Legal
Privacy Policy
Last updated 16 August 2026.
Recovery Agent is a trading name and product of Proja AI Ltd, Company No. 16963746, registered in England and Wales ("we", "us"). These terms apply to the Recovery Agent platform and services.
1. Who we are
Proja AI Ltd, Company No. 16963746, registered in England and Wales, is the controller of personal data processed through the Recovery Agent public website and the controller of account data used to administer the Recovery Agent platform.
Where we analyse customer records under an engagement, we act as a processor on behalf of the customer under a Data Processing Agreement.
2. Data we collect
Enquiry data: name, work email, telephone, organisation, job title, service required, indicative scope information and the context you provide in the confidential assessment form.
Account data: name, email, role, organisation membership, authentication metadata, multi-factor enrolment status and session records.
Usage and audit data: actions taken in the platform, file access, downloads, approvals, and correlation identifiers recorded for security and assurance.
Customer records: transactional, contractual and evidential data uploaded by a customer under an engagement. We process this only on the customer's documented instructions.
3. Lawful bases
We rely on legitimate interests for responding to business enquiries, operating and securing the platform and preventing misuse; on contract for delivering engagements; and on legal obligation where retention or disclosure is required by law.
4. Sharing
We use vetted sub-processors for hosting, database, storage, transactional email and model inference. A current list is available on request and is maintained in the Data Processing Agreement.
We do not sell personal data. We do not use customer data to train public models. We do not use one customer's data for another customer.
5. Retention
Enquiry data is retained for up to 24 months from last contact unless an engagement begins. Engagement data is retained for the period agreed in the engagement terms, then deleted or returned. Audit records are retained for the longer of the engagement retention period and any applicable statutory period.
6. Your rights
You have the right to access, rectification, erasure, restriction, objection and portability, and the right to complain to the Information Commissioner's Office. Where we act as processor, we will refer your request to the relevant customer as controller.
7. International transfers
Where personal data is transferred outside the UK, we rely on adequacy regulations or the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, together with appropriate supplementary measures.
8. Security
We apply tenant separation, row-level security, private storage, encryption in transit and at rest, multi-factor authentication for privileged users, session timeouts and append-only audit logging. We do not claim any certification we have not formally achieved.