Privacy Policy of Estimo AI
This Privacy Policy explains how PICOSOFT AI LTD (company number 16525762) (“Picosoft AI”, “we”, “us”, or “our”) collects, uses, stores, and protects personal data when you access or use Estimo AI (the “Service”).
This Privacy Policy should be read together with our Terms and Conditions.
1. Who We Are
1.1 Company Information
Picosoft AI Ltd is a company incorporated in England and Wales (company number 16525762). Contact: contact@estimo.ai.
1.2 Data Controller (Our Responsibility)
We act as the Data Controller only for personal data that we collect directly for our own purposes, such as your account name, email address, and billing information.
1.3 Data Processor (Your Responsibility)
In relation to User Content (e.g., names, addresses, or details of your clients that you input into the Service), you are the Data Controller and we are the Data Processor. You warrant that you have a lawful basis and any necessary consents to provide such third-party personal data to us for processing. We process this data strictly to generate AI Outputs as instructed by you.
2. Scope of This Policy
This Privacy Policy applies to:
- Visitors to our website;
- Users who create an account or use the Service;
- Communications with us by email or other means.
It does not apply to third-party websites or services linked from the Service.
3. Personal Data We Collect
We may collect and process the following categories of personal data:
3.1 Account and Contact Data
- Name
- Email address
- Account credentials
- Billing and subscription status
3.2 Usage and Technical Data
- IP address
- Device and browser information
- Log files and usage activity
- Date and time of access
3.3 User Content
- Text and information submitted by you for the purpose of drafting quotes
We do not intentionally collect special category personal data.
4. How We Use Personal Data
We process personal data for the following purposes:
- To provide, operate, and maintain the Service;
- To generate AI-assisted draft outputs based on user input;
- To manage accounts, subscriptions, and payments;
- To communicate with users regarding service-related matters;
- To monitor usage, performance, and security;
- To improve and develop the Service using aggregated and anonymised data;
- To comply with legal and regulatory obligations.
5. Legal Bases for Processing
We rely on the following legal bases under UK GDPR and EU GDPR:
- Contract: processing necessary to provide the Service;
- Legitimate interests: operating, securing, and improving the Service;
- Legal obligation: compliance with applicable laws;
- Consent: where required by law (e.g. certain communications).
You agree not to submit:
- Health data, biometric data, or other special category personal data;
- Financial account numbers, payment card data, or banking credentials;
- Government-issued identification numbers or documents;
- Any personal data you are not lawfully entitled to process.
You remain solely responsible for the accuracy, completeness, and lawfulness of all User Content you submit. We are not responsible for errors or omissions resulting from inaccurate or incomplete User Content.
No Client / Third-Party Relationship
- We have no contractual or other relationship with your clients, customers, or end users. No third party may rely on the Service or any AI Output.
- Exclusion for Modified / Exported Outputs
- We shall have no liability for AI Outputs once exported from the Service, or where such outputs are modified, adapted, combined, or reused by you or any third party.
- User-Provided Data Disclaimer
- We shall not be liable for any loss or damage arising from errors, inaccuracies, or omissions in User Content provided by you.
6. AI Processing and Data Use
User Content submitted to the Service is processed by automated systems solely for the purpose of generating AI-assisted draft outputs as requested by the user.
We do not use User Content to identify individuals, perform profiling, or make automated decisions producing legal or similarly significant effects.
We do not use identifiable User Content to train general-purpose AI models.
We may use aggregated and anonymised data derived from use of the Service for analytics, system performance monitoring, model evaluation, and service improvement. Such data does not identify individual users and cannot reasonably be re-identified.
7. Data Sharing and Third Parties
We do not sell your personal data. To provide and secure the Service, we share data with trusted third-party sub-processors. By using the Service, you acknowledge that your data is subject to the privacy practices of these providers:
- AI Processing (OpenAI): We use OpenAI’s API to generate AI Outputs. User Content submitted via the API is not used by OpenAI to train their global models.
- Payment Processing (Stripe): All financial transactions are handled by Stripe. We do not store or have access to your credit card or banking credentials; Stripe acts as an independent controller for these transactions.
- Analytics and Monitoring (Google Analytics & Microsoft Clarity): We use these tools to capture how you interact with our website through behavioral metrics and heatmaps to improve site security and user experience.
- Infrastructure (Cloud Hosting): Your data is stored on secure servers located in the United Kingdom.
- Professional Advisers: We may disclose data to regulators, legal advisers, or law enforcement where we have a legal obligation to do so.
8. International Data Transfers
Personal data may be processed outside the UK or European Economic Area.
Where international transfers occur, we ensure appropriate safeguards are in place, including standard contractual clauses or equivalent mechanisms.
9. Data Retention
We retain personal data only for as long as necessary to:
- Provide and operate the Service;
- Meet contractual, legal, accounting, or regulatory obligations;
- Resolve disputes and enforce agreements.
User Content may be deleted or anonymised upon account termination or request, subject to legal, regulatory, and technical constraints, including backup retention cycles.
We do not retain User Content longer than is reasonably necessary for the purposes for which it was submitted.
10. Data Security
We implement appropriate technical and organisational measures to protect personal data against unauthorised access, loss, misuse, or alteration.
However, no system is completely secure, and we cannot guarantee absolute security.
11. Your Rights
In accordance with applicable data protection laws (including the UK GDPR), you may have rights to request access, rectification, or erasure, or to object to certain processing. These rights are subject to legal exemptions and our own statutory retention obligations. To exercise these rights, contact contact@estimo.ai. You also have the right to lodge a complaint with a supervisory authority (such as the ICO in the UK).
12. Cookies and Tracking
We use cookies and similar technologies to operate and secure the Service, understand usage patterns, and improve performance.
Cookies may be categorised as:
- Strictly necessary cookies, required for core functionality and security;
- Analytics cookies, used to understand how users interact with the Service.
Where required by applicable law, we will obtain your consent before placing non-essential cookies on your device. You may manage your cookie preferences through your browser settings or any cookie management tools made available on the Service.
Further information may be provided in a separate Cookie Policy where applicable.
13. Children
The Service is not intended for children under 18, and we do not knowingly collect personal data from children.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. Continued use of the Service after changes take effect constitutes acceptance.
15. Contact Us
For privacy-related enquiries or to exercise your rights, contact contact@estimo.ai.