Privacy Policy

Last updated: 20 January 2026

Insightful AI Solutions Limited (“we”, “our”, “us”) is committed to protecting your privacy. This privacy policy explains how we collect, use, store, and protect your personal data when you use our website.

Who we are

Insightful AI Solutions Limited
Registered office: Suite 7 Marbury House Farm, Bentleys Farm Lane, Higher Whitley, Warrington, Cheshire, WA4 4QW
Company number: 16377460
ICO registration number: ZB914449

For privacy queries, contact us at hello@insightfulai.co.uk

What data we collect

We collect personal data when you interact with our website. The data we collect includes:

Contact forms:

  • Your name
  • Your email address
  • Your organisation name
  • Your phone number (if provided)
  • Any information you include in your message


Newsletter signup:

  • Your email address
  • Your name (if provided)


Website usage data:

  • IP address
  • Browser type and version
  • Device information
  • Pages visited and time spent on pages
  • Referring website
  • Date and time of visit


Cookies:
We use cookies to understand how you interact with our website, keep our services secure, and improve your experience. See our cookie policy below for details.

How we use your data

Contact form enquiries: We use your data to respond to your enquiry, provide information about our services, and follow up on potential consultancy work.

Our legal basis for processing this data depends on the nature of your enquiry:

  • If you are enquiring about our services as a prospective client, we process your data based on legitimate interests (responding to business enquiries and managing potential client relationships)
  • If you are an existing client or discussing specific work, we process your data based on contract performance (fulfilling our contractual obligations) or taking steps to enter into a contract


Newsletter:
We use your email address to send you updates about AI governance, regulatory changes, and our services.

Our legal basis for processing this data is:

  • Consent: If you have subscribed to our newsletter through our website signup form, we rely on your explicit consent. You can withdraw consent and unsubscribe at any time using the link in every email.
  • Soft opt-in (for existing clients): If you are an existing client, we may send you information about similar services to those you have purchased from us, unless you have opted out. This is permitted under the Privacy and Electronic Communications Regulations (PECR). You can opt out at any time using the unsubscribe link in every email.


Website analytics:
We use Google Analytics and Microsoft Clarity to understand how visitors use our website. This helps us improve the site and identify technical issues. Our legal basis for processing this data is legitimate interests (improving our website).

Payment processing: We do not collect or store payment card details. All payments are processed by Stripe, which handles your payment information securely according to their privacy policy.

Who we share your data with

We share your data with the following third parties:

Beehiiv: Our newsletter platform. When you subscribe to our newsletter, your email address is stored on Beehiiv’s servers (located in the United States). Beehiiv is certified under the EU-US Data Privacy Framework.

Stripe: Our payment processor. When you make a payment, Stripe processes your payment details according to their privacy policy. We never see or store your full payment card details.

Google Analytics: We use Google Analytics to track website usage. Google processes data according to their privacy policy. Analytics data is anonymised where possible.

Microsoft Clarity: We use Microsoft Clarity for website analytics. Microsoft processes data according to their privacy policy.

We do not sell your data to third parties. We do not share your data with marketing partners or use it for purposes beyond those stated in this policy.

Where we store your data and international transfers

UK-based storage: Contact form data and enquiry information is stored on UK-based servers in London.

International transfers: Some of the third parties we use to process your data are located outside the UK. We ensure these transfers comply with UK GDPR requirements through appropriate safeguards:

Beehiiv (United States): Newsletter subscriber data is stored on Beehiiv’s servers in the United States. Beehiiv is certified under the EU-US Data Privacy Framework, which the UK government recognises as providing adequate protection for international data transfers.

Google Analytics (United States): Website analytics data is processed by Google in the United States. We have entered into Google’s Data Processing Amendment, which incorporates the UK International Data Transfer Agreement (UK IDTA) and EU Standard Contractual Clauses (SCCs) to ensure your data is protected to UK GDPR standards.

Microsoft Clarity (United States): Website analytics data is processed by Microsoft in the United States. Microsoft’s Data Protection Addendum incorporates the UK International Data Transfer Agreement (UK IDTA) and EU Standard Contractual Clauses to safeguard your data.

Stripe (United States and EU): Payment data is processed by Stripe, which operates servers in both the United States and the European Union. Stripe’s Data Processing Agreement includes UK IDTA and Standard Contractual Clauses to protect data transferred outside the UK.

You can request copies of the specific safeguards we have in place for international transfers by contacting hello@insightfulai.co.uk

How long we keep your data

Contact form enquiries: We retain enquiry data for three years from the date of your last contact with us. This allows us to maintain a record of previous conversations and provide continuity if you contact us again.

Newsletter subscribers: We retain your email address until you unsubscribe from our newsletter.

Website analytics: Analytics data is retained for 26 months, after which it is automatically deleted.

Payment records: We retain basic payment records (transaction date, amount, invoice number) for seven years to comply with UK tax and accounting requirements. Full payment details are held by Stripe according to their retention policy.

If you would like us to delete your data sooner, contact us at hello@insightfulai.co.uk

Your rights

Under UK GDPR, you have the following rights:

Right to access: You can request a copy of the personal data we hold about you.

Right to rectification: You can ask us to correct inaccurate or incomplete data.

Right to erasure: You can ask us to delete your data in certain circumstances.

Right to restrict processing: You can ask us to limit how we use your data.

Right to data portability: You can ask for your data in a machine-readable format.

Right to object: You can object to our processing of your data based on legitimate interests.

Right to withdraw consent: Where we process your data based on consent (such as newsletter signup), you can withdraw consent at any time.

To exercise any of these rights, contact us at hello@insightfulai.co.uk. We will respond within 30 days.

Data protection complaints procedure

If you have a concern about how we handle your personal data, we encourage you to contact us first so we can resolve the issue.

How to complain:

You can submit a data protection complaint by:

  • Emailing hello@insightfulai.co.uk with “Data Protection Complaint” in the subject line
  • Writing to us at: Data Protection Complaint, Insightful AI Solutions Limited, Suite 7 Marbury House Farm, Bentleys Farm Lane, Higher Whitley, Warrington, Cheshire, WA4 4QW


What happens next:

  1. We will acknowledge receipt of your complaint within 30 days
  2. We will investigate your concern and review our processing activities
  3. We will provide you with a full written response explaining our findings and any actions we have taken
  4. If you remain dissatisfied with our response, you have the right to escalate your complaint to the Information Commissioner’s Office


Escalating to the ICO:

If you are unhappy with how we have handled your complaint, you can contact the Information Commissioner’s Office at:

  • Website: ico.org.uk
  • Telephone: 0303 123 1113
  • Post: Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF

Security

We take reasonable steps to protect your data from unauthorised access, loss, or misuse.

Technical safeguards:

  • Contact form data is transmitted using SSL/TLS encryption
  • Access to personal data is restricted to authorised personnel only (limited to our core team)
  • Our website hosting and data storage providers use industry-standard security measures including firewalls, intrusion detection, and encrypted data storage
  • We maintain regular backups of data to prevent loss


Organisational safeguards:

  • Staff who handle personal data are trained in data protection requirements
  • We review and update our security measures regularly to address new threats
  • Access to systems containing personal data is protected by strong passwords and authentication

However, no internet transmission is completely secure. We cannot guarantee the security of data transmitted to our website. Once we receive your data, we use appropriate technical and organisational measures to protect it.

Cookies

Our website uses cookies to improve your experience and understand how you use the site.

What are cookies? Cookies are small text files stored on your device when you visit a website. They help websites remember your preferences and track usage.

What cookies do we use?

Strictly necessary cookies: These cookies are essential for the website to function. They enable basic features like page navigation, access to secure areas, and security functions. The website cannot function properly without these cookies. Under the Privacy and Electronic Communications Regulations (PECR), we do not need your consent to use strictly necessary cookies.

Analytics cookies: We use Google Analytics and Microsoft Clarity to track website usage. These cookies collect information about which pages you visit, how long you spend on the site, and how you found us. This helps us improve the website. We anonymise IP addresses where possible to protect your privacy.

Under PECR, we obtain your consent for analytics cookies through our cookie banner when you first visit the website.

Third-party cookies: Some cookies are set by third-party services that appear on our pages (Google Analytics, Microsoft Clarity, Beehiiv). These services have their own privacy policies governing how they use cookies:

  • Google Analytics privacy policy: policies.google.com/privacy
  • Microsoft Clarity privacy policy: privacy.microsoft.com
  • Beehiiv privacy policy: beehiiv.com/privacy


Managing cookies:
You can control cookies through your browser settings. Most browsers allow you to:

  • View what cookies are stored and delete them individually
  • Block third-party cookies
  • Block all cookies
  • Delete all cookies when you close your browser

However, disabling certain cookies may affect website functionality. Strictly necessary cookies cannot be disabled if you wish to use our website.

For more information about cookies and how to manage them, visit www.aboutcookies.org or www.allaboutcookies.org

Changes to this policy

We may update this privacy policy from time to time. When we make changes, we will update the “Last updated” date at the top of this page.

If we make significant changes to how we process your data, we will notify newsletter subscribers by email.

Contact us

For questions about this privacy policy or how we handle your data, contact us at:

Email: hello@insightfulai.co.uk
Address: Suite 7 Marbury House Farm, Bentleys Farm Lane, Higher Whitley, Warrington, Cheshire, WA4 4QW

For data protection queries or complaints, you can also contact the Information Commissioner’s Office:

Website: ico.org.uk

Telephone: 0303 123 1113

Post: Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF