Hobson AI – Privacy, Security & Data Protection Policy
Last Updated: 23/08/2025
At Hobson AI, we take the security, privacy, and integrity of client data seriously. This document explains how we handle, store, and process information when you use our services.
On This Page
1. Who We Are
Hobson AI operates through hobsonschoice.ai and provides AI-powered document intelligence and knowledge services.
Business address:
5 Technology Park, Collindeep Lane, Collindale, London NW9 6BX
Email: info@hobsonschoice.ai
2. Privacy Policy
2.1 Data We Process
We process the following types of data provided by our clients:
- Business documents (e.g., leases, lending documents, planning applications, certificates).
- Metadata extracted from those documents (e.g., dates, amounts, obligations, guarantors).
- Limited client contact details for account management.
We do not use client data for model training.
2.2 AI Models
We use enterprise versions of OpenAI. Data processed via these models is not stored or used for training. More on OpenAI's privacy here: OpenAI Privacy for Enterprise.
2.3 Data Retention
- Documents and extracted data are stored only for the duration of the client contract.
- Data is securely deleted upon request or contract termination.
3. Data Protection & Security Policy
Data is hosted securely on OVH Cloud (UK/EU) with redundancy and encryption.
- Encryption: All data is encrypted both in transit (TLS) and at rest (AES-256).
- Access Control: Only authorised staff have access to production data. Access is logged and monitored.
- Monitoring: Systems are monitored for suspicious activity and vulnerabilities.
- Backups: Regular encrypted backups are maintained for resilience.
4. Data Processing Agreement (DPA)
Hobson AI acts as a Data Processor on behalf of its clients. Clients remain the Data Controller.
4.1 Processing Activities
- Document ingestion
- Data extraction (via structured JSON pipelines)
- Storage and query resolution
- Optional retrieval-augmented generation (RAG) for contextual reasoning
4.2 Storage & Databases
- MongoDB for structured JSON extraction results
- Vector databases for semantic retrieval
- Knowledge graphs for relationship mapping
4.3 Sub-Processors
- OpenAI Enterprise (no training, no retention)
- OVH Cloud (primary hosting provider, UK/EU)
4.4 Client Rights
- Right of access, rectification, and erasure
- Right to restrict or object to processing
- Right to data portability
5. Cross-Document Intelligence
Hobson AI is designed to read across multiple document types (leases, lending files, development plans, compliance certificates) and extract consistent insights. Our safeguards ensure structured evidence is always cited with Document Type, Internal Source, and Internal Evidence for transparency.
6. Guardrails in Practice
- No fabrication of data
- Clear distinction between obligations (what documents say) and facts (what has occurred)
- Consistent schema across all outputs (tables, locators, and sources always present)
7. Governing Law & Jurisdiction
This Policy and all related agreements are governed by the laws of England and Wales. Any disputes will be subject to the exclusive jurisdiction of the courts of England and Wales.
8. Client Responsibilities
Clients are responsible for ensuring:
- Data they upload has been lawfully collected.
- Notices/consents have been obtained where required.
- Sensitive categories of data (health, children, financial accounts) are not uploaded unless contractually agreed.
9. Liability & Limitation of Liability
- Hobson AI's liability is limited to fees paid in the 12 months prior to an incident.
- We are not liable for indirect or consequential damages (e.g., lost profits, goodwill).
- These limitations do not apply in cases of gross negligence, wilful misconduct, or where prohibited by law.
10. International Data Transfers
- Data is primarily stored in the UK/EU (OVH Cloud).
- If data is transferred outside the UK/EU, Hobson AI uses approved mechanisms such as the UK IDTA and EU SCCs.
12. Industry Standards
While not formally certified, our practices align with ISO 27001 and SOC 2 principles:
- Encryption
- Role-based access control
- Continuous monitoring
- Incident response and audit trails
Summary
Hobson AI provides enterprise-grade privacy, security, and transparency for all client data. By combining strong encryption, careful data handling, and OpenAI Enterprise safeguards, we give clients confidence that their information is accurately processed and securely protected.
