Privacy Policy
How we use and protect personal information.
Last updated: 25 August 2026 | Version 1.7
Clairvoyant AI Limited, trading as Clairvynt, is the controller for the personal information covered by this notice. We are registered in Scotland under company number SC693791 and with the Information Commissioner's Office under reference C1889720.
Contact us at privacy@clairvynt.com or write to Clairvoyant AI Limited, Neo House, Riverside Drive, Aberdeen, AB11 7LH, United Kingdom.
Information we collect
- Enquiry and business contact details: your name, work contact details, organisation, role, interests and correspondence.
- Client and supplier administration: contract contacts, service records, billing details and business correspondence.
- Website and security data: request metadata such as IP address, time, requested page, browser information and security events.
- Contact-form security signals: Cloudflare Turnstile processes browser and security signals to distinguish people from abusive traffic. It does not receive the form fields you enter.
We normally receive this information from you, your organisation or its representatives. Website and security data is generated when you use the site.
Required contact-form information
Required fields are marked with an asterisk. We need your name, email address, company and area of interest to route and answer the request. If you do not provide them, we cannot respond to your enquiry through the form. A phone number and message are optional.
Client operational data
When Clairvynt processes operational documents to provide a client service, Clairvynt normally acts as that client's processor. The applicable contract and Data Processing Agreement govern that work, including its purpose, retention, security and approved sub-processors. This controller notice does not replace those terms.
Why we use personal information
| Purpose | UK GDPR lawful basis |
|---|---|
| Respond to enquiries, assess requirements and provide requested information or quotations | Our legitimate interests in developing and operating our business, and steps requested before a contract |
| Manage client, supplier and business relationships | Contract, steps before a contract, and our legitimate interests in administering business relationships |
| Invoice, keep accounts and meet tax, regulatory or legal requirements | Contract and legal obligation |
| Protect the website, contact form, systems and users from misuse | Our legitimate interests in maintaining secure and reliable services |
| Establish, exercise or defend legal claims and respond to lawful requests | Legal obligation and our legitimate interests |
When we rely on legitimate interests, we consider the business need, necessity and effect on the people concerned. You may object to that processing as described below.
Who receives it
We disclose only what is needed to operate the relevant service:
- Microsoft: business email, documents, identity services and Azure Communication Services email delivery.
- Cloudflare: website delivery, request security, Turnstile and contact-form infrastructure.
- FreeAgent: accounting and financial administration.
- Professional advisers and public authorities: where reasonably necessary or legally required.
We do not sell personal information or disclose it to third parties for their advertising.
International transfers
We mainly use services configured for the United Kingdom or European Economic Area. Some suppliers operate global support and security networks. Where personal information is transferred outside the United Kingdom, we use an applicable UK adequacy regulation or contractual safeguards such as the UK International Data Transfer Addendum, together with supplementary measures where required.
Client operational data follows the locations and safeguards agreed in the client's Data Processing Agreement and the current Sub-Processor Register.
How long we keep it
| Record | Normal retention |
|---|---|
| Enquiries and prospect correspondence | Two years after the last meaningful contact |
| Client and supplier contract records | The relationship plus six years |
| Accounting and tax records | Six years after the relevant financial year |
| Website security records | Only for the period needed to investigate abuse, maintain security and meet supplier or legal requirements |
We may keep a record longer where a legal hold, dispute or statutory duty requires it. We delete or anonymise records when the applicable period ends.
Security and website technology
We use access controls, multi-factor authentication, encryption, supplier due diligence and proportionate monitoring to protect personal information. No internet service can guarantee absolute security.
We do not use advertising or analytics cookies. We use essential security technology, including Cloudflare Turnstile on the contact form. Your browser may store or transmit limited information needed for that security check and normal website delivery.
Your rights
Depending on the circumstances, you may ask for access, correction, deletion, restriction or portability of your personal information. You may object to processing based on legitimate interests and withdraw consent where consent applies. Some rights have legal limits.
Send requests to privacy@clairvynt.com. We normally respond within one month after confirming identity and any information needed to handle the request.
Automated decisions
We do not make solely automated decisions about website visitors or business contacts that produce legal or similarly significant effects. Turnstile automatically assesses abuse risk only to protect the form.
Complaints
You can contact us so we can investigate. You may also complain to the Information Commissioner's Office, the UK supervisory authority. Its telephone number is 0303 123 1113.
Changes to this notice
We publish the current version and date on this page. We will provide a more direct notice where a material change makes that appropriate.