Privacy Policy
Last updated: 04/08/2026
EngiSolveAI respects your privacy and is committed to protecting your personal information.
This Privacy Policy explains how we collect, use, store, share and protect personal information when you:
- visit https://engisolveai.com;
- contact us or request a quotation;
- create or use an account;
- purchase engineering, software or artificial intelligence services;
- use an EngiSolveAI AI product or custom AI solution;
- communicate with an AI agent operated by us or by one of our customers;
- attend a demonstration, consultation or event;
- receive marketing communications from us; or
- otherwise interact with EngiSolveAI.
It also explains your legal rights and how to contact us about our use of your information.
- Who we are
The EngiSolveAI website and Services are operated by EngiSolveAI:
In this Privacy Policy, “EngiSolveAI”, “we”, “us” and “our” refer to the organisation identified above.
- Scope of this Privacy Policy
This Privacy Policy applies to personal information processed through:
- the EngiSolveAI website;
- contact forms and enquiries;
- engineering and consultancy engagements;
- custom AI development projects;
- hosted AI products and digital services;
- customer support and account administration;
- demonstrations and trial services;
- marketing and business-development activity;
- recruitment and contract-staffing enquiries; and
- integrations with customer or third-party systems.
A separate privacy notice, order form, data-processing agreement or customer-specific notice may apply to a particular service or project.
Where another privacy notice applies, we will make it available at the appropriate time.
- When EngiSolveAI is a controller or processor
Our legal role depends on why and how personal information is being processed.
3.1 When we act as a controller
EngiSolveAI normally acts as a data controller when we determine why and how personal information is used, including when we process information for:
- operating our website;
- responding to enquiries;
- preparing quotations and proposals;
- managing customer accounts;
- processing payments;
- administering our contracts;
- providing customer support;
- promoting our products and services;
- managing suppliers and business contacts;
- recruiting staff or contractors;
- maintaining security;
- complying with legal obligations; and
- improving our own business operations.
When we act as a controller, this Privacy Policy explains our use of the information.
3.2 When we act as a processor
EngiSolveAI may act as a data processor when a customer uses one of our custom AI solutions to process personal information for the customer’s own purposes.
Examples may include:
- an AI customer-support agent handling customer questions;
- an AI sales or lead-follow-up assistant;
- an appointment-booking agent;
- CRM and email automation;
- an AI document-processing system;
- an internal knowledge-base assistant;
- a website chatbot;
- a workforce or production-planning agent;
- a technical-report or engineering-document assistant; or
- another customer-controlled AI workflow.
In these circumstances, the customer generally decides why the information is processed and EngiSolveAI processes it on the customer’s documented instructions.
The customer’s own privacy notice should explain that processing. Questions or rights requests concerning customer-controlled information should normally be directed to the relevant customer.
Our processing obligations will be set out in the applicable contract or data-processing agreement.
3.3 Joint or independent control
In limited situations, EngiSolveAI and another organisation may each act as an independent controller or may jointly determine aspects of the processing.
Where required, we will explain the relevant responsibilities in a separate notice or agreement.
- Personal information we collect
The information we collect depends on your relationship with us and the Services you use.
4.1 Identity and contact information
This may include:
- name;
- job title;
- employer or organisation;
- postal address;
- email address;
- telephone number;
- account username; and
- professional contact details.
4.2 Account information
This may include:
- login credentials;
- account identifier;
- account preferences;
- authorised users;
- security settings;
- subscription details; and
- account activity.
We do not store passwords in readable form where authentication is managed by our systems.
4.3 Enquiry and communication information
This may include:
- contact-form submissions;
- email correspondence;
- support requests;
- meeting notes;
- call records;
- consultation information;
- feedback;
- complaints; and
- records of your instructions.
Telephone or video calls will only be recorded where you have been informed and where recording is lawful.
4.4 Contract and transaction information
This may include:
- quotations;
- proposals;
- statements of work;
- orders;
- contracts;
- invoices;
- payment status;
- billing information;
- subscription records;
- service history; and
- customer-support history.
Payment-card information may be collected directly by a payment provider rather than by EngiSolveAI.
4.5 Website and technical information
When you use our website or online Services, we may collect:
- IP address;
- browser type and version;
- device type;
- operating system;
- approximate location derived from an IP address;
- pages viewed;
- links selected;
- referring website;
- session identifiers;
- login and security events;
- error records;
- usage timestamps; and
- cookie or similar technology identifiers.
4.6 Marketing information
This may include:
- marketing preferences;
- subscription choices;
- responses to campaigns;
- event attendance;
- downloads;
- areas of professional interest;
- previous communications; and
- records of consent or objection.
4.7 Project and engineering information
Where we provide engineering or consultancy services, we may receive information contained in:
- CAD files;
- engineering drawings;
- finite element models;
- simulation files;
- technical reports;
- specifications;
- test data;
- measurement data;
- failure reports;
- photographs;
- maintenance records;
- supplier documentation;
- project correspondence; and
- design-review material.
These materials may contain names, contact details, user identifiers or other personal information.
4.8 AI inputs, outputs and interaction data
When you use an AI Product or communicate with an AI agent, we may process:
- prompts and instructions;
- questions;
- chatbot messages;
- uploaded documents;
- images or files;
- AI-generated responses;
- workflow actions;
- user feedback;
- evaluation results;
- conversation history;
- system logs;
- error reports; and
- records of human review.
Do not provide sensitive or unnecessary personal information to an AI Product unless its use has been specifically authorised and appropriate safeguards are in place.
4.9 Integration information
Custom AI solutions may connect with systems such as:
- email platforms;
- customer-relationship management systems;
- calendars;
- document repositories;
- websites;
- messaging services;
- ticketing systems;
- accounting platforms;
- engineering software;
- business databases; and
- cloud services.
Depending on the integration, we may process identifiers, messages, documents, contact records, appointments, support cases, project records and related metadata.
Access will be limited to the permissions required for the agreed functionality.
4.10 Recruitment and staffing information
Where you apply for employment, contract work or an engineering assignment, we may collect:
- curriculum vitae;
- employment history;
- qualifications;
- professional skills;
- software experience;
- references;
- availability;
- salary or rate expectations;
- right-to-work information;
- interview notes; and
- background-check information where lawful and necessary.
4.11 Special-category information
Special-category information includes information concerning matters such as health, racial or ethnic origin, political opinions, religious beliefs, trade-union membership, genetics, biometrics or sexual orientation.
We do not normally require this information for general website or AI Product use.
We will only process special-category information where:
- it is necessary for a specific lawful purpose;
- an additional legal condition applies;
- suitable safeguards are in place; and
- the processing has been appropriately documented.
Customers must not upload special-category or criminal-offence information to a custom AI solution unless the processing has been expressly agreed.
- How we obtain personal information
We may obtain personal information:
- directly from you;
- from your employer or organisation;
- from authorised users of a customer account;
- through our website;
- through an AI Product;
- through connected customer systems;
- from business partners or suppliers;
- from payment providers;
- from publicly available professional sources;
- from company websites;
- from professional networking platforms;
- from event organisers;
- from recruitment agencies; or
- from another person who refers or introduces you.
Where a customer provides information about its own customers, employees or other individuals, that customer is responsible for ensuring that it has authority to provide the information and that required privacy information has been given.
- Why we use personal information
We use personal information only where we have a lawful reason to do so.
6.1 Enquiries and quotations
We use contact details and enquiry information to:
- respond to questions;
- understand requirements;
- arrange demonstrations;
- prepare quotations;
- assess project feasibility; and
- communicate before a contract is formed.
Our lawful bases are taking steps at your request before entering into a contract and our legitimate interests in responding to business enquiries.
6.2 Providing Services
We use personal information to:
- create and administer accounts;
- deliver engineering and AI services;
- configure custom AI solutions;
- manage integrations;
- provide support;
- monitor agreed usage;
- investigate faults;
- manage projects; and
- communicate about delivery.
Our lawful bases are performance of a contract and our legitimate interests in providing and administering Services.
6.3 Payments and financial administration
We use transaction and billing information to:
- issue invoices;
- process or confirm payments;
- maintain accounting records;
- recover unpaid amounts;
- manage taxation; and
- prevent financial fraud.
Our lawful bases are performance of a contract, compliance with legal obligations and our legitimate interests in managing our finances.
6.4 Security and abuse prevention
We use technical, account and usage information to:
- authenticate users;
- protect accounts;
- detect unauthorised access;
- investigate misuse;
- prevent fraud;
- maintain network and information security;
- enforce usage restrictions; and
- protect our rights and the rights of customers and third parties.
Our lawful bases are legitimate interests, recognised legitimate interests where applicable, compliance with legal obligations and, in appropriate cases, establishment or defence of legal claims.
6.5 Service improvement
We may use usage records, error data, feedback and appropriately minimised interaction information to:
- understand how Services are used;
- diagnose defects;
- evaluate performance;
- improve user experience;
- improve reliability;
- develop new functionality; and
- test security and quality controls.
Our lawful basis is our legitimate interest in maintaining and improving our Services.
Where consent is required for a particular analytics technology, we will request consent before using it.
6.6 Marketing and business development
We may use professional contact and marketing information to:
- send product or service updates;
- provide invitations to demonstrations or events;
- communicate relevant engineering or AI information;
- measure campaign effectiveness; and
- maintain business relationships.
Depending on the circumstances, we rely on consent or legitimate interests.
You may opt out of direct marketing at any time.
6.7 Legal and regulatory compliance
We may process information to:
- comply with tax and accounting requirements;
- respond to lawful requests;
- maintain statutory records;
- establish or defend legal claims;
- investigate complaints;
- comply with court orders;
- meet regulatory obligations; and
- cooperate with law-enforcement or public authorities where legally required.
Our lawful bases are compliance with legal obligations, legitimate interests and establishment or defence of legal claims.
6.8 Recruitment
We use applicant information to:
- assess applications;
- arrange interviews;
- verify experience and qualifications;
- communicate with candidates;
- obtain references;
- assess suitability for available roles; and
- maintain recruitment records.
Our lawful bases are steps taken before entering into a contract, legitimate interests, legal obligations and consent where appropriate.
- Lawful bases
Depending on the processing, we may rely on one or more of the following lawful bases:
Contract
Processing is necessary to enter into or perform a contract with you.
Legal obligation
Processing is necessary for us to comply with a legal obligation.
Legitimate interests
Processing is necessary for our legitimate interests or those of another organisation, provided those interests are not overridden by your rights and interests.
Our legitimate interests may include:
- operating our business;
- responding to enquiries;
- delivering and improving Services;
- securing systems;
- preventing fraud;
- maintaining customer relationships;
- carrying out proportionate business-to-business marketing;
- managing suppliers; and
- establishing or defending legal claims.
Recognised legitimate interests
Where applicable, we may rely on a recognised legitimate interest specified by UK data-protection law, including certain processing required to protect public security, respond to emergencies, safeguard vulnerable people or prevent, detect or investigate crime.
Consent
Where we rely on your consent, you may withdraw it at any time. Withdrawal does not affect processing that occurred before consent was withdrawn.
Vital interests
In exceptional circumstances, processing may be necessary to protect someone’s life.
We do not normally rely on public-task grounds because EngiSolveAI is not a public authority performing official functions.
- Custom AI products and customer content
“Customer Content” includes information, prompts, documents, records, designs, messages, datasets and other material submitted to a custom AI solution.
Where we process Customer Content on behalf of a business customer:
- the customer determines the purposes of the processing;
- we process the information on documented instructions;
- access is restricted to authorised personnel and providers;
- the processing is governed by a data-processing agreement where required; and
- the customer is responsible for the lawfulness of its instructions and source data.
Customers must configure and use custom AI solutions in accordance with data-protection law.
This includes providing required privacy information to employees, customers and other users whose information may be processed.
- Use of information for AI model training
Unless a contract, order form or specific privacy notice clearly states otherwise, EngiSolveAI will not use identifiable Customer Content to train a general-purpose AI model made available to unrelated customers.
We may use:
- anonymised information;
- aggregated statistics;
- synthetic test data;
- customer-approved evaluation data;
- security and performance metrics; and
- feedback that does not reveal confidential or identifiable information
to test, maintain and improve our Services.
Some AI Products may rely on third-party model providers. The handling of submitted data by those providers will depend on the provider, configuration and contractual arrangements selected for the relevant Service.
Where commercially available, we may configure providers not to use submitted Customer Content for general model training.
The applicable order, technical documentation or data-processing agreement should identify material provider-specific arrangements.
- AI monitoring and human review
We may review selected AI interactions where reasonably necessary to:
- investigate a support request;
- evaluate output quality;
- detect misuse;
- improve safety;
- test performance;
- investigate an incident; or
- comply with legal obligations.
Human review will be limited to authorised personnel or approved providers with a legitimate need for access.
Where practical, information used for quality evaluation will be minimised, redacted, pseudonymised or anonymised.
- Automated decision-making and profiling
An automated decision is a decision made using automated processing without meaningful human involvement.
Profiling involves automated processing used to evaluate or predict aspects relating to an individual.
Our general website does not normally make solely automated decisions that produce legal or similarly significant effects.
A custom AI Product may support recommendations, classifications or workflow decisions. Unless expressly agreed otherwise, these outputs are intended to assist a human user rather than replace meaningful human judgement.
Where EngiSolveAI acts as a controller and uses personal information to make a significant decision solely through automated processing, we will apply appropriate safeguards. These may include:
- providing clear information about the decision;
- allowing you to contest the decision;
- allowing you to make representations;
- enabling meaningful human intervention;
- reviewing the quality and relevance of the data;
- testing for errors and unfair outcomes; and
- maintaining appropriate records.
Special-category information will not be used for significant solely automated decisions unless an applicable legal condition and additional safeguards are in place.
Where a customer controls an AI Product that makes or supports decisions about individuals, the customer is responsible for determining whether the use is lawful and for implementing required safeguards.
- Who we share information with
We may share personal information with the following categories of recipients where necessary.
Service and infrastructure providers
These may include providers of:
- cloud hosting;
- data storage;
- cybersecurity;
- website hosting;
- authentication;
- communications;
- customer support;
- analytics;
- monitoring;
- payment processing;
- accounting;
- document management; and
- backup services.
AI and software providers
We may use third-party providers for:
- language models;
- machine-learning services;
- document processing;
- speech processing;
- search and retrieval;
- workflow automation;
- engineering software;
- development tools; and
- application programming interfaces.
Professional advisers
We may share information with:
- solicitors;
- accountants;
- auditors;
- insurers;
- consultants; and
- other professional advisers.
Business customers
Where you communicate through an AI agent operated for one of our customers, the relevant customer may receive and control the conversation, contact details, outputs and related records.
Authorities and legal recipients
We may disclose information to:
- courts;
- regulators;
- tax authorities;
- law-enforcement bodies;
- government departments; or
- other authorised recipients
where required or permitted by law.
Corporate transactions
Information may be disclosed in connection with a proposed or completed:
- merger;
- acquisition;
- investment;
- restructuring;
- financing;
- transfer of assets; or
- sale of all or part of the business.
Recipients will be required to protect the confidentiality and security of the information.
We do not sell personal information to data brokers.
- Subprocessors
Where EngiSolveAI acts as a processor, we may appoint subprocessors to support delivery of the Services.
We will:
- conduct proportionate supplier due diligence;
- enter into appropriate contractual protections;
- restrict subprocessors to authorised purposes;
- require suitable security measures; and
- manage international transfers in accordance with applicable law.
Where contractually required, customers will receive information about subprocessors and material changes to the subprocessor list.
- International transfers
Some providers or systems may process personal information outside the United Kingdom.
Where personal information is transferred internationally, we will use a legally recognised transfer mechanism where required.
Depending on the destination and circumstances, this may include:
- UK adequacy regulations;
- the UK International Data Transfer Agreement;
- the UK Addendum to approved standard contractual clauses;
- binding corporate rules;
- another approved safeguard; or
- a lawful exception for a specific transfer.
Where appropriate, we will assess whether additional contractual, technical or organisational safeguards are required.
You may contact us for further information about the safeguards relevant to your information.
- Information security
We use appropriate technical and organisational measures designed to protect personal information against:
- unauthorised access;
- unlawful use;
- accidental loss;
- alteration;
- destruction;
- disclosure; and
- loss of availability.
Measures may include:
- access controls;
- authentication controls;
- encryption in transit and, where appropriate, at rest;
- secure development practices;
- vulnerability management;
- monitoring and logging;
- backups;
- supplier reviews;
- staff confidentiality obligations;
- incident-response procedures;
- data minimisation; and
- segregation of customer environments where appropriate.
No internet-based service can be guaranteed to be completely secure.
You are responsible for protecting your account credentials, configuring integrations appropriately and notifying us promptly of suspected unauthorised access.
- Personal data breaches
We maintain procedures for identifying, assessing and responding to personal data breaches.
Where we act as a controller, we will notify the Information Commissioner’s Office and affected individuals where required by law.
Where we act as a processor, we will notify the relevant customer without undue delay after becoming aware of a breach affecting customer-controlled personal information, in accordance with the applicable contract.
- How long we retain information
We retain personal information only for as long as reasonably necessary for the purpose for which it was collected, including legal, contractual, accounting, security and dispute-resolution requirements.
Indicative retention periods are set out below and must be confirmed before publication:
|
Information category |
Indicative retention period |
|
General enquiries that do not become customers |
24 months |
|
Customer contracts and transaction records |
Six years after the relationship ends |
|
Accounting and tax records |
Six years or the required statutory period |
|
Customer-support records |
Three years after closure |
|
Website security logs |
365 days |
|
Marketing records |
Until opt-out, followed by a suppression record |
|
Recruitment records for unsuccessful applicants |
12 months |
|
Active customer account data |
For the account term plus 5 years |
|
AI conversation history |
Specify by product and customer configuration |
|
Customer Content |
For the contract term plus the agreed deletion period |
|
Backups |
Until overwritten under the applicable backup cycle |
|
Complaint and legal records |
For the applicable limitation or regulatory period |
We may retain information for longer where:
- required by law;
- necessary for legal proceedings;
- required to resolve a dispute;
- necessary to investigate fraud or misuse; or
- the information has been anonymised so that it no longer identifies an individual.
Customer-specific retention and deletion instructions may be set out in an order form or data-processing agreement.
- Cookies and similar technologies
Our website may use cookies, pixels, scripts, local storage and similar technologies.
These technologies may be used for:
- essential website operation;
- security;
- authentication;
- remembering preferences;
- load balancing;
- analytics;
- performance measurement;
- embedded content; and
- marketing.
Some technologies are necessary for the website to function or may fall within another legal exemption. Where consent is legally required, we will not activate the relevant technology until you have made a choice.
You can manage non-essential technologies through our cookie banner or preference centre.
Rejecting non-essential technologies should be as easy as accepting them.
More information should be provided in a separate Cookie Policy containing:
- the name of each technology;
- its provider;
- its purpose;
- its duration;
- whether it is first-party or third-party; and
- how preferences can be changed.
Cookie Policy:
Browser settings may also allow you to block or delete cookies, although this may affect website functionality.
- Marketing communications
We may send marketing communications where permitted by applicable law.
Depending on the recipient and communication method, we may rely on:
- consent;
- an existing customer relationship;
- legitimate interests; or
- another permitted basis.
Marketing communications will identify EngiSolveAI and provide a clear way to opt out.
You can unsubscribe by:
- using the unsubscribe link in an email;
- changing your account preferences; or
- contacting us at info@engisolveai.com.
We may retain a minimal suppression record after an opt-out to ensure that we respect your preference.
Opting out of marketing will not stop service, security, contractual or administrative messages.
- Your data-protection rights
Depending on the circumstances, you may have the following rights.
Right to be informed
You have the right to receive clear information about how your personal information is used.
Right of access
You may request confirmation of whether we process your personal information and request a copy of it.
Right to rectification
You may ask us to correct inaccurate information or complete incomplete information.
Right to erasure
You may ask us to delete your information in certain circumstances.
Right to restriction
You may ask us to restrict how information is used in certain circumstances.
Right to data portability
Where applicable, you may request information you provided to us in a structured, commonly used and machine-readable format.
Right to object
You may object to processing based on legitimate interests in certain circumstances.
You have an absolute right to object to the use of your personal information for direct marketing.
Rights relating to automated decisions
Where a significant decision is made solely through automated processing, you may have rights to:
- receive information about the decision;
- contest the decision;
- make representations; and
- request meaningful human intervention.
Right to withdraw consent
Where processing is based on consent, you may withdraw consent at any time.
Right to complain
You may complain to us or to the relevant data-protection regulator.
These rights are not absolute. Legal exemptions may apply, and we may need to retain some information despite a request.
- Exercising your rights
To exercise a right, contact:
Email: info@engisolveai.com
Please describe your request and provide enough information for us to identify the relevant records.
We may ask for reasonable proof of identity where necessary to protect your information.
We will respond within the legally applicable period. Where a request is complex or multiple requests are made, the response period may be extended as permitted by law.
We will normally respond without charge. A reasonable fee may be charged or a request may be refused where permitted by law, including where a request is manifestly unfounded or excessive.
Where EngiSolveAI processes information solely on behalf of a customer, we may refer the request to that customer or assist the customer in responding.
- Privacy complaints
Please contact us first where you have concerns about how your personal information has been used.
Complaints may be submitted through:
Email: info@engisolveai.com
Please include:
- your name and contact details;
- a description of the concern;
- relevant dates;
- the Service or account involved;
- supporting information; and
- the outcome you are seeking.
We will acknowledge a data-protection complaint within 30 days and will investigate and respond without undue delay.
You may also complain to the UK data-protection regulator:
Information Commissioner’s Office
You can find current complaint and contact information on the ICO website.
If you live outside the United Kingdom, you may also have the right to contact the data-protection authority in your country.
- Children’s information
The EngiSolveAI website and Services are primarily intended for adults, businesses and professional users.
They are not directed at children under 18 unless a specific educational or other Service expressly states otherwise.
We do not knowingly collect children’s information through the general website.
If we learn that information has been submitted by a child without appropriate authority, we will take reasonable steps to investigate and delete or restrict it.
A customer must not deploy an EngiSolveAI product for use by children without informing us and implementing appropriate age-related protections, notices and risk controls.
- Third-party websites and services
Our website and Services may contain links to or integrations with third-party websites and services.
Those third parties may collect and use personal information under their own privacy policies.
We do not control third-party privacy practices and encourage you to review the relevant notices before providing information.
- Changes to this Privacy Policy
We may update this Privacy Policy to reflect:
- changes to our Services;
- changes to our suppliers;
- new AI functionality;
- changes to our processing activities;
- security developments; or
- legal and regulatory changes.
The updated version will be posted on this page with a revised “last updated” date.
Where a change materially affects how existing information is used, we will provide additional notice where required.
