Legal
Privacy Policy
Effective date: 1 September 2026 · Last updated: 8 September 2026
This policy explains what personal information Ionio collects when you visit ionio.ai, contact us, or work with us as a client, why we collect it, who we share it with, and the choices and rights you have over it.
01Who we are
Ionio is an AI consulting and transformation company. We help businesses identify where AI creates leverage, and we design, build and deploy the systems that deliver it. We work with clients ranging from bootstrapped founders to public companies, across manufacturing, retail and e-commerce, healthcare, legal, financial services and other sectors.
For the purposes of data protection law, Ionio is the
controller of the personal information described in this policy, except where we process information on behalf of a client, in which case that client is the controller and we act as a
processor under our contract with them. Our handling of client data as a processor is described in our
Data Policy.
Our contact details are set out in section 16.
02Scope of this policy
This policy applies to personal information we handle when you:
- visit ionio.ai or any of our subdomains, landing pages or research and blog properties;
- submit a form, book a call, subscribe to a newsletter, or download a white paper;
- email, call or message us, including through our sales and support channels;
- engage us as a client, or act as a contact at a client, prospect, supplier or partner organisation;
- apply for a role with us or otherwise interact with our recruitment processes.
It does not apply to the internal data environments of our clients, which are governed by our contracts with them and by their own privacy notices.
03Information we collect
Information you give us directly
- Identity and contact details — name, job title, company, email address, phone number, and the country or region you are based in.
- Enquiry content — what you write in a form, email, chat or call booking, including any details you choose to share about your business, systems or requirements.
- Engagement information — where you become a client, the commercial, billing and project contact details needed to deliver and invoice the work.
- Recruitment information — CV, work history, portfolio links and anything else you send us as part of an application.
Information we collect automatically
- Device and connection data — IP address, browser type and version, operating system, device type, language and approximate location derived from IP.
- Usage data — pages viewed, referring URLs, links clicked, time on page, scroll depth, and the dates and times of your visits.
- Cookie and identifier data — as described in section 6.
- Email interaction data — whether an email we sent was opened and whether links in it were clicked, where our email platform records this.
Information we receive from others
- Business contact data from lead sourcing, enrichment and CRM providers, used for business-to-business outreach and to keep records accurate.
- Referral information from partners, existing clients or people who introduce you to us.
- Public sources such as company websites, professional networks and public filings, where relevant to a business relationship.
- Service provider data from our scheduling, calling, analytics, payment and communication platforms, which report activity back to us.
Sensitive information. We do not seek to collect special category or sensitive personal data through our website or sales process. Please do not include such information in free-text fields or in materials you send us unless it is necessary and covered by a signed agreement.
04How we use information
We use personal information for the following purposes:
- To respond to you — answering enquiries, scheduling and holding calls, preparing proposals, and following up on conversations you started.
- To deliver our services — running engagements, managing project communication, providing support, and issuing invoices and receipts.
- To operate and improve our website — measuring which pages and content perform, diagnosing errors, and improving structure, speed and readability.
- For business development — contacting businesses that fit our areas of work, sending relevant research, white papers and updates, and maintaining our CRM records.
- For security and integrity — preventing and investigating fraud, abuse, spam and unauthorised access, and protecting our systems and our clients' systems.
- For legal and financial compliance — meeting accounting, tax, contractual and regulatory obligations, and establishing or defending legal claims.
- For recruitment — assessing applications and communicating with candidates.
We do not use personal information collected through our website to train machine learning models. Where AI tooling is used inside a client engagement, the terms in our
Data Policy apply.
05Legal bases for processing
Where the EU or UK General Data Protection Regulation applies, we rely on the following legal bases:
- Contract — where processing is necessary to enter into or perform a contract with you or the organisation you represent.
- Legitimate interests — for business-to-business outreach, website analytics, security, service improvement and the general running of our business, where those interests are not overridden by your rights.
- Consent — for non-essential cookies, certain marketing communications, and any other processing where consent is required. You can withdraw consent at any time.
- Legal obligation — where we must process information to comply with applicable law.
Where India's Digital Personal Data Protection Act applies, we process personal data on the basis of your consent or for legitimate uses recognised under that Act.
06Cookies and similar technologies
We and our providers use cookies, local storage and similar technologies to run the site and understand how it is used. The categories are:
- Strictly necessary — required for the site to load, for security, and for form submission and load balancing. These cannot be switched off.
- Analytics and performance — help us count visits, see which content is read, and identify errors and slow pages.
- Functional — remember preferences such as language, and support embedded content like scheduling widgets and video players.
- Marketing and attribution — measure the performance of campaigns and content, and connect an enquiry back to the source that produced it.
You can control cookies through your browser settings, including blocking or deleting them. Blocking some cookies will affect how parts of the site work. Where required by law, we ask for your consent before setting non-essential cookies, and you can change that choice at any time.
07How we share information
We do not sell personal information, and we do not share it for cross-context behavioural advertising. We disclose it only in these circumstances:
- Service providers — hosting and website infrastructure, email and calendar, CRM and sales tooling, telephony and calling platforms, analytics, cloud storage, payment and accounting providers, and customer support tools. They act on our instructions and are bound by confidentiality and data protection terms.
- AI and model providers — where an AI system is used to deliver our services. We select providers that offer enterprise or zero-retention terms and that do not train on the data we send, as described in our Data Policy.
- Professional advisers — lawyers, accountants, auditors and insurers, where necessary and under duties of confidentiality.
- Clients and partners — where you were introduced by, or your enquiry relates to, a specific partner or client engagement.
- Legal and regulatory recipients — where disclosure is required by law, court order or a valid request from a public authority, or to protect our rights, safety, property or those of others.
- Corporate transactions — in connection with a merger, acquisition, financing or sale of assets, subject to appropriate confidentiality protections.
08International transfers
We operate internationally and use service providers located in different countries, including India, the United States, the United Kingdom and the European Union. This means your personal information may be transferred to and processed in a country other than the one you are in.
Where we transfer personal information out of the European Economic Area or the United Kingdom, we rely on an adequacy decision where one exists, or on Standard Contractual Clauses together with supplementary technical and organisational measures. You can request details of the safeguards we use by contacting us.
09How long we keep information
We keep personal information only for as long as we need it for the purpose it was collected for, and then delete or anonymise it. In general:
- Enquiries that do not convert — up to 24 months from last contact.
- Client and prospect records — for the duration of the relationship and up to 7 years afterwards, to meet contractual, tax and accounting obligations.
- Website analytics and log data — typically up to 26 months, and shorter where the provider's defaults are shorter.
- Marketing subscription records — until you unsubscribe, plus a suppression record kept indefinitely so we do not contact you again.
- Recruitment records — up to 12 months after a decision, unless you ask us to keep them for future roles.
Where information is held under a client contract, the retention terms in that contract take precedence.
10How we protect information
We maintain technical and organisational measures appropriate to the risk, including encryption in transit and at rest, access control on a least-privilege basis, multi-factor authentication on business systems, segregated client environments, logging and monitoring, vendor security review, and confidentiality obligations for everyone who works with us. Our controls are described in more detail in our
Data Policy.
No method of transmission or storage is completely secure. If we become aware of a breach affecting your personal information, we will notify you and the relevant authorities where the law requires it.
11Your rights and choices
Depending on where you live, you may have some or all of the following rights:
- Access — a copy of the personal information we hold about you.
- Correction — to have inaccurate or incomplete information corrected.
- Deletion — to have your information erased where there is no continuing lawful basis to keep it.
- Restriction and objection — to limit or object to processing, including processing based on legitimate interests and direct marketing.
- Portability — to receive certain information in a structured, machine-readable format.
- Withdrawal of consent — at any time, without affecting processing carried out before withdrawal.
- Complaint — to your local supervisory authority or data protection regulator.
If you are a California resident, you also have the right to know what personal information we collect, use and disclose, the right to delete and correct it, the right to opt out of sale or sharing (we do neither), and the right not to be discriminated against for exercising these rights.
If you are in India, you have the rights of access, correction, erasure, grievance redressal and nomination available under the Digital Personal Data Protection Act.
To exercise any right, contact us using the details in section 16. We will respond within the time limits set by applicable law, and we may need to verify your identity before acting on a request. If your information is held on behalf of one of our clients, we will refer your request to that client and support them in responding.
12Marketing communications
We may send business-related emails about our services, research and white papers to business contacts. Every marketing email contains an unsubscribe link, and you can also opt out at any time by replying to any message you receive from us. Opting out of marketing does not stop operational messages relating to an active engagement, such as project updates and invoices.
13Children's privacy
Our website and services are intended for businesses and for people aged 18 and over. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us and we will delete it.
14Third-party websites
Our site links to and embeds content from third-party services, including scheduling tools, video platforms and professional networks. Those services have their own privacy policies and we are not responsible for their practices. We encourage you to read them before providing information.
15Changes to this policy
We may update this policy as our services, tooling or legal obligations change. The effective date at the top of this page shows when it was last revised. Where a change materially affects your rights, we will take reasonable steps to notify you, such as by email or a notice on the site. Continuing to use the site after an update means you accept the revised policy.
16How to contact us
For any question, request or complaint about privacy or this policy, contact us by post or telephone using the details below, or through the contact form on our website. If you are not satisfied with our response, you may raise the matter with your local data protection authority.