Last updated: 25 June 2026

GDPR Compliance Statement

1. Our commitment

GMHCO Ltd is committed to full compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. This statement explains how we apply GDPR principles across our platform, data handling practices, and organisational culture.

2. The seven GDPR principles

1

Lawfulness, fairness and transparency

We identify a lawful basis before processing personal data (see our Privacy Policy, Section 3). We publish clear, plain-English notices about how data is used and never process data in ways users would not reasonably expect.

2

Purpose limitation

Data collected for service delivery is not repurposed for advertising, third-party analytics, or training AI models without explicit consent. Each processing purpose is documented in our internal Record of Processing Activities (RoPA).

3

Data minimisation

We collect only the data necessary for the stated purpose. For example, demo accounts require only name, email, and organisation details — no payment data or national identifiers.

4

Accuracy

Users can update their personal data at any time via account settings. Inaccurate data reported to us is corrected or erased within 14 days.

5

Storage limitation

We apply the retention schedules documented in our Privacy Policy (Section 7). Demo accounts with no subscription are automatically deleted after 3 hours. Billing records are kept for 7 years as required by UK law.

6

Integrity and confidentiality

Data is encrypted in transit (TLS 1.2+) and at rest. Access is controlled by role-based permissions enforced by Keycloak. All infrastructure runs on ISO 27001-certified Hetzner data centres in the EU.

7

Accountability

We maintain a RoPA, conduct Data Protection Impact Assessments (DPIAs) for high-risk processing, train all staff on GDPR, and appoint a Data Protection Lead. We document all decisions and can demonstrate compliance on request.

3. Legal bases for processing

We rely on the following legal bases (UK GDPR Article 6):

  • Contract — processing necessary to deliver the platform service
  • Legal obligation — tax records, anti-fraud measures, regulatory reporting
  • Legitimate interests — security monitoring, platform improvement (always balanced against individual rights)
  • Consent — marketing to non-customers; certain optional cookies

Where we process special category data (e.g. information about clients' immigration status held in case files uploaded by your firm), we rely on Article 9(2)(f) — processing necessary for legal claims — and require your firm to be the Data Controller for that client data, with TeamsAI acting as Data Processor.

4. Data subject rights

We uphold all rights under UK GDPR Articles 15–22:

RightHow to exerciseResponse time
Access (SAR)Email dpo@teamsai.uk30 days
RectificationAccount settings or email us14 days
ErasureEmail dpo@teamsai.uk30 days
RestrictionEmail dpo@teamsai.uk30 days
PortabilityExport via platform or email30 days
ObjectEmail dpo@teamsai.uk30 days
Withdraw consentUnsubscribe link or email usImmediate

We will never charge a fee for exercising rights (unless requests are manifestly unfounded or excessive). Identity verification may be required before releasing personal data.

5. Data processor agreements

Where TeamsAI acts as a Data Processor on behalf of your firm (processing client personal data in case files), a Data Processing Agreement (DPA) is available. Contact privacy@teamsai.uk to request or review your DPA.

All our sub-processors (Hetzner, Stripe, NVIDIA NIM) have signed standard contractual clauses (SCCs) and are listed in our Privacy Policy, Section 5.

6. International data transfers

Primary data storage is in the EU (Hetzner Germany/Finland). When AI inference requests are sent to NVIDIA NIM (US), we rely on standard contractual clauses approved by the ICO. No personal data is included in inference prompts without your explicit configuration.

7. Data Protection Impact Assessments

We conduct DPIAs before introducing any processing that is likely to result in a high risk to individuals, including:

  • AI-assisted processing of case file documents
  • Automated compliance checks on client records
  • Browser automation accessing third-party government portals

8. Breach notification

In the event of a personal data breach that is likely to result in a risk to individuals, we will:

  • Notify the ICO within 72 hours of becoming aware
  • Notify affected data subjects without undue delay if the breach poses a high risk
  • Document all breaches in our internal breach register

9. Data Protection Lead

Our Data Protection Lead can be contacted at dpo@teamsai.uk. They oversee compliance, review processing activities, and act as the point of contact for the ICO.

10. Supervisory authority

The UK supervisory authority is the Information Commissioner's Office (ICO):

You have the right to lodge a complaint with the ICO at any time if you believe we have not handled your data lawfully.