1. Who we are (the controller)
The data controller for My AI Expert Witness (at myaiexpertwitness.info) for the purposes of UK GDPR is Trance Limited — an overseas entity registered with Companies House under the Economic Crime (Transparency and Enforcement) Act 2022 (registration OE025742) and registered with the UK Information Commissioner’s Office (ICO registration C1894395). Trance Limited is incorporated in the Turks and Caicos Islands and its registered address is published on the public Register of Overseas Entities at Companies House. For any privacy enquiry or data-subject request, please use our contact form; you can also contact the ICO at ico.org.uk or 0303 123 1113.
2. What we collect
- Contact data: any name, email address and optional phone number you give us
- Enquiry data: the questions, interests or enquiries you submit, and our correspondence with you
- Technical data: IP address, browser, timestamps and minimal logs needed to operate the platform securely
Please do not send us special category data (such as health or political information) or sensitive financial account details — we do not need them to provide information to you.
3. Lawful basis (UK GDPR Article 6)
- Legitimate interests — to operate the platform, respond to enquiries, keep the service secure and improve it (we never use your data to train AI models)
- Legal obligation — record-keeping and regulatory compliance
- Consent — for any optional updates you ask to receive, withdrawable at any time
4. Who we share data with
- Anthropic — AI processing where an AI feature is used (data sent for inference, not retained for training under their commercial API terms)
- Resend — transactional email delivery
- Hetzner — server hosting (UK / EU data residency)
We do not sell or rent your data and we do not share it with advertising networks.
5. Where your data is stored
Your data is stored on servers in the United Kingdom / European Economic Area. Some providers (for example Anthropic for AI inference) may process data outside the UK under appropriate safeguards, including the UK International Data Transfer Addendum.
6. How long we keep it
- Contact and enquiry data: while relevant to your relationship with us, then deleted within a reasonable period unless we must keep it longer by law
- Backups: rolling local plus offsite copies
7. Your rights
Under UK GDPR you have the right to access, correct, erase, restrict or port your data, to object to processing, and to withdraw consent. Use our contact form to exercise any right; we aim to respond within 30 days. If you are unhappy with how we handle your data you can complain to the Information Commissioner’s Office at ico.org.uk or 0303 123 1113.
8. Cookies
See our Cookies Policy.
9. Security
We use TLS encryption for all traffic, encrypted backups, hashed passwords where accounts exist, least-privilege access controls and offsite backups. No system is perfectly secure; if we suffer a notifiable breach we will notify the ICO and affected users without undue delay.
10. Children
The platform is intended for adults aged 18 or over. We do not knowingly collect data from children.