time. Withdrawing consent does not affect the lawfulness of processing carried out before the withdrawal.
9.8 How to exercise your rights
To exercise any of your rights, please contact us via the contact page or email us at info@intelligenceailtd.com. We aim to respond to all requests within one calendar month. We may ask you to verify your identity before acting on a request.
9.9 Right to complain
If you are concerned about how we handle your personal data, you have the right to lodge a complaint with the UK Information Commissioner's Office (ICO). You can find information about how to do this at ico.org.uk. We would, however, appreciate the chance to address your concerns first.
10. Cookies and Similar Technologies
We use cookies and similar technologies to make our website work, to understand how visitors use it, and, where you consent, to support marketing or personalisation features. Cookies are small files placed on your device that store limited information.
10.1 Categories of cookies we use
- Essential cookies: required for the website and Platform to function securely, for example to remember your login session or preserve your preferences.
- Analytics cookies: help us understand how visitors interact with the website so we can improve its design and performance.
- Marketing cookies: may be used to deliver relevant content or to measure the effectiveness of our communications, but only where you have given consent.
10.2 Managing cookies
You can manage your cookie preferences through the cookie banner on our website or through your browser settings. Please note that disabling essential cookies may affect the functionality of the website and Platform. Full details are available in our Cookie Policy.
11. Children's Privacy
Our website, Platform, and services are intended for business use by individuals aged 18 and over. We do not knowingly collect personal data from children under the age of 18. If we become aware that a child has provided us with personal data, we will take steps to delete that information as soon as possible.
If you believe a child has provided personal data to us, please contact us using the details in Section 14.
12. Automated Decision-Making and Profiling
Our Platform may use AI-assisted features to suggest workflow improvements, identify bottlenecks, or recommend optimisations based on patterns in workflow execution data. These suggestions are designed to support your own business decisions, not to replace them.
12.1 No solely automated significant decisions
We do not make decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you. Where any automated suggestion could have meaningful consequences, a human is able to review, override, or amend the decision.
12.2 Fraud and security risk scoring
Stripe and some of our infrastructure providers may carry out automated checks as part of fraud prevention or security monitoring. These checks are performed by the relevant third party in accordance with their own terms and privacy notices.
13. Security
We take the security of personal data seriously and implement a range of technical and organisational measures to protect it from unauthorised access, alteration, disclosure, or destruction.
13.1 Measures we use
- Encryption in transit: data transmitted between your browser and our servers is protected using HTTPS/TLS.
- Access controls: access to personal data and production systems is restricted to authorised personnel who need it to perform their role.
- Secure hosting: our website and Platform are hosted on reputable cloud infrastructure with robust physical and network security.
- Authentication: user Accounts are protected by encrypted credentials and, where available, multi-factor authentication.
- Monitoring and logging: we monitor systems for unusual activity and review logs to detect and respond to security incidents.
- Regular review: we review our security practices periodically and apply patches and updates to address known vulnerabilities.
13.2 Limitations
No method of transmission or storage is completely secure. While we work to maintain industry-appropriate safeguards, we cannot guarantee absolute security. You are responsible for keeping your login credentials confidential and for using the security features we make available.
13.3 Reporting security concerns
If you believe your interaction with us is no longer secure or if you suspect a data breach, please contact us immediately using the details in Section 15.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, services, or legal obligations. When we make material changes, we will revise the "Last updated" date at the top of this page.
We encourage you to review this policy periodically. For significant changes that affect how we use your personal data, we may also notify you through the email address associated with your Account or by posting a prominent notice on our website before the changes take effect. Your continued use of the website or Platform after the changes become effective constitutes acceptance of the revised policy.
15. Contact Us and Data Controller Information
INTELLIGENCE AI LTD is the data controller for the personal data described in this Privacy Policy.
Registered address: 128 City Road, London, United Kingdom, EC1V 2NX
Company number: 17356575
Email: info@intelligenceailtd.com
For any privacy-related questions, to exercise your rights, or to raise a concern about how we handle your personal data, please contact us via the contact page on our website, or by email at info@intelligenceailtd.com. We will respond as promptly as possible and, where required by law, within the applicable time limit.