Privacy Policy.
How we collect, use, and protect personal data.
Introduction
This Privacy Policy explains how we collect, use, store, and protect your personal data when you use our website and services.
We operate in accordance with the UK GDPR, the Data Protection Act 2018, and the Data (Use and Access) Act 2025.
Who we are
The data controller is:
- Perkins SmartOps Ltd, a company registered in England and Wales
- Company number: 16995399
- Registered office (mail only): 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ. We work from Northamptonshire.
- Email: [email protected]
- Information Commissioner's Office registration: ZC087054
We have not appointed a data protection officer. We are not required to, and David Perkins is responsible for data protection here. Write to the address above and it reaches him.
What data we collect
We may collect the following types of personal data:
- Contact information you provide: name, email address, phone number, company name
- Communication data: the content of emails and messages you send us
- Technical data: IP address, browser type, device information, pages visited (collected via privacy-respecting analytics)
- Service data: information about your business processes shared during discovery calls and project work
Business contacts and prospect data
As part of business-to-business marketing, we may hold contact details for people at organisations we believe could benefit from our services. This is limited to business contact information: name, job role, firm, business email address, and business telephone number. We collect it either directly from you or from public sources such as company websites, public business directories, and professional networks.
Our lawful basis for this is legitimate interests, namely contacting organisations about relevant business services. We have carried out and recorded a legitimate interests assessment for this, and you can ask us for a summary of it.
Where we contact an organisation by email, we email limited companies, limited liability partnerships and other corporate subscribers only. We do not send marketing email to sole traders or to ordinary partnerships, and we confirm the legal form of every organisation at Companies House before we write. Every email we send says who we are and carries a line inviting you to tell us not to email again.
We do not make marketing telephone calls. We stopped in July 2026. We still hold business telephone numbers in the prospect records described above, on the same basis and for the same periods as the rest of that data, and if we ever start calling again we will screen every number against the Telephone Preference Service and Corporate Telephone Preference Service registers first.
We keep prospect contact details for 12 months from the date we researched them if we never make contact, and for two years from the last contact once a conversation has started. You can object to this processing, ask us to stop contacting you, and ask us to erase the details we hold about you, at any time by emailing [email protected]. We will action any such request promptly, and we keep a note of the request so that you are not contacted again by mistake.
How we use your data
We use your personal data for the following purposes:
- To respond to your enquiries and provide our services
- To send you information you have requested about our services
- To improve our website and services
- To comply with legal obligations
We will never sell your data to third parties. We will never use your data for purposes other than those stated above without your consent.
Legal basis for processing
Under UK GDPR, we process your data on the following legal bases:
- Legitimate interests: replying to an enquiry you send us, contacting organisations about services that are relevant to them, keeping the website and our systems secure, and keeping our own business records. Where we rely on legitimate interests for prospect contact details we have written the assessment down, and you can ask us for a summary of it.
- Steps taken before entering a contract: quoting, scoping, and preparing a proposal at your request.
- Contractual necessity: delivering the work you have engaged us for.
- Legal obligation: tax, accounting and company records we are required to keep.
We do not currently rely on consent for anything, so there is no consent for you to withdraw. Answering your enquiry is a legitimate interest, not something you have consented to, and calling it consent would give you a right that does not match what is actually happening. If we ever do rely on consent, we will ask for it plainly, record it, and let you withdraw it at any time.
You can object to any processing we do on the basis of legitimate interests. Email us and we will stop, unless we have compelling grounds that override your rights, in which case we will tell you what they are.
Data storage and security
Our own servers are in the United Kingdom: the website is hosted in a UK data centre, and the automation servers we run are London-region machines. Some of the services we use to run the business are provided from outside the United Kingdom, and the section on international transfers below says which and why.
We implement appropriate technical and organisational measures to protect your data, including encryption, access controls, and regular security reviews.
How long we keep it
We keep personal data for the periods set out in our records retention policy. The ones most likely to apply to you:
- Enquiries that do not become work: 6 months from the last contact.
- Prospect contact details: 12 months from the date we researched them if we never make contact, and 2 years from the last contact once a conversation starts.
- Engagement letters, statements of work, data processing agreements and non-disclosure agreements: 6 years from the end of the engagement, which is the limitation period for a contract claim.
- Invoices and tax records: 7 years.
- Meeting notes, discovery recordings and draft reports: 2 years from the end of the engagement.
- Working copies of your business data held during a project: the life of the engagement, plus up to 30 days after it ends.
- Server and workflow logs: 90 days, on a rolling basis.
Where a period above has passed and we are not required by law to keep something, we delete it. Ask us at any time what we hold about you and we will tell you.
Your rights
Under UK GDPR, you have the right to:
- Access the personal data we hold about you
- Rectify inaccurate personal data
- Erase your personal data (the "right to be forgotten")
- Restrict processing of your personal data
- Data portability: receive your data in a structured, machine-readable format
- Object to processing based on legitimate interests
- Withdraw consent at any time where processing is based on consent
To exercise any of these rights, contact us at [email protected].
Automated decision-making
We do not make decisions about you by purely automated means that produce legal or similarly significant effects. Our automation services are designed with human oversight: where an automated workflow informs a decision, a person reviews it. If that ever changed, you would have the right to be told, to ask for a person to review the decision, to put your point of view, and to contest the outcome.
Analytics
We use Umami, a privacy-respecting analytics tool that is self-hosted on our own infrastructure. Umami does not use cookies, does not collect personal data, and does not track users across websites. It complies with GDPR, CCPA, and PECR without requiring cookie consent.
Third-party services
These are the providers that can come into contact with personal data we hold. We do not share your personal data with any of them beyond what running the business requires, and we do not sell it to anybody.
Software we run ourselves
The following are open-source tools installed on our own servers. No third-party company receives the data that passes through them.
- n8n: the workflow automation platform our builds run on
- Umami: website analytics, cookieless and anonymous
- Documenso: electronic signature, at sign.perkins-smartops.com
Infrastructure
- Mythic Beasts: hosting for this website and for the servers our automation platform runs on. UK company, UK data centre.
- Cloudflare: domain name service and content delivery for this website. A United States company operating a global network.
Services we use to run the business
- Anthropic: the Claude AI models we use to draft, analyse and build. A United States company.
- OpenRouter: a gateway we use in our own systems and while testing, so we can compare models without rebuilding. A United States business.
- Google: Workspace, which is our email, calendar and file storage. A United States company.
- Cal.com: the booking page you use to put a call in the diary. A United States company.
- Xero: accounting and invoicing. A New Zealand company whose platform is hosted in the United States.
What we send to an AI model, and what we do not
We are an AI and automation company, so it is fair to ask what reaches an AI model. We use Anthropic's Claude to draft documents, analyse processes, write code and prepare reports, so some material about your business is processed by Claude in the course of the work. In practice that is the working material of the job: notes from a discovery session, a description of how one of your processes runs, the steps in a task we are automating, a draft of a report.
Automations we build for you are different. Where a build has an AI step in it, that step runs on your own account with the model provider, in your name and under your contract with them, not ours. We use OpenRouter in our own systems and while testing models, and it does not sit in the path of anything we build for you.
Not everything, and nothing automatically. A person decides what goes, task by task, and a good deal never goes at all. We send only what the task needs and strip out personal details that add nothing to it. Something told to us in confidence stays between us, and parts of a job are simply done by hand instead. We also do not put your customers' or clients' personal data into an AI model: our engagement terms keep us away from end-customer personal data in the first place.
None of it is used to train a model, and it is worth being precise about how that is secured, because it is not the same promise in both places. Where we call Claude through Anthropic's programming interface, it is a term of the commercial contract: Anthropic may not train on what we send. Where the work runs on our Claude subscription, which is most of it, training is off by default and it is a setting we keep switched off rather than a clause anyone has signed. We say that plainly rather than describe both as the same guarantee.
If you would rather your material was not processed by an AI model at all, tell us before the work starts and we will tell you honestly what we can and cannot do without one.
International transfers
Some of the providers above are outside the United Kingdom, so some personal data leaves it. Where that happens, the transfer relies on the safeguards in that provider's own data processing terms.
For Anthropic, Google, Cloudflare and Xero, that safeguard is the International Data Transfer Addendum issued by the Information Commissioner under section 119A of the Data Protection Act 2018, applied to the European Commission's standard contractual clauses. We checked each of them on 11 August 2026. Ask us and we will send you a copy.
OpenRouter names the European Commission's standard contractual clauses in its privacy policy but not the addendum. Nothing of yours goes there unless you are a supplier or we are testing, because client builds run on your own account with the model provider.
Cal.com holds the name, email address and message of anyone who books a call with us, and its own privacy notice covers how it handles and transfers that. If you would rather not use the booking page, email us instead and nothing goes to Cal.com.
Complaints
If you are unhappy with how we have handled your personal data, contact us at [email protected]. We follow a written complaints procedure: we acknowledge your complaint, look into it without undue delay, tell you the outcome, and keep a record of it and how we resolved it.
You can also complain to the Information Commissioner's Office at any time. You do not have to come to us first, and going to them does not affect anything else you are entitled to.
Changes to this policy
We may update this Privacy Policy from time to time. Any changes will be posted on this page with an updated revision date.
Contact us
If you have questions about this Privacy Policy or wish to exercise your data rights, contact us at:
Perkins SmartOps Ltd
71-75 Shelton Street, Covent Garden, London, WC2H 9JQ
Email: [email protected]
Our Terms of Use, Cookie Policy and Disclaimer apply alongside this policy.