Privacy Policy
ACQI.AI LTD ("**ACQI**", "**we**", "**us**", "**our**") explains here how we process personal data when you visit **acqi.ai**, use **app.acqi.ai**, request a demo, communicate with us, or use the ACQI platform products (Discovery, Migration, Governance, and related modules, including the ARIA AI co-pilot where enabled).
{{EFFECTIVE_DATE}}— to be confirmed before final publication{{ICO_REGISTRATION_NUMBER}}— to be confirmed before final publication{{LAST_UPDATED}}— to be confirmed before final publication{{LEGAL_EMAIL}}— to be confirmed before final publication{{PRIVACY_EMAIL}}— to be confirmed before final publication{{REGISTERED_OFFICE_ADDRESS}}— to be confirmed before final publication{{TRADECO_COMPANY_NUMBER}}— to be confirmed before final publication
Page is published for transparency; founder will fill these before the final version goes out under counsel review.
# Privacy Policy
Effective date: {{EFFECTIVE_DATE}} Last updated: {{LAST_UPDATED}} Controller: ACQI.AI LTD ("ACQI", "we", "us", "our")
| Company | ACQI.AI LTD |
|---|---|
| Company number | {{TRADECO_COMPANY_NUMBER}} |
| Registered office | {{REGISTERED_OFFICE_ADDRESS}} |
| Privacy contact | {{PRIVACY_EMAIL}} |
| ICO registration | {{ICO_REGISTRATION_NUMBER}} (if registered) |
This Privacy Policy explains how we process personal data when you visit acqi.ai, use app.acqi.ai, request a demo, communicate with us, or use the ACQI platform products (Discovery, Migration, Governance, and related modules, including the ARIA AI co-pilot where enabled).
Important architecture note. ACQI is desktop-first. Credentials you supply for scanning customer IT environments are designed to remain on your device. Customer estate discovery data is typically processed under your control. Separate rules apply when we act as a processor under a Master Services Agreement and Data Processing Agreement — see Section 4 and our DPA overview.
---
1.Scope
This Policy covers personal data we process as a controller, including:
- Website visitors and marketing contacts
- Prospective customers and demo requesters
- User accounts for the ACQI application
- Support, security, and sales correspondence
- Event and webinar attendees
- Suppliers and partners (business contact data)
It does not replace the customer-facing Data Processing Agreement (DPA) that governs personal data inside a customer’s IT estate when we process that data on the customer’s documented instructions.
---
2.Categories of personal data we collect
2.1 Data you provide
| Category | Examples |
|---|---|
| Account | Username, authentication identifiers, role/permissions metadata |
| Commercial | Demo requests, RFP content, contract signatory details, billing contacts |
| Communications | Emails, meeting notes, support tickets, feedback |
| Marketing preferences | Opt-in/out, cookie consent choices |
2.2 Data collected automatically
| Category | Examples |
|---|---|
| Usage | Pages viewed, feature usage events, crash diagnostics (if enabled) |
| Cookies / similar tech | See Cookie Policy |
2.3 Data we do not intentionally collect via the website
- Payment card data on acqi.ai (enterprise invoicing / off-site payment processors if used)
- Special category data (health, biometrics, etc.) — please do not submit it via forms
- Credentials for your Azure/AD/M365/AWS environments via marketing forms
2.4 Customer IT-estate data (discovery / migration / governance)
When you run discovery or related modules against an environment you control or are authorised to assess, the Platform may process employee and IT inventory personal data (for example names, UPNs, email addresses, device names, group memberships, mailbox metadata, license assignments).
Roles:
| Scenario | Our role | Your role |
|---|---|---|
| You transmit estate data to ACQI-hosted services under an MSA | Processor (Art 28) | Controller |
| Website lead capture / account identity | Controller | Data subject / business contact |
Credentials used to authenticate to target systems are designed to be stored locally on the endpoint (OS-protected storage where available) and not uploaded to ACQI as part of normal discovery operation. If a future feature requires credential escrow or cloud-hosted agents, we will update this Policy and obtain contractual coverage before enabling it.
---
3.Purposes and legal bases (UK GDPR / EU GDPR)
| Purpose | Legal basis (Art 6) |
|---|---|
| Respond to demo / sales / support requests | Contract steps / legitimate interests |
| Perform paid services under MSA/SOW | Contract |
| Process customer estate personal data as processor | Contract with customer; customer ensures a lawful basis for data subjects |
| Secure systems, prevent abuse, debug | Legitimate interests — security and service integrity |
| Product analytics (aggregated / product improvement) | Legitimate interests or consent where required (cookies) |
| Marketing emails to business contacts | Soft opt-in / legitimate interests where lawful; otherwise consent. You may opt out any time |
| Comply with law (tax, court, ICO, Companies House) | Legal obligation (Art 6(1)(c)) |
| Defend legal claims | Legitimate interests / legal claims |
We do not sell personal data.
---
4.Processor activities (enterprise customers)
Where ACQI processes personal data on your behalf inside the Platform:
- Processing is governed by the MSA and DPA (Art 28 UK GDPR / EU GDPR).
- We process only on documented instructions.
- Subprocessors are listed at Subprocessors and in DPA Annex B–2.
- We assist with data subject requests, breaches, and deletion/return as set out in the DPA.
- We do not use customer estate personal data to train foundation models for other customers (see AI Features Disclosure and DPA clause on model training).
Request the full DPA: {{LEGAL_EMAIL}}.
---
5.AI features (ARIA and related)
Optional AI features may send prompts and selected context to a model provider acting as our subprocessor.
- Do not paste secrets, passwords, or regulated data into AI chats unless your organisation’s policy and the DPA allow it.
- AI outputs are assistive, not legal, financial, or security advice.
- See AI Features Disclosure.
---
6.Sharing and recipients
We may share personal data with:
| Recipient | Why |
|---|---|
| AI model providers | Only if you use AI features that call them |
| Professional advisers | Legal, accounting, insurance |
| Corporate group | ACQI HOLDINGS LTD as needed for governance — subject to confidentiality |
| Regulators / courts | When legally required |
| Acquirers | In a merger/sale of business, under appropriate safeguards |
We require processors to protect data under written terms (Art 28).
---
7.International transfers
We are established in the United Kingdom. Personal data may be transferred to the EEA, US, or other countries where our subprocessors operate.
Where required, we use:
- UK adequacy regulations / decisions
- UK International Data Transfer Agreement (IDTA) or UK Addendum to EU SCCs
- EU Standard Contractual Clauses (for EU GDPR flows)
- Supplementary measures (encryption in transit/at rest) as appropriate
Details for enterprise processing: DPA clause on international transfers.
---
8.Retention
| Data | Typical retention |
|---|---|
| Customer contract / billing | Term + up to 7 years (tax / legal) |
| Support tickets | Up to 3 years after closure unless longer needed for disputes |
| Security logs | Typically 12–24 months |
| Cookie consent records | Duration of consent + evidence period |
| Processor data (customer estate) | Per DPA / SOW — generally delete or return within 30 days after end of processing, subject to legal holds and encrypted backups (≤ 90 days) |
---
9.Security
We implement technical and organisational measures appropriate to risk, including access control, encryption in transit (TLS), encryption at rest for hosted components where used, least-privilege access, and staff confidentiality obligations.
Desktop-first controls for credentials are a core design goal. No security measure is perfect; please see Security & Trust.
We do not claim SOC 2, ISO 27001, or similar certifications on this site unless and until independently attained and listed here.
---
10.Your rights
Depending on your location (UK GDPR / EU GDPR / other laws), you may have rights to:
- Access
- Rectification
- Erasure
- Restriction
- Portability
- Object (including to direct marketing)
- Withdraw consent
- Lodge a complaint with a supervisory authority
UK supervisory authority: Information Commissioner’s Office (ICO) — https://ico.org.uk
To exercise rights: email {{PRIVACY_EMAIL}}. We may need to verify identity.
If we process data as a processor, we will redirect data subject requests to the relevant controller (usually your employer or the customer organisation), except where law requires us to act.
California / US state privacy (if applicable)
If you are a California resident and we are subject to the CCPA/CPRA for your data: we do not “sell” or “share” personal information for cross-context behavioural advertising as those terms are defined, unless we update this Policy and provide required notices/opt-outs. Contact {{PRIVACY_EMAIL}} for requests to know, delete, or correct.
---
11.Children
The Platform and website are B2B services not directed at children under 16. We do not knowingly collect children’s data.
---
12.Automated decision-making
We do not use website or account personal data for solely automated decisions that produce legal or similarly significant effects about you (Art 22). AI features produce recommendations for human review in an M&A / IT context — customers remain responsible for decisions.
---
13.Third-party sites
Links to third-party sites (e.g. Microsoft, AWS, LinkedIn) are governed by those parties’ policies.
---
14.Changes
We may update this Policy. Material changes will be indicated by updating Last updated and, where appropriate, additional notice (email or in-app). Continued use after the effective date constitutes acknowledgment of the updated Policy where permitted by law.
---
15.Contact
| Privacy | {{PRIVACY_EMAIL}} |
|---|---|
| Postal | ACQI.AI LTD, {{REGISTERED_OFFICE_ADDRESS}} |
---
Draft for solicitor review. Not legal advice. Align with incorporation-pack DPA (doc 19) before processing customer estate personal data.