Privacy Policy
How we handle your data
At Intellikon AI, we are committed to protecting your privacy, safeguarding your personal data, and maintaining transparency in how we collect, process, and store information. This Privacy Policy explains how INTELLIKON AI LTD and INTELLIKON AI LLC (collectively, "Intellikon AI") handle personal data across intellikon.ai, studio.intellikon.ai, and related AI development and software reseller services.
Who We Are (Data Controller)
INTELLIKON AI LTD (Company No. 16713444) Ebenezer House, 41 Clarence Street, Southend-On-Sea, England, SS1 1BH is the Data Controller for personal data processed through intellikon.ai and studio.intellikon.ai. INTELLIKON AI LTD is registered with the UK Information Commissioner's Office under registration number ZC064584.
INTELLIKON AI LLC (Company No. 10527367) 8 The Green, STE A, Dover, Delaware 19901 is our US contracting entity. Where you contract with INTELLIKON AI LLC, your personal data is shared with INTELLIKON AI LTD and processed as described in this policy.
Data Protection & Privacy Contact: info@intellikon.ai
Information We Collect
A. Information You Provide Directly
- Contact & Communication Data: Name, business email address, job title, company name, phone number, and any details submitted via contact forms, software licence inquiries, or waitlist requests.
- Account & Profile Data: Login credentials, hashed passwords, multi-factor authentication settings, role-based access information, and settings used to access Intellikon AI Studio.
- Reseller & Transaction Data: Details required to process software licensing (e.g. Cadonix / Arcadia suite licences), billing addresses, payment methods, and transaction histories.
- Customer Content & AI Model Inputs: Technical data, schematics, prompt parameters, and inputs provided to our AI platforms, workflow components (e.g. NUCLEUS, AEGIS, VERA, PULSE, LEXIS, PRISM), or extraction pipelines.
B. Information Automatically Collected
- Device & Usage Technical Data: IP address, browser type, operating system, unique device identifiers, referrer URLs, session interaction metrics, and logs.
- Cookies & Similar Technologies: Strictly necessary session cookies used to secure logins and preserve platform state, and cookieless website analytics. See Section 9.
C. Data We Do Not Seek
We do not seek to collect special category data — data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic or biometric data, health data, or data concerning sex life or sexual orientation — nor data relating to criminal convictions or offences. Please do not submit such data into our platforms unless agreed with us in writing in advance.
How We Use Your Data & Legal Bases for Processing
Under the UK / EU GDPR, we rely on the following legal bases:
| Purpose of Processing | Type of Data | Legal Basis (GDPR) |
|---|---|---|
| Service Delivery & Account Management (providing Studio access, running AI platforms) | Contact, Account, Customer Content | Performance of a Contract |
| Reseller Operations & Licensing (issuing Cadonix / Arcadia licences and support) | Contact, Reseller & Transaction Data | Performance of a Contract / Legal Obligation |
| Customer Support & Ticket Triage (e.g. automated triage via AEGIS) | Contact, Technical Logs, Support Inquiries | Legitimate Interests (efficient support routing) |
| Product Improvement & Security (improving prompt governance, platform stability) | Usage & Technical Data, Anonymised Inputs | Legitimate Interests (platform integrity and R&D) |
| Marketing & Direct Outreach (e.g. outreach campaigns via PULSE) | Business Contact Data | Consent or Legitimate Interests (B2B marketing) |
| Legal, Accounting & Regulatory Compliance | Any relevant data | Legal Obligation / Legitimate Interests |
Where we rely on legitimate interests, we have assessed whether those interests are overridden by your rights, and you may object at any time. Where we rely on consent, you may withdraw it at any time without affecting processing already carried out.
How We Share & Disclose Information
We do not sell, rent, or trade your personal information. We share data only in the following circumstances:
- Authorised Software Partners: For reseller operations (such as Cadonix / Arcadia software), the customer licence and registration data necessary to issue a legitimate direct licence is shared with the software manufacturer.
- Third-Party Cloud, Infrastructure & AI Providers: We use a defined set of sub-processors under data processing agreements — Website hosting: Framer; Application hosting: Vercel and Railway; AI providers: Anthropic, OpenAI and Google; Transactional email: Resend. A current sub-processor list is available on request at info@intellikon.ai.
- Professional Advisers: Accountants, auditors, legal advisers, insurers and bankers, under duties of confidentiality.
- Legal Requirements: Where required to comply with law enforcement requests, court orders or regulatory obligations, or to protect the rights, property and safety of Intellikon AI or others.
- Corporate Transactions: In the event of a merger, acquisition, reorganisation or sale of assets, data may transfer as part of standard business assets under confidentiality agreements.
Security Practices & Standards
Intellikon AI employs technical and organisational security controls appropriate to the risk:
- Encryption: Data in transit is encrypted using modern TLS protocols (HTTPS); data at rest is secured with industry-standard AES-256 encryption.
- Access Controls: Role-Based Access Control (RBAC), multi-factor authentication (MFA), tenant isolation enforced at the database layer, and least-privilege staff access.
- Governance: Platform prompt management and quality gating (via NUCLEUS) to safeguard operational workflows.
No system is completely secure and we cannot guarantee the security of data transmitted over the internet. Where a personal data breach is likely to result in a risk to your rights and freedoms, we will notify the Information Commissioner's Office within 72 hours as required, and notify affected individuals where the risk is high.
International Data Transfers
As a dual-entity UK and US company, personal data may be accessed or processed across jurisdictions. When transferring personal data outside the UK or the European Economic Area, we apply compliant safeguards:
- Standard Contractual Clauses (SCCs) approved by the European Commission.
- UK International Data Transfer Agreements (IDTA) or the UK Addendum, supported by a transfer risk assessment.
- Enterprise deployment options such as isolated region cloud hosting or local infrastructure.
You may request details of the safeguards applied to a specific transfer using the contact details below.
Data Retention
We retain personal data only as long as necessary for the purposes it was collected for, including satisfying legal, accounting or reporting requirements:
- Account Data: Retained for the active duration of your contract or account, then deleted or anonymised within 90 days of termination.
- Transaction & Licensing Records: Retained for up to 7 years in compliance with UK and US tax and corporate regulations.
- Technical Logs & Security Audits: Retained typically between 30 and 180 days before automated deletion or aggregation.
- Contact Form, Waitlist & Enquiry Data: Retained for 24 months from last contact.
- Marketing Contact Data: Retained until you unsubscribe, or after 24 months of no engagement.
- Backups: Deleted data may persist in encrypted backups for up to 30 days before rotating out.
Your Legal Privacy Rights
Where applicable data protection law grants them, you have the following rights over your personal data:
- Right to Access / Know: Request a copy of the personal data we hold about you.
- Right to Rectification: Request correction of inaccurate or incomplete data.
- Right to Erasure ("Right to be Forgotten"): Request deletion of your personal data, subject to legal retention obligations.
- Right to Restrict or Object: Object to our reliance on legitimate interests, or request restriction of processing.
- Right to Data Portability: Request transfer of your data to another controller in a structured, machine-readable format.
- Right to Opt Out of Direct Marketing: Unsubscribe at any time using the link in our communications or by contacting us.
- Right to Withdraw Consent: Where we rely on your consent, you may withdraw it at any time without affecting processing already carried out.
To exercise any of these rights, contact info@intellikon.ai. We will respond within one month. We may extend this by up to two further months for complex requests. We may need to verify your identity before acting. There is no fee unless a request is manifestly unfounded or excessive.
Cookies and Similar Technologies
We use only cookies that are strictly necessary to deliver our services. These keep you signed in to Intellikon AI Studio, preserve your workspace state, and protect against cross-site request forgery. They are set without consent because the service cannot function without them, and they are not used to profile you or track you across other websites.
Our website analytics are provided by Framer, which does not set cookies or create persistent identifiers. Framer measures visits by hashing IP address and browser user agent against a secret that rotates and is deleted daily.
We do not use advertising, marketing or cross-site tracking cookies. Because of this, we do not currently operate a cookie consent banner. If we later introduce cookies that require consent, we will deploy a banner that blocks them until you opt in, and we will update this policy first. Full detail is in our Cookie Policy.
Third-Party Links & Reselling Platforms
Our website contains references and links to authorised third-party platforms (such as Cadonix / Arcadia suite modules). We are not responsible for the privacy practices or content of third-party websites. We encourage you to review their respective privacy statements when leaving our platform.
Children
Our services are business tools and are not directed at anyone under 18. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact info@intellikon.ai and we will delete it.
Updates to This Privacy Policy
We may update this Privacy Policy periodically to reflect technological changes, product updates, or legal amendments. Updates will be published on this page with a revised "Last Updated" date. Where a change is significant, we will notify account holders by email or through the services before it takes effect.
Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact: