AirGap Keeper logoAirGap Keeper
Privacy Policy

How We Handle Your Information

AirGap Keeper is built on the principle that the less data we hold, the lower the risk. This notice explains what we collect when you deal with us, how we protect it, how long we keep it, and your rights under UK data protection law.

Two different roles. For information about you as a website visitor, enquirer or business contact, we are the controller and this notice applies. For the documents and case files a customer sends us to process, we are only the processor — that processing is governed by our Data Processing Agreement, not this notice.

1. Who We Are

AirGap Keeper is a UK-based offline AI document processing bureau. For the purposes of the UK GDPR and the Data Protection Act 2018 we are the controller of the personal data described in this notice. Our registered office address and company details are provided on request. Data protection contact: compliance@airgapkeeper.com.

2. Information We Collect

  • Enquiry and booking data: name, job title, organisation, work email, phone number, preferred times, current setup and anything you choose to write in the message field of our enquiry and booking forms.
  • Drive intake data: organisation, contact details, matter reference, number and type of media, encryption and key availability, urgency and notes. We ask you never to send passwords, passphrases or decryption keys through a web form.
  • Correspondence: records of emails, calls and meetings needed to answer your enquiry, scope a project or manage a contract.
  • Contract and billing data: signatories, purchase orders, invoicing contacts and payment records.
  • Technical data: IP address, browser type, timestamps and pages requested, held in server logs for security and reliability.

We do not collect special category data through this website and ask that you do not include case detail, personal data about third parties, or client-confidential information in a web form.

3. How We Use It and Our Lawful Bases

  • Responding to enquiries, quoting and scoping — legitimate interests (running and growing a B2B service), or steps prior to entering a contract.
  • Delivering and administering a project — performance of a contract.
  • Security, fraud prevention and service integrity — legitimate interests in protecting our systems and our customers.
  • Service updates and marketing to business contacts — consent, or legitimate interests for existing customers, with an opt-out in every message.
  • Accounting, tax and regulatory records — legal obligation.
  • Establishing or defending legal claims — legitimate interests.

Where we rely on legitimate interests we have assessed that our interest is not overridden by your rights; you can ask for a summary of that assessment.

4. We Do Not Train AI on Your Data

We do not use enquiry data, correspondence, or customer documents to train, fine-tune or evaluate AI models. Customer documents are processed by locally hosted models on an offline environment and are never sent to a third-party AI service.

5. Who We Share It With

We never sell personal data and we do not share it for advertising. We share limited personal data with suppliers who help us operate: website and form hosting, business email, and accountancy. Each acts under written data protection terms and only on our instructions. We may also disclose personal data where required by law, by a regulator, or by a court order, and to our professional advisers where necessary.

6. International Transfers

Client document processing takes place exclusively in the United Kingdom. Business administration data is held within the UK or EEA. If any supplier arrangement ever required a transfer to a country without UK adequacy, we would put in place an appropriate safeguard such as the ICO International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, supported by a transfer risk assessment.

7. How Long We Keep It

  • Unconverted enquiries and bookings: up to 24 months from last contact, then deleted.
  • Customer project data (as processor): erased within 72 hours of project completion under our Zero-Retention Guarantee.
  • Contract and correspondence records: for the term plus six years, in line with the statutory limitation period.
  • Accounting records: six years plus the current financial year, as required by law.
  • Marketing consents and opt-outs: until withdrawn; suppression records are kept indefinitely so we do not contact you again.
  • Server logs: a maximum of 12 months.

8. Security

We apply technical and organisational measures appropriate to the risk: encryption in transit and at rest, role-based access on a least-privilege basis, access- controlled premises, vetted personnel under confidentiality undertakings, documented operating procedures, and logged erasure. Our AI processing environment is air-gapped and has no internet connection. Enquiry and intake submissions are stored in a private database that is not readable by the public.

9. Your Rights

Under the UK GDPR you have the right to:

  • be informed about how your data is used (this notice);
  • access a copy of the personal data we hold about you;
  • have inaccurate data corrected;
  • have data erased where there is no continuing lawful basis to keep it;
  • restrict processing while a concern is investigated;
  • object to processing based on legitimate interests, and to direct marketing at any time;
  • data portability, where processing is based on consent or contract and is automated;
  • withdraw consent at any time, without affecting prior processing.

We do not carry out automated decision-making producing legal or similarly significant effects on individuals. To exercise a right, email compliance@airgapkeeper.com. We respond within one month and may ask for proof of identity. If your request relates to documents we processed for a customer, we will pass it to that customer, who is the controller.

10. Cookies

We use only strictly necessary cookies and local storage required for the site to function and to keep forms secure. We do not use advertising cookies, cross-site trackers, or profiling analytics, so no consent banner is required. You can block cookies in your browser, though parts of the site may then not work.

11. Third-Party Links

Our site may link to third-party resources. We are not responsible for their privacy practices and encourage you to read their notices.

12. Complaints

Please contact us first so we can put things right. You also have the right to complain to the Information Commissioner's Office at ico.org.uk or on 0303 123 1113.

13. Changes to This Notice

We may update this notice to reflect changes in law or our practices. The current version is always published here with the effective date below, and we will tell affected customers directly about material changes.

Effective date: 1 September 2026. This document is provided for information and does not constitute legal advice.