Draft for legal review

Privacy Notice

In short: we hold account and organisation details, the posts and discussions you submit for analysis, the AI recommendations produced, and the decisions your team records. Submitted discussions are sent to our AI provider for analysis. Nothing is published automatically, and a person reviews every recommendation. You can ask us for access, correction or deletion at any time.

Effective date: To be confirmed before public launch

Last updated: 28 July 2026

Version: Draft 0.1

Status: Draft for legal review

Operated by: Mohammad Asif, trading as PublicVoiceShield, United Kingdom

This document is provided for information only. It is not legal advice and no guarantee of compliance is given. Designed to support UK GDPR compliance, subject to organisational use, configuration and legal review.

1. Who operates PublicVoiceShield

PublicVoiceShield is operated by Mohammad Asif, trading as PublicVoiceShield, based in the United Kingdom. Until a registered company is formed, Mohammad Asif acts as the data controller for account, billing and service-operation data.

A future company entity may take over this role. Placeholders are shown below and will be completed at that point: future company name [Future company name — TO BE CONFIRMED]; future company number [Future company number — TO BE CONFIRMED]; future ICO registration number [Future ICO registration number — TO BE CONFIRMED].

Where your organisation submits content about other people (for example public comments), your organisation will usually be the controller of that content and PublicVoiceShield acts as a processor on your instructions. Roles depend on how you use the service — see the Draft Data Processing Agreement.

2. Contact details

  • Privacy contact email: [Privacy contact email — TO BE CONFIRMED]
  • Business contact address: [Business contact address — TO BE CONFIRMED]
  • No Data Protection Officer has been appointed at this stage.

3. Personal data we collect

  • Account details, including your name and work email address.
  • Organisation membership, role and invitation status.
  • Authentication and security information, such as sign-in events and session records.
  • Original posts and pasted comment threads submitted for analysis.
  • AI analyses, scores, categories and suggested replies.
  • Human decisions, edited replies and internal notes.
  • Technical information such as IP address, browser and device details, where these are actually collected by our hosting provider.
  • Support communications you send to us.

Data about social-media commenters may be included when users paste public discussions into the platform. That content is provided by your organisation and processed on its instructions.

Special-category data (such as health, religious or political beliefs, or data about criminal offences) should not be submitted unless it is genuinely necessary, you are authorised to do so, and you have an appropriate lawful condition for it.

4. Purposes of processing

  • Creating and administering accounts, organisations and team access.
  • Providing the analysis, recommendation and human-decision workflow.
  • Keeping an auditable record of AI advice and human decisions.
  • Securing the service, preventing misuse and investigating incidents.
  • Improving reliability and quality of the service.
  • Responding to support requests and legal obligations.

5. Lawful bases

  • Performance of a contract — creating your account and delivering the service.
  • Legitimate interests — security, fraud prevention, service improvement and maintaining organisational audit records. We balance these against individual rights.
  • Legal obligation — where we must retain or disclose information by law.
  • Consent — used only where genuinely required, and never bundled with service acceptance. You may withdraw consent at any time.

6. AI processing and human oversight

Submitted discussions are analysed by an AI model to suggest categories, scores and draft replies. The AI does not publish anything and does not make final moderation or legal decisions. Threats, safeguarding concerns, criminal allegations, doxxing and live legal matters are marked for mandatory human escalation. AI advises. Humans decide.

7. Service providers

We use OpenAI to perform the analysis and Lovable Cloud for hosting, database, authentication and authentication emails. Only confirmed providers are listed on our Subprocessors page.

8. International data transfers

Our providers may process data outside the United Kingdom. Where that happens, an appropriate transfer mechanism (such as the UK International Data Transfer Addendum) must be in place. Processing locations are being confirmed with each provider and will be documented on the Subprocessors page before public launch.

9. Retention

Retention periods are configurable by organisation and summarised in our Data Retention Policy. Current periods are recommended defaults awaiting administrator and legal approval.

10. Security safeguards

Access is restricted to signed-in users and scoped to their own organisation by database-level access rules. API keys are held as server-side secrets and are never exposed to the browser. Analysis and decision records are append-only.

11. Your rights

  • Access to your personal data.
  • Correction of inaccurate data.
  • Deletion, in some circumstances.
  • Restriction of processing.
  • Objection to processing based on legitimate interests.
  • Portability, where applicable.
  • Withdrawal of consent, where consent is relied upon.
  • Complaint to the UK Information Commissioner's Office (ico.org.uk).

12. How to submit a privacy request

Use the Privacy Rights page, or email [Privacy contact email — TO BE CONFIRMED]. We may ask you to verify your identity before acting on a request. Requests are reviewed by a person; nothing is deleted automatically.

13. Changes to this notice

We record a version number and a last-updated date for every policy. Where a change is material, signed-in users are shown a one-time notice and asked to acknowledge the new version.