Skip to main content
Skip to main content
Koallabs SAFE-AI · v1.0
Services Framework Insights About Contact Take the Scorecard

Privacy Policy

DRAFT — pending solicitor review. Last updated 2 June 2026.

Last updated: 2 June 2026

Last reviewed: 2 June 2026. This notice explains how Koallabs handles personal data collected through this website, including the AI Readiness Scorecard and our contact form.

On this page

  • Who we are
  • What data we collect
  • Why we collect it
  • How we use AI in the scorecard
  • Where your data is stored
  • How long we keep it
  • Your rights
  • Cookies and tracking
  • Third parties we share with
  • How to contact us or complain

Who we are

This website is operated by Koallabs Ltd (incorporation in process). Koallabs is the data controller for the personal data described in this notice. You can reach us at enquiries@koallabs.ai. We are a UK-first business and we process personal data in line with UK data protection law.

What data we collect

We collect only the information you choose to give us:

  • AI Readiness Scorecard: your name, email address, organisation name, and the answers you provide to the scorecard questions.
  • Contact form: your name, email address, organisation name, and the content of your enquiry.

We do not collect special-category data, and we do not ask for more than we need to respond to you or to produce your scorecard result.

Why we collect it

We rely on two lawful bases under UK GDPR:

  • Consent — when you submit the scorecard or opt in to our newsletter. You can withdraw consent at any time (see Your rights).
  • Legitimate interest — when we follow up on a business-to-business enquiry you have sent us. Our legitimate interest is responding to and developing professional enquiries from organisations interested in our services. We have weighed this against your interests and rights, and you can object to this processing at any time.

How we use AI in the scorecard

The AI Readiness Scorecard uses automated processing to produce your result, so we want to be clear about how it works under Articles 22A–22D of the Data (Use and Access) Act 2025.

  • The nature of the processing: your answers are scored by a five-pillar weighted algorithm, and an AI model then drafts written recommendations based on that score.
  • The logic involved: each answer contributes a weighting to one of five readiness pillars; the pillar scores are combined into an overall tier, and the recommendations are generated from that tier and your individual answers.
  • The significance and consequences: the result is a readiness tier and a set of suggestions. It is guidance only. It does not make any legally binding or similarly significant decision about you, and it does not determine access to any service.
  • Your safeguards: you have the right to contest a scorecard result, to ask for human review by the founder, and to express your point of view. Email enquiries@koallabs.ai to request this.

Where your data is stored

Your data is stored and processed by a small number of service providers:

  • Hostinger — website hosting, on servers located in a United Kingdom datacenter.
  • Postmark — sending the transactional emails that deliver your scorecard result and our replies.
  • Google LLC (reCAPTCHA v3) — anti-spam protection on our forms. Where reCAPTCHA is used, a token may be transferred to Google in the United States; that transfer is covered by Google's Standard Contractual Clauses.

How long we keep it

We keep scorecard responses, contact-form submissions, and enquiry records for 24 months from the date of collection, after which we review them and delete data we no longer need. If you ask us to delete your data sooner, we will do so unless we are required to keep it for a legal reason.

Your rights under UK GDPR

You have the right to:

  • access the personal data we hold about you;
  • ask us to correct inaccurate data;
  • ask us to erase your data;
  • ask us to restrict how we use your data;
  • receive your data in a portable format;
  • object to processing based on legitimate interest;
  • rights in relation to automated decisions, including the scorecard (see How we use AI in the scorecard); and
  • withdraw consent at any time, without affecting processing carried out before you withdrew it.

To exercise any of these rights, email enquiries@koallabs.ai. We will respond within one month.

Cookies and tracking

We use a small set of cookies:

  • Essential cookies — a Drupal session cookie and a CSRF security token that keep the site working, plus the Klaro cookie that records your consent choices. These are set without consent because the site cannot function without them.
  • Consent-gated cookies — Google reCAPTCHA v3 for anti-spam. This is loaded only after you agree to it.

You can change your choices at any time using the Manage cookie preferences link in the footer of every page.

Third parties we share with

We share personal data only with the providers listed in Where your data is stored: Hostinger, Postmark, and Google (reCAPTCHA v3). We do not sell your data, and we do not currently use newsletter, CRM, or advertising-tracking tools. If that changes, we will update this notice before any new processing begins.

How to contact us or complain

If you have a question about this notice or about how we handle your data, email enquiries@koallabs.ai.

If you are not satisfied with our response, you can complain to the Information Commissioner's Office at ico.org.uk or by calling 0303 123 1113. We would, however, appreciate the chance to address your concern first.

Questions about this policy? Email enquiries@koallabs.ai

Koallabs

Secure AI adoption for growing businesses. The SAFE-AI Framework — built for 5-to-500 person organisations.

Navigate
  • Framework
  • Services
  • Why it matters
  • FAQ
Start here
  • Take the Scorecard
  • Book a discovery call
  • Read the insights
Contact
  • enquiries@koallabs.ai
  • Send a message
  • Privacy Policy
  • Terms
© 2026 KOALLABS · MADE IN THE UK SAFE-AI · V1.0 Manage cookie preferences