Legal
Website privacy policy.
What personal data we collect when you visit jesmond.ai or contact us, why we collect it, who we share it with, how long we keep it, and the rights you have. It does not cover case material put into the Jesmond service.
Version 1.5, 3 September 2026
A. Who we are and what this policy covers
1. Jesmond AI (Defend This) Ltd (Jesmond, we, us) is a company registered in England and Wales under company number 17367476, with its registered office at Chequers House, Chequers Lane, Watford WD25 0LG. We operate the website at jesmond.ai (the website).
2. This policy explains what personal data we collect when you visit the website or contact us, why we collect it, who we share it with, how long we keep it, and the rights you have. We are the controller of that personal data, which means we decide why and how it is processed.
3. This policy does not cover personal data contained in the material that customers put into the Jesmond service. That is governed by the terms of use and data processing agreement described in section K.
4. Questions about this policy or about your personal data should be sent to hello@jesmond.ai or by post to our registered office. Contact details for our data protection officer are available on request.
B. The personal data we collect
5. When you contact us, whether by email, through the website or in person, we collect your name, your email address, your organisation and role where you give them, and the content of your message.
6. When you visit the website, our systems record technical information, namely your IP address, browser type and version, operating system, device type, the pages you view, the date and time you view them, and how long you spend. Some of this is collected through cookies and similar technologies, described in section I.
7. If you ask for a demonstration, a proposal or access to the Jesmond service, we collect the business details needed to respond, namely your name, work email address, telephone number where you give it, organisation and role.
8. We do not ask you for special category data (such as health, ethnicity, religion, trade union membership or sexual orientation) or data about criminal offences, and you should not send it to us through the website.
C. Why we use personal data and our lawful basis
9. UK GDPR requires us to have a lawful basis for each purpose for which we use personal data. Paragraphs 10 to 14 set out our purposes and the basis for each.
10. To respond to enquiries and to correspond with you, including about a demonstration or proposal. Our lawful basis is our legitimate interest in answering the people who contact us and, where you represent a prospective customer, the taking of steps at your request before entering into a contract.
11. To keep the website secure, to detect and prevent misuse, and to investigate incidents. Our lawful basis is our legitimate interest in protecting our systems and the people who use them and, where relevant, compliance with a legal obligation.
12. To understand how the website is used and to improve it. Our lawful basis is our legitimate interest in developing and improving the website. Where we use non-essential cookies or similar technologies for this purpose, we ask for your consent first.
13. To send you information about Jesmond and our other products which we think will interest you. Where the law requires it, we do this only with your consent, and you can opt out at any time by using the link in any message or by emailing us. Otherwise our lawful basis is our legitimate interest in marketing our services to business contacts.
14. To comply with our legal and regulatory obligations, for example in keeping records or responding to a lawful request from a court, regulator or law enforcement body. Our lawful basis is compliance with a legal obligation.
15. Where we rely on legitimate interests, we have considered whether those interests are outweighed by your interests, rights and freedoms and concluded that they are not. You can ask us for more information about that assessment, and you have the right to object, described in paragraph 27.
16. We do not use your personal data to make decisions about you by automated means that produce legal or similarly significant effects. We do not sell personal data.
D. Who we share personal data with
17. We share personal data with service providers who process it on our behalf and on our instructions, namely the providers who host the website, our email and communications providers, and the systems we use to manage enquiries and customer relationships. Each is bound by contract to process personal data only on our instructions and to keep it secure.
18. We share personal data with our professional advisers, including lawyers, accountants and insurers, where necessary to obtain their advice or services.
19. We disclose personal data where the law requires it, for example to a court, regulator or law enforcement body, where disclosure is necessary to establish, exercise or defend legal claims, or where it is necessary to protect the rights, property or safety of Jesmond, our customers or others.
20. If Jesmond is sold, merges with another business or transfers its assets, personal data may be transferred to the buyer or successor, who will be bound by this policy in relation to it.
E. International transfers
21. We are based in the United Kingdom and store personal data here. Some of our service providers may process personal data outside the United Kingdom, including in the United States. Where that happens, we ensure the transfer is covered by adequacy regulations made under the UK GDPR, by the International Data Transfer Agreement or Addendum issued by the Information Commissioner, or by another safeguard the law permits. You can ask us for details of the safeguard that applies to a particular transfer.
F. How long we keep personal data
22. We keep personal data only for as long as we need it for the purpose for which we collected it, and after that only for as long as the law requires or we need it to deal with a dispute or enforce our agreements.
23. As a guide, we keep correspondence with enquirers for 24 months from our last contact, and marketing consents and opt-outs for as long as we need them to honour your choice.
G. Security
24. We have put in place technical and organisational measures appropriate to the risk to protect personal data against unauthorised access, disclosure, alteration or destruction, including encryption of data in transit, access controls, and contractual security obligations on our service providers. No system is completely secure, and transmission over the internet carries risk. If you believe your personal data has been compromised, tell us at once at hello@jesmond.ai.
25. Where a personal data breach is likely to result in a risk to individuals, we will notify the Information Commissioner within 72 hours of becoming aware of it and, where the risk is high, the individuals concerned, as UK GDPR requires.
H. Your rights
26. Under UK GDPR you have the right to ask us for access to the personal data we hold about you, to have inaccurate data corrected and incomplete data completed, to have your data erased in certain circumstances, to restrict our processing in certain circumstances, and to receive the data you have given us in a portable form.
27. You have the right to object to processing based on our legitimate interests. We will stop unless we can show compelling legitimate grounds which override your interests, rights and freedoms. Where the processing is for direct marketing, we will stop on request in every case.
28. Where we rely on your consent, you may withdraw it at any time. Withdrawal does not affect processing carried out before you withdrew.
29. To exercise any of these rights, email hello@jesmond.ai. We will respond within one month, or tell you within that month if we need longer because the request is complex or you have made several. We do not charge for dealing with requests unless they are manifestly unfounded or excessive. We may ask you to confirm your identity before acting.
30. If you are unhappy with how we have handled your personal data, please contact us first so that we can try to put it right. You also have the right to complain to the Information Commissioner’s Office, the UK supervisory authority, at https://ico.org.uk/make-a-complaint/.
I. Cookies
31. The website uses strictly necessary cookies only. If we introduce analytics or other non-essential cookies, we will ask for your consent through a banner before they are set and will describe them here.
32. The website is for businesses and their staff and is not directed at children.
J. Changes to this policy
33. We may update this policy from time to time. We will post the new version on the website with a new version number and date and, where the change is material and we hold your contact details, we will tell you by email. This version was published on 3 September 2026.
K. Terms of use and data processing agreement
34. This policy covers the website. It is not the basis on which the Jesmond service is provided. Customers who take up the service enter into a written agreement with us at the time of contracting, made up of terms of use and a data processing agreement, and those documents govern the service and the case material put into it.
35. The terms of use govern access to and use of the service. They cover who may use the service on the customer’s behalf, the issue and safekeeping of access credentials, acceptable use, the customer’s responsibility for the material it puts into the service and for checking every document the service produces before it is used, intellectual property, fees, confidentiality, liability, and term and termination.
36. The data processing agreement governs personal data in the case material. It records the respective roles and responsibilities of the customer and Jesmond, the subject matter, duration, nature and purpose of the processing, the types of personal data and the categories of individuals concerned, the third party artificial intelligence provider and any other sub-processor, the terms on which they process the data, including the commitment that it is not used to train models, the countries in which processing takes place and the safeguards for any transfer outside the United Kingdom, the security measures applied, the assistance we give with requests from individuals and with security incidents, and what happens to the data when the contract ends.
37. The customer remains responsible for deciding what case material to put into the service, for having a lawful basis to do so, and for telling its employees and others whose data is involved how that data is used.
38. Where anything in this policy is inconsistent with the customer agreement, the customer agreement prevails in relation to the service and the case material. Anyone whose personal data is in case material should direct requests about it to the customer, whose agreement with us sets out how we will assist.
39. Prospective customers can ask for a copy of our standard terms of use and data processing agreement by emailing hello@jesmond.ai.