Legal
Privacy policy
How EU AI Fit collects, uses, and protects your data. Last updated 4 September 2026.
1. Who we are
EU AI Fit is a trading name of The Driving Training Centre Ltd, company number 12361535, whose registered office is 9 Glissons, Ferndown, England, BH22 9DX. The company is the controller of personal data processed through the EU AI Fit website and platform unless a customer agreement identifies a different role for a particular processing activity.
The current service includes public information, an in-browser exposure check, contact forms, invite-only readiness pilots and controlled customer workspaces.
For any questions about this privacy policy or your personal data, contact us at support@euaifit.com.
2. What data we collect
We collect and process the following categories of data:
Account data: Your name, email address, and organisation name when you create an account. If you sign in via Google or Microsoft SSO, we receive your verified email and profile name from the provider. If you use passwordless email sign-in, we send a short-lived, single-use code to the address you provide. The stored verification token is hashed.
Enquiry data: Information you submit through our contact form, including your email address and any company information or message you choose to provide.
Pilot-update data: When you ask for pilot updates, we store your email address, subscription status, source, consent time, confirmation time and unsubscribe status. We use this only after you actively consent and confirm your email address.
Pilot data: If you join an invite-only readiness pilot, we process the AI-system, obligation, reviewer and audit information entered in your workspace. If your organisation selects managed evidence storage, this can include evidence files and associated metadata. The purpose, capacity, retention, hosting, subprocessors and approved transfer methods will be explained during onboarding. Do not submit confidential AI-system evidence through the public contact form.
Exposure-check data: The public exposure check runs in your browser. When a check is completed, the answers are verified transiently by our server and we retain only the result category and completion time as an anonymous product metric. The analytics record does not contain the answers, email address, IP address, cookie identifier, browser identifier or user account. If you optionally request an emailed lower-exposure result, your answers and email address are sent to our server and email-delivery provider solely to compose and deliver that requested message. EU AI Fit does not store the answers or add the address to a marketing list. We retain only hashed email and network identifiers for up to 24 hours to prevent abuse.
Usage data: Standard server logs including IP address, browser type, timestamps, and page views. We use this for security, abuse prevention and product improvement. If you consent to optional Google Analytics, the Google tag processes the public route path without query parameters, page title, device and browser information, approximate location, page-speed and responsiveness measurements, and a small number of journey events with broad result or enquiry categories. Performance measurements include TTFB, FCP, LCP, INP and CLS with a random page-load measurement identifier. We do not send form content, email addresses, assessment answers, customer names, AI-system identifiers or authenticated-workspace activity to Google Analytics. Advertising features, Google signals and Enhanced Measurement are disabled. Google states that GA4 uses IP addresses to derive location information but does not log or store individual IP addresses. The EU AI Fit property retains user and event data for two months without extending that period following new activity, and our Analytics cookies are configured to expire within 180 days. You can withdraw consent through Cookie settings in the site footer.
We also report aggregate business outcomes, such as new enquiries, confirmed subscriptions, accounts, accepted agreements and workspaces, from the operational records already required to provide those services. Email sign-in requests and verification attempts are rate-limited using hashed email and network identifiers. These records stop being used for rate-limit decisions after 24 hours and are deleted during subsequent authentication activity.
Email delivery data: Our email-delivery provider processes recipient addresses, message content and delivery metadata needed to send messages, manage bounces and complaints, and protect delivery. Open or link measurement, if enabled for a message, is treated as email measurement rather than a website cookie and must be limited to the stated operational or consented marketing purpose.
We do not sell your data. We do not use your data to train AI models.
3. Where data is stored
The public website is delivered through our hosting provider and uses encrypted HTTPS connections. Contact submissions and subscription messages are sent through our email-delivery provider when configured. Pilot-update consent records are retained in the EU AI Fit service database. Managed evidence files are held in private object storage configured for the pilot and are available only through authenticated workspace access.
Reference-only workspaces retain evidence in the customer's own controlled system and EU AI Fit stores the evidence reference and review metadata. Pilot customers receive current hosting, subprocessor, retention, and international-transfer information during onboarding.
Where optional public-site Analytics is accepted, Google processes the limited measurement data described above. Google may process data outside the UK or EEA under the safeguards described in its data-processing terms. Our legal basis for optional Analytics storage/access and associated processing is consent.
4. How we protect your data
We use HTTPS, restricted service access, managed authentication, organisation-scoped authorisation, file integrity checks and audited evidence access for the current website and early workspace. Managed storage tiers include retention-review and controlled-deletion workflows. Production file approval requires the configured malware-scanning control.
During the pilot, customers should use only the approved transfer method and avoid sending confidential, special-category, or production data through public forms. Contact support@euaifit.com for the current security and subprocessor information.
5. Pilot updates and retention
We rely on your consent to send product and pilot update emails. A new subscription remains pending until you use the confirmation link sent to your email address. Confirmation links expire after 48 hours, and repeated requests are rate-limited.
Every update includes a way to unsubscribe. When you unsubscribe, we retain a minimal suppression record so that we can honour your preference. Pending, unconfirmed subscriptions are reviewed and removed when they are no longer needed. You may also ask support@euaifit.com to remove your subscription record. Withdrawing consent does not affect processing that took place before withdrawal.
6. Your rights
Under the UK GDPR and EU GDPR, you have the following rights:
• Right to access: You can request a copy of your personal data at any time.
• Right to rectification: You can correct inaccurate or incomplete data.
• Right to erasure: You can request deletion of your personal data, subject to legal retention obligations.
• Right to restrict processing: You can ask us to limit how we use your data.
• Right to data portability: You can receive your data in a structured, machine-readable format.
• Right to object: You can object to processing based on legitimate interests.
• Right to withdraw consent: Where processing is based on consent, you can withdraw it at any time.
To exercise any of these rights, email support@euaifit.com. We respond within 30 days.
7. Contact and complaints
If you have a concern about how we handle your data, contact us first at support@euaifit.com. We take all complaints seriously and will investigate promptly.
You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) in the UK at ico.org.uk, or with your local EU supervisory authority.
This privacy policy was last updated on 4 September 2026.