Privacy Policy
1. Who we are
Andrea Aita is an information management practitioner based in London, UK. Andrea is the data controller for personal information collected through this website.
Contact: info@noeinsolutions.com
2. What data we collect and why
We only collect personal data when you actively provide it to us. The table below summarises what we collect, how, and on what legal basis under UK GDPR.
| Data | Source | Purpose | Legal basis |
|---|---|---|---|
| Name, email address, company, enquiry, and any optional project details you add (such as deadlines, tools, delivery partners or programme value) | Contact form (processed by FormSubmit) | Replying to your enquiry and any follow-up about the work | Legitimate interests (Art. 6(1)(f) UK GDPR) |
| No personal data — answers stored only in your browser | BEP Readiness Checklist and EIR Health Check (client-side tools) | None: the tools score, report and export entirely in your browser. Nothing is submitted, stored on a server, or transmitted to us unless you use the optional field below. | Not applicable (no processing) |
| Email address, plus the score, band, section scores and gaps of the report on screen, and the project name if you entered one | The optional “email me the report” field on either checklist (processed by FormSubmit) | Sending you that report and replying to you about it. You are not added to any mailing list. | Legitimate interests (Art. 6(1)(f) UK GDPR) |
| Name, email address, and the company and line of context you choose to add; plus your IP address, browser type, the page that sent you to this site, any campaign tags in the link you followed, and how long the form took to fill in | The “request beta access” panel on the Capsar page (processed by Capsar.io on our own server) | Setting up your beta invite on app.noeinsolutions.com — the address becomes the account the passcode is issued against — and replying to you about it. The technical details are used to tell genuine requests from automated ones, and your address is matched to any Capsar demo you ran with it. You are not added to any mailing list. | Legitimate interests (Art. 6(1)(f) UK GDPR) |
| Project documents and text you work on in Capsar.io — for example an uploaded EIR, or the BEP field you ask the AI to draft — and any personal data inside them, such as the names and roles in a responsibility matrix | Capsar.io’s AI features: document analysis, drafting and suggestions — processed by a model on Capsar’s own server, or by Google’s Gemini API if you choose it | Producing the analysis, draft or suggestion you asked for. On Capsar’s own server the text is not sent to any outside AI provider; on Gemini, Google does not use it to train or improve its models (see section 3). | Performance of a contract (Art. 6(1)(b) UK GDPR) |
| Email address, plus the finding, the size band and the full scope shown on screen | The optional “have it sent to you” field on either scoping tool (processed by FormSubmit) | Sending you that scope and replying to you about it. You are not added to any mailing list. | Legitimate interests (Art. 6(1)(f) UK GDPR) |
| The answers you gave a scoping tool, and the scope built from them | Your own browser — saved on your device so you can close the tab, and carried to the contact form if you choose “send this as a brief” | Letting you leave and come back, and saving you retyping the scope into a brief. Nothing is transmitted to us at this stage; clearing your browser data removes it. | Not applicable (no processing by us) |
| IP address, browser type, referrer | Web server logs (nginx) | Security monitoring and debugging | Legitimate interests (Art. 6(1)(f) UK GDPR) |
3. Third-party services
We use the following third-party services that may process your data:
- FormSubmit.co — receives contact-form submissions and any checklist report or scoping report you ask for by email, and forwards them to us. Your data is processed by FormSubmit in accordance with their privacy policy.
- Google Fonts — fonts are loaded from Google’s servers, which may log your IP address. See the Google Privacy Policy.
- Google Gemini API — runs Capsar.io’s AI features when you choose it instead of the model on Capsar’s own server. When you then analyse a document or ask the AI to draft or suggest, the text it needs is sent to Google. Under Google’s paid Gemini API terms, Google does not use your prompts or its responses to improve its products, and logs them for a limited period only to detect abuse. Google may process that text in any country where it has facilities, so the AI step does not keep your data in one jurisdiction. Your projects themselves are stored on the server that runs Capsar.io.
- Stripe — processes payments for the Capsar.io tender evaluation pack. If you buy one, your card details go to Stripe and never to us — we receive only the payment reference, the amount, and the email address you paid with, so we can activate the pack on your workspace. Your data is processed by Stripe in accordance with their privacy policy.
We do not sell your data to any third party, nor do we use your information for advertising.
4. How long we keep your data
Contact-form emails, checklist report requests and the email notifying us of a beta access request are kept in our email inbox for up to two years and then deleted. The beta access request itself is stored in the Capsar.io application for up to 180 days and then deleted automatically. An invite created from a beta request lives in the application for as long as your beta access does; ask us and we will deactivate it. We run no marketing mailing list and add nobody to one. Checklist answers themselves stay in your browser: what reaches us when you ask for a report is your address and the summary shown on screen, not the answers behind it.
Records of a purchase are the exception, and we cannot delete them on request: UK tax law requires us to keep records of a sale for six years from the end of the accounting period it falls in. That record is the payment reference, the amount, the date and the account it activated a pack on — never card details, which we never hold.
5. Your rights under UK GDPR
You have the following rights regarding your personal data:
- Right of access — you can request a copy of the data we hold about you.
- Right to rectification — you can ask us to correct inaccurate data.
- Right to erasure — you can ask us to delete your data where we have no overriding reason to retain it.
- Right to object — you can object to processing based on legitimate interests.
- Right to lodge a complaint — if you are not satisfied with how we handle your data, you can contact the Information Commissioner’s Office (ICO) at ico.org.uk.
To exercise any of these rights, email info@noeinsolutions.com. We will respond within one month.
6. Cookies
This website does not set any cookies of its own. Third-party services such as Google Fonts may set their own cookies in accordance with their respective privacy policies. You can manage cookies through your browser settings.
7. Changes to this policy
We may update this policy from time to time. Material changes will be reflected in the “Last updated” date at the top of this page. Continued use of the site after changes constitutes acceptance of the revised policy.
8. Contact
For any questions about this privacy policy or to exercise your rights, contact:
Andrea Aita
London, UK
info@noeinsolutions.com