broad.ai

Privacy

Effective 5 September 2026

This explains what personal data broad.ai handles, why, and the control you have over it. The short version: we collect the minimum needed to reply to you or to run the site, we never sell it, and we do not use it for advertising.

Who we are

broad.ai is operated by Jamie Broadhurst, trading as broad.ai, based in the United Kingdom, and is the controller for the personal data described here. Contact: jamie@broadai.co.uk.

If you use the contact form

We receive the name, email address, company (if given) and message you enter. It is emailed to us so we can reply, and kept in our mailbox for as long as the conversation is relevant. We do not add you to any list. Lawful basis: our legitimate interest in answering an enquiry you chose to send.

If we have written to you about our work

We sometimes contact people in roles at companies we think we could help. If you have had an unsolicited email from us, this is the notice UK GDPR requires when your details did not come from you.

What we hold: your name, role, employer, work email address and, where public, a work phone number or professional profile link, plus a note of what we sent and whether you replied. Where it came from: publicly available professional sources — company websites, Companies House filings and public professional profiles. Why: our legitimate interest in offering relevant services to businesses, assessed against your interest in not being contacted. We write to work addresses, about work, once or twice, and stop when asked.

To stop hearing from us, reply to any message or email jamie@broadai.co.uk. We record the request so you are not contacted again, and delete the rest of your details.

If you visit the site

We use Vercel Analytics for aggregate page-view counts. It sets no cookies and does not identify individuals, so there is no consent banner. Our hosting provider keeps standard server logs (IP address, time, page requested) for security and reliability for a short period.

If you sign in to a private area

The portfolio and dashboard are shared by invitation. Signing in sets a single, strictly necessary session cookie (broadai_session) so you stay signed in; it holds no tracking data and expires within seven days. For security we keep a log of sign-in attempts — time, outcome, the code or account used, and IP address — for a limited period, so that misuse can be detected. Lawful basis: legitimate interest in keeping the private area secure.

Who else processes it

Providers acting on our instructions: Vercel (hosting and analytics), Resend (delivers contact-form email), Supabase (database), Upstash (security rate-limiting and the sign-in log), and Google Workspace (our mailbox). Some are outside the UK; where data leaves the UK it does so under the UK International Data Transfer Agreement or an adequacy decision. We do not sell personal data or share it for anyone else's marketing.

How long we keep it

Enquiries: while the conversation is live, then reviewed. Outreach records: until you ask us to stop, or twelve months after last contact, whichever is sooner; opt-outs are kept so they are honoured. Sign-in logs: rolling and short. Analytics: aggregate only, never individual.

Your rights

You can ask for a copy of what we hold, have it corrected or deleted, object to our processing it, or restrict it. Email jamie@broadai.co.uk and we will respond within one month. If you are unhappy with how we have handled your data you can complain to the Information Commissioner's Office at ico.org.uk— though we would rather you told us first.

Trimate

The Trimate app has its own policy, covering training and health data, at trimate.broadai.co.uk/privacy.

Changes

If this changes materially we will update the page and the date at the top.

← Back to broad.ai