Privacy Notice
This Privacy Notice covers the processing of personal data by HOIBOY AI LTD (UK Companies House 17211412), trading as hoiboy.uk for its AI consultancy and all of its services.
It satisfies the controller’s obligations under UK GDPR Article 13 (information to be provided where personal data are collected from the data subject) and UK GDPR Article 14 (information to be provided where personal data have not been obtained from the data subject, including the 30-day clock for notification under Article 14(3)(a)).
1. Who we are (controller identity)
- Controller: HOIBOY AI LTD (UK Companies House 17211412)
- Registered office: address recorded in the prevailing engagement-letter for engaged clients; available on request via
hello@hoiboy.ukfor general enquiries - Contact email:
hello@hoiboy.uk - Data Protection contact: Senh Hoi Ung (sole director). Email
hello@hoiboy.ukfor all data-protection queries, subject-access requests, erasure requests, and Article 21 objections
HOIBOY AI LTD does not have a separate Data Protection Officer (DPO). The sole director is the Data Protection contact and is accountable for all data-protection responsibilities under UK GDPR.
2. What this notice covers
This notice covers two scopes:
Site visitor data (general)
- Visitor analytics: aggregated, anonymised page-view counts via privacy-preserving analytics. No individual tracking, no cookies beyond strictly-necessary, no advertising trackers.
- Contact-form / email enquiries: when you email
hello@hoiboy.uk, your email address and message content are processed for the purpose of responding to your enquiry. - Community submission form: if you submit the “Get featured” form on the Asians & Gingers in Tech community page, we process the details and optional photo you send, on the basis of your explicit consent (see section 4).
- Newsletter subscription: if you subscribe using the form in the site footer, we process your name and email address so we can email you new posts, on the basis of your consent (see section 4).
- Partnership brochure: the ICT consultancy page publishes our CRE and ICT services brochure, which includes my consultancy partner Jolyn Pek’s photograph, professional credentials, the languages and Chinese dialects she speaks, location, and her client projects with the savings figures she delivered. The page itself also names her, describes her role, and says where she is based. Both are published on the basis of her consent (see section 4).
Consultancy engagement data (engaged clients only)
- Audio recordings, video frames, transcripts, and AI-summaries from recorded sessions during AI Managed Harness Services engagements.
- Operator notes and engagement metadata (timestamps, attendee lists, meeting purpose, engagement-reference codes).
- Time-logs, invoices, and VAT records for billing and statutory retention.
3. Notes + AI-assisted summaries (consultancy-engagement scope)
This section applies ONLY to clients with a signed engagement-letter. Pre-engagement Cal.com discovery calls are NEVER recorded.
I take digital notes during our calls. Typed by hand, occasionally backed by an audio recording that I transcribe and summarise locally with AI assistance. The purpose is personal accuracy: I cross-check notes against the transcript so the brief matches what you said.
Audio is deleted within 7 days of transcript verification. The transcript is deleted once we’ve locked the scope in writing. The brief itself I keep per HMRC’s 6-year business-record rule.
Nothing leaves my workstation beyond the sub-processors listed on the Sub-Processors page. PII redaction is applied before any external AI-review call; speaker-verification and face-recognition are disabled.
You can ask me to stop, or delete anything at any time, by emailing hello@hoiboy.uk.
4. Site visitor data
Visitor analytics
We use privacy-preserving analytics that aggregate page-view counts without setting cookies or tracking individuals. No personal data is collected via analytics.
Contact-form / email enquiries
When you email hello@hoiboy.uk, your email address and message content are used to respond to your enquiry. Enquiry threads are kept for 12 months from last reply, then deleted unless you have entered a paid engagement (in which case the engagement scope below applies).
Community submission form
The Asians & Gingers in Tech community page has a “Get featured” form. If you choose to submit it, we collect your name, your email address, your tech role, your superpowers, your story, and, if you add one, a photo of you.
- Purpose: to consider your story and, with your consent, publish it as part of a public feature series celebrating quiet, heads-down people in tech.
- Lawful basis: explicit consent (UK GDPR Article 9(2)(a)). The form invites you to self-identify with a community defined partly by ethnicity, and a photo is an image of an identifiable person, so a submission can include special-category data. We only process it because you tick the consent box, and you can withdraw at any time by emailing
hello@hoiboy.uk. - How it is processed: the photo is stored privately in Cloudflare R2 (not publicly reachable); the entry is emailed to us via Cloudflare; and spam protection uses Cloudflare Turnstile, which processes your IP address. Because we lightly edit submissions for form (not facts) before publishing, if your story is going to be featured we then email you the exact final wording via Google Gmail (
hoiboyuk@gmail.com) and read your reply, so nothing is published without your emailed approval of the exact wording. Working copies of your submission and of your approval are also held in local storage on our own workstation. If your story is published, the feature (your published photo, your name and your story) is committed to this site’s public GitHub repository, which is where the site is stored and built from, so it also becomes part of that repository’s public history; and a per-feature posting kit (the published images plus the announcement copy) is written to our business Google Drive so the feature can be announced on the community’s social channels. These processors are listed on the Sub-Processors page. - Retention: the photo you upload is stored privately in Cloudflare R2 and auto-expires 90 days after upload. Your submission (name, email, role, superpowers, story) reaches us as an email, which we keep while we consider and prepare the feature. Because we edit and republish submissions, for a feature we take forward we also keep a legal-evidence record: your original submission verbatim, the exact wording we published, and your emailed approval, so that if a published feature is ever challenged we can show what you sent, what we published, and that you approved it. We keep that record for the establishment, exercise or defence of legal claims (UK GDPR Article 17(3)(e)), which means it can survive an ordinary erasure request for as long as that basis applies; anything outside that record you can ask us to delete at any time by emailing
hello@hoiboy.uk. A published feature stays up until you ask us to take it down. Four stores are involved and they expire differently: the uploaded photo in Cloudflare R2, on the 90-day expiry stated above; the local record vault on our own workstation, which holds your original submission and your approval for as long as the legal-evidence basis above applies; the public GitHub repository this site is built from, whose git history keeps a published feature permanently unless we run the history purge described in the take-it-down section of the Story Guidelines; and the per-feature posting kit on our business Google Drive, which we delete when the feature is taken down.
Newsletter subscription
The site footer carries a subscribe form. If you tick the consent box and submit it, we collect your name and your email address, and nothing else.
- Purpose: to email you new posts from hoiboy.uk. That is the entire scope of what you are consenting to. We do not use this list to send you anything about our services, our consultancy or our products. If we ever want to, we have to ask you again.
- Lawful basis: consent (UK GDPR Article 6(1)(a)), with the electronic-mail marketing rules in PECR Regulation 22 applying on top. The consent box is unticked by default and it is separate from any other permission, so nothing else on this site is withheld if you leave it alone. Ticking it is what subscribing means, so the form does not submit without it, and the server refuses a submission that arrives without it. Subscription is double opt-in: you are not on the list until you click the confirmation link we email you, so a mistyped or borrowed address never joins.
- How it is processed: the form posts to a Cloudflare Pages Function on this site, which passes your name and email to Brevo, our email provider, and asks Brevo to send you the confirmation email. Spam protection uses Cloudflare Turnstile, which processes your IP address. We store two things as the record of your consent: the time you submitted the form, and the version string of the exact consent wording you agreed to (currently
2026-08-03). Brevo separately records the time you confirmed. We keep the wording version so that if the label is ever reworded we can still show which words you actually agreed to. We do not store your IP address as part of the consent record. - Retention: we keep your name, email and consent record for as long as you stay subscribed. When you unsubscribe we remove you from the list and keep only the evidence that you withdrew, so we can show we acted on it.
- How to withdraw: every email we send carries an unsubscribe link, and one click is enough. You can also email
hello@hoiboy.uk. Withdrawing is as easy as subscribing was, which is what Article 7(3) requires. - Article 17 erasure: you are one addressable contact record in Brevo, so erasure is a single deletion of that record and everything stored against it. Brevo is the only third party holding your subscription data, so that deletion is also the Article 19 notification. There is no one else for us to tell.
- Article 21 objection to direct marketing: you can object at any time, and there is no balancing test for us to apply. Because this list runs on consent, an Article 21 objection and an Article 7(3) withdrawal arrive at the same place, and the same one-click unsubscribe satisfies both.
- Article 20 portability: the data is your name and your email address. Ask at
hello@hoiboy.ukand we send you both in a structured, machine-readable file within one calendar month, through the same channel as any other subject-access request.
Partnership brochure
The ICT consultancy page publishes the CRE and ICT services brochure I produce with my consultancy partner, Jolyn Pek. It contains her photograph, her professional credentials, the languages and Chinese dialects she speaks, her location, and her client projects with the savings figures she delivered. The page itself also names her, describes her role, and says where she is based.
- Purpose: to show prospective clients the combined corporate real estate and ICT service we offer, and who they would be working with.
- Lawful basis: consent (UK GDPR Article 6(1)(a)), and explicit consent (Article 9(2)(a)) for her photograph and for the list of Chinese dialects she speaks, which taken together can reveal ethnic origin. She agreed to publication before the file was committed. She can withdraw at any time by emailing
hello@hoiboy.ukor by telling me directly. - How it is processed: the brochure is a PDF committed to this site’s public GitHub repository, which is where the site is stored and built from, and served from Cloudflare Pages. Because the repository is public, the file also becomes part of that repository’s permanent history.
- Retention: the brochure and the mention of her on the page stay published until she or I take them down, which removes the link, the file and the page’s description of her together. The public repository’s git history keeps them unless we also run a history purge, and copies already taken by third-party forks, clones and caches are outside our control.
- Withdrawal: email
hello@hoiboy.uk, or tell me directly. Withdrawing is as easy as agreeing was, which is what Article 7(3) requires.
5. Your data-subject rights
Under UK GDPR, you have the following rights:
- Article 15 right of access: request a copy of the personal data we hold about you.
- Article 16 right to rectification: request correction of inaccurate personal data.
- Article 17 right to erasure: request deletion of your personal data. Where HMRC statutory retention applies (time-logs, invoices, VAT records), we sanitise-and-retain rather than fully delete; where it does not (recordings, transcripts, AI-summaries), we cryptographically erase. For a published community feature, the original submission, the published wording, and your approval are kept as a legal-evidence record under Article 17(3)(e) (defence of legal claims) for as long as that basis applies (see section 4). An erasure request for a published feature covers every store it reached: the live page comes down, the posting kit on our business Google Drive is deleted, and the feature is purged from the public GitHub repository’s git history using the procedure described in the take-it-down section of the Story Guidelines; copies already taken by third-party forks, clones and caches are outside our control.
- Article 18 right to restriction: request that we restrict processing while we resolve a rectification or erasure dispute.
- Article 20 right to portability: where applicable, request a copy of the data in a structured, commonly used, machine-readable format.
- Article 21 right to object (handled standalone, NOT collapsed into erasure): object at any time to the recording-related processing under our Article 6(1)(f) Legitimate Interest basis. We cease processing forward; existing recordings stay under Legitimate Interest unless you also invoke Article 17. Article 21 also covers direct marketing, which for this site means the newsletter list in section 4; there the objection is absolute, needs no reason, and the one-click unsubscribe in every email satisfies it immediately.
To exercise any of these rights, email hello@hoiboy.uk with your request. We respond within one calendar month.
6. Right to lodge a complaint with the ICO
You have the right to lodge a complaint with the Information Commissioner’s Office (ICO) if you believe we have failed to meet our UK GDPR obligations.
- Website: https://ico.org.uk/make-a-complaint/
- Helpline: 0303 123 1113
- Address: Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
We encourage you to email us at hello@hoiboy.uk first so we can attempt to resolve concerns directly, but you are not required to do so before lodging an ICO complaint.
7. Article 14 specific notice (where personal data have not been obtained from the data subject)
Where you (the data subject) are notified of this Privacy Notice indirectly, for example you are a third-party engineer invited by our Client to a recorded session and you are receiving this notice via the Client (not directly from us), UK GDPR Article 14 applies and we provide notice within the 30-day clock under Article 14(3)(a). The information in sections 1-6 above applies equally; the source of your personal data in this case is the Client who invited you to the recorded session.
8. Changes to this notice
We may update this notice over time (for example, when a sub-processor changes, or when retention windows are revised). Material changes are communicated to active engagements via the engagement-letter signatory’s email address. The version-controlled history of this notice is reflected in the lastmod date at the top of this page.