RepresentAI Privacy Policy

Last updated: 07.09.2026

This Privacy Policy tells you how the RepresentAI organisations use your personal data. It applies when you visit our website, sign up for communications, interact with us on social media, take part in our events, training or examinations, or engage with our community in any other way (including by joining our WhatsApp group).

This is a combined notice covering two separate organisations that work together under the RepresentAI name. It explains which organisation looks after your personal data for each activity and how you can exercise your rights. Where the two organisations jointly decide how and why your personal data is used, they act as "joint controllers" (this simply means they share responsibility). This Policy sets out the key points of that arrangement.

1. WHO WE ARE

RepresentAI is run by two separate organisations:

RepresentAI Ltd is a company registered in England and Wales (company number 17212743), with its registered office at 66 Paul Street, London, EC2A 4NA. RepresentAI Ltd runs the RepresentAI website and handles business partnerships and commercial activity;

RepresentAI Collective CIC is a community interest company registered in England and Wales (company number 17231468), with its registered office at 6 Deepdale Close, London, N11 3FH. RepresentAI Collective CIC leads grant and donation funded community events, training and examinations.

When we say "RepresentAI", "we", "us" or "our", we mean whichever of these two organisations is responsible for the activity.

Both organisations are based in the United Kingdom. For most activities described in this Policy, one entity is responsible for your personal data (known in data protection law as the "controller"). For certain activities where the two organisations work together and jointly decide how and why your data is used, they act as joint controllers. The table in section 3 shows which entity is responsible for each activity.

RepresentAI Collective CIC is a community interest company, not a registered charity (unless separately stated). When this Policy refers to "community-benefit activities", it means the CIC's grant and donation funded work — this does not imply registered charitable status.

2. HOW TO CONTACT US

You can get in touch with us about this Policy or about your personal data using the details below:

General privacy enquiries (shared point of contact): info@representai.co.uk

RepresentAI Ltd and RepresentAI Collective CIC are registered with the Information Commissioner’s Office where required.

3. WHICH REPRESENTAI ORGANISATION IS RESPONSIBLE?

The table below shows which organisation is the controller for each main activity. Where an activity is designed and delivered together so that both organisations decide how and why personal data is used, they act as joint controllers.

Activity Controller position
Website hosting, website browsing and website enquiries RepresentAI Ltd
Business partnerships, commercial opportunities and commercial training customers RepresentAI Ltd
Grant and donation funded community events and training RepresentAI Collective CIC (or both entities jointly, where designed and delivered together)
Examinations RepresentAI Collective CIC (or both entities jointly, where designed and delivered together)
Community mailing list and shared community channels (including the WhatsApp group) Both entities jointly, where both decide the communications and audience
Grant reporting and funder administration RepresentAI Collective CIC
Donations and donor administration RepresentAI Collective CIC

4. HOW WE WORK TOGETHER

Where this Policy states that both RepresentAI Ltd and RepresentAI Collective CIC plan and run an activity together, they jointly decide how your information is used. In practice, this means:

  • the two organisations only share the personal data that is needed for that activity and do not use it for unrelated purposes;
  • they provide a single privacy contact so you have one easy point of contact for any questions;
  • each organisation is responsible for keeping the personal data it holds secure and for maintaining its own records of processing; and
  • The two organisations work together to handle requests from individuals, security incidents and personal data breaches.

You can contact either organisation to exercise your privacy rights, regardless of which one holds your information. Further details of the internal arrangement between the two organisations are available on request.

For activities where the organisations act as separate controllers, any sharing of personal data between them is governed by a data-sharing agreement. Each organisation has its own lawful reason for the sharing.

5. WHEN DOES THIS POLICY APPLY?

This Policy applies when you:

  • subscribe to our email list or updates;
  • ask to join, or join, our WhatsApp group;
  • sign up for or take part in events, training sessions, examinations or other community activities;
  • contact us (for example, by email or via a sign-up or contact form);
  • follow or interact with us on LinkedIn, Instagram or other social media;
  • engage with us as a business partner, commercial customer, donor or funder; or
  • visit or browse our website.

6. WHAT PERSONAL DATA DO WE COLLECT?

We aim to collect only the personal data we need. Depending on how you interact with us, we may collect:

  • your name, email address, phone number (including if you join the WhatsApp group) and any profile or display name you use on the relevant channel;
  • details about what you signed up for, your preferences and participation history;
  • event, training and examination information, such as registration details, attendance and, where applicable, examination entries and results;
  • messages and emails you send us and, if you join the WhatsApp group, content you post there; and
  • business, donor and funder information, including contact details, correspondence and records relating to partnerships, commercial activity, donations and grant funding.

Third-party platforms. Some events or activities may be organised or ticketed through other platforms (for example, Eventbrite). If you register through one of these platforms:

  • that platform is a separate controller of the personal data it collects directly from you (meaning it decides how to use that data, not us);
  • the platform may collect information under its own privacy notice and terms, including information that could be classed as special category data (see section 7 below for what this means); and
  • we do not control what data those platforms ask for or how they use it.

We will usually only receive the information we need to manage your participation (for example, your name, contact details and attendance status), and we will handle that information in line with this Policy. We encourage you to read the privacy notice of any third-party platform before giving them your information.

7. SPECIAL CATEGORY DATA

Our community focuses on women and LGBTQIA+ people in technology and AI. Because of this, our activities may involve what data protection law calls "special category data" — information that reveals things like sex, sexual orientation, gender identity or related characteristics. The law gives this kind of data extra protection.

You do not need to share special category data to participate in our community. However, joining certain channels (such as the WhatsApp group) or taking part in community activities may itself reveal this kind of information, and you may also choose to share it in discussions.

Where we genuinely need your consent to use special category data, we will ask for your separate, explicit permission for that specific use. Simply taking part in an activity will not be treated as consent to use special category data for every purpose. Where we can, we will offer an alternative way to take part that does not require you to reveal this type of information.

We keep special category data out of routine funder reports and business-partnership activity unless it has been anonymised or we have assessed and documented a specific lawful basis and condition. Where a lawful basis or condition other than explicit consent applies to special category data, we will say what it is.

8. WEBSITE TECHNICAL DATA

Even if you do not sign up, our website and its security providers will process some basic technical data so the site can work and stay secure (for example, your IP address, device and browser information, timestamps and basic server logs). The website is run by RepresentAI Ltd.

Our website is built on WordPress (run by Automattic Inc.) and hosted by HostGator, a brand of Newfold Digital, Inc. HostGator provides the website hosting service for us. WordPress and related services may sometimes process information for us, but may also use limited information for their own service, security or legal purposes. Their role can therefore depend on the particular service we use.

We do not use this technical data to build marketing profiles about visitors who have not signed up.

9. HOW WE USE YOUR DATA AND WHY

Here is a simple summary of why we use your personal data and the legal reason ("lawful basis") we rely on:

  • Community communications you have asked to receive, including sending newsletters, updates, event announcements and community information. Lawful basis: your consent (you can unsubscribe at any time).
  • Running the WhatsApp group, including adding you when you join or ask to join, sharing group updates, moderating the group and addressing misuse. Lawful basis: it is in our legitimate interests to run the community safely and because joining the group is a clear choice you make.
  • Responding to your messages and keeping records of correspondence. Lawful basis: it is in our legitimate interests to operate our activities and respond to enquiries.
  • Managing events, training and examinations, including handling registrations, sending you practical information, administering results and managing waiting lists. Lawful basis: It is in our legitimate interests and, where you sign up for a paid event, course or service, because it is necessary to perform our contract with you.
  • Managing business partnerships and commercial activity. Lawful basis: our legitimate interests and, where relevant, contract.
  • Administering donations and grants and reporting to funders (using anonymised or grouped data wherever possible). Lawful basis: it is in our legitimate interests and, where relevant, because we have a legal obligation to do so.
  • Keeping the website secure and running, including preventing fraud and abuse, troubleshooting and maintaining availability. Lawful basis: it is in our legitimate interests to operate the website securely.
  • Social media engagement, including to operate and post content on our social media accounts, interacting with followers and sharing community updates and event information. Lawful basis: it is in our legitimate interests to promote the community and engage with members and the public.

10. MARKETING

Email. We will only send you marketing-style emails if you have actively opted in. You can unsubscribe at any time using the link in our emails.

WhatsApp. Joining the WhatsApp group is optional. We use the group mainly for community updates. We will not send you one-to-one marketing messages on WhatsApp unless you have asked us to or have clearly opted in.

Social media. We may post community content, event announcements and updates on our Instagram and LinkedIn pages. The platform itself processes your interactions under its own privacy policy. We will not send you direct marketing messages through these platforms unless you have separately opted in.

Keeping purposes separate. Information you give us for community, event or examination purposes will not be used to market RepresentAI Ltd's commercial services unless we have a separate lawful basis and, where electronic marketing rules apply, a separate marketing permission.

11. WHO DO WE SHARE YOUR DATA WITH?

We never sell your personal data. We only share what is needed for the purpose in question. The people and organisations we may share your data with fall into three groups:

  • Between the two RepresentAI organisations. RepresentAI Ltd and RepresentAI Collective CIC share personal data with each other only as described in section 4 of this privacy policy. Neither organisation uses data received from the other for unrelated purposes.
  • Providers that help us run our services. The following providers may process personal data when helping us deliver our activities:
    • Automattic Inc. (WordPress) and Newfold Digital, Inc. (trading as HostGator), which support the website;
    • MailerLite (operated by UAB MailerLite, Lithuania), our email and newsletter provider; and
    • other IT and support providers we use from time to time to keep our systems running.
  • Third-party platforms that process data under their own privacy notices. When you use the following platforms, they decide how to handle the personal data they collect through their services and are responsible for it under their own privacy notices:
    • WhatsApp and Instagram (both part of Meta Platforms, Inc.): Meta processes your platform data under its own privacy policy. Other group members can also see certain details within the WhatsApp group;
    • LinkedIn (part of Microsoft): LinkedIn processes your platform data under its own privacy policy;
    • Eventbrite, Inc.: where we use Eventbrite for event registration, Eventbrite processes your data under its own privacy policy; and
    • any other event or ticketing platform we tell you about at the time of registration.

We may also share personal data with funders (where grant reporting requires it (using anonymised or grouped data wherever possible) and with professional advisers and regulators where needed for legal compliance, safeguarding or legal claims.

12. INTERNATIONAL TRANSFERS — WHEN YOUR DATA GOES OUTSIDE THE UK

An "international transfer" means sending personal data to a country outside the United Kingdom. Some of our providers are based overseas, so your data may sometimes be processed outside the UK. Even where data is stored in the UK, an international transfer can happen if staff based abroad can access it remotely (for example, for support or security). Whenever we make such a transfer, we put appropriate safeguards in place, such as the UK government's adequacy decisions, the UK-US Data Bridge, or approved contract terms (known as the ICO's International Data Transfer Agreement or the UK Addendum to EU Standard Contractual Clauses), together with any required risk assessment.

Organisations that process information for us

We use trusted providers to help us run the website and communicate with our community. Where a provider handles personal data only for our purposes and under our instructions, it acts as our processor. We have arrangements in place requiring those providers to keep information secure and use it only to provide the services we have asked for.

These may include:

  • HostGator / Newfold Digital, which hosts our website and related data;
  • MailerLite, which helps us manage and send email communications; and
  • Automattic / WordPress, for website-related services, where it handles information only on our behalf. The exact role of Automattic can depend on the particular product or feature used.

As some of these providers use sub-providers or support teams outside the UK, personal data may sometimes be accessed from abroad. We put appropriate safeguards in place before this happens. These can include a UK adequacy decision, the UK-US Data Bridge, or approved contract terms and a risk assessment. Our website data is hosted in a UK data centre operated by HostGator. A UK data centre does not necessarily mean that data can never be accessed from abroad — for example, a support team may need remote access.

 Organisations that use information under their own privacy notices

We also use platforms that decide how they use personal data for their own services. They are not our processors. They are responsible for their own use of information under their own privacy notices and terms.

These include:

  • Meta, including WhatsApp and Instagram. Meta is responsible for your account, how its platforms work and the information it processes through them. See Meta's Privacy Policy at https://www.facebook.com/privacy/policy/;
  • LinkedIn, including LinkedIn page analytics and any advertising features. LinkedIn is responsible for information it processes through its platform. See https://www.linkedin.com/legal/privacy/eu; and
  • Eventbrite and other event platforms. These platforms are generally responsible for the information they collect directly from you for their own ticketing, payment, account, fraud-prevention and platform services. If a platform provides a specific feature solely to administer a RepresentAI event, it may instead act as a processor for that limited feature. The exact role of Eventbrite can depend on the particular product or feature used. See https://www.eventbrite.co.uk/help/en-gb/articles/460838/eventbrite-privacy-policy/.

Each platform may transfer or process data outside the UK under its own safeguards. Please read the relevant privacy notice before using its services.

13. HOW LONG DO WE KEEP YOUR DATA?

We only keep your data for as long as we need it. Here is a guide to our typical retention periods:

  • email subscribers: until you unsubscribe, plus a short "do not contact" record so we can respect your opt-out;
  • WhatsApp group: while you are a member, plus limited moderation and admin records where needed to keep the group safe;
  • enquiries: usually up to 12 months after the last message, unless a complaint or safeguarding issue means we need to keep it longer;
  • event, training and examination records: usually up to 24 months after the activity, unless we need to keep them longer for legal, accounting or accreditation reasons;
  • donor, funder and partnership records: for as long as we need them to manage the relationship and meet legal, accounting and reporting requirements; and
  • social media followers: we do not separately store your platform profile data. The platform keeps data under its own policies. We may keep message content for up to 12 months after the last message (or longer where needed for legal or compliance purposes).

14. YOUR RIGHTS

Under data protection law, you have a number of rights over your personal data. These are subject to certain legal conditions, but in summary you can:

  • ask for a copy of your data, have it corrected, deleted, or have its use restricted, and receive it in a portable format;
  • object to how we use your data (you always have an absolute right to object to direct marketing); and
  • withdraw your consent at any time (where we rely on consent). Withdrawing consent is as easy as giving it.

You can exercise your right with either organisation using the contact details in section 2 of this privacy policy.

15. COMPLAINTS

If you are unhappy with how we have handled your data, please contact us first using the details in section 2. We have a process for handling data protection complaints and will respond to you.

You also have the right to complain to the Information Commissioner's Office (ICO), the UK's data protection regulator, at https://ico.org.uk/make-a-complaint/data-protection-complaints/.

16. COOKIES AND TRACKING

We aim to keep tracking to a minimum. We only use cookies that are strictly necessary to make the website work and keep it secure. WordPress (which our site is built on) sets these essential cookies automatically. Our email provider, MailerLite, uses a small tracking pixel in emails to tell us whether an email has been opened; you can prevent this by turning off image loading in your email app. If we ever introduce non-essential cookies (for example, for analytics), we will show you a cookie banner with clear choices and publish a separate Cookie Policy.

17. CHANGES TO THIS POLICY

We may update this Policy from time to time. The latest version will always be on our website, with the "Last updated" date shown at the top.