Privacy & Responsibility

How VenueMindAI collects, processes, and protects your data — and how our AI systems are designed to operate responsibly, transparently, and within legal boundaries.

GDPR Compliant AI Transparency Statement Last Updated: May 2025

1. Who We Are

VenueMindAI ("we", "our", "us") is a compliance technology company providing AI-powered Martyn's Law compliance audits for venues across the United Kingdom. Our registered address and data controller details are available on request.

We are committed to protecting the privacy and security of personal data in compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

2. Data We Collect

We collect personal data in the following circumstances:

Audit Enquiry & Intake Forms

Name, job title, email address, telephone number, venue name, venue address, venue type, approximate capacity, and any additional notes you provide.

Audit Delivery

Venue documentation, floor plans, staffing information, existing security procedures, and other materials provided for the purpose of conducting your compliance audit.

Website Usage

Standard analytics data including pages visited, time on site, browser type, and referring source. No personally identifiable information is collected through website analytics without your consent.

Newsletter & Communications

Email address provided voluntarily for the purpose of receiving compliance updates and Compliance Hub content.

3. How We Use Your Data

  • To respond to your audit enquiry and provide a compliance assessment
  • To deliver your compliance report and associated documentation
  • To send you compliance updates and Compliance Hub content (where you have consented)
  • To improve our AI platform and audit methodology (using anonymised, aggregated data only)
  • To comply with our legal obligations

5. Data Sharing

We do not sell, rent, or trade your personal data to any third party. Data may be shared only in the following limited circumstances:

  • Trusted processors: Our AI platform infrastructure providers operate under strict data processing agreements and do not retain your data beyond the purpose of audit delivery.
  • Legal requirement: Where we are required to disclose data by law, court order, or regulatory authority.

6. Data Retention

Audit records and associated documentation are retained for 6 years from the date of delivery, in line with standard UK commercial record-keeping practice. Enquiry data from non-proceeding contacts is deleted after 12 months. Newsletter subscriber data is retained until you unsubscribe. You may request deletion at any time (see Your Rights, below).

7. Security Measures

We implement appropriate technical and organisational measures to protect personal data from unauthorised access, disclosure, alteration, or destruction. All data is processed and stored within the UK or the European Economic Area. We conduct regular security reviews and access controls are restricted to authorised personnel only.

8. AI Transparency Statement

VenueMindAI uses artificial intelligence as a core component of our compliance audit process. We believe transparency about how AI operates in our service is essential — both as a matter of good practice and as an emerging legal expectation.

AI Transparency & Governance Notice

This report was produced using the VenueMindAI Workflow, which utilises generative AI to assist in gap analysis against Martyn's Law frameworks. To ensure accuracy and compliance, all AI-generated findings have been verified and finalised by a human consultant. No personally identifiable information (PII) is processed through AI systems. For our full AI Responsibility Policy, please contact VenueMindAI.

What Our AI Does

Our AI platform cross-references venue data — including capacity, layout, staffing, and existing security documentation — against the full requirements of the Terrorism (Protection of Premises) Act. It identifies compliance gaps, generates structured recommendations, and produces draft procedural documents tailored to your venue type and tier.

What Our AI Does Not Do

Our AI does not make autonomous legal determinations. Every AI-generated audit output is reviewed by a qualified compliance specialist before delivery. The AI does not process sensitive personal data about individuals at your venue, nor does it make decisions that have legal effects on any individual without human oversight.

Human-in-the-Loop Accountability

A VenueMindAI compliance specialist reviews, validates, and signs off every audit report before it is delivered to the client. AI outputs are treated as a first draft and professional starting point — not the final word. Responsibility for the report's accuracy rests with our human compliance team.

Data Use in AI Processing

Venue data submitted for audit purposes is processed by our AI solely for the purpose of generating your compliance assessment. It is not used to train our AI models without your explicit written consent. Anonymised, aggregated data may be used to improve audit accuracy, with no personally identifiable information included.

Regulatory Position

VenueMindAI monitors developments in AI regulation, including the EU AI Act and UK Government AI governance frameworks, and will update our practices accordingly. Our audit reports are compliance guidance tools and do not constitute legal advice. Clients are advised to seek independent legal counsel for matters requiring formal legal opinion.

9. Your Rights Under UK GDPR

You have the following rights regarding your personal data:

Right of Access

Request a copy of the personal data we hold about you.

Right to Rectification

Request correction of inaccurate or incomplete data.

Right to Erasure

Request deletion of your personal data in certain circumstances.

Right to Restriction

Request we limit how we use your data in certain situations.

Right to Portability

Receive your data in a structured, machine-readable format.

Right to Object

Object to processing based on legitimate interests or for direct marketing.

You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk if you believe your data has been handled unlawfully.

10. Contact Us & Data Requests

To exercise any of your rights, raise a data protection concern, or submit a subject access request, please contact our Data Compliance team:

privacy@venuemindai.co.uk
We will respond to all data requests within 30 days, as required by UK GDPR.
This Privacy Policy was last updated in May 2025. We reserve the right to update it in line with legislative changes. Material updates will be communicated to active clients and subscribers.