ardento.

Last updated 8 September 2026

Privacy policy

This policy explains what personal data Ardento Ltd collects, why we collect it, and the rights you have over it. We keep it short because we collect very little.

Who we are

Ardento Ltd is an AI integration consultancy. We are the data controller for the personal data described in this policy. You can reach us through the contact form on our home page or by email: .

What we collect and why

When you contact us. If you use the contact form or email us, we hold your name, email address, organisation and whatever you tell us about your problem. We use this to reply, to scope any work you ask us to do, and to keep a record of our conversation. Our lawful basis is our legitimate interest in responding to enquiries and running our business, or the steps needed to enter into a contract with you.

When you visit this website. This site does not set cookies and does not use analytics or advertising trackers. Our hosting provider, Vercel, records standard server logs (IP address, browser type, pages requested, timestamps) for security and to keep the service running. We do not use these logs to identify individual visitors.

When we work with you. During an engagement we may process personal data held in your systems on your behalf. In that case you are the controller and we act as your processor under a written contract that sets out what we may do with it. This policy does not cover that processing; the contract does.

What we do not do

  • We do not sell personal data or share it with anyone for marketing.
  • We do not add you to a mailing list because you emailed us.
  • We do not use personal data from enquiries to train AI models.
  • We do not make automated decisions about you that have legal or similar effects.

Who we share it with

We use a small number of suppliers to run the business: our email provider, our website host (Vercel), and Resend, which delivers contact-form messages to our inbox. Vercel also runs the bot detection that protects the form; it analyses request signals such as IP address and browser characteristics to tell people from automated traffic. They only process data on our instructions and under contracts that require them to protect it. Some of these suppliers are based outside the UK; where that is the case we rely on the UK International Data Transfer Agreement or an adequacy decision to make the transfer lawful.

We will disclose personal data if the law requires us to, for example in response to a court order.

How long we keep it

We keep enquiry correspondence for up to two years after our last contact, unless it leads to an engagement, in which case we keep it for the life of the contract plus six years to meet our legal and accounting obligations. Server logs are retained by our host for a short rolling period and then deleted.

How we protect it

Access to personal data is limited to the people who need it. Our systems use encryption in transit and at rest, multi-factor authentication and vetted suppliers. Security-first engineering is how we work for clients, and we apply the same standard to ourselves.

Your rights

Under UK GDPR you can ask us to:

  • tell you what personal data we hold about you and give you a copy;
  • correct data that is inaccurate or incomplete;
  • delete your data;
  • restrict or object to how we use it;
  • give you your data in a portable format.

To exercise any of these rights, contact us at . We will respond within one month. There is no charge unless a request is clearly unfounded or excessive.

If you are unhappy with how we have handled your data, you have the right to complain to the Information Commissioner's Office at ico.org.uk. We would appreciate the chance to resolve it with you first.

Changes to this policy

We will update this page if our practices change and revise the date at the top. We will not reduce your rights under this policy without telling you.