Privacy policy
This policy explains what personal data TheAifaLabs collects, why we collect it, how long we keep it, who we share it with, and the rights you have over it.
Last updated: 1 August 2026 · Version 2.1
1. Who we are
TheAifaLabs ("we", "us", "our") operates theaifalabs.com and sells digital products, software services and study material. For the purposes of the UK GDPR and EU Regulation 2016/679, TheAifaLabs is the data controller for personal data collected through this website and for data you give us during a commercial engagement.
Where we process data on a client's behalf — for example when we run sentiment analysis over a client's own customer reviews — we act as a data processor and the client remains the controller. Those engagements are governed by a separate Data Processing Agreement.
| Controller | TheAifaLabs |
|---|---|
| Registered address | Street address, City, State PIN, Country |
| Privacy contact | jhi@theaifalabs.com |
2. Data we collect
2.1 Data you give us
- Enquiry data — name, email address, subject, the content of your message, and the optional interest category, submitted through the contact form.
- Newsletter data — email address and subscription date.
- Order data — billing name, email, billing address, country, tax identifiers where required, and the products purchased.
- Account data — for AifaSense subscriptions: username, hashed password, workspace settings and team member email addresses you invite.
- Support data — anything you send us in a support ticket, including attachments.
2.2 Data we collect automatically
- Technical data — IP address (truncated where analytics allows it), browser type and version, operating system, device type, screen size and referring URL.
- Usage data — pages viewed, time on page, downloads initiated, and in-app feature usage for subscribers.
- Delivery data — whether a transactional or newsletter email was delivered, opened or bounced.
2.3 Data we never collect
We do not collect special-category data (health, biometrics, religious or political affiliation, sexual orientation) and ask you not to send it. We do not store full payment card numbers at any point — card data is captured by our payment processor and never reaches our servers.
3. Why we process it, and the legal basis
| Purpose | Data used | Legal basis (Art. 6 GDPR) |
|---|---|---|
| Reply to your enquiry | Enquiry data | Consent (6(1)(a)) — given via the form checkbox |
| Deliver a purchased product and provide support | Order, account, support data | Contract (6(1)(b)) |
| Issue invoices and meet tax obligations | Order data | Legal obligation (6(1)(c)) |
| Send the newsletter | Newsletter data | Consent (6(1)(a)) — withdrawable at any time |
| Keep the site secure and prevent abuse | Technical data | Legitimate interests (6(1)(f)) |
| Understand aggregate site usage | Usage data | Consent for non-essential cookies; otherwise legitimate interests over anonymised data |
| Defend or bring legal claims | Any relevant data | Legitimate interests (6(1)(f)) |
Where we rely on legitimate interests, we have carried out a balancing assessment and will provide a summary on request.
4. Cookies and similar technologies
A cookie is a small file stored by your browser. We group ours into three categories, and we set nothing beyond the strictly necessary category until you consent.
| Category | What it does | Consent needed | Typical lifetime |
|---|---|---|---|
| Strictly necessary | Session handling, login state, load balancing, CSRF protection, remembering your cookie choice | No | Session to 12 months |
| Analytics | Aggregate page views and traffic sources, so we know which articles are worth writing more of | Yes | Up to 13 months |
| Marketing | Measuring the performance of paid social and search campaigns | Yes | Up to 13 months |
You can withdraw or change your cookie choice at any time through the cookie settings link in the footer of the live site, or by clearing cookies in your browser. Blocking strictly necessary cookies will break checkout and login.
We honour Global Privacy Control (GPC) signals where your browser sends one, and we do not use fingerprinting to work around a refused consent.
5. Third-party processors
We keep our processor list short and we do not sell personal data to anyone, under any circumstances. Current categories:
| Category | Purpose | Data shared |
|---|---|---|
| Hosting and CDN | Serving this website and the application | Technical data, request logs |
| Payment processor | Taking payment and issuing receipts | Billing name, email, address, amount — card data goes directly to the processor |
| Email delivery | Transactional email and the newsletter | Email address, delivery events |
| Analytics | Aggregate site statistics | Truncated IP, usage data — only after consent |
| Helpdesk | Managing support tickets | Support data you send us |
| Accounting | Statutory bookkeeping | Invoice data |
Each processor is bound by a written agreement under Article 28 GDPR. The named list of current sub-processors is available from jhi@theaifalabs.com, and subscription clients are notified before a new sub-processor is added.
We may also disclose data where legally compelled to do so, or to a buyer as part of a merger or acquisition — in which case you will be told before your data is transferred.
6. International transfers
Some processors operate outside the European Economic Area. Where data leaves the EEA or the UK, one of the following applies: an adequacy decision covering the destination country, the European Commission's Standard Contractual Clauses (2021/914) plus a transfer risk assessment, or the UK International Data Transfer Addendum. Copies of the clauses relied on are available on request.
Enterprise clients may request EU-only or India-only data residency for AifaSense processing. Ask before you sign.
7. How long we keep data
| Data | Retention period |
|---|---|
| Enquiry messages | 24 months from last contact, then deleted |
| Newsletter subscription | Until you unsubscribe, plus a suppression record so we do not re-add you |
| Order and invoice records | As required by tax law in our jurisdiction (currently 8 years) |
| Account data | Duration of the subscription plus 90 days, then deleted or anonymised |
| Support tickets | 36 months from closure |
| Server and security logs | 90 days |
| Client data processed under a DPA | Per the DPA — deleted or returned within 30 days of termination |
8. Security
- TLS 1.2 or higher on every connection to our sites and APIs.
- Encryption at rest for databases and backups.
- Role-based access control, least privilege, and mandatory multi-factor authentication for all staff accounts.
- Access logging and quarterly review of who holds which permission.
- Dependency scanning and patching on a defined cadence.
- Documented incident response: we notify the relevant supervisory authority within 72 hours of becoming aware of a qualifying breach, and affected individuals without undue delay where the risk to them is high.
No system is perfectly secure. If you believe you have found a vulnerability, please report it to jhi@theaifalabs.com rather than disclosing it publicly; we will acknowledge within two business days.
9. Your rights
Under the GDPR and equivalent laws you have the right to:
- Access — get a copy of the personal data we hold about you.
- Rectification — have inaccurate data corrected.
- Erasure — have data deleted where we no longer have a lawful reason to keep it.
- Restriction — have processing paused while a dispute is resolved.
- Portability — receive data you gave us in a structured, machine-readable format.
- Object — object to processing based on legitimate interests, and to direct marketing at any time, absolutely.
- Withdraw consent — at any time, without affecting processing already carried out.
- Not be subject to solely automated decisions producing legal or similarly significant effects. We do not make such decisions about individuals.
To exercise any of these, email jhi@theaifalabs.com. We respond within 30 days and may ask you to verify your identity first. There is no charge unless a request is manifestly unfounded or excessive.
10. Children's data
Our services are not directed at children under 16, and we do not knowingly create accounts for them. Our CBSE study material is bought by parents, teachers and institutions on a student's behalf; where a purchaser is under 16, we require the transaction to be completed by a parent or guardian. If you believe a child has given us personal data directly, contact us and we will delete it.
11. Changes to this policy
We update this policy when our processing changes. The version number and date at the top always reflect the current text. For material changes affecting how we use data you have already given us, we notify active customers and subscribers by email at least 14 days before the change takes effect.
12. Contact and complaints
Privacy questions, rights requests and complaints: jhi@theaifalabs.com, or write to the registered address listed in section 1.
If you are not satisfied with our response, you can complain to your local supervisory authority. In the EU that is the data protection authority of your country of residence; in the UK it is the Information Commissioner's Office; in India it is the authority designated under the Digital Personal Data Protection Act. You do not need our permission to complain, and doing so does not affect any other remedy available to you.