Privacy Policy
This policy explains what personal data Iontek collects when you use iontek.io or work with us, why we collect it, and the choices you have. We keep it in plain English because that is how we prefer to work.
Effective date: July 3, 2026 · Last updated: July 3, 2026
01Who we are
Iontek (Iontek.io) builds custom AI applications, autonomous agents, automations, and AI readiness audits for businesses. In this policy, "Iontek", "we", "us", and "our" refer to that entity. "You" means anyone visiting iontek.io, contacting us, or working with us.
For the personal data described in this policy, Iontek acts as the data controller. Where we process data inside a client's systems as part of a project, we typically act as a data processor on that client's behalf (see section 11).
02Data we collect
Data you give us directly
- Contact and enquiry details. When you fill in our contact form or book a consultation, we collect your name, email address, company name, approximate project budget, and anything you write in your message.
- Communication history. Emails, call notes, and meeting records from our conversations with you.
- Billing details. If you become a client: business address, tax or registration numbers, and payment references. We do not store full card numbers; payments are handled by our payment providers.
Data collected automatically
- Usage data. Pages visited, approximate location (country or city level), device and browser type, and how you found us, collected through the analytics tools described in section 10.
- Technical logs. IP addresses and request logs kept by our hosting provider for security and reliability.
We do not intentionally collect special category data (such as health, religious, or biometric data) through this website, and we ask that you do not include it in enquiry messages.
03How we use your data
- To respond to enquiries and consultation requests.
- To scope, propose, deliver, and support the services you ask us for.
- To send invoices, collect payment, and keep the records we are legally required to keep.
- To improve our website and understand which content is useful.
- To protect our website and services against abuse, fraud, and security threats.
- To send occasional updates about our services, only if you have opted in, and you can opt out at any time using the link in any such email.
What we do not do: we do not sell your personal data, we do not rent it to third parties, and we do not use the contents of your enquiries or client projects to train publicly available AI models.
04Legal bases
Where laws such as the EU or UK GDPR apply, we rely on the following legal bases:
| Purpose | Legal basis |
|---|---|
| Responding to your enquiry | Legitimate interests, or steps taken at your request before entering a contract |
| Delivering contracted services | Performance of a contract |
| Invoicing, tax, and accounting records | Legal obligation |
| Website analytics | Consent (where required) or legitimate interests |
| Marketing emails | Consent |
| Security and abuse prevention | Legitimate interests |
06International transfers
We work with clients globally, so your data may be processed in countries other than your own, including the countries where our team, contractors, and infrastructure providers are located. Where data moves out of the UK, EU, or other regions with transfer rules, we rely on appropriate safeguards such as standard contractual clauses or adequacy decisions.
07How long we keep data
- Enquiries that do not become projects: up to 24 months from our last contact, so we can pick the conversation back up if you return.
- Client records and contracts: for the duration of the engagement plus the period required by tax and accounting law in the relevant jurisdiction.
- Analytics data: per the retention settings of our analytics tool, typically 14 months.
When data is no longer needed, we delete it or anonymise it.
08How we protect data
We use encryption in transit, access controls limited to the people who need access, multi-factor authentication on our core accounts, and reputable infrastructure providers. No system is perfectly secure, but if we ever become aware of a breach affecting your personal data, we will notify you and the relevant authorities as required by law.
09Your rights
Depending on where you live, you may have the right to:
- Access a copy of the personal data we hold about you.
- Correct data that is inaccurate or incomplete.
- Ask us to delete your data.
- Object to or restrict certain processing.
- Receive your data in a portable format.
- Withdraw consent at any time, where processing is based on consent.
- Complain to your local data protection authority.
To exercise any of these rights, email us. We respond within the timeframe required by applicable law, and we never charge for a reasonable request.
11Client project data
When we build AI applications, agents, or automations for a client, we often work with data inside the client's own systems. In those cases the client is the data controller and Iontek is a data processor acting under the client's instructions and a written agreement.
- Client project data is used only to deliver the agreed work.
- It is never used to train publicly available AI models.
- Access is limited to team members working on that project.
- On request at the end of an engagement, we return or delete client data in line with the agreement.
12Children
Our website and services are for businesses and are not directed at children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us data, contact us and we will delete it.
13Changes to this policy
We may update this policy as our services or the law change. The "Last updated" date at the top always reflects the current version, and for significant changes we will post a clear notice on this page.
14Contact us
Questions about privacy or this policy? Send us an email and we will get back to you.