Privacy Policy
Last updated: 28 July 2026
1. Who we are
Ayoob AI Ltd ("Ayoob AI", "we", "us") is a company registered in England and Wales under company number 15931832, with its registered office at 113 New Bridge Street, Innovation Northumbria Incubator, Newcastle upon Tyne, NE1 8ST.
We handle personal data in two distinct capacities:
- As a data controller, for personal data collected through this website and in the course of running our business.
- As a data processor, for personal data we handle on behalf of clients when delivering our services. In those engagements the client is the controller and determines the purposes of the processing. See Section 5.
We are registered with the Information Commissioner's Office under registration reference ZB923967.
Data protection contact. Husain Ayoob, Data Protection Officer.
Email: contact@ayoob.ai
113 New Bridge Street, Innovation Northumbria Incubator, Newcastle upon Tyne, NE1 8ST
2. What data we collect through this website
Where we act as controller for this website, we collect personal data only when you voluntarily provide it through our contact form:
- First name and last name
- Work email address
- Company name
- Message content (your enquiry)
We do not collect data from minors and our services are not directed at individuals under 18.
Personal data we process on behalf of clients is described separately at Section 5.
3. How we use your data
We process personal data collected through this website for the following purposes:
- To respond to your enquiry. Lawful basis: legitimate interest (Art. 6(1)(f) UK GDPR)
- To provide requested services. Lawful basis: performance of a contract (Art. 6(1)(b) UK GDPR)
- To comply with legal obligations. Lawful basis: legal obligation (Art. 6(1)(c) UK GDPR)
We do not use website enquiry data for automated decision-making or profiling.
4. Cookies
We use only essential cookies required for the website to function (e.g. cookie consent preference). We do not use analytics, advertising, or third-party tracking cookies. For full details, see our Cookie Policy.
5. Personal data we process on behalf of clients
When we deliver services to a client, we may process personal data on that client's behalf. In those engagements:
- The client is the data controller and determines the purposes of the processing. We act as processor and process personal data only on the client's documented instructions, unless required to do otherwise by law.
- Every such engagement is governed by a written data processing agreement meeting the requirements of Article 28 UK GDPR, setting out the subject matter, duration, nature and purpose of the processing, the categories of personal data and data subjects, and the obligations of each party.
- We do not use client personal data for our own purposes, for marketing, for demonstration, or for any purpose outside the scope agreed with the client.
- We do not sell client personal data under any circumstances.
Processing location. The location of processing is agreed with the client at the outset of each engagement. Where a client requires that personal data is processed and stored solely within the United Kingdom, we deliver on that basis and no personal data leaves the United Kingdom.
Third-party AI and cloud services. Some engagements involve third-party cloud or artificial intelligence services. Where they do, those providers are agreed with the client in advance, are bound by written data processing terms, and are recorded in the engagement documentation. Where a client requires that no personal data is transmitted to any third-party model provider, we deliver using locally hosted models on infrastructure we control.
Sub-processors. We carry out due diligence on any sub-processor before engagement and put in place a written agreement imposing obligations equivalent to those we owe the client. Clients are notified of sub-processors in accordance with their data processing agreement.
Retention and return. Client personal data is retained only for as long as necessary to deliver the engagement, and is returned or securely deleted at the end of the engagement or earlier on the client's instruction. Confirmation of deletion is provided on request.
Data subject rights. Where we receive a request from an individual relating to personal data we process on behalf of a client, we refer that request to the client without undue delay and assist the client in responding.
If you believe we process your personal data on behalf of one of our clients, please contact that organisation in the first instance. You may also contact us at contact@ayoob.ai and we will direct your request appropriately.
6. Data sharing
We do not sell your personal data. Where we act as controller, we may share data with:
- Email service providers. To deliver your contact form submission to our team
- Hosting providers. Our website is hosted on infrastructure that may process data on our behalf
- Professional advisers. Where necessary for legal, accounting or insurance purposes
- Legal authorities. Where required by law
All third-party processors are bound by data processing agreements and process data only on our instructions.
7. International transfers
We operate from the United Kingdom.
Client service data. The processing location for each client engagement is agreed with the client, as described at Section 5. Where an engagement requires United Kingdom only processing, no personal data is transferred outside the United Kingdom.
Website and business data. Some of the hosting, email and business support providers we use as a controller operate infrastructure outside the United Kingdom. Where personal data is transferred outside the United Kingdom, we ensure an appropriate transfer mechanism is in place in accordance with UK GDPR, such as an adequacy decision or the International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, together with a transfer risk assessment where required.
8. Data retention
We retain contact form data for a maximum of 24 months from the date of submission, or until the enquiry is resolved and any resulting engagement concludes, whichever is later. After this period, data is securely deleted.
Retention of personal data processed on behalf of clients is governed by the relevant data processing agreement, as described at Section 5.
9. Your rights
Under UK GDPR, you have the right to:
- Access your personal data (Subject Access Request)
- Rectify inaccurate personal data
- Erase your personal data ("right to be forgotten")
- Restrict processing of your personal data
- Object to processing based on legitimate interest
- Data portability. Receive your data in a structured, machine-readable format
- Withdraw consent at any time, where processing is based on consent
To exercise any of these rights, email us at contact@ayoob.ai. We will respond within one month of receiving your request. Where a request is complex or where we have received a number of requests from you, we may extend this by up to a further two months and will tell you within one month if we do.
10. Security
We implement appropriate technical and organisational measures to protect personal data. Ayoob AI holds ISO/IEC 27001:2022 certification and Cyber Essentials accreditation.
Our measures include:
- Encryption of personal data in transit using TLS, and at rest
- Access control on a least privilege basis, restricted to named authorised personnel
- Access logging and monitoring
- Documented incident management within our certified information security management system
- Regular review of technical and organisational measures
11. Personal data breaches
We maintain a documented process for identifying, containing, assessing and reporting personal data breaches.
Where we act as controller and a breach is likely to result in a risk to the rights and freedoms of individuals, we report it to the Information Commissioner's Office within 72 hours of becoming aware, in accordance with Article 33 UK GDPR. Where a breach is likely to result in a high risk, we notify affected individuals without undue delay in accordance with Article 34 UK GDPR.
Where we act as processor on behalf of a client, we notify that client without undue delay on becoming aware of a personal data breach, and within any shorter period specified in the relevant data processing agreement, and provide all reasonable assistance in their investigation and reporting.
All personal data breaches are recorded in a breach register, whether or not they are reportable.
12. Complaints
If you are unhappy with how we handle your data, please contact us first at contact@ayoob.ai so that we can try to resolve it.
You also have the right to lodge a complaint with the Information Commissioner's Office (ICO): ico.org.uk/make-a-complaint.
13. Changes to this policy
We may update this policy from time to time. Any changes will be posted on this page with an updated "Last updated" date. We encourage you to review this policy periodically.