Last updated: 25 June 2026

Privacy Policy

1. Who we are

GMHCO Ltd ("TeamsAI", "we", "us", "our") operates the TeamsAI platform at teamsai.uk — an AI-powered workforce management platform for legal and immigration firms. Our registered address is in the United Kingdom.

We are the Data Controller for personal data collected through our website and platform. For questions about this policy, contact us at privacy@teamsai.uk.

2. What data we collect

2.1 Account & organisation data

  • Name, email address, job role, phone number
  • Organisation name, registered address, country
  • Keycloak authentication credentials (passwords are hashed — we never store plaintext passwords)
  • Billing details processed via Stripe (we never store card numbers)

2.2 Platform usage data

  • Case files, client records, and documents you upload
  • AI agent run logs and task outputs
  • Audit trails of user actions within your workspace
  • IP addresses and device/browser metadata for security

2.3 Communication data

  • Emails and messages sent via the platform on your behalf
  • Support correspondence

2.4 Technical data

  • Server logs, error reports, performance metrics
  • Cookies (see Section 8)

3. Legal basis for processing

Processing activityLegal basis
Delivering the platform serviceContract (Art. 6(1)(b) UK GDPR)
Billing and paymentsContract / Legal obligation
Security and fraud preventionLegitimate interests (Art. 6(1)(f))
Marketing emails to existing customersLegitimate interests (soft opt-in)
Marketing to prospective customersConsent (Art. 6(1)(a))
Compliance with UK lawLegal obligation (Art. 6(1)(c))

4. How we use your data

  • To create and manage your organisation account and Keycloak identity
  • To run AI agents, process documents, and perform compliance checks on your behalf
  • To send transactional emails (account activation, invoices, security alerts)
  • To process payments via Stripe
  • To comply with legal obligations including anti-money-laundering and data retention rules
  • To improve the platform and diagnose issues using anonymised telemetry

5. Data sharing and third parties

We do not sell your data. We share it only with:

  • Hetzner Online GmbH — infrastructure provider (EU data centres)
  • Stripe Inc. — payment processing (PCI-DSS Level 1 certified)
  • Keycloak (self-hosted) — identity management, running on our own servers
  • NVIDIA NIM API — AI model inference for certain tasks (no training on your data)
  • Legal or regulatory authorities — if required by law or court order

All third-party processors are contractually bound to handle your data in accordance with UK GDPR requirements.

6. International transfers

Your data is primarily stored on EU servers (Hetzner, Germany/Finland). When AI inference tasks use NVIDIA NIM APIs, requests may be processed on US infrastructure. We rely on standard contractual clauses (SCCs) for these transfers.

7. Retention periods

Data typeRetention period
Active account dataDuration of subscription + 30 days
Demo accounts (no subscription)Deleted 3 hours after activation
Billing records7 years (UK legal requirement)
Security logs12 months
AI agent run logs90 days
Backups30 days rolling

8. Cookies

We use the following cookies:

  • next-auth.session-token — authentication session (essential, HttpOnly)
  • next-auth.csrf-token — CSRF protection (essential)
  • __stripe_mid / __stripe_sid — Stripe fraud prevention (functional)

We do not use advertising or cross-site tracking cookies. You can clear cookies in your browser settings at any time.

9. Your rights under UK GDPR

You have the right to:

  • Access — request a copy of your personal data
  • Rectification — correct inaccurate data
  • Erasure — request deletion ("right to be forgotten")
  • Restriction — limit how we process your data
  • Portability — receive your data in a machine-readable format
  • Object — object to processing based on legitimate interests
  • Withdraw consent — where processing is consent-based

To exercise any right, email privacy@teamsai.uk. We will respond within 30 days. You also have the right to complain to the Information Commissioner's Office (ICO) at ico.org.uk.

10. Security

We implement technical and organisational measures to protect your data, including TLS encryption in transit, encrypted database storage, role-based access controls, and regular security reviews. No system is 100% secure; in the event of a breach we will notify affected users and the ICO within 72 hours where required.

11. Changes to this policy

We may update this policy from time to time. Material changes will be notified by email or an in-platform banner. Continued use of TeamsAI after the effective date constitutes acceptance.

12. Contact

GMHCO Ltd
United Kingdom
Email: privacy@teamsai.uk