Privacy Policy
How AI Transform Studio handles personal data.
Last updated 29 August 2026
Who we are
This Privacy Policy explains how AI Transform Studio Ltd (registered in England and Wales) (“we”, “us”) processes personal data when you use AI Transform Studio at aitransformstudio.com and related application surfaces.
Contact for privacy requests: support@aitransformstudio.com.
Further company particulars are available on request at support@aitransformstudio.com.
Scope
This policy covers personal data we process as a controller for account, billing, and website operations. When you upload or connect Customer Data that includes personal data about your employees or other people, you are typically the controller and we act as your processor for that Customer Data. A separate data processing agreement is available on request for enterprise buyers; self-serve card checkout is governed by this policy and our Terms.
Personal data we collect
Depending on how you use the Service, we may process:
- Identity and contact data — name, email address
- Account and organization data — membership, roles, preferences
- Authentication data — password hashes (where used), session tokens, Google account identifiers if you sign in with Google
- Billing data — organization billing status; payment card details are handled by Stripe and not stored on our servers
- Usage and technical data — IP address, device/browser metadata, approximate logs needed to operate and secure the Service
- Support content — messages you send to support
- Customer content — prompts, artifacts, and data retrieved from systems you connect, which may incidentally include personal data
Sources
We collect data from you directly, from your organization’s admins, from authentication providers (e.g. Google), from Stripe for payment status, and from systems you connect when you authorize those connections.
Purposes and legal bases
We process personal data to provide the Service (contract), to bill and prevent fraud (contract / legitimate interests), to secure and debug the platform (legitimate interests), to send service emails such as verification codes (contract), and to comply with law.
Where UK GDPR requires consent for a specific optional processing activity, we will ask for it. We do not currently run marketing cookies or advertising trackers on the marketing site.
AI and data path
When you chat or run an agent, prompts, tool results, and related context are sent to the large language model provider whose credentials your organization has configured. That processing is under your provider relationship. We do not train third-party foundation models on your Customer Data for the benefit of other customers.
Tool calls may retrieve data from MCP servers and systems you connect. Treat tool output as untrusted input in your own processes. Artifacts are stored in our application database and file storage so you can reopen them.
International transfers
We and several subprocessors operate outside the UK. Where we transfer personal data internationally, we rely on appropriate safeguards such as the UK International Data Transfer Agreement / Addendum or adequacy regulations, as applicable to each subprocessor.
Retention
We keep account and organization data while your account is active and for a reasonable period afterward for backups, disputes, and legal obligations. You may request deletion via support@aitransformstudio.com. Billing records may be retained as required by tax and accounting rules.
Security
We use access controls, encryption in transit, organization-scoped authorization in the application, and least-privilege server secrets. The product runs on a shared multi-tenant stack with logical isolation by organization. See the Security page for a plain-language summary. No method of transmission or storage is perfectly secure.
Your rights
If UK GDPR applies to you, you may have rights to access, rectify, erase, restrict, object, and data portability, and to withdraw consent where processing is consent-based. Contact support@aitransformstudio.com. You may also complain to the UK Information Commissioner’s Office (ICO).
If you are an end user of a customer organization, please contact that organization first — they control much of the Customer Data in the workspace.
Children
The Service is for business use and is not directed to children under 16. We do not knowingly collect personal data from children.
Changes
We may update this policy by posting a new version and changing the “Last updated” date. Material changes will be called out where practicable.