A privacy notice is usually written to be legally sufficient and practically unreadable. This one is meant to be read by the person it concerns. If any part of it is unclear, that is a fault in our drafting and we would like to know about it.
This notice explains what Maxi AI Development Ltd does with personal data — what we collect, why we are allowed to hold it, how long we keep it, who else sees it, and what you can require us to do about it. It is written to be read, not to be survived. Where we have had to use a legal term, we have said what it means.
For everything described in this notice, Maxi AI Development Ltd is the data controller. That means we are the organisation that decides why your personal data is processed and how, and we are the organisation legally answerable for it.
| Registered name | Maxi AI Development Ltd |
| Registered in | England and Wales, company number 15819925 |
| Incorporated | 4 July 2024 |
| Registered office | Flat 2, 82 Crouch Hill, London N8 9ED, United Kingdom |
| ICO registration | ZB907965 — registered with the Information Commissioner's Office as a data controller |
| Data protection contact | [email protected] |
We are a two-person company. We are not required to appoint a statutory Data Protection Officer and we have not appointed one. Data protection questions are handled by the founders directly, at the address above, and you will get an answer from a person who knows the systems rather than from a queue.
This notice applies to the website at maxiai.co.uk, to enquiries and correspondence you send us, to our relationships with clients and suppliers, and to the business-to-business prospecting described in clause 05.
We operate a separate, invite-only social media dashboard at socials.maxiai.co.uk. That is a different product with a different data footprint, and it is governed by its own privacy notice and its own terms, presented to you when you are invited to it. Nothing in this notice describes what happens inside that application.
A large part of our work is building and maintaining systems that belong to our clients — websites, hosting, Microsoft 365 estates, bespoke software. When we work inside a client’s systems, any personal data in them belongs to that client. They are the controller, we are their processor, and we act only on their documented instructions under a written agreement that meets Article 28 of the UK GDPR.
If you are a customer, employee or contact of one of our clients and you want to exercise your rights over data held in their systems, your request needs to go to them, not to us. If you send it to us anyway, we will pass it on and tell you that we have.
We collect very little, and almost all of it is business contact information that you or your employer has already put into commercial circulation. Here is the whole of it.
The site sets no cookies of its own and asks for no consent, because it has nothing to ask consent for. Clause 07 sets out the detail. What is unavoidably processed is:
Business contact details taken from public sources, which is a distinct enough activity that it has clause 05 to itself.
The CV, covering note and contact details you send, and our notes from any conversation. We keep unsuccessful applications for six months in case something more suitable comes up, and delete them at that point unless you have asked us to keep them longer.
We do not knowingly collect data about anyone under 18, we do not carry out profiling or automated decision-making that produces legal or similarly significant effects, and we do not sell, rent or trade personal data. Not to anyone, at any price.
UK GDPR requires a lawful basis for every purpose we process personal data for. Not one basis for the company — one for each thing we do. This is the complete list.
| What we do | Why | Lawful basis |
|---|---|---|
| Serve the website and keep it up | You cannot be shown a page without your request being processed | Legitimate interests — running a functioning, secure website |
| Aggregate, cookieless analytics | To know which pages are read and which are not | Legitimate interests — understanding whether our own site works |
| Answer your enquiry | You asked us a question and we would like to answer it | Legitimate interests, and steps prior to entering a contract at your request |
| Scope, quote and deliver work | To do the job you have engaged us for | Performance of a contract |
| Invoice, chase payment, keep accounts | We are required to keep accurate financial records | Legal obligation, and performance of a contract |
| B2B prospecting from public sources | To offer relevant services to businesses that plausibly need them | Legitimate interests — assessed and documented (clause 05) |
| Marketing to sole traders and unincorporated partnerships | They have the protections of individuals under PECR | Consent |
| Keep a suppression list of people who told us to stop | The only reliable way to guarantee we do not contact you again | Legal obligation, and legitimate interests |
| Security, backups, fraud and abuse prevention | To keep your data and ours from being lost or stolen | Legitimate interests, and legal obligation |
| Establish, exercise or defend legal claims | If something goes wrong and has to be resolved formally | Legitimate interests, and legal obligation |
Where we rely on legitimate interests, we have weighed our interest against your rights and freedoms and concluded that ours does not override yours. You are entitled to see that reasoning: ask at [email protected] and we will send you the relevant assessment. Where we rely on consent, you can withdraw it at any moment, and withdrawing it is as easy as giving it was; withdrawal does not make our earlier processing unlawful, it just stops it going forward.
We are a small studio, and some of our work begins with us approaching a business rather than the other way round. To do that we use information that is already published — on Companies House, on company websites, in trade directories, in the press, and on public professional profiles. This clause explains exactly how we do it, and the rules we hold ourselves to. If you received a message from us and came here to find out how we got your details, this is the answer.
Publicly available does not mean unprotected. A name and a work email address published on a company website are still that person’s personal data, and the UK GDPR still applies to them in full. We treat public data with exactly the same care as data you hand us directly — the ICO’s position, and ours.
We take the minimum needed to make a relevant approach to a business: name, job title, employer, business email address, business phone number, business postal address, and the publicly stated facts about what the company does. That is the whole record.
We rely on legitimate interests under Article 6(1)(f) of the UK GDPR. The ICO expects that to be documented in a Legitimate Interests Assessment before the processing begins, and ours runs as follows.
That assessment is reviewed when what we do changes, and we will send you a copy on request. If you tell us the balance came out wrong in your case, we will take that seriously rather than defensively — see the right to object below.
Because we obtained your details from a public source rather than from you, the UK GDPR requires us to tell you, at the latest within one month, or at the point of our first communication with you if that comes sooner. We satisfy that by linking this notice in the first message we send you, and by naming the source we used if you ask which one it was.
Direct marketing is governed not only by the UK GDPR but by the Privacy and Electronic Communications Regulations 2003 (PECR), which set different rules for different channels and for different kinds of recipient. We apply them as follows.
| Channel | How we handle it |
|---|---|
| Email to corporate addresses | PECR permits unsolicited marketing email to corporate subscribers — limited companies, LLPs, public bodies. We email only named business addresses at such organisations. Every message identifies Maxi AI Development Ltd as the sender, gives a valid address to reply to, and carries a plain opt-out. We never disguise or conceal who we are. |
| Email to sole traders and partnerships | Sole traders and unincorporated partnerships count as individual subscribers under PECR and have the same protection as a private person. We do not send them marketing email without consent. Where we cannot tell from the public record which category a business falls into, we treat it as an individual subscriber — the cautious reading, deliberately. |
| Telephone | Before we call any number we screen it against the Telephone Preference Service and the Corporate Telephone Preference Service. We do not make marketing calls to registered numbers unless that specific organisation has told us it consents. We identify ourselves at the start of the call, we give a contact address on request, and we do not use automated dialling systems or pre-recorded messages. |
| LinkedIn and professional networks | Connection requests and messages sent as an ordinary user of the platform, within its terms. PECR does not govern this channel, but the UK GDPR does: we rely on the same legitimate interests assessment, keep the volume low and the relevance high, and stop on request. |
| Postal mail | Addressed post to a business address, under legitimate interests. You can object at any time and we will remove the address. |
Your right to object to direct marketing is absolute. There is no balancing test and no discretion on our side: you say stop, we stop, and we do not ask you to justify it. One line to [email protected] — or a reply to any message we have sent you — is enough for every channel at once.
When you opt out we add the minimum identifying detail to a suppression list and keep it indefinitely. That sounds contradictory and is not: a suppression list is the only mechanism that reliably prevents your details being collected afresh from the same public source in a year’s time and the whole thing starting again. The list is used for nothing except not contacting you.
Public records go stale. If we hold something about you that is wrong, tell us and we will correct it. Where a prospect record leads nowhere, we delete it twelve months after the last meaningful contact — we do not keep indefinite lists of businesses that never replied.
Our records are held in the United Kingdom and the European Economic Area. Three of the providers in clause 06 — Cloudflare, EmailJS and Google — are United States companies, so some personal data is transferred outside the UK.
Those transfers are made under one or both of the safeguards the UK recognises:
In each case the effect is intended to be the same: the data carries its UK-level protection with it, and the provider is contractually bound to that standard. You can ask us which mechanism applies to a particular provider and we will tell you.
We keep personal data for no longer than the purpose requires. Where the law fixes a period, the law wins. Where it does not, these are the periods we have set ourselves.
| Record | Kept for |
|---|---|
| Aggregate website analytics | Retained by Cloudflare in aggregate form; contains no personal data we can tie to you |
| Technical connection and security logs | Short-lived, and in the ordinary course no more than 30 days |
| Enquiry form submissions and correspondence that goes nowhere | 24 months from the last message either way |
| Prospect records where there was no engagement | 12 months from the last meaningful contact |
| Suppression list (people who opted out) | Indefinitely — that is the point of it. Minimal data only |
| Client contracts, proposals and project correspondence | 6 years after the engagement ends, matching the limitation period for contract claims |
| Invoices and accounting records | 6 years from the end of the accounting period they fall in, as HMRC requires |
| Unsuccessful job applications | 6 months, unless you ask us to keep them on file |
At the end of a period we delete the record or irreversibly anonymise it. Backups roll off on their own cycle, which means a deleted record can persist in a backup for a short period after deletion from the live system; it is not restored to active use, and it goes when that backup expires.
We sell security work, so it would be awkward to be careless with our own. The measures are proportionate to a two-person company holding business contact details, not to a bank, and we would rather describe them accurately than impressively.
No system is perfectly secure and we will not pretend otherwise. If a breach occurs that is likely to result in a risk to your rights and freedoms, we will report it to the ICO within 72 hours of becoming aware of it, and where the risk is high we will tell you directly and plainly.
The UK GDPR gives you the following rights. Some are qualified — they apply in defined circumstances rather than universally — and we have said so where that is the case rather than implying more than the law gives you.
Email [email protected] or write to the registered office. You do not need to use a particular form of words, cite an article number, or explain yourself. We will:
Please tell us first — most problems are a misunderstanding, and we can usually fix one faster than a regulator can. But you are not obliged to come to us first, and you do not lose anything by going straight to the regulator.
You have the right to complain to the Information Commissioner's Office, the UK’s supervisory authority for data protection.
| Post | Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF |
| Helpline | 0303 123 1113 |
| Online | ico.org.uk |
You also have the right to an effective judicial remedy, and to seek compensation through the courts if you have suffered damage or distress as a result of a breach of data protection law.
We will update this notice when what we do changes — a new provider, a new purpose, a new channel. The date at the head of the page is the date the current version took effect.
Where a change materially affects you, and particularly where it would introduce tracking or a new purpose for data we already hold, we will make the change before the new processing begins and not retrospectively, and we will tell affected clients and contacts directly rather than relying on you to re-read this page.
Version history. 10 September 2026 — first published.
Anything in here that you want explained, challenged or acted on goes to [email protected] and reaches a founder, not a ticket queue. The terms governing use of this website are set out separately in our Terms of Service.