Privacy Policy
This Privacy Policy explains how Bhatt Group Ltd collects, uses, stores, shares, and protects personal data when individuals access https://review.ministerai.app, create or use an account, use ReviewMinister, submit information through a public review or feedback page, purchase a subscription or product, contact us, or otherwise interact with our services.
In this Policy, “we”, “us”, “our”, and “Company” refer to Bhatt Group Ltd. “Platform” refers to ReviewMinister, including its dashboards, public review pages, review links, QR and NFC journeys, AI features, integrations, and associated services.
Please read this Policy carefully. It explains what personal data we process, why we process it, the lawful bases on which we rely, who receives the data, how long it may be retained, and the rights available to individuals.
1. Who We Are
For personal data processed for our own business purposes, the data controller is:
65A High Street, Littlehampton West Sussex BN17 5EJ, UK
Website: https://review.ministerai.app
Privacy email:
General support: support@review.ministerai.app
Company number: 15376015
ICO registration number:
Our data-protection contact is: .
If we appoint a formal Data Protection Officer, their contact details will be published here: .
2. When We Act as Controller or Processor
2.1 When We Act as Controller
We generally act as a controller when we determine why and how personal data is used, including when we process:
- account registration and profile information;
- billing, subscription, order, and payment records;
- website activity and cookie preferences;
- sales, support, and business communications;
- fraud, security, and abuse-prevention information;
- legal-document acceptance records;
- our own analytics, service improvement, and compliance records;
- direct marketing preferences.
2.2 When We Act as Processor
A business customer may use the Platform to collect or manage information relating to its own customers, visitors, reviewers, or other individuals. Where the business customer determines the purpose and essential means of that processing, the business customer is the controller and we ordinarily act as its processor.
This may include:
- review-link visits associated with that business;
- star ratings and experience selections;
- optional private feedback;
- AI review-generation prompts based on customer selections;
- copied-review and redirection events;
- business-specific review analytics;
- customer data uploaded or entered by the business.
In those circumstances, requests concerning the business customer’s use of the data should normally be directed to that business first. We will assist the business customer in responding where required by our data-processing agreement and applicable law.
2.3 Independent Controllers
Some service providers, including payment providers, banks, fraud-prevention services, and third-party review platforms, may process personal data as independent controllers for their own purposes. Their own privacy policies will apply to that processing.
3. Who This Policy Applies To
This Policy applies to personal data relating to:
- website visitors;
- registered and prospective Platform users;
- business owners, employees, representatives, and administrators;
- customers placing orders for subscriptions or physical products;
- people visiting a public review or feedback link;
- people scanning a QR code or tapping an NFC product;
- people providing ratings, selections, or optional feedback;
- support contacts, suppliers, and business partners;
- job applicants where recruitment functionality is used;
- other individuals who communicate with us.
4. Personal Data We Collect
4.1 Account and Identity Data
We may collect:
- full name;
- email address;
- telephone number;
- username or account identifier;
- profile image;
- authentication-provider identifier;
- password-related authentication records, where applicable;
- account role, permissions, and status;
- language, locale, and communication preferences.
Passwords are not intended to be stored by us in readable form. Where password authentication is supported, authentication credentials are handled using appropriate secured authentication systems.
4.2 Business and Organisation Data
We may collect:
- business or organisation name;
- business category and description;
- registered or trading address;
- business telephone number and email address;
- business logo and branding;
- website and social-profile URLs;
- Google or other third-party business-review links;
- business location, city, region, and country;
- team members, roles, and access permissions;
- subscription and plan information;
- configuration and feature preferences.
4.3 Review-Journey and Feedback Data
When someone uses a public review or feedback page, we may process:
- the business or review link visited;
- the source of the visit, such as QR, NFC, or direct link;
- star rating selected;
- experience tags, chips, or attributes selected;
- optional feedback or comments;
- language and localisation choices;
- AI-generated review suggestions;
- regeneration or retry events;
- whether suggested content was copied;
- whether the visitor proceeded to a third-party review platform;
- dates, times, session identifiers, and technical events.
Unless a particular review journey expressly requests identifying information, public reviewers should not be required to provide their name, email address, telephone number, or other direct identity information merely to generate a review suggestion.
Do not submit unnecessary sensitive information. Public review and feedback fields should not be used to provide health information, financial information, passwords, government identifiers, criminal allegations, or other highly sensitive information.
4.4 Order, Subscription, and Transaction Data
We may collect:
- Order number and transaction identifier;
- subscription plan and billing period;
- products and quantities ordered;
- billing and delivery names and addresses;
- payment status and payment-provider references;
- currency, amount, taxes, discounts, and refunds;
- renewal, cancellation, suspension, and expiry dates;
- shipment, carrier, and tracking information;
- invoice and receipt information;
- chargeback and dispute records.
Complete payment-card details are generally collected and processed directly by our payment provider rather than stored by us. We may receive limited payment information, such as card brand, last four digits, expiry details, billing country, payment status, and transaction references.
4.5 Legal Acceptance and Consent Records
We may retain records showing:
- which legal document or policy was accepted;
- the accepted document version;
- the acceptance wording shown;
- the date and time of acceptance;
- the associated user and Order identifiers;
- checkout or payment-session identifiers;
- IP address or IP hash;
- browser, device, and user-agent information;
- cookie and marketing-consent choices;
- withdrawal or modification of consent.
4.6 Technical, Device, and Usage Data
We may collect:
- IP address or a cryptographic hash derived from it;
- browser type and version;
- device type and operating system;
- screen or viewport information;
- language and time-zone settings;
- session and authentication events;
- pages, routes, and features accessed;
- click, copy, scan, visit, and navigation events;
- error, crash, and performance logs;
- referrer and campaign information;
- approximate location derived from IP address;
- security, fraud, and abuse indicators.
4.7 Communications and Support Data
We may collect:
- emails and support messages;
- chat or contact-form submissions;
- complaints and refund requests;
- attachments, screenshots, and diagnostic information;
- call or meeting notes;
- survey and feedback responses;
- marketing preferences and communication history.
4.8 Security and Abuse-Prevention Data
We may process:
- failed login attempts;
- suspicious request patterns;
- rate-limit events;
- bot-protection and CAPTCHA results;
- invalid or blocked user-agent information;
- honeypot-form events;
- provider quota and usage events;
- fraud and chargeback indicators;
- account suspension and investigation records;
- IP hashes and related security identifiers.
4.9 Data From Connected Services
Where you choose to connect or authenticate through a third-party service, we may receive information authorised by you and made available by that service, such as:
- name and email address;
- profile image;
- authentication identifier;
- business-profile or location information;
- authorised integration data;
- access and refresh tokens, where technically necessary.
The exact information depends on the service, permissions selected, and integration configuration.
5. How We Collect Personal Data
We collect personal data:
- directly from you when you create an account or place an Order;
- when you configure a business profile or review journey;
- when you submit a rating, feedback, or AI-generation request;
- automatically when you use the Website or Platform;
- through cookies and similar technologies;
- from authentication, payment, delivery, and integration providers;
- from a business customer that has authorised your access;
- from public business sources where lawful;
- from fraud-prevention, security, and compliance services;
- from communications you send to us.
6. Purposes and Lawful Bases
We process personal data only where we have an appropriate lawful basis. The basis depends on the data, purpose, relationship, and circumstances.
| Purpose | Typical Data | Typical Lawful Basis |
|---|---|---|
| Create and administer accounts | Identity, contact, authentication, role, and profile data | Performance of a contract; legitimate interests in administering users and organisations |
| Provide the Platform and its features | Account, business, configuration, review-journey, and usage data | Performance of a contract; legitimate interests; processing under customer instructions where we act as processor |
| Generate AI-assisted review suggestions | Ratings, selected experience tags, optional feedback, language, business context, and technical request data | Performance of a contract; legitimate interests; customer instructions where we act as processor |
| Process purchases and subscriptions | Contact, Order, billing, payment-reference, tax, and transaction data | Performance of a contract; legal obligations; legitimate interests in payment administration and fraud prevention |
| Deliver NFC, QR, and printed products | Customer, business, personalisation, delivery, and tracking data | Performance of a contract; legal obligations |
| Provide support and respond to requests | Contact, account, transaction, communication, and diagnostic data | Performance of a contract; legitimate interests in customer service and issue resolution |
| Maintain security and prevent abuse | IP hashes, device data, logs, authentication activity, fraud and security indicators | Legitimate interests; legal obligations; establishment, exercise, or defence of legal claims |
| Record legal acceptance | Accepted policy version, timestamp, user and Order IDs, IP hash, and device information | Performance of a contract; legal obligations; legitimate interests in evidencing agreements and resolving disputes |
| Analyse and improve the Platform | Aggregated or pseudonymised usage, feature, error, and performance data | Legitimate interests; consent where required for non-essential analytics technologies |
| Send transactional communications | Contact, Account, Order, Subscription, and security data | Performance of a contract; legal obligations; legitimate interests |
| Send marketing communications | Contact information, preferences, and engagement information | Consent where required; legitimate interests where lawfully permitted |
| Comply with legal and regulatory duties | Transaction, tax, identity, audit, security, complaint, and legal records | Legal obligation; legitimate interests; legal claims |
7. Performance of a Contract
We rely on contractual necessity where processing is needed to:
- create and maintain your Account;
- provide the features you requested;
- process subscriptions and Orders;
- deliver physical or digital products;
- provide support and account communications;
- manage renewal, cancellation, and refunds;
- take steps you requested before entering into a contract.
8. Legitimate Interests
Where we rely on legitimate interests, those interests may include:
- operating and improving our services;
- protecting accounts, users, and systems;
- detecting fraud and preventing abuse;
- understanding feature usage and service performance;
- managing business relationships;
- maintaining appropriate audit and transaction evidence;
- recovering debts and defending legal claims;
- communicating with existing business customers where lawfully permitted.
We consider the necessity of the processing and balance our interests against the individual’s interests, rights, and reasonable expectations.
9. Consent
We may rely on consent for:
- non-essential cookies and similar technologies;
- certain analytics or marketing technologies;
- some forms of electronic direct marketing;
- optional integrations or permissions;
- other processing where consent is the appropriate lawful basis.
You may withdraw consent at any time. Withdrawal does not affect the lawfulness of processing carried out before consent was withdrawn.
10. Review and Feedback Processing
Public review pages are designed to help visitors describe an experience and create review wording that they may choose to publish independently.
Depending on the configuration, the Platform may process:
- a rating from one to five stars;
- experience tags or selectable attributes;
- optional written feedback;
- business identity and location context;
- chosen language or regional language variant;
- generated review suggestions;
- copy and redirect events.
The visitor remains responsible for deciding whether to use, edit, copy, or publish generated wording. We do not publish a review to a third-party platform merely because a suggestion was generated.
10.1 Low-Rating Feedback
Where a visitor provides a low rating and optional feedback, access to that feedback may depend on the business customer’s subscription plan and configuration.
The business customer is responsible for using the feedback lawfully and transparently.
10.2 Review Authenticity
Review and feedback data must not be used to fabricate customer experiences, impersonate individuals, manipulate ratings, or circumvent third-party platform rules.
11. AI Processing
The Platform may use artificial-intelligence providers to generate, translate, transliterate, classify, summarise, or improve review-related text.
Information sent to an AI provider may include:
- the rating selected;
- experience tags or attributes;
- optional feedback entered by the visitor;
- business name, category, and general location;
- language and tone instructions;
- technical prompt and response metadata.
We aim to minimise information sent to AI providers and do not intend to send payment-card information, passwords, or unnecessary direct identifiers in AI prompts.
Users and visitors should not enter confidential, highly sensitive, or unnecessary personal information into AI-generation or feedback fields.
11.1 Multiple AI Providers
We may use more than one AI provider and route requests between providers for reliability, quality, availability, language support, rate-limit management, or service continuity.
The active providers may change over time. Current provider categories or named subprocessors may be listed at: .
11.2 Provider Use of Submitted Data
We configure AI providers, where available and appropriate, so that submitted business and review data is processed to provide the requested service and is not used to train general-purpose models on our behalf.
Actual provider retention and use will depend on the relevant provider, service tier, contractual terms, configuration, and legal requirements.
11.3 Human Review
AI-generated output is not assumed to be accurate, lawful, or appropriate without review. Users should review generated wording before publishing it.
12. Automated Decision-Making and Profiling
We may use automated systems for:
- generating review suggestions;
- detecting abusive or suspicious activity;
- applying rate limits;
- prioritising security alerts;
- routing requests to available service providers;
- producing analytics and activity summaries.
We do not intend to make decisions based solely on automated processing that produce legal or similarly significant effects on individuals, unless this is lawfully permitted and appropriate safeguards are provided.
Account restrictions may be triggered automatically in response to suspected abuse or security events, but significant enforcement actions may be reviewed where appropriate.
13. Supabase
We may use Supabase services for database hosting, authentication, file storage, server functions, logs, and related infrastructure.
Data processed through Supabase may include:
- account and authentication information;
- business profiles and settings;
- review and feedback records;
- orders, subscriptions, and transaction references;
- uploaded business logos or files;
- audit, security, and application logs.
The location and handling of data may depend on the selected Supabase project region, service configuration, subprocessors, and applicable contractual arrangements.
14. Stripe and Payment Processing
We may use Stripe to process subscription payments, product payments, invoices, refunds, and related financial events.
Stripe may collect and process payment details, billing details, device information, transaction data, fraud-prevention signals, and other information required to provide its services.
Stripe may act as our processor for some activities and as an independent controller for certain payment, regulatory, fraud-prevention, and compliance purposes.
We ordinarily receive payment references and limited payment-method details, but not complete readable card numbers.
15. Authentication Providers
We may allow users to sign in using a third-party identity provider, such as Google.
When you use third-party sign-in, the provider may send us information such as your name, email address, profile image, and provider-specific authentication identifier.
The identity provider processes information under its own privacy policy in addition to our processing.
16. Analytics
We may use analytics to understand:
- how visitors reach and use the Website;
- which Platform features are used;
- where users encounter errors;
- performance and reliability;
- conversion, engagement, and retention trends;
- QR, NFC, and direct-link activity;
- subscription and product performance.
Wherever practical, analytics data may be aggregated, minimised, pseudonymised, or configured to reduce unnecessary identification.
Non-essential analytics technologies will be used on the basis of consent where consent is legally required.
17. Cookies and Similar Technologies
We may use cookies, local storage, pixels, scripts, tags, and similar technologies.
17.1 Strictly Necessary Technologies
These may be used to:
- authenticate users;
- maintain sessions;
- secure accounts and payments;
- remember checkout contents;
- store privacy and cookie choices;
- prevent fraud and abuse;
- provide functionality explicitly requested by the user.
Strictly necessary technologies may be used without consent where the law permits.
17.2 Analytics Technologies
Analytics technologies help us measure usage, performance, errors, and engagement. Where required, they will not be activated until consent is given.
17.3 Functional Technologies
Functional technologies may remember settings such as language, region, appearance, business selection, or other preferences.
17.4 Marketing Technologies
Marketing technologies may be used to measure campaigns, attribute conversions, or personalise advertising where implemented and lawfully permitted.
17.5 Managing Cookies
You can manage non-essential cookie choices through: .
You may also control cookies through your browser. Blocking some essential or functional technologies may prevent parts of the Website or Platform from working correctly.
Further details are available in our Cookie Policy: .
18. IP Addresses and IP Hashing
We may process an IP address for security, routing, localisation, session management, fraud prevention, and legal compliance.
For selected analytics, review events, acceptance records, or abuse controls, we may store a cryptographic hash derived from the IP address rather than the raw IP address.
An IP hash is pseudonymous information rather than guaranteed anonymous information. It may still be treated as personal data where it can reasonably be linked to an individual or device.
Hashes may be generated using a secret salt or similar security control to make simple reversal or comparison with external datasets more difficult.
19. Direct Marketing
We may send product news, offers, educational content, or other marketing communications where:
- you have given consent;
- the law permits communication to an existing customer;
- another lawful basis and marketing rule applies.
You may unsubscribe using the link in a marketing message or by contacting .
Unsubscribing from marketing does not stop transactional, security, billing, or service communications.
20. Transactional Communications
We may send communications concerning:
- email verification and account activation;
- password reset or security changes;
- payment confirmation or failure;
- subscription activation, renewal, cancellation, or refund;
- order production, shipment, delivery, or cancellation;
- daily or monthly activity reports;
- important service, security, or legal updates;
- support requests and complaints.
These messages may be necessary to provide the service or administer the contractual relationship.
21. How We Share Personal Data
We may share personal data with the following categories of recipient where necessary and lawful:
- database, hosting, storage, and infrastructure providers;
- authentication and identity providers;
- AI and language-processing providers;
- payment processors, banks, and fraud-prevention providers;
- email, messaging, and notification providers;
- analytics, logging, monitoring, and error-tracking providers;
- delivery carriers, printers, and fulfilment partners;
- customer-support and communication providers;
- professional advisers, auditors, insurers, and accountants;
- regulators, courts, law-enforcement agencies, and public authorities;
- buyers, investors, or successors in a corporate transaction;
- business customers where data relates to their review journey or account.
We do not sell personal data in the ordinary meaning of exchanging personal data directly for money.
22. Subprocessors
Where we act as a processor, we may appoint subprocessors to support hosting, authentication, AI generation, payments, communications, monitoring, analytics, security, fulfilment, and support.
We require processors and subprocessors to protect personal data through appropriate contractual and security obligations.
Our current subprocessor information may be published at: .
Business customers may also receive notice of material subprocessor changes where required by the applicable data-processing agreement.
23. International Transfers
Some suppliers, systems, support personnel, or infrastructure may be located outside the United Kingdom.
Where personal data is transferred internationally, we use an appropriate legal mechanism where required. Depending on the destination and circumstances, this may include:
- UK adequacy regulations;
- the UK International Data Transfer Agreement;
- the UK Addendum to EU Standard Contractual Clauses;
- another approved contractual transfer mechanism;
- a legally permitted exception for a particular transfer.
We may also assess the laws and practices of the destination and implement supplementary technical, contractual, or organisational safeguards where appropriate.
Information about relevant transfer mechanisms may be requested through .
24. Data Location
Primary service data may be hosted in the infrastructure region selected for the Platform. Backups, logs, support systems, AI providers, payment systems, and subprocessors may process data in other locations.
The exact location may vary according to provider architecture, customer configuration, resilience requirements, and service availability.
25. Data Security
We use reasonable technical and organisational measures designed to protect personal data against unauthorised access, loss, alteration, disclosure, or destruction.
Measures may include:
- encrypted network connections;
- encryption provided by infrastructure and storage services;
- hashed or securely managed authentication credentials;
- role-based access controls;
- least-privilege permissions;
- audit and security logging;
- rate limiting and bot protection;
- IP hashing and pseudonymisation;
- environment and secret management;
- backups and service-recovery controls;
- supplier security reviews;
- incident-response procedures;
- staff confidentiality and access restrictions.
No internet service or storage system can be guaranteed to be completely secure. Users must also protect their credentials and devices.
26. Personal Data Breaches
We maintain procedures for investigating suspected personal-data breaches.
Where required, we will notify the relevant supervisory authority and affected individuals within the applicable legal timeframes.
Business customers will be informed of relevant incidents affecting data processed on their behalf in accordance with the applicable data-processing agreement.
27. Retention
We retain personal data only for as long as reasonably necessary for the purpose for which it was collected, including legal, accounting, tax, security, fraud-prevention, dispute, and contractual requirements.
The actual period may depend on the nature of the record, account status, legal obligations, limitation periods, active disputes, and customer instructions.
| Data Category | Indicative Retention Approach |
|---|---|
| Active account and business-profile data | Retained while the Account remains active and for a limited period after closure for restoration, support, security, and legal purposes. |
| Review and feedback data | Retained according to the business customer’s configuration, subscription, instructions, and our applicable retention schedule. |
| AI request and response data | Retained only as necessary for delivery, troubleshooting, abuse prevention, and service improvement, subject to provider-specific retention. |
| Orders, payments, invoices, and tax records | Normally retained for the period required by tax, accounting, anti-fraud, and commercial-record obligations. |
| Legal acceptance records | Retained for the life of the contract and an appropriate period afterwards to evidence acceptance and manage disputes. |
| Support and complaint records | Retained for issue resolution and an appropriate period afterwards according to risk and legal limitation periods. |
| Security and abuse logs | Retained for a proportionate period based on the nature and severity of the security risk. |
| Cookie-consent records | Retained for an appropriate period to remember choices and evidence consent or withdrawal. |
| Marketing records | Retained while marketing is active and, where necessary, as a suppression record after opt-out. |
More detailed retention periods may be maintained in our internal retention schedule. You may request further information by contacting .
28. Account Closure and Deletion
When an Account is closed, some personal data may be deleted, anonymised, or placed beyond ordinary operational use.
We may retain data where necessary for:
- unpaid amounts and transaction reconciliation;
- tax, accounting, and legal obligations;
- fraud and abuse prevention;
- legal-document acceptance evidence;
- complaints, chargebacks, and disputes;
- establishment, exercise, or defence of legal claims;
- backup integrity and disaster recovery;
- compliance with another lawful retention requirement.
Data in backups may remain until the backup is securely overwritten according to the applicable backup cycle.
29. Anonymised and Aggregated Data
We may create statistics or datasets that are aggregated or anonymised so that individuals are no longer reasonably identifiable.
We may use genuinely anonymised information for analytics, benchmarking, research, reporting, product improvement, capacity planning, and business purposes.
We will not describe information as anonymous where it remains reasonably capable of being linked to an individual.
30. Children
The Website and Platform are intended for business users and adults. They are not directed to children.
You must be at least 18 years old to create an Account, purchase a Subscription, or place an Order unless another lawful arrangement has been expressly approved.
A public review page may be accessible through a general link. Children should not submit personal information through such pages.
If we learn that personal data was collected from a child inappropriately, we will take reasonable steps to investigate and delete or restrict it as appropriate.
31. Your Data-Protection Rights
Depending on the circumstances and applicable law, you may have the following rights:
31.1 Right to Be Informed
You have the right to receive clear information about how your personal data is collected and used.
31.2 Right of Access
You may request confirmation of whether we process your personal data and a copy of that data, together with related information.
31.3 Right to Rectification
You may request correction of inaccurate personal data and completion of incomplete data.
31.4 Right to Erasure
You may request deletion of personal data in circumstances provided by law. This right is not absolute and may not apply where retention is legally required or otherwise justified.
31.5 Right to Restrict Processing
You may request temporary restriction of processing in specified circumstances.
31.6 Right to Data Portability
For eligible data processed by automated means on the basis of consent or contract, you may request the data in a structured, commonly used, and machine-readable format.
31.7 Right to Object
You may object to processing based on legitimate interests in certain circumstances.
You may object at any time to processing for direct-marketing purposes.
31.8 Rights Relating to Automated Decisions
You may have rights concerning decisions based solely on automated processing that produce legal or similarly significant effects.
31.9 Right to Withdraw Consent
Where processing is based on consent, you may withdraw consent at any time.
31.10 Right to Complain
You may complain to the UK Information Commissioner’s Office or another competent supervisory authority.
32. Exercising Your Rights
To exercise a privacy right, use: or email .
Please provide:
- your name;
- the email address associated with the relevant Account or interaction;
- the right you wish to exercise;
- enough information to identify the relevant data;
- any business or Order identifier that may help us locate the records.
We may request proportionate proof of identity before disclosing or changing personal data.
We normally respond within one month, although the period may be extended where legally permitted because of complexity or multiple requests.
We do not ordinarily charge a fee. A reasonable fee may be permitted for requests that are manifestly unfounded or excessive, or we may be permitted to refuse such a request.
33. Requests Relating to Business-Customer Data
If your data was collected through a review link, QR code, NFC product, or feedback journey operated for a particular business, that business may be the controller.
You should normally contact the business first. If you contact us, we may forward the request to the business or ask for enough information to identify the relevant controller.
34. Complaints to the ICO
We encourage you to contact us first so that we can try to resolve your concern.
You also have the right to lodge a complaint with the UK Information Commissioner’s Office.
Information Commissioner’s Office
Website:
https://ico.org.uk/
Telephone: 0303 123 1113
Individuals outside the United Kingdom may also have the right to contact a supervisory authority in their own jurisdiction.
35. Third-Party Links and Review Platforms
The Website or Platform may link to third-party websites and review platforms, including Google, Trustpilot, Yelp, Tripadvisor, or others.
When you leave our Platform and access a third-party service, that third party’s privacy policy and terms apply.
We are not responsible for how an independent third party processes personal data through its own website or service.
36. Business Transfers
If we participate in a merger, acquisition, financing, restructuring, sale of assets, or transfer of all or part of the business, personal data may be disclosed to advisers, potential counterparties, and successors where necessary and subject to appropriate confidentiality and data-protection safeguards.
37. Legal Disclosure
We may preserve or disclose personal data where reasonably necessary to:
- comply with law, court orders, or regulatory requests;
- enforce our agreements;
- protect users, the public, or our systems;
- prevent, detect, or investigate fraud or crime;
- establish, exercise, or defend legal claims;
- respond to a lawful request from a competent authority.
We assess requests and disclose only information reasonably required, where legally permitted.
38. Changes to This Privacy Policy
We may update this Policy to reflect:
- changes to the Platform or business model;
- new providers, integrations, or processing activities;
- changes in law, regulation, or regulatory guidance;
- security, operational, or compliance improvements;
- changes to international-transfer arrangements.
The version, effective date, and last-updated date appear at the top.
Where a change materially affects how we use personal data, we will provide additional notice or request consent where required.
39. Contact Us
Questions, concerns, privacy requests, and complaints may be sent to:
65A High Street, Littlehampton West Sussex BN17 5EJ, UK
Privacy email:
Support email: support@review.ministerai.app
Privacy request form:
Website: https://review.ministerai.app
Document Version Information
| Field | Value |
|---|---|
| Document | Privacy Policy |
| Version | 1.0 |
| Effective Date | 1 Aug 2026 |
| Last Updated | 1 Aug 2026 |
| Controller | Bhatt Group Ltd |
| Platform | ReviewMinister |
| Website | https://review.ministerai.app |
| Privacy Contact |
