Plain English Summary: We collect your name, business details, email and phone when you contact us or become a client. We use it to provide our service and communicate with you. We never sell your data. You can ask us to delete it at any time.
Evans Automate AI Ltd ("Evans Automate", "we", "us", "our") is a UK-registered company providing AI automation systems and services to local businesses across the United Kingdom.
We are the data controller responsible for the personal data we collect through this website (evansautomate.co.uk), our services, and any communications with you. As data controller, we are registered with and regulated by the Information Commissioner's Office (ICO) under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, as amended by the Data (Use and Access) Act 2025.
Registered business: Evans Automate AI Ltd
Registered in England & Wales
Data controller contact: jon@evansautomate.co.uk
Website: evansautomate.co.uk
We collect personal data in the following ways:
Information you give us directly:
Information collected automatically:
Information collected as part of our services:
We do not collect or process any special category data (such as health information, racial or ethnic origin, political opinions, religious beliefs, or biometric data) through our website or standard services. We do not knowingly collect data from individuals under the age of 18.
We use personal data only for the specific purposes for which it was collected. These include:
We will never use your data for unsolicited marketing, sell it to third parties, or use it for any purpose not described in this policy without first obtaining your explicit consent.
Under UK GDPR, we must have a valid legal basis for processing your personal data. We rely on the following lawful bases:
Where we act as a data processor on behalf of our clients (for example, processing their customers' contact data to operate SMS or email automation systems), we do so under a data processing agreement and strictly on documented instructions from our client as data controller.
We do not sell, rent or trade personal data. We share data only in the following limited circumstances:
All third parties we work with are required to comply with applicable data protection law and to implement appropriate technical and organisational security measures.
We retain personal data only for as long as is necessary for the purpose it was collected, or as required by law. Our retention periods are as follows:
When data is no longer required, we delete or securely anonymise it in accordance with our data retention schedule. You may request earlier deletion of your data subject to our legal obligations — see Section 7 below.
Under UK GDPR and the Data Protection Act 2018, you have the following rights in relation to your personal data:
To exercise any of these rights, contact us at jon@evansautomate.co.uk. We will respond within one month. We may need to verify your identity before processing your request. There is no charge for exercising your rights unless requests are manifestly unfounded or excessive.
Right to complain: If you are unhappy with how we have handled your data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk or by calling 0303 123 1113. We would, however, appreciate the opportunity to address your concerns before you approach the ICO.
Our website uses cookies — small text files stored on your device — to help us understand how visitors use the site and to improve your experience.
Types of cookies we use:
You can control and disable cookies through your browser settings at any time. Please note that disabling certain cookies may affect the functionality of the website. By continuing to use our website, you consent to our use of cookies as described above.
As an AI automation business, we use and deploy automated systems on behalf of our clients. This section explains how these systems interact with personal data and how we ensure compliance with the UK GDPR and the Data (Use and Access) Act 2025.
Client-facing automations: Where we operate automated systems on behalf of a client — such as SMS follow-up sequences, AI webchat tools, or appointment reminder workflows — we do so as a data processor acting on the client's documented instructions. The client remains the data controller for their customers' personal data, and we process it solely to deliver the agreed service.
No significant automated decision-making: Our systems are used to automate communications and workflows, not to make significant decisions about individuals. No automated decision produced by our systems carries legal or similarly significant consequences for any individual. Human oversight and review remain available at all times.
Transparency: Where our automated systems contact individuals on behalf of a client (for example, sending an SMS after a missed call), those messages will identify the business sending them. Individuals always have the ability to opt out of further automated contact.
GDPR compliance in client systems: All automation systems we build are designed with GDPR compliance by default, including opt-out handling, data minimisation, and appropriate retention limits. We advise clients on their obligations as data controllers and provide documentation on request.
We take the security of your personal data seriously and implement appropriate technical and organisational measures to protect it against unauthorised access, loss, destruction, alteration or disclosure. These include:
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the ICO within 72 hours of becoming aware of it, and will notify affected individuals without undue delay where required by law.
No method of transmission over the internet is 100% secure. While we take all reasonable steps to protect your data, we cannot guarantee absolute security.
Some of the third-party services we use may process or store data outside the United Kingdom. Where this occurs, we ensure that appropriate safeguards are in place in accordance with UK GDPR requirements for international data transfers, including:
The primary third-party services we use (GoHighLevel, Twilio, Google Workspace, Calendly, Formspree) are each subject to contractual data processing terms and maintain appropriate international transfer mechanisms.
If you have any questions about this Privacy Policy, wish to exercise any of your rights, or have a concern about how we have handled your personal data, please contact us:
We aim to respond to all data protection enquiries within 5 working days and to fulfil all data subject requests within one calendar month of receipt.
If you are not satisfied with our response, you have the right to complain to the Information Commissioner's Office (ICO):
Information Commissioner's Office
Website: ico.org.uk
Telephone: 0303 123 1113
Address: Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
This Privacy Policy was last reviewed and updated on 18 March 2026. We may update it from time to time to reflect changes in the law, our services or business practices. We will notify clients of material changes. The current version will always be available at evansautomate.co.uk/privacy.html.