Skip to main content

qubisec.com

Privacy notice aligned to UK data protection principles

Privacy Policy

This privacy policy explains how QUBiSEC collects, uses, stores and protects personal information when you visit our website, contact us, request information, book a discovery call or discuss our AI solutions.

1. Who we are

QUBiSEC is a UK-focused AI solutions company. We provide information about AI agents, healthcare AI, CareVoice AI, SME automation and enterprise AI advisory through this website and through direct communication with prospective clients, partners and stakeholders.

For personal data collected through this website, contact forms, email enquiries and discovery call requests, QUBiSEC is normally the data controller. This means we decide why and how this personal data is used.

Contact: qubisec.contact@gmail.com | Phone: +44 7780 272 373 | Location: Milton Keynes, United Kingdom.

2. Scope of this policy

This privacy policy applies when you:

  • visit or browse the QUBiSEC website;
  • submit a contact form, discovery call request or enquiry;
  • email or call QUBiSEC;
  • discuss a potential pilot, demo, advisory engagement or service requirement;
  • interact with QUBiSEC content, resources or marketing communications.

If QUBiSEC provides services to an organisation under a separate contract, additional data protection terms, data processing agreements, service schedules or client-specific privacy notices may also apply.

3. Personal data we may collect

We only aim to collect information that is relevant to our website, enquiries, business communication, service delivery and legal obligations.

Category Examples How we collect it
Identity and contact data Name, work email, phone number, job title, organisation name. Contact forms, email, phone calls, discovery call requests and direct communication.
Business and enquiry data Organisation type, area of interest, current workflow challenges, service requirements and project context. Forms, calls, meetings, emails, proposals and pilot discussions.
Communication data Emails, call notes, meeting notes, enquiry history and follow-up records. When you communicate with us or when we follow up on your request.
Technical and website data IP address, browser type, device type, pages visited, approximate location, referral source and interaction data. Website hosting, analytics, security logs and cookies where enabled.
Marketing preference data Newsletter interest, consent status, opt-out preferences and communication preferences. Subscription forms, email preferences and direct requests.
Important healthcare data note

Please do not submit patient-level health information, medical records, urgent clinical concerns or confidential care information through general website contact forms.

4. How we use personal data

We may use personal data to:

  • respond to enquiries and contact requests;
  • arrange discovery calls, demos, pilot discussions or advisory meetings;
  • understand your organisation’s needs and assess whether QUBiSEC can support you;
  • prepare proposals, service information or follow-up materials;
  • provide, manage and improve our website and services;
  • manage client relationships, records and operational administration;
  • send relevant business updates where permitted by law;
  • protect our website, systems, users and business from misuse, security incidents or fraud;
  • meet legal, regulatory, accounting and compliance obligations.

5. Lawful bases for processing

Under UK data protection law, we must have a lawful basis for using personal data. The lawful basis depends on the activity.

Purpose Likely lawful basis Explanation
Responding to enquiries Legitimate interests or steps before entering into a contract We need to respond when you contact us about QUBiSEC, CareVoice AI or our services.
Discovery calls, proposals and service discussions Steps before entering into a contract or legitimate interests We use relevant information to understand requirements and prepare appropriate responses.
Providing contracted services Contract or legitimate interests We process relevant business contact and project data to deliver agreed services.
Legal, tax, accounting or compliance records Legal obligation We may need to keep certain records to comply with applicable laws and regulations.
Website security and fraud prevention Legitimate interests We use limited technical data to keep our website and systems secure.
Optional marketing communications Consent or legitimate interests, depending on context You can unsubscribe or object to direct marketing at any time.

6. Healthcare and special category data

Some QUBiSEC services relate to healthcare communication workflows. However, this website is not intended to collect patient-level health information, clinical records or urgent medical information.

If QUBiSEC is involved in a healthcare pilot or service where special category data may be processed, we will agree appropriate written terms with the client before processing begins. This may include a data processing agreement, clear roles and responsibilities, security controls, retention rules, lawful basis analysis and the relevant UK GDPR Article 9 condition where applicable.

CareVoice AI is designed to support healthcare communication workflows. It does not diagnose, prescribe medication, recommend clinical treatment or replace healthcare professionals. Urgent, sensitive or unclear matters should be escalated to appropriate human teams.

7. Who we may share personal data with

We do not sell personal data. We may share limited personal data where necessary with:

  • website hosting, email, form, CRM, analytics, security and cloud service providers;
  • professional advisers such as accountants, lawyers, consultants or insurers;
  • technology partners or delivery partners where required for a project and where appropriate terms are in place;
  • public authorities, regulators or law enforcement where legally required;
  • a potential buyer, investor or successor organisation if QUBiSEC is involved in a business transfer, subject to appropriate safeguards.

Where we use service providers that process personal data for us, we expect them to protect the data and use it only for agreed purposes.

8. International transfers

Some service providers used for email, website hosting, analytics, communication, cloud storage or security may process personal data outside the United Kingdom.

Where personal data is transferred internationally, we will seek to use appropriate safeguards where required, such as an adequacy decision, the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses or other lawful transfer mechanisms.

9. How long we keep personal data

We keep personal data only for as long as reasonably necessary for the purpose it was collected, including for legal, accounting, reporting, service delivery, security or dispute-resolution purposes.

Data type Indicative retention period
General website enquiries Up to 24 months after the last meaningful contact, unless a longer period is needed for business or legal reasons.
Discovery call and proposal records Up to 24 months, or longer if the enquiry becomes an active client relationship.
Client, contract and invoice records Usually up to 6 years after the end of the relationship, where needed for tax, accounting or legal purposes.
Marketing preferences Until you unsubscribe or ask us to stop, with suppression records retained to respect opt-out requests.
Technical logs and security data Kept for a limited period based on security, troubleshooting and hosting requirements.

10. Your data protection rights

Depending on the circumstances, you may have the following rights under UK data protection law:

A
AccessAsk for a copy of the personal data we hold about you.
R
RectificationAsk us to correct inaccurate or incomplete information.
E
ErasureAsk us to delete personal data in certain circumstances.
L
RestrictionAsk us to limit how we use your personal data in certain cases.
O
ObjectionObject to processing based on legitimate interests or direct marketing.
P
PortabilityAsk for data in a portable format where this right applies.
C
Withdraw consentWithdraw consent where we rely on consent as the lawful basis.
I
ICO complaintComplain to the UK Information Commissioner’s Office if you are concerned.

To exercise your rights, contact us at qubisec.contact@gmail.com. We may need to verify your identity before responding.

11. Cookies and website analytics

Our website may use cookies or similar technologies to make the website work, improve performance, understand how visitors use the site and protect the website from misuse.

Essential cookies may be required for website operation and security. Non-essential analytics, marketing or tracking cookies should only be used where the correct consent or lawful basis is in place.

You can usually control cookies through your browser settings. If we introduce a detailed cookie banner or cookie preference centre, it will provide further information about the cookies used on this website.

12. Security

We use reasonable technical and organisational measures to protect personal data against unauthorised access, loss, misuse, alteration or disclosure. These measures may include access controls, secure hosting, encrypted communication where available, account security practices, data minimisation and supplier due diligence.

No website, email or online service can be guaranteed as completely secure. Please do not send sensitive medical, financial or confidential information through general website contact forms unless we have agreed a secure method with you.

13. Children’s data

QUBiSEC’s website and services are intended for business, healthcare, SME and enterprise audiences. We do not knowingly collect personal data from children through this website.

If you believe a child has provided personal data to us through the website, please contact us so we can review and delete it where appropriate.

14. Changes to this policy

We may update this privacy policy from time to time to reflect changes in our services, website, technology, legal requirements or business operations.

The latest version will be published on this page with the updated date shown near the top of the policy.

15. Contact and complaints

If you have questions about this privacy policy, how QUBiSEC uses personal data, or if you want to exercise your data protection rights, contact us:

You also have the right to complain to the UK Information Commissioner’s Office if you are unhappy with how your personal data is handled. The ICO is the UK supervisory authority for data protection.