Draft — not for publication. This policy has been prepared by an AI assistant and must be reviewed by a qualified solicitor before publication. Items marked “Before publication” throughout this document represent known gaps that must be resolved before this policy is live.
Privacy Policy
Askar Research Ltd
Last updated: [DATE] — Version 3.0 (Draft)
1. Who We Are
Askar Research Ltd (“Askar”, “we”, “us”, “our”) is a company registered in England and Wales under company number 16241609. Our registered office is in Horsham, England.
We operate the website at www.askarresearch.com and provide a market & consumer intelligence agent: an autonomous AI research service that gathers evidence from public sources and business-provided materials, performs analysis, and delivers structured, cited research intelligence to business customers.
Data Controller contact details:
| Company | Askar Research Ltd |
| Company number | 16241609 |
| [email protected] | |
| Website | www.askarresearch.com |
We are the data controller in respect of the personal data described in this policy. We are not currently required to appoint a Data Protection Officer under UK GDPR Article 37. We have assessed our processing activities against the criteria in Article 37 and concluded that appointment is not currently required given the scale of our processing and the nature of the data processed. We will keep this assessment under review as the business grows.
2. Scope of This Policy
This policy explains:
- what personal data we collect about you and why;
- the lawful basis on which we process it;
- how long we retain it;
- who we share it with;
- your rights under UK data protection law; and
- how to exercise those rights or make a complaint.
This policy applies to:
- visitors to our website (www.askarresearch.com);
- registered users of our service; and
- individuals who contact us via our contact form or by email.
Our service is intended for use by businesses and their authorised personnel. It is not directed at individuals under the age of 18. By registering for our service, you confirm that you are 18 or over and are authorised to use the service on behalf of your organisation. We do not knowingly collect personal data from anyone under 18. If you believe a person under 18 has submitted personal data to us, please contact us immediately at [email protected] so we can delete it.
3. The Data We Collect and Why
3.1 Account Registration Data
Data collected: Email address, full name, company name.
Purpose: To create and administer your account; to verify your identity; to provide access to the service; to communicate with you about your account and our services.
Lawful basis: Performance of a contract (UK GDPR Article 6(1)(b)) — processing is necessary to provide the service you have signed up for.
3.2 Authentication Data
Data collected: Password hashes (we do not store your password in plain text), JSON Web Tokens (JWTs), refresh tokens, IP address, and browser user agent string.
Purpose: To authenticate your identity and maintain secure sessions on our service. IP addresses and user agent strings are collected at login and token refresh events to support fraud detection, account security, and security audit logging.
Lawful basis: Performance of a contract (UK GDPR Article 6(1)(b)); legitimate interests (UK GDPR Article 6(1)(f)) — specifically, our legitimate interest in maintaining the security of our service and detecting unauthorised access.
Retention of IP addresses: IP addresses stored in session tokens are deleted within 7 days. IP addresses recorded in our security audit log are retained for:
Before publication: Define retention period for IP addresses in the security audit log — recommend 2 years for security events. Deploy deletion job.
3.3 Security and Audit Logging
Data collected: User account identifiers, action types (e.g., login, password change, account deletion request), timestamps, IP addresses, and browser user agent strings.
Purpose: To maintain an audit trail of security-relevant events; to detect and investigate unauthorised access; to support incident response; to comply with our security obligations.
Lawful basis: Legitimate interests (UK GDPR Article 6(1)(f)) — our legitimate interest in the security and integrity of the service.
Administrative access: Authorised Askar administrators may access user accounts where necessary to provide technical support or investigate security incidents. All such access is logged in our audit system.
Before publication: Define and implement a retention period for the audit log. Indefinite retention cannot be justified under UK GDPR Article 5(1)(e). Recommend: 2 years for routine security events. Deploy deletion job.
3.4 Usage and Research Data
Data collected: Research queries and business context you submit, documents you upload, the reports and research intelligence generated for you, feature interactions, service activity logs, and AI model call inputs and outputs (including the full content of prompts sent to AI models and responses received).
Purpose: To provide the core research service; to improve service performance and accuracy; to diagnose technical issues; and to understand how features are used.
Lawful basis: Performance of a contract (UK GDPR Article 6(1)(b)) for service delivery; legitimate interests (UK GDPR Article 6(1)(f)) for technical diagnostics.
Important — AI model calls: Your research queries, business context, and uploaded document content may be transmitted to third-party AI model providers via OpenRouter, Inc. in order to generate research intelligence. This means the content of your research queries is processed by OpenRouter and, through them, by one or more underlying AI model providers (such as Anthropic, OpenAI, and others). We are working to put contractual protections in place with these providers to prevent your data from being used to train their models; as at the date of this policy, such protections are not confirmed for every provider we use (see Section 4.1). See Section 4.1 and Section 9 for further details.
Note on AI-generated outputs: Our service uses AI models, together with evidence gathered from public sources and any materials you provide, to generate research intelligence in response to your queries. This Output is AI-generated analysis; it is not independently verified fact and does not represent the views of Askar or any third party. Where the content of your research queries or uploaded documents includes personal data about identifiable individuals, you are responsible as a data controller for that data in accordance with your own obligations under UK GDPR. Please refer to Section 9 for further information.
3.5 Payment Data
Data collected: Billing name, billing address, transaction amounts, purchase history (subscription tier and date). We do not store card numbers, CVV codes, or other payment instrument data.
Purpose: To process your subscription and any Credit purchases; to maintain transaction records for accounting and legal compliance purposes; to handle refund or dispute queries.
Lawful basis: Performance of a contract (UK GDPR Article 6(1)(b)); compliance with a legal obligation (UK GDPR Article 6(1)(c)) — specifically, our obligations under tax and accounting law to retain financial records.
Payment card data is processed directly by Stripe, Inc. (our payment processor). Stripe operates under its own privacy policy and acts as an independent data controller for the purposes of card data. Please see stripe.com/gb/privacy for details.
3.6 Website Analytics Data
Data collected: Aggregate usage events — page views, referral source, browser type, device type, operating system, approximate geographic location (country level), and interaction events. We use PostHog (EU Cloud) configured in anonymous, cookieless mode: our analytics set no cookies and store no persistent identifiers on your device, and we do not track you across other websites. Analytics events are not linked to your account or identity.
IP addresses: Your IP address is processed transiently at the point of collection (to derive approximate country-level location and filter automated traffic) and is not stored with analytics events.
Purpose: To understand how visitors use our website; to identify and fix usability issues; to measure the effectiveness of our marketing; to improve the website.
Lawful basis: Legitimate interests (UK GDPR Article 6(1)(f)) — our legitimate interest in understanding and improving our website. Because our analytics set no cookies and store no equivalent identifiers on your device, the consent requirement under the Privacy and Electronic Communications Regulations 2003 (PECR) does not apply to this processing. Only strictly necessary session and authentication cookies are used by the service (see our Cookie Policy).
Before publication: Verify the deployed PostHog configuration matches this section — anonymous/cookieless mode enabled, no cookies or localStorage identifiers set, IP storage disabled — and obtain solicitor confirmation of the PECR position (see solicitor briefing pack, 2026-06-12). Do not publish until verified.
PostHog, Inc. acts as a data processor on our behalf for analytics data, with data hosted in the EU (PostHog EU Cloud). For further information, see posthog.com/privacy.
3.7 Contact Form and Email Enquiries
Data collected: Your name, email address, and the content of your message.
Purpose: To respond to your enquiry; to maintain a record of communications for follow-up purposes.
Lawful basis: Legitimate interests (UK GDPR Article 6(1)(f)) — we have a legitimate interest in responding to business enquiries and maintaining a record of correspondence.
4. How We Share Your Data
We do not sell your personal data. We share personal data only in the following circumstances:
4.1 Third-Party Service Providers (Processors)
We use the following third-party processors to operate our services. Each is engaged on the basis of a data processing agreement or equivalent contractual arrangement:
Before publication: Confirm that data processing agreements are in place with all processors listed below. Current status: DigitalOcean — verify; Stripe — yes; OpenRouter — NOT CONFIRMED (critical blocker); Resend — NOT CONFIRMED; Sentry — NOT CONFIRMED; BetterStack — NOT CONFIRMED; PostHog — verify.
| Processor | Purpose | Data Processed | Location |
|---|---|---|---|
| DigitalOcean LLC | Cloud hosting; servers and managed databases on which the service and your account data are stored | All account, research, and usage data at rest | London, United Kingdom (LON1 region) |
| Stripe, Inc. | Payment processing | Billing name, address, payment intent metadata | United States / United Kingdom (see Section 7) |
| OpenRouter, Inc. | AI model inference routing — your research queries, business context, and document content are transmitted to OpenRouter, which routes them to one or more underlying AI model providers, in order to generate research intelligence | Research query content, business context, document content, AI model prompts and responses | United States (see Section 7) |
| PostHog, Inc. | Website analytics — anonymous, cookieless usage analytics (see Section 3.6) | Aggregate page-view and interaction events; no persistent identifiers | European Union (PostHog EU Cloud) |
| Resend Inc. | Transactional email delivery — sends account verification emails, password reset emails, and other service notifications | Email address, full name (as included in email content), and transactional email content | United States (see Section 7) |
| Sentry (Functional Software Inc.) | Application error monitoring and performance tracing — captures errors and stack traces to help us diagnose and fix technical issues | Account identifiers (user ID), stack traces, request context, and potentially fragments of request data | United States (see Section 7) |
| BetterStack | Application log aggregation — stores structured application logs used for operational monitoring and debugging | Request logs including account identifiers (user ID), request paths, and response status codes. Sensitive fields (passwords, tokens, email addresses) are redacted before logging. | United States (see Section 7) |
OpenRouter sub-processors: OpenRouter routes AI inference requests to third-party model providers (which may include Anthropic, OpenAI, Meta, Mistral, and others depending on configuration). The specific model providers used at any time are determined by our service configuration. Whether underlying providers retain prompt data for training purposes is governed by OpenRouter’s API terms and our arrangements with those providers. We are working to secure contractual no-training commitments from all underlying providers we use; as at the date of this policy, this has not been confirmed for every provider, and we do not represent that your data is never used for training. We will update this section as confirmations are obtained.
4.2 Legal Disclosure
We may disclose personal data if required to do so by law, regulation, or court order, or where necessary to protect the rights, property, or safety of Askar Research Ltd, our users, or others.
4.3 Business Transfers
In the event of a merger, acquisition, sale of assets, or other business reorganisation, personal data may be transferred to the relevant third party. Any such transfer will be subject to appropriate safeguards and will comply with UK GDPR. The acquiring entity will be required to process your data in accordance with this policy or a compatible policy. We will notify you of any such transfer and any resulting changes to this policy.
4.4 Enterprise Customers and Data Processing
When enterprise customers upload research documents, provide business briefs, or submit research queries containing data about their own customers or research subjects, Askar acts as a data processor on behalf of the customer in respect of that data. The customer remains the data controller.
A Data Processing Agreement (DPA) governing Askar’s processing of customer data is available on request. Please contact [email protected] to request a DPA.
4.5 Client Data Isolation and Aggregated Learning
Each customer organisation’s data, documents, and the knowledge Askar derives from them are held in a private, access-controlled scope. Access to that scope is available only through the Service; Askar does not make one customer’s raw Content, documents, or research available to another customer.
Askar may derive general, anonymised, aggregated patterns from usage across its customer base to improve the Service and its shared knowledge base. Such patterns are only incorporated into the shared knowledge base where they have been anonymised and aggregated across a sufficient number of customer organisations (a minimum threshold, currently no fewer than five) that no individual customer, its data, or any individual can reasonably be identified from the pattern. Raw customer data is never incorporated into the shared knowledge base or made available to other customers.
5. Retention Periods
We retain personal data only for as long as necessary for the purposes for which it was collected, taking into account our legal obligations.
| Category | Retention Period | Rationale |
|---|---|---|
| Account data (name, email, company) | Duration of active account, plus 6 years after account closure | Limitation periods under the Limitation Act 1980 (6 years for contract claims); legal obligations |
| Authentication tokens | Session duration (JWTs expire per session); refresh tokens expire after 7 days | Security and session management |
| Password hashes | Duration of active account; deleted upon account deletion | Account security |
| IP addresses (session tokens) | 7 days (token expiry) | Security; minimum necessary |
| Security audit log | [Before publication: Define retention period and deploy deletion job. Recommend 2 years.] | Security compliance; legitimate interests (proportionate to risk) |
| Usage and research data (queries, business context, reports) | [Before publication: Define and implement retention period. Current system retains data indefinitely. Deletion jobs must be deployed before publication.] | Product improvement; support; limitation periods |
| AI model call history (prompts and responses) | [Before publication: Define and implement retention period. Verify automated cleanup job is scheduled and running. Schema provides for 30-day expiry but job not verified as deployed.] | Technical debugging; minimum necessary |
| Payment records (transaction logs, billing details) | 7 years from the end of the relevant financial year | Legal obligation under tax and accounting legislation (Companies Act 2006; HMRC guidance) |
| Analytics data (PostHog, anonymous/cookieless) | [Before publication: Confirm configured PostHog EU Cloud retention period] | Industry standard; minimal retention; no persistent identifiers stored |
| Contact form submissions | 2 years from date of last correspondence | Legitimate interests (follow-up, dispute resolution) |
Database backups: Our cloud infrastructure provider (DigitalOcean) maintains automated encrypted database backups. Deleted data is removed from live databases upon deletion but may persist in encrypted backups for up to [Before publication: Confirm DigitalOcean managed database backup retention window — typically 7 days] days until backup rotation. Backup data is not accessible in normal operations and is used solely for disaster recovery.
When data is no longer required, it is securely deleted or irreversibly anonymised.
6. Your Rights
Under the UK GDPR and the Data Protection Act 2018, you have the following rights in relation to your personal data:
6.1 Right of Access (Article 15)
You have the right to request a copy of the personal data we hold about you, together with information about how we process it. Registered users may also access and export their account data directly via the service.
6.2 Right to Rectification (Article 16)
You have the right to request that we correct any inaccurate or incomplete personal data we hold about you. You can update basic account details directly within the service.
6.3 Right to Erasure (Article 17)
You have the right to request deletion of your personal data where, for example:
- the data is no longer necessary for the purpose it was collected;
- you withdraw consent (where consent is the lawful basis);
- you object to processing and there are no overriding legitimate grounds; or
- the data has been unlawfully processed.
This right is not absolute. We may retain data where required by law (e.g. financial records) or for the establishment, exercise, or defence of legal claims.
Before publication: The current implementation uses a soft-delete on account deletion but the automated hard-deletion job has not yet been deployed. Do not publish this section (or accept deletion requests) until the deletion job is live and verified. Once deployed, insert the actual deletion timeline and confirm the backup retention window.
6.4 Right to Restriction of Processing (Article 18)
You have the right to request that we restrict processing of your personal data in certain circumstances, for example while we verify the accuracy of data you have contested.
6.5 Right to Data Portability (Article 20)
Where processing is based on consent or contract and carried out by automated means, you have the right to receive your personal data in a structured, commonly used, machine-readable format, and to transmit it to another controller.
6.6 Right to Object (Article 21)
You have the right to object at any time to processing of your personal data where the lawful basis is legitimate interests. We will cease processing unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or processing is necessary for legal claims.
You also have the right to object to processing for direct marketing purposes (if applicable). We will always honour such objections without requiring justification.
6.7 Rights in Relation to Automated Decision-Making (Article 22)
See Section 9 below.
6.8 Right to Withdraw Consent
Where processing is based on consent (e.g. analytics cookies), you may withdraw consent at any time without affecting the lawfulness of processing prior to withdrawal.
How to Exercise Your Rights
To exercise any of the above rights, contact us at:
Please include sufficient information to identify yourself (e.g. your registered email address). We will respond within one calendar month of receipt of a valid request. This period may be extended by a further two months for complex or numerous requests, in which case we will notify you within the first month.
We will not charge a fee for handling your request unless it is manifestly unfounded or excessive, in which case we may charge a reasonable administrative fee or refuse to act on the request.
7. International Transfers
Some of our third-party processors are based outside the United Kingdom. Where personal data is transferred outside the UK, we ensure appropriate safeguards are in place in accordance with UK GDPR Chapter V.
| Processor | Transfer Destination | Safeguard Mechanism |
|---|---|---|
| Stripe, Inc. | United States | UK IDTA / Standard Contractual Clauses (UK Addendum); Stripe is also certified under the UK–US Data Bridge where applicable |
| OpenRouter, Inc. | United States | [Before publication: Confirm DPA status and international transfer mechanism with OpenRouter. Do not assert SCCs or IDTA are in place until a signed agreement is held.] |
| Resend Inc. | United States | [Before publication: Confirm DPA and transfer mechanism with Resend.] |
| Sentry (Functional Software Inc.) | United States | [Before publication: Confirm DPA and transfer mechanism with Sentry.] |
| BetterStack | United States | [Before publication: Confirm DPA and transfer mechanism with BetterStack.] |
DigitalOcean processes your data on servers located in the United Kingdom (London region); no international transfer occurs for data stored on those servers. PostHog processes analytics data within the European Union (EU Cloud); UK–EU adequacy means no additional transfer safeguard is required for that processing.
You may request a copy of the relevant transfer mechanism by contacting us at [email protected].
8. Security
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, accidental loss, destruction, or damage. These include:
- encryption of data in transit (TLS 1.2 or higher) and at rest;
- hashed (not plain-text) password storage (bcrypt);
- JWT-based authentication with short-lived access tokens and refresh token rotation;
- access controls limiting staff access to personal data on a need-to-know basis;
- use of managed cloud infrastructure with automated security patching (DigitalOcean);
- structured application logging with redaction of sensitive fields; and
- regular review of our security practices.
Administrative access: Authorised administrators may access user accounts where necessary to provide technical support or investigate potential security incidents. All administrative access to user accounts is logged in our audit system. We will not access your research data for any purpose other than technical support or security investigation.
No method of transmission or storage is completely secure. If you suspect a security incident involving your data, please contact us immediately at [email protected].
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the Information Commissioner’s Office (ICO) within 72 hours of becoming aware, and will notify affected individuals without undue delay where required.
9. Automated Decision-Making and AI-Generated Outputs
Our service uses third-party AI language models (accessed via OpenRouter, Inc.), together with evidence gathered from public sources and materials you provide, to generate research intelligence in response to your research queries. We wish to be transparent about the nature of this processing and these outputs.
What the AI does: When you submit a research query, our system (the Askar research agent) gathers relevant evidence, constructs prompts incorporating that evidence and your query, and sends them to one or more AI language models via the OpenRouter API. The models return generated analysis, which the agent synthesises into a structured, cited research report.
Your data is transmitted to third-party AI providers: The content of your research queries, business context, and any documents you upload are transmitted to OpenRouter and, through them, to the underlying AI model provider(s). This means your query and document content leaves our infrastructure and is processed by third-party AI services, in most cases in the United States. See Section 4.1 and Section 7 regarding the safeguards for these transfers, and Section 4.1 regarding the current status of no-training contractual protections with underlying model providers.
AI-generated analysis, not verified fact: The research intelligence delivered by the service is AI-generated analysis based on the evidence available to the agent at the time of your query. It reflects patterns and inferences drawn from that evidence and from the underlying AI models, and does not represent guaranteed, complete, or independently verified factual conclusions.
No legally significant automated decisions about you: We do not use automated processing to make decisions about you (as a user of the service) that produce legal or similarly significant effects within the meaning of UK GDPR Article 22. The AI outputs are research tools provided for your use as the researcher and decision-maker.
Your responsibility as a researcher: When you use our service to conduct market research, you are responsible for how you interpret and apply the AI-generated results. We make no warranty that AI-generated outputs are complete, accurate, or representative of actual market or consumer conditions.
If you have questions about how AI is used in our service, please contact us at [email protected].
10. Cookies and Similar Technologies
We use cookies and similar tracking technologies on our website in accordance with the Privacy and Electronic Communications Regulations 2003 (PECR) and UK GDPR. For full details, please see our Cookie Policy.
Cookie Categories
Strictly necessary cookies — These cookies (session and authentication cookies set when you log in) are essential for the website to function and cannot be switched off. They do not require your consent under PECR.
We do not use analytics or advertising cookies. Our website analytics (PostHog, EU Cloud — see Section 3.6) runs in anonymous, cookieless mode: it sets no cookies and stores no persistent identifiers on your device. Because we set no cookies that would require consent, we do not show a cookie consent banner.
Before publication: Verify the deployed PostHog configuration matches this section before publication (see the same verification item under Section 3.6). If the deployed configuration changes to use cookies or persistent identifiers, this section and the Cookie Policy must be updated and a consent banner deployed before publication.
You can review the categories and duration of any cookies in use at any time by visiting our Cookie Policy page. You can also configure your browser to refuse some or all cookies; however, this may affect website functionality (for example, staying logged in).
For more information about cookies generally, visit www.aboutcookies.org or the ICO’s guidance at ico.org.uk/your-data-matters/online/cookies.
11. Third-Party Links
Our website may contain links to third-party websites. We are not responsible for the privacy practices of those sites and encourage you to read their privacy policies.
12. How to Complain
If you have concerns about how we handle your personal data, we ask that you contact us first at [email protected] so that we can attempt to resolve the matter.
If you remain dissatisfied, you have the right to lodge a complaint with the Information Commissioner’s Office (ICO), the UK supervisory authority for data protection:
- Website: www.ico.org.uk
- Helpline: 0303 123 1113
- Address: Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
13. Changes to This Policy
We may update this privacy policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons. We will update the “Last updated” date at the top of this policy. Where changes are material, we will notify registered users by email or via a prominent notice on our service.
We encourage you to review this policy periodically.
14. Contact Us
For any questions, requests, or concerns relating to this privacy policy or our data practices, please contact:
Askar Research Ltd
[email protected]
www.askarresearch.com
Company No. 16241609, registered in England and Wales
Askar Research Ltd — Company No. 16241609, registered in England & Wales. For privacy queries: [email protected]