Draft for legal review
Privacy Notice
In short: we hold account and organisation details, the posts and discussions you submit for analysis, the AI recommendations produced, and the decisions your team records. Submitted discussions are sent to our AI provider for analysis. Nothing is published automatically, and a person reviews every recommendation. You can ask us for access, correction or deletion at any time.
Effective date: To be confirmed before public launch
Last updated: 28 July 2026
Version: Draft 0.1
Status: Draft for legal review
Operated by: Mohammad Asif, trading as PublicVoiceShield, United Kingdom
This document is provided for information only. It is not legal advice and no guarantee of compliance is given. Designed to support UK GDPR compliance, subject to organisational use, configuration and legal review.
1. Who operates PublicVoiceShield
PublicVoiceShield is operated by Mohammad Asif, trading as PublicVoiceShield, based in the United Kingdom. Until a registered company is formed, Mohammad Asif acts as the data controller for account, billing and service-operation data.
A future company entity may take over this role. Placeholders are shown below and will be completed at that point: future company name [Future company name — TO BE CONFIRMED]; future company number [Future company number — TO BE CONFIRMED]; future ICO registration number [Future ICO registration number — TO BE CONFIRMED].
Where your organisation submits content about other people (for example public comments), your organisation will usually be the controller of that content and PublicVoiceShield acts as a processor on your instructions. Roles depend on how you use the service — see the Draft Data Processing Agreement.
2. Contact details
- Privacy contact email: [Privacy contact email — TO BE CONFIRMED]
- Business contact address: [Business contact address — TO BE CONFIRMED]
- No Data Protection Officer has been appointed at this stage.
3. Personal data we collect
- Account details, including your name and work email address.
- Organisation membership, role and invitation status.
- Authentication and security information, such as sign-in events and session records.
- Original posts and pasted comment threads submitted for analysis.
- AI analyses, scores, categories and suggested replies.
- Human decisions, edited replies and internal notes.
- Technical information such as IP address, browser and device details, where these are actually collected by our hosting provider.
- Support communications you send to us.
Data about social-media commenters may be included when users paste public discussions into the platform. That content is provided by your organisation and processed on its instructions.
Special-category data (such as health, religious or political beliefs, or data about criminal offences) should not be submitted unless it is genuinely necessary, you are authorised to do so, and you have an appropriate lawful condition for it.
4. Purposes of processing
- Creating and administering accounts, organisations and team access.
- Providing the analysis, recommendation and human-decision workflow.
- Keeping an auditable record of AI advice and human decisions.
- Securing the service, preventing misuse and investigating incidents.
- Improving reliability and quality of the service.
- Responding to support requests and legal obligations.
5. Lawful bases
- Performance of a contract — creating your account and delivering the service.
- Legitimate interests — security, fraud prevention, service improvement and maintaining organisational audit records. We balance these against individual rights.
- Legal obligation — where we must retain or disclose information by law.
- Consent — used only where genuinely required, and never bundled with service acceptance. You may withdraw consent at any time.
6. AI processing and human oversight
Submitted discussions are analysed by an AI model to suggest categories, scores and draft replies. The AI does not publish anything and does not make final moderation or legal decisions. Threats, safeguarding concerns, criminal allegations, doxxing and live legal matters are marked for mandatory human escalation. AI advises. Humans decide.
7. Service providers
We use OpenAI to perform the analysis and Lovable Cloud for hosting, database, authentication and authentication emails. Only confirmed providers are listed on our Subprocessors page.
8. International data transfers
Our providers may process data outside the United Kingdom. Where that happens, an appropriate transfer mechanism (such as the UK International Data Transfer Addendum) must be in place. Processing locations are being confirmed with each provider and will be documented on the Subprocessors page before public launch.
9. Retention
Retention periods are configurable by organisation and summarised in our Data Retention Policy. Current periods are recommended defaults awaiting administrator and legal approval.
10. Security safeguards
Access is restricted to signed-in users and scoped to their own organisation by database-level access rules. API keys are held as server-side secrets and are never exposed to the browser. Analysis and decision records are append-only.
11. Your rights
- Access to your personal data.
- Correction of inaccurate data.
- Deletion, in some circumstances.
- Restriction of processing.
- Objection to processing based on legitimate interests.
- Portability, where applicable.
- Withdrawal of consent, where consent is relied upon.
- Complaint to the UK Information Commissioner's Office (ico.org.uk).
12. How to submit a privacy request
Use the Privacy Rights page, or email [Privacy contact email — TO BE CONFIRMED]. We may ask you to verify your identity before acting on a request. Requests are reviewed by a person; nothing is deleted automatically.
13. Changes to this notice
We record a version number and a last-updated date for every policy. Where a change is material, signed-in users are shown a one-time notice and asked to acknowledge the new version.