Version 2026-09-21.
This notice explains how UIE Ltd handles personal data when you use WorldAuth Advertising, the Ad-DMI engine, this website or the free audit and resolver. We are the controller for this data.
Contact us:
- Email: privacy@worldauth.com
- Post: UIE Ltd, 66 Paul Street, London EC2A 4NA
We have not appointed a Data Protection Officer because the law does not require us to. UIE Ltd is registered with the Information Commissioner's Office.
Contact from the EU and elsewhere. Anyone, anywhere, can reach us at privacy@worldauth.com for data protection, or legal@worldauth.com for anything else.
If a customer gives us advertising copy that contains personal data (such as a named spokesperson or a testimonial), we process it for that customer as its processor. The customer's own privacy notice then applies to it.
When we capture publicly available advertising pages ourselves — for an Agent Preference Audit, or for examples we publish — we are the controller of any personal data that happens to be on them (for example, a named spokesperson). Our lawful basis is legitimate interests: analysing and evidencing advertising claims. We quote only what the analysis needs, and keep full-page archives internally as evidence for 6 years.
1. What we collect, why, and our lawful basis
| What | Why | Lawful basis (UK GDPR Art 6) | How long we keep it |
|---|---|---|---|
| Your email address, and the organisation you create | To create your account and sign you in by emailed link | Contract (6(1)(b)) | While your account is open, and for 90 days after it closes |
| Sign-in link token | To sign you in | Contract | We store only a hash of it. It expires after 15 minutes |
| Session token | To keep you signed in | Contract | We store only a hash of it, for up to 30 days, or until you sign out. Expired sessions and used or expired sign-in tokens are deleted automatically within a day |
| Billing name, address, VAT/tax number, and subscription status | To take payment and keep accounting records | Contract; legal obligation (6(1)(c)) for tax and company records | 6 years after the end of the financial year the record relates to |
| Card details | To take payment | Contract | We never receive or store them. Stripe collects them on its own page |
| Messages you send us | To answer you | Legitimate interests (6(1)(f)): replying to people who contact us | 2 years after the conversation ends |
| Business contact details of people at organisations we approach (name, job title, work email) | To tell businesses about our services | Legitimate interests: marketing our services to businesses | Until you object, or 2 years without contact |
| Your IP address, when you use the free audit or free resolver | To stop any one caller overloading the service | Legitimate interests: keeping the service available and secure | We hold it in memory only, for at most 60 seconds. We never write it to our database |
| Records of resolver use and record renders | To count and report use of a customer's Records, and our own | Legitimate interests: operating and billing the service | Individual events are deleted automatically after 35 days. Totals we have already reported may be kept |
| Text pasted into the free audit | To grade it and show you the result | Legitimate interests: providing the free audit you asked for | Processed in memory and never sent to an AI provider. We keep only a one-way hash of it and the grade, for 2 years |
We obtain business contact details of people we approach from public sources, such as company websites and professional profiles, and from introductions. We email sole traders and partnerships only with their consent or where they are existing customers (the "soft opt-in"), and every marketing email has a way to opt out.
About the resolver records. These records store:
- the class of caller (for example "AI agent, vendor stated as X");
- the host that referred it;
- the time.
They do not store your IP address or the raw browser identification string. We do not believe they identify anyone, but we treat them carefully in case they could.
Please do not paste personal data into the free audit. It is built for advertising copy. If you do, the text is processed briefly in memory, and the hash we keep could count as pseudonymised personal data.
Our hosting provider's logs. Our hosting provider, Vercel, keeps standard request logs at the platform level for security and operations. These may include IP addresses and browser information. Vercel keeps them for the period set by its own service. Our statement above that we never store IP addresses applies to our own application and database, not to these platform logs.
2. Who we share it with
We share personal data only with the service providers below, and only as far as each one needs it. Except where stated, each acts on our instructions under a data processing agreement:
| Provider | What for | Where |
|---|---|---|
| Vercel Inc. | Hosting and serving the website and API through its global network | United States and other regions |
| Neon Inc. (database, provisioned through Vercel) | Storing account and service data | European Union (database region); Neon Inc. is a US company |
| Resend | Sending sign-in and service emails | United States |
| Anthropic PBC | AI model processing for the Agent Preference Audit only. This covers advertising copy and competitor copy, not account data | United States |
| Stripe Payments UK Ltd and Stripe, Inc. | Payments and invoices. Stripe is also a separate controller for fraud prevention and its own legal obligations (see stripe.com/privacy) | United Kingdom and United States |
We may also disclose data:
- if the law requires it;
- to protect our rights;
- to a buyer of our business, which would be bound by this notice.
We do not sell personal data. We do not use it for advertising profiles.
3. International transfers
Some of these providers process data in the United States. For each transfer we rely on one of the following:
- the UK's adequacy regulations for the United States (the "UK Extension" to the EU–US Data Privacy Framework), for providers certified under it;
- otherwise, the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, together with our own transfer risk assessment.
Email us for a copy of the relevant safeguard.
4. Automated decisions
We do not make decisions about you based solely on automated processing that have legal or similarly significant effects on you.
Grades and audit results are about advertising copy and AI-model behaviour, not about people.
5. Your rights
You have the right to:
- access your personal data;
- correct it;
- delete it;
- restrict how we use it;
- object to our use of it. You can object at any time, and we will always stop using your data for direct marketing when you ask;
- port it to another provider.
Where we rely on consent, you can withdraw it at any time.
You need to give us your email address and billing details if you want an account or a paid service. Everything else is optional.
To use any of these rights, email privacy@worldauth.com. We will reply within one month. The law lets us extend this in some cases, and if so we will tell you why.
6. Complaints
If you are unhappy with how we have handled your data, please complain to us first at privacy@worldauth.com, with "Data protection complaint" in the subject line. We will:
- acknowledge your complaint within 30 days;
- look into it without undue delay;
- tell you the outcome.
You also have the right to complain to the UK regulator, the Information Commissioner's Office (from 30 September 2026, the Information Commission), at ico.org.uk or by phone on 0303 123 1113.
If you live in the European Economic Area, you can also complain to the data protection authority in your country.
7. Children
Our services are for businesses and adults. We do not knowingly collect data from anyone under 18.
8. Security
Here is how we protect your data:
- Sign-in tokens and session tokens are stored only as hashes.
- Signing keys are encrypted at rest.
- Traffic is encrypted in transit.
- Access to production systems is restricted.
9. Changes
We will post any change to this notice here and update the version date. If a change materially affects account holders, we will email them.