How Ayin handles the information you share. Written plainly — because a privacy policy that needs a lawyer to read is not a privacy policy.
Everything else is the detail. Start here.
Ayin is an international advisory and compliance practice. We help businesses and individuals secure market access, platform standing, and cross-border standing across regulated environments.
For the purposes of data protection law, Ayin is the data controller in respect of personal information collected through this website and in the course of client engagements, except where we expressly process data as a processor on a Client's instructions (see Clause 2).
You can reach us at: hello@ayin.group
When you submit the intake form on ayin.group, we collect: your name, your business name, your email address, and any note you choose to add. We also receive — if you completed the Exposure Instrument before submitting — a summary of your mapped crossing.
We collect this so we can respond to your enquiry and understand the context of your business before we do.
In the course of an engagement, we may receive and process information about your business, its products, its supply chain, its staff, its account history, and its regulatory or platform standing — as necessary to build the standing and documentation you have engaged us for.
Where this information includes personal data about individuals other than you, we process that data on your behalf, under your instruction, as a data processor. The specific terms of that processing are covered in our Terms of Service and, where applicable, a separate Data Processing Addendum.
We may collect anonymised information about how visitors use this site — pages visited, time on page, referral source — using privacy-respecting tools that do not identify you personally. See Clause 5 for the specifics.
We do not collect information we do not need. We do not infer, score, or profile site visitors beyond the Exposure Instrument's own on-screen, session-only logic. The data minimisation principle is not just a compliance obligation for us — it is how we operate.
Under UK GDPR and EU GDPR, we are required to identify a lawful basis for each type of processing. Ours are straightforward:
We use the information we collect only for the purposes described here:
We do not use your information for marketing without your explicit consent. We do not send newsletters. We do not add you to mailing lists.
We do not use your information to train or fine-tune any AI system, including our own tools, and we do not transmit personal data to a third-party AI system except where a sub-processor's own infrastructure (see Clause 6) uses it solely to deliver the service we've engaged it for.
| Category | What it does |
|---|---|
| Strictly necessary | This site uses no cookies for session management, authentication, or shopping baskets — there are no such features. Any strictly necessary cookies that arise from third-party form processing are subject to those processors' own policies. |
| Analytics | Where used, we rely on privacy-first tools that do not set persistent tracking cookies, do not fingerprint devices, and do not share data with advertising networks. |
| Advertising | None. We do not use advertising cookies, behavioural advertising networks, or third-party trackers on this site. |
| Preference | None at present. If introduced (for example, a language or unit preference), they will be listed here before deployment. |
You can control cookies through your browser settings. Because we use minimal cookies, disabling them will not materially affect your experience of this site. We do not currently distinguish or honour browser-level "Do Not Track" signals because we set none of the cookies such signals are designed to block; we do, however, honour the Global Privacy Control signal as an opt-out request under the CCPA/CPRA — see Clause 10.
We do not sell, rent, or trade your personal information. Full stop. The table below lists every processor that touches personal data collected through this site or an engagement, what it does, and where it sits.
This ledger is reviewed whenever a processor changes. If you'd like the current list confirmed before relying on it, write to hello@ayin.group.
Where required by law, court order, or regulatory requirement, we may be obliged to disclose information. Where legally permissible, we will notify you before doing so.
Where data is transferred outside the UK or EEA — for example, to a processor based in the United States — we ensure appropriate safeguards are in place. For transfers to the US, this means relying on Standard Contractual Clauses (SCCs), the UK International Data Transfer Agreement (IDTA), or the EU–US Data Privacy Framework, as applicable to the specific processor.
Formspree, our form processor, is based in the United States. Their transfers are covered by the EU–US Data Privacy Framework and equivalent UK mechanisms where applicable.
We do not transfer client engagement data internationally beyond what is reasonably necessary to perform the engagement, and never without an appropriate safeguard in place.
We keep personal information only as long as necessary for the purposes for which it was collected, or as required by law.
Under UK GDPR and EU GDPR, you have the following rights in relation to your personal data:
| Right | What it means |
|---|---|
| Access | You can ask us what personal data we hold about you and receive a copy of it. |
| Correction | You can ask us to correct inaccurate or incomplete personal data. |
| Erasure | You can ask us to delete your personal data, subject to our legal obligations to retain certain records. |
| Restriction | You can ask us to pause processing your data in certain circumstances — for example, while we investigate a complaint. |
| Portability | You can ask for your data in a structured, machine-readable format to take to another provider, where processing is based on consent or contract. |
| Objection | You can object to processing based on legitimate interest. We will stop unless we have compelling grounds that override your interests. |
| Automated decisions | You have the right not to be subject to solely automated decision-making with significant effects. See Clause 12. |
To exercise any of these rights, write to hello@ayin.group. We respond within 30 days, and may need to verify your identity before acting on certain requests.
If you are a California resident, the California Consumer Privacy Act, as amended by the California Privacy Rights Act (CCPA/CPRA), gives you the rights below in addition to anything described elsewhere in this policy.
Identifiers (name, email address, business name); and, where you choose to provide it, commercial information you include in a free-text enquiry. We do not collect biometric information, precise geolocation, or sensitive personal information as defined by the CPRA.
| Right | What it means |
|---|---|
| To know | You can ask what personal information we have collected, used, disclosed, and the categories of source and recipient. |
| To delete | You can ask us to delete personal information we hold about you, subject to legal retention obligations. |
| To correct | You can ask us to correct inaccurate personal information. |
| To opt out of sale/sharing | Not applicable — we do not sell or "share" (as the CPRA defines that term, including for cross-context behavioural advertising) personal information, so there is nothing to opt out of. |
| To limit use of sensitive PI | Not applicable — we do not collect sensitive personal information as defined by the CPRA. |
| Non-discrimination | We will not deny services, charge different prices, or provide a different quality of service because you exercised a privacy right. |
We honour the Global Privacy Control signal as a valid opt-out preference signal where applicable. You may also designate an authorised agent to submit a request on your behalf; we may require proof of that authorisation before acting on it.
To exercise a California right, write to hello@ayin.group with the subject line "California privacy request."
We take appropriate technical and organisational measures to protect personal data against unauthorised access, loss, destruction, or alteration. These include:
No system is without risk. In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will: (1) contain and assess the breach without undue delay; (2) notify the relevant supervisory authority within 72 hours of becoming aware, where required; and (3) notify affected individuals directly without undue delay where the breach is likely to result in a high risk to their rights and freedoms, describing the nature of the breach, the likely consequences, and the measures taken or proposed.
Ayin builds standing and compliance infrastructure for other organisations. We hold ourselves to the same standard we build for others.
We do not make decisions about you — or about whether to take on an engagement — using solely automated means with legal or similarly significant effect.
The Exposure Instrument on this site is a self-serve heuristic tool. Any inputs you give it are processed in your browser session to generate an illustrative readout; that readout is not stored against your identity unless you separately submit it through the contact form, and it is never used to make a decision about you — it is offered for your own orientation only. See our Disclaimer for the limits of that tool.
This site and Ayin's services are directed at businesses and their representatives — not at individuals under 18. We do not knowingly collect personal data from anyone under 18, and we do not knowingly sell or share the personal information of anyone under 16.
If you believe we have inadvertently received data from a person under 18, please contact us at hello@ayin.group and we will delete it promptly.
This policy will be updated as our services develop or as the regulatory landscape requires. When we make material changes, we will update the "last reviewed" date at the top of this page.
Where a change materially affects how we process data from existing clients or contacts, we will notify those individuals directly.
The current version of this policy is always at ayin.group/privacy.
If you have a complaint about how we handle your personal data, please contact us first at hello@ayin.group. We take complaints seriously and will investigate and respond promptly.
If you remain unsatisfied, you have the right to lodge a complaint with the relevant supervisory authority: