Legal
Privacy Policy
Last updated: 10 May 2026
1. Who We Are
StratAi Ltd (trading as StrategyAI) operates the platform at strategyai.co.uk ("the Platform"). For the purposes of UK GDPR and the Data Protection Act 2018, StratAi Ltd is the data controller.
Company number: 17186176
ICO Registration: ZC143495
Contact: admin@strategyai.co.uk
2. Data We Collect
Account data: Name, work email, firm, role/title, LinkedIn profile URL, password (hashed via Supabase Auth — we never see your password in plain text).
Usage data: Pages visited, signals viewed, signals saved, feedback submitted, session timestamps, IP address, browser type, device type.
Consent records: NDA acceptance timestamp, IP address, user agent, NDA version — required for legal evidence of consent.
Payment data: Handled entirely by Stripe (PCI-DSS Level 1 certified). We store a Stripe customer ID and subscription status only — never card numbers, CVCs or bank details.
Communications: Emails you send to admin@strategyai.co.uk, support conversations, feedback submitted in-product.
Cookies: See our Cookie Policy.
3. Legal Basis for Processing
| Purpose | Legal basis |
|---|---|
| Delivering the subscription service | Contract |
| Improving the Platform, analytics, security, fraud prevention | Legitimate interest |
| Marketing emails, non-essential cookies | Consent (withdrawable any time) |
| Retaining records for HMRC, GDPR audit logs | Legal obligation |
4. How We Use Your Data
- To provide and personalise your access to the Platform
- To match BD signals to your sector, geography and firm
- To process subscription payments via Stripe
- To send transactional emails (magic links, signal digests, billing)
- To detect, investigate and prevent fraud or misuse
- To comply with legal and regulatory obligations
We do not sell, rent or trade your personal data. We do not use your data to train third-party AI models.
5. Where Your Data Is Stored
| Service | Purpose | Location |
|---|---|---|
| Cloud database & authentication | Database, authentication, file storage | EU (Frankfurt) |
| Stripe | Payment processing | EU & US (Stripe Inc., Stripe Payments UK Ltd) |
| Transactional email provider | Transactional email delivery | EU |
| Messaging & alerts provider | WhatsApp alerts (opt-in only) | EU & US |
| Large language model (LLM) provider | Signal scoring (no personal data sent — only company-level public information) | US |
All international transfers rely on UK International Data Transfer Agreements or EU Standard Contractual Clauses.
A full list of our named sub-processors is available on request.
6. How Long We Keep Data
| Data type | Retention |
|---|---|
| Account data | For as long as your account is active, plus 12 months |
| Consent / NDA records | 6 years (UK contract law limitation period) |
| Payment / billing records | 7 years (HMRC requirement) |
| Usage logs and analytics | 24 months |
| Marketing preferences | Until you withdraw consent |
You can request deletion of your account at any time (see Section 8).
7. Who We Share Data With
We share data only with the processors listed in Section 5, and only as necessary to deliver the Platform. We do not share data with consulting firms, recruiters, advertisers, or any third party not listed above.
We may disclose data if required by law, court order, or to protect our legal rights.
8. Your Rights
Under UK GDPR you have the right to:
- Access the personal data we hold about you
- Correct inaccurate data
- Request deletion of your data ("right to be forgotten")
- Restrict or object to processing
- Receive your data in a portable format
- Withdraw consent at any time
- Lodge a complaint with the ICO (ico.org.uk)
To exercise any of these rights, email admin@strategyai.co.uk. We will respond within 30 days.
9. Security
We protect your data with:
- TLS encryption in transit (HTTPS everywhere)
- AES-256 encryption at rest (Supabase managed)
- Row-Level Security policies on every database table
- Magic-link authentication (no stored passwords on the client)
- 2-session concurrent login limit per user
- Audit logging on all sensitive operations
See our Security page for full detail.
10. Children
StrategyAI is a B2B service for senior strategy consulting professionals. We do not knowingly collect data from anyone under 18.
11. Changes to This Policy
We will update this policy as the Platform evolves. Material changes will be notified by email to active users at least 14 days before they take effect.
12. Contact
Data Protection Queries: admin@strategyai.co.uk
Complaints: Information Commissioner's Office, ico.org.uk, 0303 123 1113