Skip to main content

Privacy Notice

Last updated: 12 August 2026

1. Scope of this Notice

This Privacy Notice explains how Affirmed Agency Ltd uses personal data when it acts as a controller, including information about website visitors, prospective clients, Client contacts, authorised app users, payers and people who communicate with us.

Where Affirmed processes Client Personal Data only on a Client's documented instructions, the Client determines the purpose of that processing and Affirmed acts as its processor. That activity is governed by Article IV of the Affirmed Legal Framework, and the Client is responsible for its own privacy information to the affected people. This Notice does not turn processor activity into controller activity.

This Notice provides information. It is not a contract and does not itself request consent.

2. Who is responsible

Affirmed Agency Ltd is a company registered in England and Wales under company number 16475050.

  • Registered office: 124 City Road, London, England, EC1V 2NX
  • Privacy contact: louis@affirmed.co

3. Personal data we use and why

The exact data depends on how you interact with us. We obtain it from you, the Client or organisation you represent, authorised colleagues, connected platforms, payment and service providers, devices and browsers, referrals, and public business sources.

ContextPersonal dataPurposeUK lawful basis
Website operation and securityIP address, device and browser information, request and security logs, cookie choicesDeliver and protect the website, prevent abuse and diagnose faultsLegitimate interests in operating and securing our business; legal obligation where applicable
Optional analytics and advertisingOnline identifiers, consent status, page and campaign interactions, approximate location and referral informationUnderstand website use and measure or improve marketingConsent for non-essential cookies or similar technologies
Enquiries, calls and prospective relationshipsName, work contact details, role, organisation, correspondence, call or booking details, business needs and source of enquiryRespond, assess fit, prepare proposals and manage the relationshipLegitimate interests in developing and administering business relationships; steps requested before a contract where you contract personally
Client administration, invoices and agreement evidenceClient and contact identity, authority and contact details; invoice, fee, payment and tax information; the invoice and Framework records presented; acceptance wording and action; timestamps; IP address, user agent and related audit evidenceForm and administer agreements, issue and collect invoices, evidence acceptance, manage disputes and keep business recordsContract where you are personally the Client; otherwise legitimate interests in contracting with and administering the Client; legal obligations for tax and accounting records
App accounts, access and securityName, business email, profile, workspace membership, roles, authentication and access records, settings, activity, support messages, IP address, device and audit logsCreate and administer accounts, authorise access, provide support and secure the appLegitimate interests in providing and protecting the service; contract where you contract personally
Google connection administration and securityConnecting-user identity, OAuth scopes, connection status, selected-account references, timestamps, errors and security or audit recordsLet authorised users establish, administer, troubleshoot, secure or remove a Google connectionLegitimate interests in administering and securing the Client service; contract where you contract personally
Client-selected Google account accessAccount or property identifiers, names, permissions, access bindings and other data accessed or changed through Google Ads, Analytics, Tag Manager or Merchant Center on the Client's instructionsPerform the access or account-management action requested by the ClientThe Client determines the lawful basis. Affirmed acts as processor and Article IV of the Legal Framework applies
Payments and accountingPayer and billing contacts, invoice and transaction details, payment status, refund or dispute information and limited payment-method metadata supplied by StripeTake and reconcile payment, handle refunds or disputes, prevent fraud and meet accounting dutiesContract where you pay personally; legitimate interests in collecting business debts and preventing fraud; legal obligation for financial records
Business marketingName, work email, organisation, role, preferences, engagement and suppression statusSend relevant business communications and measure engagementConsent where required; otherwise legitimate interests in business-to-business marketing. You can opt out at any time
Legal, compliance and claimsRelevant identity, communications, contractual, transaction, security and evidential recordsComply with law, respond to regulators, establish or defend rights and investigate misuseLegal obligation and legitimate interests in protecting rights, people and systems

Please do not send special-category, criminal-offence or other highly sensitive personal data unless it is genuinely necessary and an appropriate lawful arrangement is in place. If Client materials contain that data, Article IV of the Legal Framework governs Affirmed's processor role.

We do not use controller data to make decisions about people based solely on automated processing that produce legal or similarly significant effects.

Information you need to provide

Client legal identity, required contact and billing details, invoice and payment information, and the identity and access information marked as required in the app are needed to create or administer an account, form or administer the Agreement, issue a valid invoice, take payment, secure access or provide the relevant service. Some information is required by law or contract; other fields are optional and identified as such. If required information is not supplied, Affirmed may be unable to create the account, enter into or administer the Agreement, issue or collect an invoice, take payment or provide the relevant feature or service.

4. Cookies and similar technologies

We use strictly necessary technology to operate the website and remember privacy choices. With your consent, Google Tag Manager may enable analytics or advertising technologies, including Google Analytics and Google Ads, to measure visits and campaigns. Embedded media, including YouTube's privacy-enhanced player, may receive device or usage information when you choose to load or play it.

CookieHub provides the consent controls shown on the website. You can accept, reject or change non-essential categories through those controls. Withdrawing consent does not affect processing that occurred before withdrawal.

5. Google API data and app connections

When an authorised app user connects Google services, Affirmed requests only the scopes needed for the connection features selected. Depending on the service, this may include:

  • Google Ads accessible customer account IDs, names, currency, advertiser or manager status, manager-link status and permissions;
  • Google Analytics 4 account and property summaries, property IDs and names, access bindings and permissions;
  • Google Tag Manager account and container identifiers, names, public container IDs, user permissions and access information;
  • Google Merchant Center merchant account identifiers, names, user access and permissions; and
  • Google OAuth refresh tokens, granted scopes, connection status, selected account metadata, connecting-user identifiers, timestamps and related status or error information.

We use this data only to display available accounts; create, accept, verify, manage or remove authorised access; maintain connection status; troubleshoot and secure the feature; and comply with applicable legal or abuse-prevention duties.

Affirmed acts as controller when it processes the connecting user's identity and related connection-administration, security and audit records for its own service administration. Where Affirmed accesses or changes Client-selected account or property data solely on the Client's instructions, Affirmed acts as processor and Article IV of the Legal Framework applies.

We do not sell Google user data or use it for retargeting, interest-based advertising, credit decisions, data brokerage, unrelated profiling or training general artificial-intelligence models. Website analytics and advertising described in section 4 concern website-visitor data and do not apply to data received through Google OAuth or Google APIs.

Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.

Google connection data may be shared with Google to perform the requested action, Supabase to store connection records, and limited authorised personnel and service providers needed to operate and secure the app. We do not intentionally include OAuth tokens in error-monitoring data.

OAuth refresh tokens and connection metadata are kept while needed to provide the connected feature. When all Google services for a workspace are disconnected, we revoke the shared token where possible and delete the stored token record. Disconnecting a particular service removes its connection record and, where supported, Affirmed's access. Limited security, audit, legal or dispute records may be retained where necessary.

Users can disconnect Google services inside the app or email louis@affirmed.co for help removing access or connection data.

6. AI services used on Client instructions

This section provides operational transparency about disclosures made while Affirmed acts on a Client's instructions. It does not make those operations Affirmed's independent-controller processing or alter Article IV of the Legal Framework.

Affirmed may use both processor AI services and AI services whose providers independently determine some purposes and essential means.

Where a provider acts as Affirmed's subprocessor, it is identified in the Subprocessor Register and Article IV applies.

Where a provider acts as an independent controller, the Client instructs and authorises the disclosure under clause 26.4. The provider's own terms and privacy information govern its independent processing, which may include security, abuse prevention, legal compliance, service administration or service or model improvement. The Client remains responsible for ensuring that its lawful basis, privacy information and other controller obligations cover the instructed disclosure. Affirmed remains responsible for security and transfer obligations imposed directly on Affirmed by applicable law.

Affirmed currently uses ChatGPT Pro, supplied to UK users by OpenAI OpCo, LLC in the United States, and Claude Max, supplied to UK users by Anthropic Ireland, Limited in Ireland, as independent-controller AI services. They are not listed as subprocessors merely because they receive information under that arrangement. Inputs may include the data categories described in clause 25.4 of the Legal Framework, including identifiable, customer-level or bulk data where lawful and appropriate; sensitive data described in clause 25.5 is excluded unless separately agreed. The precise retention, training and other processing treatment depends on the provider's then-current terms, settings and privacy information.

Because ChatGPT Pro is a consumer service supplied from the United States, Affirmed does not treat the consumer subscription alone as a UK restricted-transfer safeguard. Affirmed submits Client Personal Data through ChatGPT Pro only where an applicable valid transfer mechanism or statutory exception covers the disclosure; otherwise it uses non-personal or effectively anonymised material, or routes the task through an authorised business or API service.

7. Who receives personal data

We disclose personal data only where reasonably needed for the purposes above, including to:

  • personnel and contractors who need it for their role and are subject to confidentiality duties;
  • infrastructure, database, storage, monitoring and AI providers, including those identified in the Subprocessor Register where they process Client Personal Data;
  • Plus Five Five, Inc., trading as Resend, for transactional account, invitation, billing and service emails;
  • Stripe for payment processing; Google for connected services and website analytics or advertising; CookieHub for consent management; and YouTube when embedded media is loaded;
  • the Client or organisation you represent and its authorised users;
  • professional advisers, insurers, auditors, prospective purchasers or successors under appropriate confidentiality protections; and
  • courts, regulators, law-enforcement bodies or other recipients where lawfully required or necessary to protect rights and safety.

Google and other connected platforms may act as independent controllers for some activity. Their own terms and privacy information then apply.

8. International transfers

Affirmed operates from the United Kingdom and uses providers whose personnel, infrastructure or subprocessors may be located in other countries. Where UK transfer restrictions apply, we use an available lawful mechanism appropriate to the transfer, such as UK adequacy regulations, the UK Extension to the EU-US Data Privacy Framework where the recipient's certification applies, the UK International Data Transfer Agreement, or the UK Addendum to approved EU Standard Contractual Clauses. We may also use supplementary technical or organisational measures where appropriate.

The Subprocessor Register describes the current locations and mechanisms for Client Personal Data processed by subprocessors under Article IV. The main transfers made for Affirmed's controller activities and the current processor-side disclosures to independent-controller AI services under clause 26.4 are summarised below. A provider may use additional locations through its published subprocessor list or privacy information.

RecipientMain processing locationsSafeguard used for restricted transfers
Stripe group entities — payments, refunds, disputes and fraud preventionUnited Kingdom, Ireland, United States and global support locationsUK adequacy regulations for qualifying Irish processing; the UK Extension to the EU-US Data Privacy Framework for certified US recipients, or the UK Addendum to approved EU Standard Contractual Clauses, as applicable
Google group entities — connected-service administration, analytics, advertising and YouTubeUnited Kingdom, EEA, United States and Google's global infrastructureUK adequacy regulations for qualifying EEA processing; the UK Extension to the EU-US Data Privacy Framework for certified US recipients, or approved contractual clauses where required
CookieHub ehf — website consent managementIceland and its disclosed service-provider locationsUK adequacy regulations for Iceland; Standard Contractual Clauses or another valid safeguard for restricted onward transfers
OpenAI OpCo, LLC — ChatGPT Pro used on Client instructionsUnited States and OpenAI's disclosed global service-provider locationsClient Personal Data is disclosed only where an applicable valid transfer mechanism or statutory exception covers the initial transfer; otherwise Affirmed uses non-personal or effectively anonymised material, or an authorised business or API service. OpenAI states that its own restricted transfers rely on SCCs and the UK Addendum.
Anthropic Ireland, Limited — Claude Max used on Client instructionsIreland and Anthropic's disclosed global service-provider locationsUK adequacy regulations cover the initial transfer to Ireland. Anthropic states that adequacy decisions and SCCs protect restricted onward transfers.
Plus Five Five, Inc. (Resend) — transactional emailsUnited States and disclosed subprocessor locationsThe UK Addendum to approved EU Standard Contractual Clauses
Supabase, Inc. — controller-side app, account and security recordsUnited Kingdom project region, with limited United States or global support and subprocessor accessThe UK Addendum to approved EU Standard Contractual Clauses where required
Vercel Inc. — website and app hosting, request processing and securityUnited States and global edge or support locationsThe UK Addendum to approved EU Standard Contractual Clauses where required
Functional Software, Inc. (Sentry) — error, security and performance monitoringGermany, United States and disclosed subprocessor locationsUK adequacy regulations for qualifying German processing; the UK Extension to the EU-US Data Privacy Framework or the UK Addendum to approved EU Standard Contractual Clauses where required

You may ask for further information or a copy of a relevant safeguard, subject to necessary redactions, by emailing louis@affirmed.co.

9. How long we keep controller data

We keep personal data only for as long as reasonably needed for its purpose, taking account of legal, accounting, security and dispute requirements. Our usual criteria are:

  • enquiry and prospect records: while discussions remain active and ordinarily no more than 24 months after the last meaningful contact;
  • Client relationship, agreement, invoice, payment and acceptance-evidence records: throughout the relationship and ordinarily six years afterward, or longer where a live claim or legal requirement applies;
  • app account data: while the account is active and for a limited period needed for closure, security, restoration or dispute handling;
  • routine security and audit logs: according to the applicable system cycle, ordinarily no more than 24 months unless needed for an incident or claim;
  • marketing contacts: until you opt out or the information is no longer useful, with a minimal suppression record retained to respect the opt-out; and
  • Google connection data: as described in section 5.

Client Personal Data held in Affirmed's processor capacity is returned or deleted under Article IV of the Legal Framework rather than these controller-retention periods.

10. Your rights and choices

Depending on the law and circumstances, you may have rights to request access, correction, deletion, restriction or portability of your personal data, and to object to processing. Where processing relies on consent, you may withdraw it at any time. These rights are not absolute and exemptions may apply.

Your right to object: You may object at any time to the use of your personal data for direct marketing. You may also object to processing based on legitimate interests; whether Affirmed must stop depends on applicable law and the circumstances.

To exercise a right or ask a privacy question, email louis@affirmed.co. We may need proportionate information to verify your identity and authority. If Affirmed holds the data only as a processor for a Client, we will normally direct the request to that Client.

You may complain to the UK Information Commissioner's Office or another regulator with jurisdiction. We would appreciate the opportunity to address the issue first.

11. Children

Affirmed provides business services and does not knowingly offer the website or app to children. Please contact us if you believe a child has supplied personal data directly to Affirmed inappropriately.

12. Changes

We update this Notice when our controller processing or legal obligations change and publish the current text on this page with its updated date. Where a change materially affects how we use data already collected, we will take reasonable steps to bring it to the attention of affected people before the new use where required.