Privacy Policy

Last updated: 5 May 2026

Overview

AIMICI is a trading name of MediAI Research Ltd, a private limited company incorporated in England and Wales (Companies House number: 15593436), with its registered office at Arrive Blue, Blue Road, Media City UK, Salford, England, M50 2ST ("we", "us", or "our"). MediAI Research Ltd is the data controller for personal data processed through the AIMICI Platform (the "Service"), which helps production teams, VFX studios, and creative businesses adopt AI responsibly at scale. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service.

We are committed to protecting your personal data and complying with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. Please read this policy carefully. By using the Service, you acknowledge that you have read and understood this Privacy Policy.

Information We Collect

Personal Information

When you register for an account, we collect information including your name, email address, job role, organisation name, and organisation type. If you subscribe to a paid plan, our payment processor Stripe collects your payment details on our behalf — we do not store your full card details on our servers.

Usage Data

We collect information about how you interact with the Service, including chat conversations you have with our AI assistant, token usage and consumption data, the number of conversations created within each plan period, and your subscription tier and usage limits. This data helps us provide, maintain, and improve the Service.

Technical Data

When you access the Service, we may automatically collect technical data such as your IP address, browser type and version, device information, operating system, referring URLs, and pages visited. This information is used to ensure the security and proper functioning of the Service.

Cookies and Tracking Technologies

We use essential cookies that are necessary for the Service to function, including an authentication session cookie and a cookie consent preference cookie. We may also use optional analytics cookies to help us understand how users interact with the Service — these are only set with your consent. Visit our Cookies page to learn more and manage your preferences.

How We Use Your Information

We use the information we collect for the following purposes:

  • To provide, operate, and maintain the AIMICI Platform and its AI-powered features
  • To authenticate your identity and manage your account
  • To process payments and manage your subscription
  • To personalise your experience, including tailoring AI responses to your role and organisation
  • To enforce usage limits and rate limiting associated with your membership tier
  • To communicate with you about your account, updates, and support enquiries
  • To monitor and analyse usage trends to improve the Service
  • To detect, prevent, and address technical issues and security threats
  • To comply with legal obligations

Legal Basis for Processing

Under the UK GDPR, we process your personal data on the following legal bases:

  • Contract: Processing is necessary for the performance of our contract with you, including providing the Service and managing your subscription
  • Consent: Where you have given clear consent for us to process your personal data for a specific purpose, such as optional analytics cookies
  • Legitimate interests: Processing is necessary for our legitimate interests, such as improving the Service, ensuring security, and preventing fraud, provided these interests are not overridden by your rights
  • Legal obligation: Processing is necessary to comply with a legal obligation to which we are subject

Data Sharing and Disclosure

We do not sell your personal data. We may share your information with third parties only in the following circumstances:

  • Service providers: We share data with trusted third-party providers who assist us in operating the Service (see "Third-Party Services" below)
  • Legal requirements: We may disclose your information if required to do so by law, or in response to valid requests by public authorities (e.g. a court or government agency)
  • Business transfers: In the event of a merger, acquisition, or sale of all or a portion of our assets, your personal data may be transferred as part of that transaction
  • With your consent: We may share your information for any other purpose with your explicit consent

Third-Party Services

We use the following third-party services to operate the AIMICI Platform. Each provider processes data in accordance with their own privacy policies:

  • Auth0 (Okta): Authentication and single sign-on — processes your email, name, and login credentials
  • Stripe: Payment processing — processes your email and payment information for subscription billing
  • Supabase: Database hosting — stores your account data, chat conversations, and usage records
  • OpenAI and Anthropic: AI model providers — your chat messages are sent to these providers to generate AI responses. These providers may process message content in accordance with their respective data processing agreements
  • Leadfeeder (Dealfront): B2B website visitor identification — identifies which companies visit the AIMICI website by matching visitor IP addresses against business databases. This helps us understand our potential B2B audience and follow up with relevant organisations. Data is processed by Dealfront GmbH, based in the European Union. This service is only active where you have accepted analytics cookies. See Leadfeeder's Privacy Policy

We ensure that all third-party processors provide sufficient guarantees regarding their data protection practices and that appropriate data processing agreements are in place.

Data Retention

We retain your personal data only for as long as is necessary to fulfil the purposes for which it was collected, including to satisfy any legal, accounting, or reporting requirements. When determining the appropriate retention period, we consider the amount, nature, and sensitivity of the data, the potential risk of harm from unauthorised use or disclosure, and applicable legal requirements.

Your account data is retained for the duration of your account. Chat conversation data is retained while your account is active and may be deleted upon request. If you close your account, we will delete or anonymise your personal data within 30 days, except where we are required to retain it by law.

International Data Transfers

Some of our third-party service providers are based outside the United Kingdom. When we transfer your personal data internationally, we ensure that appropriate safeguards are in place, such as Standard Contractual Clauses (SCCs) approved by the UK Information Commissioner's Office, or transfers to countries that have been deemed to provide an adequate level of data protection.

In particular, AI model providers (OpenAI and Anthropic) and certain infrastructure providers may process data in the United States. We ensure that such transfers comply with applicable data protection laws and that your data is afforded an equivalent level of protection.

Data Security

We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction. These measures include the use of HTTP-only cookies for session management, encrypted data transmission via HTTPS, rate limiting to prevent abuse, and secure authentication through enterprise-grade identity providers.

While we strive to use commercially acceptable means to protect your personal data, no method of transmission over the Internet or method of electronic storage is 100% secure. We cannot guarantee absolute security but are committed to promptly addressing any data breach in accordance with our legal obligations.

Your Rights

Under the UK GDPR, you have the following rights in relation to your personal data:

  • Right of access: You have the right to request a copy of the personal data we hold about you
  • Right to rectification: You have the right to request that we correct any inaccurate or incomplete personal data
  • Right to erasure: You have the right to request that we delete your personal data, subject to certain legal exceptions
  • Right to restrict processing: You have the right to request that we restrict the processing of your personal data in certain circumstances
  • Right to data portability: You have the right to receive your personal data in a structured, commonly used, and machine-readable format
  • Right to object: You have the right to object to the processing of your personal data where we rely on legitimate interests
  • Right to withdraw consent: Where processing is based on consent, you have the right to withdraw that consent at any time without affecting the lawfulness of prior processing
  • Right to complain: You have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk

To exercise any of these rights, please contact us at privacy@aimici.co.uk. We will respond to your request within one month.

Children's Privacy

The AIMICI Platform is intended for use by professionals and businesses and is not directed at individuals under the age of 18. We do not knowingly collect personal data from children. If we become aware that we have collected personal data from a child without appropriate parental consent, we will take steps to delete that information as soon as possible. If you believe we may have collected data from a child, please contact us at privacy@aimici.co.uk.

Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will notify you by updating the "Last updated" date at the top of this page and, where appropriate, providing additional notice (such as via email or a prominent notice within the Service). We encourage you to review this policy periodically.

Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at privacy@aimici.co.uk.

You may also write to us at:

MediAI Research Ltd Arrive Blue, Blue Road, Media City UK, Salford, England, M50 2ST Companies House number: 15593436

We aim to respond to all enquiries within 30 days.