WyseAi

Privacy notice

Wysehub Ltd. Version 1.2. Last reviewed 8 September 2026.

WyseAi is a service of Wysehub Ltd. This notice explains what happens to the work our clients send us, what we hold about the people who use and visit WyseAi, and the rights you have under the UK General Data Protection Regulation and the Data Protection Act 2018. It is written to be read, so it says what the system does rather than what a policy might say.

Who we are

Wysehub Ltd is registered with the Information Commissioner’s Office under number 15820659. Our registered address is 167-169 Great Portland Street, London, England, W1W 5PF. Our data protection contact is contact@wysehub.co.uk. AI Claims is another brand of Wysehub Ltd, covered by its own notice.

Two kinds of data, two roles

Most of the personal data WyseAi handles is inside the work our clients send us: a call recording, a document pack, a record from a claims feed. That data belongs to our client’s customers. For that work, our client is the controller and Wysehub Ltd is their processor, acting on their written instructions under a data processing agreement. If your data is in that work, the organisation you dealt with is the first place to ask, and we will help them answer.

For the people who use WyseAi on a client’s behalf, for visitors to this website, and for the business contacts we deal with, Wysehub Ltd is the controller, and this notice applies directly.

The work our clients send us

Work reaches us by API or email, from the systems our clients already run. Today that means:

  • Call recordings, which we transcribe and audit against a checklist agreed with the client.
  • Document packs, such as a quote and the screenshots behind it, which we check against the supporting evidence.
  • Records from an insurer or claims feed, including the parties to a claim, vehicle and address details, and where a claim involves injury, health information about the people involved.

Health information is special category data. We process it only because our client has a lawful basis to handle the claim it belongs to, only for that claim, and with the safeguards below. We do not use the work our clients send us to train models, ours or anyone else’s.

What comes back is the result: the answers, the evidence behind each one, the score, a report, and what the run cost. Every run is logged with the engine version, the prompt revision and the report template that produced it, so a result can be explained a year later.

How the work is protected

  • Personal details can be redacted before the AI sees them, where the workflow allows it. Redaction is agreed per workflow, not applied to everything. Where a task can be done without personal details, names, addresses, phone numbers and similar details are replaced with placeholders on the way out to a model; the key that maps a placeholder back to the original is held separately, expires after 90 days, and is then purged. Many reports need the personal details to do their job, for instance to match a caller to their policy or a document to its claim. In those workflows the details are processed under the safeguards on this page and kept only for the agreed retention.
  • Restoring a redacted detail is a recorded, justified action. It can only be done by a member of our team with the privacy role, for an approved incident or audit, and only with a written justification that is kept with the action.
  • Our engines and our AI work together. Our engine decides what needs answering and hands the model only the questions it needs, on the data agreed for that workflow. The model answers with the evidence behind each answer; the engine checks and scores every answer. Anything the model cannot support is flagged for review rather than passed off as a result.
  • Each client’s data is kept to that client. Every request is scoped to your organisation on the server before it returns anything. Your own administrator manages who on your team can see what, and changes to that access are recorded.
  • Access is logged. Sign-ins are recorded, sessions expire after an hour of inactivity and must be renewed within seven days, and the service applies rate limiting and security headers on every request.
  • Data in transit is encrypted between you and us, and between us and each processor we use.

Who processes data for us

The suppliers below run parts of the service. Which of them handle a given piece of work depends on the workflow: a call audit needs transcription, a document check does not, and the models and storage a workflow uses are agreed with each client before work begins and stated in that client’s data processing agreement. Each supplier is under a data processing agreement with us and receives only what its job needs. We do not sell personal data, and nobody receives it for their own marketing.

Processors, what they do for us, and where
WhoWhat they do for usWhere
DigitalOceanFile storage for recordings, document packs, results and reportsLondon (UK)
Amazon Web ServicesRuns the AI models (Anthropic Claude) that read and judge the work, in the workflows that use themLondon (UK)
DeepgramTranscribes call recordings, in workflows that include callsEU endpoint
AssemblyAITranscribes call recordings, in workflows that include callsEU endpoint
GoogleWeb search checks within quote checking, on the search terms onlyMay be outside the UK; see international transfers
SentryError monitoring for the serviceEU or US, under transfer safeguards
MicrosoftSends our email: sign-in codes, password resets, service notices, and the enquiries and receipts from the contact formUK or EU
XeroInvoicing our clientsUnder transfer safeguards

Professional advisers, regulators and law enforcement may receive data where the law requires it. A workflow set up for a client with a different arrangement is described in that client’s agreement rather than here.

International transfers

In our standard setup the work is stored and processed in the United Kingdom, with files and models in London and transcription on EU endpoints. Some suppliers may process limited data outside the UK: the web search checks in quote checking send search terms to Google, and our error monitoring may hold technical records with a provider outside the UK. Where a client’s workflow is set up differently, their agreement says where processing takes place. Where data leaves the UK we rely on an adequacy decision, the UK International Data Transfer Agreement or the UK Addendum to the Standard Contractual Clauses. Ask us for a copy of the safeguard that applies.

How long we keep data

  • The work our clients send us, and the results and reports we produce from it, are kept for the period agreed in that client’s contract and then deleted or anonymised. A client can ask us to delete their work sooner.
  • Where redaction is used, the key that maps a placeholder back to the original detail is kept for 90 days from when it was created, then purged.
  • The record of a run (which engine, prompt and template produced it, and what it cost) is kept for as long as the client’s results are, because it is what makes a result explainable.
  • Sign-in records and access changes are kept for 6 years, in line with our information security policy.
  • Financial records, including invoices, are kept for 6 years, as HMRC requires.
  • Enquiries and business correspondence are kept for as long as the relationship lasts and for 6 years afterwards, in line with the Limitation Act 1980.

Accounts, sign-in and this website

To use WyseAi on a client’s behalf we hold your name, work email address and role, and a record of your sign-ins. Sign-in is by password and a one-time passcode sent by email; we never see your password in clear. We process this data to provide the service under our contract with your organisation.

Visiting this website tells us your IP address, browser and the pages you request, in the ordinary server records every website keeps. We use those to run and secure the site, on the basis of our legitimate interest in doing so, and we keep them for no longer than 90 days. There are no analytics, advertising or social media scripts on this site, and nothing here profiles you.

If you write to us, through the contact form on this site or by email, we keep your message and reply to it. The form asks for your name, a work email address, your company if you want to give it, the kind of work and your message. It sets no cookies. We use those details to answer you and, if you become a client, to set up the work; the message reaches us as an email, and you receive a short receipt with a reference number. We keep enquiries for the period given under how long we keep data. We only send marketing to people who have asked for it, and every such message says how to stop.

Cookies

This site and the signed-in application set only the cookies they need to work. None of them tracks you, and none is shared with anyone else. We do not use analytics cookies today. If we introduce them, they will load only for visitors who accept them in the cookie banner, and never for anyone who chose only the necessary ones. You can change your choice at any time, here or from Cookie settings in the footer.

Your cookie preferences

Cookies, their purpose, and how long they last
CookiePurposeLasts
access_tokenKeeps you signed in60 minutes
refresh cookieRenews your sign-in without asking you again7 days
csrf_tokenProtects forms against forged requestsSession
wyseai_partnerRemembers which organisation you are working inSession
wyseai_otp_pendingCarries you through the sign-in passcode stepMinutes
wyseai_consentRemembers your cookie choice, so we do not ask again6 months

Your rights

Under the UK GDPR you can ask us:

  • for a copy of the personal data we hold about you;
  • to correct data that is inaccurate or incomplete;
  • to delete your data where there is no compelling reason for us to keep it;
  • to restrict how we use your data in certain circumstances;
  • for your data in a structured, machine-readable format;
  • to stop processing based on our legitimate interests, or for direct marketing;
  • not to be subject to a decision made solely by automated means where it has a legal or similarly significant effect on you.

On that last point: WyseAi does not make decisions about people. It produces results, with the evidence behind them, for our client’s own staff to act on, and anything the AI cannot support is flagged for a person to review.

To exercise a right, write to contact@wysehub.co.uk. We respond within one calendar month. If your data is in work a client sent us, we will pass your request to them as the controller and help them answer it. If you are unhappy with how we handle your request you can complain to the Information Commissioner’s Office at www.ico.org.uk or on 0303 123 1113.

Changes to this notice

We update this notice when the service changes in a way that affects it, for instance when a processor is added or removed. The version and review date at the top tell you which one you are reading, and where a change is material we take reasonable steps to tell the people it affects.

How to contact us

Wysehub Ltd, 167-169 Great Portland Street, London, England, W1W 5PF. Email contact@wysehub.co.uk or telephone 0333 880 9113.

Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF. Telephone 0303 123 1113.

Back to home

Cookies. This site uses cookies it needs to work. It can also use analytics cookies, but only if you say so. What each one does.

Manage preferences