Privacy Policy
Last updated 15 July 2026
This policy explains how AyrisIQ collects, uses and protects personal data when you visit our website, request access, or use the AyrisIQ workspace as part of an organisation we work with. We are committed to handling personal data in line with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
Who we are
AyrisIQ Ltd is the data controller for personal data collected through our website and for our own account/contact records. Registration of AyrisIQ Ltd is in progress; this notice will be updated with the company number when Companies House issues it. For governance data your organisation uploads into its AyrisIQ workspace, your organisation is the data controller and AyrisIQ acts as a data processor on its behalf, under a data processing agreement.
Questions about this policy can be sent to hello@ayrisiq.co.uk.
What we collect
- Enquiry and access-request details — name, email address, organisation, role and any message you send us via the website.
- Workspace data — the governance documents, policies, audits, incident records, training records and related content your organisation uploads. Patient records and patient-identifiable information are outside the permitted use. Common-identifier scans reduce accidental entry but cannot guarantee anonymity; closed-pilot complaint and incident entry stores a deliberately de-identified summary rather than source text.
- Account and usage data — login events, actions taken in the workspace, and audit records of changes and security-relevant activity.
- Basic technical data — standard web server logs (IP address, browser type, pages visited). We do not currently use analytics, advertising or tracking cookies — see our Cookie Policy for details.
Special category data in staff records
Some workspace content your organisation uploads — for example, occupational health notes, DBS check status, or immunisation records held as part of staff training and competency evidence — can be special category data under UK GDPR. Your organisation remains the controller for this data and is responsible for having a lawful basis for processing it (typically an employment, health-and-safety, or occupational-medicine basis). AyrisIQ processes it only as instructed, under the data processing agreement with your organisation, with the same security and access controls as the rest of the workspace.
How we use it, and our lawful basis
- To respond to enquiries and access requests (legitimate interests).
- To provide the AyrisIQ service to organisations that have signed up (performance of a contract).
- To maintain security, prevent misuse, and keep an audit trail of activity in the workspace (legitimate interests and, where applicable, legal obligation).
How AI processing works
Some AyrisIQ features (for example, reading an uploaded document to build a governance profile, or drafting a suggested fix) can send minimised governance content to Amazon Bedrock in London. Staff-evidence and complaint/incident AI are disabled by default. No patient-identifiable content is permitted; technical scans are a backstop, not an anonymisation guarantee. Provider contracts, retention and DPA evidence are launch gates for real data. AI drafts remain advisory and require a person to review and approve them.
How long we keep it
Workspace data is retained for the duration of your organisation's relationship with AyrisIQ, plus a limited period afterwards where needed for legal, audit or contractual reasons. Enquiry and access-request details are kept only as long as needed to respond, then deleted or anonymised.
Who we share it with
We use a small number of sub-processors to run the Service — for example, our cloud hosting provider, AI processor, transactional-email supplier and Sentry error-reporting service. The current supplier list and open contractual evidence are published in the Trust Centre. We do not sell personal data or share it for third-party marketing.
International transfers
Where personal data is processed outside the UK or EEA, we put appropriate safeguards in place, such as the UK International Data Transfer Addendum or equivalent Standard Contractual Clauses.
Security
Data is encrypted in transit and by the storage providers at rest. Access and organisation boundaries are enforced in application and database policy. Production cross-tenant, restore and independent security evidence must be completed before a real-data pilot; see the Trust Centre for the current status.
Your rights
Under UK GDPR you have the right to:
- ask what personal data we hold about you and get a copy of it;
- ask us to correct inaccurate data;
- ask us to delete data, in certain circumstances;
- object to, or ask us to restrict, certain processing; and
- ask for data you provided to be moved to another provider.
To exercise any of these rights, contact hello@ayrisiq.co.uk. If you're not satisfied with our response, you can complain to the UK Information Commissioner's Office (ICO) at ico.org.uk.
Changes to this policy
We may update this policy from time to time. Material changes will be reflected by an updated "last updated" date at the top of this page.
