Legal
Privacy Policy
How we collect, use and protect your personal data.
01Who we are
This policy explains how Jack Summer Ltd, trading as Claromai ("Claromai", "we", "us", "our") collects, uses and protects personal data when you visit this website, get in touch, or book a discovery call. We are the data controller for the personal data described here.
Jack Summer Ltd is registered in England & Wales, company number 11859690, and trades as Claromai for our AI adoption consultancy services. Our registered office is 20-22 Wenlock Road, London, N1 7GU.
02What we collect
We collect personal data you give us directly. We don't buy or scrape lists, and we don't currently use analytics or advertising trackers on this site.
- Enquiry form: your name, business name, email address, where you heard about us, and anything you tell us about what's eating your time, submitted via the "Request my free call" form.
- Email and calls: anything you share when you email us or speak with us on a discovery call, including notes we take about your business so we can prepare an Opportunity Map.
- Client data: if you go on to become a client, the personal and business data needed to scope, build and support a workflow, as set out in your engagement agreement rather than this policy.
03How we use it
We use your data to respond to enquiries, arrange and run discovery calls, prepare proposals, and — where you become a client — to deliver and support the work agreed. We rely on the following legal bases under UK GDPR:
- Legitimate interests: responding to your enquiry and following up about a service you asked us about.
- Contract: where we're taking steps at your request before entering a contract, or performing one already in place.
- Consent: for anything beyond this, such as adding you to a mailing list — we'll ask separately and you can withdraw it at any time.
04Who we share it with
We don't sell personal data. We share it only with the service providers ("processors") that help us run the business — for example our email provider, call-scheduling tool, and the software we use to build and support client workflows — and only to the extent needed for them to provide that service to us. We may also disclose data where required by law, or to protect our legal rights.
05International transfers
Some of the tools we use to run the business are hosted outside the UK, including in the United States. Where that happens, we rely on adequacy regulations or Standard Contractual Clauses (or an equivalent, approved safeguard) to make sure your data stays protected to a UK standard.
06How long we keep it
We keep enquiry and lead data for as long as reasonably needed to follow up, and delete it if nothing progresses within 24 months. Client data is kept for the duration of the engagement and afterwards only as long as needed to meet our legal, accounting and tax obligations (normally up to 7 years for financial records).
07Cookies
This site does not currently set analytics, advertising or tracking cookies. If that changes — for example if we add website analytics — we'll update this policy and, where required, ask for your consent first.
08Your rights
Under UK GDPR, you have the right to:
- Access — ask what personal data we hold about you.
- Rectification — ask us to correct inaccurate data.
- Erasure — ask us to delete data we no longer need.
- Restriction — ask us to limit how we use your data.
- Portability — get your data in a portable format.
- Objection — object to processing based on legitimate interests.
To exercise any of these, email hello@claromai.com. If you're unhappy with how we've handled your data, you can also complain to the Information Commissioner's Office (ICO) at ico.org.uk.
09Security
We use reasonable technical and organisational measures to protect the data we hold, including access controls and working only with reputable service providers. No method of transmission or storage is completely secure, but we take proportionate steps to keep your data safe.
10Children's privacy
This site and our services are aimed at business owners and are not directed at children. We do not knowingly collect personal data from anyone under 16.
11Changes to this policy
We may update this policy from time to time, for example as our tools or services change. We'll update the date at the top of this page when we do — please check back periodically.
12Claromai Ops
This section applies to Claromai Ops, our advertising reporting application, and sits alongside the rest of this policy. It covers people who hold a Claromai Ops account and the data their organisation connects to it.
Account data. We hold each user's name, email address, role, a protected (hashed) form of their password, and a log of sign-ins and administrative actions. We use this to provide and secure the service, on the basis of our contract with the customer.
Advertising platform data. When a customer connects an advertising platform such as Meta (Facebook and Instagram) or LinkedIn, they sign in with that platform and authorise Claromai Ops to read their advertising data. We request read-only access. We receive the names and identifiers of ad accounts and campaigns, and daily figures for spend, impressions, clicks and conversions. We use this only to show that customer their own reports, forecasts and recommendations. We do not create, change or pause adverts. We do not sell this data, use it for our own advertising, share it with other customers, or combine it across customers. The access keys issued by each platform are stored encrypted.
Leads. A customer can choose to have enquiries from their own website forms, or from an advertising platform's lead forms, collected in Claromai Ops. These may include a person's name, email address, business name and message. For this data the customer is the data controller and we act as their processor, handling it only on their instructions. We do not store the IP address or browser details of the person who submitted an enquiry. If the customer connects their own CRM, leads are sent to it on their instruction.
Where it is held. Claromai Ops is hosted by Netlify, and its database by Turso, both in the United States, under the safeguards described in section 05. Stored access keys are encrypted, and each organisation's data is kept separate from every other's.
How long we keep it. We keep this data for as long as the customer's account is open. Disconnecting an advertising platform in the application removes the stored access key and the advertising data received through it. When an account is closed we delete its data within 30 days, other than records we must keep by law.
Deleting your data. To have data held in Claromai Ops deleted, including data received from Meta or another advertising platform, disconnect the platform in the application or email hello@claromai.com from the address on the account. We will confirm once it is done. You can also withdraw Claromai Ops's access at any time in the advertising platform's own settings.
13Contact us
Questions about this policy or your data? Email hello@claromai.com or write to us at Jack Summer Ltd (trading as Claromai), 20-22 Wenlock Road, London, N1 7GU.