🍪 We use cookies

    We use cookies to improve your experience on our website, analyse traffic, and for marketing purposes. By clicking "Accept All", you consent to our use of cookies. You can also customise your preferences or reject non-essential cookies. Learn more

    Locai

    Privacy Policy

    Effective Date: 27 July 2026

    Version: 1.2

    Loc.ai Ltd ("we", "our", or "us") is a company registered in England and Wales. We are committed to protecting and respecting your privacy. This policy describes how we collect, use, and share information when you use our public website (www.locai.co.uk), Locai Control (control.locai.co.uk), Locai Workspace (workspace.locai.co.uk), and the Locai Link edge agent (collectively, the "Services").

    1. Our Role (Controller vs. Processor)

    Under the UK General Data Protection Regulation (UK GDPR):

    • We are the Data Controller for your Website Data (newsletter signups), Account Data (billing details, admin users), and the product usage and session recording data described in sections 2D and 2E.
    • We are the Data Processor for your Fleet Data (IP addresses, device identifiers, and operational logs generated by your devices). We process this data solely to provide the Service to you, as further detailed in our Data Processing Addendum (DPA).

    Where a recording or usage event made under sections 2D or 2E also contains Fleet Data, we act as Controller for the purpose of creating and analysing that record. Business customers should read section 2E alongside their DPA.

    2. The Data We Collect

    We collect different types of data depending on how you interact with us.

    A. Website Visitors (Marketing & Sales)

    • Contact Information: If you sign up for our notification list or early access programme, we collect your email address.
    • Usage Data: Information about how you interact with our website, including pages visited and time spent.
    • Technical Data: Browser type, device information, and IP address for functionality and security.

    B. Platform Customers (Account Data)

    • Identity Data: Name, username, and email address of account holders.
    • Financial Data: Billing address and payment card details (processed securely by Stripe; we do not store full card numbers).
    • Service Usage: Logs of how you use the dashboard and API.

    C. Operational Metadata (Your Devices)

    When you install Locai Link, the software transmits "heartbeat" data to our Control Plane:

    • Device Identifiers: Unique Node IDs (UID) and hashed MAC addresses.
    • Network Data: Public IP addresses (required for connectivity).
    • Health Metrics: CPU/RAM usage and version numbers.

    D. Product Usage Analytics (Workspace and Control)

    We record that certain actions happened in our applications, and nothing about what was in them. This includes which pages and panels were opened, which features were used and whether they succeeded or failed, which model was selected and where it ran, response latency, error codes, browser and operating system, approximate country, and an opaque account identifier.

    We do not collect the text of your prompts, any model output, the contents or filenames of documents you process, or anything typed into any input field. Your IP address is discarded at the point of collection.

    Full detail for Workspace is at How we measure Workspace usage.

    E. Session Recordings (Control only)

    On Locai Control, and only with your consent, we record your interactions with the dashboard. A recording is a reconstruction of your session built from your navigation, clicks, mouse movement, scrolling, and the content displayed on screen. It is not a video file and it does not use your camera or microphone.

    We use recordings to diagnose faults that are difficult to reproduce and to understand where the console is confusing.

    Recordings may show operational information about your estate, including node names, IP addresses, health metrics, and model names, because that information appears on the pages being recorded. All text entered into form fields is masked before the recording leaves your browser, and we do not record any page that displays inference content.

    Session recording is off unless you turn it on. We ask for your consent the first time you sign in to Control, you can change your answer at any time under Settings, then Privacy, and declining does not restrict any feature of Control. Recordings are deleted after 30 days.

    If you are using Control under your employer's account, your employer may have set this preference for your organisation. We will still ask you individually before any recording is made.

    3. The Data We DO NOT Collect ("Zero Egress")

    We do not access or process your Inference Content. Unless you explicitly configure the Service to route data to us:

    • We do not see the images, video feeds, audio, or text inputs sent to your devices.
    • We do not see the raw output or predictions generated by your AI models.

    This data remains local on your Authorized Nodes. The product usage analytics in section 2D never contain it, and the session recordings in section 2E exclude any page on which it is displayed.

    4. How We Use Your Data & Legal Basis

    Purpose Data Type Legal Basis
    Launch & Marketing: Sending updates, launch notifications, and newsletters. Website Data (Email) Consent (you asked to join).
    Service Provision: Managing your account, billing, and fleet connectivity. Account & Fleet Data Contract (to fulfil our MSA).
    Product Improvement: Understanding how our applications are used, and fixing faults. Product Usage Analytics (2D) Legitimate Interest. You may object at any time.
    Diagnosis & Usability: Investigating faults and improving the Control console. Session Recordings (2E) Consent. You may withdraw at any time.
    Improvement: Analysing website usage to improve UX. Usage Data Legitimate Interest.
    Security: Preventing fraud and unauthorised access. Technical Data Legitimate Interest.

    5. Sharing Your Data

    We do not sell your data. We share data only with:

    • Analytics: PostHog, which hosts our product usage analytics and session recordings on EU infrastructure in Frankfurt and processes them only on our instructions under a data processing agreement.
    • Service Providers: Third-party tools that help us operate, such as email marketing platforms.
    • Infrastructure Sub-processors: Vendors who host our platform (e.g., AWS) or process payments (e.g., Stripe).
    • Legal Authorities: If required by law or to protect our rights.

    Our current sub-processor register is available on request.

    6. Data Retention

    • Marketing Data: We retain your email for as long as you remain subscribed. If you unsubscribe, we will delete your data within 30 days.
    • Account Data: We retain account data for the duration of your subscription plus 6 years for tax and legal compliance.
    • Fleet Data: Operational logs are retained for up to 90 days to assist with debugging, then deleted.
    • Product Usage Analytics: Deleted after 12 months.
    • Session Recordings: Deleted after 30 days.

    7. International Transfers

    Our primary infrastructure is in the UK and EEA. Product usage analytics and session recordings are held in Frankfurt. Some service providers, including for email marketing and payments, are based in the USA. Where we transfer personal data outside the UK we rely on UK adequacy regulations where they apply, and otherwise on the International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, together with a transfer risk assessment.

    8. Your Rights

    Under the UK GDPR, you have the right to:

    • Access: Request a copy of your data.
    • Correction: Fix inaccurate data.
    • Erasure: Request deletion of your data (Right to be Forgotten).
    • Object: Object to processing we carry out on the basis of legitimate interests, including our product usage analytics.
    • Withdraw Consent: Unsubscribe from marketing, or turn off session recording, at any time.
    • Complaint: Lodge a complaint with the ICO (ico.org.uk) if you believe we have violated your rights.

    To exercise these rights, contact us at privacy@locai.co.uk.

    9. Cookies and Similar Technologies

    We group these by what the law requires of each, following the Privacy and Electronic Communications Regulations as amended by the Data (Use and Access) Act 2025.

    Strictly necessary. Required for the Services to work, for example keeping you logged in to Control or Workspace. These do not require your consent and cannot be turned off.

    Statistical. Used solely to produce aggregate statistics about how our website and applications are used, so we can improve them. These do not require your consent, but you can object: use the controls on our cookie notice for the website, or Settings then Privacy in Workspace and Control. We do not use these to track or monitor you as an individual, and we do not share the information with anyone for their own purposes.

    Consent required. Session recording on Control, described in section 2E. This is off unless you turn it on, and you can turn it off again at any time in the same place.

    We do not use advertising or cross-site tracking technologies in Control or Workspace.

    10. Changes to This Policy

    We will post any changes on this page and update the version number and effective date. Where a change materially affects how we use your data, we will notify account holders by email.