Controller and contact

Brackenfold AI Services Ltd is responsible for personal information collected for its own website administration and business enquiries. Its registered address is 28 Alderwick Close, Ancoats, Manchester, M4 6LN, United Kingdom. Privacy enquiries should be sent to [email protected] with “Privacy” in the subject line.

Where we process information on behalf of a client, the client may be the controller and we may act as a processor. The relevant agreement determines responsibilities, instructions and any additional privacy information required for that work.

Information collected and why

When you send an enquiry, we receive the information you include, such as your name, email address, organisation and description of requirements. The contact form prepares an email draft on your device. It does not transmit its fields to us when you select “Prepare email draft”; we receive the message only if you send it through your email service.

Web hosting and security systems may process technical information such as IP addresses, request times, requested pages, browser details and error records. These records support delivery, troubleshooting and protection against misuse. Please do not include passwords, special-category personal information or confidential client records in an initial enquiry.

We use enquiry information to respond, assess potential work and administer business communications. Applicable lawful bases include taking steps at your request before entering a contract, legitimate interests in running and protecting the business, and compliance with legal obligations. Where consent is required for a particular activity, it is obtained separately and can be withdrawn.

Cookies and similar storage are addressed in the cookie policy. The website is not configured to use Google Analytics or Google Tag Manager. Optional tracking must be assessed against the applicable consent requirements before being introduced.

Service providers and international transfers

Hosting providers, email providers, technical support providers and professional advisers may process information where necessary for their functions. Access is limited to the purpose of the service and subject to appropriate contractual or professional obligations. We do not sell enquiry information or use it for cross-context behavioural advertising.

A provider may process information outside the United Kingdom. Where a restricted transfer occurs, the relevant safeguards must be established, such as an adequacy arrangement or approved contractual protections, together with any required transfer assessment. Information about safeguards relevant to your enquiry can be requested using the privacy contact above.

Contact messages are not submitted to an AI model by this website. Any use of client information in an AI service requires a separately agreed purpose, provider assessment and processing arrangement.

Retention and protection

Information is retained only while needed for its stated purpose, relevant legal obligations or the establishment, exercise or defence of legal claims. Enquiries that do not lead to work are reviewed for deletion when follow-up is no longer reasonably needed. Contract and accounting records follow the applicable business retention requirements. Technical records are retained according to operational and security needs.

Access controls, appropriate provider settings and limited sharing are used to reduce risk. No online service or email channel can guarantee absolute security. If you believe information has been disclosed incorrectly, contact us promptly without forwarding additional sensitive material unnecessarily.

Your rights and complaints

The UK GDPR and the Data Protection Act 2018, as amended, govern relevant UK processing. Depending on the circumstances, you may request access, correction, erasure, restriction or portability, object to processing, or withdraw consent. We may need proportionate identity checks before responding. Exceptions and statutory limits may apply.

The EU GDPR may also apply where its territorial conditions are met. California residents may have rights under the CCPA, as amended by the CPRA, where that legislation applies to the business and processing concerned, including rights relating to access, correction, deletion and sale or sharing. Exercising an applicable privacy right will not result in unlawful discrimination.

You may complain to the Information Commissioner’s Office or another competent supervisory authority. You can contact us first so that we can address the concern, but this does not limit your right to complain directly. Material changes to our handling of information will be reflected in this policy.