NO APP· No new tech to learn· Works on mobile· WhatsApp · SMS · Voice call · 24/7

1. Who We Are

1.1 Family Ties AI Ltd ("Family Ties AI", "we", "us", "our") is a company registered in England and Wales (Company Number: 17225036. Our registered office is at:

10A VILLAGE WAY
PINNER
HA5 5AF

1.2 We provide an AI-powered care companion service ("Sophia") and a family monitoring interface ("Guardian"), delivered via WhatsApp and our associated platforms, designed to support elderly and vulnerable adults and their families.

1.3 We are the Data Controller in respect of the personal data we collect and process about you. This means we determine the purposes and means of processing your personal data.

1.4 Our Data Protection contact email is privacy@familytiesai.com

1.5 We are registered with the Information Commissioner's Office (ICO). Our ICO Registration Number is: ZC153407

2. About This Privacy Policy

2.1 This Privacy Policy explains:

  • What personal data we collect about you
  • Why we collect it and the legal basis for doing so
  • Who we share it with
  • How long we keep it
  • Your rights under UK GDPR and the Data Protection Act 2018
  • How to contact us or make a complaint

2.2 This Policy applies to:

  • Elderly users who interact with Sophia, our AI care companion
  • Family members and guardians who use the Guardian dashboard or monitoring features
  • Beta testers participating in our testing programme
  • Visitors to our website at familytiesai.com

2.3 Please read this Policy carefully. If you do not agree with it, please do not use our services.

2.4 This Policy should be read alongside our Terms and Conditions and, where applicable, our Beta Testing Agreement and Consent Form.

3. What Personal Data We Collect

3.1 We collect different categories of personal data depending on who you are and how you use our services.

3.1.1 Elderly Users (Sophia Users)

3.1.2 Family Members and Guardians

3.1.3 All Users

3.2 Special Category Data — Important Notice

We process special category data within the meaning of Article 9 UK GDPR, specifically health-related data and data concerning the physical or mental wellbeing of elderly users. We do this only:

  • With your explicit consent (Article 9(2)(a) UK GDPR); and/or
  • Where necessary for reasons of substantial public interest (Article 9(2)(g) UK GDPR, Schedule 1 Data Protection Act 2018)

We will never process special category data without a clear, documented lawful basis.

4. How We Collect Your Personal Data

4.1 We collect personal data through the following means:

(a) Directly from you:

  • When you or a family member registers for our service
  • When you interact with Sophia via WhatsApp
  • When you complete consent forms or beta testing agreements
  • When you contact us by email or phone

(b) Through our AI system:

  • Sophia's conversations with elderly users are processed to deliver the service and may contain personal and special category data

(c) From family members or authorised representatives:

  • Where a family member or guardian registers an elderly user and provides their details

(d) Automatically:

  • Via our website and platform through cookies and similar technologies (see Section 12)

4.2 We do not collect personal data from third-party data brokers or public sources.

5. Why We Use Your Personal Data — Lawful Basis

We are required by UK GDPR to have a lawful basis for every processing activity. Our bases are set out in full below.

Legitimate Interests Note: Where we rely on legitimate interests, we have conducted a Legitimate Interests Assessment (LIA). Our interests are to improve the safety and quality of our AI service for vulnerable users. We are satisfied that our interests are not overridden by your rights, given the safeguards we apply (anonymisation, access controls, and data minimisation). You have the right to object to this processing — see Section 10.

6. Mental Capacity and Consent

6.1 We recognise that some of our elderly users may have fluctuating or limited mental capacity. We take our obligations under the Mental Capacity Act 2005 seriously.

6.2 Where there is any doubt as to whether an elderly user has capacity to consent to our service, we will:

  • Require a family member, guardian, or authorised representative to provide consent on their behalf
  • Document the basis for any best-interests decision
  • Review consent arrangements regularly

6.3 Consent given on behalf of a user without capacity must be given by a person who is:

  • A registered Lasting Power of Attorney (Health and Welfare); or
  • A Court-appointed deputy; or
  • A person otherwise lawfully authorised under the Mental Capacity Act 2005

6.4 We will never rely solely on assumed or implied consent for special category data processing where capacity is in doubt.

7. Who We Share Your Data With

7.1 We do not sell your personal data. We do not share it for marketing purposes.

7.2 We share personal data only with trusted third-party processors who process data strictly on our behalf and under our documented instructions. Our current processor list is as follows:

7.3 All processors are bound by written Data Processing Agreements (DPAs) that require them to:

  • Process data only on our documented instructions
  • Implement appropriate technical and organisational security measures
  • Not sub-process without our authorisation
  • Assist us in responding to data subject rights requests
  • Return or delete data on termination

7.4 We may also disclose personal data:

  • To comply with a legal obligation or court order
  • To protect the vital interests of an elderly user or another person
  • To our professional advisers (solicitors, accountants) under strict confidentiality obligations
  • In the event of a business sale or merger, to the extent permitted by law

7.5 We will notify you of any material changes to our processor list.

8. International Data Transfers

8.1 Some of our processors are based outside the United Kingdom. Where we transfer personal data outside the UK, we ensure appropriate safeguards are in place in accordance with Chapter V UK GDPR.

8.2 Our transfer mechanisms include:

  • UK-US Data Bridge (for transfers to Data Privacy Framework-certified US processors)
  • UK International Data Transfer Agreement (UK IDTA)
  • UK Addendum to EU Standard Contractual Clauses

8.3 You may request a copy of the relevant transfer safeguards by contacting us at privacy@familytiesai.com

9. How Long We Keep Your Data

9.1 We keep personal data only for as long as necessary for the purposes set out in this Policy, or as required by law.

9.2 Where we are required by law to retain data longer, we will do so but will restrict access to it.

9.3 When data is no longer required, it is securely deleted or anonymised in accordance with our Data Retention Policy.

10. Your Rights Under UK GDPR

10.1 You have the following rights in respect of your personal data:

10.2 To exercise any of these rights, please contact us at: privacy@familytiesai.com

FAMILY TIES AI LTD
10A VILLAGE WAY
PINNER
HA5 5AF

We will respond within one calendar month of receipt of your request. We will not charge a fee unless a request is manifestly unfounded or excessive.

10.3 We may need to verify your identity before processing your request.

10.4 Withdrawal of Consent: If you withdraw consent, we will stop processing your data as soon as reasonably practicable. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

11. Automated Decision-Making and AI

11.1 Our service uses artificial intelligence to power Sophia, our AI care companion. Sophia generates personalised responses and identifies patterns in user wellbeing and behaviour in order to deliver the service.

11.2 Users are clearly and fully informed that Sophia is an AI companion — not a human — during the sign-up and onboarding process. Our consent and onboarding documentation sets out in plain English what Sophia is, how it works, and what data it processes.

11.3 We do not make solely automated decisions about users that produce legal or similarly significant effects without human review.

11.4 Where Sophia identifies a potential concern — such as a change in mood, repeated distress signals, or a safeguarding indicator — a human member of our team reviews the alert before any action is taken.

11.5 You have the right to request human review of any AI-generated assessment that affects you. Contact us at privacy@familytiesai.com

12. Cookies

12.1 Our website uses cookies and similar tracking technologies. A full breakdown of the cookies we use is available in our Cookie Policy

12.2 You can manage your cookie preferences at any time via our cookie banner or browser settings.

13. Data Security

13.1 We take the security of your personal data seriously. We implement appropriate technical and organisational measures including:

  • Encryption of data in transit and at rest
  • Multi-factor authentication for all system access
  • Role-based access controls (least privilege principle)
  • Regular security testing and vulnerability assessments
  • Staff training on data protection obligations
  • Incident response procedures

13.2 In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the ICO within 72 hours and notify you without undue delay, in accordance with Articles 33 and 34 UK GDPR.

13.3 No method of transmission over the internet is 100% secure. Whilst we take all reasonable steps, we cannot guarantee absolute security.

14. Children

14.1 Our service is not intended for persons under the age of 18. We do not knowingly collect personal data from children.

14.2 If you believe we have inadvertently collected data from a child, please contact us immediately at privacy@familytiesai.com and we will delete it without undue delay.

15. Changes to This Policy

15.1 We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal obligations.

15.2 Where changes are material, we will notify you by email or via a prominent notice on our platform at least 14 days before the changes take effect.

15.3 The current version of this Policy is always available at Privacy Policy. The version number and last updated date at the top of this document confirm which version you are reading.

16. Complaints

16.1 We take privacy concerns seriously. If you have a complaint about how we handle your personal data, please contact us first at:

📧 privacy@familytiesai.com
📮 FAMILY TIES AI LTD
10A VILLAGE WAY
PINNER
HA5 5AF

We will acknowledge your complaint within 5 working days and aim to resolve it within 28 days.

16.2 If you are not satisfied with our response, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):

🌐 www.ico.org.uk
📞 0303 123 1113
📮 Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF

17. Contact Us

For any questions about this Privacy Policy or how we handle your personal data:

Family Ties AI Ltd
📧 privacy@familytiesai.com
📮 FAMILY TIES AI LTD
10A VILLAGE WAY
PINNER
HA5 5AF
🌐 familytiesai.com

*This Privacy Policy was drafted for Family Ties AI Ltd and reflects