Legal

Privacy Policy

Last updated: 27 September 2026

Hyphosxai Ltd (trading as HyphosXAI) respects your privacy. This Privacy Policy explains how we collect, use, store, and share personal data when you visit https://hyphosxai.com or use our services.

This policy is written for a UK marketing site and related AI service offerings. It is intended as clear operational information for visitors and clients. It is not a substitute for formal legal advice.


1. Who we are (data controller)

Controller: Hyphosxai Ltd (trading as HyphosXAI)
Companies House number: 17216294
SIC: 62012 (Business and domestic software development)
Incorporated: 13 May 2026
Registered office: The Grain Barn West, Lordship Farm, Church Lane, Ware, United Kingdom, SG12 0NS
Website: https://hyphosxai.com
Telephone: +44 7415 166681

Privacy / data-protection email: legal@hyphosxai.com

For data-protection enquiries and to exercise your rights, please contact us by telephone on +44 7415 166681 or email legal@hyphosxai.com.

We are the controller of personal data processed in connection with our website and the services we provide, except where we act as a processor on a client’s documented instructions (for example under a separate data processing agreement for enterprise engagements).


2. Scope

This policy covers:

  • Visitors to our marketing website
  • People who enquire about or purchase our services
  • Clients using our AI operating desks and related packages
  • Newsletter or marketing subscribers (only if you opt in)
  • Business contacts at organisations we think may be interested in our services

It does not replace any separate contract, statement of work, or data processing agreement we may enter into with a business client.


3. What we collect

Depending on how you interact with us, we may process:

3.1 Enquiry and contact data

When you use our enquiry form we collect your name, work email address, the service you are enquiring about and your message. Our system also records the page you sent it from and the time it was sent. If you contact us by email or phone, we collect the details and content you share. To prevent spam, the form uses a hidden field and keeps a one-way coded (hashed) version of your IP address to limit repeat submissions.

3.2 Account and service data

Account identifiers, configuration preferences, workspace or project details you supply, and records needed to deliver the service.

3.3 Billing and payment data

Billing contact details, company details for invoices, payment status, and transaction metadata. Card payments (when live) are processed by Stripe; we do not store full card numbers on our systems.

3.4 Messages, files, and content you provide to assistants

Prompts, instructions, uploaded files, and outputs generated in the course of using our AI operating desks (for example Founder Desk, Pipeline Desk, Books Copilot, Content Desk, Sprint Pilot) and related website packages.

3.5 Connector and authorisation data

Where you authorise connectors (for example email, calendar, Slack, CRM, Xero, Stripe, or other tools), we may process OAuth tokens, scopes you grant, and technical metadata needed to maintain the connection. You control which tools you connect and the permissions you approve.

3.6 Usage and technical logs

IP address, device/browser type, approximate location derived from IP, pages viewed, timestamps, error logs, and similar technical data needed for security, performance, and troubleshooting.

3.7 Marketing preferences

Newsletter or marketing opt-in status and related preference records, only where you have chosen to receive them.

3.8 Cookies and similar technologies

Information collected via cookies and similar technologies, as described in our Cookies Policy and summarised in section 11 below.

3.9 Business contact data

If we contact you about our services at work, we use your name, job title, business email address, company name and where we found your details (for example your company's website or Companies House).

We do not intentionally collect special category data unless you choose to include it in content you send us. Please avoid sending unnecessary sensitive personal data.


4. Why we use your data and lawful bases (UK GDPR)

Purpose Examples Lawful basis
Respond to enquiries Quote requests, demos, support Legitimate interests (responding to business enquiries); contract where steps are taken at your request
Provide services Operate AI desks, Sprint Pilot, website packages Contract
Billing and accounting Invoices, Stripe payments, records Contract; legal obligation
Improve and secure services Logs, abuse prevention, reliability Legitimate interests (security and service integrity)
AI processing to deliver outputs Prompts/outputs via AI providers (e.g. xAI/Grok) Contract; legitimate interests in delivering the service
Marketing Newsletters, product updates, and emails to business contacts about our services Emails to individuals and sole traders: consent (or an existing customer relationship where the law allows). Emails to business contacts at companies and LLPs: legitimate interests. You can opt out at any time.
Cookies (non-essential) Analytics/marketing cookies Consent
Legal compliance Responding to lawful requests, defending claims Legal obligation; legitimate interests

Where we rely on legitimate interests, we balance those interests against your rights and freedoms. You may object to processing based on legitimate interests (see section 10).

Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of processing before withdrawal.


5. AI processing and human oversight

Our services use AI systems (including models provided by third parties such as xAI / Grok) to help draft, summarise, research, and automate workflows.

Please note:

  • Prompts, files, and outputs you provide or generate may be processed by us and by AI model providers to deliver the service.
  • Where a service is operated with human oversight, clients typically approve external actions before they are taken.
  • AI outputs may be incomplete, outdated, or incorrect. They are tools to assist you; they are not a substitute for professional judgement.
  • Books Copilot (including Xero-aware features) is an assistance tool only. It does not provide accountancy, audit, or tax advice.
  • We do not guarantee the accuracy of AI-generated content. You remain responsible for reviewing outputs before publishing, sending externally, or relying on them for business decisions.

Further detail on use of the services appears in our Terms of Use.


6. Who we share data with

We share personal data only where needed for the purposes above, including with:

  • Stripe — payment processing (when live)
  • IONOS Cloud Ltd — hosts our website and processes enquiry form submissions, which it sends on to our company mailbox
  • Google (Google Workspace) — hosts our company email, including enquiries sent through our form
  • AI model providers — such as xAI/Grok, to process prompts and generate outputs as part of the service
  • Connector providers you authorise — email, calendar, Slack, CRM, Xero, Stripe, and similar tools, according to the scopes you approve
  • Analytics providers — only where you have consented to analytics cookies (if enabled)
  • Professional advisers — lawyers, accountants, insurers, where reasonably necessary
  • Authorities — where required by law

IONOS Cloud Ltd and Google handle personal data on our behalf to provide these services, under their standard business terms. AI model providers process prompts and outputs for us under their business terms. Stripe, connector providers you authorise, professional advisers and authorities are not our processors. They handle personal data under their own terms, professional duties or legal powers, and are responsible for it themselves.

We do not sell your personal data.

Our company books and banking stack may use Xero and Tide. Clients may use their own tools; any client-side connections remain under the client’s authorisation and account policies.


7. International transfers

Some providers (including certain AI and cloud services) may process data outside the United Kingdom.

Where personal data is transferred internationally, we use appropriate safeguards permitted under UK data protection law, which may include:

  • Transfers to countries covered by a UK adequacy regulation
  • The UK International Data Transfer Agreement (IDTA) and/or the UK Addendum to the EU Standard Contractual Clauses (SCCs), as applicable
  • Other lawful transfer mechanisms and supplementary measures assessed as appropriate for the risk

We keep transfer arrangements under review as our provider stack evolves. Enterprise clients may receive further detail under a separate data processing agreement.


8. How long we keep data

We retain personal data only as long as reasonably necessary for the purposes set out in this policy, including:

  • Enquiry data: up to 12 months after our last contact with you, unless you become a customer (then the customer periods below apply) or we need it longer for a legal claim.
  • Customer / service data: for the life of the contract and a reasonable period afterwards (often up to 6 years for contractual records, aligned with limitation periods)
  • Billing and accounting records: as required by law (commonly up to 6 years)
  • Marketing preferences: until you unsubscribe or we delete inactive lists
  • Cookies: as described in the Cookies Policy (or until you clear them / withdraw consent)
  • Security logs: typically shorter operational periods unless needed for investigations

Exact periods may vary by record type. When data is no longer needed, we delete or anonymise it where practicable.


9. Security

We take appropriate technical and organisational measures to protect personal data against unauthorised access, loss, or misuse. Measures may include access controls, encryption in transit where appropriate, least-privilege practices, and staff awareness.

No method of transmission or storage is completely secure. We do not claim absolute security. Please use strong credentials for any accounts and notify us promptly of suspected unauthorised access.


10. Your rights

Under UK GDPR, you have rights in relation to your personal data, including:

  • Access — to obtain a copy of personal data we hold about you
  • Rectification — to correct inaccurate or incomplete data
  • Erasure — to request deletion in certain circumstances
  • Restriction — to limit processing in certain circumstances
  • Portability — to receive certain data in a structured, commonly used format
  • Object — to object to processing based on legitimate interests, and to object to direct marketing. If you object to direct marketing, we will stop, and we keep your email address on a suppression list so we don't contact you again.
  • Withdraw consent — where processing is based on consent
  • Complain — to the Information Commissioner’s Office (ICO)

ICO contact: https://ico.org.uk | Telephone: 0303 123 1113

To exercise your rights, contact us by telephone on +44 7415 166681 (or email legal@hyphosxai.com). We may need to verify your identity before responding. We aim to respond within one month, subject to UK GDPR rules.

Some rights are not absolute (for example where we must keep records for legal obligations or to establish/defend legal claims).


11. Cookies (summary)

We use cookies and similar technologies as described in our dedicated Cookies Policy.

In short:

  • Strictly necessary storage is used to make the site work, for example to remember your cookie choices. It does not need your consent, but we still describe it.
  • Preferences, analytics, and marketing cookies (if used) are only set with your consent, via a separate cookie consent mechanism — not by accepting this Privacy Policy or our Terms.
  • You can change your preferences at any time via Cookie settings (footer) and through browser controls.

Please read the Cookies Policy for what we store, why, how long it lasts, and which third parties (if any) are involved.


12. Children

Our website and services are aimed at businesses and adults. They are not directed at individuals under 18. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us so we can delete it.


13. Changes to this policy

We may update this Privacy Policy from time to time. The “Last updated” date at the top will change when we do. Material changes may be highlighted on the website or notified to clients where appropriate. Please check this page periodically.


14. Contact

Hyphosxai Ltd
The Grain Barn West, Lordship Farm, Church Lane, Ware, United Kingdom, SG12 0NS
Telephone: +44 7415 166681

For privacy rights and data-protection questions, use the telephone number above or email legal@hyphosxai.com.