Privacy Policy
This Privacy Policy explains what data we collect, how we use it, the lawful bases for processing, how long we keep it, and your rights as a data subject.
Effective date: 10 September 2026
Version: 2.0
01
About BABL & Your Data
BABL AI Inc. (“BABL AI”, “we”, “us”, or “our”) provides AI audit and assurance, advisory, education, research, and related services.
We are committed to protecting the privacy and security of personal data in accordance with:
- the UK General Data Protection Regulation (UK GDPR);
- the EU General Data Protection Regulation (EU GDPR), where applicable;
- the Data Protection Act 2018; and
- the Privacy and Electronic Communications Regulations 2003 (PECR), as amended.
This Privacy Policy explains what data we collect, how we use it, the lawful bases for processing, how long we keep it, and your rights as a data subject.
Data Controller: BABL AI Inc.
Registered address: 630 Fairchild St, Iowa City, IA 52245
Email for privacy enquiries: security@babl.ai
BABL AI may act as a controller or processor depending on the circumstances and the processing activity.
We generally act as a controller when we determine why and how personal data is processed, including for our website, marketing, events, education services, business development, administration, and our own legal or security obligations.
In some client engagements, we may act as a processor where we process personal data solely on a client’s documented instructions. Where required, those activities are governed by a data processing agreement.
In some professional services activities, BABL may act as an independent controller where we need to exercise independent professional judgment or process information for our own legal, regulatory, security, or professional obligations.
Typical categories:
- Contact & Identification: name, email, phone, organization, role/title, business address
- Account & Education: account details, enrolments, course progress, assessments, certification records, and related learning information
- Client Service: audit documentation, meeting notes, contracts, project deliverables, billing details
- Events & Webinars: registration details, attendance, Q&A/polls/chat, video/audio where recorded
- Marketing & Communications: subscription status, engagement metrics, campaign attribution, CRM history
- Technical & Usage: IP address, device data, browser/OS, logs, page views, session metadata, error reports
- Special Category Data: We do not generally seek to collect special category data. However, it may occasionally be provided to us in connection with a client engagement or other interaction. Where this occurs, we handle it in accordance with applicable law and contractual requirements.
- Children’s Data: Our services are not directed to individuals under 18. We do not knowingly collect such data.
- Directly from you: forms, email/phone, LMS accounts, event registrations, subscriptions, contracts
- From clients: during audit/advisory engagements via secure transfer
- From third parties and public sources: professional networking platforms, company websites, business directories, partners, event organizers, and other lawful sources
02
How We Use Personal Data
| Purpose | Examples | Lawful Basis (GDPR Art 6) |
| Deliver contracted services | Audits, advisory, education, certifications | Contract (where the individual is party to the contract) and/or legitimate interests |
| Operate learning platform | Account creation, progress tracking, assessments, certificates | Contract (6(1)(b)) / Legitimate interests (6(1)(f)) |
| Host webinars & events | Registration, attendance, live hosting | Contract and/or legitimate interests, depending on the event and relationship |
| Record webinars | Recording, storage, reuse where stated | Consent (6(1)(a)) |
| Marketing & CRM | Newsletters, updates, event invites, co-marketing | Consent and/or legitimate interests, subject to applicable electronic marketing rules, including PECR |
| Security & compliance | Access logs, monitoring, risk assessments, legal requests | Legal obligation (6(1)(c)) / Legitimate interests (6(1)(f)) |
| Analytics & improvement | Usage metrics, performance, UX research | Consent and/or legitimate interests, depending on the technology and applicable legal requirements |
| Research & statistics | Aggregated/anonymized industry insights | Legitimate interests, where applicable |
| Legal claims/defence | Respond to claims/requests, maintain audit trail | Legal obligation (6(1)(c)) / Legitimate interests (6(1)(f)) |
| Business operations | Invoicing, payments, supplier management, HR | Contract (6(1)(b)) / Legal obligation (6(1)(c)) |
Where we rely on legitimate interests, we assess whether our interests are necessary and appropriately balanced against the rights and interests of affected individuals. You may object at any time.
03
Sharing & International Transfers
We use third-party service providers to support our operations. Depending on the service and processing activity, these organisations may act as processors, independent controllers, or other recipients of personal data.
Typical categories:
- Communication & Events: Zoom; Google Meets, Zoho One
- Email & Marketing: Zoho One
- Hosting & Infrastructure: Google Workspace; Cloudflare
- Business & CRM: Zoho One; Stripe/PayPal, Quickbooks
- Learning Management: WordPress, Teachable
- Analytics/UX: Google Analytics 4
Subprocessor List: maintained at www.babl.ai/subprocessors.
Change Notification: Where required by our agreements, we notify relevant clients of material changes to subprocessors in accordance with the applicable contractual terms.
We never sell your data, ever.
Some processors access/store data outside the UK/EEA (e.g., US). We comply with UK GDPR Chapter V and EU GDPR Chapter V (Articles 44–49) using:
- EU Standard Contractual Clauses (SCCs) (Art 46(2)(c))
- UK International Data Transfer Addendum (IDTA) (for UK transfers)
- Transfer Impact Assessments (TIAs) and supplementary measures
Security measures include TLS in transit, encryption at rest, MFA, and contractual commitments regarding government access requests. Where feasible/contracted, we offer UK/EEA storage options.
04
Retention, Security, & Privacy Controls
We keep data only as long as necessary for stated purposes and legal obligations. We retain personal data for no longer than necessary for the purposes for which it was collected, including to provide our services, comply with legal and regulatory requirements, establish or defend legal claims, and maintain appropriate business records.
Retention periods vary according to the nature of the information, the purposes for which it is processed, contractual obligations, applicable limitation periods, and legal or regulatory requirements.
When personal data is no longer required, we securely delete or anonymise it in accordance with our retention procedures.
We maintain appropriate technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access.
Our security measures may include, as appropriate:
- access controls and least-privilege principles;
- multi-factor authentication;
- encryption in transit and at rest where supported and appropriate;
- security logging and monitoring;
- staff security and privacy training;
- supplier risk management;
- incident response procedures; and
- business continuity and recovery measures.
We review and develop our security controls as part of our information security management program.
We carry out data protection impact assessments where required, including where proposed processing is likely to result in a high risk to individuals’ rights and freedoms. DPIAs assess the necessity and proportionality of the processing, relevant privacy risks, and appropriate safeguards.
We apply data protection by design and by default where appropriate and seek to minimise the personal data we collect and use. We consider privacy and data protection when designing new systems, services, forms, and processing activities.
Our Breach Response Playbook is aligned with ISO/IEC 27001:2022 A.5.24–A.5.28 and GDPR Arts 33–34:
- Assess and respond to suspected personal data breaches without undue delay;
- Where required, notify the relevant supervisory authority without undue delay and, where applicable, within 72 hours of becoming aware of the breach;
- Notify affected individuals without undue delay where risk is high (Art 34);
- If we act as processor, notify the controller without undue delay; and
- Maintain a breach log (Art 33(5)).
We review legal requests for validity, jurisdiction, and scope, and disclose personal data only where required or permitted by law. Where appropriate and legally permitted, we may notify affected individuals.
05
Marketing, Events, & Business Relationships
We process personal data for marketing in accordance with applicable data protection and electronic marketing laws.
Where required, we obtain consent before sending electronic marketing.
In certain circumstances, we may rely on the products and services “soft opt-in.” This applies only where we obtained an individual subscriber’s contact details in the course of a sale or negotiation of a sale, the marketing relates to our own similar products or services, and we provided a clear opportunity to opt out when the details were collected and in each subsequent marketing communication.
For corporate subscribers, PECR generally does not require prior consent for electronic mail marketing. However, where the contact information relates to an identifiable individual, EU/UK GDPR still applies and we must have an appropriate lawful basis.
Sole traders and certain partnerships are treated as individual subscribers under PECR.
You may unsubscribe from marketing or object to direct marketing at any time.
We host webinars, training sessions, and other events using third-party conferencing and event platforms.
Typical categories:
- Data collected: registration details, attendance, Q&A/polls/chat; recordings (video/audio) where applicable
- Basis: registration/attendance under legitimate interests (6(1)(f)); Where an event is recorded, we provide appropriate notice and identify the applicable lawful basis.
- Practices: notice at registration and event start; secure storage; 12-month retention unless extended by consent.
- Transfers: protected by SCCs/IDTA and platform security; see our subprocessor list. Participants may object to recording, request copies of their data, or request deletion (subject to legitimate retention needs).
We process business contact information for purposes such as managing relationships with current and prospective clients, professional contacts, suppliers, and partners; responding to enquiries; administering contracts; and communicating about relevant business matters. Where appropriate, we rely on legitimate interests for this processing.
Personal data relating to employees, job applicants, and contractors is handled in accordance with applicable law and any separate privacy notices or internal policies provided to those individuals.
06
AI, Research, & Cookies
We may use aggregated or effectively anonymised information for research, statistical analysis, and service improvement. Where information has been anonymised so that an individual is no longer identifiable, it is no longer treated as personal data under applicable data protection law.
We do not currently use solely automated decision-making about individuals that produces legal or similarly significant effects. We may use AI-assisted tools in our operations or professional services, subject to appropriate human oversight and applicable confidentiality, security, and data protection requirements. At BABL AI our work is always human initiated, directed and reviewed. Accountability and responsibility always lies with a person.
We use cookies and similar technologies on our website. Some are necessary for the operation and security of the site, while others may support preferences, analytics, or marketing.
Where required by applicable law, we obtain consent before using non-essential cookies or similar technologies.
You can manage your choices through our cookie banner or Cookie Settings. For further information about the technologies we use, their purposes, and their duration, see our Cookie Policy at www.babl.ai/cookie-policy.
07
Subprocessors
Where BABL acts as a processor and engages another processor to assist with that processing, we do so in accordance with applicable data protection law and our contractual commitments.
Information about relevant subprocessors is available on our Subprocessors page: maintained at www.babl.ai/subprocessors
Where required by the applicable agreement, we provide clients with notice of material subprocessor changes and any applicable opportunity to object.
08
Your Rights & Complaints
Depending on applicable law and the circumstances of our processing, you may have rights in relation to your personal data, including the right to: UK/EU GDPR to access (Art 15), rectify (Art 16), erase (Art 17), restrict (Art 18), portability (Art 20), object (Art 21), withdraw consent (Art 7(3)), and not be subject to automated decisions (Art 22).
How to exercise: Email security@babl.ai. We generally respond to valid requests within the timeframe required by applicable law. Under UK/EU GDPR, this is normally within one month, subject to permitted extensions in certain circumstances.
Please contact us first at security@babl.ai so we can address your concern.
You may also lodge a complaint with your supervisory authority (GDPR Art 77):
United Kingdom – Information Commissioner’s Office (ICO)
https://ico.org.uk | +44 303 123 1113 | Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
If the EU GDPR applies, you may also have the right to lodge a complaint with the supervisory authority in the EEA country where you live or work, or where you believe a data protection infringement occurred.
A list of other EEA authorities: https://edpb.europa.eu/about-edpb/about-edpb/members_en
(One-stop-shop generally applies to EEA-established controllers; as a non-EEA controller, we cooperate with relevant authorities via our EU Representative.)
09
Changes & Contact
We may update this Privacy Policy from time to time to reflect changes in our services, practices, legal requirements, or other circumstances. The latest version will be published on our website with an updated effective date. Where appropriate or required, we may provide additional notice of material changes.
If you have questions about this Privacy Policy, our privacy practices, or the way we handle your personal data, please contact:
BABL AI Inc.
630 Fairchild St
Iowa City, IA 52245
United States
Privacy enquiries: security@babl.ai
General enquiries: info@babl.ai