Privacy policy

Effective Date: 28/07/2025

1. Who We Are

Ask Gloria AI (“we”, “our”, or “us”) is an artificial intelligence platform that provides businesses with secure, instant access to internal company information across files, databases, CRM systems, and more.

Contact details:

We act as a Data Controller for personal data you provide directly to us (e.g., when registering for an account). When accessing your integrated business systems, we act as a Data Processor, processing data solely on your behalf and under your control.

2. What Information We Collect

a) Personal Data (as Controller)

We may collect and process the following information you provide directly to us:

  • Name
  • Company name
  • Email address
  • Login credentials or authentication tokens (encrypted)
  • Contact details

b) Technical and Usage Data

When you use our website or platform, we may collect:

  • IP address
  • Browser type and version
  • Pages visited and time spent
  • Diagnostic and performance data

This is collected separately from business data and used only for service improvement, troubleshooting, and security.

c) Business Data Accessed via Integrations (as Processor)

When you connect your systems (e.g., Microsoft SharePoint, CRMs, databases), our platform queries and processes business data in real time to respond to your requests.

Important:

  • We do not store or retain integrated business data beyond the duration of the query or session.
  • A query means a single question/response interaction.
  • A session means multiple interactions within one active conversation.
  • Once a query or session ends, the business data queried is not stored by us.

d) Conversations

  • We store conversations (both current and historical) between you and the AI assistant to provide continuity, improve service, and allow review of prior interactions.
  • Conversations are stored securely in our database.
  • Each tenant (customer) has their own unique encryption key, ensuring isolation and confidentiality of data.
  • Data is encrypted at rest and in transit.

3. How We Use Your Information

  • Provide, personalise, and improve our AI services
  • Ensure performance, reliability, and security
  • Communicate with you regarding account management and support
  • Comply with legal or regulatory obligations

We always rely on a valid lawful basis for processing, including contractual necessity, legitimate interests, consent, or legal obligation.

4. Data Security

  • End-to-end encryption where applicable
  • Secure access controls and authentication
  • Role-based access and data minimisation
  • Regular security testing and audits

5. Sharing Your Data

We do not sell or trade your data. Data may be shared only with:

  • Trusted cloud hosting or IT service providers (under strict contractual terms)
  • Authorised personnel under confidentiality agreements
  • Regulators or legal authorities, where required by law

For integrated systems (e.g., Microsoft 365, CRMs), data access is governed by your agreements with those platforms.

6. Your Rights (UK GDPR)

You have the right to:

  • Access the personal data we hold about you
  • Request correction or deletion of your data
  • Restrict or object to our processing
  • Request data portability
  • Withdraw consent at any time (where consent is the basis of processing)
  • Lodge a complaint with the Information Commissioner’s Office (ICO)

To exercise your rights, please contact us at: enquiries@askgloria.ai

7. Cookies and Tracking

We use cookies and similar technologies to enable core functionality and improve user experience. You can manage or disable cookies in your browser settings. See our Cookie Policy for details.

8. Data Retention

  • Personal/account data: retained only as long as necessary to provide services, meet contractual obligations, or comply with law.
  • Business data via integrations: processed in real time and not stored by us.
  • Conversations: retained securely in encrypted databases to enable continuity and service improvement, with tenant-specific encryption keys.

9. International Data Transfers

Where data is transferred outside the UK (e.g., for hosting or support), we ensure appropriate safeguards are in place, such as Standard Contractual Clauses (SCCs) or reliance on providers in countries deemed adequate by the UK Government.

10. Changes to This Policy

We may update this Privacy Policy from time to time. Updates will be posted on our website and, where appropriate, notified to you by email.

11. Contact Us

If you have any questions about this policy or how we handle your data, please contact: