Book a demo

Legal

Privacy policy

This policy explains how we use personal information in connection with our public website and business enquiries. Last updated 17 September 2026.

1. Who we are

Kestrel Applied Intelligence Ltd (company number SC901708), trading as Kestrel Automotive Intelligence (referred to as “Kestrel”, “we”, “us” or “our”), is a private limited company registered in Scotland with its registered office at 242 Seatown, Cullen, Buckie, Scotland, AB56 4SN, and is the controller of the personal information described in this policy. This means we decide why and how that information is used.

For privacy questions, rights requests or complaints, email hello@kestrel-automotive.com. Please use the subject “Privacy” where possible.

2. Scope of this policy

This policy applies when you visit kestrel-automotive.com, submit its demo or contact form, email us, or otherwise communicate with us about Kestrel in a business capacity.

It does not serve as the privacy notice for a dealership’s customers using a Kestrel-powered website or telephone service. In that setting, the dealership will ordinarily be the controller and Kestrel will ordinarily process personal information on the dealership’s documented instructions. Section 12 explains this distinction.

3. Personal information we collect

Information you provide. When you submit the contact form or correspond with us, we may collect your name, work email address, dealership or group, the systems you use, the subject of your enquiry, your message, and any information in later correspondence or meeting notes. Name and email are required on the form so that we can identify and reply to you; the other fields are optional.

Technical information. When your browser requests a page or you submit the form, our hosting systems automatically receive information such as your IP address, date and time of the request, requested page, browser and device type, referring page and request headers. We use hidden form fields to identify likely automated submissions. If one is completed, a shortened version of its contents and your browser’s user-agent may appear in our security logs.

Bot-protection challenge. The contact form is protected by Cloudflare Turnstile, a security check that distinguishes a person from an automated script. When the form loads, your browser contacts Cloudflare, which assesses technical signals such as your IP address, user-agent, and browser and device characteristics, and may store a token or similar identifier in your browser for the purpose of that check. Depending on that assessment, the check may complete on its own or ask you to confirm that you are not a robot. We receive only the pass-or-fail result and the website address the check was served on, not the underlying signals. If the check does not complete, your enquiry still reaches us; it is simply marked for review. We also record whether a submission looked automated, together with the reasons, so that we can tune the check without discarding genuine enquiries.

Information from other business contacts. A colleague, employer, dealership or commercial partner may give us your business contact details or copy you into correspondence. We record the source where it is not apparent from the communication.

Please do not put financial account details, health information, criminal-offence information or other sensitive personal information in the website form. If you provide information about another person, you must be entitled to do so and should direct them to this policy.

4. Why we use it and our lawful bases

To respond to enquiries and arrange demonstrations. We use form entries and correspondence to understand and answer your request, assess compatibility, arrange a demonstration and prepare a proposal. Where you are considering contracting with us personally, this is necessary to take steps at your request before entering a contract. In other cases, we rely on our legitimate interests in developing our business and responding to people who contact us.

To manage business relationships. We use contact and correspondence records to follow up an active enquiry, manage a customer, supplier or partner relationship and provide support. We rely on performance of a contract where you are personally a party to it, and otherwise on our legitimate interests in administering our business and serving the organisation you represent.

To operate and secure the website. We use technical information to deliver pages and the form, diagnose faults, prevent spam and abuse, investigate security events and maintain service integrity. This includes running the bot-protection challenge described in section 3 and scoring submissions for signs of automated or bulk unsolicited contact, so that genuine enquiries reach us and are not buried. We rely on our legitimate interests in operating a reliable service, keeping our enquiry channel usable, and ensuring the security of our network and information systems.

To comply with law and protect legal rights. We may use and preserve relevant information for accounting and tax obligations, to respond to lawful requests, and to establish, exercise or defend legal claims. We rely on compliance with legal obligations and, where applicable, our legitimate interests in protecting our business and legal rights.

We have considered the necessity and impact of the processing for which we rely on legitimate interests. You may ask for further information about that assessment and may object as explained in section 10.

5. Direct marketing

Submitting an enquiry does not add you to a newsletter or general marketing list, and we do not currently operate one through this site. We may follow up the specific request or commercial discussion you initiated. If we introduce optional marketing, we will provide the required choice at collection, comply with UK electronic-marketing rules and honour objections or opt-outs at any time.

6. Who receives personal information

We disclose personal information only where reasonably necessary for the purposes above:

We do not sell personal information and do not disclose enquiry details to unrelated organisations for their own marketing.

7. International transfers

Although Kestrel is based in the UK, some website, security and email suppliers — including Cloudflare and Resend — are established in the United States and operate global infrastructure. As a result, website requests, technical information and enquiry content may be accessed or processed outside the UK.

Where UK personal information is transferred to a separate organisation outside the UK, we require an authorised transfer mechanism. Depending on the recipient and transfer, this may be UK adequacy regulations (including the UK Extension to the EU–US Data Privacy Framework for an actively certified US recipient) or contractual safeguards such as the UK International Data Transfer Addendum, together with the required data-protection assessment. You may contact us for further information or a copy of the relevant safeguards, subject to necessary redactions.

8. How long we keep it

We apply the following retention periods unless a longer period is required by law, a dispute or investigation, or a shorter period is appropriate:

At the end of the applicable period, we delete or irreversibly anonymise the information. Residual copies may remain in access-controlled backups until they are overwritten in the ordinary backup cycle.

9. Cookies, local storage and analytics

The website does not run analytics, advertising pixels or behavioural-tracking scripts, and does not use cookies or browser storage to recognise you across visits or build a profile of you.

It does use one strictly necessary security technology. The Cloudflare Turnstile challenge that protects the contact form, described in section 3, may set a cookie or store a token in your browser for as long as the check requires. This is used solely to tell a person from an automated script and to protect the form from abuse; it is not used for analytics, advertising or tracking. Because it is strictly necessary to provide a service you have asked for, it does not require consent under UK electronic-privacy rules, so the site does not display a cookie consent banner. If you would rather not load it, you can email us directly at hello@kestrel-automotive.com instead of using the form.

The site does load Montserrat and Geist font files from Google Fonts. This causes your browser to make requests to Google’s servers and disclose technical request information, including your IP address and browser user-agent. Google states that the Google Fonts API does not send cookies and is designed to limit collection to what is needed to serve fonts. We use these fonts on the basis of our legitimate interest in presenting a consistent, readable website. You can block remote fonts through your browser or privacy tools; the site will fall back to a system font.

We will update this policy and, where legally required, obtain consent before introducing non-essential cookies or similar technologies.

10. Your data-protection rights

Depending on the circumstances, you may have the right to:

This website does not make decisions about you based solely on automated processing that produce legal or similarly significant effects.

To exercise a right, email hello@kestrel-automotive.com. There is normally no fee. We may ask for proportionate information to confirm your identity and clarify the scope of your request. We normally respond within one calendar month, subject to any extension permitted by law.

11. Security

We use measures appropriate to the nature of the information and the risks involved. The public site is served over HTTPS and uses security headers designed to restrict unauthorised scripts, framing, device permissions and insecure transport. Access to enquiry information is limited to people and providers who need it. No internet service can be guaranteed completely secure, and you should not send confidential or sensitive information through the public form.

12. Kestrel services supplied to dealerships

A Kestrel deployment may handle customer voice or chat conversations, contact and vehicle information, call recordings, transcripts, booking details, buying intent and reporting data on behalf of a dealership. The precise data, purposes, integrations and retention rules depend on that dealership’s configured service.

For that processing, the dealership will ordinarily decide the purpose and essential means and act as controller; Kestrel will ordinarily act as its processor under a written data-processing agreement. The dealership must provide its customers with the applicable privacy information and is normally the first contact for a customer-rights request. Kestrel assists the dealership in meeting its legal obligations. Kestrel may separately act as controller for limited account, billing, security and legal-compliance information, in which case it will provide the relevant privacy information.

Kestrel does not use dealership customer conversations to train a shared model for other dealerships. The service supports conversations and operational workflows; it is not intended to make solely automated lending, credit or other decisions producing legal or similarly significant effects.

13. Children

This business website is directed at adults acting in a professional capacity and is not intended for children. If we learn that a child has submitted personal information through the form, we will delete it unless we have a lawful reason to retain it.

14. Complaints

You can make a data-protection complaint by emailing hello@kestrel-automotive.com with the subject “Data protection complaint”. Please explain what happened and the outcome you are seeking. We will acknowledge the complaint within 30 days, investigate it appropriately and communicate the outcome without unjustifiable or excessive delay.

You also have the right to complain to the Information Commissioner’s Office (ICO), the UK supervisory authority. The ICO can be contacted at Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF or on 0303 123 1113. We would welcome the opportunity to address your concern first, but you do not have to contact us before approaching the ICO.

15. Changes to this policy

We review this policy when our services, suppliers or legal obligations change. We will post the revised version here and change the date at the top. If a change materially affects how we use information already collected, we will take reasonable steps to bring it to the attention of the people affected before the new use begins.