1. Controller, scope and status of this policy
VOLTECHAI LIMITED (the Company, we, us or our) is a private limited company operating from 268a Barking Road, London, E6 3BA, United Kingdom. This privacy policy explains how we process personal data when you visit https://voltechai.pro, correspond with the desk at admin@voltechai.pro, telephone +44 7894 123987, submit an authorisation request docket, or otherwise engage us for AdTech development, media streaming infrastructure, social platform engineering, custom computer programming or computer related consulting. This policy is issued under the United Kingdom General Data Protection Regulation, the Data Protection Act 2018, and, where electronic marketing or cookies are concerned, the Privacy and Electronic Communications Regulations 2003 as amended. It is not a government form, a visa notice or a banking disclosure. It is the privacy notice of a London engineering bureau.
The Company is the controller of personal data that it determines the purposes and means of processing, including website logs, enquiry records, contract administration, supplier due diligence and ordinary business correspondence. Where we process personal data solely on documented instructions from a client in the course of building programmatic advertising software, OTT platforms, social graph systems, audience analytics engines or content distribution fabric, we act as a processor and the client remains controller of end-user or customer data unless a written addendum states otherwise. You should not send us credentials, production datasets or special category data through the public request docket.
This policy applies to living individuals. It does not confer rights on companies except where a named individual is identifiable. It applies to visitors in the United Kingdom and, where UK law still attaches because we offer services from London, to persons outside the United Kingdom who contact the bureau. If you are engaging us as a business representative, the personal data we hold is usually limited to your professional identity, role, organisational email and the content of your request.
Effective date: 4 September 2026. We may revise this policy when our processing, suppliers or the law change. The current version will be published at voltechai.pro with a revised date. Material changes that affect existing clients will be notified using the contact details we hold. Continued use of the site after publication constitutes notice of the updated text. Historic versions may be requested from admin@voltechai.pro.
2. Categories of personal data
Identity and contact data include your name, job title, organisation, postal address if supplied, telephone number and email address. The public docket on the contact page collects name, email and message. We do not require a national insurance number, passport scan or proof of address to answer an engineering enquiry. If you later become a contracting party, we may collect company registration details and the identity of authorised signatories for anti-fraud and contract validity purposes.
Professional and engagement data include the content of briefs, technical questionnaires, meeting notes, docket references, statements of work, change requests, invoice contacts and records of decisions marked during a project. Because our method is to keep a paper trail of authorisation, these records may include your opinions about vendors, latency budgets, ranking behaviour and commercial constraints. Treat the docket as a professional record.
Technical data include internet protocol address, browser type, device class, referring URL, pages viewed, timestamps, approximate location derived from IP at city or regional granularity, and cookie identifiers described in the cookie policy. We do not operate a surveillance product, a scanner application or a credit-scoring engine on this website. Logs exist to keep the site stable, to investigate abuse and to understand which bureau pages are used.
Correspondence data include emails, voicemail transcripts if we take a message, and any files you attach. Marketing data, if you opt in, include your preference flags and the campaigns you were sent. We do not buy consumer marketing lists for this site. Recruitment data, if you apply for a role, would be handled under a separate notice issued at that time. If no such notice exists yet, write to admin@voltechai.pro before sending a curriculum vitae containing excess personal data.
3. Sources
Most data comes from you: forms, email, telephone and contracts. Some data comes from your organisation when a colleague names you as a technical or commercial contact. Some technical data is generated automatically by our hosting environment when you load pages. We may receive limited business contact data from a referring professional adviser or from a public company website if you asked that party to introduce you. We do not scrape social networks to build shadow profiles of site visitors.
If you are an employee of a client and appear in project tooling that we host or administer under a processing addendum, that data is received from the client as controller. Queries about that processing should go first to your employer. We will assist the client in answering data subject requests that concern our systems, as required by the processing contract.
4. Purposes and lawful bases
We process enquiry data to assess whether an unmarked request can be routed into AdTech, streaming, social, analytics, distribution or consulting work. The lawful basis is legitimate interests in operating a specialist engineering bureau, balanced against your interest in not receiving irrelevant processing. You may object. If you enter a contract, performance of that contract becomes the primary basis for administration, billing, delivery and support.
We process website security logs under legitimate interests in keeping voltechai.pro available and in defending the Company against intrusion, fraud and denial of service. We process accounting records to comply with legal obligations under UK company and tax law. We process limited marketing of our own similar services to existing business contacts under legitimate interests or, where PECR requires consent for electronic mail, under consent. We do not sell personal data.
We may process data to establish, exercise or defend legal claims, including recovering unpaid fees and dealing with intellectual property disputes over software we write. That processing is a legitimate interest and, where necessary, a legal obligation. We may process data to meet information society or national security requests that are valid under English law. We will not treat informal fishing requests as obligatory.
Where we rely on legitimate interests, we have considered that visitors expect a London engineering company to read their docket, keep a record, and reply. We have considered that AdTech and streaming work can involve commercially sensitive descriptions and that those descriptions should not be used for unrelated profiling. We do not use visitor data to train public generative models. We do not run automated decision-making that produces legal or similarly significant effects about you as a website visitor.
5. AdTech, streaming and social-specific processing notes
Clients sometimes ask us to design programmatic advertising software, audience analytics engines or ranking algorithms that will later process large volumes of end-user data. During design, we prefer synthetic, anonymised or aggregated samples. If a client insists on using production-like data in a non-production environment, we require a written instruction, a lawful basis assessment from the controller, and technical controls that match the risk. VOLTECHAI LIMITED does not become a hidden controller of that end-user data merely because we wrote the engine.
Media streaming infrastructure may include logs of device playback sessions, CDN cache behaviour and licence server exchanges. Those logs, if they identify a person, belong to the service operator unless we host them under a processing addendum. Social platform engineering may include moderation queues and graph identifiers. We will not use client moderation queues for our own research. We will not insert undocumented tracking into a player or a feed as a side project.
Targeted advertising and public relations technology sits in a regulated environment that includes UK GDPR, PECR, and sector codes. We advise on engineering implications. We are not your data protection officer unless a separate appointment is signed. We are not a law firm. Privacy-by-design recommendations in a statement of work are professional engineering judgements, not legal opinions.
6. Recipients and international transfers
Recipients include our officers and contractors who need the data to perform their work, professional advisers such as accountants, hosting and email providers, payment providers if invoices are settled electronically, and public authorities when the law requires. We use a small number of infrastructure suppliers. We do not syndicate enquiry contents to advertising networks.
If a supplier is outside the United Kingdom, we will use a lawful transfer mechanism such as the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or a UK adequacy regulation. You may request a summary of transfer safeguards from admin@voltechai.pro. We will not disclose transfer documentation that would itself create a security risk.
Group sharing is limited because VOLTECHAI LIMITED is the operating entity named on this site. If we later establish affiliates, this policy will be updated before personal data is shared with them for new purposes. A change of control of the Company may involve due diligence disclosure under confidentiality to a prospective buyer, limited to what is necessary.
7. Retention
Unsuccessful enquiry dockets are retained for up to twenty-four months so that we can recognise a continuing conversation and defend against complaints that we ignored a brief. Contracts, invoices and tax records are retained for at least six years after the end of the financial year in which the last transaction occurred, and longer if a dispute is open. Security logs rotate on a shorter cycle unless an incident requires a freeze.
Project repositories, architecture notes and docket references that form the paper trail of an authorised outcome are retained for the life of the engagement plus a period agreed in the statement of work, typically not less than two years, so that later engineers can see why a mark was applied. If a client requires shorter retention of personal data inside those repositories, we will implement that instruction where technically feasible and lawful.
When retention ends, we delete or irreversibly anonymise personal data except to the extent backup media must expire by rotation. Destruction of media follows ordinary professional practice. We do not operate a warehouse of historic consumer profiles.
8. Security
We apply organisational and technical measures appropriate to a small London engineering bureau: access control, least privilege, encrypted transport for the public website, and staff awareness that unmarked briefs can contain commercially sensitive material. No method is perfect. You should not treat email as a high-assurance channel for secrets. If you believe a personal data breach has occurred involving us, write immediately to admin@voltechai.pro with the subject clearly stating the concern.
We will investigate suspected breaches affecting personal data we control and, where the law requires, notify the Information Commissioner’s Office and affected individuals without undue delay. Processor incidents affecting client-controlled data will be notified to the client in accordance with the processing addendum so that the controller can meet its own duties.
9. Your rights
Under UK GDPR you may have rights of access, rectification, erasure, restriction, objection, and data portability, and rights in relation to automated decision-making. You also have the right to withdraw consent where consent is the basis. Those rights are not absolute. We may refuse requests that are unfounded, excessive, or would prevent us from complying with a legal obligation or from defending a claim.
To exercise a right, write to admin@voltechai.pro from an address we can reasonably associate with you, or post to 268a Barking Road, London, E6 3BA, United Kingdom. We may need to verify identity. We will respond within one month, extendable by two further months for complex requests, in which case we will tell you why. There is ordinarily no fee.
You may complain to the Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF, United Kingdom, or via ico.org.uk. We would prefer the chance to resolve the matter first. Telephone +44 7894 123987 during desk hours if you need a status on a request already filed in writing.
10. Children
Our services are business engineering services. The website is not directed at children. We do not knowingly collect personal data from children through the public docket. If you believe a child has submitted data, contact us and we will delete it unless the law requires a short retention for security.
11. Third-party sites and maps
The contact page includes a Google Maps iframe centred on 268a Barking Road, London, E6 3BA, United Kingdom. Interaction with that iframe is subject to Google’s own terms and privacy notice. We include the map so that the address can be verified geographically. We do not receive a feed of your Google account contents. Links to other sites are provided without endorsement of their processing.
12. Recruitment and suppliers
If you apply to work with us, we will process application data to assess suitability, arrange interviews and, if successful, prepare an engagement. Unsuccessful applications are retained only as long as needed to manage the process and to defend discrimination claims, typically not more than twelve months unless you ask us to keep your details for future roles.
Suppliers who send personal data of their staff should ensure they have a lawful basis to do so. We will use that data to manage the supply relationship, access control and payment. We will not use supplier staff data for unrelated marketing.
13. Cookies and similar technologies
Cookies and similar technologies are described in the cookie policy on this site. That document is the detailed notice for PECR purposes. This privacy policy records that we process the resulting technical data as set out above. You can control non-essential cookies through the tools described in the cookie policy.
14. Record of processing and DPIA
We maintain internal records of processing activities proportionate to a company of our size and risk. Data protection impact assessments will be carried out when a project is likely to result in a high risk to individuals, for example large-scale systematic monitoring of a public social platform or extensive profiling in an advertising engine we operate as controller. Most client work does not place us in that role.
15. Contact for privacy
Privacy correspondence: admin@voltechai.pro. Postal: VOLTECHAI LIMITED, 268a Barking Road, London, E6 3BA, United Kingdom. Telephone: +44 7894 123987. Website: https://voltechai.pro. Please do not send special category data or complete customer databases to these channels without a prior written arrangement.
16. Additional narrative on balancing tests
Our legitimate interest in answering a docket is the ordinary interest of a supplier in understanding who is asking for work and what the work is. The countervailing interests of the individual are the interests in not being placed on an unrelated marketing list, not having a brief forwarded to competitors, and not having IP addresses retained longer than needed for security. We mitigate by limiting access, by not selling data, and by offering an objection route. Direct marketing to consumers is not our model.
Our legitimate interest in keeping project paper trails is the interest in being able to show why a decision was marked, which is central to the bureau method described on the public pages. Individuals named in those trails are usually acting in a professional capacity. We mitigate by restricting circulation, by honouring client instructions to minimise names, and by not publishing private docket contents on the marketing site.
Our legitimate interest in defending the website is shared with every information society service. We mitigate by collecting technical data that is ordinary for hosting, not by installing covert device fingerprinting for advertising on this corporate site. If we introduce additional measurement, the cookie policy will say so before it becomes active.
17. Joint controllers and processors we use
We do not currently operate a joint-controller arrangement for the public website. If a campaign with a media partner required joint control, we would determine responsibilities in a transparent arrangement and point you to the right contact. Processors acting for us are bound to process only on instructions, to keep data confidential, to assist with rights and breaches, and to delete or return data at the end of the service except where law requires storage.
18. Accuracy and your duties
Please keep your contact details accurate. If you write from a shared inbox, tell us who should receive replies. If you include personal data of a colleague in a brief, you should have a basis for doing so. We will take reasonable steps to correct records when you tell us they are wrong.
19. Marketing preferences
If we send electronic mail about our own engineering services to a business contact, you can refuse at any time by writing to admin@voltechai.pro with a clear request. We will keep a suppression record so that we do not contact you again for that purpose. Telephone marketing to a number registered with the Telephone Preference Service will be honoured where that regime applies. We do not operate SMS marketing for this bureau.
20. Closure
This privacy policy should be read with the cookie policy, the terms of service and the terms and conditions. Together they describe how VOLTECHAI LIMITED handles information and engagements from the London desk. If a clause in a signed statement of work conflicts with this policy on a processing role, the signed document prevails for that engagement to the extent permitted by data protection law, which cannot be contracted away to the detriment of data subjects.
21. Detailed description of website processing operations
When you load a page on voltechai.pro, your browser sends a request that our hosting environment must answer. That request typically contains an IP address, a user-agent string, the path requested and headers that browsers send by default. We process those items to deliver the page, to detect abusive automated traffic, and to understand aggregate demand for pages such as services, portfolio and contact. We do not use this channel to infer special category attributes. We do not combine it with offline electoral or credit files. We do not create a social graph of visitors.
If you submit the authorisation request docket, we process the name, email and message to decide whether we can offer a route. Messages often contain descriptions of programmatic auctions, player failures, ranking complaints or CDN shortfalls. Those descriptions are professional data. We store them in mail and in a limited internal record with a docket-style reference so that a later reply can be consistent. We do not publish your message. We do not use it as a case study without a separate written consent from an authorised representative of your organisation.
If you telephone the desk, we process the calling number as presented by the network, the time of the call and the substance of the conversation as a note. We do not record all calls as a default. If a call is recorded on a particular occasion, you will be told at the start where practicable. Voicemail, if used, is a recording you choose to leave.
If you attend 268a Barking Road by arrangement, we may process visitor names for building safety and to know who is in the premises. We do not operate a public drop-in counter. CCTV, if present in a shared building, is the responsibility of the building operator unless we tell you otherwise in a site notice.
22. Engineering artefacts and personal data
Source code, configuration, architecture diagrams and test data may incidentally contain personal data, for example a developer’s name in a commit, an email in a sample log, or a user identifier in a fixture. We treat those artefacts as part of the engagement record. We ask clients to sanitise fixtures. We will sanitise what we generate when we notice identifiers that are not required. Commit histories are difficult to rewrite; if a name in a commit is a problem, tell us early.
Continuous integration logs may capture usernames of engineers. Access-control lists contain professional identities. These are ordinary by-products of computer systems design. They are not marketing databases. Retention follows the repository and logging policies agreed with the client or, if none are agreed, our default security rotation.
23. Analytics engines we build versus analytics on this site
A frequent confusion is between audience analytics engines we engineer for clients and any measurement of this website. They are separate. Client engines may profile end users under the client’s lawful basis and policies. This website’s measurement, if any, is described in the cookie policy and is limited to understanding bureau traffic. We will not silently pipe voltechai.pro visitors into a client’s advertising graph.
24. Programmatic advertising and identifiers
If a statement of work requires us to handle advertising identifiers, hashed emails or similar tokens, we do so as processor unless the work is internal research on synthetic data. We will not insert tokens into a client system for our own yield. We will not retain copies of identifier graphs after the engagement except as backups that expire or as copies the client instructs us to keep.
25. Streaming session data
Playback logs can reveal viewing behaviour. We design systems so that operators can set retention and access. We do not watch client streams for entertainment. Where DRM licence servers or CDN providers process data, their terms apply to that processing. We will identify known sub-processors in the addendum when they are part of a hosted service we run.
26. Social graph and moderation data
Social platform engineering can expose us to user-generated content, reports of abuse and graph neighbourhoods. We process such data only to deliver the contracted system or to debug a fault the client asks us to examine. We will not use reported content as training material for unrelated models. We will not contact end users of a client’s network unless the client instructs us to do so as their processor, for example to test a notification path with consented testers.
27. Confidentiality overlapping privacy
Confidentiality obligations in our terms protect commercial secrets. Privacy law protects personal data. Both can apply to the same document. A brief that names a person and a yield problem is both confidential and personal data. We apply both regimes. Disclosure that is lawful under GDPR may still be a breach of confidence if the commercial content is revealed. We train the desk to treat unmarked requests as closed until a mark allows a public case study.
28. Automated tools used internally
We may use ordinary office software, issue trackers and code assistants when performing services. If a tool would send client personal data to a third-country model provider without a suitable transfer mechanism, we will not use that tool for that data. We do not warrant that every keystroke is free of spell-check telemetry in consumer browsers you use to contact us; you should assume email and web forms are not appropriate for the highest-secrecy material.
29. Payments and invoices
Invoice contacts’ names and emails are processed to collect fees. Bank details you supply for payment are processed for that payment and for accounting. We do not store full card numbers on this website; we do not currently take cards through the public docket. If a payment provider is introduced, its notice will apply to the card data it controls.
30. Enforcement and ICO
Nothing in this policy limits your statutory rights. If we refuse a request we will explain the exemption we rely on. The ICO can investigate. Courts of England and Wales can hear claims. We will cooperate with lawful orders. We will not treat a press campaign as a substitute for a rights request.
31. Language and interpretation
This policy is issued in English. Headings are for convenience. Words such as include are not exhaustive. References to legislation include amendments and successor regimes that apply in the United Kingdom. If the UK GDPR is replaced, this policy will be read as referring to the successor so far as practicable until we publish an update.
32. Examples of requests we will and will not action without extra verification
We will correct an obvious typographical error in your email address if you write from the original address. We will add a note that you no longer work at an organisation if a successor writes with a reasonable explanation. We will not email a copy of a contract to an unverified private address merely because someone claims to be a director. We will not delete security logs that are still needed to investigate an intrusion merely because a visitor prefers not to be in them, though we will consider restriction and minimisation.
33. Subprocessors list policy
A current list of hosting and communications subprocessors for the public site can be requested from admin@voltechai.pro. We will not publish credentials or network diagrams. Changes to subprocessors that process personal data for the public site will be reflected when this policy or the cookie policy is next updated, except that emergency security substitutions may occur first and be documented after.
34. Data minimisation in the bureau method
The bureau method of receive, sort, check, mark, route and confirm is compatible with minimisation: we need enough data to know who is asking and what must be authorised, and we do not need biographical colour. Please omit dates of birth, family details and unrelated health information. If a moderation product requires sensitive content categories, that processing belongs in a client-controlled environment with an appropriate assessment, not in the first public docket.
35. End of privacy narrative
Questions about this privacy policy should be sent to admin@voltechai.pro. The Company remains VOLTECHAI LIMITED, 268a Barking Road, London, E6 3BA, United Kingdom, operating the site https://voltechai.pro. This document is intended to be read as a complete notice for the processing it describes as of 4 September 2026.
Privacy supplemental note 1
This supplemental note 1 forms part of the same legal instrument and applies to VOLTECHAI LIMITED of 268a Barking Road, London, E6 3BA, United Kingdom, operating https://voltechai.pro and corresponding at admin@voltechai.pro and +44 7894 123987. It records that computer systems design, media streaming distribution services, social networks and other media networks, advertising technology, custom computer programming, and computer related consulting remain in scope when relevant to the document. The note is numbered 1 so that it is identifiable in a paper trail. It does not authorise processing or performance beyond what the principal clauses already authorise. Governing law remains the law of England and Wales unless a principal clause already states that rule. The bureau method of receive, sort, check, mark, route and confirm is an operational description and does not, in this supplemental note, create additional fees or reduce the liability framework already stated. If this note were ever to conflict with a numbered principal clause, the principal clause prevails. The Company will not use this note as a place to hide a new cookie, a new processor, or a new unlimited indemnity. Readers who have questions about this note may write to the privacy or legal contact already given. This paragraph exists to complete a professionally structured instrument of adequate length for the subject matter of AdTech development, media streaming infrastructure and social platform engineering as practised from London in 2026, without relying on placeholder Latin. Nothing in supplemental note 1 requires a visitor of the public website to accept a supply contract. Nothing in supplemental note 1 requires a Client under a Statement of Work to pay twice for the same Deliverable. The Information Commissioner’s Office remains the UK supervisory authority for data protection complaints as already described where this document is a privacy or cookie notice. Courts of England and Wales remain the forum as already described where this document is a contractual instrument. The address 268a Barking Road, London, E6 3BA, United Kingdom remains the postal address for notices as already described. The domain voltechai.pro remains the public site. The email admin@voltechai.pro remains the plain-text correspondence address. Supplemental note 1 ends.