About this document
This Privacy Notice applies to CLASI LTD, a private company limited by shares incorporated in England and Wales (Company No. [CO_NUMBER]) with registered office at 20 Wenlock Road, London, England, N1 7GU ("CLASI", "we", "us"). Questions about this document can be directed to privacy@clasi.co.uk. We review this document at least annually and on any material change to our services or applicable law.
Who we are
CLASI LTD is the data controller of personal data we process about visitors, prospects, clients, suppliers and applicants in the course of operating our website and providing professional services. Our UK Information Commissioner's Office (ICO) registration is held under our company name; a copy of the registration is available on request to privacy@clasi.co.uk.
Personal data we process
We process the categories of personal data listed below. We collect the minimum necessary to provide the relevant service.
- Identity and contact data: name, email address, telephone number, employer, role.
- Brief and enquiry data: information you submit through our brief form or chat widget, including project goals, budget, timeline and any narrative you choose to share.
- Technical and device data: IP address, user agent, referrer, pages viewed and approximate location derived from your IP, processed in aggregate where possible.
- Communications data: emails, chat transcripts, calendar invites and call recordings (only with your explicit consent and where lawful).
- Engagement data: status of proposals, contracts, invoices and project artefacts where you are a client representative.
- Recruitment data (if you apply for a role): CV, cover letter, right-to-work information and references.
Lawful basis
We rely on the following lawful bases under UK GDPR Article 6: (a) performance of a contract; (b) our legitimate interests in operating, securing and improving our services and pursuing prospective business, balanced against your rights; (c) compliance with legal obligations such as tax and accounting law; and (d) consent for non-essential cookies and marketing communications, which you may withdraw at any time.
How we use personal data
- Respond to enquiries and prepare proposals.
- Deliver and operate professional services agreed in writing.
- Run our live support chat, including AI assistance when no human agent is online.
- Send service communications and, with consent, occasional studio updates.
- Maintain security, prevent fraud and abuse, and meet legal obligations.
Sharing and sub-processors
We share personal data only with carefully chosen sub-processors that support our services. A current sub-processor list is available at /legal/subprocessors and includes our cloud platform, transactional email provider, model providers used for AI features, and infrastructure partners. Each sub-processor is bound by a written contract that meets UK GDPR Article 28 requirements.
International transfers
Where personal data is transferred outside the United Kingdom, we rely on the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses, supplemented by transfer impact assessments where appropriate.
Retention
We retain personal data only for as long as necessary for the purposes set out above. Brief enquiries are retained for up to 24 months unless you become a client. Client engagement records are retained for the duration of the contract and 6 years after termination to meet UK statutory retention obligations. Server logs are retained for up to 90 days.
Your rights
Under UK GDPR you have the right to access your personal data, request rectification, request erasure (where applicable), restrict or object to processing, request portability, and withdraw consent. You may also lodge a complaint with the UK Information Commissioner's Office (ico.org.uk). To exercise any of these rights, write to privacy@clasi.co.uk.
Security
We maintain technical and organisational measures aligned to ISO 27001 controls, including encryption in transit (TLS 1.3) and at rest (AES-256), least-privilege access, mandatory MFA, audit logging, secure software development practices, and regular vendor risk reviews.
Updates
We may update this document from time to time. The "last updated" date at the top reflects the most recent change. For material changes that affect your rights, we will provide reasonable notice through our website or, where appropriate, by email.
Contact
CLASI LTD 20 Wenlock Road, London, England, N1 7GU United Kingdom Email: privacy@clasi.co.uk General: hello@clasi.co.uk