UK GDPR · Data Protection Act 2018
Privacy Policy
Last updated: 15 July 2026 · Effective date: 15 July 2026
This privacy policy explains how Gordon AI Services ("GAIS", "we", "us", "our") handles personal data when you visit gordonaiservices.com or contact us by email. It is written to comply with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
Who is the data controller
Gordon AI Services is the data controller for any personal data you send to us through this website or by email.
You can reach the controller at: jeff@gordonaiservices.com.
What personal data we collect
We collect the minimum. The only personal data we ever receive from this website is what you choose to send us by email to jeff@gordonaiservices.com.
When you email us, we receive:
- your name (if you include it);
- your email address;
- the contents of your message;
- any attachments you choose to send;
- standard email metadata (date, time, message ID).
That is the full list. We do not collect any other personal data from this website.
What this website does not collect
This website is built to collect as little as possible:
- No analytics scripts. No Google Analytics, no Plausible, no Fathom, no Meta Pixel.
- No tracking pixels or advertising tags. No remarketing, no conversion pixels.
- No third-party scripts at all. No CDN-loaded fonts, no third-party JavaScript, no remote CSS.
- No cookies set by this site. (See our separate cookie notice.)
- No contact or lead forms. The only way to send us information is by emailing us directly.
- No on-site personalisation, A/B testing or fingerprinting.
Your visit to this site is not profiled, scored, segmented or shared with any third party.
Why we use your data (lawful basis)
When you email us, we rely on the lawful basis of legitimate interests (UK GDPR Article 6(1)(f)) to read your message and reply to your enquiry. We will not use your email to add you to a marketing list, share your details, or contact you about anything unrelated to your original enquiry.
If we later enter into a paid engagement with you, the lawful basis for processing related personal data will be contract (Article 6(1)(b)), and we will give you a separate data-handling note covering scope, retention and your rights at that point.
Who we share your data with
We do not sell or rent your personal data. We do not share it with third parties for marketing purposes.
The only parties that may process your email are:
- our email service provider, which hosts jeff@gordonaiservices.com and routes messages to Jeff;
- UK-based IT suppliers who help us maintain our systems under confidentiality.
We do not currently transfer personal data outside the UK. If that changes, we will update this policy and, where required, put appropriate safeguards in place (UK IDTA, UK Addendum to the EU SCCs, or another UK GDPR Article 46 mechanism).
How long we keep your data
Emails are kept only as long as we have a clear reason to keep them:
- general enquiries — kept for up to 12 months, then deleted or anonymised;
- active fit-call or pilot conversations — kept for the duration of the conversation and up to 12 months afterwards;
- paid engagement records — kept for up to 7 years to comply with HMRC record-keeping requirements, then deleted or anonymised.
You can ask us to delete your data earlier than this — see "Your rights" below.
How we protect your data
Email is not a perfectly secure medium. We treat it as semi-confidential:
- mailbox access is protected by a strong unique password and two-factor authentication;
- we never include client, vendor, applicant or property details in initial fit-call emails — see our contact page guidance;
- we do not share confidential material by SMS, WhatsApp or social-media DM;
- backups are encrypted at rest.
If we agree a live-data pilot with you, we will sign a separate data-handling agreement covering approved inputs, retention, deletion and any subprocessors before any real client data is used.
Your rights
Under UK GDPR you have the right to:
- Access — request a copy of the personal data we hold about you;
- Rectification — ask us to correct inaccurate or incomplete data;
- Erasure — ask us to delete your data (the "right to be forgotten");
- Restriction — ask us to limit how we process your data;
- Objection — object to processing based on legitimate interests;
- Portability — receive your data in a structured, commonly used, machine-readable format;
- Withdraw consent — where we rely on consent, withdraw it at any time;
- Complain — lodge a complaint with the Information Commissioner's Office (ICO).
To exercise any of these rights, email jeff@gordonaiservices.com with the subject line "Data rights request". We will respond within one calendar month.
The UK supervisory authority is the Information Commissioner's Office (ICO): ico.org.uk.
Changes to this policy
We will update this page if our data-handling changes in any material way. The "Last updated" date at the top will always show when the policy was last reviewed. Material changes that affect you directly will be communicated by email where appropriate.
Contact
Any questions about this policy, or any privacy-related request, can be sent to jeff@gordonaiservices.com.