Privacy Policy
How Deploy Safe AI collects, uses and protects your information.
Deploy Safe AI · Version 1.0 · Last updated: Thursday 3rd September 2026
1. Who we are
Deploy Safe AI is a product owned and operated by The SaaSy People Ltd, a company registered in England and Wales (company number 12341379) with its registered office at 47 Cannon Street, Arca Building, Birmingham, B2 5EF ("we", "us", "our").
- VAT registration number: 360 1161 44
- ICO registration number: ZB066023
- Data Protection Officer, and all data protection and security enquiries: security@thesaasypeople.com
- General enquiries: hello@thesaasypeople.com
This policy explains what we do with personal data when you use Deploy Safe AI. It sits alongside our Terms and Conditions.
2. When we are a controller and when we are a processor
Deploy Safe AI is a business tool, so our role depends on the data in question.
- We are the controller for the data we need in order to run the platform and our relationship with you: your account and profile data, your usage of the platform, and our communications with you. Sections 4 to 12 of this policy describe that processing.
- We are a processor for the content you submit where that content contains personal data about other people, for example an uploaded document naming an employee. In that case your organisation is the controller, we act only on your instructions, and the terms in Schedule 1 (Data Processing Terms) of our Terms and Conditions apply.
Please do not include personal data about other individuals in assessment answers unless it is necessary. Describe systems and processes, not people.
3. What we collect
- Account and profile data: your name, work email, company name, role, and the organisation profile you provide, such as size, sector and locations.
- Assessment data: your answers to our questionnaires, including descriptions of the AI systems and tools your organisation uses, and any documents you choose to upload as evidence.
- Team data: names and work email addresses of colleagues you invite to the platform.
- Usage data: log and device information used to run and secure the platform.
We do not collect or store payment card details.
4. If a colleague invited you
If your name and work email were given to us by a colleague who invited you to Deploy Safe AI, we did not collect that data from you directly. We use it only to give you access to the platform and to send service messages about your account. You can object to that use, or ask us to delete your details, by contacting security@thesaasypeople.com. Where an invitation is not accepted, the invited person's details are deleted in line with section 9.
5. How we use your information
- To provide the platform: running assessments, generating results, and operating your account.
- AI-assisted analysis: assessment answers are analysed using an AI model, currently Anthropic's Claude, accessed through the Anthropic commercial API. Under those commercial terms, Anthropic applies zero data retention and does not train its models on our customers' data. We do not make solely automated decisions about you that produce legal or similarly significant effects.
- Service recommendations: we may use your assessment results to recommend relevant services from The SaaSy People, inside the platform, in your results and by email. You can opt out of these communications at any time using the unsubscribe link or your account settings, without affecting your use of the platform.
- To improve the platform: aggregated and de-identified analysis of assessments to improve our questions, rules and scoring. We do not sell your data, and we do not share your assessment answers with any other customer.
- Legal and security: compliance with law, fraud prevention and platform security.
6. Legal bases
We rely on the following legal bases under UK GDPR:
- Performance of a contract: providing the platform you signed up for.
- Legitimate interests: service recommendations to business users, improving the platform, and security, in each case balanced against your rights and always with an opt-out for marketing. We have carried out a legitimate interests assessment for our service recommendations and will provide a summary on request.
- Consent: where consent is required, for example non-essential cookies, and for marketing email where you are a sole trader or a partnership rather than a corporate subscriber.
- Legal obligation: records we are required to keep.
Marketing emails always carry an opt-out, and we will honour an objection to direct marketing immediately.
7. Who we share it with
We use the following service providers, each acting on our instructions under a written data processing agreement:
| Provider | What they do | Location | Safeguard |
|---|---|---|---|
| Supabase | Hosting and database | European Union | UK adequacy regulations for the EEA |
| Anthropic | AI-assisted analysis | United States | UK Addendum to the EU Standard Contractual Clauses, with zero data retention under the commercial API terms |
| Resend | Email delivery | United States | UK Addendum to the EU Standard Contractual Clauses, supported by the EU-US Data Privacy Framework (UK Extension) |
We also share personal data with our professional advisers, and with authorities where the law requires it. If we change or add a provider, we will update this table.
We do not sell personal data. We do not share your assessment answers or results with any other customer.
8. International transfers
Your account and assessment data is hosted in the European Union, and we rely on the UK adequacy regulations for the EEA for that transfer.
Two of our providers process data in the United States. AI-assisted analysis is carried out by Anthropic, and email delivery by Resend. Resend stores email content and delivery logs in the United States, and the sending region shown in their platform controls where email is routed from rather than where it is stored. For both providers we rely on the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, supported in Resend's case by their participation in the EU-US Data Privacy Framework and its UK Extension.
We complete a transfer risk assessment for each transfer outside the UK and review it periodically. You can request a summary of the safeguards in place by contacting security@thesaasypeople.com.
9. Retention
- Account and assessment data: retained while your account is active and for 90 days after closure, then deleted or anonymised, unless a longer period is required by law.
- Operational and log data: retained for 90 days.
- Backups: we hold a 90-day rolling backup. Where you ask us to delete data, it is removed from live systems promptly and falls out of backups within that 90-day cycle.
- Invitations: details of an invited person are deleted within 90 days if the invitation is not accepted.
You may request earlier deletion under section 11.
10. Cookies
We use the following categories of cookie:
| Category | Purpose | Consent needed |
|---|---|---|
| Strictly necessary | Sign-in, session security and core platform function | No |
| Analytics | Understanding how the platform is used so we can improve it | Yes |
We do not use advertising, targeting or social media cookies, and we do not allow third parties to use cookies on the platform for their own purposes.
Specific cookie names, providers and durations are listed in our cookie banner. You can accept or reject analytics cookies when you first visit, and change your choice at any time through the banner controls. Rejecting analytics cookies does not affect your use of the platform.
11. Your rights
You have the right to:
- access the personal data we hold about you
- have inaccurate data corrected
- have your data erased
- restrict how we process your data
- receive your data in a portable format
- object to processing, including to direct marketing, which we will always honour
- withdraw consent where our processing is based on consent
To exercise any of these rights, contact security@thesaasypeople.com. We will respond within one month, and will tell you if we need to extend that period because the request is complex. There is no charge for a request unless it is manifestly unfounded or excessive.
If you are unhappy with how we have handled your data, you can complain to the Information Commissioner's Office at ico.org.uk, or by calling 0303 123 1113.
12. Children
Deploy Safe AI is a business tool for users aged 18 or over. We do not knowingly collect personal data from anyone under 18. If you believe we hold data about a child, contact security@thesaasypeople.com and we will delete it.
13. Security
The SaaSy People Ltd is certified to ISO/IEC 27001:2022 and accredited under Cyber Essentials. Our certifications and security documentation are available at security.thesaasypeople.com.
- Data is encrypted in transit and at rest.
- Access is role-based and limited to what each role needs.
- Our staff's access to customer data is logged.
No system is perfectly secure. Where the law requires it, we will notify you and the Information Commissioner's Office of a personal data breach.
14. Changes to this policy
We will post any changes to this policy here and update the version and date at the top. For material changes we will tell you by email or in the platform before they take effect. Previous versions are available on request.
15. Contact us
For anything relating to privacy or data protection, including a request to exercise your rights, contact our Data Protection Officer at security@thesaasypeople.com. For anything else, contact hello@thesaasypeople.com.

