Data handling

Privacy
Policy

How Ayin handles the information you share. Written plainly — because a privacy policy that needs a lawyer to read is not a privacy policy.

ControllerAyin (ayin.group)
Contacthello@ayin.group
FrameworkUK GDPR · EU GDPR · CCPA/CPRA
StatusIn force — last reviewed 23 Jun 2026
The short version — read this first

Six answers.
No fog.

Everything else is the detail. Start here.

What do you collect?
Only what you give us — name, email, business name, and any note you add in the contact form. Nothing scraped, nothing inferred.
Do you sell or share my data?
Never. We do not sell, rent, trade, or "share" personal information as those terms are defined under UK/EU GDPR or the CCPA/CPRA. Ever.
Do you use cookies?
Minimal. No advertising or tracking cookies. See Clause 5 for the full breakdown.
Do you use AI on my data?
No. Your personal information is not fed into any AI system — ours or anyone else's — to train, fine-tune, or generate output.
How long do you keep it?
Contact enquiries: 24 months, or until you ask us to delete. Client engagement data: 6 years from end of engagement (legal requirement). See Clause 8.
What are my rights?
Access, correction, deletion, restriction, portability, objection — and California-specific rights if you're a CA resident. Write to hello@ayin.group — we respond within 30 days.
§ Privacy · DOC-002
01

Who we are

Ayin is an international advisory and compliance practice. We help businesses and individuals secure market access, platform standing, and cross-border standing across regulated environments.

For the purposes of data protection law, Ayin is the data controller in respect of personal information collected through this website and in the course of client engagements, except where we expressly process data as a processor on a Client's instructions (see Clause 2).

You can reach us at: hello@ayin.group

02

What information we collect and why

Through the contact form on this site

When you submit the intake form on ayin.group, we collect: your name, your business name, your email address, and any note you choose to add. We also receive — if you completed the Exposure Instrument before submitting — a summary of your mapped crossing.

We collect this so we can respond to your enquiry and understand the context of your business before we do.

During an engagement

In the course of an engagement, we may receive and process information about your business, its products, its supply chain, its staff, its account history, and its regulatory or platform standing — as necessary to build the standing and documentation you have engaged us for.

Where this information includes personal data about individuals other than you, we process that data on your behalf, under your instruction, as a data processor. The specific terms of that processing are covered in our Terms of Service and, where applicable, a separate Data Processing Addendum.

Site analytics

We may collect anonymised information about how visitors use this site — pages visited, time on page, referral source — using privacy-respecting tools that do not identify you personally. See Clause 5 for the specifics.

We do not collect information we do not need. We do not infer, score, or profile site visitors beyond the Exposure Instrument's own on-screen, session-only logic. The data minimisation principle is not just a compliance obligation for us — it is how we operate.

03

Lawful basis for processing

Under UK GDPR and EU GDPR, we are required to identify a lawful basis for each type of processing. Ours are straightforward:

  • Contact form submissions: Legitimate interest — specifically, the legitimate interest of responding to enquiries about our services. We have assessed that this interest is not overridden by your rights, given the limited data involved and the fact that you initiated the contact.
  • Engagement data (as controller): Contract — processing is necessary for the performance of the contract between us, or to take steps at your request before entering into a contract.
  • Engagement data (as processor): Your lawful basis, under your instructions. We do not establish an independent basis for processing personal data we handle on your behalf.
  • Analytics: Legitimate interest — understanding how this site is used so we can improve it — with appropriate safeguards (anonymisation, no cross-site tracking).
  • Legal obligations: Compliance with applicable law — for example, retaining financial and engagement records, or responding to a lawful Authority request.
04

How we use your information

We use the information we collect only for the purposes described here:

  • To respond to your enquiry and, if appropriate, to arrange an engagement.
  • To provide the Services agreed under an engagement, including correspondence with Authorities on your behalf where instructed.
  • To maintain records of the engagement as required by applicable law and our own governance standards.
  • To send engagement-related communications — updates on progress, delivery of Deliverables, invoices.
  • To improve this site and the way we communicate what we offer.

We do not use your information for marketing without your explicit consent. We do not send newsletters. We do not add you to mailing lists.

We do not use your information to train or fine-tune any AI system, including our own tools, and we do not transmit personal data to a third-party AI system except where a sub-processor's own infrastructure (see Clause 6) uses it solely to deliver the service we've engaged it for.

05

Cookies and site analytics

CategoryWhat it does
Strictly necessaryThis site uses no cookies for session management, authentication, or shopping baskets — there are no such features. Any strictly necessary cookies that arise from third-party form processing are subject to those processors' own policies.
AnalyticsWhere used, we rely on privacy-first tools that do not set persistent tracking cookies, do not fingerprint devices, and do not share data with advertising networks.
AdvertisingNone. We do not use advertising cookies, behavioural advertising networks, or third-party trackers on this site.
PreferenceNone at present. If introduced (for example, a language or unit preference), they will be listed here before deployment.

You can control cookies through your browser settings. Because we use minimal cookies, disabling them will not materially affect your experience of this site. We do not currently distinguish or honour browser-level "Do Not Track" signals because we set none of the cookies such signals are designed to block; we do, however, honour the Global Privacy Control signal as an opt-out request under the CCPA/CPRA — see Clause 10.

06

Who we share data with

We do not sell, rent, or trade your personal information. Full stop. The table below lists every processor that touches personal data collected through this site or an engagement, what it does, and where it sits.

The data flow ledger — every processor, scoped
ProcessorRoleLocationSafeguard
FormspreeContact form handling
Receives and routes intake form submissions to Ayin
United States
EU–US Data Privacy Framework / UK extension; deleted from Formspree's servers within 30 days of receipt
Site hosting providerStatic site delivery
Serves this website; processes server logs (IP, timestamp, user agent)
EU / Global CDN
Standard Contractual Clauses where applicable; logs rotated on a short retention cycle
Email service providerCorrespondence
Delivers and stores email correspondence with enquirers and Clients
EU / UK
Provider's own GDPR-compliant infrastructure; access limited to Ayin personnel
Professional advisersAccounting · legal
Limited access where required for compliance, audit, or legal obligations
Per adviser's jurisdiction
Bound by professional confidentiality obligations

This ledger is reviewed whenever a processor changes. If you'd like the current list confirmed before relying on it, write to hello@ayin.group.

Legal requirement

Where required by law, court order, or regulatory requirement, we may be obliged to disclose information. Where legally permissible, we will notify you before doing so.

07

International transfers

Where data is transferred outside the UK or EEA — for example, to a processor based in the United States — we ensure appropriate safeguards are in place. For transfers to the US, this means relying on Standard Contractual Clauses (SCCs), the UK International Data Transfer Agreement (IDTA), or the EU–US Data Privacy Framework, as applicable to the specific processor.

Formspree, our form processor, is based in the United States. Their transfers are covered by the EU–US Data Privacy Framework and equivalent UK mechanisms where applicable.

We do not transfer client engagement data internationally beyond what is reasonably necessary to perform the engagement, and never without an appropriate safeguard in place.

08

How long we keep data

We keep personal information only as long as necessary for the purposes for which it was collected, or as required by law.

  • Contact enquiries that do not become engagements: 24 months from the date of the enquiry, after which we delete. You can request earlier deletion at any time.
  • Engagement records (financial and contractual): 6 years from the end of the engagement, as required by financial and tax law in most jurisdictions.
  • Engagement work product containing personal data: Returned to the Client or deleted within 60 days of engagement completion, unless the Client instructs otherwise or retention is required for an active Authority matter.
  • Authority correspondence held in an advisory-agent capacity: Retained for the period required by the relevant regime or platform, then deleted or returned per the Client's instruction.
  • Anonymised analytics data: Rolling 24-month window, after which earlier data is deleted or aggregated to the point of non-identifiability.
09

Your rights — UK & EU

Under UK GDPR and EU GDPR, you have the following rights in relation to your personal data:

RightWhat it means
AccessYou can ask us what personal data we hold about you and receive a copy of it.
CorrectionYou can ask us to correct inaccurate or incomplete personal data.
ErasureYou can ask us to delete your personal data, subject to our legal obligations to retain certain records.
RestrictionYou can ask us to pause processing your data in certain circumstances — for example, while we investigate a complaint.
PortabilityYou can ask for your data in a structured, machine-readable format to take to another provider, where processing is based on consent or contract.
ObjectionYou can object to processing based on legitimate interest. We will stop unless we have compelling grounds that override your interests.
Automated decisionsYou have the right not to be subject to solely automated decision-making with significant effects. See Clause 12.

To exercise any of these rights, write to hello@ayin.group. We respond within 30 days, and may need to verify your identity before acting on certain requests.

10

Your California privacy rights

If you are a California resident, the California Consumer Privacy Act, as amended by the California Privacy Rights Act (CCPA/CPRA), gives you the rights below in addition to anything described elsewhere in this policy.

Categories collected, in the last 12 months

Identifiers (name, email address, business name); and, where you choose to provide it, commercial information you include in a free-text enquiry. We do not collect biometric information, precise geolocation, or sensitive personal information as defined by the CPRA.

RightWhat it means
To knowYou can ask what personal information we have collected, used, disclosed, and the categories of source and recipient.
To deleteYou can ask us to delete personal information we hold about you, subject to legal retention obligations.
To correctYou can ask us to correct inaccurate personal information.
To opt out of sale/sharingNot applicable — we do not sell or "share" (as the CPRA defines that term, including for cross-context behavioural advertising) personal information, so there is nothing to opt out of.
To limit use of sensitive PINot applicable — we do not collect sensitive personal information as defined by the CPRA.
Non-discriminationWe will not deny services, charge different prices, or provide a different quality of service because you exercised a privacy right.

We honour the Global Privacy Control signal as a valid opt-out preference signal where applicable. You may also designate an authorised agent to submit a request on your behalf; we may require proof of that authorisation before acting on it.

To exercise a California right, write to hello@ayin.group with the subject line "California privacy request."

11

Security and breach notification

We take appropriate technical and organisational measures to protect personal data against unauthorised access, loss, destruction, or alteration. These include:

  • Access controls limiting who within Ayin can access personal data, on a need-to-know basis.
  • Encrypted transmission of data (this site uses HTTPS) and encryption of data at rest where supported by our processors.
  • Using reputable, security-audited processors for form handling, hosting, and email.
  • Periodic review of our own security posture and processor list.

No system is without risk. In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will: (1) contain and assess the breach without undue delay; (2) notify the relevant supervisory authority within 72 hours of becoming aware, where required; and (3) notify affected individuals directly without undue delay where the breach is likely to result in a high risk to their rights and freedoms, describing the nature of the breach, the likely consequences, and the measures taken or proposed.

Ayin builds standing and compliance infrastructure for other organisations. We hold ourselves to the same standard we build for others.

12

Automated decision-making

We do not make decisions about you — or about whether to take on an engagement — using solely automated means with legal or similarly significant effect.

The Exposure Instrument on this site is a self-serve heuristic tool. Any inputs you give it are processed in your browser session to generate an illustrative readout; that readout is not stored against your identity unless you separately submit it through the contact form, and it is never used to make a decision about you — it is offered for your own orientation only. See our Disclaimer for the limits of that tool.

13

Children

This site and Ayin's services are directed at businesses and their representatives — not at individuals under 18. We do not knowingly collect personal data from anyone under 18, and we do not knowingly sell or share the personal information of anyone under 16.

If you believe we have inadvertently received data from a person under 18, please contact us at hello@ayin.group and we will delete it promptly.

14

Changes to this policy

This policy will be updated as our services develop or as the regulatory landscape requires. When we make material changes, we will update the "last reviewed" date at the top of this page.

Where a change materially affects how we process data from existing clients or contacts, we will notify those individuals directly.

The current version of this policy is always at ayin.group/privacy.

15

Complaints and supervisory authority

If you have a complaint about how we handle your personal data, please contact us first at hello@ayin.group. We take complaints seriously and will investigate and respond promptly.

If you remain unsatisfied, you have the right to lodge a complaint with the relevant supervisory authority:

  • United Kingdom: Information Commissioner's Office (ICO) — ico.org.uk
  • European Union: Your local Data Protection Authority — edpb.europa.eu
  • California: California Privacy Protection Agency — cppa.ca.gov
Privacy contact: hello@ayin.group