This policy explains how Public Sector Analytics Limited (trading as askKira, hereafter "askKira", "we", "us") collects, uses, processes and safeguards data submitted to AI Builder and the wider askKira platform. It is written to be understood by procurement teams, DPOs, governors, trustees and the staff who actually use the product.
askKira is registered with the Information Commissioner's Office under registration ZB622646. We operate from England and Wales; all data is processed and stored within the United Kingdom.
For individual users signing up directly, askKira acts as data controller in respect of your account record. For users whose accounts are provisioned by a school, trust, charity or organisation, your organisation is the data controller and askKira operates as a data processor, acting on the organisation's documented instructions.
A UK GDPR Article 28 Data Processing Agreement governs the relationship in every case where askKira processes data on behalf of an organisation. A signed copy is available on request via dpo@askkira.com, typically within five working days.
We do not use your data for advertising, ad targeting, third-party data sale, or to train AI models that benefit other customers.
This is the most asked question, so here is the canonical answer:
Foundation models that askKira calls (OpenAI, Anthropic, Google Gemini) are accessed via API under terms that explicitly prohibit training on customer data. The text of your prompts and any documents you choose to upload are sent only for the purpose of producing the response you asked for, and only when the feature actively requires it.
askKira engages the following sub-processors to deliver the service. Each is bound by a written agreement aligned to UK GDPR Article 28 standards. We do not share your data with any party not listed here.
| Sub-processor | Purpose | Region |
|---|---|---|
| Amazon Web Services | Primary hosting and storage | UK (eu-west-2) |
| Microsoft Azure | Secondary infrastructure | UK / EU |
| OpenAI | LLM API · no training on customer data | API endpoints |
| Anthropic | LLM API · no training on customer data | API endpoints |
| Google (Gemini) | LLM API · no training on customer data | API endpoints |
| Cloudflare | Edge security and DDoS mitigation | Global edge |
| Stripe | Payments processing · PCI-DSS | UK / EU |
| Wonde | Education MIS integration (askKira platform) | UK |
Under UK GDPR you have the right to:
AI Builder uses the minimum number of cookies required to operate. We do not use advertising, tracking or behavioural-targeting cookies on this platform.
| Cookie | Purpose | Retention |
|---|---|---|
| Session cookie | Keeps you signed in. HMAC-signed, HTTPOnly, SameSite=Lax, Secure-when-HTTPS. | 30 days |
| CSRF token (in session) | Validates form submissions to prevent cross-site request forgery. | Session |
If a personal-data breach is detected, affected data controllers will be notified within 72 hours of discovery with the minimum context required to exercise their obligations under UK GDPR Article 33. Where individuals are directly affected, they will be notified without undue delay.
To report a suspected breach, email security@askkira.com.
| Data Protection Officer | dpo@askkira.com |
| Privacy enquiries | privacy@askkira.com |
| Security disclosures | security@askkira.com |
| Compliance / DPA / procurement | compliance@askkira.com |
| Registered entity | Public Sector Analytics Limited (Co. No 14889377) |
| ICO registration | ZB622646 |
We aim to respond to every enquiry within five working days.