Privacy Policy
Last updated:
AuthorKey AI ("AuthorKey AI", "we", "us", or "our") respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, store, disclose and protect personal data when you acquire a Technology Certificate, create a Vault, upload information, or otherwise use our Services.
1. Introduction
AuthorKey AI ("AuthorKey AI", "we", "us", or "our") respects your privacy and is committed to protecting your personal data.
This Privacy Policy explains how we collect, use, store, disclose and protect personal data when you acquire a Technology Certificate, create a Vault, upload information, or otherwise use our Services.
AuthorKey AI provides secure artificial intelligence infrastructure, encrypted Vault technology, Technology Certificates and related software services.
This Privacy Policy applies to all personal data processed by AuthorKey AI in connection with the provision of its Services.
This Privacy Policy applies under both the EU General Data Protection Regulation (EU GDPR) and the UK General Data Protection Regulation (UK GDPR) read with the Data Protection Act 2018. Where this Policy refers to GDPR, this should be read as referring to both EU GDPR and UK GDPR unless the context specifies otherwise.
2. Data Protection Roles
2.1 AuthorKey AI as Data Controller
AuthorKey AI acts as a data controller in relation to:
- User account administration;
- Technology Certificate issuance and verification;
- Vault administration;
- Authentication and security monitoring;
- Service operation and maintenance;
- Customer support;
- Compliance with legal obligations;
- Fraud prevention and platform security.
2.2 Business Customers
Where AuthorKey AI provides Services to business customers, AuthorKey AI may act as a data processor under separate contractual arrangements where required by applicable law.
2.3 Relationship with Glacio Ltd
AuthorKey AI uses Technology Certificate infrastructure provided by Glacio Ltd (Company Registration No. 677497, Larnaca, Cyprus). In connection with the issuance and verification of Technology Certificates, limited certificate metadata may be shared with Glacio solely for certificate issuance, registration and validation purposes.
3. Categories of Personal Data Processed
AuthorKey AI may process the following categories of personal data.
3.1 Account Information
- Name
- Username
- Email address
- Contact details
- Account credentials.
3.2 Authentication Data
- Technology Certificate identifiers;
- Authentication records;
- Two-factor authentication information;
- Login activity.
3.3 Technical Data
- IP address
- Device identifiers
- Browser type and version
- Operating system
- Session timestamps
- Usage logs
- Error reports
3.4 Vault Content
- Documents uploaded by users
- Identity documents
- Financial records
- Medical information
- Legal documents
- Personal notes
- Files and data stored within a Vault.
3.5 AI Interaction Data
- User prompts
- AI-generated responses
- Conversation history
- Contextual information required to provide personalised AI functionality.
3.6 Communications
- Customer support requests
- Correspondence
- Service-related communications.
3.7 Payment and Transaction Data
- Token pack purchase records
- Transaction reference identifiers
- Payment method type (card or bank transfer)
- Purchase amount and date
- Technology Certificate issuance records linked to payment.
4. Purposes of Processing
AuthorKey AI processes personal data for the following purposes:
- Issuing and validating Technology Certificates
- Creating and maintaining Vaults
- Providing access to the Services
- Personalising your experience based on Vault content
- Authenticating users
- Maintaining system security
- Detecting fraud and abuse
- Providing customer support
- Monitoring and improving Service performance
- Complying with legal obligations
- Enforcing contractual rights
- Responding to lawful requests from authorities
- Processing token pack purchases and managing token balances
- Issuing, recording and verifying Technology Certificates in the Certificate Registry
- Account recovery via Technology Certificate.
AuthorKey AI does not sell personal data.
AuthorKey AI does not use personal data for behavioural advertising.
AuthorKey AI does not provide personal data to third parties for marketing purposes.
5. Legal Bases for Processing
Where required under applicable law, AuthorKey AI relies on one or more of the following legal bases:
5.1 Contractual Necessity
Processing necessary for:
- Providing Services
- Managing accounts
- Operating Vaults
- Delivering the Services
- Processing token pack purchases
- Issuing Technology Certificates.
5.2 Legitimate Interests
Processing necessary for:
- Security monitoring
- Fraud prevention
- Service improvement
- Infrastructure protection
- Business administration
- Maintaining the integrity of the Certificate Registry.
5.3 Legal Obligations
Processing necessary for compliance with:
- Applicable laws
- Regulatory requirements
- Court orders
- Law enforcement requests.
5.4 Consent
Where required by law, AuthorKey AI will obtain consent before processing personal data.
5.5 Explicit Consent for Special Category Data
Where users voluntarily upload special category personal data (including health information or identity documents) to their Vault, AuthorKey AI relies on explicit consent under Article 9(2)(a) EU GDPR and, for UK users, Article 9(2)(a) UK GDPR read with Schedule 1 of the Data Protection Act 2018. Users may withdraw this consent at any time by deleting the relevant content from their Vault or submitting a deletion request to AuthorKey AI.
6. AI Services and Vault Content
Users may upload information and documents to their Vault.
Such information is processed solely for the purpose of providing the Services.
Users remain solely responsible for:
- The legality of uploaded content;
- The accuracy of uploaded information;
- Ensuring they have the right to upload such information.
AuthorKey AI does not claim ownership of user-uploaded content.
Users grant AuthorKey AI a limited licence to process such content solely for the purpose of providing the Services.
Vault content is retained for the duration of the user's account and is deleted following account closure or permanent token depletion, as described in section 9.
AuthorKey AI does not use Vault content or AI interaction data to train or improve AI models.
AI functionality is provided using a third-party large-language-model provider acting as AuthorKey AI's processor. User prompts and relevant Vault content are transmitted to that provider solely for the purpose of generating AI responses, are not used by the provider to train its models, and are otherwise processed within AuthorKey AI's systems in accordance with the security measures described in section 10.
AI-generated responses may be inaccurate, incomplete or outdated.
AI outputs are provided for informational purposes only and do not constitute:
- Legal advice
- Financial advice
- Medical advice
- Tax advice
- Professional advice of any kind.
Users should independently verify AI-generated outputs before relying on them.
7. Data Sharing
AuthorKey AI may share personal data with:
- Glacio Ltd (Company Registration No. 677497, Larnaca, Cyprus), solely for Technology Certificate issuance, registration and verification purposes
- Cloud hosting providers
- Infrastructure providers
- Cybersecurity service providers
- Technical support providers
- Professional advisers
- Auditors
- Regulators
- Government authorities where legally required.
AuthorKey AI does not sell personal data.
AuthorKey AI does not disclose personal data for advertising purposes.
All third-party service providers are required to implement appropriate security measures.
8. International Transfers
Personal data may be transferred outside the European Economic Area (EEA) and the United Kingdom where necessary for hosting, support or operational purposes.
This includes transfers to our AI model provider, Anthropic (United States), in connection with the processing of user prompts and Vault content for AI response generation.
Where such transfers occur, AuthorKey AI implements appropriate safeguards, including:
- Standard Contractual Clauses;
- Adequacy decisions;
- Encryption measures;
- Technical and organisational safeguards.
For transfers of personal data of UK users outside the United Kingdom, AuthorKey AI relies on the applicable UK transfer mechanism, which may include the ICO's International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses. EU Standard Contractual Clauses alone are not relied upon for transfers of UK personal data.
9. Data Retention
Personal data is retained only for as long as necessary to:
- Provide the Services
- Maintain Vault functionality
- Fulfil contractual obligations
- Comply with legal requirements
- Resolve disputes
- Protect legal rights.
Retention periods for the main categories of personal data are as follows:
- Account data: for the duration of the account and for a limited period after closure;
- Vault content: deleted after account closure or permanent token depletion;
- Assistant conversation history (where applicable): retained for a limited period;
- Technology Certificate records: permanent (public registry function);
- Payment and transaction records: up to 7 years (accounting and tax obligations);
- Security and audit logs: retained for a limited period.
When personal data is no longer required, it is securely deleted or anonymised.
10. Security Measures
AuthorKey AI implements appropriate technical and organisational measures designed to protect personal data.
Such measures include:
- Encryption in transit
- Encryption at rest
- Multi-factor authentication
- Access controls
- Network security controls
- Monitoring systems
- Audit logging
- Vulnerability testing
- Incident response procedures
- AES-256 encryption of Vault content
- Technology Certificate-bound access controls ensuring only the certificate holder can access their Vault.
While AuthorKey AI takes reasonable steps to protect personal data, no method of transmission or storage can be guaranteed to be completely secure.
11. Your Rights
Subject to applicable law, you may have the following rights:
- Right of access
- Right to rectification
- Right to erasure
- Right to restriction of processing
- Right to data portability
- Right to object
- Right to withdraw consent
- Right not to be subject to solely automated decision-making with significant effects (Article 22 EU GDPR / UK GDPR).
Requests may be submitted by contacting AuthorKey AI at privacy@authorvault.tech. AuthorKey AI will respond within one month of receipt of a valid request.
AuthorKey AI may require verification of identity before responding to requests.
12. Automated Processing
AuthorKey AI uses artificial intelligence systems to generate responses based on:
- User prompts
- Uploaded Vault content
- Available contextual information.
Where AI features are provided, this personalisation constitutes profiling under GDPR Article 4(4) in so far as it analyses personal information to generate personalised responses. It does not produce legal or similarly significant effects.
AuthorKey AI does not engage in automated decision-making that produces legal or similarly significant effects without appropriate safeguards.
You have the right to object to profiling under GDPR Article 21 by contacting AuthorKey AI at privacy@authorvault.tech.
13. Children's Privacy
The Services are not intended for individuals under the age of 18.
AuthorKey AI does not knowingly collect personal data from children.
If we become aware that personal data has been collected from a child without appropriate authorisation, such data will be deleted promptly. If you are a parent or guardian and believe your child has provided personal data to AuthorKey AI, please contact us at privacy@authorvault.tech.
14. Cookies and Similar Technologies
AuthorKey AI may use cookies and similar technologies for:
- Authentication;
- Session management;
- Security monitoring;
- Service functionality;
- Performance analysis.
Additional information may be provided in our Cookie Policy.
15. Complaints
If you believe your personal data has been processed unlawfully, you may:
- Contact AuthorKey AI;
- Lodge a complaint with the relevant supervisory authority;
- Contact your local data protection authority;
- If you are based in the United Kingdom: lodge a complaint with the Information Commissioner's Office (ICO), Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF | Tel: 0303 123 1113 | www.ico.org.uk;
- If you are based in the European Union: lodge a complaint with the supervisory authority of the EU member state in which you reside or work.
16. Changes to this Privacy Policy
AuthorKey AI may amend this Privacy Policy from time to time.
Updated versions will be published on our website and Platform.
Where changes materially affect how your personal data is processed or your rights, AuthorKey AI will notify you by email or in-Platform notification before the changes take effect. Where consent was the legal basis for processing, fresh consent will be sought.
17. Contact Information
For privacy-related enquiries, requests or complaints, please contact AuthorKey AI using the contact details published on our website, or email privacy@authorvault.tech.
18. Clarification of Service Nature
For the avoidance of doubt, AuthorKey AI:
- Provides software services
- Provides encrypted Vault technology
- Provides access to the Services
- Issues Technology Certificates
- Operates secure digital infrastructure.
AuthorKey AI does not:
- Provide banking services
- Provide payment services
- Provide investment services
- Issue e-money
- Provide legal advice
- Provide medical advice
- Provide financial advice
- Act as a regulated financial intermediary.
Personal data processing by AuthorKey AI is limited to the operation and provision of its software services.