Skip to content

Privacy Policy

Last updated: 30 August 2026

The short version

We collect the least we can get away with: enough to check that applicants are real people, to run meetups, to publish the listings members ask us to publish, and to send the emails people have asked for. We do not sell data and we do not run advertising trackers; we count page views with measurement that stores nothing on your device and cannot recognise you on a later visit. Everything in the AI Directory and the question threads is public because that is the point of them. You can delete your account yourself from your security settings; for anything else, email privacy@aisat.uk and we will sort it out within a month.

1. Who we are and how to contact us

AISAT (AI Strategy, Automation & Transformation) is the data controller for the personal data described in this policy. In plain terms, that means we decide what is collected on aisat.uk and why, and we are accountable for it under the UK GDPR and the Data Protection Act 2018.

The best way to reach us about anything in this policy is privacy@aisat.uk. For everything else, use hello@aisat.uk.

Who is responsible for your data

AISAT is run by its organisers, who between them decide what personal data this site collects and what happens to it. That makes them the data controller. If you want to know who handled something, or you need a postal address to send a formal notice to, email privacy@aisat.uk and we will give you one.

We are not required to appoint a Data Protection Officer and have not appointed one. Requests are handled by the AISAT organisers.

2. What we collect and why

Everything below is either something you have typed into this site, or something our hosting and email providers record in order to work at all. We do not buy data about you from anyone, and we do not build profiles of you.

Personal data AISAT collects, the reason for collecting it, and the lawful basis for doing so
What we collectWhy we need itLawful basis
Membership application: name, email address, LinkedIn profile URL, and optionally company, job title, city, plus your reason for joining and how you heard about usSo an organiser can check that you are a real person working in this field, decide whether to approve your application, and get in touch about itLegitimate interests: running a members-only community and vetting who joins it, so that the room stays safe, relevant and free of prospecting
Account and sign-in data: your email address, sign-in tokens, the times you signed in, and your Google account identifier if you sign in with GoogleTo let you sign in without a password, keep you signed in, and show you the right dashboardPerformance of our arrangement with you (you cannot have an account without it), supported by our legitimate interest in keeping accounts secure
Record of acceptance: the date and time you accepted these terms and this policy, and whether you opted in to marketingSo that we can show what you agreed to and when, if it is ever questionedLegal obligation (accountability under UK GDPR) and legitimate interests in defending claims
Directory listing: display name, photo or logo, summary and description, city, region, country, working preference, website and social links, contact email if you choose to show it, involvement, tags, and (depending on listing type) company size, founding year, Companies House number, services, engagement types, budget band, hiring status and case studies, or headline role, experience, availability, what you are looking for, right to work, notice period, speaker topics and portfolio linksTo publish the listing you have asked us to publish. All of it is public by design. See the section on the directory belowConsent: you choose to publish, and you can unpublish or delete the listing at any time
Threads and replies: the question you ask if you start a thread, what you write when you reply to one, the name on your membership shown beside either, and when you posted it, plus a record of which threads and replies you have upvotedTo publish what you wrote on the public page it belongs to, and to order threads and replies by what other members found useful. All of it except the upvotes is public by design. See the section on question threads belowConsent: nothing requires you to post, you can delete your own thread or reply yourself, and we will take either down whenever you ask
Event registration: name, email address, and optionally company and job title, plus your registration or waiting-list statusTo hold your place, send you joining details and reminders, and manage capacity and waiting listsSteps taken at your request before entering into an arrangement with you (Article 6(1)(b)), and our legitimate interest in running the event well
Badge use of your name, company and job title, with a QR code to the LinkedIn profile on your membershipTo print your badge for that eventConsent: the first of the two tick boxes on the registration form, which you can withdraw
Attendee-list use of your name, company and job titleTo compile the attendee list shared with other attendees, the speakers and the sponsors of that eventConsent: the second of the three tick boxes on the registration form, answered separately from the first, and withdrawable
Public-page use of your name, company and job title, with a link to the LinkedIn profile on your membershipTo show that you are attending on the public page for that event, which anyone on the internet can read, search engines includedConsent: the third tick box on the registration form, answered separately from the other two, and one you can withdraw yourself from your bookings page at any time
Accessibility or dietary requirements, if you choose to tell usSo that the venue and caterers can make the arrangements you needExplicit consent (Articles 6(1)(a) and 9(2)(a)): this can reveal health or religious information, so we only ever use it for the event you gave it for
Newsletter subscription: email address, where you signed up, the time you consented, which version of the wording you agreed to, and an unsubscribe tokenTo send occasional email about upcoming meetupsConsent: required for marketing email under PECR, and withdrawable in one click
Email delivery data: whether a message we sent you was delivered, bounced or was marked as spamTo know whether our emails are actually arriving and to stop sending to dead addressesLegitimate interests: making sure the emails you asked for reach you
Technical and log data: IP address, browser and device type, pages requested, timestamps and error reportsTo serve the site, keep it up, investigate faults and detect abuse such as bot sign-upsLegitimate interests: security, fraud prevention and keeping the service running
Organiser records: approval and rejection decisions, actions taken by admins, and reports made under the Code of ConductSo that decisions are accountable, and so that a pattern of behaviour is not lost when organisers changeLegitimate interests: safeguarding our members and being able to show why we acted
Correspondence: messages you send through the contact form (your name, email address, the subject you picked and what you wrote) and email you send to hello@, privacy@ or john@aisat.uk (your name and address, who else it was addressed to, the subject, the full message in both text and HTML, and the file name, type and size of any attachment)To read what you sent, answer it, and keep track of what was said and agreed. Attachments themselves stay with our email provider and are fetched only when one is openedLegitimate interests: dealing with enquiries and being able to show what was agreed. Where you write to us about your own data rights, a legal obligation to answer you

3. The lawful bases we rely on

UK GDPR requires a lawful basis for every use of personal data. We use four, and we try to be honest about which is which. Calling something consent when it is really a condition of using the service would be worse than useless to you.

Consent

We rely on consent for the things that are genuinely optional: the newsletter and any other marketing email, publishing your directory listing, posting a reply to the question of the day, using your name, company and job title on badges and the attendee list, and holding any accessibility or dietary information you give us. You can withdraw consent at any time (unsubscribe, unpublish your listing, delete a reply, ask us to take one down, or email privacy@aisat.uk), and it is as easy to withdraw as it was to give. Withdrawing consent does not make what we did beforehand unlawful, and it does not affect your membership.

Legitimate interests

We rely on legitimate interests for community administration, for vetting applications, and for security. The interests are: keeping AISAT a community of identifiable, genuine practitioners rather than bots and prospectors; being able to run meetups without chaos; and protecting members and the site from abuse. We have weighed those interests against your rights, and we think they are reasonable because the data involved is professional rather than personal in nature, you provide it knowingly, we use it only for the community, and you can object at any time. If you would like our reasoning in more detail, ask and we will send it.

Performance of an arrangement, and steps taken at your request

When you register for an event or open an account, we use your data to do the thing you asked for: hold your place, send joining details, let you sign in. Without it there is nothing to deliver.

Legal obligation

A small amount of processing is required of us by law: keeping records of consent so that we can demonstrate compliance, and responding to lawful requests from a regulator, a court or the police.

No automated decisions

We do not carry out automated decision-making or profiling that produces legal or similarly significant effects. Every membership application, and every decision to remove a listing or end a membership, is made by a person.

4. Event badges and attendee lists

This is the part of the policy people most often find surprising after the fact, so it gets its own section. When you register for an AISAT event, the form asks you three separate questions:

The three questions, as the form puts them

When you register for an event we ask three separate questions, and you may say no to any of them without losing your place. The first is whether we may print your name, company and job title on a badge, with a QR code linking to the LinkedIn profile on your AISAT membership. The second is whether those same three details may go on the attendee list we share with other attendees, speakers and sponsors of that event. The third is whether we may show them on the event's public page, with a link to the LinkedIn profile on your membership, to say that you are attending; anyone on the internet can read that page, and that one you can take down yourself at any time from your bookings page. We never put your email address, your phone number or anything you tell us about accessibility or diet on any of the three.

They are three ticks, not one, and they are answered independently. You can agree to any of them and refuse the others. No answer affects another, and none affects your place at the event: leave all three unticked and you are registered exactly as you would otherwise have been.

Who the attendee list goes to

  • Other attendees at that same event, so people can see who is in the room and follow up with someone they met.
  • The speakers at that event, so they know who they are presenting to.
  • The sponsors and hosts of that event, the organisations paying for the room, the food or the drinks. This is usually what they get in return, and we would rather say so than dress it up.

The list is limited to name, company and job title. It never includes your email address, your phone number, your accessibility or dietary notes, or anything about other events you have been to. A list is specific to one event: registering for a meetup in Leeds does not put you on a list that goes to a London sponsor.

Separately, some venues require a security or fire list of everyone entering the building. That list contains names only, goes to the venue alone, and is normally destroyed by them after the event. We rely on legitimate interests and the venue’s own requirements for that, not on the consent above, because it is a condition of being let into the building.

Showing that you are coming

The third question is different in kind from the other two, which is why it is asked separately. If you tick it, your name, company and job title appear on the public page for that event under “Who’s coming”, with a link to the LinkedIn profile on your membership. That page is open to anyone on the internet, and search engines can index it. It shows only those details, only while you hold a confirmed place, and only for that event. The link is shown only where the sentence you ticked named it: a yes given under the earlier wording, which did not, shows the three details and no link until you tick again.

People who have not ticked it are counted, not named: the page says how many more are coming and nothing else about them. The names stay on the page after the event as the record of who came, and come off it when you untick the box, when your registration is anonymised on deleting your account, or when it is deleted 23 months after the event, whichever is first. Because it is a live page rather than a printed sheet, you can take yourself off it yourself, at once, from your bookings page; there is no organiser in the way.

How to say no

  • Leave the second box unticked when you register and you will not appear on the attendee list. Nothing else changes: your place is confirmed either way, and you can still have a badge.
  • Leave the third box unticked and you are counted on the event page but never named on it.
  • Leave the first box unticked and we will not print you a badge. The only practical consequence is that there is no badge, which matters in one specific case set out under photography below.
  • Email privacy@aisat.uk at any time before the event, saying which of the three you have changed your mind about, and we will act on it.
  • Tell any organiser on the day. Bear in mind that once badges have been printed or a list has been handed to a sponsor, we cannot recall the copies that are already out in the world, so it is better to tell us in advance if you can.

None of the answers is fixed once you have registered: all three are shown on your bookings page, where ticking one you had left unticked takes effect there and then. Taking the badge or attendee-list answer back goes through a person: email privacy@aisat.uk saying which, and an organiser does it for you. The public-page answer you can untick yourself, there and then, and your name comes off the page the moment you save. The photography opt-out is on the same booking and you can move it in either direction yourself, because it is an objection rather than a consent.

The same wording appears in our Terms & Conditions, and the registration form draws on the same single source, so the three cannot drift apart.

5. Accessibility and dietary needs

The registration form has an optional box for accessibility or dietary requirements. Anything you write there may reveal information about your health or your religious beliefs, which UK GDPR treats as special category data and protects more strictly. We handle it accordingly.

  • It is entirely optional, and we rely on your explicit consent under Article 9(2)(a).
  • We use it only to make arrangements for the event you gave it for: step-free access, a reserved seat, a dietary requirement passed to the caterer.
  • We share only what is necessary, usually as an unnamed count (for example “two gluten-free”), and only with the venue for that event, or the caterer it brings in.
  • It never appears on a badge or an attendee list, and it is erased automatically 29 days after the event by a scheduled job. No one has to remember to do it.

6. Photography and recording at events

We take photographs at meetups and sometimes record talks. They are used on this site, in our email and on our social media accounts, to show what the community is actually like to people deciding whether to come.

For general shots of the room and the speakers we rely on legitimate interests rather than consent: a photograph of a full room is how a meetup is described, and asking a room full of people to sign something at the door would not make anybody freer. What makes that fair is that the opt-out is real and easy to use.

  • There is a tick box on the event registration form. Tick it and your badge is printed with a “NO PHOTOS PLEASE” marker in red, and we brief whoever is shooting. A preference nobody in the room can see is not an opt-out, so the marker is the substance of this rather than a decoration.
  • One case is worth knowing about before the night. If you also refused the badge consent, there is no badge, and so nothing for the marker to be printed on. The registration form says so at the point you make that choice. Nothing is lost: tell an organiser when you arrive and we will brief whoever is shooting, which is the part that actually does the work.
  • You can also tell any organiser on the night, and change your mind in either direction at any point in the evening.
  • For a close-up of one identifiable person used to promote a future event, we ask that person directly and rely on their consent. A message saying yes is enough.
  • If a photograph of you is already published and you would rather it were not, email privacy@aisat.uk and we will take it down. We do not ask why.

Other attendees take their own photographs, and those are theirs rather than ours: we are not the controller for them and cannot promise anything about what happens to them. Our Code of Conduct asks everyone to respect the marker and to ask before posting a close-up of somebody, which is a matter of how the room behaves rather than something we can enforce.

7. The AI Directory is public

Everything in your AI Directory listing is public. Not “public to other members”: public to anyone with a web browser. By default listings are indexed by Google and other search engines, may appear in search results and AI-generated answers, and may be cached, copied or scraped by third parties despite our terms forbidding it.

Please treat the listing form as writing a public web page, because that is what it is. Only publish what you are content for a client, a competitor or a recruiter to read. Your contact email address is shown only if you switch it on; if you leave it off, enquiries come through a form instead.

Being in the directory and being in Google are two decisions

The listing form has a switch for search engine visibility, and it is worth finding. Turn it on and your page carries a noindex instruction and is left out of our sitemap, so Google and the others are asked not to list it. The listing itself is unaffected: it still appears in the AI Directory, and anyone with the link can still open it.

We say “asked” deliberately. It is a request that search engines honour in practice rather than a wall, a page that has already been indexed can take weeks to drop out, and copies held by other people are nobody’s to delete. That asymmetry is the reason the switch exists: taking a page down is something you can do, while getting it un-indexed afterwards is something you have to ask for.

Removing a listing

  • You can unpublish your listing yourself from your dashboard at any time, which takes it off the public site immediately. To have it deleted outright rather than hidden, email privacy@aisat.uk and we will do it for you. Asking us to delete your account unpublishes the listing at once and deletes it, drafts and all, with everything else.
  • Once it is unpublished the page stops being served by us, normally within minutes.
  • Search engines may keep a cached copy for a while. We cannot delete their copies, but we can ask them to refresh, and you can also use the removal tools that Google and Bing provide for content that is no longer live.

8. Question threads are public

We publish a question of the day, approved members can start threads of their own on AI Threads, and approved members can reply to either. Those threads are public in the same sense the directory is. Not “public to other members”: anyone with a web browser can read the question and every reply to it without signing in, and there is no members-only setting.

Your reply is published with the name on your membership beside it, and the page it sits on is indexed by Google and other search engines. It may appear in search results and in AI-generated answers, and it may be cached, copied or scraped by third parties despite our terms forbidding it. A thread has no switch to keep it out of Google the way a directory listing does, and what we say under the directory above about caches applies here just as much: a page that has already been indexed can take weeks to drop out, and copies other people hold are not ours to delete. Please treat the reply box as writing a public web page, because that is what it is, and do not put anything about your employer in it that you would not put on your own website. The box says the same thing directly above the place you type.

Your own replies carry a Delete button, and so does any thread you started yourself; pressing it takes what you wrote off the site at once. Deleting a thread hides the replies other people wrote under it as well, because a reply is only public while its question is. Those replies are not deleted and their authors keep their own Delete buttons over them, but they stop being visible to anyone, and nobody is asked first. The confirmation says so before you press it. There are two cases that button cannot cover, though, and for those what follows is a promise rather than a courtesy: an organiser has already taken the reply down, or you can no longer sign in to the account that posted it. Email privacy@aisat.uk and we will take a reply down. You do not have to give a reason, we will not ask you for one, and it does not matter how old the reply is or what you have decided you no longer like about it. Posting is something you consent to, and a consent you cannot withdraw is not a consent, so this is how you withdraw it. Deleting your account removes your replies outright, as set out under account deletion below.

Every reply also carries a Report button, and pressing it sends the organisers your name, the email address on your account, whatever reason you typed and a copy of the reply as it stood at the time. It lands in the same mailbox the contact form feeds, and it is treated as a Code of Conduct report: what happens next is in the Code of Conduct, and how long we keep it is in the retention table below.

Upvotes are the other way round. We record which reply you voted for, so that the same person cannot vote for the same reply twice, and that record is not public: a thread shows a total, and who voted for what is not shown to other members or to anyone reading the page. Pressing the button again takes your vote back and deletes the record of it.

9. Email we send you

We send three kinds of email, and they are not the same thing.

  • Service email: sign-in links, application decisions, event confirmations and reminders, cancellations, and a single note after you are approved telling you that a listing in the AI Directory is included with your membership and how to add yourself to it. These are part of running your account and your bookings, so you cannot unsubscribe from them without deleting your account or cancelling your booking. The directory note is the one message here that is not a reply to something you did, so to be plain about it: it is sent once, it is never repeated, and it advertises nothing but a part of the membership you already hold.
  • The community newsletter: occasional email about upcoming meetups. This is marketing, it is consent-based, and every message has a one-click unsubscribe link that works without signing in. Members can also switch it on and off at any time from their email preferences, and anyone can email us and we will remove them.
  • Replies to your own messages: if you email us or use a contact form, we will answer. The message, our reply and the rest of that thread are stored in a mailbox on this site, so that a conversation reads as a conversation. Organisers cannot see it. It carries legal correspondence and Code of Conduct reports, so the database refuses that table to every signed-in account without exception, and the only way in is a page that has already established you are the person who runs AISAT.

We do not use tracking pixels to record who has opened a newsletter, and we do not sell, rent or swap our list. When you unsubscribe we keep a record that you did, and the date, so that we do not add you back by accident.

10. Who we share your data with

We use a small number of service providers to run the site. They process data on our instructions, under each provider’s written data processing terms, and none of them is allowed to use it for its own purposes.

The processors and third parties AISAT shares personal data with
WhoWhat they do for usWhat they receive
SupabaseOur database, authentication and file storage. Our project runs in Supabase's London region (AWS eu-west-2), in the UK.Everything stored on the site: account and application data, directory listings, event registrations, uploaded images, the threads you start and the replies you post on AI Threads and the votes you cast on other people's, and the messages you send us through the contact form or by email
VercelHosting and the content delivery network that serves the pages. The application itself runs in Vercel's London regionTechnical and log data such as IP address, request paths and timestamps, plus anything in transit through a page or form
ResendBoth directions of our email: sending sign-in links, event confirmations and the newsletter, and receiving the mail sent to hello@, privacy@ and john@aisat.ukYour email address, your name where the message uses it, the content of the message, delivery outcomes, and, for mail you send us, any attachment (the files stay with Resend rather than being copied into our own storage)
CloudflareThe anti-bot check on the sign-in page, which stops a script asking us to email thousands of sign-in links. Only involved on /loginYour IP address and signals about your browser and device, sent when the page loads the check. It sets nothing on aisat.uk and receives nothing you type
GoogleOptional sign-in with a Google account. Only involved if you choose it.The fact that you signed in, and the email address and account identifier Google returns to us
WhatsApp (Meta)The community group chat. Optional, and separate from your account.Your phone number, WhatsApp display name and photo, and whatever you post (visible to Meta and to all 274+ other people in the group)
Event venuesHosting our in-person meetupsA names-only security or fire list where the building requires one, and anonymised accessibility or dietary needs
Speakers and event sponsorsSpeaking at or paying for a specific eventThe attendee list for that event only (name, company and job title), where you have consented

Two of those deserve a word more. WhatsApp is operated by Meta, and Meta is not our processor: it is an independent controller running its own platform on its own terms. We have no agreement with it about your data, no control over what it does, and no visibility of it. Joining shares your phone number with every other member of the group, more than 274 people, and they can see it whether or not you ever post. The group runs on WhatsApp, which is Meta's: Meta handles your number, your profile and your activity under its own privacy policy, on terms we neither control nor can change on your behalf. You can read WhatsApp’s privacy policy before you decide. Joining is optional, nothing about your membership depends on it, and you can leave at any time. Google only ever sees you if you choose the “Sign in with Google” button; sign in with a magic link instead and Google is not involved.

Those providers use suppliers of their own: Supabase runs on AWS, and Resend and Vercel on infrastructure they do not own. We stay accountable for that chain, we subscribe to each provider’s notifications of changes to it, and you can ask us for the current list at any time at privacy@aisat.uk. We will tell you who is involved and where they are.

We will also disclose personal data if we are legally required to disclose it to a court, a regulator or the police, or where it is necessary to protect someone’s safety. We do not sell your data, and we do not share it with advertisers or data brokers. There are no advertising trackers on this site, and the only measurement we run counts page views without writing anything to your device, reading anything from it, or recognising you on a later visit; see our Cookie Policy.

If AISAT is ever sold or merged

This is a different thing from the paragraph above, and the two are worth keeping apart. “We do not sell your data” means we will never sell, rent or hand your details to another organisation to market to you, or to a data broker to resell. That promise stands whatever else happens.

Separately: AISAT might one day be taken over, merged with another organisation, incorporated into a company, or have its activities transferred to somebody else who will run the community. If that happens, the personal data described in this policy would transfer with it, as part of the organisation rather than as a product being sold. That is normal, and it is not the same as selling a mailing list, but you should know it can happen.

If it does, three things apply. We will tell you before it takes effect, or as soon as we reasonably can, using the email address we hold for you. Whoever takes over will be bound by this policy, or by one that protects you at least as well, until you are told otherwise and given a chance to object. And your rights below do not change: you can still ask for your data, correct it, or have it deleted, from us beforehand or from them afterwards. If you would rather not go with it, tell us and we will delete what we hold before the transfer.

During the negotiations leading up to any such transfer we may need to show the other side that the community is what we say it is. Anything shared at that stage is aggregated or anonymised, in numbers rather than names, under a confidentiality agreement. Personal data itself only moves if a transfer actually completes.

11. AI tools we use

We use AI assistants the way most small organisations now do: to draft and tidy up writing, to summarise notes, and to help prepare briefings before an event. Being told that in a policy is the least you are owed, so here is what it actually means for your data.

  • We use paid business or API tiers, not personal accounts. On those tiers the provider acts as our processor and does not train its models on what we put in. That distinction is the whole point: the same tool on a consumer account would be a different arrangement, and not one we would be willing to describe here.
  • We minimise before anything goes in. Names, roles and public professional information where they are genuinely needed. Not email addresses, not phone numbers, and never anything you have told us about accessibility or diet.
  • No decision about you is made by a machine. Membership applications, moderation and anything touching an introduction or a speaking slot are decided by a person who has read the thing themselves.

The AI portrait studio

One feature works differently from everything above, because it sends a photograph of you rather than a few words about you. On the Meet the Team page, an approved member can upload a square photo and have it redrawn as a cartoon robot in the style of the organisers’ portraits. It is entirely optional, it happens only when you choose to upload something, and it is the one place on this site where an image of your face leaves us.

The photo goes to Google, through the paid Gemini API, and comes straight back as a new image. The paid tier is doing real work in that sentence: on it, Google does not use what we send to train or improve its models, and there is no human review for that purpose. The free tier says the opposite, in terms, and members’ faces are not something we were ever going to put on it. Google keeps what passes through for a limited period for abuse and security monitoring, under its own terms.

We keep nothing. Not the photo you upload, not the picture that comes back, not a copy or a link to one. The result is sent to your browser and is gone when you close the tab, so if you want to keep it you have to save it. The only record we hold is a row saying that your account generated an image and when, which is the least that can enforce the one-a-week limit, and it holds no image and no filename.

Before you upload

We ask you to confirm that the photograph is of you and that you are over 18, and we mean it rather than collecting a tick. A photo of somebody else is their personal data, not yours to send — and a colleague, a friend or a child cannot consent to being redrawn by a company they have never heard of because you thought it would be funny. If it is not your face, please do not upload it.

The lawful basis is your consent, given by choosing to upload. There is nothing to withdraw afterwards because nothing is kept, but you can stop using the feature at any time and it will have left no trace of your face on our side.

Saying it here does not make it lawful on its own, and we do not pretend otherwise: it is lawful because of the terms we are on, and this section is how you get to know about it. If you want the current list of tools and the terms we hold them under, email privacy@aisat.uk.

12. Where we get data about you

Nearly everything we hold came from you, filled into a form on this site. Two things do not, and you are entitled to know about both.

Your LinkedIn profile

Membership requires a LinkedIn URL, and an organiser looks at that page to check you are a real, identifiable person. That is what keeps the WhatsApp group free of spam accounts. We read the page; we do not copy it into our database beyond the URL you gave us.

Briefings before an event

Before a meetup we sometimes prepare a short briefing on who is coming, so organisers can make useful introductions rather than leaving people standing on their own. It is built from public professional sources (typically the LinkedIn profile on your membership and your company’s own website), and it covers name, role, employer and what you appear to work on.

  • We rely on legitimate interests, and the briefing is used for that event only.
  • It is not published, not shared with sponsors, and not kept after the event.
  • You can ask us not to include you, either by replying to your booking confirmation or by emailing privacy@aisat.uk. There is no downside to asking and we do not need a reason.

This section exists because Article 14 of the UK GDPR says that when we compile information about you from somewhere other than you, we have to tell you we are doing it and where it came from. This page is where we do that. It is not repeated in the email confirming your place, so if you have come here from a link in that email, this paragraph is the notice.

13. Sending data outside the UK

Our database is in London. We chose Supabase’s London region (AWS eu-west-2) deliberately, which means the account data, directory listings, event registrations and correspondence that make up almost everything we hold sit in the UK at rest.

The application that reads and writes that database runs in Vercel’s London region too. That is a setting rather than an accident, and it matters: the default is to run wherever the platform feels like running, which for us meant Washington DC, and code executing in the United States is processing the data it handles in the United States however British the database behind it is.

Three providers do their work in the United States, because that is where the service is. Email passes through Resend in both directions, and the anti-bot check on the sign-in page is Cloudflare, which receives your IP address when that page loads. And if you use the AI portrait studio on the Meet the Team page, the photograph you choose is sent to Google to be redrawn. That one only happens when you upload something: nothing is sent to Google by visiting the page, or by being a member. Data handled by those parts of the service may be transferred to or accessed from outside the UK.

One more thing, because “hosted in the UK” is a phrase that is often asked to carry more than it can. Our database and hosting providers are not UK companies, even though the regions we run in are. Choosing London puts the data in London; it does not move the company, so platform logging and remote support can still mean access from outside the UK. The safeguards below are what cover that.

Where that happens, we rely on one or more of the following:

  • Adequacy: for transfers to the EEA, which the UK has found to provide adequate protection;
  • The UK Extension to the EU–US Data Privacy Framework: where the provider is certified under it; or
  • Standard Contractual Clauses with the UK International Data Transfer Addendum: together with a transfer risk assessment, where a provider is not covered by the above.

If you would like to see the safeguards that apply to a particular provider, email privacy@aisat.uk and we will tell you which mechanism we rely on and how to get a copy.

14. How long we keep things

We keep personal data only as long as we have a reason to. These are the actual periods, not a vague promise to review things periodically.

How long AISAT keeps each kind of personal data
WhatHow longThen what
Declined membership applications6 months from the decisionDeleted, apart from a note that an application was declined and when
Applications you started but never submitted12 monthsDeleted
Member account and profileFor as long as you are a memberDeleted 30 days after you ask us to delete it, whether you use the button in your security settings or email us. You can cancel during those 30 days by signing in
Directory listingWhile it is published, plus as long as you keep an unpublished draft of itUnpublishing takes it off the public site straight away and keeps the draft so you can put it back. Ask us to delete it and we will, within 30 days. Asking to delete your account unpublishes it immediately and deletes it, drafts and all, with the account. Search engine caches are outside our control
The photo or logo you upload to a listingWhile your listing uses itDeleted from our file storage when you replace it, remove it, or delete your account, so the public image address stops working
Threads you start and replies you post on AI Threads, and the upvotes you cast on other people'sIndefinitely, while the thread stays up. The archive is meant to be permanent: a question and the answers under it are the page, and removing old replies would leave a thread that no longer reads as oneDeleted 30 days after you ask us to delete your account, by the same nightly job: your replies are deleted outright rather than anonymised, and your upvotes go with the account. A thread you started is deleted outright if nobody answered it; if other people did answer, the question you wrote is erased from it and replaced with a note saying it was removed at your request, and its web address is changed so the old one stops working. That is so your words go while other people's answers are not destroyed along with them. Delete a thread or a reply yourself and it comes off the site at once, or ask us and we will take either down for you. Anything you or an organiser removes stops being shown at once, and the row is kept, hidden from the page, as the record of what it said and who took it down. A removal by an organiser is a moderation record from that point; either way the row runs to the three years in the row below, or goes sooner if you delete your account
Event registrations and attendance records23 months after the event endsDeleted automatically by a nightly scheduled job. If your account is deleted first, the row is kept but anonymised: your name and email address are replaced with a placeholder, your company, job title and notes are cleared, and the cancellation link in your old confirmation email stops working, so that the attendance count for a past event stays right. Aggregate numbers with no names may be kept for planning
Accessibility and dietary notes29 days after the event endsErased automatically by a nightly scheduled job, or when your account is deleted, whichever comes first
The admin log of what organisers did, and to whomIndefinitely: it is the evidence that a decision was made, by whom and whenWhen your account is deleted, any free-text note an organiser wrote about you is cleared, leaving the bare action and its date. An audit trail the person it concerns can erase is not an audit trail
Newsletter subscriptionUntil you unsubscribeYour address moves to a suppression list, kept so that we never email you again by mistake. That record survives deleting your account, for the same reason: without it, a stale spreadsheet import could quietly re-subscribe someone who asked to be gone
Email delivery logs at our email providerUp to 30 daysDeleted automatically by the provider
Server, security and error logsTypically up to 30 daysRotated and deleted automatically
Contact-form messages and email you send to hello@, privacy@ or john@aisat.ukWhile the matter is open. Once a thread is archived it is deleted automatically 24 months after its last messageDeleted, including the attachment records. Deleting your account does not delete these: a thread runs to the same period either way. We keep correspondence longer where it concerns a Code of Conduct report or a legal claim, under the rows below
Code of Conduct reports and moderation records3 years, or longer where there is a safeguarding reasonDeleted, or kept in a minimal form where a repeat risk exists. A report is not deleted because the person it is about deletes their account: it belongs to whoever wrote it, and it is our evidence that we handled it
Records of consent and of accepting these policiesWith the thing they are consent forYour acceptance of these policies is part of your profile and is deleted with it, 30 days after you ask. A log of event consent changes is kept with the registration and deleted with it, 23 months after the event. The exception is the record that you unsubscribed from the newsletter, which we keep so that nobody can put you back on the list by accident
Database backupsRolling, overwritten within 30 daysDeleted data disappears from backups as they roll over

What happens when you delete your account

There is a delete button in your security settings. You type delete my account to confirm, and the deletion is then scheduled for 30 days later rather than done on the spot, so that one mistaken press cannot destroy a listing you spent an hour writing. We email you the date. Sign in before it and a banner offers you a button that cancels the whole thing.

One thing does not wait for the 30 days: your directory listing is unpublished the moment you ask, so the public site stops showing you within the minute. Cancelling brings the account back but not the listing, because publishing it again is your own switch and sits where it always has. And we would rather be straight about what a grace period costs than pretend it away: your data genuinely still exists for those 30 days, which is the price of being able to change your mind.

On the night itself a scheduled job works through what we hold about you in three ways, and the third is the one worth reading.

  • Deleted: your sign-in account, your profile, your directory listing and everything filed under it (company or individual details, case studies, portfolio links and tags), the photo or logo you uploaded, and any organiser permissions you held. Your replies on AI Threads go with them, and so do the upvotes you cast. The replies are deleted rather than anonymised, deliberately: an answer describing one project at one named employer is not anonymous with the name taken off it, and somebody who has asked to be gone should be gone. They are removed before the account itself, so that no reply is ever left standing on a public page with the author quietly detached from it. A thread you started goes the same way if nobody answered it. If other people did answer, we keep the page and destroy the question in it: your words are replaced with a note saying the question was removed at its author’s request, and the web address changes so the old one no longer works. That is the one place we stop short of deleting the row, and it is not for our benefit: deleting it would take every answer other members wrote with it, without asking any of them.
  • Anonymised rather than deleted: your event registrations. Your name and email address are replaced with a placeholder, your company, job title and any accessibility or dietary notes are cleared, and the cancellation link in your old confirmation email stops working. The row itself stays, because how many people came to a meetup is a fact about the meetup, and deleting the row would quietly rewrite it months afterwards. The admin log of organiser actions is treated the same way: anything an organiser typed about you is cleared, and the record that an action happened, and when, is kept.
  • Kept, deliberately: two things, which we would rather name here than let you discover later. The first is your newsletter suppression record: the row stays, marked unsubscribed, because deleting it would let a stale spreadsheet import quietly re-subscribe someone who had asked to be gone. The second is correspondence, and any Code of Conduct report about you. Email you sent us runs to its own period in the table above, and a report is not yours to erase: it belongs to the person who wrote it, and it is our evidence that we dealt with it.

That is why we say we delete everything we can lawfully delete, rather than that we delete all your data. The second would not be true, and you should be able to predict from this page exactly what survives and why.

Emailing privacy@aisat.uk still works if you would rather we did it for you; we schedule the same deletion rather than doing a hand-made version of it. The one account this does not cover is the owner’s, which cannot be deleted from the site at all, because doing so would leave the community with nobody able to get back in.

15. How we protect your data

We are a volunteer community, not a bank, but we take some care with this.

  • Row-level security is enabled on every table in our database, so a signed-in member can only read and write the rows they are entitled to. The key that bypasses those rules never leaves the server.
  • Encryption in transit (HTTPS/TLS across the whole site) and at rest (our database and file storage are encrypted by the provider).
  • No passwords: we use magic links and Google sign-in, so there is no password of yours for us to leak.
  • Limited access: only AISAT organisers can see member and attendee data, only where they need it to run the community, and admin actions are logged.
  • Sensible defaults: separate credentials per environment, secrets kept out of the codebase, and dependencies kept current.

No system is perfectly secure. If there is a personal data breach that is likely to result in a risk to your rights and freedoms, we will report it to the Information Commissioner within 72 hours of becoming aware of it, and tell you directly where the risk is high. If you think you have found a security problem with the site, please email privacy@aisat.uk rather than posting it publicly, and we will thank you properly.

16. Your rights

Under UK GDPR you have the following rights. They are not absolute (some depend on the lawful basis we are relying on), but if one does not apply we will tell you why.

  • The right to be informed about how your data is used. That is what this policy is for.
  • The right of access: a copy of the personal data we hold about you, and an explanation of how we use it.
  • The right to rectification: to have inaccurate data corrected and incomplete data completed. Most of it you can edit yourself in your dashboard.
  • The right to erasure: to have your data deleted where we no longer need it, where you withdraw consent, or where you have successfully objected. For your whole account you do not have to ask anybody: there is a delete button in your security settings, and what it removes, anonymises and keeps is set out above. Email us instead if you prefer, or for anything narrower than the whole account. We may keep the minimum needed to honour an unsubscribe or to deal with a legal claim.
  • The right to restrict processing: to have us pause using your data, for example while we check whether it is accurate.
  • The right to data portability: to receive the data you gave us, in a structured, machine-readable format, where we rely on consent or contract and process it automatically.
  • The right to object: to processing based on legitimate interests, and an absolute right to object to direct marketing, which we will always act on immediately.
  • Rights relating to automated decision-making and profiling: you have the right not to be subject to solely automated decisions with legal or similarly significant effects. We do not make any, so this right should never need to be used here.

You can also withdraw consent at any time where consent is the basis we rely on: unsubscribe, unpublish your listing, or ask to come off an attendee list.

How to exercise a right

Email privacy@aisat.uk and say what you want. There is no charge. We will respond within one month; if a request is complex or you have made several, we may extend that by up to two further months, and we will tell you within the first month if we need to. We may ask you to confirm your identity (usually just by replying from the address we hold) so that we do not hand your data to someone else.

17. Complaining, to us or to the ICO

Complaining to us

If you are unhappy with how we have handled your personal data, please tell us at privacy@aisat.uk. Say what happened and what you would like us to do about it; you do not need to cite any law, and you do not need to use the word “complaint” for us to treat it as one.

  • We will acknowledge it within 30 days, and in practice within a few days.
  • We will then look into it and tell you the outcome, or tell you why it is taking longer and when to expect an answer.
  • We keep a log of complaints and what we did about them, which is how a pattern gets noticed rather than repeated.

Most things turn out to be a misunderstanding we can fix quickly, and complaining to us does not affect your membership in any way.

Complaining to the ICO

You also have the right to complain to the UK’s data protection regulator, the Information Commissioner’s Office, and you do not have to come to us first.

  • Website: ico.org.uk
  • Helpline: 0303 123 1113
  • Post: Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF

18. Cookies

This site uses a small number of strictly necessary cookies and no advertising or analytics cookies at all, which is why you have not been shown a cookie banner. We do count page views, using a tool that identifies a visit by a code worked out on the server and discarded after 24 hours; because it writes nothing to your device and reads nothing from it, it does not change that answer. One of them is set for every visitor: the cookie that remembers your browser has entered the shared password standing in front of the site before launch. The rest are set when you sign in. Each one is named, with what it does and how long it lasts, in our Cookie Policy.

19. Children

AISAT is aimed at working professionals. The site and our events are for people aged 18 and over, and we do not knowingly collect personal data about children. If you believe a child has given us their data, email privacy@aisat.uk and we will delete it.

20. Changes to this policy

We will update this policy when what we do changes: a new provider, a new feature, a different retention period. The date at the top always shows the current version.

If a change materially affects you, we will tell members by email or with a notice on the site before it takes effect. Where a change means we need your consent, we will ask for it rather than assume it. Older versions are available on request.

A note on this policy

This policy was written to reflect what the site actually does, and it has not been reviewed by a solicitor or a data protection specialist. If you are relying on it (as a member, a sponsor or a partner) and something matters to your own compliance position, please take your own advice and ask us any questions you need to.