This Data Protection Policy explains how Quantum Intelligence Hub LTD and the broader QIH ecosystem may process, protect, store, manage, transfer, and secure operational data, infrastructure-related information, educational records, ecommerce data, communication records, and digital interaction data across interconnected global digital environments.
Version 4 — Last updated: 23 August 2026
This Data Protection Policy describes the governance principles followed by Quantum Intelligence Hub Ltd (“QIH”, “we”, “us” or “our”) when processing personal data within the QIH ecosystem and when providing digital infrastructure, AI Digital Reception, automation, website, hosting, education, ecommerce, consultancy and related services.
Company: Quantum Intelligence Hub Ltd
Company number: 17246860
Registered office: 71–75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom
This policy states QIH’s data protection governance standards. Our Privacy Policy explains how personal data is used in specific public-facing contexts. Where QIH processes customer data on behalf of a business customer, the applicable service agreement and Data Processing Addendum govern that processing.
This policy applies to personal data processed through QIHHUB.COM and related QIH-operated platforms, internal business systems and contracted services. Depending on the processing activity and the location of the individuals concerned, QIH applies relevant requirements under:
QIH acts as a controller when it determines why and how personal data is processed, including for website administration, enquiries, customer relationships, billing, security, service improvement and QIH’s own legal obligations.
QIH generally acts as a processor when a business customer determines the purposes of processing and uses QIH services to handle its own callers’, contacts’, employees’ or end users’ data. In that role, QIH processes data only on documented instructions, subject to the applicable agreement and law.
Each customer remains responsible for determining its lawful basis, providing required notices, managing consent where needed, configuring retention and access appropriately, and ensuring that its instructions to QIH are lawful.
QIH’s processing is designed to follow the principles of:
Access, use and retention are limited according to business need, contractual responsibilities, risk and applicable law.
Depending on the platform and service, QIH may process:
QIH does not seek special-category or highly sensitive data through ordinary public interfaces unless a specific service requires it and appropriate safeguards and lawful conditions have been established.
Where QIH acts as controller, processing may be based on:
Where QIH acts as processor, the customer controller determines the lawful basis and purpose.
AI Digital Reception and related services may process inbound calls, caller identifiers, recordings, transcripts, messages, appointment requests, customer-service instructions and AI-generated summaries. The customer must configure and use these functions lawfully and provide callers or contacts with required information.
Where recording or transcription is enabled, the applicable notice, consent or other lawful basis must be established before or at the start of processing. QIH does not permit customers to use the platform for unlawful covert monitoring, indiscriminate surveillance, unauthorised profiling or prohibited automated marketing.
QIH may use AI to classify enquiries, answer routine questions, translate content, route communications, summarise interactions and support appointments or operational workflows. AI outputs may contain errors and should be reviewed where they could materially affect an individual.
QIH services must not be configured to make solely automated decisions producing legal or similarly significant effects unless the processing is lawful, necessary safeguards are implemented and affected individuals receive the information and rights required by applicable law.
QIH considers data protection during the design, procurement, configuration and material change of systems. Measures may include data minimisation, role-based access, separation of customer environments, limited logging, secure defaults and documented review.
A Data Protection Impact Assessment is considered where processing is likely to create a high risk to individuals, including certain large-scale monitoring, sensitive-data, profiling or novel AI activities.
Taking account of the nature, scope, context and risk of processing, QIH implements proportionate technical and organisational measures that may include:
No system can guarantee absolute security. QIH nevertheless remains responsible for security duties allocated to it by applicable law and contract.
Access to personal data is restricted to authorised personnel and contractors who require it for an approved purpose. QIH applies appropriate confidentiality, access-review and security-awareness requirements. Access should be removed or adjusted when duties change or engagement ends.
QIH may use carefully selected providers for hosting, cloud infrastructure, AI processing, communications, telephony, messaging, payments, analytics, security, support and automation. Providers receive only the access reasonably required for their function and are subject to appropriate contractual and security requirements.
When QIH acts as processor, subprocessors are appointed in accordance with the applicable Data Processing Addendum and required customer authorisation or notification process. QIH remains responsible for its own legal and contractual duties; a provider remains responsible for breaches attributable to that provider under applicable law and contract.
Personal data may be processed outside the country in which it was collected where QIH, a customer or an authorised provider operates internationally. Where transfer restrictions apply, QIH uses an applicable lawful transfer mechanism, which may include:
Transfer-risk and supplementary-security measures are considered where required. International routing is not treated as automatically lawful merely because a service provider operates globally.
Personal data is retained only for as long as reasonably necessary for its stated purpose, contractual commitments, security, dispute management, accounting or legal obligations. Retention periods depend on the type of record and QIH’s role as controller or processor.
At the end of a processor service, customer personal data is returned or deleted in accordance with the customer’s documented choice, the applicable agreement, backup cycles and any legal retention requirement. Records are securely deleted, anonymised or rendered inaccessible when retention is no longer justified.
Subject to applicable law, individuals may have rights to:
Requests may require identity verification. Where QIH acts only as processor, the request may be referred to or handled in cooperation with the relevant customer controller.
QIH maintains procedures to identify, contain, investigate, document and remediate suspected personal data breaches.
QIH maintains proportionate records of processing, provider arrangements, security measures, incidents, retention decisions and relevant assessments. Compliance is reviewed when services, laws, risk or processing operations materially change.
When QIH acts as processor, audit and information rights are governed by the Data Processing Addendum and exercised in a manner that protects other customers, confidential information and system security.
Individuals should first contact QIH using the details below so that concerns can be investigated. Individuals also have the right to complain to the UK Information Commissioner’s Office or, where applicable, another competent EEA or local supervisory authority.
Information Commissioner’s Office: ico.org.uk/make-a-complaint/
QIH does not exclude responsibility for data protection obligations that cannot lawfully be excluded. Responsibility for an incident or infringement is allocated according to each party’s role, instructions, acts, omissions, security duties, contractual commitments and applicable law.
A customer is responsible for unlawful instructions, missing notices or consent, excessive collection and unauthorised use under its control. QIH is responsible for processing outside lawful documented instructions or failures attributable to QIH. Providers remain responsible for failures attributable to them, without removing any non-delegable duty imposed on QIH or the customer.
For data protection enquiries or rights requests:
QUANTUM INTELLIGENCE HUB LTD
71–75 Shelton Street,
Covent Garden,
London, WC2H 9JQ
United Kingdom
Privacy: privacy@qihhub.com
Security: security@qihhub.com
Support: support@qihhub.com

Quantum Intelligence Hub uses cookies and similar technologies to improve website security, performance, analytics and user experience. You may accept all cookies, reject non-essential cookies, or manage your preferences at any time.