Privacy policy

Last updated: September 2026

AISCG respects your privacy and is committed to protecting your personal data.

Purpose of this privacy policy

This privacy notice explains how AI Strategy and Compliance Group Limited ("AISCG", "we", "us" or "our") collects, uses, stores and protects personal data in connection with our business, website and AI, HR and compliance consultancy services.

It applies to personal data we process about our clients and prospective clients, their personnel and other individuals whose personal data is provided to us in connection with our services, as well as people who visit our website, contact us, subscribe to our communications or otherwise interact with us.

This website is not intended for children and we do not knowingly collect personal data relating to children.

This privacy notice should be read together with any other privacy notice, fair processing notice, contractual terms or other information we may provide when we collect or process personal data about you. Those notices may provide additional information about particular processing activities.

Who we are and our role

AI Strategy and Compliance Group Limited (company number 17394411) is the legal entity responsible for the processing described in this privacy notice.

Depending on the services we provide and the nature of a particular engagement, AISCG may act as:

  • an independent data controller, where we determine the purposes and means of processing personal data;

  • a data processor, where we process personal data solely on behalf of a client and in accordance with that client's documented instructions; or

  • in limited circumstances, a joint controller, where AISCG and another organisation jointly determine the purposes and means of processing personal data.

Our role will depend on the particular services, responsibilities and arrangements agreed with the relevant client. The applicable engagement letter, statement of work, data-processing agreement or other contractual arrangements will set out the relevant responsibilities where appropriate.

Where AISCG acts as a processor, the relevant client will generally remain the controller of the personal data concerned. We will process that data only in accordance with the client's documented instructions and applicable data-protection law.

Contact details

If you have any questions about this privacy policy or our privacy practices, please contact us in the following ways:

Full name of legal entity: AI Strategy and Compliance Group Limited

Company number: 17394411

Registered office: Suite 2, Teal House, BW Consultants Ltd, Duck Island Lane, Ringwood, Hampshire, BH24 3AA

Email address: hello@aiscg.co.uk

You have the right to make a complaint at any time to the Information Commissioner's Office (ICO), the UK regulator for data protection issues (www.ico.org.uk). We would, however, appreciate the chance to deal with your concerns before you approach the ICO, so we ask you to please contact us in the first instance.

Changes to the privacy policy and your duty to inform us of changes

We keep our privacy policy under regular review. It is important that the personal data we hold about you is accurate and current. Please keep us informed if your personal data changes during your relationship with us.

Third-party links

Our website may include links to third-party websites, plug-ins and applications. Clicking on those links or enabling those connections may allow third parties to collect or share data about you. We do not control these third-party websites and are not responsible for their privacy statements. When you leave our website, we strongly encourage you to read the privacy policy of every website you visit.

The data we collect about you

Personal data

Personal data means information relating to an identified or identifiable individual. It does not include information that has been anonymised so that an individual can no longer be identified.

Depending on our relationship with you and the services we provide, we may process personal data relating to

  • prospective, current and former clients;

  • client representatives and other business contacts;

  • client employees, workers, contractors and other personnel;

  • individuals involved in HR, employment, AI governance or compliance assessments;

  • individuals involved in workplace investigations, employee-relations matters or compliance reviews;

  • job applicants and recruitment candidates, where relevant to our services;

  • suppliers, consultants, subcontractors and professional advisers;

  • website users;

  • event attendees;

  • newsletter subscribers and marketing contacts;

  • individuals who contact us or provide feedback; and

  • other individuals whose personal data is provided to us in connection with a consultancy engagement.

In certain circumstances, our collection of the different categories of data set out above may include the collection of Special Categories of Personal Data about you (this includes details about your race or ethnicity, religious or philosophical beliefs, sex life, sexual orientation, political opinions, trade union membership, information about your health, and genetic and biometric data). We also may collect Criminal Convictions and Offences Data. We will seek to collect and use only personal data that is reasonably necessary for the relevant purpose.

We will only process special category data where it is necessary, proportionate and lawful. Where required, we will identify an appropriate Article 6 lawful basis and an applicable Article 9 condition under the UK GDPR, together with any additional condition or safeguards required under the Data Protection Act 2018.

Where criminal offence data is processed, we will comply with the requirements applicable to such processing under the UK GDPR and Data Protection Act 2018.

Where AISCG acts as a processor, the relevant client will generally determine the lawful basis and applicable conditions for processing the personal data concerned, and AISCG will process the information in accordance with the client's documented instructions.

If you fail to provide personal data

Where we need to collect personal data by law, or under the terms of our engagement with you, and you fail to provide that data when requested, we may not be able to provide some or all of the services or perform the relevant contractual obligations.

Where AISCG is acting as a processor, the relevant client may determine what information is necessary for the relevant processing activity.

How we collect your personal data

We use different methods to collect data from and about you including:

  • Carrying out our AI and HR compliance consultancy services where we will in almost all instances act as a controller of that personal data.

  • When we communicate with you by email or other electronic correspondence, by telephone or using video conferencing software.

  • You may give us your personal data by filling in forms or by corresponding with us by post, phone, email or otherwise. This includes personal data you provide when you:

    • make a request for our services;

    • subscribe to our publications;

    • request marketing to be sent to you;

    • complete a survey; or

    • provide us with feedback.

  • Networking (for example, at in-person or virtual events).

  • Identity and Contact Data from publicly available sources such as Companies House;

  • Through third parties or publicly available sources.

  • Through your actions (for example, when submitting a subscription form or contact us form).

  • Through automated technologies or interactions. As you interact with our website, we will automatically collect Technical Data about your equipment, browsing actions and patterns. We collect this personal data by using cookies and other similar technologies. See the Cookies section below for further details.

  • Technical Data from our analytics provider.

Information provided by clients

In connection with consultancy engagements, clients may provide us with personal data relating to their employees, workers, contractors, applicants, customers or other individuals.

This may include information from HR, legal, compliance, management or other business functions.

Where we process this information solely on behalf of a client, we may act as the client's processor.

Information from other people

We may receive personal data from:

  • colleagues, managers or other representatives of a client;

  • witnesses or individuals involved in workplace matters;

  • suppliers, consultants or subcontractors;

  • professional advisers;

  • event organisers;

  • referees or other contacts;

  • persons who refer you to us; and

  • other individuals who provide information in connection with our services.

Publicly available information

We may obtain business and professional information from publicly available sources, including:

  • Companies House;

  • professional websites;

  • publicly available business websites;

  • professional networking platforms; and

  • other publicly available sources.

Automatically collected information

When you use our website, we may automatically collect Technical Data and Usage Data through cookies and similar technologies.

Further information is provided in the Cookies section below.

How we use your personal data

We will only use your personal data when the law allows us to. Most commonly, we will use your personal data in the following circumstances:

  • Contract, where processing is necessary to enter into or perform a contract with you;

  • Legitimate interests, where processing is necessary for our legitimate interests or those of a third party and those interests are not overridden by your interests, rights or freedoms;

  • Legal obligation, where processing is necessary to comply with a legal obligation to which we are subject;

  • Consent, where we have obtained valid consent and consent is the appropriate lawful basis;

  • another lawful basis where permitted by applicable data-protection law.

Where we process special category data, we will also identify an appropriate Article 9 condition where required.

Where we process criminal offence data, we will comply with the additional requirements applicable to such processing.

Except as set out above, we do not generally rely on consent as a legal basis for processing your personal data.

Purposes for which we will use your personal data

We have set out below, in a table format, a description of the ways we plan to use your personal data, and which of the legal bases we rely on to do so.

We may process your personal data for more than one lawful basis depending on the specific purpose for which we are using your data. Contact us if you need details about the specific legal basis we are relying on to process your personal data where more than one ground has been set out in the table below.

Purpose or activityType of dataLawful basis for processing including basis of legitimate interest
Responding to enquiriesIdentity, contact, correspondenceLegitimate interests or steps before entering into a contract
Establishing and managing client relationshipsIdentity, contact, professional and contractual informationContract and/or legitimate interests
Providing consultancy servicesClient contact details, project information, relevant employee dataContract; processor instructions where applicable
Reviewing client HR or workforce informationEmployee, worker or applicant information relevant to the engagementDetermined by the client where AISCG acts as processor; otherwise an applicable Article 6 basis
Managing client accounts and invoicesIdentity, contact, transaction dataContract; legal obligation
Managing suppliers and professional advisersIdentity, contact, professional and transaction dataContract and/or legitimate interests
Compliance and conflict checksIdentity, contact, business informationLegal obligation and legitimate interests
Maintaining business and professional recordsIdentity, contact, correspondence and engagement informationLegitimate interests and/or legal obligation
Website security and administrationTechnical and usage dataLegitimate interests; legal obligation where applicable
Managing marketing preferencesIdentity, contact, marketing preferencesConsent or legitimate interests where legally permitted
Processing special category dataRelevant HR or sensitive dataArticle 6 basis plus appropriate Article 9 condition

The precise lawful basis may vary depending on the particular circumstances. If you require further information about the lawful basis applicable to a particular processing activity, you can contact us.

AI, automation and technology

Because AI and technology form part of our business and consultancy services, we may use artificial intelligence, automation and other technology in appropriate circumstances.

This may include using technology to assist with:

  • document review and analysis;

  • summarising information;

  • identifying themes or patterns;

  • preparing draft materials;

  • research;

  • compliance assessments;

  • quality assurance;

  • administrative tasks; and

  • other consultancy or business activities.

Where AI-enabled tools process personal data, we will take appropriate steps to ensure that their use is lawful, proportionate and consistent with our contractual and confidentiality obligations.

Depending on the circumstances, this may include:

  • assessing the suitability and security of an AI tool before use;

  • minimising the personal data provided to the tool;

  • using anonymised or pseudonymised information where appropriate;

  • applying access controls;

  • considering where the provider processes the information;

  • checking the provider's contractual and data-protection arrangements;

  • maintaining appropriate human oversight; and

  • taking reasonable steps to assess the accuracy and reliability of AI-generated outputs.

We will not treat AI-generated information as inherently accurate and will apply appropriate human review where the nature of the task requires it.

Client data and AI tools

As part of our consultancy services and internal business operations, AISCG may use artificial intelligence (AI) and AI-enabled tools, including Anthropic Claude, Microsoft Copilot and other AI services, to assist with activities such as summarising information, identifying themes or trends, analysing documents, preparing draft materials, supporting research, and developing consultancy outputs.

Where personal data is processed using AI tools, AISCG will take appropriate steps to ensure that the processing is lawful, proportionate and consistent with our contractual and confidentiality obligations. We will seek to minimise the personal data submitted to AI tools and, where appropriate, use anonymised, pseudonymised or otherwise minimised information.

Where AISCG is acting as a processor on behalf of a client, we will only use AI tools to process the client's personal data where this is authorised by the client and permitted by the applicable contract, data processing agreement and instructions. We will consider the security, confidentiality, data retention, data-use and international-transfer arrangements applicable to the AI service before using it for personal data.

We will use appropriate access controls and human oversight when AI tools are used in our work. AI-generated content will not be treated as inherently accurate, complete or suitable for decision-making without appropriate human review. Where AI is used to assist with HR, employment, compliance or other matters affecting individuals, outputs will be reviewed by appropriately qualified personnel and will not be relied upon without considering the relevant context and evidence.

AISCG does not ordinarily make decisions about individuals based solely on automated processing where those decisions have legal or similarly significant effects. Where such processing is proposed or becomes necessary, AISCG will assess the applicable legal requirements and implement the safeguards required by data protection law.

The AI services we use may process information on our behalf or, depending on the service and configuration, act as an independent controller for certain processing. The applicable privacy notice, contractual terms and data protection arrangements of the relevant provider will therefore also apply. We will not knowingly use an AI service in a way that is inconsistent with applicable data protection law, our contractual obligations or a client's documented instructions.

Marketing communications

We may use personal data to communicate with you about our services, events, publications and other information that may be relevant to you.

We will comply with applicable data-protection and electronic-marketing requirements, including the Privacy and Electronic Communications Regulations ("PECR"), when sending electronic marketing.

Depending on the circumstances, we may rely on consent or another lawful basis permitted by applicable law. Where we rely on a form of consent, you may withdraw your consent at any time.

Where we rely on a lawful form of existing-customer or business-to-business marketing, we will ensure that the relevant legal requirements are met.

Third-party marketing

We will not share your personal data with third parties for their own direct-marketing purposes unless we have a lawful basis to do so and, where required, have obtained your consent.

Opting out

  • You can ask us to stop sending marketing communications at any time.

  • You can do this by contacting us or, where available, using the unsubscribe facility included in our marketing communications.

  • You have an absolute right to object to the processing of your personal data for direct marketing purposes.

Change of purpose

  • We will normally use your personal data only for the purposes for which we collected it.

  • If we need to use your personal data for another purpose, we will consider whether that purpose is compatible with the original purpose and whether another lawful basis or other information is required.

  • Where appropriate, we will provide you with additional information before undertaking the new processing.

  • We may process personal data without your knowledge or consent where this is required or permitted by law.

Confidentiality and client information

Our consultancy engagements may involve confidential business information, intellectual property and commercially sensitive information that is not personal data.

  • Such information is handled in accordance with our contractual confidentiality obligations, professional standards and applicable law.

This privacy notice relates to personal data. Confidential or commercially sensitive information that does not constitute personal data may be subject to separate contractual confidentiality provisions.

Where we act as a processor, the relevant client's instructions and data-processing agreement will govern the processing of personal data on that client's behalf.

Disclosures of your personal data

We may share your personal data with the parties set out below:

  • other companies that form, or may form in the future, the AISCG group and who are based in the UK.

  • external third parties such as:

    • service providers acting as processors who provide services such as marketing agencies and IT and system administration services;

    • professional advisers acting as processors including accountants, legal services providers, bankers, auditors and insurers who provide services to us;

    • HM Revenue & Customs, regulators and professional bodies who require reporting of processing activities in certain circumstances;

  • Third parties to whom we may choose to sell, transfer or merge parts of our business or our assets. Alternatively, we may seek to acquire other businesses or merge with them. If a change happens to our business, then the new owners may use your personal data in the same way as set out in this privacy policy.

We require all third parties to respect the security of your personal data and to treat it in accordance with the law. We do not allow our third-party service providers to use your personal data for their own purposes and only permit them to process your personal data for specified purposes and in accordance with our instructions.

Depending on the circumstances, these organisations may act as our processors, sub processors or independent controllers.

Where a third party acts as our processor, we will require it to process personal data in accordance with our documented instructions, maintain appropriate confidentiality and implement appropriate security measures.

Where a third party acts as an independent controller, it will be responsible for its own processing in accordance with applicable law.

International transfers

Some of our external third parties are based outside the UK so their processing of your personal data will involve a transfer of data outside the UK.

Whenever we transfer your personal data out of the UK, we ensure a similar degree of protection is afforded to it by ensuring at least one of the following safeguards is implemented:

  • We will only transfer your personal data to countries that have been deemed to provide an adequate level of protection for personal data.

  • Where we use certain service providers, we may use specific contracts approved for use in the UK which give personal data the same protection it has in the UK.

Data security

We have put in place appropriate security measures to prevent your personal data from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. In addition, we limit access to your personal data to those employees, agents, contractors and other third parties who have a business need to know. They will only process your personal data on our instructions and they are subject to a duty of confidentiality.

We have put in place procedures to deal with any suspected personal data breach and will notify you and any applicable regulator of a breach where we are legally required to do so.

Data retention

We will only retain your personal data for as long as reasonably necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, regulatory, tax, accounting or reporting requirements. We may retain your personal data for a longer period in the event of a complaint or if we reasonably believe there is a prospect of litigation in respect to our relationship with you.

To determine the appropriate retention period for personal data, we consider the amount, nature and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure of your personal data, the purposes for which we process your personal data and whether we can achieve those purposes through other means, and the applicable legal, regulatory, tax, accounting or other requirements.

In some circumstances you can ask us to delete your data. Our retention schedule is set out at the end of this notice.

We may, in some instances, anonymise your personal data (so that it can no longer be associated with you) for research or statistical purposes, in which case we may use this information indefinitely without further notice to you.

Your data protection rights

Under certain circumstances, you have rights under data protection laws in relation to your personal data to:

Request access to your personal data (commonly known as a "data subject access request"). This enables you to receive a copy of the personal data we hold about you and to check that we are lawfully processing it.

Request correction of the personal data that we hold about you. This enables you to have any incomplete or inaccurate data we hold about you corrected, though we may need to verify the accuracy of the new data you provide to us.

Request erasure of your personal data. This enables you to ask us to delete or remove personal data where there is no good reason for us continuing to process it. You also have the right to ask us to delete or remove your personal data where you have successfully exercised your right to object to processing (see below), where we may have processed your information unlawfully or where we are required to erase your personal data to comply with local law. Note, however, that we may not always be able to comply with your request of erasure for specific legal reasons which will be notified to you, if applicable, at the time of your request.

Object to processing of your personal data where we are relying on a legitimate interest (or those of a third party) and there is something about your particular situation which makes you want to object to processing on this ground as you feel it impacts on your fundamental rights and freedoms. You also have the right to object where we are processing your personal data for direct marketing purposes. In some cases, we may demonstrate that we have compelling legitimate grounds to process your information which override your rights and freedoms.

Request restriction of processing of your personal data. This enables you to ask us to suspend the processing of your personal data in the following scenarios:

  • If you want us to establish the data's accuracy.

  • Where our use of the data is unlawful but you do not want us to erase it.

  • Where you need us to hold the data even if we no longer require it as you need it to establish, exercise or defend legal claims.

  • You have objected to our use of your data but we need to verify whether we have overriding legitimate grounds to use it.

Request the transfer of your personal data to you or to a third party. We will provide to you, or a third party you have chosen, your personal data in a structured, commonly used, machine-readable format. This right only applies to automated information which you initially provided consent for us to use or where we used the information to perform a contract with you.

Withdraw consent at any time where we are relying on consent to process your personal data. However, this will not affect the lawfulness of any processing carried out before you withdraw your consent. If you withdraw your consent, we may not be able to provide certain services to you. We will advise you if this is the case at the time you withdraw your consent.

If you wish to exercise any of the rights set out above, contact us.

Where AISCG acts as a processor

If we process your personal data solely on behalf of one of our clients, the client will generally be responsible for responding to your rights request as the controller.

Where appropriate, we may refer your request to the relevant client and assist that client in responding in accordance with applicable law and our contractual arrangements.

How to exercise your rights

If you wish to exercise any of your rights, please contact us using the details under Contact details above.

You do not normally have to pay a fee to exercise your rights.

However, where permitted by law, we may charge a reasonable fee or refuse to act on a request that is manifestly unfounded or excessive.

Identity verification

We may ask you for information reasonably necessary to verify your identity before responding to a request.

This is a security measure designed to prevent personal data from being disclosed to someone who is not entitled to receive it.

Time limit for responding

We will normally respond to a valid request within one month of receiving it.

Where permitted by law, this period may be extended by up to a further two months where the request is complex or we have received a number of requests.

If an extension is necessary, we will inform you within the initial one-month period and explain why the extension is required.

Cookies

Our website sets no non-essential cookies. We do not use advertising cookies, tracking cookies or a cookie consent banner, because there is nothing to consent to.

A cookie is a small text file placed on your device when you visit a website. Similar rules apply to other technologies that store information on or access information from your device.

The website may set strictly necessary cookies or use similar technologies that are needed for it to function, such as protecting the contact form from automated abuse. These are exempt from the consent requirement.

To understand how visitors use our website we use Plausible Analytics, a privacy-focused analytics service. Plausible does not use cookies, does not store anything on your device, does not collect personal data and does not track visitors across websites. It records aggregate information such as page views, referring sites, browser type and country, and the data is hosted within the UK and EU. Because it stores nothing on your device, the consent requirements that apply to analytics cookies do not apply to it.

If we introduce any cookie or similar technology in future that requires consent, we will update this notice and obtain consent before setting it.

If you have any questions or concerns about our use of cookies, please contact us.

Data minimisation, accuracy and human oversight

We seek to collect and process only personal data that is adequate, relevant and reasonably necessary for the purposes for which it is processed.

We take reasonable steps to ensure that personal data is accurate and kept up to date where necessary.

Where our services involve AI, automation or analytical tools, we will apply appropriate human oversight and reasonable checks appropriate to the nature and sensitivity of the processing.

AI-generated or automated outputs will not automatically be treated as accurate or determinative.

Retention schedule

We retain personal data only for as long as reasonably necessary for the purposes for which it was collected, including where necessary to satisfy legal, regulatory, tax, accounting, insurance or reporting requirements.

We may retain information for longer where necessary to establish, exercise or defend legal claims, deal with complaints or disputes, or comply with other legal requirements.

Our retention periods will depend on the nature of the information and the purpose for which it is processed.

Indicative retention categories include:

CategoryRetention approach
Client and contract recordsFor the duration of the relationship and for an appropriate period afterwards where required for legal, regulatory, insurance or legal-claims purposes
Financial and accounting recordsIn accordance with applicable legal and accounting requirements
Enquiry recordsFor as long as reasonably necessary to manage the enquiry and any resulting relationship
Marketing recordsUntil you unsubscribe or the information is no longer required, subject to applicable suppression requirements
Consultancy working papersIn accordance with our documented retention schedule, contractual obligations and professional requirements
Client HR information where AISCG acts as processorIn accordance with the client's documented instructions and applicable contractual arrangements
Complaints and legal claimsFor as long as reasonably necessary to investigate, resolve and defend the matter
Cookie and website dataIn accordance with the applicable cookie settings and retention periods
Consent and marketing preference recordsFor as long as necessary to demonstrate and respect your preferences