Legal
Privacy Policy
Last updated: May 2025
TrackerAI Ltd ("we", "us", "our") is committed to protecting your personal data. This Privacy Policy explains what information we collect, how we use it, and your rights in relation to it. It applies to all users of our website at trackerai.ai, our demo application, and our API services.
We are the data controller for personal data collected through the Service and are committed to handling it in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
1. Data We Collect
Account and Registration Data
- Full name and email address
- Password (stored as a one-way hash — never in plain text)
- Professional details you optionally provide (e.g. practice name, role)
Usage Data
- Queries and inputs submitted to the AI diagnostic engine
- API call logs including timestamps, endpoint accessed, and response status
- Feature usage patterns and session duration
Technical Data
- IP address and approximate geographic location
- Browser type, device type, and operating system
- Referrer URLs and pages viewed
- Cookies and similar tracking technologies (see our Cookie Policy)
Communications
- Emails you send to us at hello@trackerai.ai
- Support tickets and feedback submissions
2. How We Use Your Data
We process your personal data for the following purposes:
- Service delivery — to provide, operate, and maintain the TrackerAI platform
- Authentication and security — to verify your identity and protect against unauthorised access
- Product improvement — to analyse usage patterns and improve model performance and user experience
- Communications — to send important service updates, security alerts, and (where you have opted in) product news
- Legal compliance — to meet our obligations under applicable law
3. Legal Bases for Processing
We rely on the following legal bases under UK GDPR:
- Contract performance — processing necessary to provide the Service you have signed up for
- Legitimate interests — improving our platform, fraud prevention, and security monitoring
- Legal obligation — complying with applicable laws and regulations
- Consent — for optional marketing communications (you may withdraw consent at any time)
4. Data Retention
We retain your account data for as long as your account remains active, plus an additional 90-day grace period after deletion. API logs are retained for 12 months for security and debugging purposes. Anonymised, aggregated usage data may be retained indefinitely for product analytics.
5. Data Sharing
We do not sell your personal data. We share it only with:
- Infrastructure providers — cloud hosting and database services (e.g. Neon, Modal) under strict data processing agreements
- Analytics tools — anonymised, aggregated data only
- Law enforcement — where required by valid legal process
6. International Transfers
Some of our infrastructure providers are based outside the UK. Where personal data is transferred to countries not deemed adequate by the UK ICO, we ensure appropriate safeguards are in place (such as Standard Contractual Clauses) before the transfer occurs.
7. Your Rights
Under UK GDPR you have the right to:
- Access — request a copy of the personal data we hold about you
- Rectification — ask us to correct inaccurate or incomplete data
- Erasure — request deletion of your data (subject to legal retention obligations)
- Restriction — ask us to limit how we process your data in certain circumstances
- Portability — receive your data in a structured, machine-readable format
- Objection — object to processing based on legitimate interests
- Withdraw consent — at any time, for processing based on consent
To exercise any of these rights, email us at hello@trackerai.ai. We will respond within 30 days. You also have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk.
8. Security
We implement appropriate technical and organisational measures to protect your personal data, including TLS encryption in transit, hashed credential storage, and access controls limiting who within our team can access production data. See our Security page for more detail.
9. Children
The Service is not directed at or intended for use by anyone under the age of 18. We do not knowingly collect personal data from minors.
10. Changes to This Policy
We may update this Privacy Policy periodically. Material changes will be communicated via email or a notice within the platform. The "Last updated" date at the top of this page will always reflect the most recent revision.
11. Contact Us
For any privacy-related questions or to exercise your rights, contact our team at hello@trackerai.ai.