Privacy Policy
How we handle your personal data — UK GDPR compliant
Who We Are
Scrutiny AI operates from Scotland, United Kingdom. For the purposes of UK data protection law, the data controller is Scrutiny AI. You can contact us at contact@scrutinyai.io.
What Data We Collect
We collect personal data only through our API access request form. The fields collected are:
- Name
- Email address
- Organisation
- Use case description
We do not collect IP addresses beyond what is used by Cloudflare for security and infrastructure purposes (see Cloudflare's privacy policy). We do not use analytics. We do not use tracking cookies. We do not serve advertising.
How We Use Your Data
The data you submit via the contact form is used solely to evaluate and respond to your API access request. Your submission is forwarded to our team by email and is not stored in any database. No data is retained after the email is forwarded.
Legal Basis for Processing
We process your personal data on the basis of legitimate interests (Article 6(1)(f) UK GDPR). Our legitimate interest is evaluating and responding to enterprise enquiries. This processing is necessary for us to operate our business, and we do not believe it causes undue harm to your rights or interests given the limited data collected and the immediate-discard architecture.
Data Retention
Form submission data is forwarded to contact@scrutinyai.io immediately upon receipt and is not stored by our systems. Email correspondence may be retained in our email account for as long as is reasonably necessary to manage the business relationship. You may request deletion of email correspondence at any time.
Sharing Your Data
We do not sell, rent, or share your personal data with third parties for marketing or commercial purposes. Your data may be processed by the following infrastructure providers as part of delivering our service:
- Cloudflare, Inc. — website hosting, security, and infrastructure. Cloudflare processes request metadata as part of providing DDoS protection, WAF, and CDN services. Cloudflare acts as a data processor on our behalf. See Cloudflare's privacy policy for further detail.
Cookies
This website does not set cookies for tracking or analytics purposes. Cloudflare may set a cookie (__cf_bm) for bot management and security purposes. This is a strictly necessary cookie and does not require consent under UK GDPR.
Cloudflare Turnstile, used to protect our contact form, processes request metadata for the purpose of distinguishing humans from automated submissions. Turnstile does not use cookies for tracking.
Your Rights
Under UK GDPR, you have the following rights regarding your personal data:
- Right of access — request a copy of the personal data we hold about you
- Right to rectification — request correction of inaccurate personal data
- Right to erasure — request deletion of your personal data where there is no overriding legitimate reason for us to retain it
- Right to restriction — request that we restrict processing of your data in certain circumstances
- Right to object — object to processing based on legitimate interests
- Right to data portability — receive your personal data in a structured, commonly used format
To exercise any of these rights, contact us at contact@scrutinyai.io. We will respond within one month.
Complaints
If you are unhappy with how we handle your personal data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK supervisory authority for data protection. You can contact the ICO at ico.org.uk.
International Transfers
Cloudflare operates globally and may process data outside the UK. Cloudflare maintains UK GDPR compliance through appropriate safeguards. We do not knowingly transfer personal data to countries without adequate data protection laws.
Changes to This Policy
We may update this policy from time to time. The current version is always available at this URL. Significant changes will be noted in the version date below.
Contact
Data protection enquiries: contact@scrutinyai.io
Last reviewed: April 2026