The short version
We collect almost nothing. This website has no analytics, no advertising cookies and no third-party trackers. If you send an enquiry we keep your details in order to reply to you — nothing else. We don't sell data and we don't add anyone to a mailing list.
Who we are
Brookes AI is the trading name of [Registered company name] Ltd, a company registered in England and Wales under company number [00000000], with its registered office at [Registered office address].
For the purposes of UK GDPR and the Data Protection Act 2018 we are the data controller for the personal data described in this notice. You can contact us about anything on this page at hello@brookesai.com.
Where we deliver services to a client, we usually act as a data processor for personal data held in that client's own systems. That relationship is governed by a separate data processing agreement, not by this notice — see Client data during an engagement below.
Reading this website
You can read every page here without telling us anything. There is no signup wall, no analytics script and no advertising or tracking cookie on any page.
The site is served by Cloudflare Pages, which keeps basic server logs (including IP addresses) for security, abuse prevention and network operation. Those logs are Cloudflare's, held under their own terms, and we do not receive or analyse them.
Cookies
We set no cookies of our own. Cloudflare may set strictly necessary cookies for security and bot mitigation. Because we run no analytics, advertising or profiling cookies, no consent banner is required under the Privacy and Electronic Communications Regulations.
If you send an enquiry
The enquiry form on our homepage collects your name, company name, work email address, an optional phone number, your company size, your area of interest, and whatever you write in the message box.
When you submit it, that information is transmitted to a serverless function running on Cloudflare and emailed to us via Resend, our email delivery provider. Your IP address and country are recorded alongside the message as an anti-abuse measure.
Why we're allowed to hold it
Our lawful basis is legitimate interests — you have approached us about our services and reasonably expect a reply. Where an enquiry becomes an engagement, the basis for continuing to hold contact details becomes performance of a contract.
How long we keep it
- Enquiries that don't proceed: deleted within 24 months.
- Enquiries that become clients: retained for the duration of the engagement and for six years afterwards, as required for tax and accounting purposes.
- Anything you ask us to delete: removed on request, unless we are legally required to keep it.
Client data during an engagement
Delivering an automation project usually means we are given access to systems that contain personal data belonging to our client — their customers, their staff, their suppliers. In that situation:
- Our client is the data controller; we act as their processor.
- A written data processing agreement is signed before we are given any access.
- We request the narrowest access that allows the work to be done, and it is revoked on completion.
- We do not use client data for any purpose other than delivering the agreed work.
- We do not use client data to train AI models, and we use provider tiers where inputs and outputs are contractually excluded from model training.
- We identify every sub-processor involved in a workflow before it goes live, so our client can approve it.
Who else sees your information
We use a small number of service providers. In connection with this website and our enquiry handling, they are:
- Cloudflare — website hosting, DNS and the enquiry endpoint.
- Resend — delivery of enquiry emails to us.
- [Your email provider] — our business email, where enquiries are received and stored.
Beyond those, nobody. We do not sell personal data, we do not share it with advertisers, and we run no retargeting of any kind.
International transfers
Some of the providers above operate infrastructure outside the UK. Where personal data is transferred internationally it is done under a UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or an adequacy decision. We'll tell you which mechanism applies to a specific provider if you ask.
Your rights
Under UK GDPR you have the right to:
- ask what personal data we hold about you, and get a copy of it;
- have inaccurate data corrected;
- have data erased, where we have no overriding reason to keep it;
- restrict or object to our processing;
- receive data you gave us in a portable format;
- withdraw consent at any time, where consent was the basis for processing.
Email hello@brookesai.com and we'll respond within one calendar month — realistically within a couple of working days, because there won't be much to look through. There is no charge.
If you think we've handled your data badly and we haven't put it right, you can complain to the Information Commissioner's Office at ico.org.uk or on 0303 123 1113.
Security
We use multi-factor authentication on all business accounts, encrypted storage and transport throughout, and least-privilege access to any client system. No system is perfectly secure, but if a breach affecting your personal data occurs we will notify you and, where required, the ICO within 72 hours.
Children
Our services are sold business to business. We do not knowingly collect personal data relating to anyone under 18 through this website.
Changes to this notice
If this notice changes in a way that materially affects you, we'll update the date below and, where the change is significant and we hold your contact details, tell you directly. We won't quietly broaden what we do with your data.
A note on this page
Written in plain English deliberately, and it reflects what actually happens. It isn't legal advice. If you're relying on it for something important, take your own.
Last updated: August 2026