Legal & Compliance
Privacy & Data Policy
Last updated: 29 April 2026 • Effective date: 29 April 2026
Contents
- Who We Are
- What Data We Collect and Why
- Legal Basis for Processing
- How We Use Your Data
- How Long We Keep Your Data
- Who We Share Your Data With
- International Data Transfers
- Your Rights
- Jurisdiction-Specific Rights
- Cookies and Tracking
- Security
- Children's Privacy
- Changes to This Policy
- Contact and Complaints
1. Who We Are
The data controller for all personal data collected through this website and its affiliated services is:
Adrian Dunkley
Trading as StarApple AI and Maestro AI Labs
Kingston, Jamaica
Email: ai@maestrosai.com
"We", "us", and "our" throughout this policy refer to Adrian Dunkley and the above affiliated entities. "You" refers to any individual whose personal data we process.
2. What Data We Collect and Why
AI Boss Test Registration (AI Boss Group)
When you begin the AI Boss Test, we collect:
- First name — to personalise communications
- Email address — to add you to the AI Boss Group, a community of AI-engaged professionals
We do not collect your score, answers, or any assessment data at the individual level.
Contact Form
When you submit the contact form on this site, we collect:
- Name, email address, and message — to respond to your enquiry
Newsletter Sign-Up
Where newsletter sign-up forms appear, we collect:
- Email address — to send you updates about AI, StarApple AI programmes, and the Caribbean AI ecosystem
Usage Data (Automatically Collected)
Our hosting provider (Netlify) may automatically collect standard server logs including:
- IP address (anonymised or truncated)
- Browser type and version
- Pages visited and time of visit
- Referring URL
This data is used solely for security, performance monitoring, and aggregate analytics. It is not linked to any identifiable individual.
3. Legal Basis for Processing
We process your personal data on the following lawful bases under the UK GDPR, EU GDPR, and Jamaica Data Protection Act 2020:
- Consent (Article 6(1)(a) GDPR) — For AI Boss Group registration and newsletter subscriptions. You provide consent by submitting the form and may withdraw it at any time.
- Legitimate interests (Article 6(1)(f) GDPR) — For contact form responses, where processing is necessary to reply to your direct enquiry and our interest does not override your rights.
- Contract performance (Article 6(1)(b) GDPR) — Where processing is necessary to deliver a service you have requested (e.g., delivering assessment results).
4. How We Use Your Data
- To add you to the AI Boss Group mailing list and send relevant AI leadership content
- To respond to contact form enquiries
- To send newsletters where you have subscribed
- To understand aggregate usage patterns and improve this website
- To comply with legal obligations
We do not use your data for automated decision-making or profiling that produces legal or similarly significant effects.
We do not sell your personal data to third parties.
5. How Long We Keep Your Data
- AI Boss Group / newsletter lists — retained until you unsubscribe or request deletion
- Contact form submissions — retained for up to 24 months, or until the matter is resolved
- Server logs — retained by Netlify per their own retention schedule (typically 30 days)
When data is no longer needed, it is securely deleted or anonymised.
6. Who We Share Your Data With
We do not sell, rent, or trade your personal data. We may share data with the following service providers, who act as data processors under a contractual obligation to protect it:
- Netlify, Inc. — our website hosting and form collection provider. Form submissions are stored in Netlify's secure dashboard. Netlify is certified under applicable data transfer frameworks. See Netlify's Privacy Policy.
- Typeform S.L. — used for training programme enrolment forms linked from this site. See Typeform's GDPR page.
- Google Fonts — fonts are loaded from Google's CDN; Google may collect IP address data per their Privacy Policy.
We may disclose personal data where required by law, court order, or regulatory authority.
7. International Data Transfers
This website is operated from Jamaica and uses service providers based in the United States (Netlify) and the European Union (Typeform). Your data may therefore be transferred to, stored in, and processed in countries outside your own.
Where data is transferred from the UK or EEA, we rely on:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- The UK International Data Transfer Agreement (IDTA) where applicable
- Adequacy decisions where available
We take all reasonable steps to ensure your data receives the same level of protection wherever it is processed.
8. Your Rights
Under applicable data protection law, you have the following rights:
- Right to access — request a copy of the personal data we hold about you
- Right to rectification — request correction of inaccurate or incomplete data
- Right to erasure — request deletion of your data ("right to be forgotten")
- Right to restriction — request that we limit how we process your data
- Right to data portability — receive your data in a structured, machine-readable format
- Right to object — object to processing based on legitimate interests or for direct marketing
- Right to withdraw consent — where processing is based on consent, withdraw it at any time without affecting the lawfulness of prior processing
- Right not to be subject to automated decisions — we do not carry out solely automated decision-making with legal or significant effects
To exercise any of these rights, contact us at ai@maestrosai.com. We will respond within 30 days (or within the timeframe required by applicable law). We may need to verify your identity before fulfilling a request.
9. Jurisdiction-Specific Rights
European Union — GDPR (Regulation 2016/679)
EU residents have the full suite of rights set out in Section 8. You may also lodge a complaint with the data protection supervisory authority in your EU member state.
United Kingdom — UK GDPR & Data Protection Act 2018
UK residents have equivalent rights under UK GDPR. You may lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.
Jamaica — Data Protection Act 2020
Jamaican residents have rights under the Data Protection Act 2020, including the right to access, correct, and object to processing of personal data. You may lodge a complaint with the Office of the Information Commissioner of Jamaica.
California, United States — CCPA / CPRA
California residents have the right to know what personal information we collect, the right to delete it, and the right to opt out of sale (we do not sell personal data). To exercise these rights, contact ai@maestrosai.com. We do not discriminate against users who exercise their CCPA rights.
Canada — PIPEDA
Canadian residents have rights under the Personal Information Protection and Electronic Documents Act (PIPEDA), including the right to access and correct personal information. Contact us at ai@maestrosai.com to exercise these rights. You may also contact the Office of the Privacy Commissioner of Canada.
Australia — Privacy Act 1988
Australian residents have rights under the Privacy Act 1988, including the right to access, correct, and complain about handling of personal information. You may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
Other Jurisdictions
We respect applicable data protection laws in all jurisdictions where our users reside. If you have questions about your rights in a jurisdiction not listed above, please contact us at ai@maestrosai.com.
10. Cookies and Tracking
This website uses no first-party analytics cookies and no advertising or retargeting cookies.
Third-party services that may set cookies or make network requests include:
- Google Fonts — font delivery; may log your IP address
- Netlify — hosting and form processing; may set functional session cookies
We do not use Google Analytics, Facebook Pixel, or any third-party behavioural tracking tools.
If you wish to control or block cookies, you can do so through your browser settings. Disabling cookies will not affect your ability to use this website.
11. Security
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, accidental loss, destruction, or alteration. These include:
- HTTPS encryption for all data transmitted to and from this website
- Form submissions processed via Netlify's secure infrastructure
- Access to submitted data restricted to authorised personnel only
No method of transmission over the internet is 100% secure. While we strive to protect your data, we cannot guarantee absolute security. In the event of a data breach that poses a risk to your rights and freedoms, we will notify relevant supervisory authorities and affected individuals as required by law.
12. Children's Privacy
This website and the AI Boss Test are intended for individuals aged 16 and over. We do not knowingly collect personal data from children under 16 (or the applicable age of digital consent in your jurisdiction). If you believe we have inadvertently collected data from a child, please contact us immediately at ai@maestrosai.com and we will delete it promptly.
13. Changes to This Policy
We may update this policy from time to time to reflect changes in our practices, services, or legal obligations. When we make material changes, we will update the "Last updated" date at the top of this page. We encourage you to review this policy periodically.
Continued use of this website after a policy update constitutes acceptance of the revised policy.
14. Contact and Complaints
For any questions, requests, or concerns about this policy or how your data is handled, contact us at:
Adrian Dunkley
StarApple AI / Maestro AI Labs
Kingston, Jamaica
ai@maestrosai.com
We aim to respond to all data-related requests within 30 days. If you are not satisfied with our response, you have the right to lodge a complaint with the relevant data protection authority in your country of residence (see Section 9).