1. Who We Are

adBrain Limited (“adBrain”, “we”, “us”, or “our”) is a company registered in the United Kingdom. Our registered office address is 5 Brayford Square, London, E1 0SG, United Kingdom. Full registered details are on our Legal & Company Information page.

We are the data controller for personal data collected through our website (adbrain.uk) and in the course of our sales, marketing, and support activities. Where we process personal data contained within customer enterprise data on behalf of our clients, we act as a data processor under a separate Data Processing Agreement. That processing is governed by those agreements and is not the subject of this notice.

This Privacy Policy explains how we collect, use, store, and share your personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. It applies to website visitors, prospective customers, and contacts at existing client organisations.

Our privacy contact is: [email protected].

2. Personal Data We Collect

Website visitors

  • IP address and approximate location derived from it
  • Browser type, device type, and operating system
  • Pages visited, time on page, and referring URL
  • Cookie identifiers (see Section 9)

Enquiries and marketing contacts

  • Name, job title, and company name
  • Business email address and telephone number
  • The content of any message you send us
  • Information you share during sales calls or demonstrations

Customer account contacts

  • Name, job title, and contact details of individuals at client organisations
  • Billing and invoicing details
  • Records of support requests and communications
  • Platform usage logs and audit trails associated with named accounts

We collect this data directly from you, automatically when you visit our website, and occasionally from publicly available sources such as LinkedIn or company websites in the course of business development.

We only process personal data where we have a lawful basis under Article 6 of the UK GDPR.

PurposeLegal Basis
Responding to your enquiries and providing our servicesContract / Pre-contractual steps
Managing your account, billing, and supportContract / Legal obligation
Sending service communications (updates, security notices)Contract / Legitimate interests
Sending marketing communications to existing business contactsLegitimate interests (B2B soft opt-in, PECR)
Sending marketing communications to new prospectsConsent (where required) or Legitimate interests
Website analytics and performance improvementLegitimate interests
Security monitoring and fraud preventionLegitimate interests
Compliance with legal obligations (tax, audit, court orders)Legal obligation

Where we rely on legitimate interests, we have carried out a balancing test and are satisfied our interests do not override your rights. You may request details of that assessment. Where we rely on consent, you may withdraw it at any time; withdrawal does not affect processing carried out before withdrawal.

4. How Long We Keep Your Data

  • Contract and account data: Duration of the contract, plus 6 years after termination (Limitation Act 1980).
  • Financial and invoicing records: 6 years (HMRC requirement).
  • Marketing and prospect data: Until you opt out, or 2 years from last meaningful contact.
  • Security and access logs: 12 months.
  • Website analytics data: 14 months.
  • Customer Data processed as a processor: Deleted or returned within 30 days of contract termination, per the relevant Data Processing Agreement.

5. Who We Share Your Data With

We do not sell your personal data. We may share it, only to the extent necessary, with:

  • Cloud infrastructure providers (e.g. Cloudflare for our website; Azure, AWS, or Google Cloud, or the client’s own environment, for platform deployments), bound by data processing agreements.
  • AI model providers, where a system we have built and deployed for a client uses third-party model APIs to deliver the service, disclosed in the client Data Processing Agreement, and contractually barred from using customer data for model training without explicit written consent.
  • CRM and marketing platforms, to manage our business contacts.
  • Professional advisors (legal, accounting, insurance), under confidentiality.
  • Regulatory authorities and law enforcement, where required by law or valid court order.
  • Business purchasers, in a merger, acquisition, or sale, subject to equivalent protections.

6. International Data Transfers

Your data is primarily processed within the United Kingdom and the European Economic Area (EEA). The UK recognises EEA countries as adequate, and the European Commission’s adequacy decisions for the UK were renewed in December 2025, so transfers in both directions are permitted without additional safeguards. Where we use providers outside the UK and EEA, we rely on an ICO-approved International Data Transfer Agreement (IDTA), the UK Addendum to EU Standard Contractual Clauses, or the UK-US Data Bridge, as applicable.

7. Your Rights

Under the UK GDPR you have the rights to be informed; of access; to rectification; to erasure; to restriction; to data portability; to object (including an absolute right to object to direct marketing); and rights related to automated decision-making. We do not make decisions producing legal or similarly significant effects about you solely by automated means without human review.

To exercise any right, contact [email protected]. There is no charge, and we respond within one calendar month. We will verify your identity first.

8. Your Right to Complain to the ICO

Please contact us first at [email protected]. You may also complain to the Information Commissioner’s Office (ICO):

  • Website: www.ico.org.uk
  • Address: Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
  • Helpline: 0303 123 1113

9. Cookies

Our website uses cookies. First-party analytics cookies used solely for statistical purposes may be set without prior consent under the Data (Use and Access) Act 2025, provided a free opt-out is offered; we offer that opt-out and do not use advertising or cross-site tracking cookies. Full details, categories, and controls are set out in our dedicated Cookie Policy.

10. How We Keep Your Data Secure

We implement appropriate technical and organisational measures: encryption in transit (TLS) and at rest, strict access controls, regular security reviews, and personnel training. In the event of a personal data breach likely to risk your rights and freedoms, we will notify the ICO within 72 hours and inform affected individuals without undue delay where the risk is high.

11. Changes to This Policy

We may update this policy to reflect changes in our practices or the law. The revised version is published here with an updated effective date; for material changes we give at least 30 days’ notice.

12. Contact Us

  • Email: [email protected]
  • Post: adBrain Limited, 5 Brayford Square, London, E1 0SG, United Kingdom