01 / Legal
Privacy policy
2026-09-16
Controller
Controller: Teledi AI, the trading name under which the service is provided. There is not yet an incorporated company to which controllership attaches; the register details will be published in the legal notice and in this policy upon incorporation.
Contact address for data protection matters: hola@teledi.ai.
No data protection officer has been appointed, as none of the conditions in article 37(1) GDPR apply. Enquiries are handled through the contact address above.
What we process, and why
This site has no analytics and no third-party cookies. There are two contact channels, email and the form on the contact page, so the personal data we hold is whatever you choose to put in your message.
The form collects four fields and nothing else: name, email, company (optional) and the text of your message. Your IP address, your browser and any tracking identifier are not recorded, and the submission is not stored on this website: it is passed to our internal enquiry inbox and answered from there.
Purpose: answering your enquiry, preparing a technical proposal and, where it goes ahead, managing the resulting engagement. We do not profile and we do not take automated decisions about the people who write to us.
Categories of data: professional identification and contact details (name, role, company, email, and a phone number if you provide one) together with whatever information about your processes and systems you include in the conversation.
Lawful basis
Answering your enquiry and preparing a proposal rely on steps taken at your request prior to entering into a contract (article 6(1)(b) GDPR) and, where you write on behalf of a company, on the legitimate interest in maintaining that business relationship (article 6(1)(f) GDPR).
On the contact form, submitting requires ticking the box that accepts this policy, which is an affirmative act under article 7 GDPR. Without that consent the form refuses the submission. You can withdraw it at any time by writing to the contact address, without affecting the lawfulness of processing carried out beforehand.
Delivering a contracted project relies on performance of the contract (article 6(1)(b) GDPR). Meeting tax and accounting obligations relies on article 6(1)(c) GDPR.
Retention
Enquiries that do not lead to an engagement are kept for a maximum of twelve months from the last contact and then deleted.
Project documentation is kept for the duration of the engagement and then restricted for the limitation periods that apply under commercial, tax and contractual liability law.
Recipients and processors
We do not sell or share personal data, and we disclose it to third parties only where the law requires it. To run the business we use hosting, email, workflow-automation and development providers acting as processors under a contract meeting article 28 GDPR. Messages sent from the contact form travel through the automation provider to our internal enquiry inbox.
In the projects we deliver for clients, our usual position is that of processor in respect of the client's own end-user data. The specific allocation of roles is fixed in the processing agreement signed before the project begins.
For the systems we build, the default configuration hosts data inside the European Union. Where a project requires a provider that processes data outside the European Economic Area, the transfer is documented and relies on an adequacy decision or on standard contractual clauses under chapter V GDPR, and it is agreed with the client before it is implemented.
AI transparency
Article 50 of Regulation (EU) 2024/1689 requires that people be told they are interacting with an AI system where that is not obvious from the context. We treat that as an engineering requirement rather than a footnote: the agents we build identify themselves as automated systems when a conversation opens, and always carry an explicit route to a human.
This website is static and contains no AI system that interacts with visitors. The agents described here are deployed inside each client's own infrastructure, under their control and with their own transparency notice.
In the systems we deliver, each generated answer is tied to the log of the query and the sources retrieved for it, and each action executed against a target system is written to an audit log. That record is the foundation of the traceability obligations under the EU AI Act, which are applicable from 2 August 2026 and whose breach can be penalised under article 99(4) with fines of up to EUR 15 million or 3 % of global annual turnover.
Teledi is a technical implementer, not a legal adviser. We leave the system in a state where your counsel can evidence compliance with documentation and logs; the legal characterisation of the system, its risk classification and the specific obligations that fall on your organisation must be determined with your own legal advice.
Your rights
You have the rights of access, rectification, erasure, restriction of processing, data portability and objection, as well as the right not to be subject to solely automated individual decisions, under articles 15 to 22 GDPR.
To exercise them, write to hola@teledi.ai stating which right you wish to exercise. We respond within one month of receiving the request, extendable by two further months where the complexity justifies it, under article 12(3) GDPR.
If you believe the processing does not comply with the law, you can lodge a complaint with a supervisory authority. Our lead supervisory authority is the Spanish Data Protection Agency (www.aepd.es), and under article 77 GDPR you may also complain to the authority in the Member State of your habitual residence or place of work.
Security
We apply technical and organisational measures proportionate to the risk, under article 32 GDPR: encryption in transit, access control by individual identity, access logging, and periodic review of the permissions granted to both people and automated agents.
Changes to this policy
Any change to this policy is published on this page, with the update date visible at the top of the document. Where a change materially affects the processing described here, it is also communicated to clients with an engagement in progress.
02
Tell us which process to fix
Describe the process and the systems behind it. You get back a technical proposal — architecture, timeline and acceptance criteria — not a service catalogue.
Email hola@teledi.ai