1. Overview
AI Automation Agency (“we”, “us”, or “our”) operates as a premium AI automation service provider. This Privacy Policy applies to all information collected through our website at neuronagency.ai, our client portal, and any services we deliver — including AI workflow automation, chatbot deployment, CRM integrations, and related professional services.
By using our website or engaging our services, you agree to the collection and use of information in accordance with this policy. If you disagree with any part of this policy, please discontinue use of our services and contact us at privacy@neuronagency.ai.
We do not sell, rent, or trade your personal information to third parties for marketing purposes — ever. Our business model is built on client trust, and that trust starts here.
This policy was last updated on May 30, 2026. We will notify you of material changes by email (if you are a registered user) or by placing a prominent notice on our website.
2. Information We Collect
We collect information in three ways: information you provide directly, information collected automatically, and information received from third parties in the course of delivering our services.
Information you provide directly:
- Contact form submissions (name, email, company, role, message)
- Strategy call booking data (name, company, role, challenge description)
- Account registration details if you access a client portal
- Billing and payment information (processed by Stripe — we do not store card details)
- Communications you send us by email, Slack, or other channels
Information collected automatically:
- IP address and approximate geographic location (country/city)
- Browser type, operating system, and device type
- Pages visited, time on page, and navigation path
- Referral source (how you arrived at our site)
- Cookie and session identifiers (see Section 6)
Information received from third parties:
- Integration credentials and API tokens you provide to connect your tools (stored in encrypted secrets management — see Section 8)
- Data from your connected business systems that flows through automation pipelines we build on your behalf
3. How We Use Your Data
We use collected information for the following purposes:
- Service delivery: Building, testing, deploying, and maintaining the AI automation systems you engage us to create
- Communication: Responding to enquiries, sending project updates, and providing support
- Billing: Processing payments and sending invoices
- Legal compliance: Meeting our obligations under GDPR, HIPAA (where applicable), and other applicable regulations
- Security: Detecting, preventing, and responding to fraud, abuse, or security incidents
- Product improvement: Aggregated, anonymised analytics to improve our website and service quality
We do not use your data for advertising, profiling, or sale to third parties. We do not use your business data to train AI models.
4. Data Sharing
We share personal data only in the following limited circumstances:
- Sub-processors: We use a small number of trusted third-party services to operate our business (listed below). Each is bound by appropriate data processing agreements.
- AI API providers: When building your automation, data may pass through AI APIs (OpenAI, Anthropic). We configure these integrations to opt out of training data usage and apply PII redaction where appropriate.
- Legal requirements: We may disclose data where required by law, regulation, or court order.
- Business transfer: In the event of a merger or acquisition, your data may transfer to the successor entity subject to equivalent protections.
Our primary sub-processors include: Stripe (payments), Vercel (hosting), Google Analytics (anonymised web analytics), Notion (project management), Slack (internal communications), HashiCorp Vault (secrets management).
We will update this list when we add or change sub-processors and provide 30 days’ notice to clients where contractually required.
5. AI Automation & Client Data
This section specifically addresses how we handle data that flows through the AI automation systems we build for clients.
Your data is yours. All data processed through automation pipelines we build belongs to you. We access it only to deliver the service you engaged us for.
No training use. Client business data is never used to train, fine-tune, or improve any AI model — by us or by our AI API sub-processors. We configure all API integrations with data training opted out.
PII redaction. Where workflows involve personal data (names, emails, financial information), we apply automated PII redaction before data is sent to external AI APIs.
Data minimisation. We design workflows to process the minimum data necessary to achieve the automation objective.
Audit logging. All data processing events in production systems are logged with timestamps, identifiers, and outcomes. Logs are retained for 90 days by default and can be extended by contractual agreement.
6. Cookies & Tracking
Our website uses a minimal set of cookies:
| Cookie | Purpose | Duration |
|---|---|---|
_ga, _gid |
Google Analytics (anonymised, IP masked) | 2 years / 24h |
session |
Maintain login state in client portal | Session |
csrf_token |
Security — prevent cross-site request forgery | Session |
We do not use advertising cookies, cross-site tracking, or retargeting pixels. You can opt out of analytics cookies via our cookie preference centre (banner on first visit) or by configuring your browser.
7. Data Retention
We retain personal data for as long as necessary to fulfil the purpose for which it was collected:
- Website enquiry data: 3 years from last contact
- Client project data: Duration of engagement + 5 years
- Billing records: 7 years (legal requirement)
- Automation pipeline logs: 90 days (default); configurable by contractual agreement
- Email communications: 3 years from end of engagement
When data is no longer needed, we securely delete or anonymise it. Clients may request earlier deletion subject to legal retention requirements.
8. Security
We implement security measures appropriate to the sensitivity of the data we process:
- Encryption at rest: AES-256 for all stored credentials and sensitive data
- Encryption in transit: TLS 1.3 for all data transmission
- Secrets management: HashiCorp Vault for all API keys and credentials — never stored in code or config files
- Access control: Role-based access; least-privilege principle applied throughout
- Monitoring: 24/7 anomaly detection on all production systems
- Penetration testing: Independent security assessment conducted quarterly
In the event of a confirmed data breach, we will notify affected clients within 24 hours and supervisory authorities within 72 hours as required by GDPR Article 33.
9. Your Rights
Under GDPR and applicable data protection laws, you have the following rights:
- Right to access: Request a copy of the personal data we hold about you
- Right to rectification: Request correction of inaccurate data
- Right to erasure (“right to be forgotten”): Request deletion of your data (subject to legal retention requirements)
- Right to restriction: Request we limit processing of your data in certain circumstances
- Right to data portability: Receive your data in a structured, machine-readable format
- Right to object: Object to processing based on legitimate interests
- Right to withdraw consent: Where processing is based on consent, withdraw it at any time
To exercise any of these rights, email privacy@neuronagency.ai. We will respond within 30 days. You also have the right to lodge a complaint with your national supervisory authority (in the UK: ICO at ico.org.uk; in the EU: your local DPA).
10. International Transfers
Our team is distributed across 12 countries. Where personal data is transferred outside the UK or EEA, we rely on one of the following safeguards:
- Adequacy decisions issued by the UK ICO or EU Commission
- Standard Contractual Clauses (SCCs) with data recipients
- Binding Corporate Rules where applicable
We do not transfer personal data to countries without adequate protection unless appropriate safeguards are in place. A list of the countries to which we transfer data is available on request.
11. Children’s Privacy
Our services are not directed to individuals under the age of 16. We do not knowingly collect personal data from children. If you believe we have inadvertently collected data from a minor, please contact us immediately at privacy@neuronagency.ai and we will delete it promptly.
12. Policy Changes
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will:
- Update the “Last updated” date at the top of this page
- Notify registered users and active clients by email at least 14 days before changes take effect
- Display a prominent notice on our website for 30 days
Your continued use of our services after the effective date of any change constitutes acceptance of the updated policy. If you do not agree to the updated terms, please discontinue use of our services and contact us to close your account.
Questions about this policy? Contact our Data Controller at privacy@neuronagency.ai or write to: AI Automation Agency, Data Privacy Team, [address on file].