Privacy Policy

Last updated: 5 August 2026

This policy explains how Ghera Tech ("we", "us") collects and uses personal data, in line with the EU General Data Protection Regulation (GDPR) and the UK GDPR.

1. Who we are

Ghera Tech is the data controller for the personal data described in this policy. You can reach us at office@gheratech.eu for any privacy-related question or request.

2. What we collect

This website does not use cookies, analytics, or third-party tracking.

3. Why we use it and our legal basis

4. AI and your data

We do not use client data to train our own or third-party AI models without your explicit, separate consent. Where a project requires processing data through an AI system, we agree the scope with you in writing beforehand, document it, and apply appropriate safeguards including access controls, minimisation, and human oversight.

5. Who we share it with

We share personal data only with service providers who help us operate (for example email and cloud hosting), and only under contracts that require them to protect it. We do not sell personal data. Where data is transferred outside the EEA or UK, we rely on adequacy decisions or Standard Contractual Clauses.

6. How long we keep it

Enquiry emails are kept for up to 24 months. Client project data is kept for the duration of the engagement plus any period required by law or contract, then deleted or returned to you.

7. Your rights

Under the GDPR you have the right to access your data, correct it, have it erased, restrict or object to its processing, and receive it in a portable format. You may also withdraw consent at any time where consent is the legal basis. To exercise any of these rights, email office@gheratech.eu. We will respond within one month.

If you believe we have handled your data improperly, you have the right to complain to your national data protection authority.

8. Security

We apply technical and organisational measures appropriate to the risk, including encryption in transit, access control on a need-to-know basis, and prompt notification of any breach affecting your rights.

9. EU AI Act

Where we build or deploy AI systems, we work to the requirements of the EU AI Act. In practice this means:

For any specific system we deliver, the applicable obligations and who bears them are set out in the project agreement.

10. Changes to this policy

We may update this policy from time to time. The date at the top reflects the most recent version.

Note: This policy is a starting template. Before publishing, have it reviewed by a legal professional and fill in your registered company name, address, and — if applicable — your Data Protection Officer or EU representative.