Ask My HRAsk My HR CIC
🔒

Privacy Policy

How we protect your privacy and handle your data

Last Updated: December 30, 2024

Ask My HR CIC (Company Number: 16760789, ICO Registration: ZC036886) is committed to protecting your privacy. This policy explains how we collect, use, and protect your information in compliance with UK GDPR.

Our Commitment to Privacy

Ask My HR is designed with privacy at its core. Most of our services require no registration and no personal information.

Anonymous Services (No Data Collection):

• AI chat conversations - completely anonymous

• Document generators - no storage of generated documents

• Calculators (wages, SSP, holiday)

• ET1 Helper

• All employment information pages

Optional Forms (With Your Consent):

Only when you choose to contact us, share feedback, volunteer, or share your story do we collect information - and only what is necessary to respond to you.

Anonymous Services - What We Collect

For AI Chat, Document Generation, and Calculators:

We collect minimal technical data:

• Your questions and messages (processed anonymously, not stored permanently)

• Browser type and device type

• Approximate location (country level only, e.g., "United Kingdom")

• Pages visited and features used

• Session duration

We DO NOT collect:

• Your name

• Email address

• Phone number

• Account credentials (we have no accounts)

• Precise location (city, street, GPS)

• IP address (we anonymize it)

**Chat conversations are NOT stored permanently.** They are processed in real-time and deleted automatically.

Information Collected Through Forms

When you choose to contact us or submit feedback, we collect only what is necessary:

Feedback Form (/feedback):

• Name (optional)

• Email address (optional)

• Your feedback message (required)

• Purpose: To improve our service

• Retention: 12 months

Volunteer Application (/volunteer):

• Name (required)

• Email address (required)

• Phone number (optional)

• Languages, experience, availability

• Purpose: To evaluate volunteer candidates

• Retention: 24 months

Success Story Sharing (/share-story):

• Your story content (required)

• Display preference (anonymous/pseudonym/name)

• Email (only if you consent to follow-up)

• Purpose: To demonstrate our impact and inspire others

• Retention: Story content (anonymized, permanent for impact reports), Contact details (12 months if provided)

Contact Form (/contact):

• Name (required)

• Email address (required)

• Subject and message (required)

• Purpose: To respond to your inquiry

• Retention: 12 months

**IMPORTANT:** All forms require your explicit consent via checkbox before submission. The AI chat and document generation remain completely anonymous.

How We Use Your Information

We use the information we collect only for legitimate purposes:

Anonymous Services:

• Providing employment rights guidance

• Generating AI responses to your questions

• Creating documents you request

• Improving service quality and accuracy

• Understanding which topics need better coverage

• Ensuring system security and preventing abuse

Form Data:

• Responding to your feedback or inquiries

• Evaluating volunteer applications

• Demonstrating our impact to funders (anonymized stories)

• Improving our service based on user feedback

We DO NOT:

• Sell your data to anyone

• Share your conversations or forms with third parties (except as described below)

• Use your data for marketing

• Track you across other websites

• Create profiles or databases of identified users

Third-Party Services

We use these trusted third-party services, all compliant with UK GDPR or using Standard Contractual Clauses:

OpenAI (AI Responses):

• Purpose: Processes your questions anonymously to generate employment law guidance

• Location: United States (Standard Contractual Clauses in place)

• Data retention: OpenAI does not permanently store your conversations

• Privacy policy: https://openai.com/privacy

Vercel (Hosting & Infrastructure):

• Purpose: Hosts our website and services

• Location: UK/EU data centers (GDPR compliant)

• Data retention: Technical logs kept for 30 days

• Privacy policy: https://vercel.com/legal/privacy-policy

Web3Forms (Form Submission Processing):

• Purpose: Securely forwards form submissions (feedback, volunteer applications, contact) to our email

• Location: United States (Standard Contractual Clauses in place)

• Data retention: Web3Forms does not permanently store your form data

• Privacy policy: https://web3forms.com/privacy

• Your data is encrypted during transmission (256-bit SSL)

Google Analytics (Anonymous Usage Statistics):

• Purpose: Understand how users navigate our site to improve user experience

• Data collected: Anonymized page views, feature usage, approximate location (country)

• Retention: 90 days

• Your IP address is anonymized

• You can opt out: https://tools.google.com/dlpage/gaoptout

All third-party services:

• Are GDPR compliant or use Standard Contractual Clauses

• Have appropriate security measures

• Process data only as instructed

• Do not sell your data to third parties

Data Retention Periods

We keep your data only as long as necessary for the purposes described:

Anonymous Usage (Chat & Documents):

• Chat conversations: Not stored permanently - processed in real-time and deleted

• Usage analytics: Anonymized, kept for 90 days

• Technical logs: 30 days for security purposes

• Generated documents: Not stored by us (you download them)

Form Submissions:

• Feedback forms: 12 months

• Volunteer applications: 24 months (to evaluate candidates over time)

• Success stories: Story content (anonymized, kept permanently for impact reporting), Contact details (12 months if provided)

• Contact inquiries: 12 months

Automatic Deletion:

• Data is automatically deleted after the retention period expires

• You can request early deletion anytime by emailing dpo@askmyhr.co.uk

Why We Keep Data:

• To respond to your inquiries and provide support

• To evaluate volunteer candidates fairly

• To demonstrate our impact to funders (using anonymized stories)

• To improve our service based on user feedback

• To comply with legal obligations (e.g., financial records)

Data Security

We take data security seriously and implement appropriate measures:

Technical Measures:

• All data transmitted with 256-bit SSL encryption (HTTPS)

• Secure hosting in UK/EU data centers

• Automatic data deletion after retention periods

• Limited access to data (technical staff only)

• Regular security audits and updates

• Firewalls and intrusion detection systems

Organizational Measures:

• Staff trained on data protection

• Clear data processing procedures

• Regular privacy impact assessments

• Incident response plan

Your Responsibilities:

• Keep your device secure

• Use a secure internet connection

• Do not share sensitive personal information in anonymous chat

• Download generated documents immediately and store them securely

Your Rights Under UK GDPR

Under UK GDPR, you have the following rights regarding your personal data:

1. Right to Access

Request copies of your personal data

2. Right to Rectification

Request correction of inaccurate or incomplete data

3. Right to Erasure ("Right to be Forgotten")

Request deletion of your personal data

4. Right to Restrict Processing

Request that we limit how we use your data

5. Right to Data Portability

Receive your data in a portable format

6. Right to Object

Object to processing of your data

7. Right to Withdraw Consent

Withdraw consent at any time (for consent-based processing)

8. Right to Lodge a Complaint

File a complaint with the Information Commissioner's Office (ICO)

HOW TO EXERCISE YOUR RIGHTS:

📧 **Email:** dpo@askmyhr.co.uk

📝 **Subject:** Data Subject Rights Request

Please include:

• Which right you want to exercise

• Type of form you submitted (if applicable: feedback/volunteer/story/contact)

• Date you submitted the form (if you remember)

• Your email address (for verification)

OUR COMMITMENT:

• We will respond within **1 month**

• No charge (unless request is clearly unfounded)

• Clear explanation of action taken

IMPORTANT NOTES:

• Anonymous chat conversations cannot be retrieved or deleted (we don't store them linked to you)

• For success stories, we keep anonymized content for impact reporting but delete your contact details upon request

NOT SATISFIED WITH OUR RESPONSE?

You have the right to lodge a complaint with the Information Commissioner's Office (ICO):

🌐 **Website:** https://ico.org.uk/make-a-complaint/

📞 **Phone:** 0303 123 1113

📋 **Our ICO Registration:** ZC036886

Contact Us

Data Protection Officer:

📧 dpo@askmyhr.co.uk

General Inquiries:

📧 enquiry@askmyhr.co.uk

Company Information:

Ask My HR CIC

Company Number: 16760789

ICO Registration: ZC036886

Type: Community Interest Company (CIC)

Questions about this policy?

If you have any questions about how we handle your data, please email dpo@askmyhr.co.uk