Privacy Policy
Last updated: 1 June 2024 — QORA AI LIMITED
QORA AI LIMITED ("we", "us", "our") is committed to protecting and respecting your privacy. This Privacy Policy explains how we collect, use, disclose and safeguard information about you when you visit our website at qoraai.codes ("the Website"), contact us through our intake gate or engage our services. We are registered and operate under the laws of England and Wales.
This Privacy Policy is issued in accordance with the requirements of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. We act as the data controller in respect of personal data processed under this policy. Our registered address is 15 Water Lane, Cobham, KT11 2PA, United Kingdom.
Please read this Privacy Policy carefully. By using our Website or submitting information to us, you acknowledge that you have read and understood the terms of this policy. If you do not agree with any part of this Privacy Policy, please do not use our Website or submit information to us.
1. Who We Are
QORA AI LIMITED is a technology services company registered in England and Wales. We provide cloud computing solutions, artificial intelligence development, DevOps engineering, cybersecurity services, data analytics and digital transformation consultancy to business clients in the United Kingdom, European Union and internationally.
For the purposes of data protection legislation, the data controller is QORA AI LIMITED, 15 Water Lane, Cobham, KT11 2PA, United Kingdom. Our contact email address for data protection matters is devops@qoraai.codes.
We are not currently required to register with the Information Commissioner's Office (ICO) as a data controller, but we fully comply with all obligations imposed by UK GDPR and the Data Protection Act 2018. Where we become subject to mandatory registration requirements, we will register accordingly.
2. Information We Collect
We collect and process several categories of personal data depending on how you interact with us. The categories of personal data we may collect are described below.
2.1 Information You Provide Directly
When you complete our contact form, request a service consultation, send us an email or otherwise communicate with us directly, we may collect the following information:
- Your full name
- Your email address
- Your telephone number (if provided)
- Your company or organisation name (if provided)
- The content of your enquiry, requirement description or messages you send to us
- Your job title or role (if provided)
- Any other personal information you choose to include in communications with us
2.2 Technical and Usage Data
When you visit our Website, we may automatically collect certain technical information about your device and your use of our Website, including:
- Your Internet Protocol (IP) address
- Browser type and version
- Operating system
- Referring website addresses
- Pages viewed and time spent on each page
- Date and time of access
- Clickstream data and navigation patterns
- Device type and screen resolution
2.3 Cookie Data
Our Website uses cookies and similar tracking technologies to collect information about your browsing activities. For full details of the cookies we use and how you can control them, please see our Cookie Policy.
2.4 Business Contact Information
In the course of our business operations, we may receive contact details of individuals at organisations that are clients or prospective clients. This may include names, email addresses, telephone numbers and professional information shared with us in a business context.
3. How We Use Your Information
We use the personal data we collect for specific, explicit and legitimate purposes. We will only process your personal data where we have a lawful basis for doing so under UK GDPR.
3.1 To Respond to Enquiries and Provide Services
Lawful basis: Performance of a contract or steps taken at your request prior to entering into a contract (Article 6(1)(b) UK GDPR).
We use your contact information to respond to service enquiries submitted through our intake gate, to classify and assign your technology requirement to the appropriate service line, to provide you with information about our services, and to administer and perform any contractual engagement we enter into with you or your organisation.
3.2 Legitimate Business Interests
Lawful basis: Legitimate interests pursued by us or a third party (Article 6(1)(f) UK GDPR).
We may process your personal data where it is necessary for our legitimate business interests, including: improving our Website and services; maintaining accurate business records; conducting due diligence on prospective clients; communicating relevant service updates to existing clients; ensuring the security of our systems; and managing our business relationships. We have assessed that our legitimate interests are not overridden by your rights and freedoms.
3.3 Compliance with Legal Obligations
Lawful basis: Compliance with a legal obligation (Article 6(1)(c) UK GDPR).
We may be required to process your personal data to comply with legal obligations, including tax and accounting requirements, fraud prevention requirements, court orders and regulatory obligations imposed on our business.
3.4 Marketing Communications
Lawful basis: Consent (Article 6(1)(a) UK GDPR).
Where you have given your explicit consent, we may send you marketing communications about our services, technology insights or company updates. You may withdraw your consent at any time by contacting us at devops@qoraai.codes or by using the unsubscribe mechanism included in any marketing communication we send you.
4. Legal Bases for Processing
We process personal data only where we have a valid lawful basis under Article 6 of UK GDPR. The primary lawful bases we rely upon are:
- Contract: Processing is necessary for the performance of a contract or pre-contractual steps at your request.
- Legal obligation: Processing is necessary to comply with a legal obligation applicable to us as a data controller.
- Legitimate interests: Processing is necessary for our legitimate business interests, provided those interests are not overridden by your rights and freedoms.
- Consent: You have given clear consent to the processing of your personal data for a specific purpose.
5. How We Share Your Information
We do not sell, trade or otherwise transfer your personal data to third parties for commercial purposes. We may share your personal data in the following limited circumstances:
5.1 Service Providers and Sub-processors
We work with carefully selected third-party service providers who process personal data on our behalf under appropriate data processing agreements. These include providers of hosting and cloud infrastructure, email communications, analytics, project management tools and accounting software. All such providers are required to implement appropriate security measures and to process data only on our documented instructions.
5.2 Professional Advisers
We may share personal data with our professional advisers including solicitors, accountants and insurers, to the extent necessary for the provision of their services to us and subject to appropriate confidentiality obligations.
5.3 Legal and Regulatory Disclosure
We may disclose personal data to law enforcement authorities, regulatory bodies or courts where required to do so by law, court order or where we believe disclosure is necessary to prevent fraud, protect the rights or property of QORA AI LIMITED, or to protect the safety of our clients or the public.
5.4 Business Transfers
In the event that we sell, transfer or merge any part of our business or assets, personal data held by us may be transferred to the acquirer. Any such transfer will be subject to appropriate confidentiality obligations and data protection terms.
6. International Data Transfers
We primarily process and store personal data within the United Kingdom and the European Economic Area. Where we transfer personal data outside the UK or EEA, we ensure that appropriate safeguards are in place in accordance with UK GDPR. These safeguards may include adequacy decisions made by the UK Secretary of State, standard contractual clauses approved for use under UK data protection law, or other recognised transfer mechanisms. Where we rely on standard contractual clauses, these are incorporated into our data processing agreements with the relevant recipients.
7. Data Retention
We retain personal data only for as long as is necessary to fulfil the purpose for which it was collected, or as required by applicable law. Our specific retention periods are as follows:
- Enquiry and contact form data: Retained for 24 months from the date of last contact, unless the enquiry results in an active engagement in which case the retention period is extended to the duration of the engagement plus 7 years.
- Client engagement records: Retained for 7 years from the completion of the engagement, in accordance with our statutory accounting and record-keeping obligations under UK law.
- Marketing consent records: Retained for the duration of your consent plus 3 years, or until you withdraw your consent, whichever is earlier.
- Website analytics data: Retained for 26 months in aggregate or anonymised form.
- Security and access logs: Retained for 12 months for security monitoring purposes.
After the applicable retention period, personal data is securely deleted or anonymised such that it can no longer be used to identify individuals.
8. Data Security
We implement appropriate technical and organisational measures to protect personal data against unauthorised or unlawful processing, accidental loss, destruction or damage. These measures include:
- Encryption of personal data in transit using TLS/HTTPS
- Encryption of personal data at rest using industry-standard encryption protocols
- Access controls ensuring that only authorised personnel can access personal data on a need-to-know basis
- Regular security assessments and penetration testing of our systems
- Staff training on data protection obligations and information security practices
- Incident response procedures for managing and reporting personal data breaches
- Secure disposal procedures for hardware and digital storage media
While we take all reasonable steps to protect your personal data, no transmission over the internet or electronic storage system is completely secure. We cannot guarantee absolute security, but we will notify you and any applicable regulatory authority of a personal data breach in accordance with our legal obligations.
9. Your Rights Under UK GDPR
Subject to applicable exemptions and conditions, you have the following rights in relation to your personal data:
9.1 Right of Access
You have the right to request a copy of the personal data we hold about you. We will respond to such requests within one month of receipt, which may be extended by a further two months where requests are complex or numerous.
9.2 Right to Rectification
You have the right to request that we correct any inaccurate or incomplete personal data we hold about you. We will respond to rectification requests within one month.
9.3 Right to Erasure
In certain circumstances, you have the right to request that we delete personal data we hold about you, including where the data is no longer necessary for the purpose for which it was collected, where you withdraw consent and there is no other lawful basis for processing, or where you object to processing and there are no overriding legitimate grounds.
9.4 Right to Restriction of Processing
You have the right to request that we restrict the processing of your personal data in certain circumstances, such as where you contest the accuracy of the data or where you have objected to processing pending verification of our legitimate grounds.
9.5 Right to Data Portability
Where processing is based on your consent or on a contract, and where processing is carried out by automated means, you have the right to receive personal data in a structured, commonly used and machine-readable format, and to request that we transmit that data directly to another controller where technically feasible.
9.6 Right to Object
You have the right to object to the processing of your personal data where processing is based on our legitimate interests or for direct marketing purposes. Where you object to direct marketing, we will cease processing for that purpose immediately. Where you object to processing based on legitimate interests, we will cease processing unless we can demonstrate compelling legitimate grounds that override your rights.
9.7 Rights Related to Automated Decision-Making
You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or significantly affects you. We do not currently conduct solely automated decision-making of this nature.
9.8 Exercising Your Rights
To exercise any of the rights described above, please contact us at devops@qoraai.codes with the subject line "Data Subject Request". We will verify your identity before processing any request. We will not charge a fee for responding to rights requests unless they are manifestly unfounded or excessive, in which case we may charge a reasonable fee or refuse to act on the request.
10. Cookies and Tracking Technologies
Our Website uses cookies and similar technologies. For detailed information about the specific cookies we use, their purpose and your options for managing cookie preferences, please read our Cookie Policy.
11. Children's Privacy
Our Website and services are directed exclusively at business clients and professional users. We do not knowingly collect personal data from individuals under the age of 18. If we become aware that we have inadvertently collected personal data from a person under 18, we will take immediate steps to delete that information. If you believe we have collected personal data from a minor, please contact us at devops@qoraai.codes.
12. Third-Party Links
Our Website may contain links to third-party websites, platforms or services that are not operated by us. This Privacy Policy does not apply to those third-party websites. We have no control over and accept no responsibility for the content, privacy policies or practices of any third-party websites. We strongly encourage you to review the privacy policy of any third-party website you visit.
13. Changes to This Privacy Policy
We reserve the right to update or modify this Privacy Policy at any time. Where we make material changes, we will update the "Last updated" date at the top of this policy and, where appropriate, notify you by email or by placing a prominent notice on our Website. Your continued use of our Website or services after any changes are made constitutes your acceptance of the updated policy. We recommend that you review this Privacy Policy periodically.
14. How to Complain
If you have concerns about how we handle your personal data, please contact us in the first instance at devops@qoraai.codes. We aim to respond to all data protection complaints within 30 days.
If you are not satisfied with our response, you have the right to lodge a complaint with the Information Commissioner's Office (ICO), the supervisory authority for data protection in the United Kingdom. The ICO can be contacted at:
- Website: ico.org.uk
- Telephone: 0303 123 1113
- Post: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, SK9 5AF
15. Contact Us
If you have any questions, concerns or requests relating to this Privacy Policy or our data protection practices, please contact us at:
- Company: QORA AI LIMITED
- Address: 15 Water Lane, Cobham, KT11 2PA, United Kingdom
- Email: devops@qoraai.codes
- Telephone: +44 7512 558811
This Privacy Policy is governed by and construed in accordance with the laws of England and Wales. Any disputes arising in connection with this Privacy Policy shall be subject to the exclusive jurisdiction of the courts of England and Wales.