Privacy Policy
1. Who we are
Tollivar Ltd ("Tollivar", "we", "us", "our") is a UK-registered strategic consultancy specialising in AI governance and strategy. We advise organisations on the governance, risk management and responsible use of AI and data-driven technologies.
For the purposes of UK GDPR and EU GDPR, Tollivar is a controller of the personal data it processes for its own business operations, marketing and client relationship management.
2. What personal data we collect
The types of personal data we may collect include:
Contact details: name, job title, employer, email address, telephone number, postal address.
Professional information: role, areas of responsibility, sector, interests in AI governance.
Engagement information: correspondence, notes of meetings, proposals, statements of work and feedback.
Website and communications data: IP address, device and browser type, pages visited, interaction with our emails (such as opens and clicks).
Event and training data: registrations, attendance, dietary or access requirements where provided.
Recruitment data (if you apply to work with us): CV, cover letter, professional history and references.
We do not routinely collect or store special categories of personal data (such as health or political opinions) in our own systems, but we may be exposed to descriptions or screenshots of how our clients manage such data in their AI systems. Where this occurs, we will seek to minimise the personal data we receive, and we will treat any incidental personal data with enhanced care.
3. How we collect personal data
We collect personal data in the following ways:
Directly from you, when you contact us, request information, attend our events, subscribe to updates, or engage us to provide services.
From your organisation, when we interact with you as a contact or stakeholder.
Automatically, when you use our website (through cookies and similar technologies, subject to your settings).
From publicly available sources (such as professional profiles, public registers and publications) and from introductions or referrals.
4. How we use personal data and lawful bases
We use personal data for the purposes and on the legal bases set out below, under UK GDPR and EU GDPR.
Providing and managing our services: to communicate with clients, understand requirements, deliver strategic advice, and administer our engagements. Our legal basis is performance of a contract or legitimate interests in running our business.
Business development and marketing: to send relevant insights, invitations and information about our services to professional contacts. Our legal basis is legitimate interests, or consent where required (for example, some electronic marketing).
Operating and improving our website and services: to monitor usage, maintain security and improve our content. Our legal basis is legitimate interests in securing and developing our services.
Legal, regulatory and governance purposes: to comply with legal obligations, maintain appropriate records and manage risk (including insurance). Our legal basis is legal obligation or legitimate interests.
Recruitment: to assess applications and manage our recruitment processes. Our legal basis is legitimate interests in recruiting and consent where appropriate.
Where we rely on legitimate interests, we balance our interests against your rights and freedoms and only proceed where our interests are not overridden.
5. Use of AI and cloud tools
We use reputable third-party AI and cloud providers (such as OpenAI, Anthropic Claude and Google Cloud) to support internal work, including research, drafting and productivity tools. We do not intentionally input large client datasets or highly sensitive personal data into these tools. Where we need to reference client scenarios, we aim to anonymise or minimise personal information and use configuration settings designed to protect confidentiality.
We have contractual and technical safeguards in place with such providers where possible, including standard data protection terms and appropriate international transfer mechanisms.
6. International data transfers
Some of our service providers and tools may process personal data outside the UK and the European Economic Area. Where this occurs, we will ensure that an adequate level of protection is in place, for example by:
Relying on an adequacy regulation; or
Entering into appropriate data transfer agreements (such as the UK International Data Transfer Agreement or EU Standard Contractual Clauses), together with supplementary measures where needed.
7. Sharing personal data
We may share personal data with:
Our professional advisers (for example, legal, accounting or insurance advisers) where necessary.
Our IT and cloud service providers, who are subject to contractual confidentiality and security obligations.
Third parties where required by law, regulation or a court order.
Event partners where we co-host events, with appropriate information provided at the time of registration.
We do not sell personal data.
8. Data retention
We retain personal data only for as long as necessary for the purposes for which it was collected, and in line with our internal retention policies and legal obligations. Factors we consider include the nature of the relationship, any legal or contractual requirements, and the likelihood of further engagement.
9. Your rights
Depending on your location and applicable law, you may have the right to:
Access your personal data and obtain a copy.
Correct inaccurate or incomplete data.
Erase your data in certain circumstances.
Restrict or object to our processing.
Port your data to another controller in a structured, commonly used format.
Withdraw consent where we rely on consent (for example, for certain marketing).
Lodge a complaint with a supervisory authority.
If you wish to exercise these rights, please contact us at [insert email]. We may need to verify your identity before responding.
If you are in the UK, you also have the right to complain to the Information Commissioner's Office (ICO) at www.ico.org.uk.
10. Cookies and similar technologies
We use cookies and similar technologies to operate and improve our website, understand usage and, where relevant, tailor content. You can control cookies through your browser settings and, where implemented, our cookie banner and preference tools.
11. Security
We take reasonable technical and organisational measures to protect personal data, including access controls, encryption in transit where appropriate, and regular review of our security practices. No system is completely secure, but we aim to reduce risks to a level appropriate to the nature of the information.
12. Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in law, guidance or our practices. When we do, we will change the "Last updated" date above. If changes are material, we may provide a more prominent notice.
Version: v1.0 | Last updated: 5 February 2026