1. Introduction and who we are
ARIA is a product of QED Ltd, a company registered in England and Wales ("QED", "we", "us" or "our"). ARIA is a conversational artificial intelligence platform that lets organisations express their existing content as a conversation. It includes an embedded chat experience, a dedicated voice conversational page, our GapRadar™ insight feature that surfaces questions your content does not yet answer, and our answer engine optimisation (AEO) tooling that helps your content perform well in AI-driven answer engines.
Data protection law distinguishes between a "controller", who decides why and how personal data is processed, and a "processor", who processes personal data on a controller's behalf and under its instructions. Our role depends on whose data is being processed and why.
- QED acts as a controller for personal data relating to visitors to our website and to the administrators and authorised users who hold ARIA accounts. We decide why and how that data is handled, and this policy governs it.
- QED acts as a processor when we handle end-user conversation data and other Customer Content that a customer connects to ARIA or collects through ARIA. In that case we process personal data only on the documented instructions of our customer, who is the controller for that data.
Where we act as a processor, the customer's own privacy notice and our agreement with that customer govern the processing. This policy primarily describes the personal data for which QED is the controller.
2. Scope of this policy
This policy applies to personal data that QED controls: information collected through our marketing website, information about account administrators and authorised users of the ARIA application, and information about people who contact us, subscribe to communications or otherwise interact with us directly.
This policy does not govern personal data that we process as a processor on behalf of a customer. The processing of end-user conversation data and other Customer Content connected to or collected through ARIA is governed by the customer agreement and the accompanying Data Processing Agreement (DPA) between QED and the relevant customer, together with that customer's own privacy notice. If you are an end user interacting with an ARIA assistant deployed by an organisation, please refer to that organisation's privacy notice to understand how your data is handled.
3. Definitions
The following terms are used throughout this policy:
- Personal Data: any information relating to an identified or identifiable natural person.
- Processing: any operation performed on personal data, such as collecting, storing, using, disclosing, anonymising or deleting it.
- Controller: the party that determines the purposes and means of processing personal data.
- Processor: the party that processes personal data on behalf of, and under the instructions of, a controller.
- Customer: the organisation that subscribes to ARIA and connects content or deploys ARIA assistants.
- Customer Content: the content, data and materials a customer connects to, uploads to or collects through ARIA, including knowledge sources and conversation data.
- End User: an individual who interacts with an ARIA assistant deployed by a customer.
- Subprocessor: a third party engaged by QED to process personal data in connection with the service.
- Cookies: small text files and similar technologies placed on a device to store or read information.
4. Information we collect
We collect the categories of personal data described below, depending on how you interact with us and ARIA.
Account and profile data
When you create or administer an ARIA account, we collect details such as your name, work email address, organisation name, role, job title, password credentials and account preferences. This information identifies you, secures your account and lets us provide the service to your organisation.
Billing and transaction data
For paid plans we collect billing details such as your billing name, billing address, plan, invoices and transaction history. Payments are handled by our third-party payment processor. We do not store full payment card numbers on our systems; the payment processor handles card data in accordance with applicable standards and provides us with limited information such as a payment token, the card type and the last four digits.
Customer Content you connect
Customers connect content to ARIA so that it can ground its answers in their material, for example website pages, documents and knowledge sources. This Customer Content may contain personal data. Where it does, we process it as a processor on the customer's instructions.
Conversation data
ARIA processes the messages, voice input and other interactions exchanged between end users and an assistant, together with the answers ARIA generates. Conversation data may include personal data that an end user chooses to provide. We process conversation data as a processor on the customer's instructions.
Usage, log and device data
We automatically collect technical information about how the service and website are accessed and used, such as IP address, browser type, device and operating system characteristics, referring pages, timestamps, feature usage, diagnostic logs and error reports. This helps us operate, secure and improve the service.
Cookies and similar technologies
We and our providers use cookies and similar technologies on our website and within the application to keep you signed in, remember preferences and understand usage. See section 9 for details and your choices.
Communications and support data
When you contact us through forms, email or support channels, we collect the content of your messages, your contact details and any information you choose to provide, so that we can respond and keep records of our correspondence.
Single sign-on data
If you sign in using single sign-on or a third-party identity provider, we receive limited profile information from that provider, such as your name, email address and a unique identifier, to authenticate you and provision your account.
5. How we collect information
We collect personal data in three main ways:
- Directly from you, when you create an account, connect content, configure the service, make a payment, contact us or otherwise provide information.
- Automatically, when you use the website or application, through cookies, logs and similar technologies that record usage and device information.
- From third parties and integrations, such as identity providers used for single sign-on, our payment processor, analytics providers and any sources a customer connects to ARIA.
6. How we use personal data
As a controller, we use personal data for the following purposes:
- To provide, operate and maintain ARIA and our website, including the chat, voice, GapRadar™ and AEO features.
- To ground assistant answers in the content a customer has connected, so that responses reflect that content.
- To authenticate users and to keep accounts, data and the service secure, including detecting, preventing and investigating fraud, abuse and security incidents.
- To handle billing, process payments, manage subscriptions and maintain financial records.
- To provide customer support and respond to enquiries, requests and complaints.
- To understand usage, measure performance, troubleshoot issues and improve and develop our products through analytics.
- To communicate with you about the service, including service notices, updates and, where permitted, marketing.
- To comply with legal obligations and to establish, exercise or defend legal claims.
7. Legal bases for processing
Where the UK GDPR and the EU GDPR apply, we rely on the following legal bases when we act as a controller:
- Performance of a contract: to create and administer your account, deliver the service to your organisation, process payments and provide support under our terms.
- Legitimate interests: to secure and improve the service, prevent fraud and abuse, understand usage through analytics, and promote our products to business contacts. Examples include keeping accounts safe, diagnosing faults and developing new features. We balance these interests against your rights and freedoms, and we do not rely on this basis where our interests are overridden by your interests.
- Consent: for non-essential cookies and certain marketing, where consent is required.
- Legal obligation: to meet obligations such as tax, accounting and responding to lawful requests.
Where we rely on consent, you may withdraw it at any time, for example through our cookie controls or by using the unsubscribe link in our messages or by contacting us. Withdrawing consent does not affect the lawfulness of processing carried out before the withdrawal.
8. AI processing and model training
ARIA uses large language models and related artificial intelligence to generate conversational answers grounded in the content a customer connects. We do not use Customer Content, including conversation data, to train shared or third-party foundation models. Customer Content is not added to any general training corpus.
Processing is isolated per tenant, so that one customer's content and conversations are not used to answer or inform another customer's interactions. Where we use third-party model providers to generate responses, those providers act under contract with QED on a no-retention basis, meaning they do not retain Customer Content beyond what is required to return a response and do not use it to train their own models.
Because outputs are generated by AI, they may be incomplete, inaccurate or otherwise imperfect. Outputs should be reviewed and should not be relied upon as a substitute for professional judgement.
9. Cookies and similar technologies
We use cookies and similar technologies that fall into the following categories:
- Essential cookies, which are necessary to run the website and application, keep you signed in and maintain security. These cannot be switched off.
- Functional cookies, which remember your preferences and choices to improve your experience.
- Analytics cookies, which help us understand how the website and application are used so that we can improve them.
You can control non-essential cookies through our cookie settings where available and through your browser settings. Blocking some cookies may affect how the website and application function.
10. How we share information
We share personal data only as needed to provide the service and run our business, and always with appropriate safeguards. We may share personal data with:
- Subprocessors and service providers, such as hosting, infrastructure, security, analytics and support providers, who process data on our behalf under contract.
- AI model providers, who generate responses under contract with us on a no-retention basis as described in section 8.
- Professional advisers, such as auditors, accountants and lawyers, where reasonably necessary.
- Payment processors, to process payments for paid plans.
- Authorities and other parties, where required by law, regulation, legal process or governmental request, or to protect rights, safety and the integrity of the service.
- Successors, in connection with a merger, acquisition, financing, reorganisation or sale of assets, subject to appropriate confidentiality protections.
We do not sell personal data.
11. Subprocessors
We engage carefully selected subprocessors to help deliver ARIA. We maintain a current list of our subprocessors and the functions they perform. We provide advance notice of changes to that list so that customers have an opportunity to review and, where their agreement provides for it, object to a new subprocessor. To request the current subprocessor list or to subscribe to change notifications, contact us at privacy@qedcode.io.
12. International data transfers
By default, personal data is stored within the European Union and the United Kingdom. Where personal data is transferred outside the UK or the European Economic Area, we put in place appropriate safeguards recognised under data protection law. Depending on the destination, we rely on an adequacy decision, the European Commission's Standard Contractual Clauses, and the UK International Data Transfer Addendum to the Standard Contractual Clauses. You can contact us to learn more about the safeguards we use for a particular transfer.
13. Data retention
We retain personal data for as long as it is needed for the purposes described in this policy, including providing the service, and for any further period required to meet legal, accounting, tax or security obligations or to establish, exercise or defend legal claims. When personal data is no longer needed, we delete or anonymise it.
Where we act as a processor, customers control the retention of conversation data and other Customer Content through their configuration and instructions. On closure of an account, we delete or return Customer Content in accordance with the customer agreement and within the window stated there, subject to any retention required by law.
14. Information security
We maintain technical and organisational measures designed to protect personal data against unauthorised access, disclosure, alteration and loss. These measures include encryption in transit and at rest, access controls, tenant isolation, logging and monitoring, and regular review of our practices. No method of transmission or storage is completely secure, but we work to protect your data and to respond promptly to incidents. For more detail, please see our Security page.
15. Your rights
Subject to applicable law, you have the following rights in relation to your personal data:
- The right to access the personal data we hold about you.
- The right to rectification of inaccurate or incomplete data.
- The right to erasure of your data in certain circumstances.
- The right to restrict processing in certain circumstances.
- The right to data portability for data you provided to us.
- The right to object to processing based on legitimate interests, and to direct marketing.
- The right to withdraw consent where processing is based on consent.
- The right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects.
To exercise your rights, contact us at privacy@qedcode.io. We may need to verify your identity before acting on a request. We will respond within the timeframe required by law, which is generally one month and may be extended for complex requests. In most cases there is no fee, although we may charge a reasonable fee or decline to act where a request is manifestly unfounded or excessive. If you are an end user, you may need to direct your request to the customer that deployed the ARIA assistant, and we will assist that customer as required.
You also have the right to lodge a complaint with a supervisory authority. In the United Kingdom this is the Information Commissioner's Office (ICO), and in the European Union it is the data protection authority of your country. We would, however, appreciate the chance to address your concerns first.
California privacy notice
If you are a California resident, the California Consumer Privacy Act, as amended by the California Privacy Rights Act (CCPA/CPRA), gives you the right to know what personal information we collect and how we use and disclose it, the right to delete personal information, the right to correct inaccurate personal information, and the right not to be discriminated against for exercising your rights. We do not sell your personal information and we do not share it for cross-context behavioural advertising. To exercise these rights, contact us at privacy@qedcode.io.
16. Automated decision making
ARIA generates conversational answers and insights using artificial intelligence. It does not make decisions that produce legal effects concerning you or that similarly significantly affect you without human involvement. Where decisions with such effects might arise, they involve meaningful human review rather than being based solely on automated processing.
17. Children
ARIA is a business service that is not directed to children under the age of 16, and we do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us at privacy@qedcode.io and we will take appropriate steps to delete it.
18. Marketing communications
We may send you marketing communications about ARIA where you have opted in, where this is otherwise permitted by law, or where you are an existing business contact and applicable rules allow it. You can opt out of marketing at any time by using the unsubscribe link in our messages or by contacting us at privacy@qedcode.io. Even if you opt out of marketing, we may still send you essential service communications.
19. Third-party links
Our website and the service may contain links to third-party websites and services that we do not control. We are not responsible for the privacy practices or content of those third parties. We encourage you to review the privacy notices of any third-party sites you visit.
20. Changes to this policy
We may update this policy from time to time to reflect changes in our practices, technology, legal requirements or other factors. When we make changes, we will update the "Last updated" date at the top of this page. If the changes are material, we will provide additional notice, for example by email or through the service, as appropriate. We encourage you to review this policy periodically.
21. How to contact us
If you have any questions about this policy, wish to exercise your rights, or want to raise a concern or complaint about how we handle personal data, please contact us:
- By email at privacy@qedcode.io.
- By post to QED Ltd, registered in England and Wales, [registered office address and company number].
We will review and respond to your enquiry as required by applicable law. If you are not satisfied with our response, you have the right to complain to the ICO or to your local supervisory authority, as described in section 15.