Skip to main content

Quantum Intelligence Hub

GDPR Compliance Framework

This framework explains how Quantum Intelligence Hub LTD (“QIH”, “we”, “us”) approaches compliance with the UK GDPR, the Data Protection Act 2018, the EU GDPR where applicable, and the Privacy and Electronic Communications Regulations (“PECR”). It covers QIH-operated websites and services, including QIH HUB AI and AI Digital Reception. This page is a public compliance statement. Customer-specific processing instructions, service scope, retention settings and allocation of responsibilities are governed by the applicable Master Service Agreement, Data Processing Agreement (“DPA”), order form and service configuration. If those documents conflict with this page, the signed contractual documents prevail.
Core principle: personal data is processed lawfully, fairly and transparently; collected for specified purposes; limited to what is necessary; kept accurate; retained only as required; and protected using proportionate technical and organisational measures.
Version
4.0
Updated
23 August 2026
Company No.
17246860
Jurisdiction
United Kingdom

1. Scope and Applicable Law

The applicable framework depends on the location of the individual, customer and processing activity:
  • United Kingdom: UK GDPR, Data Protection Act 2018 and PECR;
  • European Economic Area: EU GDPR and applicable national e-privacy rules;
  • Other jurisdictions: any mandatory local privacy, communications, consumer or sector-specific laws that apply to the service.
QIH does not represent that one legal basis or notice is suitable for every customer, campaign or country. Customers must assess the laws applicable to their own use of the services.

2. Controller and Processor Roles

QIH acts as a controller for personal data used to operate its own websites, accounts, billing, security, customer support, supplier management and legal compliance. Where QIH processes customer-provided contact data, call or message content, appointment details, knowledge-base material or other personal data solely on a customer’s documented instructions, QIH generally acts as a processor and the customer generally acts as the controller. Customers acting as controllers are responsible for:
  • identifying a valid lawful basis and providing required privacy notices;
  • ensuring uploaded data and instructions are lawful, accurate and relevant;
  • obtaining any consent required for recording, cookies or electronic marketing;
  • setting appropriate access, retention and deletion rules;
  • responding to data-subject requests, with QIH assistance where contractually required.
A third-party provider may act as QIH’s subprocessor or as an independent controller, depending on the service and contractual arrangement.

3. Categories of Personal Data

Depending on the service configuration, QIH may process:
  • identity, business and contact information;
  • account, authentication and authorised-user information;
  • billing records and payment references (card details are normally handled by the relevant payment processor);
  • website, cookie, device, browser, IP address, audit and security-log data;
  • support requests and service communications;
  • customer-provided knowledge-base and operational information;
  • telephone or channel identifiers, call metadata, messages and appointment details;
  • where enabled and lawfully configured, call audio, recordings, transcripts, summaries and AI-generated service notes.
Customers must not submit special-category data, criminal-offence data or unnecessary sensitive information unless this has been expressly agreed, a lawful condition exists and suitable safeguards have been implemented.

4. Purposes and Lawful Bases

QIH identifies the applicable lawful basis before processing data as a controller. Depending on context, this may include:
  • contract: providing requested services and administering accounts;
  • legal obligation: tax, accounting, regulatory and lawful-request compliance;
  • legitimate interests: security, fraud prevention, service improvement and business administration, subject to a balancing assessment;
  • consent: where freely given, specific, informed and withdrawable consent is required;
  • vital interests or public task: only in the limited circumstances in which the law permits them.
Consent is not treated as the default basis for every activity. Direct marketing, cookies and similar technologies are assessed separately under PECR and other applicable communications laws.

5. AI Digital Reception and Automated Systems

AI Digital Reception can answer incoming communications, collect details, provide configured information, prepare summaries and support appointment or routing workflows. Where required, callers and users should be informed that they are interacting with an AI-assisted system and whether a call is being recorded or transcribed.
  • AI output may be incomplete or inaccurate and should be reviewed where material;
  • customers must configure escalation routes for matters requiring human judgement;
  • QIH does not intentionally use the service to make solely automated decisions producing legal or similarly significant effects unless a lawful basis, transparency measures and required safeguards are in place;
  • recording and transcription must be activated only where lawful notices and, where necessary, consent have been arranged.
Additional rules are set out in the AI Usage Policy.

6. Data-Subject Rights

Subject to applicable law, individuals may request access, rectification, erasure, restriction, portability, or object to processing. They may withdraw consent where consent is relied upon and may raise a concern with the Information Commissioner’s Office (“ICO”) or their competent EEA supervisory authority. QIH may verify identity before fulfilling a request. Rights are not absolute; lawful exemptions, third-party rights, security needs and statutory retention duties may apply. When QIH acts only as processor, requests may be referred to the relevant customer/controller.

7. Cookies, Analytics and PECR

Strictly necessary cookies may be used to provide requested functions, maintain security or manage sessions. Where PECR or other applicable law requires it, non-essential analytics, advertising or similar technologies are not placed until valid consent is obtained. Users must be able to reject non-essential technologies as easily as they accept them and to revisit their choice. See the Cookie Policy and the consent controls presented on the relevant website.

8. Children and Sensitive Processing

AI Digital Reception and general QIH business services are not designed for children unless a specific written arrangement provides otherwise. Customers must not intentionally collect children’s data through the services without an appropriate lawful basis, age-appropriate transparency, parental authorisation where required and suitable safeguards. High-risk or sensitive use cases may require a Data Protection Impact Assessment (“DPIA”) before activation.

9. Retention and Deletion

Personal data is retained according to its purpose, contractual settings, legal requirements and QIH’s applicable retention schedule. Relevant factors include account status, customer instructions, security investigations, dispute management, tax and accounting duties, and backup cycles. When data is no longer required, it is deleted, anonymised or securely isolated from routine use. Residual copies may remain in protected backups until they are overwritten under the normal backup cycle, unless preservation is legally required.

10. Security Measures

QIH applies proportionate measures appropriate to risk, which may include encryption in transit, controlled administrative access, multi-factor authentication where supported, role-based permissions, logging, monitoring, backups, environment separation, incident procedures and supplier review. No online system can guarantee absolute security. Customers remain responsible for protecting their credentials, endpoints, user permissions and integrations and for notifying QIH promptly of suspected compromise.

11. Personal Data Breaches

QIH investigates suspected personal data breaches and takes proportionate containment, remediation and documentation steps. When acting as processor, QIH will notify the relevant controller without undue delay in accordance with the DPA. When acting as controller, QIH assesses whether notification to the ICO or another competent authority is required. Under UK GDPR, a reportable breach must generally be notified without undue delay and, where feasible, within 72 hours after awareness. Individuals are informed without undue delay where the breach is likely to result in a high risk to their rights and freedoms.

12. International Data Transfers

Where personal data is transferred outside the UK or EEA, QIH uses a lawful transfer mechanism as required. Depending on the transfer, this may include an adequacy regulation or decision, the UK International Data Transfer Agreement, the UK Addendum to EU Standard Contractual Clauses, EU Standard Contractual Clauses, or another legally permitted mechanism. Where required, QIH or the relevant controller considers transfer risks and supplementary technical, contractual or organisational safeguards. Hosting in another country does not remove the controller’s obligation to assess the transfer.

13. Subprocessors and Independent Providers

Services may depend on vetted providers for hosting, cloud or AI processing, telephony/SIP, messaging channels, email, analytics, payments, support or security. Processor relationships are governed by appropriate data-protection terms. Material subprocessors and change-notification arrangements may be identified in the DPA or customer documentation. QIH remains responsible for its own legal and contractual duties when engaging subprocessors. Independent controllers, such as some payment or communications providers, are responsible for their own processing under their privacy notices and applicable law.

14. Privacy by Design and DPIAs

QIH considers data minimisation, purpose limitation, access control, retention and security during service design and change management. A DPIA is considered where new technology or processing is likely to create a high risk, including certain systematic monitoring, large-scale sensitive processing, recording or significant automated-decision use cases. Customers are responsible for their own DPIA where their intended deployment requires one. QIH will provide reasonable processor information and assistance where contractually required.

15. Accountability and Responsibility

Each party is responsible for the processing activities, instructions, security controls and legal duties within its control. Responsibility for an infringement or breach is allocated according to the applicable law, contractual role, causation and each party’s acts or omissions. Nothing in this framework excludes or limits liability where doing so is prohibited by law. QIH maintains appropriate records and reviews this framework as services, providers and legal requirements evolve.

16. Contact, Complaints and Official Guidance

Quantum Intelligence Hub LTD Company No. 17246860 71–75 Shelton Street, Covent Garden London WC2H 9JQ, United Kingdom Privacy: privacy@qihhub.com Legal: legal@qihhub.com Security: security@qihhub.com Individuals may complain to the UK Information Commissioner’s Office or, where applicable, an EEA supervisory authority.

Related QIH policies

Official guidance