Privacy Policy

Privacy Policy

Last Updated: 5 March 2026 | Version: 2.0

UK GDPR Compliance: This Privacy Policy has been prepared in accordance with the UK General Data Protection Regulation (UK GDPR) and Data Protection Act 2018 requirements. As HaveAI Technologies Ltd, we take the protection of your personal data very seriously.

This Privacy Policy explains how your personal data is collected, used, stored, and protected when you use the haveai.io website and HaveAI platform services operated by HaveAI Technologies Ltd ("HaveAI", "we", "our").

1. Data Controller Identity

Company Name:
HaveAI Technologies Ltd
Registered Office:
71-75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ
Company Number:
17193263
Contact Email:
[email protected]
Data Protection Contact:
[email protected]
ICO Registration:
Pending registration

2. Controller / Processor Role

Important Distinction

HaveAI assumes different roles in different data processing activities. It is important to understand this distinction:

A) When HaveAI is the DATA CONTROLLER:

  • Platform Users (B2B): Businesses and employees who register on the HaveAI platform and use the admin panel
  • Website Visitors: People who visit the haveai.io website
  • Potential Customers: Those who request demos, fill out contact forms
  • Platform Operations: Account management, billing, support requests, security

B) When HaveAI is the DATA PROCESSOR:

For end users' data who use the chatbots of our customers (businesses using the HaveAI platform), HaveAI acts as a processor. In this case:

  • Data Controller: Our customer (business) that integrates the chatbot into their website
  • Data Processor: HaveAI (processes data according to customer instructions)
  • Data Subject: The end user using the chatbot
  • Legal Basis: Data Processing Agreement (DPA)

Note: End users using chatbots should direct their data processing questions primarily to the business providing the chatbot (controller).

3. Personal Data We Collect

In our Controller role, we collect the following personal data:

A) Identity Data

  • First name, last name
  • Email address
  • Phone number (optional)
  • Company name (for B2B users)

Source: Registration form, account creation

B) Account Data

  • Username
  • Hashed password (encrypted)
  • Account preferences and settings
  • Platform configuration (chatbot settings, AI training data)

Source: Platform usage

C) Technical Data

  • IP address
  • Browser type and version
  • Device type (desktop, mobile, tablet)
  • Operating system
  • Timezone and language preferences
  • Cookies and similar tracking technologies

Source: Automatic collection (cookies, server logs)

D) Usage Data

  • Platform usage statistics
  • Login/logout times
  • Feature usage (which features you use)
  • API calls and response times
  • Error logs

Source: Platform analytics

E) Financial Data

  • Billing information (company name, address, tax number)
  • Payment method information (last 4 digits of card - processed by payment processor)
  • Transaction history

Note: Card details are not stored on HaveAI servers. Payment transactions are processed by a PCI-DSS compliant payment processor.

F) Communication Data

  • Support requests and ticket content
  • Email correspondence
  • Feedback and survey responses
  • Chat messages (platform support chat)

Source: Customer communication

✅ We Do Not Collect Special Category Data

HaveAI does not intentionally collect special category personal data under UK GDPR Article 9 (race, ethnicity, political opinions, religious beliefs, health data, sexual orientation, etc.). Please do not share such information through the platform.

4. How We Use Your Personal Data

In accordance with UK GDPR Article 6, we only process your personal data when we have a lawful basis:

Processing PurposeData CategoriesLegal Basis (UK GDPR)
Account creation and managementIdentity, Account DataContract Performance (Article 6(1)(b))
Providing platform services (AI chatbot, widget, analytics)Account, Technical, Usage DataContract Performance (Article 6(1)(b))
Payment processing and billingIdentity, Financial DataContract Performance (Article 6(1)(b)), Legal Obligation (Article 6(1)(c))
Customer supportIdentity, Communication DataContract Performance (Article 6(1)(b)), Legitimate Interests (Article 6(1)(f))
Platform security, fraud preventionTechnical, Usage Data, LogsLegitimate Interests (Article 6(1)(f)), Legal Obligation (Article 6(1)(c))
Platform improvement, analyticsTechnical, Usage Data (anonymized)Legitimate Interests (Article 6(1)(f))
Marketing (newsletters, product updates)Identity, Contact DataConsent (Article 6(1)(a)) - You can unsubscribe at any time
Legal obligations (tax, accounting)Identity, Financial DataLegal Obligation (Article 6(1)(c))

5. Cookies and Tracking Technologies

We use cookies and similar tracking technologies on our website. For detailed information, please see our Cookie Policy page. Cookie Policy

Legal Basis: Under UK PECR (Privacy and Electronic Communications Regulations) and UK GDPR, we obtain consent for non-essential cookies.

6. Data Sharing and Third Parties

We only share your personal data with third parties in the following circumstances:

A) Service Providers

Third-party service providers we trust to deliver platform services. All service providers have signed UK GDPR Article 28 compliant Data Processing Agreements.

  • Cloud Hosting: DigitalOcean, LLC (Frankfurt, Germany — EU region)
  • AI Processing: Google Gemini API (zero data retention, no model training)
  • CDN & Security: Cloudflare, Inc. (DDoS protection, WAF)
  • Messaging: Telegram Messenger LLP (bot API); WhatsApp & Instagram via Meta Platforms Ireland Limited and ZERNIO SOFTWARE SL (BSP bridge, EEA)
  • Payment Processing: Stripe Payments Europe, Ltd. (PCI-DSS compliant)

For detailed list: Subprocessors page: Subprocessors

B) Legal Obligations

We may disclose your data to authorities in the following circumstances:

  • Court order or legal process
  • ICO (Information Commissioner's Office) request
  • Law enforcement investigations
  • Fraud prevention and platform security

C) Business Transfers

In the event of a sale, merger, or transfer of HaveAI, your personal data may be transferred to the new owner. You will be notified in advance in such cases.

7. International Data Transfers

HaveAI servers are located within the European Union (Germany). However, some service providers are located outside the UK/EEA. All international data transfers comply with UK GDPR Chapter V requirements:

Transfer Mechanisms

  • EEA Countries: Adequacy decision (UK GDPR Article 45)
  • USA: EU-US Data Privacy Framework (Google, Cloudflare certified participants)
  • Other Countries: Standard Contractual Clauses (2021 version) + supplementary measures

For detailed transfer matrix: DPA Annex 5: DPA Annex 5

8. Data Retention

We only retain your personal data for as long as necessary:

Data CategoryRetention PeriodBasis
Account DataAs long as account is activeContract performance
Financial Records7 years (from last transaction)UK tax law (Companies Act 2006)
Support Tickets3 yearsLegitimate interests (customer service quality)
System Logs90 daysSecurity monitoring
Security Logs1 yearSecurity compliance
Marketing ConsentUntil consent is withdrawnConsent (Article 6(1)(a))
Deleted Account DataPermanent deletion after 30 days (grace period)Account recovery possibility

9. Your Rights

Under UK GDPR, you have the following rights:

1. Right to Access - Article 15

You can request a copy of the personal data we process about you. The first request is free.

2. Right to Rectification - Article 16

You can request correction of inaccurate or incomplete personal data.

3. Right to Erasure ("Right to be Forgotten") - Article 17

Under certain conditions, you can request deletion of your personal data. However, some data may not be deleted due to legal retention obligations (tax records, etc.).

4. Right to Restriction of Processing - Article 18

In certain circumstances (e.g., when data accuracy is contested), you can request that we restrict processing of your data.

5. Right to Data Portability - Article 20

You can request to receive the personal data you provided to us in a structured, commonly used, machine-readable format (JSON, CSV) or have it transferred to another controller.

6. Right to Object - Article 21

You can object to processing based on legitimate interests (e.g., direct marketing). You can always unsubscribe from direct marketing.

7. Rights Related to Automated Decision-Making - Article 22

You can object to solely automated decision-making (without any human intervention). HaveAI platform uses AI, but important decisions (e.g., account closure) require human review.

8. Right to Withdraw Consent

For processing based on consent (e.g., marketing emails), you can withdraw your consent at any time. This does not affect the lawfulness of processing before withdrawal.

How to Exercise Your Rights?

To exercise your rights above:

  • Email: [email protected]
  • Platform: Account Settings → Privacy & Data
  • Response time: We will respond within 30 days at the latest (UK GDPR Article 12(3))

10. Data Security

In accordance with UK GDPR Article 32, we implement appropriate technical and organizational measures to protect your personal data:

Technical Measures

  • TLS 1.3 encryption (data in transit)
  • AES-256-GCM encryption (data at rest)
  • Regular security audits & penetration tests
  • WAF (Web Application Firewall)
  • DDoS protection
  • Intrusion detection systems

Administrative Measures

  • Access controls (MFA, RBAC)
  • Staff GDPR training
  • Confidentiality agreements (NDAs)
  • Incident response plan
  • Regular backup & disaster recovery
  • Vendor security assessments

For detailed security measures: DPA Annex 3: DPA Annex 3

Data Breach Notification

If we detect a data breach affecting your personal data, in accordance with UK GDPR Articles 33 and 34:

  • We will notify the ICO within 72 hours
  • In high-risk situations, we will inform you without delay
  • We will explain the measures we have taken/will take

11. Children's Privacy

⚠️ Use Prohibited Under Age 16

The HaveAI platform is not intended for individuals under 16 years of age. We do not knowingly collect personal data from children under 16. If we become aware that we have collected data from a child under 16, we will delete it immediately. If you are a parent or guardian and believe your child has provided us with personal data, please contact [email protected].

Legal Basis: UK GDPR Article 8 - Child's consent in relation to information society services

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. For significant changes:

  • A new "Last Updated" date will be shown on this page
  • Email notification will be sent for material changes
  • Continued use (platform usage after changes) means acceptance of the new policy

You can request to see previous versions at [email protected].

13. Contact & Complaints

Contact HaveAI

Data Protection Enquiries:
[email protected]
General Contact:
[email protected]
Postal Address:
71-75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ

Right to Lodge a Complaint with the ICO

Under UK GDPR Article 77, if you have concerns about our data processing practices, you have the right to contact the UK supervisory authority, the Information Commissioner's Office (ICO):

Information Commissioner's Office (ICO)

Website: https://ico.org.uk
Helpline: 0303 123 1113
Address: Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF, United Kingdom

We encourage you to contact us first, but you always have the right to contact the ICO directly.

14. Additional Resources

Your personal data privacy is our priority. For any questions, you can always reach us at [email protected].