AIXO DEV
Privacy Policy
AIXO DEV
Privacy Policy
Last updated: 17 September 2026
This Privacy Policy explains how AIXO AI Ltd collects and uses personal information when you use aixo.uk, visit AIXO DEV, contact us or request an AIXO CLEAR START.
1. Who we are and who is responsible for your information
AIXO DEV is operated by AIXO AI Ltd. For the personal information described in this policy, AIXO AI Ltd is the data controller unless we tell you otherwise for a particular service.
AIXO AI Ltd
Registered in England and Wales
Company number: 16847255
Registered office: 71–75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ
Privacy contact: privacy@aixo.uk
Website: aixo.uk
2. What this policy covers
This policy applies to the public AIXO website at aixo.uk and AIXO DEV at aixo.uk/dev/, including direct email enquiries, the Standard Contact form, AIXO CLEAR START, website security and anti-abuse controls, optional Web Analytics where enabled, and related correspondence.
It does not describe personal information processed under a separate client contract where a different privacy notice or data-processing arrangement applies.
3. Information we collect
Direct email enquiries
If you contact us by email, including through an email link on aixo.uk, we receive your email address and the information you choose to include in your message.
Standard Contact form
- Name.
- Email address.
- Subject.
- Free-text message.
AIXO CLEAR START
- Name and business email address.
- The starting point, issue or task you select during the guided journey.
- Optional business name, website address and phone number where you choose to provide them.
Website operation, security and anti-abuse
- Technical request information needed to deliver and secure the service.
- IP address may be processed temporarily during a request.
- For contact-form rate limiting, pseudonymous HMAC-based keys may be derived from IP address and email address. Raw IP addresses are not stored by that throttle mechanism.
- Normal hosting, web-server, security and application error logs may be created as part of operating the service.
Optional Web Analytics
When Analytics is enabled, the site uses first-party, server-side analytics. A pseudonymous visitor identifier is generated using HMAC-SHA256 from request information including IP address, User-Agent and Accept-Language together with a private server-side key.
The raw IP address, User-Agent and Accept-Language are not stored in their original form in the Web Analytics database. The analytics record may include the pseudonymous visitor identifier, date, country code, first and last seen timestamps, page-view count and the normalised page path. Query parameters and referrer information are not stored in Web Analytics.
Information you place in free text
Please do not send passwords, payment-card information, customer records, health information or other sensitive or special-category information through the website forms unless we have specifically asked you to do so through an appropriate secure channel.
4. Where the information comes from
Most personal information is provided directly by you when you complete a form, choose options during AIXO CLEAR START, email us or otherwise contact us. Technical and analytics information is generated from your browser or device request when you use the website.
5. Why we use personal information and our lawful bases
| Purpose | Typical information | Lawful basis |
|---|---|---|
| Respond to ordinary business and direct email enquiries | Contact details and enquiry content | Legitimate interests in communicating with people who contact us and operating our business |
| Provide AIXO CLEAR START or take steps you request before paid work | Contact details, selected issue/task and optional business information | Steps at your request before entering into a contract; in some cases legitimate interests where the request is not contractual |
| Protect the website, prevent abuse and investigate technical problems | Technical request data, pseudonymous throttle keys, security and error information | Legitimate interests in maintaining the security, reliability and integrity of the service; legal obligation where a specific security duty applies |
| AI-assisted spam and abuse classification for the Standard Contact form | Free-text message only | Legitimate interests in preventing spam and abuse, with data minimisation and human review safeguards |
| Optional Web Analytics | Pseudonymous visitor and page-use data described above | Consent under the current AIXO DEV implementation. Analytics remains off unless you enable it through the site controls. |
Where we rely on legitimate interests, our interests include responding to genuine enquiries, protecting the website from abuse and understanding the operation of the service in a proportionate way. We do not use these interests to justify advertising profiling or unrelated reuse of enquiry content.
6. AIXO CLEAR START and automated decisions
The context for AIXO CLEAR START comes from the choices you make during the guided journey. A person at AIXO uses that context to understand what you would like us to examine. AIXO CLEAR START is not an automated diagnosis, AI lead score or automated quotation.
We do not use the website AI spam classifier to make solely automated decisions about whether to accept a person as a client, set prices, assess commercial suitability or make another decision producing legal or similarly significant effects.
7. Spam protection and use of OpenAI
The Standard Contact form uses deterministic anti-abuse controls such as validation, CSRF protection, bot-trap controls and rate limiting. It also uses an AI-assisted spam and abuse classifier through the OpenAI Responses API.
Structured contact identity fields are deliberately excluded from the classifier input. The classifier receives only the free-text message field. A visitor may nevertheless choose to type personal information into that message, so the classifier may process personal information voluntarily included there.
AIXO CLEAR START structured submissions do not pass through the AI spam classifier.
The classifier is used solely for spam and abuse detection. It may return limited anti-abuse information such as spam/not-spam/review status, category, short reason or label and risk/spam probabilities.
Requests are sent with provider-side application storage disabled through store: false. AIXO does not store the submitted message or provider response in its local AI usage logs. The local usage record contains operational information such as provider/model, capability, request result, token usage, duration and estimated cost.
Optional sharing of production API inputs and outputs with OpenAI for model improvement is disabled. OpenAI states that API data is not used to train or improve its models by default unless a customer opts in. Under OpenAI's standard API controls, abuse-monitoring logs may contain customer content and may be retained for up to 30 days unless a different approved retention control applies.
8. Web Analytics
AIXO DEV uses first-party, server-side Web Analytics only when Analytics is enabled through the site controls.
- No advertising pixels or advertising trackers are used by the current AIXO DEV implementation.
- No separate analytics visitor-identification cookie is used.
- No analytics identifier is stored in localStorage or sessionStorage.
- Raw IP addresses are not written to Web Analytics tables.
- User-Agent and Accept-Language may be used to create the pseudonymous HMAC identifier but are not stored in their original form in Web Analytics.
- Web Analytics does not store referrer information or query strings.
- Only the normalised page path is stored.
- AI Traffic Analytics receives only aggregated statistical snapshots such as totals, daily counts and top pages. It does not receive visitor-level analytics records.
- Analytics records are retained for 90 days and removed by a daily automated cleanup job.
For the current cookie and browser-storage inventory, see our Cookie Policy.
9. Who receives personal information
Personal information is accessible only where needed for the purposes described above. Recipients may include:
- authorised AIXO personnel;
- Hexane Networks, which currently provides hosting and email infrastructure for aixo.uk;
- underlying hosting infrastructure used by Hexane, including the current OVH UK network infrastructure supporting the live site;
- OpenAI and its relevant sub-processors, but only for the limited Standard Contact spam-classification purpose described above;
- professional advisers, regulators, courts or public authorities where disclosure is necessary and lawful.
We do not share website-enquiry information with advertising partners and do not sell personal information to advertisers.
10. International transfers
The current live AIXO DEV site and email infrastructure are hosted through Hexane Networks and the live origin is within OVH UK infrastructure. Provider-level support, security or backup arrangements may involve additional provider systems that are not exposed through the WF WebEngine application configuration.
The OpenAI spam classifier may involve processing of UK personal data by OpenAI OpCo, LLC and relevant sub-processors outside the UK. OpenAI's current Data Processing Addendum provides for UK data transfers using the EU Standard Contractual Clauses as amended by the UK International Data Transfer Addendum. OpenAI also publishes a current sub-processor list.
Where another provider processes personal information outside the UK, we use an applicable UK adequacy arrangement or other appropriate safeguard where required by data protection law.
11. How long we keep information
- Direct email, Standard Contact and AIXO CLEAR START enquiries that do not become active client work: normally up to 12 months after the last meaningful contact, after which the relevant website enquiry record and relevant mailbox copies are deleted unless there is a specific legal, security or dispute-related reason to retain them longer.
- Active client work: relevant information may be moved into the client/project record and retained according to the contractual, accounting, tax, professional and legal requirements applying to that relationship.
- Web Analytics: 90 days.
- Anti-abuse throttle records: approximately 48 hours before cleanup.
- OpenAI API abuse-monitoring logs: under OpenAI's standard API controls, customer content may be retained for up to 30 days unless a different approved retention control applies.
- Hosting and server logs: retention is controlled by the hosting provider's operational and security arrangements. AIXO's application also maintains technical/error logs with size-based rotation.
12. Cookies and browser storage
The current public AIXO DEV site uses a technical PHP session cookie and a cookie that records your Analytics choice. It does not use a separate analytics visitor cookie and does not use localStorage or sessionStorage for analytics identifiers or visitor profiling.
See the Cookie Policy for names, purposes, durations and current controls.
13. Security
We use proportionate technical and organisational measures to protect personal information. These include secure transport, restricted access, server-side form validation, CSRF protection, bot-trap controls, rate limiting, data minimisation and pseudonymisation where appropriate.
No internet service can be guaranteed completely secure. If you believe information you sent through AIXO DEV has been compromised, please contact us promptly at privacy@aixo.uk.
14. Required and optional information
Fields marked as required are needed for us to receive, understand or respond to your request. Optional fields do not have to be provided. If required information is not provided, we may be unable to respond or provide the requested first review.
15. Your data protection rights
Depending on the circumstances and the lawful basis we rely on, you may have rights to:
- ask for access to your personal information;
- ask us to correct inaccurate or incomplete information;
- ask us to delete information in certain circumstances;
- ask us to restrict processing in certain circumstances;
- receive certain information in a portable format where the right to data portability applies;
- object to certain processing based on legitimate interests;
- withdraw consent at any time where processing is based on consent. Withdrawal does not affect processing that was lawful before withdrawal.
Your right to object: where we rely on legitimate interests, you may object to that processing. We will consider your objection and stop the processing where the law requires us to do so.
To exercise a right, email privacy@aixo.uk. We may need to verify your identity before acting on a request.
You can change or withdraw your optional Analytics choice at any time through Cookie settings on the AIXO DEV website.
16. Data protection complaints
If you are concerned about how we have handled your personal information, please email privacy@aixo.uk and make clear that you are raising a data protection complaint.
We will acknowledge receipt of a data protection complaint within 30 days, take appropriate steps to investigate and respond without undue delay, keep you informed where appropriate, and tell you the outcome without undue delay.
You also have the right to complain to the UK Information Commissioner's Office (ICO). You can find current complaint information at ico.org.uk/make-a-complaint/.
17. Changes to this policy
We keep this policy under review and update it when our website, providers, processing purposes or legal requirements change. Where a material new use of personal information requires notice before it begins, we will provide that information at the appropriate time.
Last updated: 17 September 2026.
18. Contact
Privacy questions, rights requests and data protection complaints can be sent to privacy@aixo.uk.