Ayu Digital

Privacy Policy

Last updated: 21 September 2026

Your data is yours. This policy explains what personal data we handle when you use the Ayu Digital website or our Android and iOS apps, why we handle it, how we keep it secure, and the choices you have. We aim to write it in plain English.

1. Who we are

Ayu Digital is a UK-based AI, automation and bespoke software consultancy. In this policy, “we”, “us” and “our” mean Ayu Digital. You can reach us at info@ayudigital.co.uk.

2. What this policy covers

This policy applies to our website (https://ayudigital.co.uk) and to the mobile apps we publish on the Google Play Store and Apple App Store, including apps we build and operate for our customers.

What an individual app collects depends on what it does. The app store listing for each app describes the categories of data it uses, and this policy explains how we treat that data.

3. Our role: controller and processor

Where we decide why and how your personal data is used — for example when you email us or use our own apps — we are the “controller” of that data.

Where we build or run an app on behalf of a customer (for example, your employer or another organisation that provides you with the app), the customer decides why and how the data is used and we act as their “processor”. In that case we only use the data on the customer’s documented instructions, and the customer’s own privacy notice will also apply. Requests about that data are best directed to the customer, though we will help them respond.

4. The information we collect

Depending on how you use our website and apps, this may include:

  • Information you give us — such as your name, email address, account details, and anything you write to us or enter into an app.
  • Information from your organisation — if an app is provided to you by a customer, they may give us details such as your name, work email address and role so that you can use it.
  • Technical information collected automatically — such as device type, operating system version, app version, language settings, and crash and performance diagnostics.
  • Usage information — how features of an app are used, so we can keep it working and improve it.

We only ask for device permissions (such as notifications, camera or location) when a feature needs them, and you can withdraw a permission at any time in your device settings. We do not collect more than we need to provide the service.

5. How we use your information

  • To provide, operate and support our apps and website.
  • To respond to your enquiries and requests.
  • To keep our services secure, prevent misuse and fix faults.
  • To understand how our apps are used so we can improve their reliability and usability.
  • To meet our legal and contractual obligations, including those we owe to our customers.

We do not sell your personal data, and we do not use it for third-party advertising.

We do not use personal data that we process on behalf of a customer to train AI models unless that customer has instructed us to do so. Where an app uses AI features, we design it so that personal data is used only for what the feature needs.

6. Our legal bases for using personal data

Under UK data protection law (the UK GDPR and the Data Protection Act 2018) we must have a lawful basis for using personal data. Depending on the context, we rely on:

  • Contract — where we need your data to provide an app or service you have asked for.
  • Legitimate interests — for example keeping our services secure and improving them, balanced against your rights and interests.
  • Legal obligation — where the law requires us to keep or disclose information.
  • Consent — where we ask for it, such as for certain device permissions. You can withdraw consent at any time.

7. Who we share information with

We share personal data only where it is necessary, and never in exchange for payment. Recipients may include:

  • Our customers, where we operate an app on their behalf.
  • Carefully chosen service providers that help us run our services, such as hosting, cloud infrastructure and diagnostics. They may only use the data to provide their service to us, and are bound by contract to protect it.
  • Professional advisers, regulators, law enforcement or courts where we are required to do so by law.
  • A successor organisation, if our business is ever restructured or sold, subject to the protections in this policy.

8. International transfers

Some of our service providers may process data outside the UK. Where they do, we make sure an appropriate safeguard is in place — such as a UK adequacy decision or the UK International Data Transfer Agreement or Addendum — so that your data continues to receive an equivalent level of protection.

9. How we keep your data secure

We take the security of personal data seriously and apply appropriate technical and organisational measures to protect it against loss, misuse and unauthorised access, including:

  • Encryption of data in transit.
  • Access controls that limit who can see personal data to those who need it to do their job.
  • Choosing suppliers who meet recognised security standards.
  • Collecting only the data we need, and deleting it when it is no longer needed.

No system is perfectly secure, but if a personal data breach occurs that puts your rights at risk, we will act promptly to contain it and will notify the people and regulators affected as the law requires.

10. How long we keep your data

We keep personal data only for as long as we need it for the purposes above. For data we process on behalf of a customer, retention is set by that customer’s instructions, and we delete or return the data when our engagement ends. Where the law requires us to keep records for longer, we keep them only for that period.

11. Your rights

You have the right to:

  • Be told how your data is used, and to ask for a copy of it.
  • Have inaccurate data corrected.
  • Have your data deleted, in certain circumstances.
  • Restrict or object to certain uses of your data.
  • Receive your data in a portable format, where that applies.
  • Withdraw consent at any time, where we rely on it.

To exercise any of these rights, or to ask us to delete your account and associated data, email info@ayudigital.co.uk. We will respond within one month. If an app is provided to you by an organisation, we may need to refer your request to them.

If you are unhappy with how we have handled your data, you can complain to the UK Information Commissioner’s Office at ico.org.uk. We would appreciate the chance to put things right first.

12. Children

Our website and apps are not intended for children under 13, and we do not knowingly collect personal data from them. If you believe a child has given us personal data, please contact us and we will delete it.

13. Third-party links and app stores

Our website and apps may link to other sites and services. We are not responsible for their privacy practices. When you download our apps, Apple and Google process your data under their own privacy policies.

14. Changes to this policy

We may update this policy from time to time. The date at the top of the page shows when it was last changed. If we make a significant change, we will take reasonable steps to let you know, for example by updating the app or notifying you in it.

Questions about this page?

We're happy to help. Email us at info@ayudigital.co.uk and a real person will reply.