Privacy Policy
Last updated: 26 August 2026 · Version 1.0
Contents
1. Who we are
Aphelion Solutions Ltd ("Aphelion Solutions", "we", "us", "our") is a company registered in England and Wales. We operate the website at aphelionsolutions.com and provide AI adoption advisory services and digital products.
We are the data controller for the personal data we collect about you. This means we determine how and why your data is processed.
If you have any questions about how we handle your data, contact us at ukenquiry@aphelionsolutions.com.
2. What data we collect
Data you give us directly
| Data | When collected |
|---|---|
| Name and email address | When you purchase a product, submit an intake form, contact us, or request account access |
| Organisation name | When you purchase a product or submit an intake form |
| Payment information | At checkout — handled directly by Stripe; we never see or store your card details |
| Intake form responses | When you purchase the AI Adoption Roadmap, AI Change Management Plan Generator, or complete the AI Readiness Assessment — includes business details, strategic objectives, and workforce information you choose to share |
| IP address | When you accept our Terms & Conditions at checkout |
| Communications | When you email or message us |
Data collected automatically
When you visit our website we may collect standard technical data including your IP address, browser type, pages visited, and referral source. This is used for security, performance monitoring, and understanding how visitors use the site.
Data we do not collect
We do not collect special category data (health, ethnicity, biometric, political or religious data). We do not build advertising profiles or sell your data to any third party.
3. How we use your data
| Purpose | Data used |
|---|---|
| Delivering your purchased product — generating your roadmap, plan or governance kit and emailing it to you | Name, email, organisation, intake form responses |
| Processing payment — creating a Stripe checkout session and confirming payment | Name, email, organisation |
| Sending transactional emails — order confirmation, delivery notification, magic-link sign-in | Name, email |
| Account access — allowing you to sign in to view your purchases and reports | Email, token |
| Recording Terms & Conditions acceptance — compliance record at time of purchase | Email, IP address, timestamp |
| Responding to enquiries — answering questions you send us | Name, email, message content |
| Improving our products — understanding how our AI outputs perform and where intake forms can be clearer | Aggregated, anonymised intake data |
| Legal compliance — meeting our obligations under applicable law | As required |
We do not use your data for automated decision-making that has a legal or similarly significant effect on you, beyond generating the AI output you have specifically purchased.
4. Legal basis for processing
Under UK GDPR, we must have a legal basis for processing your personal data. We rely on the following:
- Contract — processing your name, email and intake form responses is necessary to deliver the product you have purchased.
- Legitimate interests — we have a legitimate interest in improving our products, maintaining security, and understanding how visitors use our site, provided this does not override your rights.
- Legal obligation — we may process data to comply with legal obligations such as tax record-keeping and responding to lawful requests from authorities.
- Consent — where we send you marketing communications, we will ask for your explicit consent first. You can withdraw consent at any time.
5. Who we share your data with
We share your data only with the third-party processors necessary to deliver our services. We do not sell your data. Each processor is bound by a data processing agreement.
| Processor | Purpose | Location |
|---|---|---|
| Stripe | Payment processing | USA (EU-US Data Privacy Framework) |
| Resend | Transactional email delivery | USA |
| Anthropic | AI generation of roadmaps, plans and governance documents | USA |
| Supabase | Database storage of purchase records, assessments and plans | EU (AWS eu-west-2) |
| Netlify | Website hosting and serverless function execution | USA / global CDN |
We may also disclose data to law enforcement or regulatory authorities where required by law, or to protect the rights, safety or property of Aphelion Solutions or others.
6. International transfers
Some of our third-party processors are based in the United States. When we transfer personal data outside the UK, we ensure appropriate safeguards are in place, including:
- Transfers to processors covered by the UK Extension to the EU-US Data Privacy Framework;
- Standard contractual clauses approved by the UK Information Commissioner's Office (ICO); or
- Other recognised transfer mechanisms under UK GDPR.
You can request information about the specific transfer mechanisms in place by contacting us at ukenquiry@aphelionsolutions.com.
7. How long we keep your data
| Data type | Retention period |
|---|---|
| Purchase records (name, email, product) | 7 years — required for financial record-keeping |
| AI-generated outputs (roadmaps, plans, governance documents) | Until you request deletion, or 3 years from last access |
| Intake form responses | 3 years from date of submission |
| Assessment results | 3 years from date of submission |
| T&C acceptance records | 7 years — legal compliance |
| Email communications | 3 years from last contact |
| Account access tokens | Not stored — expire after 1 hour |
When data is no longer required we delete it securely or anonymise it so it can no longer be linked to you.
8. Your rights
Under UK GDPR you have the following rights in relation to your personal data:
To exercise any of these rights, email us at ukenquiry@aphelionsolutions.com. We will respond within 30 days. We may need to verify your identity before acting on a request.
Note that some rights are not absolute — for example, we may be unable to erase data we are legally required to retain.
9. Cookies
Our website uses a small number of cookies and similar technologies:
- Strictly necessary cookies — required for the site to function (e.g. session state). These cannot be disabled.
- Analytics cookies — if Google Analytics is active on the site, it uses cookies to understand how visitors interact with our pages. No personally identifiable information is shared with Google Analytics.
We do not use advertising or tracking cookies. We do not share cookie data with third parties for marketing purposes.
You can control cookies through your browser settings. Disabling certain cookies may affect site functionality.
10. Children's privacy
Our products and services are intended for business professionals and are not directed at children under the age of 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.
11. Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. The current version will always be available at aphelionsolutions.com/privacy.
Where changes are material, we will notify existing customers by email where practicable. The date at the top of this page indicates when it was last updated.
12. Contact and complaints
Get in touch
For any privacy-related questions, requests or concerns:
ukenquiry@aphelionsolutions.com
Aphelion Solutions Ltd
United Kingdom
If you are not satisfied with our response, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):
ico.org.uk/make-a-complaint · 0303 123 1113