Policies
Policies
Last updated: 12 August 2026
ieon Limited is a company registered in England and Wales, company number 16875950, registered office 5th Floor, 167–169 Great Portland Street, London W1W 5PF, United Kingdom.
The policies below set out how we handle personal data, how we use cookies, and the standards we hold ourselves to on bribery, corruption and the reporting of wrongdoing. Questions about any of them: contact@ieon.ai.
Contents
Privacy Policy
1. Who we are
ieon Limited ("ieon", "we", "us") is a company registered in England and Wales, company number 16875950, with its registered office at 5th Floor, 167–169 Great Portland Street, London W1W 5PF, United Kingdom. We operate the website ieon.ai and provide Edge AI products and services, including Edge Studio.
ieon operates through the following group entities:
| Entity | Registration | Address |
|---|---|---|
| ieon Limited (United Kingdom) | Company No. 16875950 | 5th Floor, 167–169 Great Portland Street, London W1W 5PF, United Kingdom |
| ieon for Artificial Intelligence and Software Development (Qatar) | C.R. No. 233955 | Building 115, Street 2322, Zone 51, QSTP Free Zone, Qatar |
| ieon AI (Saudi Arabia) | C.R. No. 7054899419 | Riyadh, Kingdom of Saudi Arabia |
For the purposes of UK data protection law, ieon Limited is the data controller for personal data collected through this website and in the course of our business relationships, including where an enquiry relates to our Qatar or Saudi operations. Where a contract is entered into with our Qatar or Saudi entity, that entity is the controller for personal data processed under it, and this policy applies alongside the applicable local law — the Qatar Personal Data Privacy Protection Law (Law No. 13 of 2016) together with QSTP and Qatar Free Zone requirements, and the Saudi Personal Data Protection Law (Royal Decree M/19 of 2021, as amended) and its implementing regulations.
Where we process personal data on behalf of a customer as part of a service engagement, we act as a data processor under the terms of the relevant contract or Data Processing Agreement.
Questions about this policy or your data: contact@ieon.ai.
2. Scope
This policy covers the ieon.ai website and the enquiries we receive through it. We do not operate user accounts on this website, we do not sell or trade data, and we do not run advertising or visitor profiling.
It does not cover personal data we process on a customer's behalf under a service contract. In those engagements the customer is the controller, we act as processor on their written instructions, and the applicable Data Processing Agreement governs — not this policy.
ieon Limited processes personal data only for its own core business purposes — corresponding with business contacts, keeping accounts and records, marketing our own services, and staff administration (including records kept under our internal governance policies). On that basis we have self-assessed as exempt from the ICO data protection fee.
It does not apply to third-party websites we link to. We are not responsible for their privacy practices.
3. What personal data we collect
Browsing ieon.ai does not require you to give us any information about yourself. We collect only two things:
What you choose to send us. Our enquiry form asks for your first name, last name and email address, and optionally your job title. Only the first three are required. It also includes a free-text message field, so we receive whatever you choose to write there. We use this only to reply to you and to take forward any project you want to discuss. We aim to respond within one business day.
Standard server logs. Our hosting provider automatically records the IP address, browser type and pages requested for every visit, as every web server does. These are used for security and troubleshooting, and are not linked to any individual.
What we do not collect or do
- No user accounts, logins or passwords on this website.
- No payment card or financial details.
- No special category data (health, biometric, ethnicity, political or religious data). Please do not send it through our forms.
- No advertising trackers, no visitor profiling, no automated decision-making.
- No sale, rental or exchange of data with any third party.
4. Why we use it, and our lawful basis
| Purpose | Lawful basis |
|---|---|
| Responding to enquiries sent through our contact form or by email | Legitimate interests (responding to a request made to us); steps prior to entering a contract |
| Providing and supporting our products and services | Performance of a contract |
| Managing customer and supplier relationships and billing | Performance of a contract; legal obligation |
| Operating, securing and troubleshooting our website | Legitimate interests (running a safe, functional website) |
| Occasional updates to business contacts about our services | Consent, or legitimate interests where permitted for existing business contacts under PECR |
| Meeting legal, tax and accounting obligations | Legal obligation |
| Establishing, exercising or defending legal claims | Legitimate interests |
Where we rely on legitimate interests, we have assessed that our interests do not override your rights and freedoms. You can ask us for details of that assessment.
5. Marketing
We do not run mass marketing campaigns and we do not maintain a marketing mailing list. We may send occasional updates about our services to business contacts who have asked to hear from us or who have discussed similar services with us. Any such message includes a way to opt out, and you can ask us to stop at any time by emailing contact@ieon.ai. This does not affect operational messages such as replies to your enquiry, contract correspondence and invoices.
6. Who we share data with
We share personal data only where necessary, and only with:
- Service providers acting on our instructions — currently our website hosting provider and our business email provider, and our professional advisers (legal and accounting) where relevant.
- Group companies and contractors working on a specific engagement, bound by confidentiality obligations.
- Authorities and regulators, where required by law, court order or regulatory request.
- A buyer or successor in the event of a merger, acquisition, financing or sale of assets, subject to appropriate confidentiality protections.
We do not sell personal data, we do not share it with third parties for their own marketing purposes, and we do not use third-party advertising or data-broker services.
7. International transfers
Our primary hosting and processing takes place in the United Kingdom and the European Economic Area. Some of our service providers, and some of our project delivery teams, operate outside the UK — including our group entities in Qatar and Saudi Arabia, and contractors in Europe and Asia.
Personal data may be shared between ieon Limited, ieon Qatar and ieon AI (Saudi Arabia) where necessary to deliver a service, respond to an enquiry or administer the group. These transfers are governed by an intra-group data transfer agreement incorporating the safeguards below.
Where personal data is transferred outside the UK, we rely on one of the following safeguards:
- an adequacy decision or adequacy regulations covering the destination country;
- the International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses; or
- another lawful transfer mechanism, supported by a transfer risk assessment.
You can request a copy of the relevant safeguard by emailing contact@ieon.ai.
8. How long we keep it
We keep personal data only as long as we need it for the purpose it was collected for, or as required by law.
- Website enquiries that do not lead to a relationship: up to 24 months from last contact.
- Correspondence with business contacts: until you ask us to stop, and reviewed at least every 24 months.
- Customer, partner and supplier records: for the duration of the relationship and 6 years afterwards, to meet contractual, tax and limitation-period requirements.
- Server logs: retained by our hosting provider for a short rolling period, typically no more than 12 months.
At the end of the retention period we securely delete or anonymise the data.
9. Security
We apply technical and organisational measures appropriate to the risk and to the small volume of data we hold, including encryption in transit (HTTPS), access controls on a least-privilege basis, multi-factor authentication on our business systems, secure development practices, and staff confidentiality obligations.
No system is completely secure. If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the ICO within 72 hours where required, and notify you directly where the risk is high.
We will never ask you for a password or payment details by phone or email. If you receive such a request claiming to be from ieon, report it to contact@ieon.ai.
10. Your rights
Under UK GDPR you have the right to:
- be informed about how we use your data — this policy;
- access a copy of the personal data we hold about you;
- rectify inaccurate or incomplete data;
- erase your data in certain circumstances;
- restrict processing in certain circumstances;
- data portability — receive certain data in a structured, machine-readable format;
- object to processing based on legitimate interests, and to direct marketing at any time; and
- withdraw consent where we rely on it, without affecting prior processing.
You also have the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects. We do not make such decisions about website visitors.
To exercise any right, email contact@ieon.ai. We will respond within one month, and will tell you if we need to extend that period. There is normally no charge.
If you are unhappy with our response, you can complain to the Information Commissioner's Office at ico.org.uk, by calling 0303 123 1113, or by writing to Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF. We would appreciate the chance to address your concerns first.
11. Children
Our website and services are directed at businesses and professionals. We do not knowingly collect personal data from anyone under 18. If you believe we have, contact contact@ieon.ai and we will delete it.
12. Changes to this policy
We review this policy at least annually and update it when our practices or the law change. The "last updated" date at the top shows the current version. Where changes are significant, we will notify affected individuals directly or through a prominent notice on the website.
13. Governing law
This policy and any dispute arising from it are governed by the laws of England and Wales, and subject to the exclusive jurisdiction of the courts of England and Wales.
Cookie Policy
1. What cookies are
Cookies are small text files placed on your device when you visit a website. Similar technologies — local storage, pixels and tags — work in comparable ways. We refer to all of them as "cookies" in this policy.
2. Your consent
Under the Privacy and Electronic Communications Regulations (PECR), non-essential cookies may only be set with your consent.
ieon.ai uses strictly necessary cookies only. These are required for the site to function — maintaining your session, protecting against abuse, and remembering any preference you set. They are exempt from the consent requirement under PECR and cannot be switched off.
We do not use analytics, advertising, or tracking cookies, and we do not allow third parties to set cookies through our site. Because of this, you will not see a cookie consent banner on ieon.ai.
3. Third-party content
Our site links out to third-party platforms, including LinkedIn and YouTube. Following such a link takes you to that provider's site, where their own cookies and privacy policy apply. We do not embed players or widgets that set third-party cookies on ieon.ai itself, and we will update this policy if that changes.
4. Browser controls
Most browsers let you block or delete cookies, and many support "do not track" or global privacy control signals. Blocking strictly necessary cookies may stop parts of the site working. See aboutcookies.org for browser-specific instructions.
5. Contact
Questions about cookies: contact@ieon.ai.
Anti-Bribery and Corruption Policy
1. Policy statement
ieon Limited and its group entities conduct their business honestly and without the use of corrupt practices or acts of bribery to obtain an unfair advantage. We take a zero-tolerance approach to bribery and corruption, and are committed to acting professionally, fairly and with integrity in all our dealings and relationships wherever we operate.
We are committed to implementing and enforcing effective systems to counter bribery, in line with the UK Bribery Act 2010 and the six principles set out in the Ministry of Justice guidance: proportionate procedures, top-level commitment, risk assessment, due diligence, communication and training, and monitoring and review.
2. Who this applies to
This policy applies to all individuals working at all levels for or on behalf of ieon Limited and its group entities in Qatar (C.R. 233955) and Saudi Arabia (C.R. 7054899419) — including directors, employees, contractors, consultants, agents, interns, secondees and any other third party acting for us, in every country where we operate.
The UK Bribery Act has extraterritorial reach. Conduct that would be an offence in the UK is treated as an offence under this policy regardless of where it takes place, and regardless of local custom or practice.
3. Definitions
Bribe — a financial or other advantage offered, promised, given, requested or accepted to induce or reward the improper performance of a function or activity, or to influence a person in their official capacity.
Corruption — the abuse of entrusted power or position for private gain, including kickbacks, embezzlement, collusion and undisclosed conflicts of interest.
Facilitation payment — a small unofficial payment made to secure or speed up a routine action a person is already obliged to perform. Facilitation payments are bribes and are illegal under the Bribery Act 2010, regardless of amount or local practice.
Public official — anyone holding a legislative, administrative or judicial position, anyone exercising a public function, and officers and employees of state-owned enterprises and public international organisations. Dealings with public officials carry heightened risk.
4. What is prohibited
You must not:
- offer, promise, give, request, agree to receive or accept a bribe, directly or through a third party;
- make or accept a facilitation payment or kickback of any kind;
- offer or accept a gift or hospitality intended to obtain or reward improper performance, or that could reasonably be seen that way;
- make a political donation on behalf of ieon;
- make a charitable donation that is, in substance, a bribe or is intended to influence a business decision;
- threaten or retaliate against anyone who has refused to pay or accept a bribe, or who has raised a concern under this policy; or
- engage in any activity that might lead to a breach of this policy, or ignore a suspicion that one has occurred.
5. Gifts and hospitality
This policy does not prohibit normal and appropriate hospitality given to or received from third parties. A gift or hospitality is acceptable only if it:
- is not made with the intention of influencing a decision or obtaining a business advantage, and is not offered in expectation of something in return;
- complies with local law and with the recipient organisation's own policy;
- is given in ieon's name, not in your personal name;
- does not consist of cash or a cash equivalent such as a gift voucher;
- is reasonable, proportionate and appropriate in the circumstances, taking account of the reason, timing and value; and
- is given openly, not secretly.
Gifts or hospitality with a value above £50 per person, and anything involving a public official at any value, require prior written approval from a director and must be recorded in the gifts and hospitality register. Nothing may be offered during a live tender, bid or contract negotiation without director approval.
6. Third parties and due diligence
Third parties acting for ieon — agents, resellers, distributors, introducers, consultants and partners — are the highest-risk area under the Bribery Act, because a company can be liable for a bribe paid by an associated person acting on its behalf.
Before appointing a third party who will represent us, interact with public officials, or introduce business, we will:
- carry out risk-based due diligence on ownership, reputation, sanctions exposure and any history of corruption;
- ensure remuneration is commercially justifiable and proportionate to the service actually provided, with no success fees or commissions that lack a clear rationale;
- include contractual anti-bribery warranties, audit rights and a right to terminate for breach; and
- keep a record of the due diligence carried out.
We keep a register of higher-risk relationships and review it periodically.
7. Records and internal controls
All accounts, invoices, expense claims and other records must be prepared accurately and completely. No accounts may be kept "off book". Expenses relating to gifts, hospitality or payments to third parties must be submitted with a clear description of the business purpose. Financial approvals follow documented authority limits and segregation of duties.
8. Raising a concern
If you are offered a bribe, are asked to make one, suspect that bribery may have occurred or may occur, or are unsure whether something is permitted, raise it as early as possible — through your manager, a director, or the channels in our Whistleblowing Policy. Reports may be made anonymously.
We will support anyone who raises a genuine concern in good faith, even if it turns out to be mistaken, and no one will suffer detriment for refusing to participate in bribery or corruption, even if it results in ieon losing business.
9. Training and responsibility
The board of directors has overall responsibility for this policy and for ensuring it complies with our legal and ethical obligations. Managers are responsible for ensuring those reporting to them understand and apply it. All staff receive anti-bribery training on induction and refresher training thereafter, proportionate to their role and risk exposure.
10. Breach
Breach of this policy may result in disciplinary action up to and including summary dismissal for gross misconduct. For third parties, it may result in immediate termination of the contract or relationship. Bribery is a criminal offence: individuals face up to 10 years' imprisonment and unlimited fines, and organisations face unlimited fines and disqualification from public procurement.
11. Monitoring and review
The board reviews this policy at least annually, together with the gifts and hospitality register, the third-party risk register and any concerns raised, and updates it in response to changes in our operations, risk profile or the law.
Whistleblowing Policy
1. Policy statement
ieon Limited and its group entities are committed to conducting business with honesty and integrity, and expect the same of everyone who works for and with us. We encourage anyone with a genuine concern about wrongdoing in our business to come forward and voice that concern.
This policy sets out how to raise a concern, how it will be handled, and the protection available to you. It is designed to reflect the Public Interest Disclosure Act 1998 (PIDA), which protects workers who make qualifying disclosures in the public interest from dismissal and detriment.
2. Who this applies to
This policy applies to employees, directors, contractors, consultants, agents, secondees, interns, volunteers and suppliers across all ieon group entities in the UK, Qatar and Saudi Arabia. The statutory protections described below arise under UK law; staff of the Qatar and Saudi entities are afforded equivalent protection as a matter of ieon policy, alongside any local statutory rights. It is a statement of policy and does not form part of any employment contract.
3. What to report
Raise a concern where you reasonably believe one or more of the following has occurred, is occurring, or is likely to occur:
- a criminal offence, including fraud, bribery or corruption;
- a failure to comply with a legal or regulatory obligation;
- a miscarriage of justice;
- a danger to the health and safety of any individual;
- damage to the environment;
- a personal data breach, or misuse of confidential or proprietary information;
- misuse of AI systems, models or customer data, including deployment outside agreed purposes;
- financial irregularity, misreporting or improper accounting;
- serious breach of our internal policies, including our Anti-Bribery and Corruption Policy; or
- the deliberate concealment of any of the above.
Personal grievances about your own employment — pay, terms, or how you have been treated individually — are normally handled under our grievance procedure rather than this policy, unless the matter is in the public interest.
4. Protection for whistleblowers
- No detriment. No one who raises a genuine concern will suffer dismissal, disciplinary action, demotion, isolation or any other detriment as a result. This applies even if the concern turns out to be mistaken, provided you held a reasonable belief.
- No obligation to be right. You do not need proof. You need a reasonable belief and a genuine concern.
- Protection from retaliation. Anyone who subjects a whistleblower to detriment will face disciplinary action, up to and including dismissal.
- Bad faith. Knowingly making a false or malicious allegation may itself be treated as a disciplinary matter.
If you believe you have suffered detriment for raising a concern, report it immediately to a director or through the external channel below.
5. Confidentiality and anonymity
We will treat your identity and your report as confidential, and will only disclose your identity where we are legally required to do so, or where it is unavoidable for a proper investigation — and we will discuss it with you first wherever possible.
You may report anonymously. We will take anonymous reports seriously, but anonymity can limit our ability to investigate, ask follow-up questions or protect you, so we encourage you to identify yourself where you feel able to.
6. How to raise a concern
Step 1 — Internal. Speak to your line manager or, if that is not appropriate or you do not have one, to any director.
Step 2 — Dedicated channel. Email contact@ieon.ai, monitored by a nominated director. Where the concern involves that director, it will be routed to the remaining directors and, if necessary, to an independent adviser instructed by the board.
Step 3 — External. You can report directly to a prescribed person or body without losing PIDA protection. The full list is published on GOV.UK. Depending on the subject, this may include the Information Commissioner's Office (data protection), the Health and Safety Executive, HMRC, the Serious Fraud Office, or Companies House. The independent charity Protect (protect-advice.org.uk, 020 3117 2520) offers free, confidential advice on whistleblowing before you decide what to do.
When raising a concern, include as much detail as you can: what happened, when, who was involved, and any supporting information. Do not attempt to investigate the matter yourself, and do not gather evidence in a way that would breach confidentiality obligations or the law.
7. How we handle reports
- Acknowledgement within 5 working days.
- Initial assessment to decide whether the matter falls under this policy and what form of investigation is appropriate. We may meet you, in person or remotely, and you may be accompanied by a colleague or, where applicable, a trade union representative.
- Investigation by a director or an appointed investigator with no conflict of interest, conducted fairly, confidentially and with due process. Where the matter is serious or complex, we may appoint an external investigator or refer it to the police or a regulator.
- Outcome. We will tell you the outcome and what action we have taken, so far as confidentiality and the rights of others allow. We may not be able to share full details.
- Escalation. If you are not satisfied with how your concern has been handled, you may take it to the external routes in section 6.
We aim to conclude investigations within 30 working days and will keep you updated if more time is needed.
8. Records
Records of reports, investigations and outcomes are held securely, with access limited to those directly involved, and are processed in accordance with our Privacy Policy. They are retained for 6 years and then securely destroyed.
9. Training, review and responsibility
The board has overall responsibility for this policy. All staff are made aware of it on induction. The board reviews the policy and any reports received at least annually, and updates the policy where needed.