Privacy Policy
Last updated: 19 July 2026
1. Introduction
Project Buckingham Ltd, trading as probuck.ai ("we", "our", "us"), is committed to protecting your privacy. This policy explains how we collect, use, and safeguard your personal data when you use our platform, in accordance with the UK General Data Protection Regulation (UK GDPR), the EU General Data Protection Regulation (EU GDPR), and other applicable data protection laws.
2. Our Role: Controller and Processor
Project Buckingham Ltd, a company incorporated in England and Wales (registration number 17263496) and trading as probuck.ai, acts in two capacities:
- Data controller for account and platform data (e.g., names, email addresses, authentication credentials, usage logs, and audit logs). We decide how this data is processed to provide, secure, and improve the platform.
- Data processor for Customer Content (documents, files, and other materials you upload to the platform). We process this content solely on your instructions, as set out in our Terms of Service, and you remain the data controller for that content.
For enquiries, please use our contact page.
Sections 3 to 5 below describe personal data that we process in our capacity as data controller. Customer Content that you upload to the platform is processed by us as a data processor on your instructions; the lawful basis, purposes, and data subject information for that content are determined by you as controller and are governed by our Terms of Service and any applicable Data Processing Agreement.
3. Data We Collect (Controller Role)
As data controller, we collect the following categories of personal data:
- Account data: name, email address, and authentication credentials (including hashed passwords and TOTP multi-factor authentication secrets).
- Usage data: access logs, feature usage, IP addresses, session metadata, and browser user-agent strings, collected for security, fraud prevention, and platform improvement.
- Audit data: records of authentication events, administrative actions, and security-relevant activity.
- Communication data: messages you send via the contact form, support channels, or help chatbot.
- Billing data (where billing is enabled): contact and transaction details processed via our Merchant of Record, Paddle.com Market Ltd, which acts as an independent data controller for payment, tax, and invoicing purposes. See Section 8 (Sub-Processors).
We do not treat the contents of documents or files you upload as data collected by us in a controller capacity — those constitute Customer Content and are addressed in Section 2 above.
4. Lawful Basis for Processing (Controller Role)
The lawful bases below (UK GDPR / EU GDPR Article 6) apply to the controller-role data described in Section 3:
- Contract performance: to provide the platform services you have signed up for.
- Legitimate interests: to maintain platform security, prevent fraud, and improve our services.
- Legal obligation: to comply with applicable laws, including data retention and tax requirements.
- Consent: where required, such as for optional communications.
For Customer Content processed in our processor capacity, the lawful basis for processing the underlying personal data is the responsibility of the customer as controller.
5. How We Use Your Data (Controller Role)
We use the controller-role data described in Section 3 to:
- authenticate users and operate multi-factor authentication;
- secure the platform, detect and prevent fraud or abuse, and investigate security incidents;
- provide customer support and respond to enquiries;
- send service-related communications (e.g., security alerts, billing notices, material policy changes);
- maintain audit logs and meet legal, regulatory, and accounting obligations;
- monitor performance and improve the reliability and usability of the platform.
We do not sell your personal data, and we do not use Customer Content to train artificial intelligence models, build user profiles, or for any purpose other than delivering the platform on your instructions.
6. Data Hosting & International Transfers
Your primary data stores (database and object storage) are hosted in the European Union. Certain sub-processors listed in §8 may process limited data outside the EEA/UK (primarily in the United States). Where they do, we rely on one or more of the following transfer mechanisms recognised under the UK GDPR and EU GDPR:
- EU–US Data Privacy Framework (DPF) and the UK Extension (UK–US Data Bridge), where the relevant sub-processor is actively self-certified on the official DPF List maintained by the U.S. Department of Commerce.
- Standard Contractual Clauses (SCCs) issued by the European Commission and the UK International Data Transfer Addendum (IDTA) issued by the ICO, for all other transfers or as a supplementary safeguard alongside the DPF.
We have conducted a Transfer Impact Assessment (TIA) to evaluate the legal regime in the destination country and confirm that the combination of safeguards above provides essentially equivalent protection to that required under EU/UK law.
7. AI Processing & Data Governance
When documents are processed using AI capabilities, they are sent to Google Cloud (Gemini Enterprise Agent Platform, formerly Vertex AI) for analysis. Under Google's Cloud Service Terms, your data is not used to train AI models and is not retained beyond the duration of the API request. Your documents and queries remain private.
8. Sub-Processors
We engage the following sub-processors to deliver the platform. This list is also incorporated by reference into our Terms of Service for the purposes of clause 19 (Data Processing) and may be updated from time to time; material changes will be notified in-product.
| Sub-processor | Purpose | Data location |
|---|---|---|
| Supabase | Database, authentication, edge functions | EU |
| Lovable | Front-end application hosting and development platform | EU |
| Google AI / Google Cloud Gemini Enterprise Agent Platform / OpenRouter | AI inference, embeddings, vision extraction (where the Organisation's own Google API key, Gemini Enterprise (formerly Vertex) service account, or OpenRouter API key is used — see Terms §21) | Per the Organisation's provider configuration |
| Resend | Transactional email (authentication, notifications) | United States / EU |
| Cloudflare | Primary object storage for customer-uploaded documents and derived artefacts (thumbnails, previews); signed-URL downloads for viewing and export | EU |
| Paddle.com Market Ltd | Merchant of Record for paid subscriptions: payment processing, subscription management, sales tax / VAT compliance, invoicing, and refund handling. See Terms §11A and our Refund Policy. | United Kingdom / EU / United States |
9. Data Retention
We retain controller-role data (as described in Section 3) for as long as your account is active. For Customer Content, we retain documents in accordance with the controller's instructions. Specific retention periods:
- Documents (Customer Content): retained on behalf of the controller until deleted by an authorised user of that organisation. Soft-deleted documents are permanently purged after 7 days as a technical feature of the platform.
- Audit logs: retained for 365 days, then automatically purged.
- Account data: retained until account deletion is requested.
10. Your Rights
Under the UK GDPR and EU GDPR, you have the following rights:
- Right of access: request a copy of your personal data.
- Right to rectification: request correction of inaccurate data.
- Right to erasure: request deletion of your personal data ("right to be forgotten").
- Right to restriction: request restriction of processing in certain circumstances.
- Right to data portability: receive your data in a structured, machine-readable format.
- Right to object: object to processing based on legitimate interests.
- Right to withdraw consent: where processing is based on consent, withdraw it at any time.
Where your personal data is contained within Customer Content (for example, a document uploaded by your employer), you should contact the relevant Data Controller (the organisation that uploaded the content). If you contact us directly, we will forward your request to the appropriate controller where we are able to identify them.
To exercise any of these rights, please contact us via our contact page. We will respond within 30 days.
11. Data Security
We implement appropriate technical and organisational measures to protect your personal data, including AES-256 encryption at rest, TLS 1.2 or higher encryption in transit, multi-factor authentication, role-based access control, and comprehensive audit logging. For full details, see our Security page.
12. Cookies
For information about our use of cookies, please see our Cookie Policy.
13. Supervisory Authority
If you are unhappy with how we handle your personal data, you have the right to lodge a complaint with your local data protection authority. In the UK, this is the Information Commissioner's Office (ICO) at ico.org.uk.
14. Changes to This Policy
We may update this policy from time to time. Material changes will be communicated via the platform or email. Continued use of the platform after changes constitutes acceptance of the updated policy.
15. Contact
For privacy-related enquiries, data subject access requests, or complaints, please use our contact page.