THE AI PRACTITIONER
← All policies

Privacy Policy

Reference
AIP-PS-001 · Version 1.0
Effective
1 September 2026
Owner
Tim Parkin, Director
Next review
1 September 2027, or sooner on material change
Applies to
theaipractitioner.ai and all personal data processed in the course of AIP's business

1. Introduction

Groundframe Ltd (company number 09715227), registered office 49 Station Road, Polegate, East Sussex, BN26 6EA, United Kingdom, trading as The AI Practitioner (“AIP”, “we”, “us”, “our”), is the Data Controller responsible for your personal data under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

Groundframe Ltd t/a The AI Practitioner is the Data Controller for all personal data described in this policy, without exception. Where AIP engages other organisations to process personal data on our behalf — for example the technology and professional-service providers listed in Section 12 — those organisations act only as Processors, under our instructions and subject to written processor terms; they do not become Controllers of that data.

Tim Parkin, Director, is AIP’s policy owner and designated privacy contact, and the operational lead for data protection matters. He acts on behalf of Groundframe Ltd as Data Controller; he is not personally the Data Controller and is not personally the contracting party for AIP’s services.

This policy explains what personal data we collect, why we collect it, how we use it, and the rights you have over it. It applies to visitors to theaipractitioner.ai, prospective and current clients, and anyone else whose personal data we process in the course of running an AI consultancy.

Data protection contact: Tim Parkin, Director — info@theaipractitioner.ai

2. We Do Not Sell Your Data

Our commitment

AIP does not sell, rent, trade or otherwise commercially exploit your personal data, and never has. This applies to all personal data we process, including website visitor data, enquiry data and client data.

This commitment is consistent across this Privacy Policy, our Cookie Policy (AIP-PS-002) and our Terms of Website Use (AIP-PS-004).

3. Definitions

TermDefinition
AIPThe AI Practitioner, the trading name of Groundframe Ltd (company number 09715227).
Personal dataAny information relating to an identified or identifiable living individual.
ProcessingAnything done with personal data — including collecting, storing, using, sharing, or deleting it.
Data ControllerThe organisation that decides why and how personal data is processed. Groundframe Ltd is the Data Controller for the purposes of this policy.
ProcessorAn organisation that processes personal data on the Data Controller’s behalf and under its instructions, for example a hosting or software provider.
UK GDPRThe United Kingdom General Data Protection Regulation, as it forms part of UK law under the Data Protection Act 2018.
ICOThe Information Commissioner’s Office, the United Kingdom’s independent regulator for data protection.
Restricted transferMaking personal data accessible to a separate organisation located outside the United Kingdom, which UK GDPR requires to be protected by an appropriate safeguard. See Sections 4 and 12.
Legitimate Interests Assessment (LIA)AIP’s internal record of the three-part test — purpose, necessity, balancing — used to justify relying on legitimate interests as a lawful basis for a particular purpose. See Section 7.
Vendor registerAIP’s internal record of each supplier we use: its contracting entity, the personal data involved, where that data is processed, the transfer mechanism relied on, and the processor terms in place. Maintained under our Data Protection Policy (AIP-PS-003).

4. Our International Operating Context

Groundframe Ltd is a United Kingdom company. AIP’s day-to-day operations, including work carried out by Tim Parkin, are managed from Siem Reap, Cambodia. We are transparent about this because it means personal data controlled by a UK company is, in the ordinary course of business, accessed by AIP personnel from outside the United Kingdom.

Current ICO guidance defines a restricted transfer by reference to personal data being made accessible to a separate organisation outside the United Kingdom. Access by AIP’s own personnel, acting for the same UK controller, is not the same thing as sharing data with a separate overseas organisation, and we do not describe it as one. That does not place it outside our data-protection controls. This access is governed in exactly the way the rest of our processing is governed: authenticated, least-privilege access to our systems; the technical and organisational security measures described in Section 16; documented accountability for who can reach what and why; and disclosure of this operating context to clients during onboarding.

Separately, where we make personal data available to a processor or other organisation located outside the United Kingdom, that is a restricted transfer and the safeguards described in Section 12 apply. Section 12 sets out, recipient by recipient, where data is processed and which safeguard we rely on.

AIP’s clients and website visitors may themselves be located outside the United Kingdom, including in the European Union and the United States. Where this creates additional obligations — for example, whether AIP needs to appoint an EU Article 27 representative once we have a material volume of EU data subjects — we assess this proportionately as our international client base grows, rather than pre-emptively building infrastructure we do not yet need. This assessment is reviewed at each policy review and recorded in our internal Policy Evidence and Source Register.

5. The Data We Collect

We collect the following categories of personal data. Some of this data is required for us to provide our services; Section 8 explains what happens if required data is not provided.

CategoryExamplesSource
Enquiry / contact formName, organisation, email address and message contentProvided directly by you
Client engagement dataName, contact details, role, organisation, and information shared during a consulting engagementProvided directly by you or your organisation
Booking dataName, email address, and the meeting details you give when booking a session through our external booking pageProvided directly by you
Billing and transaction dataInvoice details, payment records, bank or payment-provider referencesProvided directly by you, or generated through Xero or Stripe
Contractual and procurement dataSignatory details, procurement or vendor-onboarding informationProvided directly by you or your organisation
Attendance and participation recordsNames and roles of workshop or training attendees, attendance logsProvided by you or your organisation
Feedback, surveys and testimonialsFeedback form responses, testimonial text, survey answersProvided directly by you
Support and correspondence recordsEmails, meeting notes, and notes relating to queries or issues you raiseCreated in the course of communicating with and supporting you
Publicly sourced professional informationPublicly available professional details, for example from a company website or LinkedIn, used to understand a prospective client’s contextPublicly available sources
Website usage dataAggregated, cookieless measurement of site traffic and performance — see Section 11Collected automatically via Cloudflare Web Analytics

Sessions are not recorded. Recording and transcription are switched off across the platforms we use, and we do not create session recordings or transcripts as part of our normal delivery. If a client ever asks us to record a session, that would be a separate, specific arrangement agreed in writing, with the consent of everyone present and its own retention terms; it is not part of our standard service and no such data is held at present.

Marketing lists. We do not operate a newsletter or marketing mailing list, and there is no newsletter sign-up form on theaipractitioner.ai. If we introduce one, it will be on the basis of a separate, unbundled opt-in obtained specifically for that purpose, and this policy will be updated before it goes live.

5.1 Special-Category and Criminal-Offence Data

AIP does not ask for, and has no operational need for, special-category personal data — information about health, race or ethnicity, religious or philosophical belief, political opinion, trade union membership, genetic or biometric data, or sex life or sexual orientation. We ask that clients and contacts do not send us such information.

If special-category data nevertheless reaches us incidentally — for example, buried in a document a client shares for an unrelated purpose — we do not treat that as a licence to process it. We minimise it, we do not use it for any purpose of our own, and we delete it where it is not needed. We do not rely on the legal-claims condition as a general justification for holding incidentally received special-category data. Before AIP ever processes special-category data intentionally, we will identify a specific condition under UK GDPR Article 9 and a matching Article 6 lawful basis first, and record both, in line with our Data Protection Policy (AIP-PS-003).

AIP does not process personal data relating to criminal convictions or offences.

6. Personal Data We Obtain Indirectly

In addition to data you give us directly, we sometimes receive personal data about you from other sources. Foreseeable indirect sources include:

  • Your employer or the corporate client that has engaged us, where you are a colleague or nominated contact
  • Colleagues who introduce you to an engagement or workshop
  • Referral partners who introduce a prospective client to AIP
  • Event organisers, where you attend or register for an event we are involved in
  • Publicly available professional sources, such as a company website or professional networking profile

Where we receive personal data indirectly, we use it only for the purposes described in Section 7, on the lawful basis identified there, and we provide you with the privacy information required by UK GDPR within the legally required period — generally within a reasonable period after obtaining the data, and by the time of first communicating with you, unless a lawful exception applies (for example, where you already have the information, or providing it would be impossible or involve disproportionate effort).

7. How We Use Your Data — and Our Lawful Basis

Where we rely on legitimate interests as our lawful basis in the table below, we have carried out and keep on file a Legitimate Interests Assessment (LIA) for that purpose, weighing our interest against your rights and interests; each LIA is reviewed periodically, and at least at every policy review.

PurposeLawful basis
Responding to a pre-contract enquiry or discussing a proposal with a prospective individual clientLegitimate interests — to respond to requests you make of us; or steps taken at your request prior to entering a contract
Engaging with a corporate client’s personnel during onboarding or an engagementLegitimate interests — AIP’s interest in performing the contract with the corporate client, balanced against the individual’s interests
Arranging and confirming a booked sessionPerformance of a contract; or steps taken at your request prior to entering a contract
Delivering and managing a client engagement with an individual clientPerformance of a contract
Invoicing, tax treatment and debt recoveryPerformance of a contract; legal obligation (tax records); legitimate interests (recovering sums owed)
Collecting and publishing testimonialsConsent
Maintaining suppression records (e.g. unsubscribe or do-not-contact requests)Legal obligation and legitimate interests — complying with marketing law and respecting your choices
Handling complaints and legal claimsLegal obligation; legitimate interests — managing and defending legal positions
Maintaining business, accounting and tax recordsLegal obligation
Understanding and improving website performance using cookieless, aggregated analyticsLegitimate interests — running and improving our own website, with no tracking of individuals
Business development, such as identifying and approaching prospective corporate clientsLegitimate interests — AIP’s interest in growing the business, balanced against your interests
Preventing fraud and maintaining securityLegitimate interests

Where we rely on legitimate interests, our specific interest is stated in the table above. Where we rely on consent, that consent is sought separately and specifically for the purpose described, and you can withdraw it at any time by contacting us — this does not affect the lawfulness of processing carried out before withdrawal.

7.1 Direct Marketing and PECR

AIP does not currently send electronic marketing. We have no newsletter, no marketing mailing list and no marketing automation. If that changes, we will comply with the Privacy and Electronic Communications Regulations (PECR) as well as UK GDPR, which in practice will mean:

  • We would send electronic marketing only on the basis of your consent, or, where the soft opt-in exemption applies (for example, to an existing client about similar services, with a clear opportunity to opt out when their details were collected), on that basis
  • Every marketing email would include a clear, working unsubscribe link
  • We would not make marketing calls or send marketing texts without your consent
  • This policy would be updated before any marketing activity began

We already maintain a suppression list of anyone who has asked not to be contacted, so that do-not-contact requests continue to be honoured — see Section 15 for how long suppression records are kept.

8. Data You Must Provide, and What Happens If You Don’t

Some personal data is required for us to provide our services, and we cannot proceed without it. For example: to respond to an enquiry we need at least a name and a way to contact you; to enter into and deliver a client engagement we need billing and contact details for invoicing and communication; to determine the correct tax treatment of an engagement we need accurate information about your location and business status; and to comply with our legal and tax obligations we need certain financial records. Where the data we ask for is optional, we will make this clear at the point of collection. If required data is not provided, we may be unable to respond to your enquiry, proceed with an engagement, or meet a legal obligation, and we will tell you if this is the case.

9. Automated Decision-Making and Profiling

AIP does not make solely automated decisions about individuals — that is, decisions made without meaningful human involvement — that produce legal effects or similarly significantly affect you.

Where AI tools are used in our service delivery, as described in Section 10, they support our work under meaningful human oversight; a person remains responsible for reviewing outputs and for decisions that affect you. If this position changes in future — for example, if we introduce a tool that makes automated decisions with legal or similarly significant effect — we will review and update this policy, and identify the additional rights that would apply, before that use begins.

10. Use of Artificial Intelligence Tools

AIP is an AI consultancy, and we use AI tools, including large language models, to support our own work — for example in preparing materials, drafting and supporting research — always under human review.

The AI services approved for use at AIP are Anthropic Claude, OpenAI ChatGPT and Google Gemini. These are named in our Data Protection Policy (AIP-PS-003) and governed by our AI Usage & Governance Policy (AIP-PS-006).

Our rule is a straightforward one, and it is absolute:

  • No identifiable, confidential or unpublished client information is entered into any AI service. Not into an approved tool, and not into any other tool.
  • AI use is limited to public information, synthetic or illustrative material, properly anonymised material, and AIP’s own non-client content.
  • A person remains responsible for reviewing any AI-assisted output before it is relied upon or shared.
  • Adding a new AI service requires approval through our internal AI Tool Register before it is used for anything.

Because of that restriction, AI providers do not receive identifiable client personal data from us. They are nevertheless listed as recipients in Section 12, so that the picture we give you is complete.

11. Cookies, Analytics and External Website Services

Analytics. theaipractitioner.ai uses Cloudflare Web Analytics, and nothing else, to measure site traffic and performance. It is cookieless: it does not set cookies, does not read or write browser storage on your device, and does not build a cross-site identifier or a profile of you. Measurement is aggregated.

Fonts. The site uses two typefaces, Fraunces and Plus Jakarta Sans, served externally by Google Fonts. Loading a page therefore causes your browser to make a request to Google’s font infrastructure, which involves your IP address in the ordinary way that any external web request does. We disclose this because it is an external request, not because it is used to track you.

Booking. Our booking page is provided by Cal.com and is hosted on Cal.com’s own domain. It is linked from our website, not embedded within it. When you follow that link you are on Cal.com’s site, and Cal.com’s own privacy and cookie practices apply there.

No cookie banner. There is no cookie banner on theaipractitioner.ai. That is not an oversight: a production verification of the live site found no consent-requiring storage or tracking technology in use — no advertising pixels, no social embeds, no marketing tags, no CAPTCHA and no embedded booking widget. If we ever deploy a technology that requires consent, we will update this policy and our Cookie Policy and put a compliant consent mechanism in place before it goes live. Full detail is in our companion Cookie Policy (AIP-PS-002).

12. Who We Share Your Data With, and International Transfers

We share personal data only with the recipients below, and only to the extent necessary. Each is engaged under that provider’s processor terms, and the definitive record for every supplier — its contracting entity, the personal data involved, where that data is processed, the transfer mechanism relied on and the processor terms in place — is our internal vendor register, maintained under our Data Protection Policy (AIP-PS-003) and reviewed at each policy review.

RecipientWhat they do for usWhere processed and transfer basis
Cloudflare, Inc.Website hosting, content delivery, DNS and security; the /api/contact endpoint that receives enquiry submissions; Cloudflare Web AnalyticsUnited States, over a global network with UK and EU points of presence. Transfers outside the UK are covered by the UK International Data Transfer Addendum to the EU Standard Contractual Clauses.
Notion Labs, Inc.Our CRM and knowledge system, and the destination record created for each contact-form submission and client engagementUnited States. Covered by the UK Addendum to the EU Standard Contractual Clauses.
Google (Google Workspace)Email, file storage and calendar — including the notification generated when an enquiry arrivesEuropean Union and United States. Covered by UK adequacy regulations for EU processing, and by the UK Addendum to the EU Standard Contractual Clauses for transfers to the United States.
Google (Google Fonts)External web-font delivery to your browser, as described in Section 11United States. Covered by the UK Addendum to the EU Standard Contractual Clauses.
XeroAccounting and invoicingXero is a New Zealand company, and New Zealand is covered by UK adequacy regulations. Where processing occurs outside an adequate country, the UK Addendum to the EU Standard Contractual Clauses applies.
Cal.com, Inc.External scheduling and booking, and the Cal Video meeting option where that is usedUnited States. We currently use Cal.com’s European deployment (Cal.eu), but Cal.com states that its data is processed in the United States, so we treat this as a transfer covered by the UK Addendum to the EU Standard Contractual Clauses rather than relying on adequacy.
StripePayment processing where an invoice is settled by cardIreland and the United States. Covered by UK adequacy regulations for EU processing and by the UK Addendum to the EU Standard Contractual Clauses for transfers to the United States.
Zoom Communications, Inc.Our default remote meeting platformUnited States. Covered by the UK Addendum to the EU Standard Contractual Clauses.
MicrosoftMicrosoft Teams, as an alternative meeting platform where a client requires itEuropean Union and United States. Covered by UK adequacy regulations for EU processing and by the UK Addendum to the EU Standard Contractual Clauses for transfers to the United States.
Anthropic (Claude), OpenAI (ChatGPT), Google (Gemini)Approved AI services supporting our own work, subject to the absolute restriction in Section 10 — no identifiable, confidential or unpublished client information is entered into themUnited States. Covered by the UK Addendum to the EU Standard Contractual Clauses.
Our bank and payment providersReceiving and reconciling paymentUnited Kingdom.
Our accountant, legal advisers and insurersProfessional advice and statutory support, where necessaryUnited Kingdom.
Regulators and authoritiesHMRC, Companies House and the ICO, where required by lawUnited Kingdom.

Our domain registrar administers the theaipractitioner.ai domain. It does not process personal data beyond ordinary domain administration, so it is recorded in our internal asset and vendor register rather than listed above as a recipient of your personal data.

Where a recipient above is a separate organisation located outside the United Kingdom, sharing personal data with it is a restricted transfer under UK GDPR, and we rely on the safeguard stated in that recipient’s row so that your data receives a level of protection essentially equivalent to that under UK GDPR. This is separate from AIP’s own personnel accessing UK-controlled data from Cambodia, which is described in Section 4 and is not a restricted transfer to a separate organisation.

Our booking provider currently operates the European Cal.eu environment. We are migrating that account to Cal.com, and the migration is tracked as a supplier-continuity action in our internal vendor register. This does not change what data is processed or the safeguards that apply to it.

13. Just-in-Time Privacy Notices

This policy is intended to be the full and authoritative statement of how AIP processes personal data, but we do not expect you to read all of it at every point you give us data. A link to this policy is shown beside the contact form on theaipractitioner.ai, so you have the information you need at the point of decision. No consent checkbox is used on that form: submitting an ordinary service enquiry does not rely on consent as its lawful basis, and asking you to tick a box would misrepresent what is actually happening. Where we ever do rely on consent — for example, to publish a testimonial — we ask for it separately and specifically at that point.

14. Post-Engagement Data Lifecycle

When an engagement ends, we do not immediately delete the associated records. Instead, information is controlled-archived: access is restricted to what is needed for legal, accounting and continuity purposes, and confidentiality continues to apply in the same way as during the engagement.

Archived information is not reused for unrelated purposes, such as marketing to you without a separate lawful basis. At the end of the applicable retention period set out in Section 15, we securely delete or irreversibly anonymise the personal data, unless a documented lawful basis justifies continued retention.

15. How Long We Keep Your Data

The table below is drawn from a single master retention schedule maintained under our Data Protection Policy (AIP-PS-003). That schedule is the authoritative internal record, and the periods published here match it. Suppression records are deliberately kept for longer than the underlying contact data, so that we do not inadvertently re-contact someone who has asked us not to — see Section 7.1.

DataRetention
Enquiry data that does not become a client relationship12 months from last contact, then deleted
Client engagement records6 years from the end of the engagement, in line with UK limitation periods
Booking records that do not become an engagement12 months from the booking date, then deleted
Financial and tax records6 years, to meet HMRC requirements
Contractual and procurement data6 years from the end of the contractual relationship, in line with UK limitation periods
Attendance and participation records6 years from the end of the related engagement, in line with client engagement records
Feedback, testimonials and survey responsesRetained while used for the stated purpose (for example, displayed as a testimonial) and reviewed at each policy review; deleted or anonymised on request
Support and correspondence records24 months from resolution of the query, then deleted
Suppression / do-not-contact recordsKept for as long as reasonably necessary to ensure your do-not-contact request continues to be honoured

We do not create session recordings or transcripts (Section 5), so no retention period is stated for them. If a recording were ever made under a specific written agreement, its retention period would be set in that agreement and recorded in the master retention schedule.

16. How We Protect Your Data

As a director-led business, we keep our security measures proportionate to the data we hold, and we are precise about what is in place today and what is still being rolled out. Current measures are:

  • Encrypted connections (HTTPS/TLS) across theaipractitioner.ai and the cloud systems we use
  • Full-disk encryption, password protection, current patching and backup on the devices used for AIP business
  • A password manager (NordPass) generating and storing a unique password for every account, with no shared logins
  • Least-privilege access, recorded in an internal access register that covers human users, service accounts, API identities, automations and external advisers
  • Minimising the data we collect, and not collecting special-category data or data we do not need
  • Working only with established providers, under their processor terms, as described in Section 12

Multi-factor authentication (MFA). We want to be accurate rather than reassuring here. MFA is enabled on Stripe, Xero, NordPass, our Apple account and our business banking. It is not yet enabled on every other system we use. Completing that rollout is an active, prioritised security improvement, starting with Google Workspace, Cloudflare, our domain registrar and Notion. In the meantime every account uses a unique, strong password held in the password manager, and MFA is required for any new system we onboard where the provider supports it.

We do not operate a formal Information Security Management System (ISMS) and we do not hold a security certification such as ISO 27001 or Cyber Essentials. These are not proportionate for a business of our size, and we do not claim controls we do not have. As AIP grows beyond a director-led operation, we intend to formalise these measures under a dedicated Information Security Policy.

17. Personal Data Breaches

If we become aware of a personal data breach, we investigate it promptly to understand what happened, what data and how many people are affected, and the risk of harm. Where the breach is likely to result in a risk to individuals’ rights and freedoms, UK GDPR requires notification to the ICO without undue delay and, where feasible, within 72 hours of us becoming aware of it, and we work to that clock. Where the breach is likely to result in a high risk to affected individuals, we also notify them directly, without undue delay. This public commitment describes the outcome you can expect; the full internal breach-response procedure is set out in our Data Protection Policy (AIP-PS-003) and is not duplicated here.

18. Your Rights

Under UK GDPR, and subject to the conditions and exemptions that apply to each right, you have the right to:

  • Be informed about how we use your personal data — this policy is how we do that
  • Access the personal data we hold about you
  • Rectification — have inaccurate or incomplete data corrected
  • Erasure — have your data deleted, in certain circumstances
  • Restrict processing in certain circumstances
  • Object to processing based on legitimate interests, or carried out for direct marketing. Objecting to direct marketing is absolute — we always stop, without applying any balancing test. Objecting to other processing based on legitimate interests is not automatic — we will consider your objection and stop unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing is needed for legal claims, in line with UK GDPR Article 21.
  • Data portability — receive data you provided to us, where processing is based on consent or contract and carried out by automated means
  • Withdraw consent at any time, where we rely on consent, without affecting processing carried out before withdrawal
  • Rights related to solely automated decision-making with legal or similarly significant effect, including the right not to be subject to such a decision — see Section 9; this does not currently apply to AIP’s processing

Not every right applies in every case — for example, the right to erasure and the right to portability depend on the lawful basis used and the circumstances. We will explain which rights apply when you contact us.

We normally respond within one calendar month of receiving a request, extendable by up to two further months for complex requests, with you notified of the extension and reason. We may need to verify your identity before disclosing personal data. Exercising your rights is normally free of charge, unless a request is manifestly unfounded or excessive, in which case we may charge a reasonable fee or decline to act.

19. How to Exercise Your Rights

To exercise any of the rights in Section 18:

  • Contact us at info@theaipractitioner.ai, telling us which right you wish to exercise and providing enough detail for us to locate your data
  • Identity verification — we may ask you to confirm your identity before we act on a request, to protect your data from unauthorised disclosure
  • Response timing — we aim to acknowledge your request promptly and respond in full within one calendar month, as described in Section 18
  • However you phrase it — we will recognise a request as a rights request even if you don’t cite “GDPR”, name a specific right, or use formal language; if in doubt, we will ask you to clarify rather than dismiss the request
  • If you are unhappy with our response, you can raise a complaint using our internal process below, or contact the ICO directly

20. Complaints and ICO Registration

If you are unhappy with how we have handled your personal data, please contact us first at info@theaipractitioner.ai so we can try to resolve it directly. In line with the Data (Use and Access) Act 2025 complaints requirements, we will:

  • Provide a clear route for you to raise a complaint
  • Acknowledge your complaint within 30 days
  • Investigate it appropriately
  • Communicate the outcome to you without undue delay

Internal escalation: complaints are handled personally by Tim Parkin, Director, as AIP’s sole director and privacy contact. We acknowledge complaints within 30 days, as above, and aim to complete our investigation and provide a substantive response within 90 days of receipt where reasonably possible; if a complaint is more complex, we will tell you and give a revised timescale.

ICO registration. Groundframe Ltd is registered with the Information Commissioner’s Office under registration reference C2019678. The registration date, reference, renewal date and supporting evidence are recorded in our internal Policy Evidence and Source Register.

You also have the right to complain to the UK Information Commissioner’s Office at ico.org.uk or 0303 123 1113, whether or not you have raised the matter with us first.

21. Children’s Data

AIP provides professional training and consultancy services, principally to businesses. Our services are not directed at, or marketed to, children, and we do not knowingly collect personal data from anyone under the age of 18.

If we become aware that we have inadvertently collected personal data from someone under 18 without appropriate consent, we will delete that data promptly, unless we are required to retain it for a legal reason, and will take steps to prevent further collection from that individual. If you believe a minor has provided us with personal data, please contact us at info@theaipractitioner.ai so we can address it.

22. Changes to This Policy

We may update this policy as our tools, services, or the law change. The version number and status shown in the document control table above reflect the current version.

We distinguish between material and minor changes. A material change is one that affects what data we collect, why, who we share it with, your rights, or our lawful basis — for example, adding a new processor or a new purpose of processing; material changes are dated and, where appropriate, notified to active clients. A minor change is a clarification, correction, or formatting update that does not change the substance of how we process your data; minor changes update the version number without separate notification. All changes to this policy, whether material or minor, are approved by Tim Parkin, Director. The version history table below is the authoritative log of all changes to this policy — if there is any inconsistency between this table and any other summary of changes, the table below governs.

Tim Parkin, Director, also owns AIP’s internal Policy Evidence and Source Register, which records the supporting evidence, dates and references — for example ICO registration and processor terms — behind the commitments made in this policy and our other Tier 1 policies.

22.1 What Changed at Version 1.0

Version 1.0 is the outcome of the fifth and final review in this cycle, applying the v0.4 to v1.0 Update Notes of 31 August 2026. The substantive changes were:

  • ICO registration recorded as completed under reference C2019678, and the publication-readiness gates removed as satisfied.
  • Company number corrected to 09715227, and all pre-launch, dormancy and working-draft wording removed.
  • Contact-form flow corrected to the live implementation: submissions reach a Cloudflare endpoint, create a Notion record and generate a Google Workspace notification.
  • AI position rewritten — Claude, ChatGPT and Gemini named as the approved services, under an absolute restriction on identifiable, confidential or unpublished client information.
  • Analytics and cookies confirmed as Cloudflare Web Analytics only, with Google Fonts disclosed and the absence of a cookie banner explained.
  • Recipient table rebuilt from the confirmed supplier register: Acuity and Mailchimp removed; Cal.com, Stripe, Zoom, Microsoft Teams and Google Fonts added.
  • Recordings and transcripts removed as a data category and retention row, because none are created; retention aligned to a single master schedule.
  • Special-category wording narrowed, so the legal-claims condition is no longer relied on as a general justification.
  • Security stated exactly — the precise multi-factor authentication position replaces the previous blanket claim.

This version is approved by Director approval. No external legal review has been carried out.

22.2 Version History

VersionDateAuthor / ApproverStatusSummary of change
0.112/Jul/2026Tim Parkin, DirectorWorking DraftInitial working draft prepared for internal review.
0.215/Jul/2026Tim Parkin, DirectorRevised Working DraftCorrected Data Controller identification and Cambodia access wording. Added Definitions, AI tools, breaches, automated decision-making, indirect data, data lifecycle and rights procedure. Added the no-sale commitment.
0.317/Jul/2026Tim Parkin, DirectorRevised Working DraftAdded pre-launch ICO gating, confirmed processors in place of placeholders, AI providers as a recipient category, an expanded retention schedule, and new sections on required data and just-in-time notices.
0.418/Jul/2026Tim Parkin, DirectorRevised Working DraftReviewed with no structural or content changes required; confirmed ready to progress to Version 1.0 once the publication gates were satisfied.
1.031/Aug/2026Tim Parkin, DirectorApprovedFifth and final review. Published as Version 1.0, effective 1 September 2026. Changes are set out in full at Section 22.1.

22.3 Privacy Governance Metrics

To keep our data protection practice honest without over-engineering it, we track a small set of metrics internally: the number of individual rights requests received and whether we responded within the statutory timescale; the number of personal data breaches and their severity; and the number of complaints received and their outcome. These are reviewed at each policy review and recorded in our Policy Evidence and Source Register.

23. Contact Us

Data Controller: Groundframe Ltd t/a The AI Practitioner (company number 09715227)

Privacy contact: Tim Parkin, Director

Email: info@theaipractitioner.ai

Post: 49 Station Road, Polegate, East Sussex, BN26 6EA, United Kingdom

This policy is published by Groundframe Ltd, registered in England and Wales, company number 09715227. Questions about it go to info@theaipractitioner.ai.