Privacy Policy

Last Updated: June 10, 2025

1. Introduction

This Privacy Policy governs the collection, processing, and protection of personal data by ainavi.co.uk ("we", "us", or "our"). As ainavi.co.uk is a website, it is operated by the individual or entity responsible for the website. For the purpose of this policy, we will assume it is operated by [Your Legal Entity Name], registered in [United Kingdom] with company number [Your Company Number, if applicable, otherwise remove] and registered office at [Your Registered Business Address, if applicable, otherwise remove or adapt to a suitable contact address].

We are committed to protecting your privacy and ensuring the security of your personal information in accordance with:

  • The UK General Data Protection Regulation (UK GDPR)

  • The Data Protection Act 2018

  • The Privacy and Electronic Communications Regulations (PECR)

  • Other applicable UK and EU laws

By using our website, you consent to the data practices described in this policy.

2. Detailed Definitions

Personal Data: Any information relating to an identifiable individual (e.g., name, ID number, location data).

Processing: Any operation performed on personal data (collection, recording, organisation, etc.).

Data Controller: The entity determining purposes and means of processing (us).

Data Processor: A third party processing data on our behalf.



3. Comprehensive Data Collection

3.1 Data You Provide Directly

We collect information when you:

  • Register an account (username, password, contact details)

  • Complete forms (contact requests, surveys, applications)

  • Make purchases (billing address, payment details via secure gateways)

  • Subscribe to newsletters (email preferences)

  • Participate in interactive features (comments, reviews)

3.2 Data Collected Automatically

  • Technical Data: IP address, browser type/version, device characteristics

  • Usage Data: Pages visited, time spent, navigation paths, clickstream data

  • Location Data: Approximate geographic location derived from IP address

3.3 Data From Third Parties

We may receive data from:

  • Analytics providers (Google Analytics)

  • Advertising networks (Google Ads, Meta Pixel)

  • Payment processors (Stripe, PayPal)

  • Social media platforms (Facebook, Twitter integrations)

4. Lawful Bases & Processing Purposes

We process data under these UK GDPR Article 6 lawful bases:

PurposeLawful BasisExamplesService deliveryContractual necessityAccount creation, order processingCustomer supportLegitimate interestResponding to inquiriesMarketing communicationsConsentEmail newsletters (opt-in required)Website analyticsLegitimate interestImproving user experienceLegal complianceLegal obligationFraud prevention, tax reporting

5. Data Sharing & International Transfers

5.1 Categories of Recipients

  • IT Service Providers: Hosting companies, cloud storage providers

  • Marketing Platforms: Email service providers (Mailchimp)

  • Payment Processors: Stripe, PayPal (we do not store card details)

  • Professional Advisors: Accountants, lawyers (when necessary)

5.2 International Transfers

Where data is transferred outside the UK, we implement safeguards:

  • UK Adequacy Regulations (for EU/EEA transfers)

  • Standard Contractual Clauses (SCCs)

  • Binding Corporate Rules (BCRs) where applicable

6. Cookie Policy (PECR Compliance)

6.1 Cookie Categories

TypePurposeExamplesConsent RequiredEssentialWebsite functionalitySession cookies, login securityNoPerformanceAnalytics & improvementsGoogle Analytics (anonymized)YesFunctionalEnhanced featuresLanguage preferencesYesTargetingAdvertising & personalizationFacebook PixelYes

6.2 Consent Management

We use a cookie banner with:

  • Clear opt-in for non-essential cookies

  • Granular preference controls

  • Easy withdrawal options

7. Data Retention Schedule

We retain data only as long as necessary:

Data TypeRetention PeriodRationaleAccount data3 years after last activityCustomer relationship managementFinancial records7 yearsLegal obligation (HMRC)Marketing consents2 years after last interactionConsent renewalWebsite analytics26 months (anonymized thereafter)Business intelligence

8. Your Rights (UK GDPR Chapter 3)

8.1 Comprehensive Rights Overview

  1. Right to Access – Obtain a copy of your data (Subject Access Request)

  2. Right to Rectification – Correct inaccurate/incomplete data

  3. Right to Erasure – Request deletion ("right to be forgotten")

  4. Right to Restriction – Limit processing in certain circumstances

  5. Right to Data Portability – Receive your data in a structured format

  6. Right to Object – Stop processing for direct marketing/legitimate interests

  7. Right to Withdraw Consent – For consent-based processing

  8. Right to Complain – Lodge a complaint with the ICO

8.2 How to Exercise Rights

Submit requests to admin@ainavi.co.uk with:

  • Proof of identity (to prevent unauthorized access)

  • Specific details about your request We respond within 30 calendar days (may extend by 2 months for complex requests).

9. Security Measures

We implement state-of-the-art protections:

  • Technical: Encryption (TLS 1.3), firewalls, regular security audits

  • Organizational: Staff training, access controls, data minimization

  • Procedural: Incident response plan, regular backups

10. Children's Data Protection

We do not knowingly collect data from children under 13 without parental consent. Parents may contact us to review or delete such data.

11. Policy Updates & Notification

We will:

  • Post policy changes on this page with a new "Last Updated" date

  • Notify users of material changes via email (where appropriate)

  • Archive previous versions for transparency

12. Contact & Complaints



For questions or to exercise rights:

Email: admin@ainavi.co.uk

Privacy Policy

Last Updated: June 10, 2025

1. Introduction

This Privacy Policy governs the collection, processing, and protection of personal data by ainavi.co.uk ("we", "us", or "our"). As ainavi.co.uk is a website, it is operated by the individual or entity responsible for the website. For the purpose of this policy, we will assume it is operated by [Your Legal Entity Name], registered in [United Kingdom] with company number [Your Company Number, if applicable, otherwise remove] and registered office at [Your Registered Business Address, if applicable, otherwise remove or adapt to a suitable contact address].

We are committed to protecting your privacy and ensuring the security of your personal information in accordance with:

  • The UK General Data Protection Regulation (UK GDPR)

  • The Data Protection Act 2018

  • The Privacy and Electronic Communications Regulations (PECR)

  • Other applicable UK and EU laws

By using our website, you consent to the data practices described in this policy.

2. Detailed Definitions

Personal Data: Any information relating to an identifiable individual (e.g., name, ID number, location data).

Processing: Any operation performed on personal data (collection, recording, organisation, etc.).

Data Controller: The entity determining purposes and means of processing (us).

Data Processor: A third party processing data on our behalf.



3. Comprehensive Data Collection

3.1 Data You Provide Directly

We collect information when you:

  • Register an account (username, password, contact details)

  • Complete forms (contact requests, surveys, applications)

  • Make purchases (billing address, payment details via secure gateways)

  • Subscribe to newsletters (email preferences)

  • Participate in interactive features (comments, reviews)

3.2 Data Collected Automatically

  • Technical Data: IP address, browser type/version, device characteristics

  • Usage Data: Pages visited, time spent, navigation paths, clickstream data

  • Location Data: Approximate geographic location derived from IP address

3.3 Data From Third Parties

We may receive data from:

  • Analytics providers (Google Analytics)

  • Advertising networks (Google Ads, Meta Pixel)

  • Payment processors (Stripe, PayPal)

  • Social media platforms (Facebook, Twitter integrations)

4. Lawful Bases & Processing Purposes

We process data under these UK GDPR Article 6 lawful bases:

PurposeLawful BasisExamplesService deliveryContractual necessityAccount creation, order processingCustomer supportLegitimate interestResponding to inquiriesMarketing communicationsConsentEmail newsletters (opt-in required)Website analyticsLegitimate interestImproving user experienceLegal complianceLegal obligationFraud prevention, tax reporting

5. Data Sharing & International Transfers

5.1 Categories of Recipients

  • IT Service Providers: Hosting companies, cloud storage providers

  • Marketing Platforms: Email service providers (Mailchimp)

  • Payment Processors: Stripe, PayPal (we do not store card details)

  • Professional Advisors: Accountants, lawyers (when necessary)

5.2 International Transfers

Where data is transferred outside the UK, we implement safeguards:

  • UK Adequacy Regulations (for EU/EEA transfers)

  • Standard Contractual Clauses (SCCs)

  • Binding Corporate Rules (BCRs) where applicable

6. Cookie Policy (PECR Compliance)

6.1 Cookie Categories

TypePurposeExamplesConsent RequiredEssentialWebsite functionalitySession cookies, login securityNoPerformanceAnalytics & improvementsGoogle Analytics (anonymized)YesFunctionalEnhanced featuresLanguage preferencesYesTargetingAdvertising & personalizationFacebook PixelYes

6.2 Consent Management

We use a cookie banner with:

  • Clear opt-in for non-essential cookies

  • Granular preference controls

  • Easy withdrawal options

7. Data Retention Schedule

We retain data only as long as necessary:

Data TypeRetention PeriodRationaleAccount data3 years after last activityCustomer relationship managementFinancial records7 yearsLegal obligation (HMRC)Marketing consents2 years after last interactionConsent renewalWebsite analytics26 months (anonymized thereafter)Business intelligence

8. Your Rights (UK GDPR Chapter 3)

8.1 Comprehensive Rights Overview

  1. Right to Access – Obtain a copy of your data (Subject Access Request)

  2. Right to Rectification – Correct inaccurate/incomplete data

  3. Right to Erasure – Request deletion ("right to be forgotten")

  4. Right to Restriction – Limit processing in certain circumstances

  5. Right to Data Portability – Receive your data in a structured format

  6. Right to Object – Stop processing for direct marketing/legitimate interests

  7. Right to Withdraw Consent – For consent-based processing

  8. Right to Complain – Lodge a complaint with the ICO

8.2 How to Exercise Rights

Submit requests to admin@ainavi.co.uk with:

  • Proof of identity (to prevent unauthorized access)

  • Specific details about your request We respond within 30 calendar days (may extend by 2 months for complex requests).

9. Security Measures

We implement state-of-the-art protections:

  • Technical: Encryption (TLS 1.3), firewalls, regular security audits

  • Organizational: Staff training, access controls, data minimization

  • Procedural: Incident response plan, regular backups

10. Children's Data Protection

We do not knowingly collect data from children under 13 without parental consent. Parents may contact us to review or delete such data.

11. Policy Updates & Notification

We will:

  • Post policy changes on this page with a new "Last Updated" date

  • Notify users of material changes via email (where appropriate)

  • Archive previous versions for transparency

12. Contact & Complaints



For questions or to exercise rights:

Email: admin@ainavi.co.uk