Last updated: 12 August 2026
This Privacy Notice explains how Affirmed Agency Ltd uses personal data when it acts as a controller, including information about website visitors, prospective clients, Client contacts, authorised app users, payers and people who communicate with us.
Where Affirmed processes Client Personal Data only on a Client's documented instructions, the Client determines the purpose of that processing and Affirmed acts as its processor. That activity is governed by Article IV of the Affirmed Legal Framework, and the Client is responsible for its own privacy information to the affected people. This Notice does not turn processor activity into controller activity.
This Notice provides information. It is not a contract and does not itself request consent.
Affirmed Agency Ltd is a company registered in England and Wales under company number 16475050.
The exact data depends on how you interact with us. We obtain it from you, the Client or organisation you represent, authorised colleagues, connected platforms, payment and service providers, devices and browsers, referrals, and public business sources.
| Context | Personal data | Purpose | UK lawful basis |
|---|---|---|---|
| Website operation and security | IP address, device and browser information, request and security logs, cookie choices | Deliver and protect the website, prevent abuse and diagnose faults | Legitimate interests in operating and securing our business; legal obligation where applicable |
| Optional analytics and advertising | Online identifiers, consent status, page and campaign interactions, approximate location and referral information | Understand website use and measure or improve marketing | Consent for non-essential cookies or similar technologies |
| Enquiries, calls and prospective relationships | Name, work contact details, role, organisation, correspondence, call or booking details, business needs and source of enquiry | Respond, assess fit, prepare proposals and manage the relationship | Legitimate interests in developing and administering business relationships; steps requested before a contract where you contract personally |
| Client administration, invoices and agreement evidence | Client and contact identity, authority and contact details; invoice, fee, payment and tax information; the invoice and Framework records presented; acceptance wording and action; timestamps; IP address, user agent and related audit evidence | Form and administer agreements, issue and collect invoices, evidence acceptance, manage disputes and keep business records | Contract where you are personally the Client; otherwise legitimate interests in contracting with and administering the Client; legal obligations for tax and accounting records |
| App accounts, access and security | Name, business email, profile, workspace membership, roles, authentication and access records, settings, activity, support messages, IP address, device and audit logs | Create and administer accounts, authorise access, provide support and secure the app | Legitimate interests in providing and protecting the service; contract where you contract personally |
| Google connection administration and security | Connecting-user identity, OAuth scopes, connection status, selected-account references, timestamps, errors and security or audit records | Let authorised users establish, administer, troubleshoot, secure or remove a Google connection | Legitimate interests in administering and securing the Client service; contract where you contract personally |
| Client-selected Google account access | Account or property identifiers, names, permissions, access bindings and other data accessed or changed through Google Ads, Analytics, Tag Manager or Merchant Center on the Client's instructions | Perform the access or account-management action requested by the Client | The Client determines the lawful basis. Affirmed acts as processor and Article IV of the Legal Framework applies |
| Payments and accounting | Payer and billing contacts, invoice and transaction details, payment status, refund or dispute information and limited payment-method metadata supplied by Stripe | Take and reconcile payment, handle refunds or disputes, prevent fraud and meet accounting duties | Contract where you pay personally; legitimate interests in collecting business debts and preventing fraud; legal obligation for financial records |
| Business marketing | Name, work email, organisation, role, preferences, engagement and suppression status | Send relevant business communications and measure engagement | Consent where required; otherwise legitimate interests in business-to-business marketing. You can opt out at any time |
| Legal, compliance and claims | Relevant identity, communications, contractual, transaction, security and evidential records | Comply with law, respond to regulators, establish or defend rights and investigate misuse | Legal obligation and legitimate interests in protecting rights, people and systems |
Please do not send special-category, criminal-offence or other highly sensitive personal data unless it is genuinely necessary and an appropriate lawful arrangement is in place. If Client materials contain that data, Article IV of the Legal Framework governs Affirmed's processor role.
We do not use controller data to make decisions about people based solely on automated processing that produce legal or similarly significant effects.
Client legal identity, required contact and billing details, invoice and payment information, and the identity and access information marked as required in the app are needed to create or administer an account, form or administer the Agreement, issue a valid invoice, take payment, secure access or provide the relevant service. Some information is required by law or contract; other fields are optional and identified as such. If required information is not supplied, Affirmed may be unable to create the account, enter into or administer the Agreement, issue or collect an invoice, take payment or provide the relevant feature or service.
We use strictly necessary technology to operate the website and remember privacy choices. With your consent, Google Tag Manager may enable analytics or advertising technologies, including Google Analytics and Google Ads, to measure visits and campaigns. Embedded media, including YouTube's privacy-enhanced player, may receive device or usage information when you choose to load or play it.
CookieHub provides the consent controls shown on the website. You can accept, reject or change non-essential categories through those controls. Withdrawing consent does not affect processing that occurred before withdrawal.
When an authorised app user connects Google services, Affirmed requests only the scopes needed for the connection features selected. Depending on the service, this may include:
We use this data only to display available accounts; create, accept, verify, manage or remove authorised access; maintain connection status; troubleshoot and secure the feature; and comply with applicable legal or abuse-prevention duties.
Affirmed acts as controller when it processes the connecting user's identity and related connection-administration, security and audit records for its own service administration. Where Affirmed accesses or changes Client-selected account or property data solely on the Client's instructions, Affirmed acts as processor and Article IV of the Legal Framework applies.
We do not sell Google user data or use it for retargeting, interest-based advertising, credit decisions, data brokerage, unrelated profiling or training general artificial-intelligence models. Website analytics and advertising described in section 4 concern website-visitor data and do not apply to data received through Google OAuth or Google APIs.
Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
Google connection data may be shared with Google to perform the requested action, Supabase to store connection records, and limited authorised personnel and service providers needed to operate and secure the app. We do not intentionally include OAuth tokens in error-monitoring data.
OAuth refresh tokens and connection metadata are kept while needed to provide the connected feature. When all Google services for a workspace are disconnected, we revoke the shared token where possible and delete the stored token record. Disconnecting a particular service removes its connection record and, where supported, Affirmed's access. Limited security, audit, legal or dispute records may be retained where necessary.
Users can disconnect Google services inside the app or email louis@affirmed.co for help removing access or connection data.
This section provides operational transparency about disclosures made while Affirmed acts on a Client's instructions. It does not make those operations Affirmed's independent-controller processing or alter Article IV of the Legal Framework.
Affirmed may use both processor AI services and AI services whose providers independently determine some purposes and essential means.
Where a provider acts as Affirmed's subprocessor, it is identified in the Subprocessor Register and Article IV applies.
Where a provider acts as an independent controller, the Client instructs and authorises the disclosure under clause 26.4. The provider's own terms and privacy information govern its independent processing, which may include security, abuse prevention, legal compliance, service administration or service or model improvement. The Client remains responsible for ensuring that its lawful basis, privacy information and other controller obligations cover the instructed disclosure. Affirmed remains responsible for security and transfer obligations imposed directly on Affirmed by applicable law.
Affirmed currently uses ChatGPT Pro, supplied to UK users by OpenAI OpCo, LLC in the United States, and Claude Max, supplied to UK users by Anthropic Ireland, Limited in Ireland, as independent-controller AI services. They are not listed as subprocessors merely because they receive information under that arrangement. Inputs may include the data categories described in clause 25.4 of the Legal Framework, including identifiable, customer-level or bulk data where lawful and appropriate; sensitive data described in clause 25.5 is excluded unless separately agreed. The precise retention, training and other processing treatment depends on the provider's then-current terms, settings and privacy information.
Because ChatGPT Pro is a consumer service supplied from the United States, Affirmed does not treat the consumer subscription alone as a UK restricted-transfer safeguard. Affirmed submits Client Personal Data through ChatGPT Pro only where an applicable valid transfer mechanism or statutory exception covers the disclosure; otherwise it uses non-personal or effectively anonymised material, or routes the task through an authorised business or API service.
We disclose personal data only where reasonably needed for the purposes above, including to:
Google and other connected platforms may act as independent controllers for some activity. Their own terms and privacy information then apply.
Affirmed operates from the United Kingdom and uses providers whose personnel, infrastructure or subprocessors may be located in other countries. Where UK transfer restrictions apply, we use an available lawful mechanism appropriate to the transfer, such as UK adequacy regulations, the UK Extension to the EU-US Data Privacy Framework where the recipient's certification applies, the UK International Data Transfer Agreement, or the UK Addendum to approved EU Standard Contractual Clauses. We may also use supplementary technical or organisational measures where appropriate.
The Subprocessor Register describes the current locations and mechanisms for Client Personal Data processed by subprocessors under Article IV. The main transfers made for Affirmed's controller activities and the current processor-side disclosures to independent-controller AI services under clause 26.4 are summarised below. A provider may use additional locations through its published subprocessor list or privacy information.
| Recipient | Main processing locations | Safeguard used for restricted transfers |
|---|---|---|
| Stripe group entities — payments, refunds, disputes and fraud prevention | United Kingdom, Ireland, United States and global support locations | UK adequacy regulations for qualifying Irish processing; the UK Extension to the EU-US Data Privacy Framework for certified US recipients, or the UK Addendum to approved EU Standard Contractual Clauses, as applicable |
| Google group entities — connected-service administration, analytics, advertising and YouTube | United Kingdom, EEA, United States and Google's global infrastructure | UK adequacy regulations for qualifying EEA processing; the UK Extension to the EU-US Data Privacy Framework for certified US recipients, or approved contractual clauses where required |
| CookieHub ehf — website consent management | Iceland and its disclosed service-provider locations | UK adequacy regulations for Iceland; Standard Contractual Clauses or another valid safeguard for restricted onward transfers |
| OpenAI OpCo, LLC — ChatGPT Pro used on Client instructions | United States and OpenAI's disclosed global service-provider locations | Client Personal Data is disclosed only where an applicable valid transfer mechanism or statutory exception covers the initial transfer; otherwise Affirmed uses non-personal or effectively anonymised material, or an authorised business or API service. OpenAI states that its own restricted transfers rely on SCCs and the UK Addendum. |
| Anthropic Ireland, Limited — Claude Max used on Client instructions | Ireland and Anthropic's disclosed global service-provider locations | UK adequacy regulations cover the initial transfer to Ireland. Anthropic states that adequacy decisions and SCCs protect restricted onward transfers. |
| Plus Five Five, Inc. (Resend) — transactional emails | United States and disclosed subprocessor locations | The UK Addendum to approved EU Standard Contractual Clauses |
| Supabase, Inc. — controller-side app, account and security records | United Kingdom project region, with limited United States or global support and subprocessor access | The UK Addendum to approved EU Standard Contractual Clauses where required |
| Vercel Inc. — website and app hosting, request processing and security | United States and global edge or support locations | The UK Addendum to approved EU Standard Contractual Clauses where required |
| Functional Software, Inc. (Sentry) — error, security and performance monitoring | Germany, United States and disclosed subprocessor locations | UK adequacy regulations for qualifying German processing; the UK Extension to the EU-US Data Privacy Framework or the UK Addendum to approved EU Standard Contractual Clauses where required |
You may ask for further information or a copy of a relevant safeguard, subject to necessary redactions, by emailing louis@affirmed.co.
We keep personal data only for as long as reasonably needed for its purpose, taking account of legal, accounting, security and dispute requirements. Our usual criteria are:
Client Personal Data held in Affirmed's processor capacity is returned or deleted under Article IV of the Legal Framework rather than these controller-retention periods.
Depending on the law and circumstances, you may have rights to request access, correction, deletion, restriction or portability of your personal data, and to object to processing. Where processing relies on consent, you may withdraw it at any time. These rights are not absolute and exemptions may apply.
Your right to object: You may object at any time to the use of your personal data for direct marketing. You may also object to processing based on legitimate interests; whether Affirmed must stop depends on applicable law and the circumstances.
To exercise a right or ask a privacy question, email louis@affirmed.co. We may need proportionate information to verify your identity and authority. If Affirmed holds the data only as a processor for a Client, we will normally direct the request to that Client.
You may complain to the UK Information Commissioner's Office or another regulator with jurisdiction. We would appreciate the opportunity to address the issue first.
Affirmed provides business services and does not knowingly offer the website or app to children. Please contact us if you believe a child has supplied personal data directly to Affirmed inappropriately.
We update this Notice when our controller processing or legal obligations change and publish the current text on this page with its updated date. Where a change materially affects how we use data already collected, we will take reasonable steps to bring it to the attention of affected people before the new use where required.