Legal

Privacy Policy

Last updated: 10 April 2026 · Effective date: 10 April 2026

Plain English summary: We collect only what we need to run the service. We never sell your data. Your business data stays yours. You can delete everything at any time.

1. Who we are

AskBiz Ltd ("AskBiz", "we", "us", "our") is the data controller responsible for your personal data.

Registered address: AskBiz Ltd, London, United Kingdom

Data Protection contact: privacy@askbiz.co

AskBiz operates a business intelligence platform that allows users to upload business data and receive AI-powered analytical insights. We are subject to the UK General Data Protection Regulation (UK GDPR), the EU General Data Protection Regulation (EU GDPR 2016/679), and the California Consumer Privacy Act (CCPA) where applicable.

2. Data we collect and why

2.1 Account data

When you create an account we collect: name, email address, business type, and country. Legal basis: Contract — necessary to provide the service.

2.2 Business data you upload

CSV, XLSX, or other files you upload ("Business Data") are processed solely to provide you with analytical responses. We do not use your Business Data to train AI models, sell to third parties, or share with any other user. Legal basis: Contract.

Business Data is encrypted at rest (AES-256) and in transit (TLS 1.3). Files are stored in isolated per-user storage and are not accessible to other users or AskBiz employees without your explicit request.

2.3 Usage data

We collect anonymised usage data including: pages visited, features used, query counts, and session duration. This helps us improve the product. Legal basis: Legitimate interests.

2.4 Payment data

Payments are processed by Stripe, Inc. We do not store card numbers, CVV codes, or full payment details. We receive a tokenised reference and subscription status from Stripe. Stripe's privacy policy governs payment data handling.

2.5 Communication data

If you contact us by email, we retain that correspondence for up to 3 years to resolve disputes and improve support quality.

2.6 Technical data

IP address, browser type, device type, operating system, and referral source. Used for security monitoring, fraud prevention, and service improvement. Legal basis: Legitimate interests.

3. How we use your data

We use your data exclusively to:

  • Provide and maintain the AskBiz platform
  • Process your AI queries and return analytical responses
  • Manage your account and subscription
  • Send transactional emails (confirmations, alerts, invoices)
  • Detect and prevent fraud or abuse
  • Comply with legal obligations
  • Improve the product through aggregated, anonymised analytics

We do not use your data to: train AI models on your business data, serve advertising, sell or rent your data to any third party, or make automated decisions with legal or significant effects without human review.

4. Data sharing and third parties

We share data only with the following categories of processors, all bound by data processing agreements:

ProcessorPurposeLocationSafeguard
Supabase, Inc.Database and authenticationUSA / EUSCCs + SOC2 Type II
Anthropic, PBCAI query processingUSASCCs + enterprise DPA
Stripe, Inc.Payment processingUSA / EUSCCs + PCI-DSS Level 1
Vercel, Inc.Hosting and deliveryUSA / EUSCCs + SOC2 Type II
Resend, Inc.Transactional emailUSASCCs

We do not transfer data to countries without adequate protection unless appropriate safeguards (Standard Contractual Clauses or equivalent) are in place.

5. Data retention

We retain your data for as long as your account is active. Upon account deletion:

  • Account and profile data: deleted within 30 days
  • Uploaded Business Data: deleted within 7 days
  • Conversation history: deleted within 30 days
  • Payment records: retained for 7 years (legal obligation)
  • Anonymised usage analytics: retained indefinitely (no personal data)

You can request immediate deletion of your Business Data at any time from Settings → Delete my data, or by emailing privacy@askbiz.co.

6. Your rights

Depending on your location, you have the following rights:

RightWhat it meansApplies under
AccessReceive a copy of your personal dataGDPR, UK GDPR, CCPA
RectificationCorrect inaccurate dataGDPR, UK GDPR
ErasureDelete your account and all dataGDPR, UK GDPR, CCPA
PortabilityExport your data in machine-readable formatGDPR, UK GDPR
RestrictionLimit how we process your dataGDPR, UK GDPR
ObjectionObject to legitimate interests processingGDPR, UK GDPR
Opt-out of saleWe do not sell data — right automatically metCCPA
Non-discriminationEqual service regardless of privacy choicesCCPA

To exercise any right, email privacy@askbiz.co. We will respond within 30 days. We may ask you to verify your identity before fulfilling a request.

If you are in the EU or UK and believe we have handled your data unlawfully, you have the right to lodge a complaint with your local supervisory authority (UK: ICO at ico.org.uk; EU: your national DPA).

7. Cookies

We use the following cookies:

CookiePurposeDuration
sb-auth-tokenAuthentication sessionSession
signalx-preferencesUser settings (currency, theme)1 year
_vercel_analyticsAnonymous usage analytics30 days

We do not use advertising cookies or third-party tracking cookies. You can clear cookies in your browser settings at any time. Clearing the authentication cookie will sign you out.

8. Security

We implement industry-standard security measures including:

  • TLS 1.3 encryption for all data in transit
  • AES-256 encryption for data at rest
  • Row-level security (RLS) in our database — users can only access their own data
  • SOC 2 Type II compliant infrastructure providers
  • Regular security reviews and penetration testing
  • Staff access controls on a need-to-know basis
  • Multi-factor authentication for all internal systems

In the event of a data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours and affected users without undue delay, as required by GDPR Article 33.

9. Children's privacy

AskBiz is not directed at children under the age of 16. We do not knowingly collect personal data from children. If you believe we have inadvertently collected data from a child, please contact us immediately at privacy@askbiz.co and we will delete it promptly.

10. Changes to this policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email and by displaying a prominent notice in the app at least 14 days before the changes take effect. Continued use of AskBiz after the effective date constitutes acceptance of the updated policy.

All previous versions of this policy are archived and available on request.

11. Contact us

For any privacy-related questions, requests, or concerns:

Email: privacy@askbiz.co

Post: AskBiz Ltd, London, United Kingdom

We aim to respond to all privacy enquiries within 5 business days.

Terms of Service← Back to AskBiz