Skip to main content

Quantum Intelligence Hub

Data Protection Policy

Version 4 — Last updated: 23 August 2026

This Data Protection Policy describes the governance principles followed by Quantum Intelligence Hub Ltd (“QIH”, “we”, “us” or “our”) when processing personal data within the QIH ecosystem and when providing digital infrastructure, AI Digital Reception, automation, website, hosting, education, ecommerce, consultancy and related services.

Company: Quantum Intelligence Hub Ltd
Company number: 17246860
Registered office: 71–75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom

This policy states QIH’s data protection governance standards. Our Privacy Policy explains how personal data is used in specific public-facing contexts. Where QIH processes customer data on behalf of a business customer, the applicable service agreement and Data Processing Addendum govern that processing.

1. Scope and Applicable Framework

This policy applies to personal data processed through QIHHUB.COM and related QIH-operated platforms, internal business systems and contracted services. Depending on the processing activity and the location of the individuals concerned, QIH applies relevant requirements under:

  • the UK GDPR and Data Protection Act 2018;
  • the Privacy and Electronic Communications Regulations 2003, as amended;
  • the EU GDPR and applicable EEA national laws where they apply; and
  • other mandatory local data protection and electronic communications laws applicable to a particular service.

2. Roles and Responsibilities

QIH as controller

QIH acts as a controller when it determines why and how personal data is processed, including for website administration, enquiries, customer relationships, billing, security, service improvement and QIH’s own legal obligations.

QIH as processor

QIH generally acts as a processor when a business customer determines the purposes of processing and uses QIH services to handle its own callers’, contacts’, employees’ or end users’ data. In that role, QIH processes data only on documented instructions, subject to the applicable agreement and law.

Customer responsibilities

Each customer remains responsible for determining its lawful basis, providing required notices, managing consent where needed, configuring retention and access appropriately, and ensuring that its instructions to QIH are lawful.

3. Data Protection Principles

QIH’s processing is designed to follow the principles of:

  • lawfulness, fairness and transparency;
  • purpose limitation;
  • data minimisation;
  • accuracy;
  • storage limitation;
  • integrity and confidentiality; and
  • accountability.

Access, use and retention are limited according to business need, contractual responsibilities, risk and applicable law.

4. Categories of Personal Data

Depending on the platform and service, QIH may process:

  • identity, business and contact details;
  • account, authentication and access records;
  • billing, transaction references and service records;
  • website, device, browser, cookie and analytics data;
  • support messages, enquiries and correspondence;
  • telephone numbers, call metadata, recordings and transcripts where enabled;
  • chat, messaging, appointment and customer-service content;
  • AI prompts, responses, summaries and interaction metadata;
  • security events, audit trails, IP addresses and infrastructure logs;
  • education, ecommerce or automation records relevant to the selected service; and
  • other information deliberately submitted through an authorised QIH feature.

QIH does not seek special-category or highly sensitive data through ordinary public interfaces unless a specific service requires it and appropriate safeguards and lawful conditions have been established.

5. Purposes and Lawful Bases

Where QIH acts as controller, processing may be based on:

  • contract: to provide requested services and administer accounts;
  • legitimate interests: to operate, secure, improve and support services, prevent abuse and manage business relationships, after considering individual rights;
  • legal obligation: for accounting, tax, regulatory, fraud prevention and lawful disclosure duties;
  • consent: where consent is required, including for certain marketing, cookies or recording activities; and
  • other lawful grounds: where specifically permitted by applicable law.

Where QIH acts as processor, the customer controller determines the lawful basis and purpose.

6. AI Digital Reception and Communications Data

AI Digital Reception and related services may process inbound calls, caller identifiers, recordings, transcripts, messages, appointment requests, customer-service instructions and AI-generated summaries. The customer must configure and use these functions lawfully and provide callers or contacts with required information.

Where recording or transcription is enabled, the applicable notice, consent or other lawful basis must be established before or at the start of processing. QIH does not permit customers to use the platform for unlawful covert monitoring, indiscriminate surveillance, unauthorised profiling or prohibited automated marketing.

7. Automated Processing and Human Oversight

QIH may use AI to classify enquiries, answer routine questions, translate content, route communications, summarise interactions and support appointments or operational workflows. AI outputs may contain errors and should be reviewed where they could materially affect an individual.

QIH services must not be configured to make solely automated decisions producing legal or similarly significant effects unless the processing is lawful, necessary safeguards are implemented and affected individuals receive the information and rights required by applicable law.

8. Privacy by Design and Risk Assessment

QIH considers data protection during the design, procurement, configuration and material change of systems. Measures may include data minimisation, role-based access, separation of customer environments, limited logging, secure defaults and documented review.

A Data Protection Impact Assessment is considered where processing is likely to create a high risk to individuals, including certain large-scale monitoring, sensitive-data, profiling or novel AI activities.

9. Security Measures

Taking account of the nature, scope, context and risk of processing, QIH implements proportionate technical and organisational measures that may include:

  • access controls, authentication and least-privilege administration;
  • encryption in transit and other encryption where appropriate;
  • tenant or operational separation;
  • system, security and audit logging;
  • monitoring, malware protection and abuse prevention;
  • backup, restoration and continuity controls;
  • security patching and vulnerability management;
  • confidentiality requirements for authorised personnel; and
  • incident response and provider coordination procedures.

No system can guarantee absolute security. QIH nevertheless remains responsible for security duties allocated to it by applicable law and contract.

10. Personnel and Access Management

Access to personal data is restricted to authorised personnel and contractors who require it for an approved purpose. QIH applies appropriate confidentiality, access-review and security-awareness requirements. Access should be removed or adjusted when duties change or engagement ends.

11. Service Providers and Subprocessors

QIH may use carefully selected providers for hosting, cloud infrastructure, AI processing, communications, telephony, messaging, payments, analytics, security, support and automation. Providers receive only the access reasonably required for their function and are subject to appropriate contractual and security requirements.

When QIH acts as processor, subprocessors are appointed in accordance with the applicable Data Processing Addendum and required customer authorisation or notification process. QIH remains responsible for its own legal and contractual duties; a provider remains responsible for breaches attributable to that provider under applicable law and contract.

12. International Data Transfers

Personal data may be processed outside the country in which it was collected where QIH, a customer or an authorised provider operates internationally. Where transfer restrictions apply, QIH uses an applicable lawful transfer mechanism, which may include:

  • an adequacy regulation or adequacy decision;
  • the UK International Data Transfer Agreement or UK Addendum;
  • EU Standard Contractual Clauses;
  • another legally recognised safeguard; or
  • a permitted statutory derogation in limited circumstances.

Transfer-risk and supplementary-security measures are considered where required. International routing is not treated as automatically lawful merely because a service provider operates globally.

13. Data Retention and Secure Disposal

Personal data is retained only for as long as reasonably necessary for its stated purpose, contractual commitments, security, dispute management, accounting or legal obligations. Retention periods depend on the type of record and QIH’s role as controller or processor.

At the end of a processor service, customer personal data is returned or deleted in accordance with the customer’s documented choice, the applicable agreement, backup cycles and any legal retention requirement. Records are securely deleted, anonymised or rendered inaccessible when retention is no longer justified.

14. Data Quality and Individual Rights

Subject to applicable law, individuals may have rights to:

  • receive information about processing;
  • access their personal data;
  • correct inaccurate or incomplete data;
  • request erasure or restriction;
  • object to certain processing;
  • receive portable data where applicable;
  • withdraw consent without affecting earlier lawful processing; and
  • request safeguards relating to qualifying automated decisions.

Requests may require identity verification. Where QIH acts only as processor, the request may be referred to or handled in cooperation with the relevant customer controller.

15. Personal Data Breach Management

QIH maintains procedures to identify, contain, investigate, document and remediate suspected personal data breaches.

  • When QIH acts as processor, it notifies the relevant controller without undue delay after becoming aware of a personal data breach and provides reasonable assistance.
  • When QIH acts as controller, it assesses risk and notifies the ICO or another competent authority without undue delay and, where required, within 72 hours of awareness.
  • Where a breach is likely to result in a high risk to individuals, affected individuals are informed without undue delay unless a lawful exception applies.
  • Breaches and the reasoning behind notification decisions are documented.

16. Records, Accountability and Audits

QIH maintains proportionate records of processing, provider arrangements, security measures, incidents, retention decisions and relevant assessments. Compliance is reviewed when services, laws, risk or processing operations materially change.

When QIH acts as processor, audit and information rights are governed by the Data Processing Addendum and exercised in a manner that protects other customers, confidential information and system security.

17. Complaints and Regulatory Rights

Individuals should first contact QIH using the details below so that concerns can be investigated. Individuals also have the right to complain to the UK Information Commissioner’s Office or, where applicable, another competent EEA or local supervisory authority.

Information Commissioner’s Office: ico.org.uk/make-a-complaint/

18. Responsibility and Non-Excludable Duties

QIH does not exclude responsibility for data protection obligations that cannot lawfully be excluded. Responsibility for an incident or infringement is allocated according to each party’s role, instructions, acts, omissions, security duties, contractual commitments and applicable law.

A customer is responsible for unlawful instructions, missing notices or consent, excessive collection and unauthorised use under its control. QIH is responsible for processing outside lawful documented instructions or failures attributable to QIH. Providers remain responsible for failures attributable to them, without removing any non-delegable duty imposed on QIH or the customer.

20. Contact

For data protection enquiries or rights requests:

QUANTUM INTELLIGENCE HUB LTD
71–75 Shelton Street,
Covent Garden,
London, WC2H 9JQ
United Kingdom

Privacy: privacy@qihhub.com
Security: security@qihhub.com
Support: support@qihhub.com