Privacy Policy
Last updated 31 July 2026
This policy explains what personal data AvanzaProntoAI collects, why we collect it, how long we keep it and what rights you have. We have tried to write it in plain English rather than legal boilerplate, because you should be able to understand it without a solicitor.
1. Who we are
AvanzaProntoAI ("we", "us") provides AI workflow automation services to businesses in the United Kingdom. We are the data controller for the personal data described in this policy.
Contact: hello@avanzapronto-ai.co.uk
Before you publish: replace this box with your registered business name, trading address and, if you have one, your ICO registration number. If you operate as a sole trader you must still give a contact address. This is a legal requirement under UK GDPR Article 13, not a formality.
2. What we collect
When you use the workflow builder
If you type a description of a business process into the "Build my workflow" tool and press generate, we receive:
- The process description you wrote, in your own words
- The frequency figure you selected
- The workflow, integrations and estimates our system generated in response
- The page you were on and the site you arrived from, if any
- Your IP address and approximate country, recorded by our hosting provider
Please do not include customer names, account numbers, health information or other personal details of third parties in the description. Describe the shape of the process, not the people in it. If you do include such details, we will delete them on request.
When you request the assessment report
If you ask us to send the report, we additionally collect the email address you provide.
When you book an audit call
Bookings are handled by Calendly, which collects your name, email address and chosen time slot. Calendly processes this under its own privacy policy.
When you buy the AI Automation Sprint
Payments are processed by Stripe. Stripe collects your card details, billing address, phone number, company name and any process description you enter at checkout. We never see or store your full card number. We receive confirmation of payment plus the contact and company details you supplied.
When we deliver a project
Building an automation usually requires access to systems you already use. Where that involves personal data belonging to your customers or staff, you remain the data controller and we act as your data processor. Section 8 covers this.
3. Why we use it, and our lawful basis
| What we do | Lawful basis |
|---|---|
| Generate a workflow from your description and show it back to you | Legitimate interests — providing the service you asked for |
| Email you the assessment report you requested | Legitimate interests — responding to a direct request |
| Follow up once about your free audit | Legitimate interests — B2B marketing to a business contact who approached us |
| Take payment and deliver the sprint | Performance of a contract |
| Keep financial records | Legal obligation — HMRC requires six years |
| Understand which processes people ask about, in aggregate | Legitimate interests — improving what we offer |
Where we rely on legitimate interests, we have considered whether our interest is outweighed by your rights. You can object at any time — see section 7.
4. Marketing
If you give us your email address to receive the report, we will send you the report and one follow-up message about the free audit. That is what the form promises and that is what we do.
We do not add you to a mailing list, sell your details or pass them to anyone for marketing. Every message we send includes a way to opt out, and one reply asking us to stop is enough.
5. Who we share it with
We use the following providers, each of which processes data on our behalf:
| Provider | Purpose |
|---|---|
| Vercel | Website hosting and server logs |
| n8n | Routing enquiries into our own systems |
| Google (Gmail / Workspace) | Email correspondence |
| HubSpot | Recording enquiries and client records |
| Stripe | Payment processing |
| Calendly | Booking audit calls |
| Anthropic | Generating workflow suggestions from your description |
We do not sell personal data. We will disclose data where the law requires it, or to establish or defend a legal claim.
6. International transfers
Some of the providers above are based in the United States or store data there. Where personal data leaves the UK, it is protected by the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or an adequacy decision, depending on the provider.
7. How long we keep it
- Workflow descriptions with no email attached — 12 months, then deleted
- Enquiries where you gave an email — 24 months from last contact
- Client records and project documentation — 6 years after the engagement ends
- Financial records — 6 years, as HMRC requires
- Server logs — as retained by our hosting provider, typically 30 days
8. Your rights
Under UK GDPR you have the right to:
- Ask what personal data we hold about you, and get a copy
- Have inaccurate data corrected
- Have your data deleted, where we have no overriding reason to keep it
- Restrict or object to how we use it, including objecting to marketing at any time
- Receive your data in a portable format
- Withdraw consent, where we relied on consent
Email hello@avanzapronto-ai.co.uk and we will respond within one month. There is no charge.
If you are not satisfied with our response you can complain to the Information Commissioner's Office at ico.org.uk or on 0303 123 1113. We would rather you raised it with us first, but that is your right either way.
9. When we work on your systems
During a sprint we may process personal data that belongs to your business — your customers, your staff. In that relationship you are the controller and we are the processor. We will:
- Only process that data on your documented instructions
- Use official APIs and the narrowest permissions the automation needs
- Keep it confidential and not use it for our own purposes
- Tell you without undue delay if we become aware of a breach
- Delete or return it when the engagement ends, unless you ask otherwise
For engagements involving significant volumes of personal data we will put a written data processing agreement in place before work starts.
10. Cookies
This site sets no advertising or analytics cookies. We do not track you across other websites. Our hosting provider may set strictly necessary cookies required to serve the site securely; these are exempt from consent requirements under PECR.
If we add analytics in future, we will update this policy and ask for your consent first.
11. Security
We use encrypted connections throughout, restrict access to client data to those who need it, and connect to your systems using official integrations with scoped permissions rather than shared passwords. No system is perfectly secure, but we do not take shortcuts with other people's data.
12. Children
Our services are for businesses. We do not knowingly collect data from anyone under 18.
13. Changes to this policy
If we change this policy we will update the date at the top. Material changes affecting how we use data you have already given us will be notified by email where we hold one.