Thompson Intelligence

Your data, handled properly.

No legal fog. This page explains exactly where your numbers go when we work together, what protects them, and what I will never do with them.

One locked room per client. Only your key opens yours.

Every build runs on Supabase: underneath, it's PostgreSQL, the same battle-tested database technology used by banks and governments, run on independently audited enterprise cloud infrastructure. Your company gets its own walled-off space inside it, enforced at the database level.

The protections, one by one

A locked room of your own

Think of a bank vault: every client has their own safe-deposit box, and each key opens exactly one box. Isolation is enforced at row level in the database, so one client’s credentials cannot reach another client’s data. I hold administrative access because I build and run the system, and I use it only to do the work you have asked for.

Scrambled in transit and at rest

Encrypted while it travels and while it sits on disk. Intercepted, it reads as meaningless noise, not your numbers.

Backed up automatically

The database is backed up on a schedule, so a mistake or failure never means your history is gone.

At rest in London

The database lives in Supabase’s London region and never moves. One hop leaves the UK: the daily briefing is written via Anthropic’s API in the US. It is not used for training, it is deleted within 30 days, and it is flagged here rather than hidden. A UK-only route exists if you need it.

Log-ins, not attachments

Access is through named accounts you control. No copies of your data travelling by email attachment.

Built on audited infrastructure

Supabase's security is audited by outside firms and trusted by hundreds of thousands of companies. Nothing homemade where it matters.

What I collect, and what I don't

Collected, because the build needs it
  • The business exports you hand me: sales reports, invoices, spreadsheets
  • Contact details for the people who log in
  • The questions you want answered, in your words
Not collected, ever
  • No tracking pixels following your customers
  • No scraping of anything you didn't hand over
  • No personal data beyond what the log-ins need

Two promises worth more than certificates

You get read-only access to your own database.A credential scoped to your data, included in the welcome pack. Check any figure I show you against the source, any time.
Reporting cannot alter your records.Every connection I make to read your systems is read-only. Where a job you have commissioned has to write something back, that is agreed with you in writing first and named in the build. And if this service ever winds down: 90 days’ written notice, a documented handover, and your data returned. It is in the terms, not a promise.

What I will never do

Never sold

Your data is never sold, rented or shared with anyone outside your build. There is no version of this business where your numbers are the product.

Never used for training

Your data is processed to answer your questions. It is not used to train AI models, mine or anyone else's.

Never held hostage

Ask, and you get a full export of everything. Leave, and your data is deleted on request, confirmed in writing. You own it, always.

Your rights, simply

Under UK GDPR you can ask what I hold, get a copy, have it corrected, or have it deleted. Email me and it happens. The full notice, including lawful bases, retention and how to complain, is below.

Make a data request

The full privacy notice

Written to be read, not to be survived. Last updated 19 August 2026.

Who is responsible for your data

Oliver Thompson, trading as Thompson Intelligence, a sole trader based in Abingdon, Oxfordshire. I am the data controller for enquiries made through this site, and a data processor for client business data handled under a build contract. Contact: oli@thompsonintelligence.co.uk or 07568 608878.

What this website collects

The checklist form does not send anything to a server. It opens your own email app with the request written out, and you press send. What I then hold is that email. This site sets no cookies, runs no analytics, and makes no third-party requests: every font, script and stylesheet is served from this domain. There is no tracking pixel, no advertising network and no session recording.

Why I am allowed to hold it

  • Consent for the checklist. You asked for it, and you can withdraw at any time.
  • Legitimate interests for business-to-business enquiries and replies, which is the basis for contacting a named business about work it might want.
  • Contract for client business data, processed only to deliver the work agreed and only for as long as that work runs.

How long I keep it

  • Enquiries and correspondence: three years from our last exchange, then deleted.
  • Client business data: for the life of the engagement, then returned and deleted on request, confirmed in writing. If nothing is requested, deleted within 90 days of the work ending.
  • Invoices and records I must keep for tax: six years, as HMRC requires.

Who else touches it

I use a small number of established suppliers, each under their own data protection terms: Google Workspace (email and calendar), Vercel (website hosting), Supabase (client databases, data at rest in London), Anthropic (the AI models behind briefings), n8n (automation), and Cal.com (booking). Client data is never used to train any AI model. Nothing is sold, rented or shared with anyone outside your build.

Your rights

Under UK GDPR you can ask for a copy of what I hold, have it corrected, have it deleted, restrict or object to how it is used, or ask for it in a portable format. Email me and I will action it within one month, usually the same week. There is no charge.

If you are not happy

Tell me first and I will try to put it right. If that fails, you have the right to complain to the Information Commissioner’s Office, the UK regulator, at ico.org.uk/make-a-complaint or on 0303 123 1113. You do not need my permission to do that.