Last updated: July 2026 · EverydAI, London, United Kingdom
This notice explains what personal data EverydAI ("we", "us") collects, why, and what your rights are. It covers visitors to this website, prospective clients, and the people whose data our client Systems touch. Contact for anything in this notice: marcel@theeverydai.com.
1. Who we are
EverydAI builds and operates AI systems for businesses, based in London, United Kingdom. For data you give us directly (enquiries, the diagnosis questionnaire, client onboarding) we are the controller. For personal data inside a client's Systems (their inbox, CRM and files) the client is the controller and we are their processor, acting under our Data Processing Agreement.
2. What we collect and why
Website enquiries and the questionnaire. Name, email, and your answers about your business. Lawful basis: legitimate interests (responding to you) and, where you book a call, steps to enter a contract.
Clients. Contact and billing details, the contents of the diagnosis session, and the configuration of your Systems. Lawful basis: contract and legal obligation (accounting records).
Data inside client Systems. Emails, calendar entries, CRM records and documents that a client connects. We process this only on the client's instructions, as their processor. We connect with the minimum access needed, read-only wherever possible, and client records stay in the client's own accounts.
The Debrief. Weekly reflections generated for the account owner alone. Not visible to their team, and not used by us beyond operating the service.
3. What we never do
We do not sell personal data. We do not share it for marketing. And we do not use your data, or your clients' data, to train public AI models: our AI providers are engaged on business terms that exclude model training, and your corrections only ever shape your own System.
4. Sub-processors
We use a small number of carefully chosen providers to run the service: Anthropic (AI processing, under a data processing agreement on business terms), Make (workflow automation, EU-hosted), Google Workspace (email and documents), Supabase (database and authentication), and Vercel (website hosting). We keep this list current here, and clients are notified of changes with the opportunity to object, as set out in the DPA.
5. International transfers
Some providers process data outside the UK, including in the United States. Where they do, transfers are protected by the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, alongside each provider's security measures, so that protection is not materially lower than in the UK.
6. How long we keep things
Enquiries that go nowhere: deleted within 12 months. Client records: for the engagement plus 6 years, to meet accounting and legal obligations. Data inside client Systems: retained per the client's instructions and returned or deleted at the end of the engagement, as the DPA sets out. Website analytics, where used, are aggregate and short-lived.
7. Security
Access on a need-to-know basis, encryption in transit, minimum-scope and read-only connections wherever possible, secrets held in managed environment stores, and every System action logged with its reasoning. Our written security procedures are available to clients on request.
8. Automated decision-making
Our Systems draft and organise; they do not make decisions with legal or similarly significant effects about anyone. Anything that leaves a client's business is approved by a human first, by design.
9. Your rights
You can ask for access to your data, correction, deletion, restriction, portability, and you can object to processing based on legitimate interests. Email marcel@theeverydai.com and we will respond within one month. Where we act as a processor, we will pass your request to the client controller and help them answer it. You will never be charged for a reasonable request.
10. Complaints
If you are unhappy with how we have handled your data, please tell us first via our complaints procedure. You also have the right to complain to the Information Commissioner's Office at ico.org.uk or on 0303 123 1113.
11. Changes
We will update this notice when our practices change and show the date at the top. Significant changes affecting clients are notified directly.