Last updated: 25 June 2026
Privacy Policy
1. Who we are
GMHCO Ltd ("TeamsAI", "we", "us", "our") operates the TeamsAI platform at teamsai.uk — an AI-powered workforce management platform for legal and immigration firms. Our registered address is in the United Kingdom.
We are the Data Controller for personal data collected through our website and platform. For questions about this policy, contact us at privacy@teamsai.uk.
2. What data we collect
2.1 Account & organisation data
- Name, email address, job role, phone number
- Organisation name, registered address, country
- Keycloak authentication credentials (passwords are hashed — we never store plaintext passwords)
- Billing details processed via Stripe (we never store card numbers)
2.2 Platform usage data
- Case files, client records, and documents you upload
- AI agent run logs and task outputs
- Audit trails of user actions within your workspace
- IP addresses and device/browser metadata for security
2.3 Communication data
- Emails and messages sent via the platform on your behalf
- Support correspondence
2.4 Technical data
- Server logs, error reports, performance metrics
- Cookies (see Section 8)
3. Legal basis for processing
| Processing activity | Legal basis |
|---|---|
| Delivering the platform service | Contract (Art. 6(1)(b) UK GDPR) |
| Billing and payments | Contract / Legal obligation |
| Security and fraud prevention | Legitimate interests (Art. 6(1)(f)) |
| Marketing emails to existing customers | Legitimate interests (soft opt-in) |
| Marketing to prospective customers | Consent (Art. 6(1)(a)) |
| Compliance with UK law | Legal obligation (Art. 6(1)(c)) |
4. How we use your data
- To create and manage your organisation account and Keycloak identity
- To run AI agents, process documents, and perform compliance checks on your behalf
- To send transactional emails (account activation, invoices, security alerts)
- To process payments via Stripe
- To comply with legal obligations including anti-money-laundering and data retention rules
- To improve the platform and diagnose issues using anonymised telemetry
5. Data sharing and third parties
We do not sell your data. We share it only with:
- Hetzner Online GmbH — infrastructure provider (EU data centres)
- Stripe Inc. — payment processing (PCI-DSS Level 1 certified)
- Keycloak (self-hosted) — identity management, running on our own servers
- NVIDIA NIM API — AI model inference for certain tasks (no training on your data)
- Legal or regulatory authorities — if required by law or court order
All third-party processors are contractually bound to handle your data in accordance with UK GDPR requirements.
6. International transfers
Your data is primarily stored on EU servers (Hetzner, Germany/Finland). When AI inference tasks use NVIDIA NIM APIs, requests may be processed on US infrastructure. We rely on standard contractual clauses (SCCs) for these transfers.
7. Retention periods
| Data type | Retention period |
|---|---|
| Active account data | Duration of subscription + 30 days |
| Demo accounts (no subscription) | Deleted 3 hours after activation |
| Billing records | 7 years (UK legal requirement) |
| Security logs | 12 months |
| AI agent run logs | 90 days |
| Backups | 30 days rolling |
8. Cookies
We use the following cookies:
- next-auth.session-token — authentication session (essential, HttpOnly)
- next-auth.csrf-token — CSRF protection (essential)
- __stripe_mid / __stripe_sid — Stripe fraud prevention (functional)
We do not use advertising or cross-site tracking cookies. You can clear cookies in your browser settings at any time.
9. Your rights under UK GDPR
You have the right to:
- Access — request a copy of your personal data
- Rectification — correct inaccurate data
- Erasure — request deletion ("right to be forgotten")
- Restriction — limit how we process your data
- Portability — receive your data in a machine-readable format
- Object — object to processing based on legitimate interests
- Withdraw consent — where processing is consent-based
To exercise any right, email privacy@teamsai.uk. We will respond within 30 days. You also have the right to complain to the Information Commissioner's Office (ICO) at ico.org.uk.
10. Security
We implement technical and organisational measures to protect your data, including TLS encryption in transit, encrypted database storage, role-based access controls, and regular security reviews. No system is 100% secure; in the event of a breach we will notify affected users and the ICO within 72 hours where required.
11. Changes to this policy
We may update this policy from time to time. Material changes will be notified by email or an in-platform banner. Continued use of TeamsAI after the effective date constitutes acceptance.
12. Contact
GMHCO Ltd
United Kingdom
Email: privacy@teamsai.uk