Privacy Policy

Last updated 31 July 2026

This policy explains what personal data AvanzaProntoAI collects, why we collect it, how long we keep it and what rights you have. We have tried to write it in plain English rather than legal boilerplate, because you should be able to understand it without a solicitor.

1. Who we are

AvanzaProntoAI ("we", "us") provides AI workflow automation services to businesses in the United Kingdom. We are the data controller for the personal data described in this policy.

Contact: hello@avanzapronto-ai.co.uk

Before you publish: replace this box with your registered business name, trading address and, if you have one, your ICO registration number. If you operate as a sole trader you must still give a contact address. This is a legal requirement under UK GDPR Article 13, not a formality.

2. What we collect

When you use the workflow builder

If you type a description of a business process into the "Build my workflow" tool and press generate, we receive:

  • The process description you wrote, in your own words
  • The frequency figure you selected
  • The workflow, integrations and estimates our system generated in response
  • The page you were on and the site you arrived from, if any
  • Your IP address and approximate country, recorded by our hosting provider

Please do not include customer names, account numbers, health information or other personal details of third parties in the description. Describe the shape of the process, not the people in it. If you do include such details, we will delete them on request.

When you request the assessment report

If you ask us to send the report, we additionally collect the email address you provide.

When you book an audit call

Bookings are handled by Calendly, which collects your name, email address and chosen time slot. Calendly processes this under its own privacy policy.

When you buy the AI Automation Sprint

Payments are processed by Stripe. Stripe collects your card details, billing address, phone number, company name and any process description you enter at checkout. We never see or store your full card number. We receive confirmation of payment plus the contact and company details you supplied.

When we deliver a project

Building an automation usually requires access to systems you already use. Where that involves personal data belonging to your customers or staff, you remain the data controller and we act as your data processor. Section 8 covers this.

3. Why we use it, and our lawful basis

What we doLawful basis
Generate a workflow from your description and show it back to youLegitimate interests — providing the service you asked for
Email you the assessment report you requestedLegitimate interests — responding to a direct request
Follow up once about your free auditLegitimate interests — B2B marketing to a business contact who approached us
Take payment and deliver the sprintPerformance of a contract
Keep financial recordsLegal obligation — HMRC requires six years
Understand which processes people ask about, in aggregateLegitimate interests — improving what we offer

Where we rely on legitimate interests, we have considered whether our interest is outweighed by your rights. You can object at any time — see section 7.

4. Marketing

If you give us your email address to receive the report, we will send you the report and one follow-up message about the free audit. That is what the form promises and that is what we do.

We do not add you to a mailing list, sell your details or pass them to anyone for marketing. Every message we send includes a way to opt out, and one reply asking us to stop is enough.

5. Who we share it with

We use the following providers, each of which processes data on our behalf:

ProviderPurpose
VercelWebsite hosting and server logs
n8nRouting enquiries into our own systems
Google (Gmail / Workspace)Email correspondence
HubSpotRecording enquiries and client records
StripePayment processing
CalendlyBooking audit calls
AnthropicGenerating workflow suggestions from your description

We do not sell personal data. We will disclose data where the law requires it, or to establish or defend a legal claim.

6. International transfers

Some of the providers above are based in the United States or store data there. Where personal data leaves the UK, it is protected by the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or an adequacy decision, depending on the provider.

7. How long we keep it

  • Workflow descriptions with no email attached — 12 months, then deleted
  • Enquiries where you gave an email — 24 months from last contact
  • Client records and project documentation — 6 years after the engagement ends
  • Financial records — 6 years, as HMRC requires
  • Server logs — as retained by our hosting provider, typically 30 days

8. Your rights

Under UK GDPR you have the right to:

  • Ask what personal data we hold about you, and get a copy
  • Have inaccurate data corrected
  • Have your data deleted, where we have no overriding reason to keep it
  • Restrict or object to how we use it, including objecting to marketing at any time
  • Receive your data in a portable format
  • Withdraw consent, where we relied on consent

Email hello@avanzapronto-ai.co.uk and we will respond within one month. There is no charge.

If you are not satisfied with our response you can complain to the Information Commissioner's Office at ico.org.uk or on 0303 123 1113. We would rather you raised it with us first, but that is your right either way.

9. When we work on your systems

During a sprint we may process personal data that belongs to your business — your customers, your staff. In that relationship you are the controller and we are the processor. We will:

  • Only process that data on your documented instructions
  • Use official APIs and the narrowest permissions the automation needs
  • Keep it confidential and not use it for our own purposes
  • Tell you without undue delay if we become aware of a breach
  • Delete or return it when the engagement ends, unless you ask otherwise

For engagements involving significant volumes of personal data we will put a written data processing agreement in place before work starts.

10. Cookies

This site sets no advertising or analytics cookies. We do not track you across other websites. Our hosting provider may set strictly necessary cookies required to serve the site securely; these are exempt from consent requirements under PECR.

If we add analytics in future, we will update this policy and ask for your consent first.

11. Security

We use encrypted connections throughout, restrict access to client data to those who need it, and connect to your systems using official integrations with scoped permissions rather than shared passwords. No system is perfectly secure, but we do not take shortcuts with other people's data.

12. Children

Our services are for businesses. We do not knowingly collect data from anyone under 18.

13. Changes to this policy

If we change this policy we will update the date at the top. Material changes affecting how we use data you have already given us will be notified by email where we hold one.