Solvant
Solutions
AI as a ServiceDigital TransformationCustom Software
WorkHow we work
About
AboutSecurityContact
BlogsTalk to us

Privacy Policy

Effective date: 4 August 2026
Last updated: 4 August 2026
Version: 1.0  |  Governing law: England & Wales

1. Introduction

This Privacy Policy explains how Solvant ("we", "us", "our") collects, uses, shares and protects personal data when you visit solvant.io, engage our AI consultancy services, or otherwise interact with us.

We are committed to protecting your privacy and handling your personal data in an open and transparent manner, in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations 2003 (PECR).

For the purposes of applicable data protection law, Solvant is the data controller in respect of the personal data described in this policy, except where we act as a data processor on behalf of our clients (see Section 11).

2. Who We Are and How to Contact Us

If you have any questions about this policy or wish to exercise your rights, you can contact us using the details below:

Data controllerSolvant
Data protection contactSolvant Privacy Team
Emailhello@solvant.io

3. The Personal Data We Collect

We collect and process the following categories of personal data:

3.1 Information you provide directly

  • Identity and contact data — name, job title, employer, email address, telephone number and postal address.
  • Engagement data — information you provide when scoping a consultancy project, including business requirements, objectives and correspondence.
  • Account data — credentials and preferences where you register for a client portal or service.
  • Communications — the content of emails, messages, call notes and meeting records exchanged with us.

3.2 Information we collect automatically

  • Technical data — IP address, browser type and version, device identifiers, operating system and time-zone setting.
  • Usage data — information about how you use our website and services, including pages visited and interaction patterns.
  • Cookie data — collected via cookies and similar technologies as described in our Cookie Policy.

3.3 Client project data

In the course of delivering AI consultancy, we may process datasets provided by our clients that contain personal data of third parties (for example, a client's customer or employee records used to train, test or evaluate an AI model). Where this occurs, we act as a processor and process such data strictly on the client's documented instructions under a written data processing agreement (see Section 11).

3.4 Special category data

We do not routinely collect special category data (such as data revealing health, ethnicity, or political opinions). Where a client engagement requires processing of special category data, we will only do so where a lawful condition under Article 9 UK GDPR applies and under appropriate contractual safeguards.

4. How and Why We Use Your Personal Data

We only use your personal data where the law allows us to. The table below sets out the purposes for which we process personal data and the lawful bases we rely on.

PurposeLawful basis
To respond to enquiries and provide information about our servicesLegitimate interests; steps prior to entering a contract
To deliver and manage AI consultancy engagementsPerformance of a contract
To send service communications and updatesPerformance of a contract; legitimate interests
To send marketing communicationsConsent; legitimate interests (existing clients)
To operate, secure and improve our website and servicesLegitimate interests
To comply with legal, regulatory and tax obligationsLegal obligation
To establish, exercise or defend legal claimsLegitimate interests

Where we rely on legitimate interests, we have carried out a balancing assessment to ensure our interests are not overridden by your rights. You may request further details of that assessment using the contact details above.

5. Marketing and Your Choices

We may send you marketing about services similar to those you have received from us, or which we believe may be of interest to your business, where permitted by law. You can opt out of marketing at any time by using the unsubscribe link in any marketing email or by contacting us. Opting out of marketing will not affect service communications relating to an active engagement.

6. Cookies and Similar Technologies

Our website uses cookies and similar technologies to function correctly, analyse usage and, where you consent, support marketing. Full details of the cookies we use, their purpose and duration, and how to manage your preferences, are set out in our separate Cookie Policy.

7. Who We Share Your Personal Data With

We may share your personal data with the following categories of recipients, always subject to appropriate safeguards and only where necessary:

  • Service providers and sub-processors — including cloud hosting, IT infrastructure, AI model and API providers, analytics, email and CRM platforms.
  • Professional advisers — lawyers, accountants, auditors and insurers.
  • Regulators and authorities — where required by law or to protect our rights.
  • Business transfers — in connection with a merger, acquisition or sale of assets, in which case personal data may be disclosed to the counterparty subject to confidentiality.

We require all third parties to respect the security of your personal data and to treat it in accordance with the law. We do not permit our service providers to use your personal data for their own purposes and only permit them to process it for specified purposes and in accordance with our instructions.

8. Artificial Intelligence and Automated Processing

As an AI consultancy, we design, build and deploy AI systems for our clients. We want to be transparent about how this may involve personal data:

  • We may use third-party AI models and platforms to deliver our services. Where personal data is submitted to such platforms, we take steps to ensure appropriate contractual and technical safeguards are in place, including, where available, options that exclude your data from being used to train the provider's models.
  • We do not make solely automated decisions that produce legal or similarly significant effects concerning you without a lawful basis and appropriate safeguards under Article 22 UK GDPR.
  • Where we process client data to develop or evaluate AI systems, we act on the client's instructions and apply data minimisation, pseudonymisation and access controls as appropriate.

9. International Transfers

Some of our service providers are based outside the UK, which may involve transferring your personal data to countries that do not offer the same level of data protection. Where we transfer personal data outside the UK, we ensure a similar degree of protection by relying on one of the following safeguards:

  • Transfers to countries the UK Government has deemed to provide an adequate level of protection; or
  • The use of the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses, together with a transfer risk assessment where required.

You may request a copy of the relevant safeguards by contacting us.

10. How Long We Keep Your Personal Data

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including to satisfy legal, accounting or reporting requirements. In general:

  • Enquiry and prospect data — retained for up to 24 months from last contact.
  • Client engagement records — retained for the duration of the engagement and for 6 years afterwards, in line with limitation periods and tax requirements.
  • Marketing preferences — retained until you opt out and thereafter as a suppression record.

When personal data is no longer required, we securely delete or anonymise it.

11. When We Act as a Data Processor

Where we process personal data on behalf of a client in the course of delivering our services, the client is the data controller and we are the data processor. In those circumstances:

  • We process personal data only on the client's documented instructions;
  • We enter into a written data processing agreement compliant with Article 28 UK GDPR;
  • We implement appropriate technical and organisational security measures;
  • We assist the client in responding to data subject requests and in meeting their own compliance obligations;
  • We engage sub-processors only with the client's authorisation and under equivalent contractual terms.

If you are a data subject whose personal data we process on behalf of a client, please direct any requests to that client as the controller; we will support them in responding.

12. Your Data Protection Rights

Under the UK GDPR, you have the following rights in relation to your personal data:

  1. The right to be informed about how we use your personal data.
  2. The right of access to a copy of the personal data we hold about you.
  3. The right to rectification of inaccurate or incomplete data.
  4. The right to erasure (the "right to be forgotten") in certain circumstances.
  5. The right to restrict processing in certain circumstances.
  6. The right to data portability for data you have provided to us.
  7. The right to object to processing based on legitimate interests or for direct marketing.
  8. Rights relating to automated decision-making and profiling.
  9. The right to withdraw consent at any time where we rely on consent.

To exercise any of these rights, please contact us using the details in Section 2. We will respond within one month, though this may be extended by up to two further months for complex requests. There is normally no charge, but we may charge a reasonable fee or refuse a request that is manifestly unfounded or excessive.

13. Security

We have implemented appropriate technical and organisational measures to protect personal data against unauthorised or unlawful processing, accidental loss, destruction or damage. These include access controls, encryption in transit and at rest where appropriate, staff training, and supplier due diligence. We have procedures to deal with any suspected personal data breach and will notify you and the ICO where we are legally required to do so.

14. Third-Party Links

Our website may include links to third-party websites, plug-ins and applications. Clicking on those links may allow third parties to collect or share data about you. We do not control these third-party websites and are not responsible for their privacy statements. We encourage you to read the privacy policy of every website you visit.

15. Complaints

You have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK supervisory authority for data protection issues, at www.ico.org.uk or by calling 0303 123 1113. We would, however, appreciate the chance to address your concerns before you approach the ICO, so please contact us in the first instance.

16. Changes to This Policy

We keep this Privacy Policy under regular review. Any changes will be posted on this page with an updated "Last updated" date. Where changes are significant, we will provide a more prominent notice. Please check this policy periodically to stay informed.

Solvant
Privacy policyCookie policyTerms of serviceTerms & conditions

© 2026 Solvant. All rights reserved.

We use cookies to ensure you get the best experience on our website. By continuing to use our site, you agree to our Privacy policy andCookie policy.