Privacy Policy
1. Principles & Commitment to Privacy
Gratia AI Ltd operates empirical verification environments and advanced reinforcement learning frameworks for frontier artificial intelligence laboratories. Data integrity, security, and confidentiality form the bedrock of our business. We apply zero-trust architectural principles not only to model evaluation, but strictly to the stewardship of all personal, technical, and commercial data entrusted to us.
We process personal data in strict compliance with the core principles set out in Article 5 of the UK GDPR:
- Lawfulness, fairness, and transparency: Processed legitimately with full visibility to data subjects.
- Purpose limitation: Collected strictly for specified, explicit, and legitimate corporate and technical purposes.
- Data minimisation: Limited strictly to what is adequate, relevant, and necessary.
- Accuracy: Maintained accurately and kept up to date.
- Storage limitation: Retained only for as long as necessary for the purposes of processing.
- Integrity and confidentiality: Secured against unauthorized or unlawful processing, accidental loss, destruction, or damage using rigorous encryption.
2. Data We Collect
Depending on your interaction with Gratia AI Ltd, we may process the following categories of data:
| Category | Data Elements | Purpose & Context |
|---|---|---|
| Identity & Professional Contact | Full name, business email address, organization/frontier AI lab, professional title, country of residence. | Responding to commissioning RFPs, executing commercial contracts, and direct technical consultations. |
| Enterprise Specifications | Model architectures, RL environment requirements, evaluation budgets, and target benchmark thresholds. | Scoping, authoring, and calibrating empirical evaluation benchmarks under strict Non-Disclosure Agreements (NDAs). |
| Technical & Telemetry | IP address (anonymized), browser agent, HTTP request headers, access timestamps, cryptographic handshakes. | Ensuring edge network security, DDoS prevention, rate limiting, and infrastructure diagnostics. |
3. Lawful Bases for Processing (Article 6 UK GDPR)
We only collect and process personal data where an established lawful basis exists under Article 6 of the UK GDPR:
- Contractual Performance (Art. 6(1)(b)): Where processing is necessary to take preliminary steps at your request prior to entering into a contract, or to perform an existing commercial contract for evaluation environments or datasets.
- Legitimate Interests (Art. 6(1)(f)): Where processing is necessary for our legitimate commercial interests, such as platform security, client relationship management, fraud prevention, and operational integrity, provided these interests are not overridden by your fundamental rights.
- Legal Obligation (Art. 6(1)(c)): To satisfy statutory obligations under English law, including tax accounting (HMRC) and corporate recordkeeping under the Companies Act 2006.
- Explicit Consent (Art. 6(1)(a)): Where you have voluntarily opted in to specific technical communications or marketing publications. You may withdraw consent at any time.
4. Zero-Leak Policy & Non-Disclosure
We never sell, rent, or commercialize personal data or proprietary model specifications. All benchmark environments, evaluation logs, and research data submitted by frontier AI labs are strictly isolated within single-tenant, containerized sandboxes governed by comprehensive intellectual property agreements.
We only share data with vetted third-party service providers (such as Tier-1 edge infrastructure and cloud security providers) under written Data Processing Agreements (DPAs) requiring adherence to UK GDPR standards.
5. International Transfers & Storage Security
Personal data is primarily stored and processed within the United Kingdom and the European Economic Area (EEA). Where technical data passes through edge hosting providers with points of presence outside the UK, transfers are secured under:
- UK International Data Transfer Agreements (IDTA) or the UK Addendum to the EU Standard Contractual Clauses (SCCs).
- Formal statutory adequacy regulations recognized under English law.
Technical safeguards include AES-256 data encryption at rest, TLS 1.3 encryption in transit, strict role-based access controls (RBAC), and continuous penetration auditing.
6. Data Retention
We retain personal data only for the period necessary to fulfill the purposes outlined in this Policy:
- Client & RFP Records: Maintained for the duration of the commercial relationship plus up to 6 years following contract completion to satisfy statutory limitation periods under the Limitation Act 1980 and UK tax legislation.
- Technical Edge Telemetry: Ephemeral server and security logs are automatically rotated and deleted after 30 to 90 days.
7. Your Statutory Rights Under UK GDPR
Under the UK GDPR and the Data Protection Act 2018, you possess comprehensive rights regarding your personal information:
- Right of Access (Art. 15): You have the right to request a copy of the personal information we hold about you (Subject Access Request).
- Right to Rectification (Art. 16): You may request correction of inaccurate or incomplete data.
- Right to Erasure (Art. 17): Known as the "Right to be Forgotten", allowing you to request deletion of personal data where no statutory reason for retention exists.
- Right to Restriction of Processing (Art. 18): You may request suspension of processing under specific legal conditions.
- Right to Data Portability (Art. 20): You may receive your data in a structured, commonly used, and machine-readable format.
- Right to Object (Art. 21): You have the right to object to processing based on legitimate interests or direct marketing.
To exercise any of these rights, contact our Data Protection Officer at privacy@gratiaai.co. We respond to all verified statutory requests within one calendar month without charge.
8. Regulatory Authority & Complaints
If you believe that GRATIA AI LTD has not processed your personal data in accordance with applicable UK data protection legislation, you have the right to lodge a formal complaint with the supervisory authority:
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Helpline: 0303 123 1113 | Website: ico.org.uk
9. Contact & Corporate Governance
For any inquiries, rights requests, or regulatory questions regarding this policy, please direct communications to:
Data Protection & Governance Desk
GRATIA AI LTD
Company Registration Number: 17370667
Registered in England & Wales
Official Web: https://gratiaai.co
Email: privacy@gratiaai.co