aethis.ai/legal

Privacy

Privacy notice

Last updated: 2026-05-10

Scope

This notice covers personal data handled by Aethis Limited (“Aethis”) when you visit aethis.ai, sign up for the developer dashboard, or call the public API on api.aethis.ai. It is written for the developer-facing infrastructure surface.

Personal data that you process through the API as a customer is governed by our Data Processing Addendum, available at legal@aethis.ai. The immigration product at aethis.legal has its own separate privacy notice.

Controller

Aethis Limited (Company No. 16627732), registered in England and Wales, is the data controller for personal data covered by this notice.

Contact: privacy@aethis.ai.

What we collect

Information you provide:

  • Account data when you sign up for the developer dashboard: name, email, organisation.
  • Form submissions, including pilot or developer-access enquiries.
  • Email correspondence you send to us.

Information collected automatically:

  • Server logs from API calls: timestamp, endpoint, response status, IP address, API key identifier.
  • Aggregated usage analytics from the marketing site.
  • Browser-set cookies for authentication and consent state.

Why we process it

  • To operate the API, dashboard, and marketing site (contract / legitimate interests).
  • To authenticate users and prevent abuse of the API (legitimate interests).
  • To respond to enquiries and pilot requests (legitimate interests).
  • To send product updates you have opted in to (consent).
  • To meet legal, tax, and accounting obligations (legal obligation).

We do not use personal data covered by this notice to train any AI or machine-learning model.

Sharing

We share personal data with the sub-processors listed at /subprocessors (hosting, identity, observability, and email). We do not sell personal data and we do not share it for advertising.

We may disclose data where required by law, to enforce our terms, or to protect the rights, property, or safety of Aethis, our users, or others.

International transfers

Core application data is hosted in the United Kingdom or European Union. Some sub-processors operate in the United States. Where data is transferred outside the UK we rely on UK International Data Transfer Agreements, the EU Standard Contractual Clauses, or adequacy regulations.

Retention

  • Account data: for the life of the account, plus up to 12 months after closure.
  • API request logs: 90 days, then aggregated or deleted.
  • Enquiry and pilot correspondence: up to 24 months from last contact.
  • Records held to meet legal or tax obligations: as required by law.

Your rights

Under UK GDPR you have the right to:

  • Access the personal data we hold about you.
  • Correct inaccurate or incomplete data.
  • Erase your data, where the legal basis allows.
  • Restrict or object to processing.
  • Receive a copy of data you have provided in a portable format.
  • Withdraw consent at any time, where processing is based on consent.

Exercise these rights by emailing privacy@aethis.ai. You also have the right to complain to the Information Commissioner's Office (ico.org.uk).

Cookies and analytics

aethis.ai uses essential cookies for sign-in and session management, and a privacy-friendly analytics service (Vercel Analytics) that does not set cookies or fingerprint visitors. Optional product analytics, where used, are loaded only with your consent.

Changes

We will post material changes to this notice on this page and update the “Last updated” date above. Continued use of the service after a change indicates acceptance.