← Back to Home
GOVERNANCE & COMPLIANCE

Privacy Policy

Last Updated: February 2026 • Obelisk AI LTD

01.1. Introduction

Thank you for choosing Obelisk AI Ltd ("we", "us", or "our"). We are committed to protecting and respecting your privacy and corporate data. This policy outlines how we collect, use, and safeguard the personal and business information you provide to us as an enterprise client.

02.2. Data Controller

For the purpose of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, the data controller is Obelisk AI Ltd, registered at 86-90 Paul Street, London, England, United Kingdom, EC2A 4NE.

03.3. Information We Collect

We only collect information necessary to deliver our high-tier services. This includes: Client Data: Your name, email address, phone number, and executive job title. Transactional Data: Billing information, subscription details, and payment history. We do not store your credit card details; this is handled securely by our enterprise payment processor, Stripe. Service Data: Any operational data, system access points, or API keys you provide to us to enable the delivery of our AI and automation services. Technical Data: IP addresses, browser types, and access times, collected in server logs for security monitoring.

04.4. How and Why We Use Your Data

We use your data for the following purposes, based on a lawful ground for processing: To Provide Our Services: We use your Client and Service Data to communicate with you, manage your account, and deliver the bespoke AI/automation solutions you have commissioned. (Legal Basis: Performance of a Contract) For Billing and Account Management: We use your Transactional Data to process retainers and manage your subscription term. (Legal Basis: Performance of a Contract) For Security and Analytics: We use Technical Data to protect our infrastructure from misuse and analyse system performance. (Legal Basis: Legitimate Interests)

05.5. Data Sharing and Third Parties

We do not sell your personal or corporate data. We only share it with trusted third-party service providers who are essential for us to operate, including: Payment Processor: Stripe, Inc. to process payments. Stripe handles your Transactional Data in accordance with its own enterprise privacy policy. Legal and Regulatory Bodies: We may be required to share data to comply with a legal obligation, sharing only the absolute minimum necessary.

06.6. Data Retention

We retain your data for the duration of your engagement with us and for a subsequent period of 6 years to comply with our legal and financial record-keeping obligations. After this period, your data will be securely deleted or anonymized.

07.7. Data Security

We have implemented enterprise-grade technical and organisational security measures (including end-to-end encryption) to protect your personal and business information from unauthorised access, disclosure, or destruction.

08.8. Cookies

Our platform uses only strictly necessary cookies essential for functioning correctly, such as for secure payment processing. We do not use cookies for advertising, tracking, or non-essential analytics.

09.9. International Data Transfers

Some of our third-party providers (like Stripe) are based outside the UK. When we transfer your data, we ensure it is protected by appropriate safeguards, such as Standard Contractual Clauses, ensuring compliance with strict UK data protection standards.

010.10. Your Data Rights

Under UK data protection law, you have the following rights: Access: Request a copy of the personal information we hold about you. Correction: Request that we correct any inaccurate information. Deletion: Request that we delete your personal data. Restriction: Request that we restrict the processing of your data. Data Portability: Request that we provide your data in a structured, machine-readable format. Lodge a Complaint: You have the right to lodge a complaint with the UK's supervisory authority, the Information Commissioner's Office (ICO).

011.11. Breach Notification

In the highly unlikely event of a data breach that poses a risk to your rights, we will notify you and the ICO in accordance with our legal obligations.

012.12. Contact Us

If you have any questions about this privacy policy or wish to exercise your rights, please contact your dedicated pod leader or email us at contact@obeliskai.co.uk.