Skip to content
WFAI

Legal

Privacy notice

Effective 7 August 2026 Version 1.0 WORKFLOW AI SOLUTIONS LTD Company number 17005372

01 Who we are

This privacy notice is published by WORKFLOW AI SOLUTIONS LTD, a private limited company registered in England and Wales with company number 17005372, registered office 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ. The company was incorporated on 1 February 2026.

We means that company. You means the individual whose personal data is processed: a visitor to this website, a person who emails us, a contact at a client, prospective client or supplier, or a user of any application we publish.

The contact route for every matter in this notice, including any request to exercise a right, is [email protected], or post to the registered office. That mailbox is read directly. We have appointed no Data Protection Officer, because the company meets none of the conditions in Article 37 of the UK GDPR, and no Article 27 representative, because we do not offer goods or services to individuals in the European Union. If either changes, this notice will say so.

Contents

02 Our two roles: controller and processor

Data protection law distinguishes between a controller, who decides why and how personal data is processed, and a processor, who processes it only on a controller's documented instructions. This company acts in both roles, in separated situations, and the difference decides who you should contact.

2.1 When we are the controller

We are the controller for personal data about our own business relationships and our own website: people who email us, contacts at client and supplier organisations, the records we must keep for accounting and tax, and this site's request logs. Every section below is marked with the role it describes.

2.2 When we are the processor

When we build, test or operate a workflow for a client, that workflow may handle personal data belonging to the client's customers, staff or suppliers. For that data the client is the controller and we act as a processor under a data processing agreement meeting Article 28 of the UK GDPR. Section 6 describes that role.

If your data was processed inside a client's workflow and you want to exercise a right, contact that client: we may not act on their data without instruction. If you contact us instead, we will tell you so and, where we can identify the controller, forward the request and confirm that we have.

2.3 Why the split matters here

Most personal data passing through an automation we build is never ours. We do not aggregate it, improve anything of our own with it, or train models on it, and normally it stays inside the client's accounts. Section 6.3 sets out the narrow exceptions.

Contents

03 What this notice covers

This notice covers the website at wfaisolutions.co.uk, email correspondence with the company, client and supplier relationships, and any application the company publishes. As at the effective date the company has published no application on the Apple App Store or Google Play. Sections 15 to 18 state the position for the first one, written in advance so that it is not written later under commercial pressure.

It does not cover third party websites we link to or the internal practices of our clients. Where a workflow we build changes what a client must tell its own customers, we say so at the specification step, but the client remains responsible for its own notice.

Contents

04 Data inventory, controller role

Role: controller

The complete inventory of personal data we process as controller. Each row cites the Article the basis rests on, and names the interest where the basis is legitimate interests. The table scrolls inside its own frame on a small screen.

Data inventory, controller role, as at 7 August 2026
Category Example fields Source Purpose Lawful basis Retention Recipients
Enquiry correspondence Name, email address, organisation, job title, message content, date and time received You, by email or the enquiry composer on this site Reading, answering and recording an enquiry Article 6(1)(f), legitimate interests. Interest: responding to an unsolicited business enquiry and recording what was said to whom. 24 months from the last message in the thread Our email provider (see section 8)
Prospect and pipeline records Contact name, organisation, role, conversation notes, proposal drafts, quoted fees You, and public business sources such as a company website Preparing a proposal and deciding whether to take the work Article 6(1)(b) where you asked us to take steps before a contract. Otherwise Article 6(1)(f). Interest: a business to business sales conversation you initiated. 24 months from the last contact, or the life of the contract if one begins Our email and document storage providers
Client contract records Signatory name, contact details, scope, specification documents, correspondence, project notes The client organisation and its named contacts Performing the engagement and evidencing what was agreed Article 6(1)(b) where the contact is party to the contract. Article 6(1)(f) where the contact is an employee rather than a party. Interest: administering a business contract. 6 years from the end of the engagement Our document storage and accounting providers
Accounting and tax records Invoices, purchase records, payment references, remittance details, name and address of the paying entity Clients, suppliers and our bank Keeping statutory accounting records and filing accounts and tax returns Article 6(1)(c), legal obligation, under the Companies Act 2006 and the Finance Acts 6 years from the end of the financial year Our accountant and accounting software provider, HM Revenue and Customs, Companies House
Supplier and contractor records Contact name, email, company details, agreements, invoices, registration evidence where relevant The supplier or contractor Buying services, paying for them, evidencing the arrangement Article 6(1)(b), and Article 6(1)(c) for the associated accounting records 6 years from the end of the relationship Our accounting and payment providers
Website request logs IP address, request time, path, HTTP status, user agent, approximate country derived from the IP address Generated by our hosting provider when your browser requests a page Serving the site, defending it against automated abuse, diagnosing faults Article 6(1)(f). Interest: keeping a public website available and secure against attack. Held by the provider for a rolling period not exceeding 30 days. We do not export or archive them. Cloudflare, Inc.
Data protection request records Name, contact details, the request, identity evidence supplied, our response and its date You Handling the request and demonstrating that we handled it properly Article 6(1)(c), obligation under Article 12 of the UK GDPR, with Article 6(1)(f). Interest: evidencing compliance. 3 years from closure of the request Our email provider, and the ICO if a complaint is made
Marketing consent records Email address, date consent was given or withdrawn, the wording consented to You Sending an occasional email only where you asked for one, and proving that you did Article 6(1)(a), consent, read with regulation 22 of the Privacy and Electronic Communications Regulations 2003 Until withdrawal, then a suppression record kept indefinitely Our email provider

Scroll the table sideways to read every column

We collect no special category data under Article 9 and no criminal offence data under Article 10. We do not buy contact lists, enrich records from data brokers, or run advertising pixels or tracking scripts on this site.

Contents

05 Lawful bases in detail, controller role

Role: controller

5.1 Contract, Article 6(1)(b)

Where you are party to an engagement, or have asked us to take steps before entering one, we process your data because we cannot deliver what you asked for without it. If you decline to provide it, we cannot perform the engagement.

5.2 Legal obligation, Article 6(1)(c)

Some processing is required of us rather than chosen. The clearest example is accounting records, which a company must keep for six years. We cannot delete those on request, and section 12.3 explains why.

5.3 Legitimate interests, Article 6(1)(f)

Where we rely on legitimate interests we have carried out and recorded a balancing assessment. The interests are named in the table above:

  • Answering business correspondence. You wrote to us; keeping the thread is the only way to answer consistently.
  • Conducting a business to business sales conversation. Limited to conversations you started, and stopped on request.
  • Administering a business contract. Employees of a client are not usually parties to it, but their names appear in it.
  • Keeping a public website available and secure. Request logs are the only practical defence against automated abuse.
  • Evidencing compliance. A record of what we did with a rights request is how we show we did it properly.

In each case we asked whether less data would do, whether you would expect the processing, and whether it could harm you. You may object at any time under section 12.9.

5.4 Consent, Article 6(1)(a)

We rely on consent only where the law requires it, which in practice means an occasional email you asked to receive. It is requested in plain wording, never bundled into another agreement, and withdrawn by replying to the email or writing to our contact address. Withdrawal does not affect earlier processing.

Contents

06 Client data, processor role

Role: processor

6.1 The instruction we work to

Where an engagement involves personal data belonging to a client's customers, staff or suppliers, we process it only on documented instructions under a written agreement carrying the terms required by Article 28(3) of the UK GDPR: subject matter and duration, nature and purpose, categories of data subject and data, confidentiality, security, further sub-processors, assistance with data subject requests and Articles 32 to 36, and what happens at the end.

6.2 What we will not do with client data

  • We do not use it for any purpose of our own.
  • We do not use it to train, fine tune or evaluate any machine learning model, and where an engagement uses a third party model interface we set the vendor's no-training option wherever one is offered.
  • We do not aggregate it, anonymise it for our own analytics, or keep a copy after the engagement beyond what the agreement allows.
  • We do not transfer it outside the United Kingdom except on instruction and under a mechanism in section 9.

6.3 When we hold client data at all

The workflow runs inside the client's own accounts, so in the ordinary case no client personal data reaches infrastructure we control. The exceptions are narrow and named in the agreement:

  • Sample records during specification. We ask for redacted or synthetic samples first. Where real records are unavoidable they are deleted at the end of the step.
  • Test data during build. Held only while the test is being run.
  • Diagnostic extracts during a parallel run. Deleted when the variance is closed.
  • Administrative access to a client system. Credentials are issued by the client, individually attributable to us, scoped as narrowly as the work allows and revoked at handover.

6.4 Assistance and end of engagement

If a client receives a data subject request touching a workflow we built, we assist within the timescale the agreement sets, at no charge where the assistance is proportionate. At the end of an engagement we delete or return client personal data at the client's choice and confirm in writing, except where the law requires us to keep something, in which case we say what and why.

Contents

07 Where the data comes from

Role: controller

Almost everything we hold as controller comes directly from you: an email you sent, a document you supplied, a contract you signed, a request your browser made. Two exceptions: business contact details are sometimes taken from an organisation's own public website when preparing for a conversation it invited, and payment references reach us through our bank rather than from you. We obtain personal data from no data broker, list vendor, scraping tool or enrichment service.

Contents

08 Sub-processors and service providers

Role: controller and processor

The providers below process personal data on our behalf, each under a written contract meeting Article 28 of the UK GDPR. In our processor role we add no sub-processor to a client's work without the notice period agreed in the processing agreement, and the client may object.

Named sub-processors and service providers, as at 7 August 2026
Provider Service to us Data involved Processing location Transfer mechanism
Cloudflare, Inc. Hosting and delivery of this website, network protection Request logs including IP address and user agent Global edge network, including servers in the United Kingdom and the United States UK Addendum to the EU Standard Contractual Clauses
Google Ireland Limited and Google LLC Business email and document storage on Google Workspace All correspondence, contracts, specifications and project documents European Union and United States UK Addendum to the EU Standard Contractual Clauses
Google LLC, Fonts service Delivery of the two typefaces used on this site Your IP address and browser headers, seen when your browser fetches a font file United States UK Addendum to the EU Standard Contractual Clauses
Accounting software provider, not yet appointed Bookkeeping, invoicing and preparation of statutory accounts Invoice and payment records including names and addresses None. No provider processes this data for us today, because none is appointed. None in force. The provider, its processing location and the mechanism will be named in this row before any personal data reaches it.
Accountant, not yet engaged Preparation and filing of statutory accounts and returns Accounting records containing names and payment details None today. Any firm we engage will be named here, and we will engage one that processes within the United Kingdom. None in force. No transfer is expected, and if one became necessary this row would state the mechanism before it happened.

Scroll the table sideways to read every column

The last two rows describe providers that are not yet appointed, so nothing is being processed under them. We would rather show the gap than name a provider we do not use, and each will be filled in before any personal data reaches it.

Beyond that list we disclose personal data only to professional advisers bound by confidentiality, to a regulator or court where legally required, and to an acquirer if the business is ever transferred, in which case this notice continues to apply until lawfully replaced.

Contents

09 International transfers

Role: controller and processor

9.1 The rule we apply

Personal data may leave the United Kingdom only if a route in Chapter V of the UK GDPR applies. We rely on three, in this order: an adequacy decision, then the International Data Transfer Agreement, then the UK Addendum to the EU Standard Contractual Clauses.

9.2 UK adequacy regulations

The United Kingdom has made adequacy regulations for a number of countries and territories, including the member states of the European Economic Area. Where a provider processes data only in a covered country, no further mechanism is needed: the transfer is treated as though the data had not left the United Kingdom.

9.3 The International Data Transfer Agreement

Where a provider or client requires a standalone United Kingdom instrument, we use the International Data Transfer Agreement issued by the Information Commissioner under section 119A of the Data Protection Act 2018, unamended, with the tables completed for that specific arrangement rather than left generic.

9.4 The UK Addendum to the EU Standard Contractual Clauses

Most large providers publish a processing addendum built on the European Commission's Standard Contractual Clauses. For transfers from the United Kingdom we rely on the ICO's International Data Transfer Addendum to those Clauses, which applies them with the modifications United Kingdom law requires. This is the mechanism covering the transfers marked in section 8.

9.5 Transfer risk assessment

Contract alone is not enough. Before relying on either instrument we assess whether the law and practice of the destination country would undermine it, using the ICO's transfer risk assessment approach, and record the outcome. Where it is negative we look for supplementary measures: encryption with keys held here, minimisation before transfer, pseudonymisation. If none makes the transfer safe, we do not make it.

9.6 Where a client instructs a transfer

As processor we transfer client personal data outside the United Kingdom only on documented instruction. Where an engagement involves a model interface hosted abroad, we say so at the specification step, name the destination, and offer the alternative of a model run on infrastructure the client controls. Transfer documentation affecting your data is available on request.

Contents

10 Retention periods

Role: controller

Every period below carries a reason, because a retention schedule without reasons is a list of guesses.

Retention schedule, controller role
Record Period Reason for the period
Enquiry correspondence that does not become work 24 months from the last message Long enough to recognise a returning enquirer, short enough that a dead conversation is not kept indefinitely
Prospect and proposal records 24 months from the last contact Matches the enquiry period and covers a buying cycle where a proposal is revived a year later
Client contracts, specifications and project correspondence 6 years from the end of the engagement The limitation period for a simple contract claim in England and Wales is six years under the Limitation Act 1980
Accounting records, invoices and payment records 6 years from the end of the financial year The statutory period for a private company's accounting records under section 388 of the Companies Act 2006, and the period HM Revenue and Customs expects
Supplier and contractor records 6 years from the end of the relationship Same limitation and accounting reasoning as client records
Website request logs Rolling period not exceeding 30 days, held by the provider Enough to investigate an attack after a weekend, not enough to build a history of a visitor
Data protection request files 3 years from closure Covers the period in which an ICO complaint about our handling could reach us
Marketing consent and suppression records Consent until withdrawal. Suppression indefinitely. A suppression record is the only reliable way to honour an objection permanently
Client personal data held as processor Deleted or returned at the end of the engagement, or earlier per section 6.3 The client sets retention as controller. We hold nothing beyond what the agreement permits.
Backups Overwritten on the provider's cycle, not exceeding 90 days Deleted data can persist briefly in a backup. It is not restored into use and ages out.

Scroll the table sideways to read every column

Contents

11 Security, and what we do not claim

Role: controller and processor

The measures we operate: multi-factor authentication on every account holding personal data; full disk encryption and automatic locking on work devices; current transport layer security, with this site served over HTTPS; client system access at the narrowest permission level, individually attributable and handed back at the end; credentials in a password manager, never in a document, message or code repository. Further measures are agreed in writing where an engagement warrants them.

We do not hold ISO 27001 certification, a SOC 2 report or Cyber Essentials certification, and will not represent otherwise. If your procurement process requires one, we are not yet a supplier you can use, and we would rather you learn that here than three weeks into a questionnaire.

No set of measures makes a system perfectly secure and we do not claim ours does. What we commit to is telling you quickly and plainly when something goes wrong, which section 21 describes.

Contents

12 Your rights under the UK GDPR

Role: controller

These rights apply to personal data for which we are the controller. Where we act as processor for a client, section 2.2 explains that you should approach the client.

12.1 How to exercise any of these rights

Write to [email protected] with the subject Data protection request, or post a letter to the registered office. Describe what you want; we will work out which right applies and tell you which one we used. No form, no Article citation, no reasons and no charge.

12.2 Identity verification

Before we act we must be satisfied that you are who you say you are, because disclosing personal data to the wrong person is itself a breach. A request from an email address already in the correspondence we hold is usually enough. Otherwise we ask for one further piece of evidence proportionate to the sensitivity of the data, such as confirmation of details we already hold. We ask for the least we can, keep identity evidence no longer than the request, and start the one month period when we have what we need to verify you.

12.3 Timing, extensions and refusals

We respond without undue delay and within one month of a verified request. Where a request is complex, or where you have made several, we may extend by up to two further months, telling you within the first month and explaining why.

We may refuse a manifestly unfounded or excessive request, or charge a reasonable fee instead of refusing. We may also be unable to comply in full where an exemption in the Data Protection Act 2018 applies, where complying would disclose another person's data, or where another law requires us to keep the record. The usual example is accounting records, kept six years under section 388 of the Companies Act 2006. Whenever we refuse or restrict a response we name the ground relied on and tell you about your right to complain to the ICO and to seek a judicial remedy.

12.4 Right of access, Article 15

You may ask whether we process your personal data and receive a copy, with the purposes, categories, recipients, retention period, source and your other rights. We provide it electronically in a common format unless you ask otherwise. Where a document contains another person's data we redact that part rather than withhold the whole document.

12.5 Right to rectification, Article 16

Inaccurate data can be corrected and incomplete data completed, including by adding a statement of your own. Where we have disclosed the data to a recipient in section 8, we tell that recipient about the correction unless it is impossible or disproportionate, and we tell you who we told.

12.6 Right to erasure, Article 17

You may ask us to delete data that is no longer needed for its purpose, where consent is withdrawn and no other basis applies, where you object and no overriding ground remains, or where processing was unlawful. We refuse in whole or in part where we need the record for a legal obligation such as the accounting retention above, or for legal claims within the six year limitation period, and we say which applies to which records.

12.7 Right to restrict processing, Article 18

You may ask us to pause processing while a dispute about accuracy or about the balance of legitimate interests is resolved, or instead of erasure where you need the data preserved for a claim. While a restriction is in force we store the data and do nothing else with it except with your consent or for legal claims, and we tell you before lifting it.

12.8 Right to data portability, Article 20

Where we process data you provided by automated means, on consent or on a contract with you, you may receive it in a structured, commonly used, machine readable format and ask us to transmit it to another controller where that is technically feasible. In practice this covers correspondence and documents you sent, provided as plain text, comma separated values or the original file.

12.9 Right to object, Article 21

You may object at any time to processing based on legitimate interests. We must stop unless we can show compelling legitimate grounds overriding your interests, rights and freedoms, or that we need the data for legal claims. An objection to direct marketing is honoured immediately with no balancing test, and you are added to the suppression record in section 10 so it survives.

12.10 Rights relating to automated decisions, Article 22

You have the right not to be subject to a decision based solely on automated processing producing legal effects or similarly significant effects. Section 13 explains that we make no such decisions about you.

12.11 Right to withdraw consent

Where processing rests on consent you may withdraw it at any time, as easily as you gave it, by replying to the message or writing to our contact address.

Contents

13 Automated decision making

Role: controller and processor

As controller we make no decisions about you by solely automated means. We do not score enquiries, profile visitors, or use any system that decides whether to reply without a person reading the message.

As processor, the workflows we build may include automated steps, some using a language model. Our position, stated on the home page as a scope limit and repeated here as a commitment, is that we do not build automated decisions determining credit, insurance underwriting, medical triage, immigration status or employment outcomes without a human decision maker in the path. Where a client's workflow would engage Article 22, we say so at the specification step, design in the human review point, and record it so the client can evidence it later.

Contents

14 Cookies and this website

Role: controller

This site sets no cookies of its own, runs no tracking scripts, embeds no social widgets, and has no consent banner because there is nothing to consent to. Its one third party request is to Google Fonts for the two typefaces, which discloses your IP address to Google. Full detail, including what our network provider may set for security, is in the cookie notice.

Contents

15 Mobile applications

Role: controller

As at the effective date, WORKFLOW AI SOLUTIONS LTD has published no application on the Apple App Store or on Google Play. Nothing in sections 15 to 18 describes a product that exists today.

The company's registered activity includes software development, so we may publish one, and store review requires a notice that already answers these questions. The commitments below bind the first application we publish. If one needs different treatment, we update this notice before submission.

  • No third party advertising software development kits.
  • No selling or sharing of personal data for anyone else's marketing.
  • The smallest set of device permissions the feature needs, requested when the feature is first used rather than on first launch.
  • An in-application account and data deletion path, as section 19 describes.
  • A Google Play Data Safety declaration and Apple privacy labels that match this notice.

Contents

16 Device permissions

Role: controller

How each device permission would be treated in an application we publish. Nothing requests any of these today, because nothing has been published.

Permission policy for any application published by the company
Permission Why it would be requested Required or optional If you decline How to revoke
Notifications To tell you a workflow step needs approval or a run has failed Optional The application works. You see the same items when you next open it. iOS: Settings, Notifications, then the app. Android: Settings, Apps, then the app, then Notifications.
Camera Only to photograph a document you chose to attach to a workflow item Optional You can still attach an existing file. Nothing else is lost. iOS: Settings, Privacy and Security, Camera. Android: Settings, Apps, then the app, then Permissions, then Camera.
Photos and files To let you attach a document from your device to a workflow item Optional Attachment from the device library is unavailable. Everything else works. iOS: Settings, Privacy and Security, Photos. Android: Settings, Apps, then the app, then Permissions, then Photos and videos or Files.
Precise or approximate location Not requested. No feature needs it. Not applicable Not applicable Not applicable
Contacts Not requested. Colleagues come from your organisation's own directory, not your device address book. Not applicable Not applicable Not applicable
Microphone Not requested. Not applicable Not applicable Not applicable
Biometric unlock, Face ID or fingerprint To unlock the application locally where your organisation requires it Optional You sign in with your normal credentials instead. iOS: Settings, Face ID and Passcode, Other Apps. Android: Settings, Security, then the app's biometric setting.
Tracking, iOS App Tracking Transparency Not requested. See section 17. Not applicable Not applicable iOS: Settings, Privacy and Security, Tracking, where you can switch off tracking requests for every app.

Scroll the table sideways to read every column

Declining a permission never disables a feature that does not need it, and we will not re-ask for one you refused more than once in a session.

Contents

17 App Tracking Transparency on iOS

Role: controller

Apple's App Tracking Transparency framework requires an application to ask permission before tracking a user across apps and websites owned by other companies, or before reading the device advertising identifier.

An application we publish will not present the App Tracking Transparency prompt, because it will not track you across other companies' apps or websites and will not read the advertising identifier. There is no advertising network in it, no attribution software development kit and no data broker relationship to feed. If that ever changed, the prompt would appear and this section would be rewritten before release.

Contents

18 Google Play Data Safety

Role: controller

Google Play requires a Data Safety declaration covering what an application collects and shares, whether data is encrypted in transit and whether a deletion route exists. It is read by people who will never open this page, so it must agree with this notice line by line.

For any application we publish, the declaration will state that data is encrypted in transit, that a deletion route exists both in the application and by email, that no data is shared for advertising or marketing, and that no data is used for tracking across other companies' applications. The categories declared as collected will be exactly those in section 4 plus any account data described here at release, and no more.

If you find a difference between the declaration and this notice, tell us, and treat this notice as the statement we intend to be held to while we correct the other.

Contents

19 Account and data deletion

Role: controller

19.1 The in-application route

Any application we publish will carry a deletion control inside the application, reachable without contacting us, at Settings, Account, Delete account. It asks you to confirm once, states what will be deleted and what must be retained, and starts the deletion.

19.2 The email route

You may instead write to [email protected] with the subject Account deletion request. This works whether or not the application is still installed, and it is the route for data we hold about you as a correspondent.

19.3 Timing

We complete deletion within 30 days of a verified request and confirm in writing. A copy remaining in a backup is not restored into use and ages out on the cycle in section 10, which does not exceed 90 days.

19.4 What is retained afterwards, and why

  • Accounting records with your name and payment details, where you or your organisation paid us. Six years under section 388 of the Companies Act 2006. We cannot delete these on request.
  • A suppression record, your email address and the fact that you asked not to be contacted, so the request is honoured permanently.
  • The record of the deletion request, three years, so we can show it was handled correctly.
  • Anything needed for a live legal claim, only while the claim is live.

Everything else goes. We will tell you specifically what was kept rather than pointing you back at this list.

Contents

20 Children

Role: controller

This is a business to business practice. Our services and this site are not directed at children and we do not knowingly collect personal data from anyone under 18. If you believe a child has sent us personal data, write to us and we will delete it.

Contents

21 Personal data breaches

Role: controller and processor

21.1 What counts as a breach

A personal data breach is a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data. Losing access to data counts, not only leaking it.

21.2 Containment and assessment

On becoming aware of a suspected breach we contain it first: revoke the credential, close the exposure, isolate the account. We then record what happened, the categories and approximate numbers of individuals and records involved, the likely consequences and the measures taken. That record is kept whether or not the breach is reportable, as Article 33(5) requires.

21.3 Notifying the ICO, Article 33

Where a breach is likely to result in a risk to people's rights and freedoms we notify the Information Commissioner's Office without undue delay and, where feasible, not later than 72 hours after becoming aware of it. If we cannot provide everything within 72 hours we report what we have and supply the rest in phases, saying why. If we conclude a breach is not reportable, we record the reasoning, because that judgement has to be defensible later.

21.4 Notifying you, Article 34

Where a breach is likely to result in a high risk to your rights and freedoms we tell you directly, without undue delay, in plain language: the nature of the breach, our contact point, the likely consequences, the measures taken or proposed, and anything you can do to protect yourself. We will not delay telling you in order to finish an investigation, and we will not write a message whose main purpose is to make the incident sound smaller.

21.5 When we are the processor

Where the breach affects client personal data we hold as processor, we notify the client without undue delay, which the processing agreement fixes at no later than 24 hours. The client as controller decides on notification to the ICO and to individuals, and we supply what they need to do it.

Contents

22 Complaints and the ICO

If you are unhappy with how we handled your personal data or a request about it, tell us at [email protected]. We acknowledge within five working days and answer substantively within one month.

You do not have to come to us first. You may complain at any time to the United Kingdom supervisory authority, the Information Commissioner's Office:

  • Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
  • Telephone: 0303 123 1113
  • Website: ico.org.uk

You also have the right to an effective judicial remedy under Articles 78 and 79 of the UK GDPR.

Contents

23 Changes to this notice

This is version 1.0, effective 7 August 2026, the first version published by the company.

Any change updates the version number and effective date above. Where a change materially affects how we use data we already hold, we tell affected people directly rather than relying on you to re-read the page. Superseded versions are kept and available on request.

Contents