Legal

Privacy Notice

How Vektor AI Ltd collects, uses and protects your personal data.

Last updated: May 2026 · ICO Registration: ZC143453
01Who we are

Who we are

Vektor AI Ltd is an AI consulting company that builds bespoke AI tools for professional services firms. We are registered in England and Wales and are a registered data controller with the Information Commissioner's Office (ICO).

02What data we collect

What data we collect

Depending on how you interact with us, we may collect the following:

When you contact us or book a demo: Your name, email address, company name and any information you choose to share with us.

When you use our products: Documents and files you upload for processing (invoices, bank statements, ledger data), account information for authentication, and usage data such as the number of documents processed.

Website usage: We do not use tracking scripts, advertising pixels or third-party analytics. No cookies are set beyond what is technically necessary.

03How we use your data

How we use your data

To provide our services: Document content is processed by Claude AI (Anthropic) to extract structured data. This is the core function of our products.

To communicate with you: We use your email address to respond to enquiries, send service updates and deliver authentication links. We do not send marketing emails without your explicit consent.

To improve our services: We may review anonymised usage patterns to improve accuracy and performance. We never review the content of your documents without your permission.

We do not use your data for advertising, profiling or training our own AI models.

04Our legal basis

Our legal basis

We process your data on the following legal bases under UK GDPR:

Contract: Processing necessary to provide the services you have engaged us to deliver.

Legitimate interests: Responding to enquiries, improving our services, and maintaining the security of our systems.

Consent: Where you have explicitly agreed, for example when subscribing to updates.

05Sub-processors

Sub-processors

We use the following third-party services to deliver our products. Each has been assessed for UK GDPR compliance:

ProviderPurposeLocation
AnthropicAI document processingUSA
SupabaseDatabase and authenticationEU (Ireland)
RailwayApplication hostingUSA
ResendTransactional email deliveryUSA
Anthropic: Data Processing Addendum + SCCs. Data not retained for model training.
Supabase: UK GDPR compliant. Encrypted at rest and in transit.
Railway: SOC 2 compliant. TLS encryption. No data stored on application servers.
Resend: Only email address passed. Used for authentication links only.
06How long we keep your data

How long we keep your data

Document processing data: Automatically deleted after 90 days. You can request deletion at any time.

Account data: Retained for as long as your account is active. Deleted within 30 days of account closure.

Enquiry data: Retained for up to 2 years for legitimate business purposes, then deleted.

All data is stored with encryption at rest. Transit is protected by TLS 1.2 or higher.

07Your rights

Your rights

Under UK GDPR you have the following rights. To exercise any of them, contact us at [email protected]. We will respond within 30 days.

Access
Request a copy of all personal data we hold about you.
Deletion
Request that we delete your personal data. We will do so within 30 days unless we have a legal obligation to retain it.
Portability
Request an export of your data in a machine-readable format.
Correction
Request correction of any inaccurate data we hold about you.
Objection
Object to processing based on legitimate interests. You can stop using our services at any time with no lock-in.
Restriction
Request that we restrict processing of your data in certain circumstances.

You also have the right to lodge a complaint with the ICO at ico.org.uk or by calling 0303 123 1113.

08Security

Security

We take the security of your data seriously. Our systems include:

  • Row Level Security at the database level ensuring no cross-client data access.
  • Rate limiting and prompt injection protection on all AI processing routes.
  • Secure, HttpOnly session cookies with SameSite protection.
  • Regular automated security audits.
  • All staff with data access are bound by confidentiality obligations.

In the event of a data breach that poses a risk to your rights, we will notify you and the ICO within 72 hours of becoming aware.

09Changes to this notice

Changes to this notice

We may update this privacy notice from time to time. Material changes will be communicated by email where we hold your contact details. The date at the top of this page shows when it was last updated.

10Contact us

Contact us

For any privacy-related questions, data requests or to exercise your rights:

Vektor AI Ltd
Data Controller · ICO Registration ZC143453

We aim to respond to all privacy requests within 5 working days and will always respond within the statutory 30-day period.