Privacy Notice
Last updated: May 2026
This Privacy Notice explains how ELSA AI Ltd collects, uses and protects personal data when you visit this website, contact us, make an enquiry, book a discovery call or engage with our advisory services.
ELSA AI Ltd provides advisory AI governance support for private healthcare providers, helping clinics discover, evidence and govern AI tools already being used or planned, including ambient scribes, ChatGPT, Microsoft Copilot, transcription tools, admin automation, patient communication tools and shadow AI.
This Privacy Notice applies to website visitors, prospective clients, client contacts, professional contacts and people who communicate with ELSA AI.
Final wording should be reviewed by ELSA AI’s legal/DPO adviser before reliance.
Who we are
ELSA AI Ltd is the controller responsible for the personal data described in this Privacy Notice.
Company:
ELSA AI Ltd
Registered office:
124 City Road
London
England
EC1V 2NX
United Kingdom
Contact:
contact@elsaai.co.ukPersonal data we collect
We may collect and use the following types of personal data:
- Contact and enquiry data. This may include your name, work email address, organisation name, role, clinic type, enquiry details and any message you submit through the website or by email.
- Discovery call and meeting data. This may include meeting notes, business contact details, role, organisation context, service requirements and follow-up actions.
- Client engagement data. Where you engage ELSA AI, we may process business contact details, governance information, meeting notes, service documents, project correspondence and evidence provided for advisory review.
- Billing and administration data. This may include billing contacts, invoice details, payment records, contract details and related business administration records.
- Website and technical data. This may include IP address, browser type, device information, security logs, cookie preference records and basic website functionality data.
- Marketing preference data. If you choose to receive updates from ELSA AI, we may process your name, email address and communication preferences.
Patient and clinical information
ELSA AI does not ask users to submit patient-identifiable information, clinical records, consultation details or special category health data through website forms or general email.
Please do not include patient-identifiable information, clinical records, consultation details or special category health data in website forms or general email enquiries.
If client documents are required during an engagement, secure transfer arrangements, scope controls and appropriate contractual terms will be agreed before those materials are shared.
How we use personal data
| Purpose | Personal data used | Lawful basis |
|---|---|---|
| Responding to enquiries | Name, work email, organisation, role, clinic type, enquiry details and message content. | Legitimate interests and/or steps before entering into a contract. |
| Booking and managing discovery calls | Contact details, meeting details, organisation context and service requirements. | Legitimate interests and/or steps before entering into a contract. |
| Providing advisory services | Client contact details, meeting notes, engagement documents, governance information, project correspondence and agreed evidence materials. | Performance of contract and legitimate interests. |
| Managing client relationships | Business contact details, correspondence, meeting notes, service history and action records. | Performance of contract and legitimate interests. |
| Billing, accounting and business administration | Billing contact details, invoice records, payment records, contract details and accounting records. | Legal obligation, performance of contract and legitimate interests. |
| Operating and securing the website | IP address, device/browser data, security logs, cookie preference records and form-related technical data. | Legitimate interests. |
| Sending optional updates | Name, email address and communication preferences. | Consent where required, or legitimate interests where permitted for business-to-business communications. You can unsubscribe at any time. |
| Complying with legal obligations | Records required for accounting, tax, legal, regulatory or dispute-management purposes. | Legal obligation and legitimate interests. |
Our legitimate interests
Where we rely on legitimate interests, those interests may include:
- responding to business enquiries;
- managing prospective client and client relationships;
- delivering and improving advisory services;
- operating and securing the website;
- keeping appropriate business records;
- protecting ELSA AI’s legal and commercial interests;
- communicating with professional contacts about relevant healthcare AI governance matters.
We consider whether our interests are overridden by your rights and freedoms before relying on legitimate interests.
Cookies and similar technologies
We currently use only necessary cookies and similar technologies required to operate the website, remember cookie preferences, support basic security and process website enquiries.
We do not currently use analytics cookies, marketing cookies, advertising pixels or behavioural retargeting cookies.
If this changes, we will update our Cookie Notice and ask for consent where required.
Who we share personal data with
We may share personal data with trusted service providers where necessary to operate the website, manage communications, provide services, administer the business or meet legal obligations.
This may include:
- website hosting and infrastructure providers;
- email and communication providers;
- secure document transfer or storage providers;
- professional advisers such as accountants, legal advisers or insurance advisers;
- payment, invoicing or accounting providers;
- regulators, courts or public authorities where required by law.
We do not sell personal data.
We do not share website visitor data with advertisers.
International transfers
Some service providers may process personal data outside the United Kingdom. Where this happens, ELSA AI will take steps designed to ensure appropriate safeguards are in place, such as adequacy regulations, approved contractual safeguards or other lawful transfer mechanisms.
Where client documents may involve sensitive governance or healthcare-related information, transfer arrangements should be reviewed as part of the engagement setup.
How long we keep personal data
| Data type | Typical retention |
|---|---|
| Website enquiries | Usually up to 24 months after the last interaction, unless a longer period is needed for business, legal or dispute-management reasons. |
| Discovery call and proposal records | Usually up to 24 months after the last interaction if no engagement proceeds. |
| Client engagement records | Usually up to 7 years after the end of the client relationship, unless a different period is agreed or required. |
| Billing, tax and accounting records | Usually 6 years plus the current financial year, or as required by applicable law. |
| Marketing preference records | Until you unsubscribe or ask us to stop, with suppression records retained as needed to respect your preference. |
| Website security logs and technical records | Usually short-term unless needed for security, investigation or legal reasons. |
Retention periods may vary depending on the nature of the record, contractual requirements, legal obligations or the need to establish, exercise or defend legal claims.
Your rights
Under UK data protection law, you may have the right to:
- ask for access to your personal data;
- ask for inaccurate data to be corrected;
- ask for data to be erased in certain circumstances;
- ask us to restrict processing in certain circumstances;
- object to processing in certain circumstances;
- ask for data portability in certain circumstances;
- withdraw consent where processing is based on consent.
To exercise your rights, contact: contact@elsaai.co.uk
We may need to verify your identity before responding.
Marketing communications
ELSA AI may send occasional updates about healthcare AI governance, ambient scribes, shadow AI, evidence readiness and ELSA AI services where permitted.
You can unsubscribe at any time using the unsubscribe link in the email or by contacting: contact@elsaai.co.uk
We do not sell marketing lists or use purchased mailing lists for unsolicited bulk email.
Security
ELSA AI uses reasonable organisational and technical measures designed to protect personal data from unauthorised access, loss, misuse or disclosure.
No website, email system or online service can be guaranteed to be completely secure. Please do not send patient-identifiable information, clinical records or special category health data through website forms or general email unless a secure route has been agreed.
Third-party links
This website may contain links to third-party websites or services. ELSA AI is not responsible for the privacy practices, content or security of third-party websites. You should read the privacy notices of any third-party services you use.
Complaints
If you have concerns about how ELSA AI handles your personal data, please contact us first so we can try to resolve the issue.
You also have the right to complain to the UK Information Commissioner’s Office.
Changes to this Privacy Notice
We may update this Privacy Notice from time to time if our services, website, suppliers or legal obligations change.
The latest version will be published on this page.
Contact
For questions about this Privacy Notice or how ELSA AI handles personal data, contact:
ELSA AI Ltd
Email: contact@elsaai.co.uk
Registered office:
124 City Road
London
England
EC1V 2NX
United Kingdom