DPOS AI Ltd (“the Company”, “we”, “us”, or “our”) is a United Kingdom–based data protection and regulatory compliance consultancy.
We are committed to upholding the highest standards of confidentiality, integrity, and lawful processing of personal data. This Privacy Policy explains how we collect, use, store, and protect personal data in accordance with:
This policy applies where you:
We operate solely within the United Kingdom and do not conduct international operations.
Registered in England and Wales
Registered Office: 3rd Floor, 86-90 Paul Street
London
England
EC2A 4NE
United Kingdom
Contact details for data protection matters:
Email: info@dposai.com
For queries on cookies or data collected, contact: info@dposai.com
Depending on the nature of our engagement, we may act in one of three capacities:
We act as Data Controller in respect of:
In this capacity, we determine the purposes and means of processing.
During consultancy engagements, we may process personal data on behalf of clients. In such cases:
Where formally appointed as an external DPO:
We may access personal data as necessary to fulfil our DPO responsibilities
We do not collect marketing leads online and do not operate mailing lists for promotional purposes.
We may collect the following categories of personal data:
In the course of providing services, we may access:
Such data is processed solely under contractual instruction.
Our website does not include newsletter sign-ups, automated lead capture forms, or behavioural advertising mechanisms.
Under UK GDPR, we rely on the following lawful bases:
When acting as Data Processor, the lawful basis is determined by the client as Data Controller.
We do not collect special category data for our own commercial purposes.
However, when conducting audits, DPIAs, investigations, or DPO functions, we may access special category data processed by our clients. In such circumstances:
We process personal data for the following purposes:
We do not sell personal data.
We do not conduct automated marketing campaigns.
We do not engage in profiling.
We may share personal data only where necessary and proportionate.
All third-party service providers are subject to contractual confidentiality and data protection obligations.
We do not transfer personal data outside the United Kingdom.
We retain personal data only for as long as necessary to:
Typical retention periods:
Data is securely deleted or anonymised when retention is no longer required.
As a specialist data protection consultancy, information security is embedded within our governance framework.
We implement appropriate technical and organisational measures, including:
While we apply rigorous safeguards, no system can guarantee absolute security.
Under UK GDPR, individuals have the right to:
Where we act as Data Processor, data subject requests should ordinarily be directed to the relevant Data Controller (our client).
Requests may be submitted to:
info@dposai.com
Complaints may be made to the ICO at:
www.ico.org.uk
All employees, consultants, and contractors are subject to strict confidentiality obligations.
Where appointed as outsourced DPO, we operate independently in accordance with Article 38 UK GDPR and ensure there is no conflict of interest in performing statutory duties.
We do not engage in automated decision-making or profiling that produces legal or similarly significant effects.
Our website uses only essential and limited analytical cookies necessary for:
We do not use marketing or behavioural advertising cookies
We may amend this Privacy Policy from time to time to reflect legal or operational changes. Updates will be published on our website with a revised effective date.
DPOS AI Ltd
3rd Floor, 86-90 Paul Street
London
England
EC2A 4NE
United Kingdom
Email: info@dposai.com
Telephone: +44 7417 545 043
© 2026 DPOSAI Ltd, all rights reserved.