Privacy Policy
This Privacy Policy explains how NeverOff (“we”, “us”, “our”) collects, uses and protects personal data when you visit neveroff.co.uk, contact us, or use our services. We are committed to handling your data in line with the UK GDPR and the Data Protection Act 2018.
1. Who we are
NeverOff is a service that sets up and manages a private AI workforce for small businesses. It is operated by NXT LVL Tech Ltd, a company registered in England and Wales (Company No. 15723268). NeverOff is a trading name of NXT LVL Tech Ltd. For the purposes of data protection law, the data controller is NXT LVL Tech Ltd, of 64 Barker Road, Middlesbrough, TS5 5ES.
If you have any questions about this policy or how we handle your data, contact us at hello@neveroff.co.uk.
2. Information we collect
Information you give us
- Enquiry details — when you complete our contact form or email us, we collect your name, email address and the contents of your message.
- Onboarding information — if you become a client, information needed to set up and run your service, which may include business details, billing information, and access you choose to delegate to us.
Information we process on your behalf
As part of delivering the service, your workforce accesses the accounts and tools you authorise (for example email, social media and documents) through secure APIs. Your data stays in your own connected accounts — we do not collect it into, or store it on, our own systems. It runs on a dedicated, isolated environment provisioned solely for your business and is processed only transiently to carry out your instructions, which includes sending relevant content to the AI providers listed below to generate outputs. Where this involves personal data, you are the controller and we act as your processor under a separate data processing agreement (available on request).
Information we collect automatically
- Technical data — our hosting provider may log limited technical information such as IP address, browser type and pages requested, for security and to keep the site running.
3. How and why we use it
We use personal data to:
- respond to your enquiry and arrange a demo — on the basis of taking steps at your request before entering a contract, and our legitimate interest in responding to enquiries;
- provide, manage and improve our services — on the basis of performing our contract with you;
- invoice you and keep proper business records — on the basis of performing our contract and our legal obligations;
- keep our site and systems secure and meet our legal obligations — on the basis of our legitimate interests and legal obligations.
4. Controller and processor roles
When you enquire or we market to you, we are the controller of your data. When we operate your AI workforce on data inside your accounts, you are the controller and we are your processor, acting only on your documented instructions under a data processing agreement. That agreement sets out the subject matter and duration of processing, the types of data involved, and both parties’ obligations, in line with Article 28 UK GDPR.
5. AI transparency
Outputs produced by your workforce are generated by artificial intelligence systems operated by the providers listed in section 6. AI-generated outputs may contain errors, which is why the service includes human oversight by us and approval steps for you on anything important. Content sent to AI providers to generate outputs is processed under our agreements with those providers; your data is not used by us to train AI models, and we configure provider settings so that your data is not used to train their models either, wherever the provider makes that option available.
6. Sharing and sub-processors
We do not sell your data. We share it only with trusted providers who help us run the service, including:
- hosting and infrastructure providers (including IONOS, our website and email host);
- AI model providers used to power your agents, which may include OpenAI, Anthropic and Google (Gemini);
- professional advisers, or authorities where required by law.
These providers act under contract and may only use the data to provide services to us. We will inform clients in advance of any material change to the sub-processors used to deliver their service, and you may object on reasonable grounds relating to data protection, as set out in your data processing agreement.
7. How we protect your data
Your workforce runs in a dedicated, isolated environment per client — no infrastructure or data is shared between clients. Access is encrypted in transit, protected behind a firewall, and monitored around the clock. Access to your accounts is delegated and limited: your own account passwords remain with you, and any access you grant can be revoked by you at any time. We do not store your business data on our systems, and your data is not used to train third-party models on your behalf.
In the unlikely event of a personal data breach affecting your data, we will notify you without undue delay and, where required, report it to the ICO within 72 hours of becoming aware of it.
8. How long we keep it
We keep enquiry data (such as contact-form messages) only as long as needed to deal with your enquiry and for a reasonable period afterwards. Billing and accounting records are kept for as long as UK law requires (normally six years).
We do not store your business data ourselves — it stays in your own connected accounts, so there is nothing for us to retain or hand back when the service ends, beyond removing our access. Any transient processing data in your dedicated environment is deleted when the service ends, in line with your service agreement.
9. International transfers
Some of our providers — including AI providers such as OpenAI, Anthropic and Google — are based outside the UK and may process data internationally. Where that happens, we rely on appropriate safeguards such as UK adequacy regulations, the International Data Transfer Agreement (IDTA) or Standard Contractual Clauses with the UK Addendum. If you would like details of the safeguards for a specific provider, contact us at hello@neveroff.co.uk.
10. Your rights
Under UK data protection law you have the right to access, correct, delete or restrict your personal data, to object to certain processing, and to data portability. To exercise any of these, email hello@neveroff.co.uk. We will respond within one month.
Where we act as your processor, requests from individuals whose data sits in your accounts should be directed to you as controller — we will assist you in meeting them, as set out in the data processing agreement.
You also have the right to complain to the Information Commissioner’s Office (ICO) at ico.org.uk or on 0303 123 1113. We’d appreciate the chance to resolve your concern first.
11. Cookies
This site uses only what is needed to display the page. We self-host our fonts and do not load third-party advertising or tracking cookies.
12. Changes to this policy
We may update this policy from time to time. The “last updated” date at the top shows when it last changed. If we make material changes that affect existing clients, we will let you know directly.
13. How to contact us
NeverOff — a trading name of NXT LVL Tech Ltd (Company No. 15723268)
Email: hello@neveroff.co.uk
Registered in England and Wales · 64 Barker Road, Middlesbrough, TS5 5ES