Privacy Policy
Last updated: 5 August 2026
This policy explains how Ghera Tech ("we", "us") collects and uses personal data, in line with the EU General Data Protection Regulation (GDPR) and the UK GDPR.
1. Who we are
Ghera Tech is the data controller for the personal data described in this policy. You can reach us at office@gheratech.eu for any privacy-related question or request.
2. What we collect
- Contact details — your name, email address, and any message you send us through the contact form or by email.
- Client project data — information you share with us during an engagement, which may include business documents, datasets, or system access.
This website does not use cookies, analytics, or third-party tracking.
3. Why we use it and our legal basis
- Responding to enquiries — legal basis: legitimate interest in replying to people who contact us.
- Delivering our services — legal basis: performance of a contract.
- Meeting legal and accounting obligations — legal basis: legal obligation.
4. AI and your data
We do not use client data to train our own or third-party AI models without your explicit, separate consent. Where a project requires processing data through an AI system, we agree the scope with you in writing beforehand, document it, and apply appropriate safeguards including access controls, minimisation, and human oversight.
5. Who we share it with
We share personal data only with service providers who help us operate (for example email and cloud hosting), and only under contracts that require them to protect it. We do not sell personal data. Where data is transferred outside the EEA or UK, we rely on adequacy decisions or Standard Contractual Clauses.
6. How long we keep it
Enquiry emails are kept for up to 24 months. Client project data is kept for the duration of the engagement plus any period required by law or contract, then deleted or returned to you.
7. Your rights
Under the GDPR you have the right to access your data, correct it, have it erased, restrict or object to its processing, and receive it in a portable format. You may also withdraw consent at any time where consent is the legal basis. To exercise any of these rights, email office@gheratech.eu. We will respond within one month.
If you believe we have handled your data improperly, you have the right to complain to your national data protection authority.
8. Security
We apply technical and organisational measures appropriate to the risk, including encryption in transit, access control on a need-to-know basis, and prompt notification of any breach affecting your rights.
9. EU AI Act
Where we build or deploy AI systems, we work to the requirements of the EU AI Act. In practice this means:
- Assessing each system's risk classification before development begins.
- Designing for meaningful human oversight rather than fully automated decisions about people.
- Telling users clearly when they are interacting with an AI system or viewing AI-generated content.
- Maintaining technical documentation, data governance records, and logs so our systems can be audited.
- Declining to build systems that fall within the Act's prohibited practices.
For any specific system we deliver, the applicable obligations and who bears them are set out in the project agreement.
10. Changes to this policy
We may update this policy from time to time. The date at the top reflects the most recent version.