Privacy Policy

Last updated: August 2026

Summary of key points

We want you to understand our privacy practices before you read the detail, so here are the key points:

  • We are Tracelight Ltd, a company registered in England and Wales, and we are the data controller for the personal data described in this policy (except for customer content, where we act as a processor, see details below).
  • We do not use your data to train AI models. Customer content is never used to train our models or any third-party models.
  • We use trusted sub-processors (including cloud hosting and AI model providers) to deliver our Services. A current list is maintained at https://tracelight.ai/data-processing-agreement
  • We primarily offer EU/UK data residency, with some limited exceptions.
  • You have rights over your personal data, including access, correction, erasure and objection, and you can complain to the ICO.
  • Please note: You may engage with us in an individual capacity or on an enterprise level. If engaging with Tracelight as a business on an enterprise level, you will agree a separate master services agreement and data processing agreement with us. This Privacy Policy would still apply to the data for which we act as controller.

1. Who we are and how to contact us

We are Tracelight Ltd ("Tracelight", "we", "us", "our"), a company incorporated in England and Wales with company registration number 15938877, whose registered office is at Senna Building, Gorsuch Place, London, England, E2 8JF.

This Privacy Policy explains how we collect, use, store, share and protect personal data ("personal data") relating to individuals ("you", "your") when you:

  • visit our website at tracelight.ai ("Website");
  • register for, access or use the Tracelight application and related services ("Services");
  • communicate or do business with us, or express interest in our Services.

We process personal data in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 (DPA 2018) and, where applicable, the EU General Data Protection Regulation (EU GDPR).

If you are a customer located in the United States, your contract is with Tracelight AI, Inc., a Delaware corporation, which is the controller of your account data. Tracelight Ltd provides the Tracelight platform on its behalf, and personal data relating to US customers is processed in a US-hosted environment. Some of our support is provided from the United Kingdom. In this policy "we", "us" and "our" mean Tracelight Ltd, and Tracelight AI, Inc. where it acts as controller for US customers. Both can be reached at privacy@tracelight.ai.

2. Controller and processor roles

Because of how Tracelight is used, we act in two different capacities:

As a controller. We decide how and why personal data is processed when we operate our Website, market our Services, manage accounts and billing, provide support, and run our business. This policy governs that processing.

As a processor. When our customers ("Customers") upload spreadsheets, financial models, documents and other files ("Customer Content") to the Services, that Customer Content may contain personal data. We process it only on the documented instructions of the Customer, who is the controller of that data. Our processing of Customer Content is governed by our Data Processing Agreement (DPA) with the Customer, available at https://tracelight.ai/data-processing-agreement, which Customers must review and agree to prior to using Tracelight, or by the data processing agreement in the Customer's master services agreement where one has been signed.

If you are an individual whose personal data appears in any Tracelight product via an enterprise customer who is using Tracelight, and you wish to exercise your rights, please contact the relevant enterprise customer directly (the controller). We will assist that customer in responding, as required by the relevant data processing agreement.

3. The personal data we collect

The personal data we collect depends on your relationship with us. The table below summarises the categories we may collect as a controller.

Account and contact data — First and last name, business email address, job title, employer, telephone number, account username. Source: You; your organisation's administrator.

Authentication data — SSO/SAML identifiers, multi-factor authentication data, authorisation tokens. Source: You; your identity provider.

Billing and payment data — Billing contact, billing address, payment method details processed via our payment provider (we do not store full card numbers). Source: You; our payment processor.

Usage and product data — Features used, AI actions and audit logs, in-product activity, preferences and settings. Source: Automatically, when you use the Services.

Device and technical data — IP address, approximate IP-based location, device and browser type, operating system, unique device identifiers, diagnostics and performance data. Source: Automatically.

Website and analytics data — Pages viewed, referring source, interactions with our Website and emails. Source: Automatically, via cookies and similar technologies (see Section 9).

Marketing and communications data — Marketing preferences, correspondence with us, responses to campaigns, information you submit via forms. Source: You.

Support data — Information you provide when you contact support, including the content of your messages. Source: You.

Customer Content. Customer Content may contain personal data (for example, names or contact details inside spreadsheets or models). We process this as a processor only, see Section 2.

Special category data. We do not intentionally collect special category personal data (such as data revealing racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic or biometric data, health, or data concerning sex life or sexual orientation) or data relating to criminal convictions and offences as part of operating our Website or account management. Customers must not upload special category data, or data relating to criminal convictions and offences, into the Services unless Tracelight has agreed to it in advance in writing. Without that written agreement, such use is prohibited.

Children. Our Services are intended for business use and are not directed at children – children should not use Tracelight. We do not knowingly collect personal data from anyone under 18. If you believe a child has provided us with personal data, please contact us at privacy@tracelight.ai.

4. How we use your personal data and our lawful bases

Under UK GDPR we must have a lawful basis for each processing purpose. The table below sets out what we do, why, and the lawful basis we rely on.

Creating and administering your account; providing the Services — Categories used: Account, authentication, usage data. Lawful basis: Contract.

Processing payments and managing billing — Categories used: Billing and payment data. Lawful basis: Contract; Legal obligation for tax/accounting records.

Securing the Services, authenticating users, preventing fraud and misuse, maintaining audit logs — Categories used: Authentication, usage, device data. Lawful basis: Legitimate interests - keeping the Services secure.

Providing customer support — Categories used: Support, account data. Lawful basis: Contract; Legitimate interests.

Improving and developing the Services, analytics, troubleshooting — Categories used: Usage, device, analytics data (aggregated/de-identified where possible). Lawful basis: Legitimate interests - improving our products.

Sending service and transactional communications — Categories used: Account, contact data. Lawful basis: Contract; Legitimate interests.

Sending marketing communications to business contacts — Categories used: Contact, marketing data. Lawful basis: Consent and/or Legitimate interests, consistent with PECR.

Complying with legal, regulatory and accounting obligations — Categories used: As relevant. Lawful basis: Legal obligation.

Establishing, exercising or defending legal claims; corporate transactions — Categories used: As relevant. Lawful basis: Legitimate interests; Legal obligation where applicable.

Where we rely on legitimate interests, we have carried out (or will carry out) a legitimate interests assessment (LIA) balancing our interests against your rights. You can ask us for more information about any of these assessments.

Where we rely on consent (for example, certain marketing or non-essential cookies), you can withdraw it at any time without affecting the lawfulness of processing before withdrawal.

5. Artificial intelligence and automated processing

Tracelight uses artificial intelligence to power core features of the Services, including analysing and generating spreadsheet models, reviewing and auditing models, ingesting and cleaning data, and producing cited, traceable outputs.

How AI processes data. When you use AI features, the Services process the inputs you provide (including Customer Content) to generate outputs such as models, reviews, summaries and analyses. We log AI actions to support traceability and auditability.

AI model training. We do not use Customer Content to train our AI models, and we do not permit third-party model providers (for example OpenAI, Anthropic) to use Customer Content to train their models.

Third-party AI providers. We use third-party AI/model providers as sub-processors to deliver AI features. See Section 7 and our sub-processor list at https://tracelight.ai/data-processing-agreement.

AI-generated content. Outputs generated by AI features may contain errors. You are responsible for reviewing outputs before relying on them, particularly for financial, valuation or decision-making purposes.

Automated decision-making. We do not use your personal data to make decisions based solely on automated processing (including profiling) that produce legal or similarly significant effects concerning you, within the meaning of UK GDPR Article 22. If this changes, we will update this policy and provide the safeguards required by law, including the right to obtain human intervention, to express your point of view and to contest the decision.

6. Retention of personal data

We keep personal data only for as long as necessary for the purposes for which it was collected, including to satisfy legal, accounting, regulatory or reporting requirements. Our retention criteria include the nature and sensitivity of the data, the purpose of processing, our ongoing relationship with you, and applicable legal obligations.

Indicative retention periods:

Account and Customer Content — For the duration of the account/subscription, then deleted or returned within 60 days of termination, per our DPA.

Billing and financial records — 6 years.

Marketing/prospect data (where you are not a customer) — Until you unsubscribe.

Support correspondence — Retained as a record of the service interaction for as long as we need it for that purpose. Personal data contained in customer content attached to a ticket is deleted on request, in the same way as content held in the Services.

Website analytics / cookie data — For as long as necessary to understand and improve use of our Website and Services.

When we no longer need personal data, we securely delete, de-identify or anonymise it. We may retain aggregated or de-identified data, which cannot reasonably be used to identify you, indefinitely.

7. Sharing your personal data

We do not sell your personal data. We share personal data only as described below:

  • Service providers and sub-processors who process data on our behalf under contract, including cloud hosting providers, AI/model providers, analytics providers, payment processors and support tools. A current list is available at https://tracelight.ai/data-processing-agreement.
  • Your organisation. Where you access the Services through an employer or other organisation, we may share account and usage information with that organisation's administrators.
  • Professional advisers, such as auditors, lawyers, accountants and insurers.
  • Regulators, law enforcement and government authorities, where required by law or valid legal process, or to establish, exercise or defend legal claims.
  • Corporate transactions. A prospective or actual buyer, investor or successor entity in connection with a merger, acquisition, financing, reorganisation or sale of assets.

We require all service providers to protect personal data and to process it only on our instructions.

Our Website may link to, or integrate with, third-party services (such as LinkedIn or other social media). We do not share your personal data with those providers without a lawful basis, and their processing is governed by their own privacy policies.

8. International transfers

Where we host data. Refer to our Sub-Processor List for details at https://tracelight.ai/data-processing-agreement, our primary hosting is within the UK/EEA, and in the United States for customers of Tracelight AI, Inc. Certain sub-processors are based outside these regions.

We may transfer personal data outside the UK (and, where EU GDPR applies, outside the EEA) to our service providers and sub-processors. Where we do, we ensure an appropriate safeguard is in place, such as:

  • where the recipient is in a country the UK or EU has formally recognised as providing adequate protection;
  • where the recipient is a United States organisation certified under the EU-US Data Privacy Framework and its UK Extension; or
  • otherwise, the EU Standard Contractual Clauses together with the UK Addendum, or the UK International Data Transfer Agreement (IDTA).

Where we rely on the Data Privacy Framework, we also keep contractual safeguards in place so that transfers remain lawful if the framework's status changes.

You can request a copy of the relevant safeguards by contacting us at privacy@tracelight.ai.

9. Cookies and similar technologies

We use cookies and similar technologies (such as pixels, tags and local storage) on our Website. Under the Privacy and Electronic Communications Regulations (PECR) and UK GDPR, we set non-essential cookies only with your consent, which you provide through our cookie banner and can change at any time.

We use the following categories:

Strictly necessary cookies: required to operate the Website and Services (e.g. authentication, security). These do not require consent.

Functional cookies: remember your preferences and settings. Consent-based.

Analytics/performance cookies: help us understand how the Website and Services are used. Consent-based.

Marketing cookies: help us measure and coordinate our marketing. Consent-based.

For details of the specific cookies we use, their purpose and duration, see our Cookie Policy / cookie banner settings at https://tracelight.ai/#cookie-settings. You can also manage cookies through your browser settings; guidance is available from the ICO at ico.org.uk.

Do Not Track. There is no accepted industry standard for "Do Not Track" signals, so we do not currently respond to them.

10. Your rights

Under UK GDPR and the DPA 2018, you have the following rights in relation to your personal data:

  • Right to be informed: about how we use your personal data (this policy).
  • Right of access: to obtain a copy of the personal data we hold about you.
  • Right to rectification: to have inaccurate or incomplete data corrected.
  • Right to erasure ("right to be forgotten"): to have your personal data deleted in certain circumstances.
  • Right to restrict processing: to limit how we use your data in certain circumstances.
  • Right to data portability: to receive certain data in a structured, commonly used, machine-readable format, and to have it transmitted to another controller where technically feasible.
  • Right to object: to processing based on legitimate interests, and to direct marketing at any time.
  • Rights relating to automated decision-making and profiling: see Section 5.
  • Right to withdraw consent: where we rely on consent, at any time.

How to exercise your rights. Contact us at privacy@tracelight.ai with "Data Protection Request" in the subject line. We will respond within one month of receiving your request, as required by UK GDPR. We may extend this by up to two further months for complex or numerous requests, and will tell you if we do. We may need to verify your identity before responding. There is normally no fee, though we may charge a reasonable fee or refuse requests that are manifestly unfounded or excessive.

If your personal data appears in Customer Content, please direct your request to the relevant Customer (the controller); we will assist them as required.

Complaints. If you have a concern, we would like the chance to resolve it - please contact us first. You also have the right to lodge a complaint with the UK's supervisory authority:

Information Commissioner's Office (ICO)

Website: ico.org.uk

Helpline: 0303 123 1113

If you are in the EU/EEA, you may complain to the supervisory authority in your country of residence, place of work, or where the alleged infringement occurred.

11. Security

We use appropriate technical and organisational measures to protect personal data, including:

  • Encryption of data in transit (TLS) and at rest (AES-256);
  • Access controls, authentication (including SSO/SAML and MFA support) and the principle of least privilege;
  • Strict data boundaries and secure development practices;
  • Independent audits and certifications, including SOC 2 Type II;
  • Regular risk assessments, monitoring and vulnerability management.

For more detail, contact privacy@tracelight.ai.

No method of transmission over the internet or storage is completely secure. While we take reasonable steps to protect your data, we cannot guarantee absolute security. Sign-in is handled by your organisation's identity provider, so please keep those credentials confidential and do not share them.

Personal data breaches. Where we are a controller and a breach is likely to result in a risk to your rights and freedoms, we will notify the ICO within 72 hours of becoming aware of it, and will notify affected individuals where the breach is likely to result in a high risk to them. Where we act as a processor, we will notify the relevant Customer without undue delay in accordance with our DPA.

12. For US enterprise customers

Tracelight AI, Inc., a Delaware corporation, is the controller of account data for customers located in the United States. If you are located in the United States, this Privacy Policy applies to our handling of your personal data, and, where applicable, is supplemented by your rights under US state privacy laws (such as those in California, Colorado and other states). Depending on where you live, you may have rights to request access to, correction or deletion of your personal data, and to opt out of certain uses of your data, including "sale" or "sharing" of personal data or targeted advertising, as those terms are defined under applicable US law. We do not sell your personal data, and any "sharing" or use of personal data for advertising is limited and subject to your choices. To exercise US privacy rights or to ask questions, please contact us at privacy@tracelight.ai and include "US Privacy Request" in your subject line.

13. Changes to this Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology or legal requirements. We will post the updated policy on our Website with a new "Last updated" date. Where changes are material, we will endeavour to provide notice (for example, by email or an in-product notice) at least 30 days before they take effect.

14. Contact us

If you have any questions about this Privacy Policy or how we handle your personal data, please contact us:

Tracelight Ltd

Senna Building, Gorsuch Place, London, England, E2 8JF

Email: privacy@tracelight.ai (please include "Data Protection Request" in your subject line)

Privacy lead: Aleksander Misztal, Chief Technology Officer. Please use the address above for all data protection enquiries, so that requests are logged and answered within the statutory deadline.