Privacy Policy
Privacy Policy
Last Updated: 5 March 2026 | Version: 2.0
UK GDPR Compliance: This Privacy Policy has been prepared in accordance with the UK General Data Protection Regulation (UK GDPR) and Data Protection Act 2018 requirements. As HaveAI Technologies Ltd, we take the protection of your personal data very seriously.
This Privacy Policy explains how your personal data is collected, used, stored, and protected when you use the haveai.io website and HaveAI platform services operated by HaveAI Technologies Ltd ("HaveAI", "we", "our").
1. Data Controller Identity
- Company Name:
- HaveAI Technologies Ltd
- Registered Office:
- 71-75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ
- Company Number:
- 17193263
- Website:
- https://haveai.io
- Contact Email:
- [email protected]
- Data Protection Contact:
- [email protected]
- ICO Registration:
- Pending registration
2. Controller / Processor Role
Important Distinction
HaveAI assumes different roles in different data processing activities. It is important to understand this distinction:
A) When HaveAI is the DATA CONTROLLER:
- Platform Users (B2B): Businesses and employees who register on the HaveAI platform and use the admin panel
- Website Visitors: People who visit the haveai.io website
- Potential Customers: Those who request demos, fill out contact forms
- Platform Operations: Account management, billing, support requests, security
B) When HaveAI is the DATA PROCESSOR:
For end users' data who use the chatbots of our customers (businesses using the HaveAI platform), HaveAI acts as a processor. In this case:
- Data Controller: Our customer (business) that integrates the chatbot into their website
- Data Processor: HaveAI (processes data according to customer instructions)
- Data Subject: The end user using the chatbot
- Legal Basis: Data Processing Agreement (DPA)
Note: End users using chatbots should direct their data processing questions primarily to the business providing the chatbot (controller).
3. Personal Data We Collect
In our Controller role, we collect the following personal data:
A) Identity Data
- • First name, last name
- • Email address
- • Phone number (optional)
- • Company name (for B2B users)
Source: Registration form, account creation
B) Account Data
- • Username
- • Hashed password (encrypted)
- • Account preferences and settings
- • Platform configuration (chatbot settings, AI training data)
Source: Platform usage
C) Technical Data
- • IP address
- • Browser type and version
- • Device type (desktop, mobile, tablet)
- • Operating system
- • Timezone and language preferences
- • Cookies and similar tracking technologies
Source: Automatic collection (cookies, server logs)
D) Usage Data
- • Platform usage statistics
- • Login/logout times
- • Feature usage (which features you use)
- • API calls and response times
- • Error logs
Source: Platform analytics
E) Financial Data
- • Billing information (company name, address, tax number)
- • Payment method information (last 4 digits of card - processed by payment processor)
- • Transaction history
Note: Card details are not stored on HaveAI servers. Payment transactions are processed by a PCI-DSS compliant payment processor.
F) Communication Data
- • Support requests and ticket content
- • Email correspondence
- • Feedback and survey responses
- • Chat messages (platform support chat)
Source: Customer communication
✅ We Do Not Collect Special Category Data
HaveAI does not intentionally collect special category personal data under UK GDPR Article 9 (race, ethnicity, political opinions, religious beliefs, health data, sexual orientation, etc.). Please do not share such information through the platform.
4. How We Use Your Personal Data
In accordance with UK GDPR Article 6, we only process your personal data when we have a lawful basis:
| Processing Purpose | Data Categories | Legal Basis (UK GDPR) |
|---|---|---|
| Account creation and management | Identity, Account Data | Contract Performance (Article 6(1)(b)) |
| Providing platform services (AI chatbot, widget, analytics) | Account, Technical, Usage Data | Contract Performance (Article 6(1)(b)) |
| Payment processing and billing | Identity, Financial Data | Contract Performance (Article 6(1)(b)), Legal Obligation (Article 6(1)(c)) |
| Customer support | Identity, Communication Data | Contract Performance (Article 6(1)(b)), Legitimate Interests (Article 6(1)(f)) |
| Platform security, fraud prevention | Technical, Usage Data, Logs | Legitimate Interests (Article 6(1)(f)), Legal Obligation (Article 6(1)(c)) |
| Platform improvement, analytics | Technical, Usage Data (anonymized) | Legitimate Interests (Article 6(1)(f)) |
| Marketing (newsletters, product updates) | Identity, Contact Data | Consent (Article 6(1)(a)) - You can unsubscribe at any time |
| Legal obligations (tax, accounting) | Identity, Financial Data | Legal Obligation (Article 6(1)(c)) |
5. Cookies and Tracking Technologies
We use cookies and similar tracking technologies on our website. For detailed information, please see our Cookie Policy page. Cookie Policy
Legal Basis: Under UK PECR (Privacy and Electronic Communications Regulations) and UK GDPR, we obtain consent for non-essential cookies.
6. Data Sharing and Third Parties
We only share your personal data with third parties in the following circumstances:
A) Service Providers
Third-party service providers we trust to deliver platform services. All service providers have signed UK GDPR Article 28 compliant Data Processing Agreements.
- Cloud Hosting: DigitalOcean, LLC (Frankfurt, Germany — EU region)
- AI Processing: Google Gemini API (zero data retention, no model training)
- CDN & Security: Cloudflare, Inc. (DDoS protection, WAF)
- Messaging: Telegram Messenger LLP (bot API); WhatsApp & Instagram via Meta Platforms Ireland Limited and ZERNIO SOFTWARE SL (BSP bridge, EEA)
- Payment Processing: Stripe Payments Europe, Ltd. (PCI-DSS compliant)
For detailed list: Subprocessors page: Subprocessors
B) Legal Obligations
We may disclose your data to authorities in the following circumstances:
- Court order or legal process
- ICO (Information Commissioner's Office) request
- Law enforcement investigations
- Fraud prevention and platform security
C) Business Transfers
In the event of a sale, merger, or transfer of HaveAI, your personal data may be transferred to the new owner. You will be notified in advance in such cases.
7. International Data Transfers
HaveAI servers are located within the European Union (Germany). However, some service providers are located outside the UK/EEA. All international data transfers comply with UK GDPR Chapter V requirements:
Transfer Mechanisms
- EEA Countries: Adequacy decision (UK GDPR Article 45)
- USA: EU-US Data Privacy Framework (Google, Cloudflare certified participants)
- Other Countries: Standard Contractual Clauses (2021 version) + supplementary measures
For detailed transfer matrix: DPA Annex 5: DPA Annex 5
8. Data Retention
We only retain your personal data for as long as necessary:
| Data Category | Retention Period | Basis |
|---|---|---|
| Account Data | As long as account is active | Contract performance |
| Financial Records | 7 years (from last transaction) | UK tax law (Companies Act 2006) |
| Support Tickets | 3 years | Legitimate interests (customer service quality) |
| System Logs | 90 days | Security monitoring |
| Security Logs | 1 year | Security compliance |
| Marketing Consent | Until consent is withdrawn | Consent (Article 6(1)(a)) |
| Deleted Account Data | Permanent deletion after 30 days (grace period) | Account recovery possibility |
9. Your Rights
Under UK GDPR, you have the following rights:
1. Right to Access - Article 15
You can request a copy of the personal data we process about you. The first request is free.
2. Right to Rectification - Article 16
You can request correction of inaccurate or incomplete personal data.
3. Right to Erasure ("Right to be Forgotten") - Article 17
Under certain conditions, you can request deletion of your personal data. However, some data may not be deleted due to legal retention obligations (tax records, etc.).
4. Right to Restriction of Processing - Article 18
In certain circumstances (e.g., when data accuracy is contested), you can request that we restrict processing of your data.
5. Right to Data Portability - Article 20
You can request to receive the personal data you provided to us in a structured, commonly used, machine-readable format (JSON, CSV) or have it transferred to another controller.
6. Right to Object - Article 21
You can object to processing based on legitimate interests (e.g., direct marketing). You can always unsubscribe from direct marketing.
7. Rights Related to Automated Decision-Making - Article 22
You can object to solely automated decision-making (without any human intervention). HaveAI platform uses AI, but important decisions (e.g., account closure) require human review.
8. Right to Withdraw Consent
For processing based on consent (e.g., marketing emails), you can withdraw your consent at any time. This does not affect the lawfulness of processing before withdrawal.
How to Exercise Your Rights?
To exercise your rights above:
- • Email: [email protected]
- • Platform: Account Settings → Privacy & Data
- • Response time: We will respond within 30 days at the latest (UK GDPR Article 12(3))
10. Data Security
In accordance with UK GDPR Article 32, we implement appropriate technical and organizational measures to protect your personal data:
Technical Measures
- ✓ TLS 1.3 encryption (data in transit)
- ✓ AES-256-GCM encryption (data at rest)
- ✓ Regular security audits & penetration tests
- ✓ WAF (Web Application Firewall)
- ✓ DDoS protection
- ✓ Intrusion detection systems
Administrative Measures
- ✓ Access controls (MFA, RBAC)
- ✓ Staff GDPR training
- ✓ Confidentiality agreements (NDAs)
- ✓ Incident response plan
- ✓ Regular backup & disaster recovery
- ✓ Vendor security assessments
For detailed security measures: DPA Annex 3: DPA Annex 3
Data Breach Notification
If we detect a data breach affecting your personal data, in accordance with UK GDPR Articles 33 and 34:
- • We will notify the ICO within 72 hours
- • In high-risk situations, we will inform you without delay
- • We will explain the measures we have taken/will take
11. Children's Privacy
⚠️ Use Prohibited Under Age 16
The HaveAI platform is not intended for individuals under 16 years of age. We do not knowingly collect personal data from children under 16. If we become aware that we have collected data from a child under 16, we will delete it immediately. If you are a parent or guardian and believe your child has provided us with personal data, please contact [email protected].
Legal Basis: UK GDPR Article 8 - Child's consent in relation to information society services
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. For significant changes:
- A new "Last Updated" date will be shown on this page
- Email notification will be sent for material changes
- Continued use (platform usage after changes) means acceptance of the new policy
You can request to see previous versions at [email protected].
13. Contact & Complaints
Contact HaveAI
- Data Protection Enquiries:
- [email protected]
- General Contact:
- [email protected]
- Postal Address:
- 71-75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ
Right to Lodge a Complaint with the ICO
Under UK GDPR Article 77, if you have concerns about our data processing practices, you have the right to contact the UK supervisory authority, the Information Commissioner's Office (ICO):
Information Commissioner's Office (ICO)
Website: https://ico.org.uk
Helpline: 0303 123 1113
Address: Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF, United Kingdom
We encourage you to contact us first, but you always have the right to contact the ICO directly.
14. Additional Resources
📄 Data Processing Agreement (DPA)
Data processing agreement for B2B customers with 5 annexes
🍪 Cookie Policy
Detailed information about cookies used on our website
🔗 Subprocessors List
List of third-party service providers we use
📋 Terms of Service
Platform terms and conditions
Your personal data privacy is our priority. For any questions, you can always reach us at [email protected].